Same Risk, Different Chairs: How Financial Services Leaders See Risk Differently

Same Risk, Different Chairs: How Financial Services Leaders See Risk Differently

Frederick Lam

One of the things I have learned over my career in financial services is that risk can look very different depending on where you sit. You can put a Chief Compliance Officer, General Counsel, Chief Risk Officer, Chief Technology Officer, Chief AML/BSA Officer and Chief Financial Officer in a room, give everyone the exact same set of facts, and each person may identify something different as the most important risk. None of them are necessarily wrong. They are simply looking at the issue through the lens of their own experience, responsibilities and expertise.

I think this is especially true in financial services because very few significant risks fit neatly into one category. Something that starts as a technology issue can quickly become a compliance issue. A compliance concern can create litigation exposure. A vendor problem can create operational, regulatory, reputational and financial risk at the same time. An AML or fraud issue can expose weaknesses in technology, customer onboarding, compliance controls and operational processes. The risk itself has not changed. What changes is the chair you are sitting in when you look at it.

As Chief Compliance Officer, I am naturally going to start by thinking about regulatory requirements and expectations. When the business is considering a new product, process, marketing campaign, vendor or customer experience, I am thinking about what regulations apply, what our policies require, how a regulator may view the activity, whether there is potential customer harm and whether we have appropriate controls in place. I am also thinking about whether, six months or a year from now, we will be able to demonstrate why we made a particular decision and what controls existed when we made it. Compliance in financial services is rarely as simple as reading a regulation and deciding whether the company technically satisfies it. Regulatory guidance, enforcement actions, examination expectations, customer complaints, industry practices and shifting supervisory priorities all come into play. There are situations where something is arguably permissible under a strict reading of a regulation but still creates unnecessary regulatory risk for the organization. Part of the CCO’s responsibility is recognizing that distinction and helping the business understand it.

Legal often approaches the same situation from a different direction. As General Counsel, I may be looking at what the law actually requires, what contractual obligations we have, whether a position is legally defensible, what litigation exposure exists, what rights we have if a counterparty fails to perform and what precedent a decision might set for the company. With a vendor, for example, Compliance may focus on whether the vendor has appropriate controls and whether its activities create regulatory risk for us. Legal may focus on indemnification, limitation of liability, termination rights and whether the contract adequately protects the company if something goes wrong. Those are closely related questions, but they are not the same questions.

That is a big part of why serving as both Chief Compliance Officer and General Counsel at LendingUSA has been so valuable. I frequently have to look at the same issue twice. I may first look at it as the CCO and ask what a regulator would think, whether there is a consumer protection concern, whether our controls are appropriate and whether the decision is consistent with regulatory expectations. I can then look at the same facts as General Counsel and ask what the law requires, what the company’s contractual obligations are, whether the position is defensible and what happens if the decision is challenged in litigation.

Sometimes both perspectives lead to exactly the same conclusion. Sometimes they do not. Sitting in both chairs lets me work through both sides of the issue before making a recommendation to the business.

I think this is important because our role as control function leaders should be more than telling the business whether something is allowed or prohibited. Leadership needs enough context to make an informed decision. That means explaining the requirement, the regulatory expectation, the legal exposure, the likelihood of the risk actually occurring, the potential impact if it does occur, what controls are available and what residual risk will remain after those controls are implemented. Of course, Legal and Compliance are only two chairs at the table.

