2026 Pub. 6 Issue 4

The rule goes further than removing a risk category by barring examiners from requiring or encouraging institutions to terminate customer relationships based on political, social, cultural or religious views; constitutionally protected speech; or lawful but politically disfavored business activities. The rule also includes an anti-evasion provision: Examiners cannot reroute reputational risk concerns through compliance, operational or other risk categories as a workaround. Alongside the rule, the OCC and FDIC are also jointly working to finalize a new definition of “unsafe or unsound practice” that would codify, for the first time, a regulatory definition of “unsafe or unsound practice” under Section 8 of the Federal Deposit Insurance Act, tethered to the core concept of material harm to an institution’s financial condition or material risk of loss to the Deposit Insurance Fund. The era of supervisory actions grounded in public perception concerns has ended. In addition, on April 7, 2026, the Financial Crimes Enforcement Network (FinCEN) issued a Notice of Proposed Rulemaking to “fundamentally reform” AML/CFT obligations under the Bank Secrecy Act and the Anti-Money Laundering Act of 2020, which is anticipated to be a significant overhaul of program requirements. Aligned with the new “unsafe or unsound” definition, Secretary of the Treasury Scott Bessent stated that the goal is not to measure success “by the volume of paperwork,” but rather by the “ability to stop illicit finance threats.” A well-designed BSA/AML program should align with the principles of fair access to banking services and require individualized, documented decisions in each instance. The challenge that has arisen is when institutions implemented “de-risking” strategies that resulted in exiting wholesale categories of industries or sectors based on “risks” that were not individual to a particular customer. A 2023 U.S. Department of the Treasury report confirmed that many de-risking decisions were “indiscriminate” and “overly broad,” driven by category-level judgments that bore little relationship to actual financial crime risk. The OCC issued guidance in September 2025, further reminding institutions that Suspicious Activity Report (SAR) filings must be grounded in concrete evidence of suspicious activity. Active Enforcement Investigations Underscore Need to Understand Impact A reported wave of recent subpoenas issued by the DOJ to financial institutions is a reminder that all institutions should understand how the removal of reputational risk impacts both current operating procedures and documented, historical risk-based decisions. At a minimum, banks should: 1. Confirm no remnants of reputational risk, categorical or industry-based risk-tiers or escalation requirements exist within policies and procedures (e.g., political, religious, ESG-based criteria) for whether a customer qualifies for bank services; 2. Update policies and procedures, if needed, to require individualized decisions with a focus on impartial and financially based metrics and criteria; 3. Confirm procedures are in place to comply with the Right to Financial Privacy Act when responding to government requests for information; The Show-Me Banker Magazine | 17

RkJQdWJsaXNoZXIy MTg3NDExNQ==