A few additional points may be worth considering.
The value of CF should not be derived from the ADC sampling period. The ADC sample rate does not directly determine the stability or correction speed of the buffer. With RF = 1 kΩ and CF = 33 pF, the RF/CF corner is about 4.8 MHz, but this is not the actual crossover frequency between the local and remote feedback paths. The load capacitance, RI, capacitor ESR and ESL, PCB layout, connector inductance, and the open-loop response of the OPA835 all take part.
So 33 pF looks like a reasonable starting value, but the comparison with the OPA835’s 56 MHz gain-of-one bandwidth does not by itself guarantee stability. A much larger value, such as 400 pF, would make the remote correction significantly slower and could bring back the damped ringing seen in the earlier 16-bit design.
Another point is the input bias current of the OPA835. It has bipolar inputs, and the specified bias current can reach about 400 nA at room temperature. At DC, the inverting-input bias current flows through RF.
With RF = 1 kΩ, this can produce about 0.4 mV of reference error, which is approximately 0.8 LSB for a 2.048 V, 12-bit ADC. With RF = 3.3 kΩ, the error can increase to about 1.3 mV, or roughly 2.6 LSB. The correct LSB value is 0.500 mV; the earlier 0.512 mV result used 2.096 V instead of 2.048 V.
This error is mainly a reference gain error rather than a fixed offset in every ADC result. It can be calibrated. Matching the DC resistance at the noninverting input to RF can also cancel much of the common bias-current error, leaving mainly the input offset current and resistor mismatch. The OPA835 input offset voltage should be included in the total error budget as well. In any case, this supports using the lower end of the proposed RF range.
The SAR ADC also does not draw one single current pulse per conversion. It performs a sequence of internal bit decisions during each conversion, with reference-current activity occurring at the ADC clock rate. The exact current waveform is not published, so assumptions about twelve identical spikes, or the MSB pulse always being the largest, should be treated as a useful model rather than a guaranteed internal waveform.
The STM32C092 datasheet gives a typical VREF current of about 65 µA at 2.5 MSPS. This corresponds to approximately 26 pC per conversion. If that charge were supplied entirely by an isolated 100 nF capacitor, the voltage change would be about 0.26 mV, or roughly half an LSB.
This makes the capacitor directly at the MCU VREF+ pin especially important. The local 100 nF capacitor will supply much of the high-frequency current, while the larger capacitors on the buffer board will mainly support the lower-frequency envelope. The exact charge sharing will depend on the connector and PCB inductance, RI, and the impedance of all capacitors involved.
For this reason, measuring only on the buffer board may significantly underestimate the disturbance at the MCU pin. I would inject and probe on both sides of the connector. Adding 1 to 4.7 µF directly beside the existing 100 nF at VREF+ is also worth considering, followed by another stability check with the complete interconnect and capacitor network fitted.
The LQFP64 version of the STM32C092 does have a separate VREF+ pin. The specified VREF+ range starts at 2.0 V, so a nominal 2.048 V reference gives only 48 mV of downward margin. That margin must include reference tolerance and drift, amplifier offset and bias-current errors, and dynamic droop.
Looking forward to the measurements, especially a comparison between injection and probing on the two sides of the connector.