Risk Culture: What People Do When Nobody Is Checking
Risk culture is what people do with a risk when no procedure tells them to act. A culture is measured rather than described. At Vindhya Commercial Bank Limited, invented, a data quality check caught a stale feed in month 6 and nobody raised it, and a checker refused a forged document set in month 7 and nobody linked it. Both controls worked. Neither signal was ever connected to the loss it matched.
Almost everything written about culture is written as adjectives. Open. Accountable. Speaking up. An adjective has no test attached to it, so adjectives can be printed on a wall while nothing in the building changes. The opposite approach starts with one invented bank, opens the records it already keeps, and reads four numbers out of them that nobody had to be surveyed to produce.
The reason this is worth an afternoon is narrow and practical. A control that fires and is cleared correctly can still be the beginning of a loss, and no control report will ever say so. The control did its job. The report says so. The money was in the hour afterwards, and there is no field on the form for the hour afterwards.
What is risk culture, and how is it different from values on a wall?
Start with a kitchen. A smoke alarm chirps at two in the morning because the battery is low. The alarm worked. The alarm did exactly what it was fitted to do. The next step is not in the alarm's instructions: the household either gets up and changes the battery, or takes the alarm down off the ceiling because the chirping is unbearable and work starts in five hours. Both households have a working alarm. Only one of them has a working arrangement.
Risk cultureWhat people do with a risk when no procedure tells them to act. is that difference, stated for an organisation instead of a household. A procedure tells somebody what to do at the moment a control fires. Nothing tells them what to do in the hour afterwards. Culture is the whole of that next hour. Because it is behaviour rather than belief, it can be counted.
The claim that culture is behaviour is the one people resist, so it is worth being blunt about it. If culture were a belief, measuring it would mean asking people what they believe, and the answer would be whatever they think the asker wants to hear. If culture is a set of things people did when nothing compelled them, then those things left marks in records the organisation already keeps. Nobody has to be asked anything. The marks are counted.
Notice what is missing from the drawing. The drawing does not say the people on the left were careless and the people on the right were diligent. Both paths are entirely reasonable behaviour for somebody with a queue in front of them and no instruction telling them to do the second thing. The difference between the two boxes is a design difference, not a character difference, and every useful thing in this guide follows from taking that seriously.
A data quality check fires, and the person on the desk clears it correctly and closes the record, exactly as the procedure says. Which part of that sequence is the culture reading?
How is a culture measured rather than described?
The place to look is wherever somebody had a choice and no rule. Vindhya Commercial Bank Limited, invented, keeps nine separate records of risk, and four of them contain a count of exactly that kind. The four counts are the culture readings CU1 to CU4, and the whole of their virtue is that the bank was already holding every one of them before anybody asked a question about culture.
CU1 is linkingConnecting a near miss to the cause it shares with something else the organisation already knows about.: 2 of the 5 near misses N1 to N5 turned out to be the same failure as an incident that followed, being 40.0 per cent. CU2 is optimism in the self assessmentThe business rating its own controls, used here only for its two counts.: the business rated 196 of 214 controls effective and independent testingThe same controls rated by somebody who does not run them day to day. found 172 of the same 214 effective, a difference of 24 controls. CU3 is keeping a date the bank set for itself: 31 of the 92 open issues are past dueBeyond the date the organisation itself agreed for fixing something., being 33.7 per cent, and the oldest is 412 days past. CU4 is reading the paper before the meeting: 6 of the 8 attendees at the month 12 meeting had read the monthly risk report before arriving, being 75.0 per cent.
Not one of those four required a new system, a new form, a new committee or a single question put to a single person. Every one of them is a division of two counts the bank was already writing down for other reasons. Dividing two counts the records already hold is the whole trick, and it is available to any organisation that keeps records at all.
What does it mean when a control works and nothing happens next?
The record of the year will show a control operating exactly as designed, and the loss log will show a loss, and no document anywhere will connect the two. Near miss N3 is the cleanest example in this bank's whole year, so take it slowly.
