Comment on Federal Reserve Reputation Risk Rule (R-1884)
Box Commons · 30 N Gould St Ste N, Sheridan WY 82801
- AI deployment creates a novel category of reputation risk — behavioral failures (biased outputs, hallucinated decisions) damage institutional reputation regardless of cybersecurity posture.
- Third-party behavioral credentialing provides banks with a defensible position when AI incidents occur: the system was independently verified.
- Reputation risk management should incorporate behavioral safety verification as a standard practice for AI-deploying institutions.
+ Jump to Section
I. Support for the Proposed Rule
We strongly support the proposed rule. The elimination of reputation risk from bank supervision is a necessary precondition for the development of objective, standards-based approaches to emerging financial relationships — including those between banking institutions and AI-driven entities.
We urge the Board to go further: to affirmatively recognize that independent third-party credentialing can provide the objective assessment framework that should replace subjective reputation risk evaluations.
II. Reputation Risk Has Functioned as a Barrier in Underserved Communities
The proposed rule correctly identifies that "reputation risk" has been used as a basis for supervisory pressure discouraging banks from serving lawful customers in emerging industries. What the preamble does not fully address is the disproportionate impact on institutions serving underserved communities.
The National Bankers Association has documented how Minority Depository Institutions (MDIs) face compounding challenges when subjective supervisory standards create compliance uncertainty. MDIs lack the compliance infrastructure of megabanks and are more likely to preemptively terminate relationships rather than risk adverse examination findings. When reputation risk standards discourage MDIs from partnering with technology providers, these institutions lose access to modernization tools.
Bill Bynum, CEO of HOPE Credit Union — a CDFI serving over three million people across five states — has testified that partnerships with technology providers are essential to expanding CDFIs' reach. Reputation risk as a supervisory tool creates barriers to exactly these partnerships.
III. Debanking Undermines the Community Reinvestment Act
The National Community Reinvestment Coalition (NCRC) has identified a direct tension between reputation risk-driven debanking and the goals of the Community Reinvestment Act. When banks withdraw from technology partnerships or underserved markets due to reputational pressure, the communities CRA was designed to protect bear the cost.
If the Board eliminates reputation risk from its supervisory framework without providing an alternative, objective basis for evaluating emerging financial relationships, banks may substitute their own subjective assessments for the examiner's — producing the same outcome through private risk aversion rather than supervisory pressure.
IV. The Case for Objective, Standards-Based Alternatives
The proposed rule removes a flawed supervisory tool. We urge the Board to also create the conditions for a better one. Independent third-party credentialing provides the mechanism:
Rather than evaluating whether an AI company's reputation might embarrass a bank, examiners could verify whether the AI company holds a behavioral safety credential from an independent standards body — the same way examiners currently verify whether a bank's cybersecurity vendors hold SOC 2 certifications. This approach is objective, scalable, and does not depend on any individual examiner's subjective assessment of reputational risk.
Contact:
Brice Love, Acting Executive Director
Box Commons
[email protected]
Content Integrity Notice: This comment was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.
Related Filings
Comment on FDIC GENIUS Act: Stablecoin PPSI Implementation
Urges FDIC to incorporate third-party behavioral safety credentialing into GENIUS Act implementing regulations for state-chartered banks. Addresses the unique dual supervision challenge, deposit insurance dimension, and community bank proportionality problem.
OCCComment on OCC Stablecoin NPRM: GENIUS Act for National Banks
Proposes that OCC incorporate behavioral safety credentialing into GENIUS Act implementing regulations for national banks, arguing that the existing SR 11-7 model risk management framework was designed for traditional statistical models and cannot govern autonomous AI agents.
NCUAComment on NCUA GENIUS Act: Behavioral Safety Credentialing for Credit Unions
Urges NCUA to incorporate third-party behavioral safety credentialing into GENIUS Act regulations as a cost-effective mechanism for credit unions to verify vendor-provided AI system safety without requiring in-house model risk management.