ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Sound Risk Culture and Risk Culture Programs: An Evolving Necessity

April 30, 2015
Reading Time: 4 mins read

By Eugene Ludwig

A sound risk culture is a vital component of an overall risk framework, and it is increasingly becoming a regulatory necessity. As Federal Reserve Bank of New York President William Dudley recently told a supervisory conference, “Improving culture in the financial services industry is a necessity.” Similar sentiments have been voiced by virtually all other regulatory leaders.

A successful risk culture that satisfies regulatory expectations requires strong formal risk management and compliance programs. Attempts to shape a sound culture without strong, formal risk and compliance programs will miss the mark. Regulators are looking for a risk culture that does not just foster good attitudes, but it produces results that support risk management and compliance efforts. Regulators have underlined this point both on and off the record.

A strong risk management framework today must include:

  • A strong risk appetite statement;
  • A strong board governance process, including credible challenge;
  • A strong three-lines-of-defense system consistent with heightened regulatory standards;
  • A strong compliance program, including BSA/AML and sanctions, FATCA, and consumer issues
  • High-integrity risk-related data and systems; and
  • For the largest banks, successful CCAR, CLAR, and resolution and recovery programs.

It is up to the board and senior management to ensure that such a framework is in place. Without it, it is hard to envision a successful risk culture that produces the kind of outcomes that the regulatory community would like to see. But a risk management framework that is not aligned with a strong culture will not work. If a financial entity’s employees do not display the ethics, behavioral norms, and attitudes that align with its governance and risk management policies, those policies will not be successfully implemented.

The risk-culture norms and program discussed below are meant to align with the emerging regulatory standards in this area. These standards are becoming less theoretical and more about behaviors and outcomes. Tone will always be important in terms of direction, as will institutional values. But increasingly regulators are looking for a positive alignment of tone, effort and—most important—concrete outcomes.

Fundamental principles for a sound risk culture

The foundation of a sound risk culture can be articulated in nine principles:

  1. Understand and follow, in letter and in spirit, all rules and regulations that apply to your business.
  2. Understand and follow, in letter and in spirit, all company policies and procedures applicable to your business, including those related to the risk and control systems.
  3. Understand and openly discuss the risks that are part of your business, and take risks that are consistent with the company’s risk appetite statement.
  4. Be open and honest with colleagues, particularly on any concerns about risk-related behaviors.
  5. Communicate truthfully on all matters within and outside the company. “Speak truth to power” when necessary for good of the company.
  6. Create products you understand and can readily explain to your customers, including all risks. In designing and selling those products, behave with customers as you would with a close friend or family member.
  7. Reject temptation to compromise standards in pursuit of competitive edge with others inside and outside company.
  8. Constructively challenge preconceptions, and escalate concerns in a timely, constructive way, encouraging the same of others.
  9. Learn from adverse outcomes through open dialogue and analysis of root causes.

Adherence to the elements of a sound risk culture should be regularly assessed, primarily by:

  • Second-line-of-defense and internal audit findings;
  • Regulatory feedback, including number of violations cited, MRAs, MRIAs, or other criticisms, as well as the topic of those regulatory actions;
  • Customer complaints received by the company or the regulatory community about the company, including indirect social media activity;
  • Periodic testing/surveys with other stakeholders (such as customers and suppliers); and
  • Group and individual attitudes about the company’s culture and commitment, as disclosed through formal and informal surveys and interactions.

Training for a sound risk culture

Training should be compulsory for all new employees and is meant to ensure that all colleagues, at every level, understand the bank’s risk appetite and risk focus—what the bank will and won’t do.

Continuing employment should be contingent upon participation in refresher training, which enables staff to continue to apply and contribute to the bank’s sound risk culture in all their work activities. The training will provide real-life examples of events in the company that led to sound risk decisions for the business and its customers.

The bank’s training program should include periodic “clinics” and bulletins, to highlight where a risk matter has emerged or been identified and how the company assessed, escalated, and addressed it.

The bank’s training program should also have a management dimension—what it means to lead, manage, incentivize, and measure within a sound risk culture. It should have a module for new managers and other modules for established managers.