In month 6, the collateral valuation feed at Vindhya Commercial Bank Limited was staleA data feed still delivering yesterday's values as though they were today's. for 2 working days. A data quality check caught it. The check firing is the control doing precisely what a data quality check exists to do, and a control testing report would show nothing wrong on that line at all. The feed was corrected and the record was closed. Nobody raised it as an issue. No cause was written down, no owner was named, and no other record was ever read beside it.
Four months later, in month 10, the same feed was stale again. The second time the feed ran stale for 11 working days, being 5.5 times as long, and 340 loans were wrongly marked. The loss is incident I10: gross Rs 1.4 crore, no recovery, net Rs 1.4 crore. Incident I10 is also the single deficiency rated D4 on the bank's four point scale D1 to D4, and it touches the valuation of Rs 8,640 crore of secured advances. The event that cost the most in reputation terms began as a two day nuisance that a control caught perfectly.
A data quality check caught a stale feed after 2 working days and nobody raised it. The control worked. What failed?
Why does a near miss that is recorded and never linked teach nobody anything?
Near miss N4 makes the same point from a harder angle, and it is harder because the person in the story did something visibly right. In month 7, a trade finance document set carrying the same forgery pattern as incident I13 was put in front of a checker, and the checker refused it. The refusal is the control working in the most direct sense there is: somebody looked at a set of papers and said no.
The refusal was recorded as a routine refusal. Trade finance desks refuse document sets constantly, for missing endorsements, for dates that do not agree, for a hundred ordinary reasons, and a routine refusal is exactly the right classification for almost all of them. Nothing in any procedure said to hold this one refusal up against the open investigations, so nothing did, and the refusal went into the count of refusals and stayed there.
One month later, incident I13 was discovered when a beneficiary bank claimed. Nine letters of credit had been issued against forged shipping documents over fourteen months ending in month 8. Gross Rs 22.4 crore, recovery Rs 7.0 crore, net Rs 15.4 crore, and that Rs 15.4 crore net loss is the largest of the bank's year, being 35.2 per cent of the Rs 43.8 crore net operational loss total.
A checker refused a forged document set in month 7. The fraud it belonged to had been running for fourteen months and was discovered in month 8. How much of that fraud could linking the refusal have reached?
Were the two warnings worth the same?
No, and this is the part that gets dropped when the story is told well rather than told honestly. Near miss N3 arrived in month 6 and incident I10 happened in month 10, so the whole of that incident was still in the future when the warning landed. Near miss N4 arrived in month 7 with thirteen of fourteen months of the fraud already behind it. One of those was a chance at prevention and the other was, at best, a chance at slightly earlier detection, and calling them both a missed near miss flattens a real difference.
Why insist on the distinction? Because telling a trade finance team that a routine refusal in month 7 would have saved Rs 15.4 crore says something the record does not support, and the first person who checks the dates will stop believing the rest of the argument. The honest version is stronger anyway. Two controls fired, both times the organisation learned nothing, and only one of the two occasions was a genuine chance to stop a loss before it existed. The smaller claim is the true one.
If linking is nearly free, why is skipping it a cultural fact?
Because cost is the usual excuse and it is not available here. A near missA failure that started and was stopped before it cost anything. costs nothing to collect. There is no loss to quantify, no recovery to chase, no customer to compensate, no provision to raise. The bank recorded both N3 and N4 without difficulty, along with N1, N2 and N5, so the register was working exactly as a register should.
Linking costs almost nothing either. Both records already existed and both were already written. The missing step was somebody reading one record beside another and asking whether anything else had looked like this. Reading one record beside another is minutes, not a project, and it needs no system, no vendor and no budget line. When the missing step is free, the reason it was skipped cannot be resourcing, and the only remaining explanation is that nothing in the way the work was arranged made anybody expect to take it.
