Dr. Jeffrey L. Edwards
Founder & CEO

When the Federal Reserve released its review of Silicon Valley Bank’s failure in 2023, the first finding listed wasn’t about interest rates, deposit concentrations or social media. It was about governance. The report concluded that the bank’s board of directors and management failed to manage their risks.

Let that sink in. Before regulators critiqued their own supervision, they pointed at the boardroom.

That moment marked a shift that has since accelerated. Examiners today are less interested in whether a risk report exists and more interested in a simpler, sharper question: Who owns the risk? Not the committee that reviews it. Not the vendor that monitors it. The person — with a name and a title — who is accountable when it materializes.

Most boards cannot answer that question with confidence. Not because directors aren’t diligent, but because the reporting they receive was never designed to answer it.

The Fragmentation Problem
Consider how risk typically reaches the board. Credit risk arrives through the loan committee. Compliance risk arrives in a quarterly report. Cybersecurity arrives in an annual briefing. Vendor risk arrives — if it arrives — buried in an appendix.

Each report may be accurate. Together, they obscure more than they reveal, because the risks that sink banks rarely travel alone. Silicon Valley Bank did not fail from interest rate risk or liquidity risk; it failed when the two compounded, at speed, in front of an audience with smartphones. A board reading two separate reports would have seen two manageable yellow flags — not one red one.

Fragmented reporting also hides the risks that don’t fit neatly into a category. Where does culture show up on a heat map? What about the fintech partner whose compliance program the bank has effectively adopted as its own?

Beyond Likelihood and Severity
There is a structural reason for the blind spot. The standard risk methodology only identifies two dimensions of risk — likelihood and severity — and every risk in the enterprise gets flattened onto that two-axis view. But the risks that actually threaten a bank have more dimensions than the risk methodology identifies using heat maps.

Boards should press management to assess risk across additional dimensions, such as how risks compound with one another, how predictable a risk is before it materializes, how fast it moves once it does and how reliably the controls around it operate in practice. A risk that is unlikely but unpredictable and fast-moving deserves very different board attention than one that is likely but visible months in advance — yet on a traditional heat map, the two can occupy the same square.

What Governance Intelligence Looks Like
The answer is not more reports. It is a different kind of visibility — call it governance intelligence. That should include a continuously updated, board-level view that connects culture, controls and partner risk to named owners. Four moves get a board most of the way there:

  1. 1. Assign every material risk a single accountable owner. Shared ownership is no ownership. If the answer to “who owns this?” is a committee, the real answer is nobody.
  2. 2. Demand reporting that shows compounding, not categories. Ask management to present the three risk combinations that would hurt most if they moved together — and the early signals that would reveal them.
  3. 3. Treat culture and controls as behavior, not documentation. A control tested annually tells the board what existed on the test date. Directors should ask how management knows controls are operating between examinations.
  4. 4. Extend ownership to third parties. Regulators have made clear that a bank cannot outsource accountability. Every material partner relationship deserves an internal owner who can speak to that partner’s risk posture without a briefing.

The Examination-Ready Board
Is this more work for directors? Somewhat. But it is the difference between a board that receives risk information and a board that governs risk — a distinction examiners notice and increasingly document.

The next time enterprise risk appears on the agenda, the most valuable question a director can ask isn’t, “What are our top risks?” Every bank has that slide. The question is simpler and far more revealing: For each one ask, “Who owns it?”

If the room goes quiet, the board has found its real top risk.

WRITTEN BY

Dr. Jeffrey L. Edwards

Founder & CEO

Dr. Jeffrey L. Edwards is founder and CEO of FFERM Technologies Inc. Charlotte, North Carolina. He has spent more than 30 years in financial services risk management and teaches as an adjunct professor at colleges and universities nationwide.