Skip to content
RiskTemplates · The Daily Brief Wednesday, September 2, 2026
Wire Lugano Diamonds SEC Fraud Case: How $1B in Alleged Fake Revenue Beat the Control Stack SEP 1

Feature Compliance Strategy

Reputation Risk Is Gone from Bank Supervision. Here's What the OCC-FDIC Final Rule Actually Changes.

Effective June 9, 2026, OCC and FDIC are prohibited from using reputation risk as a basis for examination findings or supervisory pressure. The rule targets regulatory debanking—but banks retain full discretion over which customers to serve. Here's what changed and what compliance teams need to know.

By Rebecca Leung · August 31, 2026 ·
Table of Contents

TL;DR

  • Effective June 9, 2026, the OCC and FDIC are prohibited from using reputation risk as a basis for examination findings or supervisory pressure
  • The rule targets regulatory debanking: agencies cannot instruct or encourage banks to drop customers based on political views, protected speech, or lawful but politically sensitive business activities
  • Banks retain full discretion over which customers to serve—the rule limits what regulators can do, not what banks can do
  • 15 interagency guidance documents have been reissued with reputation risk references removed
  • Anti-evasion provision blocks supervisors from relabeling reputation risk concerns as credit, operational, or compliance findings

For years, the friction between banks and politically disfavored industries—crypto companies, legal firearms dealers, payday lenders, cannabis-adjacent businesses—was often driven by a supervisory concept that was never clearly defined: reputation risk.

If a regulator thought a bank’s exposure to a controversial industry created reputational exposure for the institution, they could raise it in an examination. Not as a credit deficiency, not as a BSA/AML gap, not as a documented operational control failure—just as reputation risk. And since reputation risk was legitimate supervisory territory, the concern had teeth. Banks that wanted to avoid examination friction found it easier to avoid the exposure.

On June 9, 2026, that changed.


What the Final Rule Does

The OCC and FDIC joint final rule—published in the Federal Register on April 10, 2026, effective June 9, 2026—operates on two levels:

Level one: it removes reputation risk from the supervisory toolkit. The OCC and FDIC can no longer criticize a bank or take adverse action against it on the basis that a business activity creates reputational exposure for the institution. Genuine credit, operational, or compliance concerns can still be raised. Reputation risk, standing alone as an independent supervisory basis, is gone.

Level two: it prohibits agency-directed debanking. The rule bars the OCC and FDIC from requiring, instructing, or encouraging a bank to:

  • Close customer accounts based on a person’s political, social, cultural, or religious views
  • Exit relationships based on constitutionally protected speech
  • Take adverse action against customers in lawful business activities perceived to present reputation risk

This second component addresses what regulators and Congress documented as a pattern: informal examination pressure that pushed banks away from customers in politically sensitive industries. The rule codifies that this pathway is closed.


What the Final Rule Does Not Do

This is where the practical compliance picture becomes nuanced—and where some early reactions to the rule have overstated its effect.

The rule regulates agency conduct, not bank conduct. No obligations are imposed on supervised entities. Banks are not required to serve any particular customer or industry. A bank that decides it doesn’t want to serve crypto companies, or legal firearms dealers, or adult content businesses, can still make that decision based on its own business judgment, risk appetite, or risk management framework.

What the rule prohibits is regulators using examination leverage to drive that decision. If a bank chooses to exit a relationship for its own legitimate reasons—genuine credit risk, documented fraud exposure, real BSA/AML concerns, or simply a business model that doesn’t fit—the rule doesn’t interfere. If a regulator was the driving force behind that exit through explicit instruction or informal supervisory pressure, that’s what’s now prohibited.

BSA/AML, OFAC, and consumer protection obligations are fully intact. The rule is explicit: all safety-and-soundness, BSA/AML, OFAC, and consumer protection requirements survive. A regulator who identifies an actual deficiency—inadequate transaction monitoring for a high-risk customer segment, weak KYC/CIP controls, genuine UDAAP exposure—can still act on it. The rule doesn’t provide cover for compliance gaps. It closes one specific supervisory pathway: reputation risk as a standalone basis for adverse action.

The Federal Reserve was not a party to this rule. The OCC and FDIC are jointly bound. The Fed has separately removed reputation risk references from interagency guidance documents it participates in, but it has not adopted the same prohibition through separate rulemaking.


The Anti-Evasion Provision

The most technically significant provision in the rule is the anti-evasion framework.

