For most of the last decade a sponsor bank that declined a merchant category could point to a word in its examiner's handbook: reputation risk. It was one of the eight risks the OCC supervised for, it appeared in the FDIC's guidance on payment-processor relationships, and it let a prohibited-merchant list rest on something other than the numbers. That word is now gone from the examination programs of the OCC, the FDIC, the Federal Reserve and the NCUA, and since 9 June 2026 the OCC and FDIC are prohibited by their own regulation from using it.
For the people who run merchant onboarding this is not an abstract change. The FDIC rewrote the payment-processor guidance your sponsor bank applies to you, the OCC has published findings naming the sectors the largest national banks restricted, and the same regulators have said in the same documents what a bank may still refuse a customer for. Here is what the rule binds, what it leaves alone, and what to put in an underwriting policy, drawn from the rule text, the agencies' own bulletins and the executive order behind them, as of September 2026.
What the Rule Says, and Who It Binds
The final rule, published in the Federal Register on 10 April 2026 and effective 9 June, is titled Prohibition on the Use of Reputation Risk by Regulators, and the last two words are the point. It binds the OCC and the FDIC, not the banks they supervise. The agencies say so directly: the proposal did not include prohibitions, restrictions, or requirements on the self-directed activities of supervised institutions, and the final rule adopts it with minor modifications.
What it prohibits is specific. The OCC will not criticise, formally or informally, or take adverse action against an institution on the basis of reputation risk, and will not require, instruct, or encourage an institution or any employee to refrain from contracting or doing business with a third party, to terminate or modify such a relationship, or to enter one, on that basis. A separate paragraph bars the agencies from pushing a bank to drop, refuse, or change its terms with any person or entity on the basis of political, social, cultural or religious views, constitutionally protected speech, or solely on the basis of involvement in politically disfavored but lawful business activities perceived to present reputation risk. The FDIC's text at 12 CFR 302.100 is parallel.
Adverse action is defined widely: negative feedback in a report of examination, a downgrade or contribution to a downgrade of any supervisory rating, denial of or conditions on a licensing application, heightened requirements on an activity, or any action that treats the institution differently than similarly situated peers. Doing business with covers providing any product or service, including account services, and contracting with a third party for a product or service, which is where an ISO or payment facilitator sits.
Reputation risk itself is defined as any risk, regardless of how the risk is labeled by the institution or regulators, that an action or activity of an institution could negatively impact public perception of the institution for reasons not clearly and directly related to the financial or operational condition of the institution. The final rule added the words about operational condition; the reasoning in the preamble is that most activities that could damage a bank's reputation do so through traditional risk channels the agencies already supervise.
Where the Other Agencies Are
The rule codifies a policy each agency announced in 2025: the OCC said on 20 March 2025 that it would no longer examine for reputation risk, and the Federal Reserve announced on 23 June 2025 that reputational risk would no longer be a component of its examination programs, adding that the change was not intended to impact whether and how Board-supervised banks use the concept of reputational risk in their own risk management practices. The Board proposed its own codifying rule on 23 February 2026; as of mid-September 2026 the Federal Register shows no final rule from it. The NCUA finalised its rule on 25 June 2026, effective 27 July.
The clean-up has continued since. On 2 June 2026 the OCC, FDIC and Federal Reserve reissued fifteen interagency guidance documents with references to reputation risk removed and said they expect to expeditiously remove any further references, and the FFIEC's proposed revision of the CAMELS rating system, published 19 May 2026, would remove all references to reputation risk from the framework examiners rate banks against. All of it traces to Executive Order 14331, Guaranteeing Fair Banking for All Americans, signed 7 August 2025, which gave the regulators 180 days to remove reputation risk or equivalent concepts from their guidance documents, manuals, and other materials.
