Risk culture appears in repeated choices: which concerns receive attention, how pressure changes behavior, who can challenge a decision and what happens after a limit or control fails. Leaders assess it by comparing stated expectations with observable decisions and outcomes across the institution.
Translate values into observable expectations
Broad statements about integrity or accountability are difficult to test. Leaders define behaviors that should be visible in context, such as escalating material uncertainty, respecting risk limits, documenting overrides, considering customer outcomes and correcting weaknesses without waiting for an incident.
The assessment also identifies behaviors that would contradict those expectations, including suppressing bad news, rewarding volume regardless of control quality or repeatedly treating exceptions as routine. Specificity lets different reviewers examine comparable evidence without pretending every business line faces identical risks.
Use evidence from decisions as well as perceptions
Employee surveys and interviews can show whether people believe they can speak up, but perceptions are one source. Leaders also examine limit breaches, overrides, issue aging, complaint handling, audit findings, near misses, risk-acceptance decisions, performance reviews and the quality and timing of escalation.
No single measure establishes a sound or weak culture. A low incident count may reflect good control or poor reporting; a high speak-up count may reflect deterioration or growing trust in escalation. Triangulating quantitative and qualitative evidence helps distinguish those explanations.
Look for subcultures and pressure points
An institution-wide average can hide meaningful differences among products, locations, teams and management layers. Assessments compare areas with similar work, then investigate outliers and changes over time rather than assigning a universal culture score detached from context.
Periods of rapid growth, restructuring, system conversion, incentive change or sustained workload can reveal how expectations hold under pressure. Leaders ask whether staffing, deadlines and goals make compliant behavior practical and whether local managers respond consistently when results and risk discipline conflict.
Leadership actions provide strong signals
Employees observe which matters reach senior forums, whose challenge changes a decision and whether consequences apply consistently across high and low performers. Resource allocation, promotion, compensation, remediation funding and the treatment of messengers can carry more weight than formal communications.
Boards and senior management therefore review not only what leaders say but the record of material tradeoffs. They distinguish a reasoned, authorized risk decision from an undocumented exception and test whether accountability addresses root causes rather than merely assigning blame after an adverse outcome.
Assessment should lead to owned action and reassessment
Findings are translated into specific actions such as changing an incentive, clarifying decision rights, improving escalation, addressing workload or strengthening consequence management. Each action has an accountable owner, timeline, evidence of completion and a measure related to the behavior that needs to change.
Follow-up asks whether behavior and outcomes changed, not just whether training or a policy was delivered. Because culture evolves, periodic assessment and event-driven review remain part of governance, with independent challenge of the method and conclusions where appropriate.
Read the primary material
Banking Explained prioritizes regulators, official publications and first-party announcements.
