The Regulators Were Right to Drop Reputational Risk…

…But now we need to talk about the holes it leaves behind.

When the Office of the Comptroller of the Currency (OCC) and the Federal Deposit Insurance Corporation (FDIC) jointly proposed removing “reputation(al) risk” from their supervisory remit, an initial reading might prompt alarm: are regulators really stepping back from the oversight of reputational harm and public trust?

A closer analysis reveals the opposite. The proposal represents a necessary clarification in a debate that has occupied supervisory circles since the early 2000s. Having previously co-authored a specialist text on reputational risk in financial institutions, I have long argued that reputational risk is not a discrete risk category but a channel through which other risks propagate. In that sense, the OCC/FDIC’s position is not radical, it is overdue.

What the NPR achieves is a clean separation between perception and prudential risk. What it exposes, however, are several deeper questions that the industry can no longer avoid.

Supervising reputation was always conceptually unsound

The agencies’ reasoning is well-founded. Reputational risk has always been analytically weak, difficult to define and even harder to measure. Different stakeholders interpret reputational harm through different moral, political or social lenses. Using reputation as a supervisory anchor thus invites subjectivity and injects value judgements into a regime that relies on objective, evidence-based determinations of safety and soundness.

The agencies also acknowledge that there is little evidence that supervisory actions taken “in the interest of protecting a bank’s reputation” have improved outcomes. Instead, such actions have sometimes led to pressure on institutions to terminate customer relationships or limit business lines based not on financial or legal concerns, but on perceived social or political sensitivities.

In this context, the NPR’s prohibition on using reputational considerations as the basis for supervisory criticism is a logical correction. Reputation is not a risk class. It is an outcome, an impact, a consequence.

But eliminating a flawed concept does not eliminate the dynamics it previously attempted – imperfectly – to capture. Instead, the removal reveals where the real gaps lie.

Reputational risk never existed, only reputational consequences

The critical truth is this: reputational damage does not arise in isolation. It is invariably the consequence of failures elsewhere in operational risk, conduct, credit underwriting, market behaviour, liquidity management, governance or strategic decision-making.

A fraud event, a discriminatory lending pattern, a cyber breach, an ill-considered product, or a poorly communicated business strategy will all generate public scrutiny, often long before the formal risk indicators crystallise. Supervising reputational risk, therefore, misdiagnoses the problem. It focuses on the visible surface rather than the underlying failure.

By formally retiring the category, the agencies clear away a layer of conceptual clutter. What remains are four unresolved areas where clarity, policy discipline and industry debate are now unavoidable.

1. Boundary problems and the role of public perception

The first issue concerns the boundary between public perception and verifiable supervisory concerns. Many risks already straddle categories – the classic cases involving credit and operational risk attest to this – but public perception creates a boundary problem across conduct, compliance, fair lending, governance and strategic behaviour.

Consider a lender whose stringent eligibility criteria produce patterns that, while legal, generate public accusations of redlining or unfair treatment. The controversy may be reputational, but the underlying question is regulatory: do the data and decision processes reveal a breach of fair lending rules or unsafe practices?

Under the NPR, examiners cannot rely on reputational controversy alone. They must base findings solely on statutory or prudential grounds. This is appropriate. Yet it raises a practical challenge: when public perception is the earliest signal of a deeper issue, how should supervisors legitimately interpret it?

The supervisory perimeter must remain anchored in law and evidence. But if perception routinely functions as an early-warning data point, we need a more explicit articulation of how such signals trigger legitimate investigative steps without reintroducing reputational judgement through the back door.

2. Regulatory action and claims for reputational harm

A second issue arises from the possibility of unintended legal consequences. If agencies are now explicitly barred from acting based on reputational concerns, what happens when their own enforcement actions trigger reputational damage?

Enforcement orders, by design, become public. They can materially affect market confidence, counterparties’ willingness to transact, and consumer trust. They may produce financial consequences equal to or greater than the underlying infraction.

Could a bank, facing severe reputational fallout from a regulatory action, argue that the agency exceeded its authority by imposing consequences in which in turn had reputational effects? Could this shift the litigation narrative: from “the regulator acted within its mandate” to “the regulator produced reputational harm that it is no longer permitted to consider”?

