ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Clarity and concision in risk reports

In risk reports to the board, place the emphasis on messages, not metrics

December 9, 2024
Reading Time: 5 mins read
Clarity and concision in risk reports

By Walt Williams

Chief compliance and chief risk officers often struggle with presenting the right information when drafting reports for their bank committees and boards. One solution that many settle on is to share a little of everything. But that approach often means that critical insights are lost amid the deluge of data, and it leaves boards in a poor place when making decisions that drive the fate of the bank.

Instead, the adage “less is more” is the best advice when drafting reports. Rather than focusing on metrics, compliance and risk officers need to be thinking about what messages they seek to communicate with the data they have.

“We’ve got a ton of information and information overload is what we talk about now,” says Bill Tucker, CRCM, CAFP, CERP, chief compliance officer at First Carolina Bank. “We have to transcend that and somehow get this to the point of insight so the right kinds of decisions can be made and action can be driven. You need to tell a story, so you need to take a lot of things and boil them down to a place where you’re really sending a message, not just doing a data dump.”

Risk management is probably the most difficult thing to address in board reporting because, unlike other aspects of the bank, it is not dependent on financial or employee performance, which you can capture numerically, says Craig Brown, managing director of business advisory at Huron.

“Risk management is based on assessments — top and emerging risks and deficiencies,” Brown says. “There are elements that are quantifiable, whether there are credit risk trends, operational losses, liquidity or capital, but most of the areas are not. That really leads up to where the challenges occur.”

In his former life as a banker, Brown says he saw reports 500 to 600 pages long delivered to the bank’s risk management committee, and he has since seen reports weighing in at over 1,000 pages. That much information is simply not digestible in the few days that most committee and board members have to review the materials presented to them.

“Board members have a fiduciary responsibility,” he says. “When they’re inundated with information that you don’t believe to be critical, you’re exposing them to legal risk, simply because it was given to them and they reviewed it. And there might be something that’s very small in that period of time that you don’t think as a risk manager is important, but now that you put it in there, you have put the board member on the hook for knowing that information. Down the road that may become a big issue.”

The adage “less is more” is the best advice when drafting reports. Rather than focusing on metrics, compliance and risk officers need to be thinking about what messages they seek to communicate with the data they have.

Use clear language

A key challenge in board reporting is communication, not just with the board but with the other divisions in the bank.

“It doesn’t matter the size of the bank or how sophisticated it is, I ran into this everywhere: Terminology is just muddled,” Tucker says. “We play a critical part in helping clarify what is risk appetite, what is risk profile, what is risk metrics [and] what is risk tolerance. And if you’re not speaking a clear language, we can’t expect somebody to hear and understand it.”

Take a word like “account,” Tucker adds. “If you say ‘account’ to someone on the front line, they think ‘customer.’ If you say that to someone in operations, they’re thinking ‘product.’ If you say that to someone in finance, they are thinking of ‘general ledger.’ We have to be really clear about what we’re saying or otherwise our reporting up to the board is not going to be what it needs to be.”

Krysti Cunningham, CRCM, CERP, SVP and chief risk officer at Security National Bank of Omaha, also emphasizes the need to avoid confusing terminology when speaking to the various bank departments. During a panel discussion on board reporting with Tucker at the ABA Risk and Compliance Conference in June, she instead advocated for a more conversational approach.

“Talk to your business units … and say, ‘Okay, what’s keeping you up at night? How far are we willing to go?’” she says. “And then you can put that into a simple phrase: ‘This is what our risk appetite is, and these are the metrics we’re going to use.’”

Keep metrics relevant

That communication should lead to clear, concise metrics that define a report’s key performance indicators and key risk indicators. The former is looking backward, the latter forward. And risk indicators need to evolve.

“I think about things like last year with liquidity,” Cunningham says. “We had to make some changes there on how we were looking at some of those metrics. Whoever thought social media would become a key risk? We’re adjusting to the environment around us. And sometimes you have to talk to your management and your business units and ask: So this has changed. What are we doing and how are we going to tell the board?”

Also, compliance and risk officers need to remember that board members are not their only audience, according to Brown.

“I don’t think people are always aware of the fact that all of the board materials are provided to your regulators,” he says. “When they start seeing stale information, even though they may have the minutes and you may have discussed it, the regulator reads the minutes but then reads the report, and two weeks later they’re going to say, ‘Well, this has been unchanged for months now. They’re not matching the risk.’”