The bank’s board should also receive dedicated training to reflect their role in overseeing and challenging the bank’s culture.

Enforcement of a sound risk culture

Violations of a bank’s rules should be reflected, on an ongoing basis, in appraisals, promotions, and advancement opportunities, as well as compensation and retention decisions.

What else does a bank need to have a sound risk culture?

In addition to enforcement mechanisms of the type outlined above, a bank should reinforce its risk culture efforts with the use of the following “tools.”

  • Management and the board of directors must set the “tone at the top” for the program, by articulating and enforcing the principles that drive it.
  • Management should continually work to strengthen the company’s risk and control program, staying alert to ensure it does not become a check-the-box exercise.
  • Management should measure the company’s and its professionals’ adherence to risk principles and use the results to fine tune as needed.
  • The company’s compensation and other incentive structures should support a healthy risk culture and the open consideration of risk issues.

In sum, banks need to have—and many have—a sound risk culture. Today, what is meant by risk culture and a risk culture program has become more clearly articulated by the regulatory community. However, the rules and expectations that the regulatory community applies to risk culture programs will evolve over the next several years.

One thing is clear: A strong risk culture and risk culture program will be increasingly important to the regulators. All banks should take these regulatory concerns very seriously.

Eugene Ludwig is the founder of Promontory Financial Group and a former comptroller of the currency.

Tags: Risk management
ShareTweetPin

Related Posts

White House pushes state policymakers to restrict ‘junk fees’

White House releases national cybersecurity strategy

Compliance and Risk
March 6, 2026

The White House released its strategy for securing the nation’s infrastructure and private sector against cyber threats.

FS-ISAC issues framework for increasing fraud, cybersecurity team collaboration

Trump signs executive order to combat cybercrime

Compliance and Risk
March 6, 2026

President Trump signed an executive order directing federal law enforcement agencies to develop tools to better combat transnational criminal organizations responsible for cyber scams and fraud, and to establish a program to return seized or forfeited funds from...

FATF updates list of jurisdictions with anti-money laundering deficiencies

FATF updates list of jurisdictions with anti-money laundering deficiencies

Compliance and Risk
March 6, 2026

The Financial Action Task Force has updated its lists of jurisdictions with strategic deficiencies in countering anti-money laundering, the financing of terrorism and the financing of proliferation of weapons of mass destruction.

BIS seeks financial institutions for tokenized deposits project

Banking agencies release FAQ on capital treatment of tokenized securities

Compliance and Risk
March 5, 2026

Financial institutions should treat an eligible tokenized security in the same manner as the non-tokenized form of the security under the capital rule, the Federal Reserve, FDIC and OCC said in a new FAQ.

FinCEN issues alert on identifying deepfakes targeting financial institutions

ABA Foundation, government agencies release infographic on imposter scams

Compliance and Risk
March 5, 2026

The ABA Foundation joined with multiple federal agencies to release a new infographic designed to help consumers identify and avoid increasingly sophisticated imposter scams.

New task force to tackle financial fraud, scams

Bankers urge House lawmakers to take steps to combat fraud, scams

Community Banking
March 5, 2026

Warning that banks cannot fight scams alone, bankers told House lawmakers that federal agencies need to better coordinate their efforts to mitigate the problem and that social media providers and other technology providers also need to do their...

NEWSBYTES

White House releases national cybersecurity strategy

March 6, 2026

Trump signs executive order to combat cybercrime

March 6, 2026

IRS proposes regulations to implement Trump Accounts

March 6, 2026

SPONSORED CONTENT

How top agricultural lenders are approaching AI, automation and innovation in 2026

How top agricultural lenders are approaching AI, automation and innovation in 2026

March 2, 2026
Top 7 FP&A Trends in Banking for 2026

Top 7 FP&A Trends in Banking for 2026

March 1, 2026
How Instant Payments Can Accelerate B2B Payments Modernization

How Instant Payments Can Accelerate B2B Payments Modernization

February 3, 2026
Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

February 1, 2026

PODCASTS

Podcast: How the SCAM Act would encourage platforms to go after scammers

February 4, 2026

A new kind of ‘community bank’ for small businesses

January 22, 2026

Podcast: A Lone Star banking perspective

January 15, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.