The Payment-Processor Guidance Lost the Word, Not the Duties
The document that matters most to a merchant-services business is not the rule. It is FIL-3-2012, Payment Processor Relationships, Revised Guidance, the FDIC letter that tells its banks how to underwrite and monitor the third parties that process payments for merchants. On 3 February 2026 the FDIC revised the letter and its attachment to remove references to reputation risk. Before the revision the guidance said a processor without adequate merchant vetting could pose money laundering and fraud risk to a bank, as well as legal, reputational, and compliance risks if consumers are harmed, and that banks should consider the potential for legal, reputational, and other risks; the current text reads legal and compliance risks, and legal and other risks. The word was removed twice and nothing was added.
Everything else in the letter survives, and it is the list your sponsor bank is still examined against. Banks should understand, verify, and monitor the activities and the entities related to the account relationship, and cannot rely solely on due diligence performed by the payment processor. Their contracts with processors should give them timely access to information, provide for immediate account closure or termination, and establish adequate reserves for anticipated chargebacks. A processor approval program should extend beyond credit risk management and include background checks on the processor, its principal owners and its merchant clients, a review of the processor's own due-diligence standards for new merchants, and whether it resells through agents or ISO opportunities or a gateway arrangement. Nested processors and aggregators, the letter says, may be extremely difficult to monitor and control, and risk is significantly elevated in those cases.
The letter's remaining risk categories are the ones a decline has to be written in now: operational, strategic, credit, compliance and transaction risk, plus legal risk, consumer complaints, returned items, and exposure to claims of unfair or deceptive practices under Section 5 of the FTC Act. The same day's revisions stopped short of the companion letter, FIL-43-2013 on merchant customers engaged in higher-risk activities, which never used the term and still says that institutions with appropriate systems and controls will not be criticized for providing payment processing services to businesses operating in compliance with applicable law.
Older underwriters will recognise the arc. The FDIC's 2011 Supervisory Insights article and its 2012 and 2013 letters carried lists of merchant categories associated with higher risk; on 28 July 2014 the FDIC removed them, saying they had created the misperception that the listed examples of merchant categories were prohibited or discouraged, and in January 2015 it encouraged banks to assess individual customer relationships rather than declining to provide banking services to entire categories of customers. The 2026 rule is the same instruction with teeth.
The Other Direction: What the OCC Now Holds Against a Bank
The rule constrains regulators. Two other OCC actions constrain banks, and they are what will actually change a sponsor's behaviour. On 8 September 2025 the OCC issued Bulletin 2025-22, which says that as part of its holistic review of licensing filings it considers, on a case by case basis, a bank's record of and policies and procedures designed to avoid engaging in politicized or unlawful debanking, and that whether a bank has engaged in it is a factor the OCC may consider in determining the bank's CRA rating. The filings covered run from new charters and business combinations to changes in control and changes in directors and senior executive officers. A bank that wants to buy, merge or expand now has a reason to be able to show its declines were risk-based.
On 10 December 2025 the OCC published preliminary findings from its review of the nine largest national banks it supervises. Between 2020 and 2023, it found, those banks made inappropriate distinctions among customers in the provision of financial services on the basis of their lawful business activities by maintaining policies restricting access to banking services or requiring escalated reviews and approvals before providing certain customers access to financial services. At least one bank restricted sectors for activities that, while not illegal, are contrary to the bank's values. The sectors named were oil and gas exploration, coal mining, firearms, private prisons, tobacco and e-cigarette manufacturers, adult entertainment, and digital assets. Four of those seven are the spine of any high-risk merchant vertical list, and escalated reviews and approvals is a description of most high-risk onboarding queues. Comptroller Gould's June 2026 testimony to the House Financial Services Committee said the OCC has made considerable progress in reviewing the largest banks and is investigating complaints of alleged debanking.
The executive order reaches payments by name: section 4(b) required the SBA to instruct its lenders to identify potential clients denied access to payment processing services through a politicized or unlawful debanking action and notify each of the renewed option to engage in such services. Its definition of debanking covers any act by a bank or other financial services provider to directly or indirectly adversely restrict access to, or adversely modify the conditions of, accounts, loans, or other banking products or financial services on the basis of political or religious beliefs, or lawful business activities the provider disagrees with or disfavors for political reasons. Indirectly, and adversely modify the conditions of, are the words that reach pricing and reserve decisions taken on a sponsor's instruction.
