ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Rethinking your risk assessment

September 8, 2022
Reading Time: 4 mins read
Rethinking your risk assessment

Photo by Karen Martin

Change is constant, so risk identification for banks should be an ongoing process.

By Walt Williams

Risk identification traditionally has been a periodic exercise of checking off a list and then putting it on the shelf until you had to do it again. But as banks transition to a risk-based approach, it is no longer that simple for bank compliance officers. Risk assessment needs to be an ever-evolving process with participation from across the organization, and one that understands where your data is coming from and what it is telling you.

“If we only do it as a once-a-year exercise, we wind up adding new products with substantial risk and we haven’t updated the risk assessment around those new products,” says Jim Bedsole, chief compliance and risk officer at BankSouth in Greensboro, Georgia. “We may have gaps that we haven’t appropriately addressed from a risk-control standpoint.”

rightwards arrow
View more
risk and compliance articles

Timeliness is important because change generates risk, and there are three areas of constant change banks should monitor, Bedsole says.

The first is regulatory change, from change in laws and regulations to interpretive guidance put out by regulatory agencies. The second is product change as banks debut new products and services. The third is process change, which occurs whenever an institution switches up IT systems, tweaks its internal processes and makes staffing adjustments.

“One of the things to recognize is the risk assessment needs to be a regular part of your process … Maybe it’s not an everyday thing, but certainly several times a month going back and revisiting the risk assessment and just looking to see if there anything that needs to change here,” Bedsole says.

Be a team player

Compliance officers don’t operate in a vacuum, and as their institutions transition to regular risk assessment, they should not behave like they do. Thomas Williams, senior compliance manager at United Bank in Griffin, Georgia, says it is critical compliance officers look enterprise-wide and integrate risk identification into an institution’s business units.

“It’s no longer compliance setting the pace for what happens with the organization,” he says. “It’s understanding what’s happening throughout the enterprise by talking to the other business unit leaders: What challenges are they facing? Where do they need assistance? And then also pairing into that what is the institution’s risk tolerance level.”

It is up to compliance officers to facilitate those lines of cross-departmental communication, according to Williams. They need to understand where different business unit leaders are coming from and be able to give clear explanations when they must shoot down a request. The compliance office can’t just be one of saying “no,” he says.

“It’s interacting with these leaders at meetings, getting in front of them from time to time to understand what’s going on in their world, and offering to help but also creating an inviting environment,” he says.

“It’s: ‘Hey, I’m going to come over and take you to lunch because I want to find out what’s going on in your division.’

“Those conversations and those meetings build up that rapport that you’re not there to throw sand in the gears of the business units. You’re there to see how we can do things efficiently and achieve the end result because, at the end of the day, we’re all on the same team.”

Know your data

When it comes to identifying risks, any data that compliance officers have access to has value, Ann Marie Tarantino, chief compliance officer for Esquire Bank in Jericho, New York, said during a session on risk assessment at the American Bankers Association’s Regulatory Compliance Conference in June. The challenge comes when there is too much data that must be sliced and diced to get meaningful input, or when there is a small amount of data, which may be very precise but can lead down the wrong path.

“So you have to make sure you really understand what it is you’re looking at,” she said. “If you open accounts online, for instance, and you have a rate of acceptance and then you have a rate of abandonment, take a look at the rate of abandonment and take a look at why these applications are being abandoned. Is it because people can’t answer the questions? . . . We launched an online product where one of the questions that was asked—and for some reason it was asked frequently—was, ‘What’s the closest hospital to you?’ And a lot of people scratched their heads: ‘I don’t know what the closest hospital to me is.’”

Compliance officers should always be on the hunt for any potential gaps in your data. Complaint databases, for starters, are a wealth of information about risk, Tarantino says. Complaint data “can be read one way or read another way depending on how you look at it, but it can point to systemic issues—miscalculation of interest, fees posting when they shouldn’t be posting, things like that,” she said.

