Industry Intel - Conference Recaps and Thought Leadership Article
Federal regulators just codified the end of “reputation risk” as a supervisory tool. The subjective shortcut that drove years of de-risking is gone — and what has to replace it is evidence.
For years, “reputation risk” was the most powerful phrase in a bank examiner’s vocabulary — precisely because it was the vaguest. It did not require evidence of financial-crime exposure or a safety-and-soundness problem. It only required that a customer, an industry, or an activity might look bad. And “might look bad” was often enough to make a bank quietly show a lawful customer the door.
On April 7, 2026, that changed. The OCC and the FDIC issued a final rule codifying the elimination of reputation risk from their supervisory programs, barring examiners from criticizing or taking adverse action against a bank based on risks to public perception “not clearly and directly related to the financial or operational condition of the institution.” The Federal Reserve has proposed to follow. The subjective lever that helped drive a decade of wholesale de-risking is being removed from the supervisor’s hand.
Reputation was never a risk model. It was a permission slip — to act on discomfort without having to measure anything.
The most striking thing about this rule is who is indicting the old approach: the regulators themselves. In their own explanation, using reputation risk as a basis for supervisory criticism increased subjectivity without adding material safety-and-soundness value. The agencies conceded they had never clearly articulated how a bank should even measure it, and that supervision in this area came to reflect the individual perspectives of examiners rather than data-driven conclusions.
Read that back slowly, because it is a remarkable admission: a concept that shaped real-world banking decisions for years was, in practice, closer to instinct than to analysis. Removing it is of a piece with the broader direction of supervision — toward measurable, evidence-based judgments and away from the unquantifiable.
Here is the misread to avoid, and it is an important one. This is not a deregulation of financial crime. The rule constrains regulators, not your AML program. Every existing safety-and-soundness, BSA/AML, OFAC, and consumer-protection obligation remains fully in force. The rule even includes an anti-evasion provision that bars examiners from using credit, operational, or compliance risk as a pretext to smuggle a reputation judgment back in through another door.
So the point is not that risk stopped mattering. The point is narrower and sharper: only real, measurable risk is allowed to count.
Strip the politics away and, underneath, this is a data story. For years, reputation risk let institutions substitute a feeling for an assessment. Whole categories of lawful customers — money services businesses, digital-asset firms, certain nonprofits, cash-intensive businesses — were de-risked wholesale, not because each one had been screened and found risky, but because the category felt risky and the exam was simpler if you just did not bank it.
That option is closing. When “it might look bad” is no longer a defensible basis, and cannot be laundered through compliance risk, the only legitimate ground left for a customer decision is what you can actually demonstrate: this specific customer, screened against sanctions, PEP, and adverse-media data, presents — or does not present — measurable risk, and here is the evidence.
The institutions that navigate this cleanly will make five moves:
The through-line is simple. When subjective judgment is removed, evidence is what has to fill the gap. The institutions that come through this well will be the ones that can screen a customer, quantify the real risk, and document the basis for every decision — to include someone, or to decline them.