ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Sound Risk Culture and Risk Culture Programs: An Evolving Necessity

April 30, 2015
Reading Time: 4 mins read

By Eugene Ludwig

A sound risk culture is a vital component of an overall risk framework, and it is increasingly becoming a regulatory necessity. As Federal Reserve Bank of New York President William Dudley recently told a supervisory conference, “Improving culture in the financial services industry is a necessity.” Similar sentiments have been voiced by virtually all other regulatory leaders.

A successful risk culture that satisfies regulatory expectations requires strong formal risk management and compliance programs. Attempts to shape a sound culture without strong, formal risk and compliance programs will miss the mark. Regulators are looking for a risk culture that does not just foster good attitudes, but it produces results that support risk management and compliance efforts. Regulators have underlined this point both on and off the record.

A strong risk management framework today must include:

  • A strong risk appetite statement;
  • A strong board governance process, including credible challenge;
  • A strong three-lines-of-defense system consistent with heightened regulatory standards;
  • A strong compliance program, including BSA/AML and sanctions, FATCA, and consumer issues
  • High-integrity risk-related data and systems; and
  • For the largest banks, successful CCAR, CLAR, and resolution and recovery programs.

It is up to the board and senior management to ensure that such a framework is in place. Without it, it is hard to envision a successful risk culture that produces the kind of outcomes that the regulatory community would like to see. But a risk management framework that is not aligned with a strong culture will not work. If a financial entity’s employees do not display the ethics, behavioral norms, and attitudes that align with its governance and risk management policies, those policies will not be successfully implemented.

The risk-culture norms and program discussed below are meant to align with the emerging regulatory standards in this area. These standards are becoming less theoretical and more about behaviors and outcomes. Tone will always be important in terms of direction, as will institutional values. But increasingly regulators are looking for a positive alignment of tone, effort and—most important—concrete outcomes.

Fundamental principles for a sound risk culture

The foundation of a sound risk culture can be articulated in nine principles:

  1. Understand and follow, in letter and in spirit, all rules and regulations that apply to your business.
  2. Understand and follow, in letter and in spirit, all company policies and procedures applicable to your business, including those related to the risk and control systems.
  3. Understand and openly discuss the risks that are part of your business, and take risks that are consistent with the company’s risk appetite statement.
  4. Be open and honest with colleagues, particularly on any concerns about risk-related behaviors.
  5. Communicate truthfully on all matters within and outside the company. “Speak truth to power” when necessary for good of the company.
  6. Create products you understand and can readily explain to your customers, including all risks. In designing and selling those products, behave with customers as you would with a close friend or family member.
  7. Reject temptation to compromise standards in pursuit of competitive edge with others inside and outside company.
  8. Constructively challenge preconceptions, and escalate concerns in a timely, constructive way, encouraging the same of others.
  9. Learn from adverse outcomes through open dialogue and analysis of root causes.

Adherence to the elements of a sound risk culture should be regularly assessed, primarily by:

  • Second-line-of-defense and internal audit findings;
  • Regulatory feedback, including number of violations cited, MRAs, MRIAs, or other criticisms, as well as the topic of those regulatory actions;
  • Customer complaints received by the company or the regulatory community about the company, including indirect social media activity;
  • Periodic testing/surveys with other stakeholders (such as customers and suppliers); and
  • Group and individual attitudes about the company’s culture and commitment, as disclosed through formal and informal surveys and interactions.

Training for a sound risk culture

Training should be compulsory for all new employees and is meant to ensure that all colleagues, at every level, understand the bank’s risk appetite and risk focus—what the bank will and won’t do.

Continuing employment should be contingent upon participation in refresher training, which enables staff to continue to apply and contribute to the bank’s sound risk culture in all their work activities. The training will provide real-life examples of events in the company that led to sound risk decisions for the business and its customers.

The bank’s training program should include periodic “clinics” and bulletins, to highlight where a risk matter has emerged or been identified and how the company assessed, escalated, and addressed it.

The bank’s training program should also have a management dimension—what it means to lead, manage, incentivize, and measure within a sound risk culture. It should have a module for new managers and other modules for established managers.