Stay informed

Ryan Rasske, SVP for risk and compliance markets at ABA, points to other data sources that are sometimes overlooked: information from the bank’s “change management process” that could identify changes to existing products and services or introduce new bank offerings; consumer data to identify trends in behavioral changes, such as higher usage of ATMs or digital products or trending fraud losses in a specific product; employee turnover/open positions in key risk and compliance areas or core operational areas at the bank; or correlations that come about because an increase in one type of risk causes an increase in another.

Still, data collection only gets you so far. One of the best sources for identifying new and emerging risks is networking with peers across the banking industry, Rasske notes. “Establishing a strong network throughout your career (i.e., while attending local banking events, ABA schools and/or conferences) allows you to hear from others who might be experiencing a specific risk that you haven’t seen yet,” he says.

Rasske also recommends frequently reviewing publications from regulatory agencies that provide updates on new or expanding risks identified across the banking industry. For example, the OCC publishes a Semiannual Risk Perspective that monitors the condition of the federal banking system and emerging threats to the system’s safety and soundness. “Most agencies such as the Fed and FinCEN publish trending reports and industry alerts which can be a good source for identifying potential new risks,” he says.

Tags: ComplaintsDataRisk management
ShareTweetPin

Author

Walt Williams

Walt Williams

Walt Williams is senior editor of ABA Banking Journal.

Related Posts

Fed releases agenda for upcoming conference on large bank capital requirements

Fed finalizes revisions to rating system for large banks

Compliance and Risk
November 5, 2025

The Federal Reserve finalized revisions to its supervisory rating framework for large banks to address the “well managed” status of the institutions.

Treasury Department seeks feedback on stablecoins, illicit activities

ABA, associations share recommendations for implementing Genius Act

Compliance and Risk
November 5, 2025

As the Treasury Department crafts regulations to implement the Genius Act, it should seek to preserve the benefits of payment stablecoins without causing unnecessary risks for customers, credit availability and financial stability, ABA and four associations said in...

Gould outlines OCC’s review of ‘debanking’

Gould outlines OCC’s review of ‘debanking’

Compliance and Risk
November 4, 2025

The OCC is taking action to address concerns about “debanking,” including through the licensing process and CRA exams, Comptroller of the Currency Jonathan Gould said at a conference in New York City.

BIS: Stablecoins fail as ‘sound money’

ABA, state associations: Uphold Genius Act prohibition on stablecoin interest payments

Compliance and Risk
November 4, 2025

ABA and 52 state bankers associations urged the Treasury Department to uphold the Genius Act’s prohibition on stablecoin issuers paying interest or yield on payment stablecoins.

CFPB launches ‘tip line’ to report on bureau employees

Inspector general report finds CFPB cybersecurity lacking

Compliance and Risk
November 4, 2025

The CFPB's procedures for securing its information systems have deteriorated in recent months, and the issue has been made worse by the loss of contractor resources and bureau personnel, according to a recent audit by the Federal Reserve...

Survey: Banks boosting cybersecurity due to AI while also investing in technology

BIS urges central banks to reconsider approach to AI

Compliance and Risk
November 3, 2025

Central banks and other supervisory and regulatory authorities need to “raise their game” both as observers of the effects of artificial intelligence on the economy and as users of the technology, according to a new report by the...

NEWSBYTES

Mortgage rates tick up, remain near 2025 lows

November 6, 2025

FDIC issues relief guidance for Minnesota and Alaska banks affected by storms

November 6, 2025

From process efficiency to ‘digital employees’

November 5, 2025

SPONSORED CONTENT

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025
5 FedNow®  Service Developments You May Have Missed

5 FedNow® Service Developments You May Have Missed

October 31, 2025

Cash, Security, and Resilience in a Digital-First Economy

October 20, 2025
Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

Rethinking Outsourcing: The Value of Tech-Enabled, Strategic Growth Partnerships

October 1, 2025

PODCASTS

Podcast: The Erie Canal at 200

November 6, 2025

Podcast: Why branches are top priority for PNC

October 23, 2025

Podcast: From tractors to drones, how farming tech affects ag lending

October 16, 2025

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2025 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2025 American Bankers Association. All rights reserved.