When reporting risks, they should be ordered from most impactful to least impactful to the organization, Brown says. The commentary should be plainly written, explaining why something is a risk, the potential outcomes of that risk, what changes have occurred with it and what is being done to mitigate it. And the report needs to be tailored to be tailored to the risks of your bank.

“Simply because it worked elsewhere doesn’t mean it is going to work for your bank. Remember who your audience is,” he says. “They’re responsible for strategy and risk appetite. So all of your reporting should be geared towards explaining why we’re operating within the risk appetite and why we’re operating consistently with our strategy.”

Mistakes to avoid

Failing to provide those explanations can result in a lack of reverence for the target audience, which Cunningham sees as a common mistake in many reports. Risk and compliance officers can provide great information, but if a report does not make clear how those data points could affect the bank, then it may not prove useful for board members.

“Let’s tone it down and figure out how that impacts the strategic objective — where the bank wants to be going,” she says. “What are the key things they want to accomplish in the next three to five years?”

Another common mistake is complacency. It may be tempting to just take last quarter’s report, change the dates and submit that, given already busy workloads for risk and compliance officers, Tucker says.

“I never want to have a report coming from me going to the executive manager on the board that simply has the date changed,” he says. “Even if the message is the same, think of the difference in how I say it, and then what’s changed behind it that could cause the message to change.

“I think that is the forward-looking view,” Tucker adds. “What are the drivers behind [the bank’s] good performance, and where are the soft spots in that? Where are the things that could be wrong? How significant are those? They may not yet warrant escalation up to an executive management or board report, but it’ll give you an indicator of the things I need to watch.”

Walt Williams is a senior editor at the ABA Banking Journal.

Keep your bank directors informed on industry trends — in just six pages, six times a year! Subscribe to ABA Banking Journal Directors Briefing at aba.com/directorsbriefing.

Tags: Risk management
ShareTweetPin

Author

Walt Williams

Walt Williams

Walt Williams is senior editor of ABA Banking Journal.

Related Posts

New York State issues guidance on AI-related cybersecurity risks to financial institutions

Survey: Most banks experienced recent rise in cyberattacks

Compliance and Risk
June 24, 2026

A majority of U.S. bank executives said they have seen an increase in the number of cyberattacks on their institutions in the past year and have boosted their cybersecurity budgets as a result, according to the most recent...

NIST releases draft guidelines for AI cybersecurity

‘Five Eyes’ nations warn AI cybersecurity threats only months out

Compliance and Risk
June 24, 2026

Organizations have only months to prepare for the cybersecurity challenges posed by new artificial intelligence models, making cyber resilience “integral to advancing business continuity,” the leaders of the "Five Eyes" cybersecurity agencies warned in a joint statement.

G7 cybersecurity group urges financial institutions to prepare for quantum computing

White House directs agencies, contractors to protect systems from quantum computing

Compliance and Risk
June 23, 2026

Government agencies and contractors would be required to take steps to protect their systems from threats posed by quantum computers under a pair of executive orders signed by President Trump.

Regulators take issue with discrimination definition in proposed appraisal standards

FHA ends field review requirement for certain mortgages

Compliance and Risk
June 23, 2026

The Federal Housing Administration will no longer require lenders to obtain appraisal field reviews for a selection of FHA-approved mortgages, instead making the reviews optional.

FinCEN proposes severing Cambodian firm as institution of primary money laundering concern

FinCEN takes further steps to sever Cambodian firm from U.S financial system

Compliance and Risk
June 23, 2026

FinCEN proposed taking additional actions to cut off U.S. financial access to a Cambodian firm that allegedly serves as a conduit for laundering money obtained through romance scams and other cybercrimes.

New infographics provide advice for identifying money mules, check fraud

Bill would extend time for banks to review suspicious checks, wire transfers

Compliance and Risk
June 22, 2026

Rep. Young Kim (R-Calif.) has introduced legislation to allow financial institutions to place extended holds on suspicious checks and wire transfers while fraud claims are investigated.

NEWSBYTES

Survey: Most banks experienced recent rise in cyberattacks

June 24, 2026

‘Five Eyes’ nations warn AI cybersecurity threats only months out

June 24, 2026

House passes bipartisan housing bill

June 23, 2026

SPONSORED CONTENT

Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026
A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026

PODCASTS

Podcast: Talent and innovation in community banking

June 18, 2026

Podcast: Understanding bank regulators’ guidance on illegal immigration

June 11, 2026

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.