DiGi Advisory
All insights

Regulatory Commentary

Reputation Risk Leaves the Rating Sheet: A Test of Whether Your Governance Was Real or Exam-Driven

By Thomas DiGiovanni, Partner and Founder

July 21, 20265 min read

Reputation risk is being removed from bank supervision, and the rating that once forced institutions to watch it is going with it. The removal is a test of whether governance was real or exam-driven. The institutions that keep owning, measuring, and reporting the exposure will be the ones still watching when a name becomes a liability.

Reputation risk is being removed from bank supervision. Not softened, removed. The Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) finalized a rule prohibiting the use of reputation risk in supervision, effective June 9, 2026, and the Federal Reserve has moved to codify the same removal. The National Credit Union Administration (NCUA) stopped examining for reputation risk on September 25, 2025. The Federal Financial Institutions Examination Council (FFIEC) struck all 92 references to the term from its Information Technology Examination Handbook. A proposed revision to the rating system examiners use, out for comment until August 17, 2026, would pull the last references out of the framework itself. The common thread is Executive Order 14331, Guaranteeing Fair Banking for All Americans, signed August 7, 2025, which directed the agencies to stop treating a customer's reputation as a basis for supervisory pressure.

The rating stopped naming the risk. The risk did not go anywhere. A deposit base can still run. A funding line can still tighten after a bad headline. A partner can still walk away from an institution whose name has become a liability. What changed on June 9 is not the exposure. It is who is watching for it. For years, reputation risk carried an external owner by default: the examiner who asked about it. Remove the question, and in many institutions the internal owner quietly leaves with it. The removal is, in that sense, a test of whether an institution governed reputation risk because it mattered, or because someone was going to grade it.

What changed, and what did not

The agencies did not decide reputation risk is unreal. They decided it is not a legitimate basis for a regulator to criticize a bank, and in particular not a basis to push a bank into closing lawful accounts it finds politically or socially disfavored. That is the debanking concern the executive order was written to address, and it is a fair one. A supervisory judgment was being used as a lever, and removing the lever is defensible.

What the action does not do is relieve an institution of the underlying exposure. Reputational damage is still one of the fastest ways a bank or credit union loses a deposit base, and it rarely arrives on its own. It travels with a conduct failure, a data breach, a third-party blowup, a compliance miss becoming a news story. Before the references leave your rating, map where reputation risk was implicitly carried inside your current component ratings and your risk appetite, so you know exactly what you are about to stop being graded on.

The ownership question the removal exposes

In most institutions, reputation risk was never cleanly owned. It sat across compliance, communications, the business lines, and the second-line risk function, raised when an examiner asked and otherwise left unassigned. The arrangement held together only because the examination supplied the pressure. Take the pressure away and the seams show.

The danger is not that ownership transfers to the wrong place. It is that ownership evaporates. Most institutions can point to a policy mentioning reputation risk. Far fewer can name the executive accountable for it once the examiner stops asking. Assign that ownership explicitly, inside the taxonomy and risk appetite you already run rather than in a new silo, consistent with the Committee of Sponsoring Organizations of the Treadway Commission (COSO) Enterprise Risk Management framework, which treats risk ownership and appetite as responsibilities of the board and management, not of the examiner.

Measurement, before you need it

Reputation risk has always been the softest entry in the taxonomy to measure. It lived in narrative, in a paragraph in the board report, in the qualitative judgment behind the Management rating. The rating gave it a place to sit even when the measurement behind it was thin. Remove the rating and the thinness is exposed, because now there is no external prompt to produce evidence at all.

That is the opening for institutions willing to do the work. The measures exist. Complaint volume and trend, deposit and funding-flow movements against a baseline, partner and correspondent attrition, negative-media velocity, and conduct metrics already collected for other purposes can be assembled into a short set of leading indicators with stated thresholds and escalation triggers. The point is not an elaborate reputation dashboard. It is to ensure a real move in any of these signals reaches someone with the authority to act, on a defined cadence, whether or not an examiner ever asks to see it.

The rating recalibration underneath it

The removal is arriving alongside a larger change to the rating system itself. The proposed revision to the Uniform Financial Institutions Rating System, known as CAMELS for the six areas it scores (Capital, Asset quality, Management, Earnings, Liquidity, and Sensitivity to market risk), is out for comment until August 17, 2026. It would remove all references to reputation risk, and it would do more. It refocuses the ratings on factors materially affecting financial condition, emphasizes material financial risk over concerns about policies and documentation, and removes the special consideration the Management component has long been given in the composite rating. Governance quality used to reach the composite rating largely through the Management component and through reputation. Both channels are narrowing at once. An institution reading only the surface will hear that examiners care less about governance now. That reading is a trap. Fewer places for governance to land on the rating does not mean governance matters less. It means the institution, not the examiner, now has to keep it visible.

A control that exists only because it is inspected is not a control. It is a performance. Supervision is being deliberately narrowed this year, across reputation risk, across the Management component, across the checklist posture that defined the broader supervisory reset. Each narrowing hands something back to the institution to own. Reputation risk did not become safe on June 9. It became yours. Govern it because it matters. Measure it because you can. Own it because no one else is required to anymore.


Back to all insights

A 15-minute triage call to find the fastest path.

Start a Conversation