The rule anticipates that removing reputation risk from the supervisory toolkit creates an incentive to relabel it. A supervisor who believes a bank’s exposure to a controversial industry creates reputational risk could, in theory, characterize that concern as an “operational risk finding” or a “compliance program gap” to achieve the same supervisory outcome while nominally complying with the rule.

The anti-evasion provision closes that pathway: supervisors cannot use credit risk, operational risk, compliance risk, or other traditional categories as a pretext to supervise for reputation risk. If the underlying concern is reputational exposure, relabeling it as something else violates the rule.

For banks, this provision has both defensive and documentation value.

Defensive: If you receive an examination finding in a traditional risk category that you believe is actually motivated by reputational concerns—particularly for a relationship in an industry the OCC or FDIC has previously flagged on reputation grounds—you have a substantive basis to raise the anti-evasion framework. This isn’t just pushback on the examiner’s conclusion; it’s a claim that the finding methodology itself violates the rule.

Documentation: When building compliance files for relationships in politically sensitive industries, being explicit about the genuine risk analysis—credit exposure, fraud risk, BSA/AML assessment, UDAAP review—creates a record showing the decision was based on actual risk criteria, not reputation. That documentation matters both defensively (if the relationship is questioned) and proactively (as evidence that you’re applying consistent standards across your book of business).


The 15 Guidance Documents

Alongside the final rule, the OCC, FDIC, and Federal Reserve have reissued 15 interagency guidance documents with reputation risk references removed. That’s a significant parallel action—it addresses the fact that examiner thinking is shaped not just by formal rules but by the interagency guidance documents that define supervisory standards.

Removing reputation risk references from those documents reduces the surface area for reputation-risk-adjacent examination questions. Examiners drawing on pre-June 2026 guidance versions might still ask questions that don’t apply under the new framework.

For compliance teams, the practical step is updating your reference materials. If you’re using pre-June 2026 versions of interagency guidance for examination preparation, training, or policy development, update to the current versions. This is also a natural moment to review examination preparation checklists for any reputation risk framing that’s been carried forward from prior exam cycles.


What This Means for Industries That Were Frequently Flagged

The industries most directly affected by informal reputation risk supervision—crypto companies, legal firearms dealers, payday lenders, cannabis-adjacent businesses—should not read this rule as a guarantee of banking access. Banks retain full discretion over which customers to serve.

What the rule does is remove one layer of regulatory pressure. If a bank was avoiding these industries primarily because of concerns about examination friction—not because of genuine credit, fraud, or compliance concerns—the rule eliminates that driver. Banks that were already comfortable serving these industries aren’t directly affected; they weren’t under supervisory pressure to exit. Banks that were making relationship decisions based on what they believed regulators wanted to see have less regulatory basis for that concern going forward.

The practical effect is likely to be gradual. Some banks will reassess relationship decisions made in the prior supervisory environment. Others won’t change their practices—and aren’t required to, since the rule imposes no obligations. The industries that spent years hearing “it’s not us, it’s our regulators” will need to evaluate that answer in the new environment, knowing the regulatory excuse is now significantly harder to sustain.

For fintechs operating in BaaS structures, one caution: this rule addresses what federal regulators can require of banks. It doesn’t constrain a sponsor bank’s independent business judgment about which fintech partners to support. If your bank partner has concerns about your product category, customer base, or compliance program—concerns that are genuinely theirs, not driven by regulatory pressure—the rule doesn’t change that calculus. As the Bilt-Wells Fargo bank partner exit analysis illustrated, bank partner decisions about fintech relationships are business decisions with regulatory dimensions that don’t simplify neatly.


What Compliance Teams Should Actually Do

Review pending examination findings for reputation risk components. If you have open MRAs or examination findings that reference reputation risk as a standalone concern—without an independent credit, operational, or compliance rationale—those findings are worth reviewing in light of the rule. They don’t automatically disappear, but the rule creates a substantive basis for discussion with your primary regulator about whether the finding can be sustained under the new framework.

For context on how examiners frame MRA standards more broadly—including the new materiality threshold and “supervisory observations” category from the OCC/FDIC joint rulemaking—see the analysis of the unsafe or unsound practice final rule.

Update your examination preparation materials. The interagency guidance documents have been reissued. Examination preparation checklists, training programs, and policy references should reflect June 2026 versions. Pre-rule versions may describe examiner expectations that no longer apply.