Think of a shopkeeper who notices one bad note in the till on a Tuesday and puts it aside, and notices another on the Friday and puts that aside too. Neither Tuesday nor Friday costs anything. The loss arrives on the day somebody would have spotted, had they laid the two notes side by side, that both came from the same customer at the same hour. Laying two things side by side is the entire technique, and almost nobody has a procedure that requires it.
No money was lost, so collecting a near miss costs nothing. What does linking one cost?
What does a gap between a self assessment and independent testing say?
The second culture reading is about optimism, and it comes out of two counts that are easy to state and easy to get wrong. Vindhya Commercial Bank Limited has 214 key controls across the nine processes PR1 to PR9. The business assessed all 214 of them and rated 196 effective. Independent testers looked at the same population of 214 and, at the end of their work, found 172 effective.
Put those two counts on the same base and the arithmetic is short. 196 of 214 is 91.6 per cent. 172 of 214 is 80.4 per cent. The difference is 11.2 percentage points. Because 196 less 172 is 24, the difference is also 24 controls, and 24 of 214 is itself 11.2 per cent. The percentage gap and the control count are the same fact stated twice. An argument about points can therefore always be converted back into an argument about a specific number of controls.
Twenty four controls is a concrete object. A count of controls is not a mood, a tone or a sentiment. Somebody can go and get the list, and the list will name a process from PR1 to PR9 for every row on it. The list is what makes CU2 a culture reading rather than a debate: two sets of people looked at the same things and disagreed about two dozen of them, and the disagreement has an address.
The bank's record gives two counts and no map between them. The record does not say that the 172 controls the testers found effective are a subset of the 196 the business rated effective, and the subset cannot be assumed. Putting both counts on the same base of 214 compares two rates on one population. Comparing two rates does not match control to control, and anybody who needs the actual list of 24 has to go and build it from the two records rather than subtract one number from another.
Which base is the division made by, and why does that matter more than the number?
Here is where a completely honest set of records produces a misleading sentence, so read this slowly. The testers did their work in two stages. First they tested design on all 214 controls, and found 198 designed effectively and 16 carrying a design gap. Then they tested operating effectiveness on the 198 that had passed the design stage, and found 172 effective and 26 not. Both stages tie: 198 plus 16 is 214, and 172 plus 26 is 198.
So a perfectly truthful sentence is available: independent testing found 172 of the 198 it tested for operating effectiveness, being 86.9 per cent. Nothing in that sentence is false. The two rates are not measured on the same population, so printing 86.9 per cent next to the business's 91.6 per cent makes a comparison that means nothing.
One is 172 out of 198. The other is 196 out of 214. Set side by side, the two rates show an apparent gap of 4.7 percentage points. A committee paper reads that as broad agreement with a bit of noise. The full 214 is the only like for likeTwo rates put on the same base, so that the comparison between them means something. reading available, and the gap is 11.2 points. The flattering version understates the real gap by 6.5 percentage points, and nobody had to type a single wrong digit to produce it.
The everyday version is a school that reports a 95 per cent pass rate, having excluded from the count every student it advised not to sit the examination. Each number in that sentence can be checked and none of them is a lie. The baseThe count a percentage is divided by, which is also the population being described. is doing all the work, and the base is the part nobody reads aloud.
Independent testing found 172 controls effective. The business rated 196 of 214. Before anything moves: how far apart are those two, in percentage points?
Move the base and watch a number that never changed change
The count of controls the testers found effective is fixed at 172 throughout. The business rate is fixed at 196 of 214, being 91.6 per cent. Only the base the 172 is divided by moves, from 198 up to 214.
Base: 214 controls
Educational illustration. Invented figures throughout. The numerator of 172 is fixed and only the base moves. The business rate of 196 of 214 is fixed. Both counts belong to Vindhya Commercial Bank Limited, invented, and neither is a measure required by anybody. The two counts are put on one base for comparison, and that does not claim the 172 are a subset of the 196. Three readings can be checked by hand: at a base of 198 the testers report 86.9 per cent and the gap is 4.7 points; at 205, 83.9 per cent and 7.7 points; at 214, 80.4 per cent and 11.2 points. The gap reaches zero only at a base of about 188, where 172 divided by the base equals 91.6 per cent, and 188 is 10 fewer controls than were ever tested. No honest base closes it.
