ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Sound Risk Culture and Risk Culture Programs: An Evolving Necessity

April 30, 2015
Reading Time: 4 mins read

By Eugene Ludwig

A sound risk culture is a vital component of an overall risk framework, and it is increasingly becoming a regulatory necessity. As Federal Reserve Bank of New York President William Dudley recently told a supervisory conference, “Improving culture in the financial services industry is a necessity.” Similar sentiments have been voiced by virtually all other regulatory leaders.

A successful risk culture that satisfies regulatory expectations requires strong formal risk management and compliance programs. Attempts to shape a sound culture without strong, formal risk and compliance programs will miss the mark. Regulators are looking for a risk culture that does not just foster good attitudes, but it produces results that support risk management and compliance efforts. Regulators have underlined this point both on and off the record.

A strong risk management framework today must include:

  • A strong risk appetite statement;
  • A strong board governance process, including credible challenge;
  • A strong three-lines-of-defense system consistent with heightened regulatory standards;
  • A strong compliance program, including BSA/AML and sanctions, FATCA, and consumer issues
  • High-integrity risk-related data and systems; and
  • For the largest banks, successful CCAR, CLAR, and resolution and recovery programs.

It is up to the board and senior management to ensure that such a framework is in place. Without it, it is hard to envision a successful risk culture that produces the kind of outcomes that the regulatory community would like to see. But a risk management framework that is not aligned with a strong culture will not work. If a financial entity’s employees do not display the ethics, behavioral norms, and attitudes that align with its governance and risk management policies, those policies will not be successfully implemented.

The risk-culture norms and program discussed below are meant to align with the emerging regulatory standards in this area. These standards are becoming less theoretical and more about behaviors and outcomes. Tone will always be important in terms of direction, as will institutional values. But increasingly regulators are looking for a positive alignment of tone, effort and—most important—concrete outcomes.

Fundamental principles for a sound risk culture

The foundation of a sound risk culture can be articulated in nine principles:

  1. Understand and follow, in letter and in spirit, all rules and regulations that apply to your business.
  2. Understand and follow, in letter and in spirit, all company policies and procedures applicable to your business, including those related to the risk and control systems.
  3. Understand and openly discuss the risks that are part of your business, and take risks that are consistent with the company’s risk appetite statement.
  4. Be open and honest with colleagues, particularly on any concerns about risk-related behaviors.
  5. Communicate truthfully on all matters within and outside the company. “Speak truth to power” when necessary for good of the company.
  6. Create products you understand and can readily explain to your customers, including all risks. In designing and selling those products, behave with customers as you would with a close friend or family member.
  7. Reject temptation to compromise standards in pursuit of competitive edge with others inside and outside company.
  8. Constructively challenge preconceptions, and escalate concerns in a timely, constructive way, encouraging the same of others.
  9. Learn from adverse outcomes through open dialogue and analysis of root causes.

Adherence to the elements of a sound risk culture should be regularly assessed, primarily by:

  • Second-line-of-defense and internal audit findings;
  • Regulatory feedback, including number of violations cited, MRAs, MRIAs, or other criticisms, as well as the topic of those regulatory actions;
  • Customer complaints received by the company or the regulatory community about the company, including indirect social media activity;
  • Periodic testing/surveys with other stakeholders (such as customers and suppliers); and
  • Group and individual attitudes about the company’s culture and commitment, as disclosed through formal and informal surveys and interactions.

Training for a sound risk culture

Training should be compulsory for all new employees and is meant to ensure that all colleagues, at every level, understand the bank’s risk appetite and risk focus—what the bank will and won’t do.

Continuing employment should be contingent upon participation in refresher training, which enables staff to continue to apply and contribute to the bank’s sound risk culture in all their work activities. The training will provide real-life examples of events in the company that led to sound risk decisions for the business and its customers.

The bank’s training program should include periodic “clinics” and bulletins, to highlight where a risk matter has emerged or been identified and how the company assessed, escalated, and addressed it.

The bank’s training program should also have a management dimension—what it means to lead, manage, incentivize, and measure within a sound risk culture. It should have a module for new managers and other modules for established managers.

The bank’s board should also receive dedicated training to reflect their role in overseeing and challenging the bank’s culture.

Enforcement of a sound risk culture

Violations of a bank’s rules should be reflected, on an ongoing basis, in appraisals, promotions, and advancement opportunities, as well as compensation and retention decisions.