Document relationship decisions with genuine risk analysis. For any relationship that might be questioned—particularly in industries that were previously reputation-risk-adjacent—ensure your file reflects a real risk analysis. Credit exposure, fraud risk, BSA/AML assessment, consumer protection review. “This customer segment doesn’t fit our risk profile” is weaker documentation than “our transaction monitoring data shows an above-threshold SAR rate for this customer segment, creating BSA/AML exposure that we’ve assessed as not mitigable within our control environment.”

The documentation standard matters because the anti-evasion provision works in both directions. If you’re exiting a relationship for genuine risk reasons, explicit documentation of those reasons demonstrates the decision wasn’t reputation-driven. If a regulator later challenges the exit as inconsistent with the rule, your file shows you applied a risk-based framework, not a reputation-based one.

Don’t assume this changes anything for CCO personal liability. The reputation risk rule removes one supervisory tool from regulators—it doesn’t change the compliance officer’s personal accountability for the institution’s compliance program. The SEC and FINRA’s CCO liability framework, detailed in the CCO personal liability analysis, applies to compliance program failures regardless of which supervisory concepts regulators are or aren’t using. A compliance program that was inadequate under the reputation risk framework remains inadequate under the new one if genuine compliance gaps exist.


The Compliance Program Implication

The reputation risk rule doesn’t create new compliance requirements—it removes something regulators were previously allowed to do. The near-term compliance program impact is limited: update reference materials, review pending findings, improve documentation on sensitive relationships.

The longer-term implication is more structural. A supervisory environment where examiners can’t reach for reputation risk as a catch-all is one where examination outcomes should be more consistently grounded in verifiable facts—actual credit quality, documented BSA/AML controls, specific consumer compliance metrics. For compliance programs that are already well-documented and controls-based, that’s good news. For programs that relied on regulatory goodwill or relationship capital to avoid examination scrutiny on genuinely thin controls, the shift to a fact-based standard is an exposure.

The rule’s most lasting contribution may be to the documentation culture: when the supervisory standard requires a genuine risk basis for every finding, the compliance program that can demonstrate a genuine risk analysis for every relationship decision is better positioned than one that relied on informal understanding of what regulators wanted to see.


If you need to track examination findings—including MRAs that are transitioning from reputation risk bases to genuine compliance rationales—through documented remediation, the Issues Management Tracker provides a structured system for managing findings from regulatory exams, internal audits, and self-identified sources through to documented closure with evidence.


Sources

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does the OCC-FDIC reputation risk final rule prohibit?
The rule prohibits the OCC and FDIC from criticizing or taking adverse action against a financial institution on the basis of reputation risk. It also prohibits the agencies from requiring, instructing, or encouraging a bank to close customer accounts or take other adverse actions based on a person's political, social, cultural, or religious views, constitutionally protected speech, or lawful business activities perceived to present reputation risk.
When did the reputation risk final rule take effect?
The final rule was published in the Federal Register on April 10, 2026, and became effective June 9, 2026. It is a joint OCC-FDIC rule. The Federal Reserve was not a party to this rulemaking, though the Fed and other agencies have separately removed reputation risk references from interagency guidance documents.
Does the reputation risk rule require banks to serve crypto companies, firearms dealers, or other politically sensitive industries?
No. The rule regulates only the agencies' conduct—it does not impose any obligations on supervised entities. Banks retain full discretion over which customers and industries to serve. What the rule prohibits is regulators using examination pressure or informal guidance to push banks away from lawful but politically sensitive business activities.
What is the anti-evasion provision in the reputation risk rule?
The rule includes an anti-evasion framework that prohibits supervisors from using traditional risk categories—credit risk, operational risk, or compliance risk—as a pretext to supervise for reputation risk. If a supervisor's underlying concern is reputational exposure, relabeling it as a credit or operational finding to evade the rule is itself a rule violation.
What happens to existing examination findings that reference reputation risk?
Banks should review pending MRAs and examination findings that cite reputation risk as a standalone concern. The rule explicitly preserves findings grounded in genuine safety-and-soundness, BSA/AML, OFAC, or consumer protection violations. But findings where reputation risk was the primary or sole basis may be worth revisiting with your primary regulator.
Do BSA/AML, OFAC, and consumer protection obligations still apply after the reputation risk rule?
Yes, fully. The rule preserves all existing safety-and-soundness, BSA/AML, OFAC, and consumer protection requirements. If a regulator identifies a real compliance deficiency—genuine credit risk, inadequate transaction monitoring, BSA/AML gaps—they can still act on it. The rule prohibits reputation risk as an independent supervisory basis, not as context for genuine compliance failures.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.