A Chief Risk Officer may look at the same issue much more broadly. Instead of beginning with a statute or regulation, the risk function may start by asking what could prevent the organization from achieving its objectives, how significant the exposure is, how likely it is to occur and whether it falls within the company’s risk appetite. That can include operational risk, credit risk, third-party risk, reputational risk, concentration risk and a number of other exposures that may not be immediately apparent when an issue is viewed solely through a legal or regulatory lens. A Chief Technology Officer brings a completely different perspective. So much of modern financial services runs on technology that it is increasingly difficult to find a meaningful business risk that does not have some technology component. Customer disclosures are delivered through technology. Underwriting models rely on technology. Regulatory reporting depends on data that comes from technology systems. Fraud controls, customer authentication, payment processing, servicing and information security all depend on technology. A Chief AML/BSA Officer and the financial crimes team look at the organization through another lens entirely. They spend their time reviewing transaction activity and looking for patterns, unusual behavior, identity concerns, fraud indicators and situations where legitimate products or systems may be used for illegitimate purposes. They are often asking whether the activity they are seeing actually makes sense based on what we know about the customer or transaction. A series of transactions may look perfectly acceptable individually but become concerning when viewed together. That type of pattern recognition is a very different way of identifying risk, and it can expose weaknesses that may not be visible from a legal, compliance or technology perspective. The Chief Financial Officer’s chair matters just as much. An operational or regulatory decision may make perfect sense in isolation but have downstream implications for funding, liquidity, profitability or capital. Those consequences need to be understood as part of the risk decision, particularly when an organization is growing, entering new markets, launching new products or changing its funding strategy.

This is why I believe collaboration across the second line and other control functions is so important. Compliance should not operate in one silo, Risk in another and Technology somewhere else. We may have different responsibilities, and there are good reasons for maintaining independence between certain functions, but independence should not mean isolation.

A good example is a significant outage involving a customer-facing lending platform. The technology team may initially view the event in terms of system availability, recovery time and data integrity. Compliance may immediately start thinking about customer impact, regulatory obligations, servicing requirements and any communications that need to go out. Legal may be thinking about contractual obligations, potential claims and litigation exposure. Risk may be evaluating operational and reputational consequences. Finance may be looking at whether the interruption affects funding or cash flows. AML and fraud teams may need to understand whether monitoring or other controls were interrupted while the system was unavailable. It is still one event. The organization simply has several different ways of experiencing the risk created by that event.

For senior management and the Board, those different perspectives need to come together into a single picture. I do not think the Board should have to listen to a technology presentation, a compliance presentation, a risk presentation and a finance presentation and then independently figure out how all of those issues connect. Part of our responsibility as leaders is to connect those dots before the information reaches them.

When we present risk to leadership and the Board, we should be able to explain what the risk actually is, how it could affect the organization, what the potential legal and regulatory consequences are, whether customers could be impacted, what the financial implications could be, what controls are currently in place and where gaps remain. Most importantly, leadership needs to understand what risk the organization is ultimately accepting.

That last question can sometimes get lost. Risk management does not mean eliminating every possible risk. Financial services companies could not operate if that were the objective. Every product, customer, vendor, technology platform and business decision creates some level of risk. The goal is to identify it early, understand it from the appropriate perspectives, put reasonable controls around it and make a deliberate decision about what level of residual risk the organization is willing to accept. In my experience, the quality of that decision improves significantly when people from different disciplines are willing to challenge each other’s assumptions. Compliance may see something Legal does not. Legal may identify an exposure Risk has not considered. Technology may explain why a proposed control will not actually work. AML may recognize a pattern that changes everyone’s understanding of the problem. Finance may flag a downstream consequence that was not part of the original discussion.

That type of challenge can feel like organizational friction, but when it is done correctly, it is exactly what a strong risk culture should look like.

Financial services will always require specialists. The regulatory environment is too complex, technology is too important and the consequences of getting major decisions wrong are too serious for any one person or function to understand every dimension of risk. The answer is to bring those specialized perspectives together. The biggest risks facing an organization rarely arrive labeled as a compliance risk, legal risk, technology risk or AML risk. They cross those boundaries very quickly.

The more willing we are to get out of our individual chairs and understand what the people sitting in the other chairs are seeing, the better equipped we are to give management and the Board the complete picture they need to make good decisions.

-Frederick Lam. Esq.

LendingUSA

Chief Compliance & Legal Officer

For Merchants

For Merchants

Learn how we can help you increase revenue and get paid faster than before.

Free Demo
For Borrowers

For Borrowers

Get the goods and services you want with our easy payment options.

Check Your Rate
Need To Make A Payment?