|
The Office of the Comptroller of the Currency is working to ensure that banks will no longer be deputy regulators. In the past, banks have often found themselves deputized by the regulators to address concerns both inside and outside of banking. Perhaps the most famous example of this was “Operation Choke Point” that ran from 2013-2017. Banks were encouraged by examiners to avoid doing business in tobacco, firearms, and fossil fuels, for example on the basis of “reputational risk.” In an article in Compliance and Enforcement, lawyers from Davis Wright Tremain LLP point out that this was a departure from the “CAMELS (Capital adequacy, Asset quality, Management, Earnings, Liquidity and Sensitivity [to interest rate changes]) rating system, created in 1979.” In February, Comptroller Jonathan Gould testified at a hearing in the Senate Banking Committee that the agency was moving away from including reputational risk as part of the examination process. “We have also proposed a rule to eliminate reputation risk from supervision, a tool too often used to debank politically disfavored individuals or groups. We are intent on ensuring banks provide access to banking products and services based on individualized, objective, risk-based criteria, not politics or ideology,” Gould testified. As in all things, the devil could be in the details on this. If the regulators began hunting for “debanking” as violation, then the pendulum could swing the other way as potential clients cry foul whenever a bank declines to work with them or offer them a loan. Institutions still need to be able to refuse business that doesn’t fit with their risk profile without the fear of “debanking” violations being used as a cudgel to force them to accept businesses. In a cocktail hour conversation at the recent Innovative payments Conference, one bank lawyer explained to me that she had thought this through. The key for banks will be to explain why a particular business is not a right fit for the bank based on the banks’ risk profile, staffing levels to monitor loans, or similar bank-focused criteria. When Comptroller Gould spoke at our conference, he also said that the OCC would no longer rely on banks to police every third party that touches the banking system. He said it was inappropriate for regulators to force third parties to do what the regulators want them to do. Instead, he said that the regulators would be using their powers to supervise fintechs directly. While it is rare for banking regulators to go after third-party partners directly, it is not without precedent. In 2013, the FDIC imposed a consent order and civil money penalty on Achieve Financial Services, saying that it had the authority to do so because Achieve was an institution-affiliated party of its issuing bank. An “institution-affiliated party” of a bank under the Section 1813(u) of the Federal Deposit Insurance Act includes “any independent contractor (including any attorney, appraiser, or accountant)” that could violate a banking law. The act gives “the appropriate federal banking agency” the right to take actions against institution-affiliated parties directly. Fintechs and other bank parties should be on notice that the regulators are looking their way. Compliance is an essential part of financial services, not just a check-the-box exercise. Ben Jackson is the Chief Operating Officer of the Innovative Payments Association, a leading trade association representing companies in payments. With over two decades of industry experience, Ben is dedicated to providing valuable information, advocacy, and support to help members improve financial outcomes for consumers, businesses, and government agencies. Comments are closed.
|
Archives
July 2026
Categories
All
|
RSS Feed