Which base would make the gap disappear entirely?
The crossing point is worth holding on to. Knowing it makes the trap safe to walk into and out of. The gap can be shrunk by choosing a smaller base. Closing it would need a base of 188, and only 198 were ever put through the operating test, so no base that actually exists closes it. Solving for the crossing before the argument begins is what turns a disagreement into arithmetic.
The failure: the flattering base, and why it is a culture reading rather than a slip
Picture the paper being assembled the evening before the meeting. Two numbers have to go on one slide. One of them, 91.6 per cent, arrives from the business as a finished rate. The other arrives from the testers as a finished rate too, 86.9 per cent, computed correctly on the population they tested for operation. Both are put on the slide because both are what the two teams reported. The slide now says the two views differ by 4.7 points.
Nobody typed a wrong number, nobody hid anything and nobody would fail an audit of that slide, and the slide is still wrong. The 24 controls that two sets of people actively disagree about have been reported as a rounding difference, and a committee reading 4.7 points has no reason to ask for the list.
The reason this belongs with culture rather than with arithmetic is that the correction is free and available. Both counts and both bases sit in the same record. Recomputing 172 over 214 takes seconds. The deciding factor is whether anybody in the chain treats an unlike comparison as their problem when no procedure names them as responsible for it. The two near misses asked the same question in a different register.
Set against that, the reading is 11.2 points and 24 controls, stated on one base, every single time these counts appear.
What does an issue past a date the bank set for itself reveal?
CU3 is the plainest of the four readings and it is the one most organisations already have on a slide without knowing what they are looking at. Vindhya Commercial Bank Limited is carrying 92 open issues. The 92 issues age in five buckets AG1 to AG5, from 28 in the newest bucket down to 9 that are over a year old. The buckets are the ageing profile, and the ageing profile is the number that usually gets reported.
Now the second reading. Of those 92, 31 are past their agreed remediation due date, being 33.7 per cent, and the oldest is 412 days past. Age shows that the problem was hard; past due shows that a date the organisation set for itself was allowed to go by, and only the second one is a statement about what people did.
The distinction matters because the two readings can point in opposite directions on the same issue. A complicated system change raised eleven months ago, with a two year agreed date and monthly evidence of progress, is old and entirely on track. A small procedural fix raised three weeks ago with a two week date is new and already late. Report ageing alone and the first one looks bad and the second is invisible. Nobody set the ageing date; somebody, by name, agreed the remediation one.
Thirty one of 92 open issues are past their agreed due date and the oldest is 412 days past. Which of those two numbers is the culture reading?
And what do 6 of 8 attendees mean?
CU4 is the smallest count here and it takes four words to state. At the month 12 meeting, 6 of the 8 attendees had read the monthly risk report before arriving, being 75.0 per cent. The report runs 38 printed sides and goes out 5 working days ahead, so nobody was ambushed.
Resist two temptations here. The first is to treat 75.0 per cent as a good score because it is a large number. The second is to treat the 2 as a character judgement about two people. The useful question is what a paper has to be like before a quarter of the room arrives without having opened it, and that is a question about the paper, the diary and the meeting rather than about the two. A pack of 38 printed sides landing in an inbox already holding a hundred others is a design, and the design produced the 2.
What is none of these four readings?
Not one of CU1 to CU4 is a survey. Not one of them is a values statement. Not one of them is a training completion rate. Surveys, values statements and training rates get called culture measurement constantly, and here is the test that separates them: does the number record a decision somebody made when no procedure required it?
A survey records what people were willing to write down about themselves in a form with their department on it. A values statement records what a drafting group agreed to print. A training completion rate records that a course was clicked through to the end, and a click is a record of attendance and nothing more. All three describe intentions, and the four readings describe what happened, and only one of those two categories has a loss log sitting behind it.
