ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Sound Risk Culture and Risk Culture Programs: An Evolving Necessity

April 30, 2015
Reading Time: 4 mins read

By Eugene Ludwig

A sound risk culture is a vital component of an overall risk framework, and it is increasingly becoming a regulatory necessity. As Federal Reserve Bank of New York President William Dudley recently told a supervisory conference, “Improving culture in the financial services industry is a necessity.” Similar sentiments have been voiced by virtually all other regulatory leaders.

A successful risk culture that satisfies regulatory expectations requires strong formal risk management and compliance programs. Attempts to shape a sound culture without strong, formal risk and compliance programs will miss the mark. Regulators are looking for a risk culture that does not just foster good attitudes, but it produces results that support risk management and compliance efforts. Regulators have underlined this point both on and off the record.

A strong risk management framework today must include:

  • A strong risk appetite statement;
  • A strong board governance process, including credible challenge;
  • A strong three-lines-of-defense system consistent with heightened regulatory standards;
  • A strong compliance program, including BSA/AML and sanctions, FATCA, and consumer issues
  • High-integrity risk-related data and systems; and
  • For the largest banks, successful CCAR, CLAR, and resolution and recovery programs.

It is up to the board and senior management to ensure that such a framework is in place. Without it, it is hard to envision a successful risk culture that produces the kind of outcomes that the regulatory community would like to see. But a risk management framework that is not aligned with a strong culture will not work. If a financial entity’s employees do not display the ethics, behavioral norms, and attitudes that align with its governance and risk management policies, those policies will not be successfully implemented.

The risk-culture norms and program discussed below are meant to align with the emerging regulatory standards in this area. These standards are becoming less theoretical and more about behaviors and outcomes. Tone will always be important in terms of direction, as will institutional values. But increasingly regulators are looking for a positive alignment of tone, effort and—most important—concrete outcomes.

Fundamental principles for a sound risk culture

The foundation of a sound risk culture can be articulated in nine principles:

  1. Understand and follow, in letter and in spirit, all rules and regulations that apply to your business.
  2. Understand and follow, in letter and in spirit, all company policies and procedures applicable to your business, including those related to the risk and control systems.
  3. Understand and openly discuss the risks that are part of your business, and take risks that are consistent with the company’s risk appetite statement.
  4. Be open and honest with colleagues, particularly on any concerns about risk-related behaviors.
  5. Communicate truthfully on all matters within and outside the company. “Speak truth to power” when necessary for good of the company.
  6. Create products you understand and can readily explain to your customers, including all risks. In designing and selling those products, behave with customers as you would with a close friend or family member.
  7. Reject temptation to compromise standards in pursuit of competitive edge with others inside and outside company.
  8. Constructively challenge preconceptions, and escalate concerns in a timely, constructive way, encouraging the same of others.
  9. Learn from adverse outcomes through open dialogue and analysis of root causes.

Adherence to the elements of a sound risk culture should be regularly assessed, primarily by:

  • Second-line-of-defense and internal audit findings;
  • Regulatory feedback, including number of violations cited, MRAs, MRIAs, or other criticisms, as well as the topic of those regulatory actions;
  • Customer complaints received by the company or the regulatory community about the company, including indirect social media activity;
  • Periodic testing/surveys with other stakeholders (such as customers and suppliers); and
  • Group and individual attitudes about the company’s culture and commitment, as disclosed through formal and informal surveys and interactions.

Training for a sound risk culture

Training should be compulsory for all new employees and is meant to ensure that all colleagues, at every level, understand the bank’s risk appetite and risk focus—what the bank will and won’t do.

Continuing employment should be contingent upon participation in refresher training, which enables staff to continue to apply and contribute to the bank’s sound risk culture in all their work activities. The training will provide real-life examples of events in the company that led to sound risk decisions for the business and its customers.

The bank’s training program should include periodic “clinics” and bulletins, to highlight where a risk matter has emerged or been identified and how the company assessed, escalated, and addressed it.

The bank’s training program should also have a management dimension—what it means to lead, manage, incentivize, and measure within a sound risk culture. It should have a module for new managers and other modules for established managers.

The bank’s board should also receive dedicated training to reflect their role in overseeing and challenging the bank’s culture.

Enforcement of a sound risk culture

Violations of a bank’s rules should be reflected, on an ongoing basis, in appraisals, promotions, and advancement opportunities, as well as compensation and retention decisions.

What else does a bank need to have a sound risk culture?

In addition to enforcement mechanisms of the type outlined above, a bank should reinforce its risk culture efforts with the use of the following “tools.”

  • Management and the board of directors must set the “tone at the top” for the program, by articulating and enforcing the principles that drive it.
  • Management should continually work to strengthen the company’s risk and control program, staying alert to ensure it does not become a check-the-box exercise.
  • Management should measure the company’s and its professionals’ adherence to risk principles and use the results to fine tune as needed.
  • The company’s compensation and other incentive structures should support a healthy risk culture and the open consideration of risk issues.

In sum, banks need to have—and many have—a sound risk culture. Today, what is meant by risk culture and a risk culture program has become more clearly articulated by the regulatory community. However, the rules and expectations that the regulatory community applies to risk culture programs will evolve over the next several years.

One thing is clear: A strong risk culture and risk culture program will be increasingly important to the regulators. All banks should take these regulatory concerns very seriously.

Eugene Ludwig is the founder of Promontory Financial Group and a former comptroller of the currency.

Tags: Risk management
ShareTweetPin

Related Posts

Agencies form strike force to target cryptocurrency scams

Agencies form strike force to target cryptocurrency scams

Compliance and Risk
November 12, 2025

Federal law enforcement agencies announced the formation of an interagency “strike force” to target Southeast Asian cryptocurrency-related investment scams and confidence schemes.

ABA, associations object to CFPB ‘junk fee’ label for mortgage-related fees

CFPB proposes changes to fair lending enforcement

Compliance and Risk
November 12, 2025

The CFPB is proposing to remove disparate impact from its enforcement of the Equal Credit Opportunity Act, clarify the prohibition on discouraging prospective applicants, and establish new limits on special-purpose credit programs offered by lenders.

CFPB launches ‘tip line’ to report on bureau employees

CFPB proposes to streamline small-business data collection rule

Ag Banking
November 12, 2025

The CFPB is proposing revisions to its small-business lending data rule to scale back the scope of data collection, saying that adopting a “longer-term” approach that allows for the future addition of more data points would be the...

ABA Fraudcast: The bank that breaks the spell

ABA Fraudcast: The bank that breaks the spell

Compliance and Risk
November 12, 2025

Santander UK’s scam-interruption team confronts delicate issues for customers in difficult moments.

Fed releases agenda for upcoming conference on large bank capital requirements

Fed finalizes revisions to rating system for large banks

Compliance and Risk
November 5, 2025

The Federal Reserve finalized revisions to its supervisory rating framework for large banks to address the “well managed” status of the institutions.

Treasury Department seeks feedback on stablecoins, illicit activities

ABA, associations share recommendations for implementing Genius Act

Compliance and Risk
November 5, 2025

As the Treasury Department crafts regulations to implement the Genius Act, it should seek to preserve the benefits of payment stablecoins without causing unnecessary risks for customers, credit availability and financial stability, ABA and four associations said in...

NEWSBYTES

House votes to end government shutdown

November 12, 2025

Agencies form strike force to target cryptocurrency scams

November 12, 2025

U.S. Mint produces last penny

November 12, 2025

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: The Erie Canal at 200

November 6, 2025

Podcast: Why branches are top priority for PNC

October 23, 2025

Podcast: From tractors to drones, how farming tech affects ag lending

October 16, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.