Institutional or corporate culture is much in the news lately, both inside and outside of banking. Amidst the uproar over Volkswagen's intentional compliance failure relating to emission standards, senior company management felt compelled to admit that the company's culture favored misconduct, not compliance or even a timely admission that significant errors had been made. A tolerance for rule breaking gave way to a "chain of errors" because of this institutional attitude.

In short, Volkswagen lacked a "culture" that favored compliance over misconduct, even if the errors of judgment were eventually uncovered and damaged the company's reputation, sales and standing. The company's extraordinary admission of compliance failure and subsequent press reports seemed to reveal widespread knowledge of the cheating but no tolerance for exposing it and challenging superiors. Senior management claimed to have had no knowledge of these misdeeds, but ongoing investigations will ultimately determine the extent to which the management and the supervisory board have responsibility for the scandal that happened on their watch.

But what does the Volkswagen diesel engine scandal have to do with the business of banking? Everything, it would seem. Since the financial crisis of 2008, the culture of banks at the center of the crisis has been cited as both a contributing factor to the financial meltdown and as a symbol of the need for attitudinal change at banks generally. In response, regulators have encouraged banks to take steps to establish appropriate risk and compliance cultures and to encourage them to step forward and "partner" with governmental agencies in the name of "compliance." Each of these efforts, more of which are likely to come, bears some scrutiny by bank boards of directors and senior management.

In a 2014 speech, William Dudley, the President of the Federal Reserve Bank of New York, described an organization's culture as "implicit norms that guide behavior in the absence of regulations and compliance rules—and sometimes despite those explicit restraints . . . .Like a gentle breeze, culture may be hard to see, but you can feel it. Culture relates to what 'should' I do, and not to what I 'can' do."1 For all its ephemeral qualities, industry leaders recognize that a strong risk culture throughout an organization—from the very top to the lowest staff position—is a necessary adjunct to regulatory review in rooting out bad behavior.2

The most comprehensive and formal effort to codify a risk culture is the Office of the Comptroller of the Currency's (OCC) adoption of Guidelines establishing a heightened risk governance structure for national banks, thrifts and federal branches of foreign banks with $50 billion or more in consolidated assets. While limited in scope to larger federally chartered institutions, these Guidelines are likely to be informally absorbed into the regulatory consciousness of the other federal and state banking regulators and become "best practices" for banks of all sizes.3

The Guidelines acknowledge that there is no relevant definition of "risk culture." However, it is recognized that it can be considered as "shared values, attitudes, competencies and behaviors present throughout the covered bank that shape and influence governance practices and risk decisions."4 In terms of compliance with rules and regulations, it is that which infuses a sense of responsibility for compliance at every level and at every desk within the financial institution, not merely for those whose stated responsibility is compliance or internal audit. By all accounts, Volkswagen's culture was just the opposite, namely, one that out of fear for job security or an unwillingness to admit failure, tolerated breaking the rules.5

FinCEN on "Culture of Compliance"

Under U.S. banking rules, such tolerance for rule breaking is not accepted or justified. For example, in August of 2014, the Financial Crimes Enforcement Network (FinCEN) of the Treasury Department issued an advisory to financial institutions that targeted BSA/AML compliance but spoke of the need for a "culture of compliance" at every institution, without specifically defining what that would be.6 However, the advisory made it clear that nothing less than full adherence to federal anti-money rules was required without regard to "revenue interests." Moreover, a "culture of compliance" requires a well-functioning system of sharing information within the institution and sufficient human and technological resources dedicated to compliance along with an independent monitoring function.

FinCEN made it clear that the responsibility for the establishment and maintenance of a "culture of compliance" starts with the board of directors and senior management and also includes owners and "operators." The commitment to such a culture has to be visible throughout the institution so as to influence all employees in the organization and to have compliance with the rules in mind as they carry out their daily responsibilities.7

This "culture of compliance" (at least as FinCEN sees it) requires information sharing across the entire institution. Removing silos and encouraging a broad degree of information integration among all units of the institution may be the key to risk culture analyses.8 Moreover, most recently, the OCC endorsed this view in an enforcement action which specifically required that front-line staff, such as relationship managers, monitor and assist in the identification of unusual or suspicious activity in accordance with specific procedures, in addition to those employees regularly engaged in compliance oversight.9

With these regulatory attitudes in place, it is important to understand how the larger picture of risk management at a financial institution should lead to an overall "risk culture" that would stop a Volkswagen-type scandal of noncompliance from forming in the first place. Obviously, the highly regulated world of banking should act as a brake against such aberrant behavior but some would argue that the financial crisis was born out of a lack of risk culture and that the regulatory oversight alone was not sufficient to prevent the practices that led to the crisis.10

Leadership Sets the Tone

It is generally agreed that the tone of an institution's cultural values—particularly its risk culture attitudes—begins at the top with the leadership of its Board of Directors and senior management. Every bank board must take the lead in establishing and promoting the proper risk culture for the institution, its values and awareness of the hazards of the business in which it operates, the importance of institutional communications and transparency and the maintenance of discipline.

The process must start with an assessment of the organization's "risk appetite," taking into account future plans, strategic emphasis, capital blueprints and financial projections. The focus then must shift to the institution's capacity for risk given geography, market sectors, legal and regulatory restraints and institutional size. These considerations—coupled with strong compliance and internal audit functions—set the framework for the development of a strong and long-term risk culture. It is then up to management to embody these concepts and determinations throughout the organization with compensation plans, performance reviews and other business unit supports.

These steps are not one-time occurrences but part of an ongoing dynamic that must be reexamined, refreshed and repositioned on a regular, periodic basis. The world of financial services is in a constant state of flux and the enterprise must respond quickly and decisively to those changes.

With this in mind, here are three takeaways from this commentary. First, self-policing is the best defense against misbehavior or failures, and thus an organization's employees must feel empowered to speak up without fear of retribution. Second, prompt self-reporting of identified deficiencies or failures up the management chain allows for expeditious reporting to the regulatory authorities and active remediation where necessary. Third, senior management and the Board should continually ask the question, "Could an announced cultural failure at another institution happen here?"