What else does a bank need to have a sound risk culture?

In addition to enforcement mechanisms of the type outlined above, a bank should reinforce its risk culture efforts with the use of the following “tools.”

  • Management and the board of directors must set the “tone at the top” for the program, by articulating and enforcing the principles that drive it.
  • Management should continually work to strengthen the company’s risk and control program, staying alert to ensure it does not become a check-the-box exercise.
  • Management should measure the company’s and its professionals’ adherence to risk principles and use the results to fine tune as needed.
  • The company’s compensation and other incentive structures should support a healthy risk culture and the open consideration of risk issues.

In sum, banks need to have—and many have—a sound risk culture. Today, what is meant by risk culture and a risk culture program has become more clearly articulated by the regulatory community. However, the rules and expectations that the regulatory community applies to risk culture programs will evolve over the next several years.

One thing is clear: A strong risk culture and risk culture program will be increasingly important to the regulators. All banks should take these regulatory concerns very seriously.

Eugene Ludwig is the founder of Promontory Financial Group and a former comptroller of the currency.

Tags: Risk management
ShareTweetPin

Related Posts

RCC Preview: Flipping the script on traditional tech risk in banking

RCC Preview: Flipping the script on traditional tech risk in banking

Compliance and Risk
April 17, 2026

In the first part in a series, a risk and compliance expert discusses how technology risk in the financial sector increasingly defies traditional definitions and compliance efforts, and how banks can move beyond siloed thinking.

ABA, associations: FHFA fails to make case for SCP rule change

FHLBs propose allowing letters of credit for discount window advances

Community Banking
April 17, 2026

Federal Home Loan Bank members should be allowed to use short-term FHLB letters of credit to secure advances through the Federal Reserve’s discount window, the Council of FHLBs suggested in a recent letter to FHFA Director Bill Pulte.

Study: Weak fundamentals primary cause of bank failures

Study: Weak fundamentals primary cause of bank failures

Compliance and Risk
April 16, 2026

A recent study of more than 150 years of U.S. bank data has concluded that weak fundamentals are the primary driver of bank failures, and that strong banks usually survive runs.

ABA: Policymakers should avoid changes that reduce credit availability

ABA: Policymakers should avoid changes that reduce credit availability

Compliance and Risk
April 16, 2026

The Fair Credit Reporting Act is a critical consumer protection law that supports responsible lending, and policymakers should avoid changes that could restrict credit availability by reducing data accuracy or adding complexity, banker Veneshia Ferdinand told House lawmakers...

ABA urges FinCEN to reevaluate BOI collection burden on banks

FinCEN touts nearly $2B in interdicted funds related to cybercrime

Compliance and Risk
April 15, 2026

FinCEN's Rapid Response Program has facilitated the interdiction of over $268 million in stolen funds on behalf of U.S. victims since the start of 2025, bringing the total to more than $1.8 billion since its inception, according to...

FinCEN issues advisory on Iranian illegal activities

Treasury steps up Iranian sanctions, eases order against Mexican bank

Compliance and Risk
April 15, 2026

OFAC announced new sanctions to target illicit oil smuggling by Iran. In addition, the FinCEN announced it was easing a fentanyl-related order against a Mexican bank to allow the dissolution of the institution.

NEWSBYTES

FHLBs propose allowing letters of credit for discount window advances

April 17, 2026

Industrial production fell in March

April 16, 2026

Mortgage rates dip

April 16, 2026

SPONSORED CONTENT

Planning Your 2026 Budget? Allocate Resources to Support Growth and Retention Goals

How leading banks are enhancing customer engagement through financial data insights

April 10, 2026
Check Fraud Is Outpacing Legacy Controls. What Banks Should Evaluate Now.

Check Fraud Is Outpacing Legacy Controls. What Banks Should Evaluate Now.

April 1, 2026
How top agricultural lenders are approaching AI, automation and innovation in 2026

How top agricultural lenders are approaching AI, automation and innovation in 2026

March 2, 2026
Top 7 FP&A Trends in Banking for 2026

Top 7 FP&A Trends in Banking for 2026

March 1, 2026

PODCASTS

Podcast: Capitalizing on opportunities to serve high-net-worth clients

April 9, 2026

Podcast: Are credit union commercial loans risky business?

March 30, 2026

Podcast: Risk and strategy in sponsor banking

March 19, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.