The bank’s board should also receive dedicated training to reflect their role in overseeing and challenging the bank’s culture.

Enforcement of a sound risk culture

Violations of a bank’s rules should be reflected, on an ongoing basis, in appraisals, promotions, and advancement opportunities, as well as compensation and retention decisions.

What else does a bank need to have a sound risk culture?

In addition to enforcement mechanisms of the type outlined above, a bank should reinforce its risk culture efforts with the use of the following “tools.”

  • Management and the board of directors must set the “tone at the top” for the program, by articulating and enforcing the principles that drive it.
  • Management should continually work to strengthen the company’s risk and control program, staying alert to ensure it does not become a check-the-box exercise.
  • Management should measure the company’s and its professionals’ adherence to risk principles and use the results to fine tune as needed.
  • The company’s compensation and other incentive structures should support a healthy risk culture and the open consideration of risk issues.

In sum, banks need to have—and many have—a sound risk culture. Today, what is meant by risk culture and a risk culture program has become more clearly articulated by the regulatory community. However, the rules and expectations that the regulatory community applies to risk culture programs will evolve over the next several years.

One thing is clear: A strong risk culture and risk culture program will be increasingly important to the regulators. All banks should take these regulatory concerns very seriously.

Eugene Ludwig is the founder of Promontory Financial Group and a former comptroller of the currency.

Tags: Risk management
ShareTweetPin

Related Posts

CFPB claims ‘complex’ pricing drives up cost of financial products

CFPB: Creditors may be required to check immigration status

Compliance and Risk
June 8, 2026

Creditors may be legally obligated to check a consumer's immigration status for mortgage loans and credit cards, especially where removal from the U.S. may disrupt the consumer's income, the CFPB said.

ABA urges FinCEN to reevaluate BOI collection burden on banks

FinCEN issues advisory on suspicious activity linked to employment of undocumented immigrants

Compliance and Risk
June 5, 2026

FinCEN issued an advisory warning financial institutions “to be vigilant against risks presented by the unlawful employment of illegal aliens.” The advisory was jointly issued with the FDIC, OOC, NCUA and IRS.

House lawmakers propose federal studies on AI in financial services, housing

Proposed bill seeks to establish federal regulation of AI

Compliance and Risk
June 5, 2026

Two lawmakers have released a draft bipartisan bill to establish a national regulatory framework for artificial intelligence, including increased penalties for AI-enabled fraud and temporary preemption of state laws regulating AI models.

FinCEN issues guidance to help bank customers understand new BOI reporting rules

GAO: Expanded exemptions leave holes in beneficial ownership reporting

Compliance and Risk
June 4, 2026

The Treasury Department has not taken steps to address gaps in beneficial ownership reporting resulting from its decision to exempt U.S. companies from the requirements, the Government Accountability Office concluded in a new report.

ABA urges ‘same risk, same regulation’ for digital assets

ABA: Data privacy bill leaves banks in existing federal privacy regulation framework

Compliance and Risk
June 3, 2026

ABA said that legislation to establish national data privacy standards contains many of the policy priorities that it has advocated for over the years, including ensuring that banks continue to be subject to the Gramm-Leach-Bliley Act framework.

ABA urges FCC not to impair banks’ communications with customers

ABA: Regulation of foreign call centers will not combat fraud

Compliance and Risk
June 3, 2026

ABA urged the Federal Communications Commission not to impose additional regulation on foreign call centers belonging to banks and other non-telecommunications companies.

NEWSBYTES

New York Fed: Consumer inflation expectations held steady in May

June 8, 2026

ABA: Proposed rule would further erode legal restrictions on credit union membership

June 8, 2026

NCUA adopts rule to assert federal preemption over state interchange laws

June 8, 2026

SPONSORED CONTENT

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026
Credit Memos at the Convergence Point

Credit Memos at the Convergence Point

May 1, 2026

PODCASTS

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

Podcast: How consumer deposits drive full relationship banking

May 14, 2026

Podcast: How an Ohio banker talks with policymakers about stablecoin issues

May 6, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.