Most likely, courts will continue to grant deference where actions are grounded in demonstrable breaches. But by drawing a firm line in the NPR, the agencies alter the rhetorical landscape. They will need to ensure even greater precision in tying supervisory findings to explicit statutory authority.

3. Liquidity crises, market discipline and reputational acceleration

The third issue concerns systemic risk. Bank runs, whether traditional or social-media-driven, often begin with rumours and perceptions. These reputational signals may weaken confidence long before liquidity metrics flash red. A misinterpreted earnings release, a viral claim on social media, or an external downgrade can accelerate liquidity stress dramatically.

The NPR acknowledges that reputational deterioration can amplify other risks but seeks to ring-fence “reputation risk” as conceptually distinct from the underlying financial conditions. In doing so, it raises a fundamental question in crisis management:

How should supervisors justify intervention in cases where the trigger is predominantly reputational, but the consequences are undeniably prudential?

Under the proposal, agencies cannot cite “reputational risk” as a reason to intervene, yet the practical need to act may be driven by exactly those dynamics. This requires a clearer articulation of how reputational accelerants to liquidity and market risk will be addressed – not as a standalone risk class but as a well-understood form of risk transmission.

Market discipline and supervisory intervention have always existed in tension. Removing reputational reasoning heightens the need for clarity around when and how prudential authorities may act in sentiment-driven crises.

4. Culture, governance and the risk of ethical drift

The final gap concerns culture, the domain where reputational reasoning has historically been used as shorthand for “this is inappropriate even if it is technically permissible.”

Conflicts of interest, exclusionary leadership cultures, misaligned incentives and borderline behaviours rarely manifest as quantifiable risks in the short term. Yet they erode the foundations of governance and stakeholder trust over time.

If regulators now step back from any language that resembles reputational concern, there is a risk, particularly in organisations with weaker governance, that some leaders interpret this as permission to downplay ethical and cultural issues. The risk is not that supervisors will cease to care about culture; rather, that boards may mistakenly infer that the supervisory spotlight has shifted elsewhere.

The NPR does not diminish expectations around culture or conduct. But the industry now needs a more explicit understanding of how these themes will be governed and escalated without relying on the older, looser vocabulary of reputational risk.

What Should Replace Reputational Risk?

Eliminating an unsound concept does not leave a vacuum. It creates an opportunity to strengthen the foundations that should have been carrying the weight all along.

First, reputational outcomes must be treated explicitly as lagging indicators of underlying failures whether in conduct, operational controls, strategy, risk management or governance. Boards should stop asking “What is our reputational risk?” and instead ask: What within our behaviour, incentives, policies, systems or decisions is likely to create stakeholder harm?

Second, cross-boundary governance needs strengthening. Issues that trigger public scrutiny nearly always sit across multiple risk domains. A siloed approach ensures that systemic patterns go unchallenged.

Third, early-warning indicators must be integrated into formal escalation processes. Complaints patterns, whistleblower reports, sentiment analysis and customer behaviour shifts are not reputational metrics, they are signals of emerging underlying risk.

Fourth, supervisory communication must become more precise. Without the shorthand of reputational language, examiners will need to anchor expectations more tightly in the statutory and prudential framework. That discipline will improve clarity for all parties.

None of this expands the regulatory perimeter. It sharpens the tools already within it.

A necessary reset. But not the end of the conversation

The OCC and FDIC are right to eliminate reputational risk from the supervisory lexicon. Their proposal aligns regulatory practice with risk theory, reduces ambiguity, and curtails the risk of politically charged or subjective judgments.

But the removal of a flawed category does not negate the importance of what it imperfectly described. Stakeholder trust, public confidence and franchise value remain central to financial resilience. The difference now is that both regulators and firms must confront the root causes, not the reputational symptoms.

If the industry misreads this NPR as permission to ignore cultural failings or stakeholder expectations, the result will be weaker governance, not stronger institutions. If, instead, it uses the change to clarify boundaries, reinforce conduct oversight and integrate early-warning signals into broader risk management, the NPR will have achieved exactly what good regulation should: it will have improved the quality of supervision without expanding it.

Eliminating reputational risk from the rulebook is a welcome correction. The real work now lies in strengthening the governance foundations that determine whether reputational consequences arise in the first place.

Stay up to date with the latest stories from the world of governance, risk, audit and compliance >>>

Facebook
Twitter
LinkedIn