Industry Intel - Conference Recaps and Thought Leadership Article

Reputation Was Never a Risk Model

Federal regulators just codified the end of “reputation risk” as a supervisory tool. The subjective shortcut that drove years of de-risking is gone — and what has to replace it is evidence.

The vaguest phrase in banking just lost its power

For years, “reputation risk” was the most powerful phrase in a bank examiner’s vocabulary — precisely because it was the vaguest. It did not require evidence of financial-crime exposure or a safety-and-soundness problem. It only required that a customer, an industry, or an activity might look bad. And “might look bad” was often enough to make a bank quietly show a lawful customer the door.

On April 7, 2026, that changed. The OCC and the FDIC issued a final rule codifying the elimination of reputation risk from their supervisory programs, barring examiners from criticizing or taking adverse action against a bank based on risks to public perception “not clearly and directly related to the financial or operational condition of the institution.” The Federal Reserve has proposed to follow. The subjective lever that helped drive a decade of wholesale de-risking is being removed from the supervisor’s hand.

Reputation was never a risk model. It was a permission slip — to act on discomfort without having to measure anything.

The regulators made the case against themselves

The most striking thing about this rule is who is indicting the old approach: the regulators themselves. In their own explanation, using reputation risk as a basis for supervisory criticism increased subjectivity without adding material safety-and-soundness value. The agencies conceded they had never clearly articulated how a bank should even measure it, and that supervision in this area came to reflect the individual perspectives of examiners rather than data-driven conclusions.

Read that back slowly, because it is a remarkable admission: a concept that shaped real-world banking decisions for years was, in practice, closer to instinct than to analysis. Removing it is of a piece with the broader direction of supervision — toward measurable, evidence-based judgments and away from the unquantifiable.

Your BSA obligations did not move an inch

Here is the misread to avoid, and it is an important one. This is not a deregulation of financial crime. The rule constrains regulators, not your AML program. Every existing safety-and-soundness, BSA/AML, OFAC, and consumer-protection obligation remains fully in force. The rule even includes an anti-evasion provision that bars examiners from using credit, operational, or compliance risk as a pretext to smuggle a reputation judgment back in through another door.

So the point is not that risk stopped mattering. The point is narrower and sharper: only real, measurable risk is allowed to count.

From “might look bad” to “here is what we found”

Strip the politics away and, underneath, this is a data story. For years, reputation risk let institutions substitute a feeling for an assessment. Whole categories of lawful customers — money services businesses, digital-asset firms, certain nonprofits, cash-intensive businesses — were de-risked wholesale, not because each one had been screened and found risky, but because the category felt risky and the exam was simpler if you just did not bank it.

That option is closing. When “it might look bad” is no longer a defensible basis, and cannot be laundered through compliance risk, the only legitimate ground left for a customer decision is what you can actually demonstrate: this specific customer, screened against sanctions, PEP, and adverse-media data, presents — or does not present — measurable risk, and here is the evidence.

Trade the category for the customer

The institutions that navigate this cleanly will make five moves:

  1. Replace category exclusions with customer-level assessment. “We don’t bank this industry” is exactly the reflex the rule targets. Move from blanket category calls to screening and risk-rating the individual customer in front of you.
  2. Make decisions you can evidence. For every decline or exit, be able to point to the specific, financial-crime-based reason for it — not a reputational one. If the only reason is “optics,” that is no longer a reason.
  3. Audit for buried reputation calls. Find the places where “compliance risk” or “operational risk” was quietly standing in for “we’re uncomfortable,” and re-ground them in measurable risk. The anti-evasion rule now scrutinizes exactly this substitution.
  4. Separate franchise choices from risk findings. A bank can still make private business decisions on reputational or franchise grounds. But call that what it is — a business choice — and do not let it masquerade as a risk determination in your files.
  5. Invest in the data that tells the two apart. Distinguishing “reputationally awkward” from “actually risky” is a data problem before it is a policy problem. Better data is what lets you keep good customers and decline genuinely risky ones — and prove which is which.

Evidence is the only defensible currency left

The through-line is simple. When subjective judgment is removed, evidence is what has to fill the gap. The institutions that come through this well will be the ones that can screen a customer, quantify the real risk, and document the basis for every decision — to include someone, or to decline them.

VITAL4

See How Vital4 Grounds Decisions In Evidence

REQUEST A DEMO