What the Rule Leaves Alone
None of this is a right to be boarded, and an underwriting team that reads it that way will mis-sell. Three things are expressly untouched.
First, the financial and legal risks. The preamble says the rule does not prohibit supervisory feedback on traditional risk channels related to safety and soundness and compliance with applicable laws, including credit risk, market risk, and operational risk, including cybersecurity, information security, and illicit finance, provided the feedback is not a pretext designed to covertly continue supervision for reputation risk. Chargeback exposure, refund liability, return rates and Section 5 exposure are all still reasons to decline, price or reserve.
Second, the Bank Secrecy Act. The rule text says nothing in it restricts the agencies' authority to enforce the reporting provisions of Title 31, and the prohibition on views-based pressure does not apply to persons, entities or jurisdictions sanctioned by OFAC. The caution runs both ways: because BSA/AML supervision is broad enough to indirectly address reputation risk, supervisors may not use BSA and anti-money laundering concerns as a pretext for it. A sponsor's customer due diligence and suspicious activity reporting are exactly as required as they were in May.
Third, the card networks. A regulator's rule does not amend a private network's operating regulations, and the brand-protection standard those regulations contain is, in terms, a reputation standard. Mastercard's Security Rules and Procedures, Merchant Edition, dated 4 August 2026, describe the Business Risk Assessment and Mitigation program as enforcing rules under which a customer must not engage in or facilitate any action that is illegal or that, in the opinion of the Corporation, damages or may damage the goodwill or reputation of the Corporation or of any Mark. Visa's Integrity Risk Program, covered on this site earlier this week, runs on the same footing, and no OCC rule prevents a network case. The sponsorship agreement is a private contract too: a sponsor may still write a restricted-merchant list into it, and the rule only guarantees that its examiner did not ask for one.
What to Put in Place
- Re-read your prohibited and restricted merchant lists and strike the word. Any category, decline reason or escalation trigger that rests on reputation, brand, values or public perception should be re-based on a named risk from FIL-3-2012: credit, operational, compliance, legal, consumer complaints, return rates, or a card-network prohibition, with the number or rule that supports it. If none supports it, the OCC's December findings describe what the category now looks like to a regulator.
- Separate escalation from restriction, and document the risk behind each. Enhanced due diligence on a higher-risk vertical is still expected under the FDIC guidance and BSA rules; an escalated review that exists because the vertical is disfavored is what the OCC named. The record should show what additional risk the review is checking for.
- Write decline and termination reasons a sponsor can defend in a licensing file. Bulletin 2025-22 makes a bank's record of avoiding politicized debanking a factor in charters, mergers and changes in control, and your declines, taken under the sponsor's program, are part of that record.
- Keep network prohibitions as a separate column. A merchant the sponsor may not decline for reputation risk can still be one Mastercard's BRAM rules or Visa's Integrity Risk Program will not tolerate. Cite the network rule, not the bank's preference.
- Ask the sponsor which version of the guidance it is working from. FIL-3-2012 was revised on 3 February 2026; a sponsor's policy manual that still lists reputation risk as an underwriting factor is behind its own regulator. If the sponsor is a Federal Reserve member bank, the Board's rule was still a proposal in mid-September 2026 and its June 2025 statement is what governs its examiners.
The One-Line Version
Federal regulators can no longer tell a sponsor bank to drop you, price you up or hold you in review because of how your merchants look, and the guidance sponsors apply to payment processors has been rewritten to say so; but the same regulators still expect every decline to rest on credit, operational, legal or BSA risk, the OCC now counts a bank's debanking record against it, and the card networks' own brand rules are exactly where they were. The lists have to be rewritten, not thrown away.
Tags
About the author

Kyle Hall
Founder
Kyle Hall is a fintech entrepreneur, software engineer, and marketing strategist with over a decade of experience in high-risk payment processing and SaaS development. He is the CEO of PayKings, a leader in high-risk merchant services, and the founder of PulseCRM, a purpose-built CRM platform for the payments industry. Kyle specializes in building custom payment processing systems and growth strategies that empower merchant services providers to scale and succeed in the digital marketplace.