None of that is an argument against ever asking people anything. The argument is about order. Because counting is free and nobody can flatter it, count first, then go and ask questions about the specific twenty four controls, the specific thirty one issues, or the specific near miss nobody linked. Questions asked after a count are about something. Questions asked instead of a count are about nothing.
Which of these is not a risk culture measurement?
What would have to change in exactly the same records?
A recommendation that starts with a new system is a recommendation nobody acts on this year, and not one of the four steps below needs one. Taken in order, each of the four readings raises one question: what single step would move it?
| Reading | Where it stands | The step that would move it |
|---|---|---|
| CU1 near misses that came back | 2 of 5 | Check every near miss against the loss log and the open investigations before it is closed |
| CU2 controls in dispute | 24 of 214 | Compute both rates on one base before either reaches a paper, and attach the list of 24 |
| CU3 issues past a self-set date | 31 of 92 | Report past due beside ageing, so the date somebody agreed is as visible as elapsed time |
| CU4 papers read before the meeting | 6 of 8 | Put the decisions the meeting has to take on the front sheet of the pack |
Every one of those four steps connects two records the bank already keeps, and not one of them creates a new record. The first one alone would have caught both N3 and N4: N3 because the loss log would have shown the same feed, and N4 because the open investigations would have shown the same forgery pattern. Checking a near miss against the loss log is one habit, applied to a log with five rows in it, and it is the whole of the difference between the year this bank had and a better one.
The culture reading has to move next year without adding a single new record. Which of these would do it?
How does anybody actually use this?
What four different readers do with the same four counts
An internal auditor uses the readings to choose where to look next year rather than to write a paragraph about tone. The list of 24 disputed controls names a process from PR1 to PR9 on every row, so it is a work plan. The near miss log with 5 rows is an afternoon of reading, and it is the cheapest place in the whole bank to find a loss that has not happened yet.
A board or committee member uses them to test the paper in front of her. Two counts and a percentage arrive on a slide; the useful question in the room is what the base of each one is, and whether both were divided by the same thing. Asking about the base would have caught the 4.7 point version before it was ever discussed.
A lender or an analyst doing diligence on an institution cannot see any of this from outside, and should be honest that this is a limitation rather than pretending a published statement substitutes for it. Three things are visible from outside: whether disclosures separate age from overdue, whether rates come with their bases attached, and whether losses are ever discussed alongside the events that preceded them.
A person running a team of six uses the same technique at a much smaller scale, and it works exactly as well. Count how many times something was caught and nothing followed. Count how many commitments went past dates the team set for itself. Both are countable on one sheet of paper, and neither requires anybody to be asked how they feel about risk.
Who sets the expectations that sit behind any of this
Supervisory expectations on risk culture, governance and the operational risk framework originate with the Basel Committee at the Bank for International Settlements. The Committee publishes at bis.org, and the seven operational risk event categories behind a loss log like I1 to I13 come from there too. The binding requirements for a bank in India, including anything on internal control, operational risk and the reporting of losses, come from the Reserve Bank of India at rbi.org.in, and naming only the global standard is the confident error worth avoiding.
Control testing and a deficiency rated a material weakness both appear here, so one further pointer: the reporting duty on internal financial controls sits in the Companies Act, and its text, applicability, exemptions and form come from the Ministry of Corporate Affairs at mca.gov.in, with the assurance standard and guidance note from the Institute of Chartered Accountants of India at icai.org. The current position is the one held by the issuing body.
Sources
| Source | Document | Site |
|---|---|---|
| Reserve Bank of India | What actually binds a bank in India on internal control, operational risk and loss reporting | rbi.org.in |
| Bank for International Settlements | Basel Committee material on risk culture, the operational risk framework and the event categories | bis.org |
| Ministry of Corporate Affairs | The Companies Act reporting duty on internal financial controls, with its applicability and form | mca.gov.in |
| Institute of Chartered Accountants of India | The assurance standard and guidance note behind an internal financial controls opinion | icai.org |
Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.
