By Greg Baer, President and Chief Executive Officer, Bank Policy Institute (BPI)
It was recently reported that the Office of the Comptroller of the Currency (OCC) had rated a third of large US national banks as having unsatisfactory management. That report raises serious questions—not about the banks and their management but rather about the examination regime administered by the banking agencies and their management.
The OCC report should not have been a surprise, as it was consistent with the most recent “Federal Reserve Supervision and Regulation Report” for May 2024. In that report, the Board of Governors of the Federal Reserve System (the Fed) found that two-thirds of large US bank holding companies (which in most cases have national bank subsidiaries) were not well managed.
One might have expected these reports to rattle markets. After all, under Federal Reserve guidance, a well-managed firm “has sufficient financial and operational strength and resilience to maintain safe-and-sound operations through a range of conditions, including stressful ones”. Thus, the twin findings by the Fed and the OCC that substantial numbers of large US banks were deficient in that measure should have been a major policy and market concern. But there was no such concern—because any such conclusion is flatly inconsistent with the reported capital, liquidity and earnings of those banks, as well as the clear views of investors and analysts. Indeed, it is even inconsistent with the Fed’s supervision and regulation report itself, which begins by stating, “The banking system remains sound and resilient.”
So, how could the Fed and the OCC reach examination conclusions so dramatically at odds with reality? They did so in two ways: by shifting the focus of their examinations from material financial risk to so-called operational risk, and by changing their roles from examination to management consulting.
It is important to stress that we know that the low management ratings are not being driven by risks such as those that caused the banking upheaval in March 2023—namely, interest rate risk (IRR) and liquidity risk (LR). Those are actually separate components of both agencies’ rating systems and reportedly are satisfactory—not surprisingly, given that large banks weathered that episode well and mid-sized banks have acted over the past year to diminish their interest rate risks and enhance their liquidity.
Perhaps more significantly, agency examiners exhibited no prescience on that front as interest rate risks and liquidity risks were rising: The final composite rating for Silicon Valley Bank (SVB) prior to its failure was satisfactory. The same was true for First Republic Bank and Signature Bank.
So, on what were (and are) agency examiners focused, if not the material financial risks that caused those banks to fail? According to recent news reports, the OCC rates half of large US banks as deficient in how they manage “operational risk”—issues such as information technology (IT), vendor management and cybersecurity—and those low operational risk ratings drove the low ratings for management in general. The Federal Reserve captures operational risk through a “governance and controls” rating that is distinct from its capital and liquidity ratings. Its supervision and regulation report released in November 2022—shortly before SVB’s failure—stated: “While many firms have broadly met expectations in capital planning and liquidity risk management, they still have work to do to meet supervisory expectations for governance and controls. Governance and controls findings represent over 75 percent of the outstanding issues at large financial institutions. Governance and controls findings include deficiencies related to operational resilience, information technology, third-party risk management, and compliance.”
As the SVB experience suggests, it seems clear that their focus on operational risks is distracting examiners and banks from material financial risks. A recent academic paper looked at how banks were examined in 2022, the year before interest rate risk and liquidity risk doomed or imperiled many banks. The study looked at the Liquidity (L) and Sensitivity to Market Risk Including Interest Rate Risk (S) ratings assigned by examiners while the Federal Reserve was raising interest rates. They found that L and S downgrades accelerated at banks with high interest rate risk exposure, although only 16 percent of the quintile of banks with the highest levels of interest rate risk saw a downgrade. More significantly, for present purposes, though, there was no correlation to downgrades in the management rating and no correlation to downgrades in the overall composite rating. That is a remarkable indictment of the examination regime.
The focus on operational risk, therefore, seems ill-advised. But even if it were a material risk, three additional questions arise.
First, why is the government examining banks (as opposed to every other US industry) for operational risks? The traditional and rational justification for the regulation and examination of banks is moral hazard: the presence of deposit insurance and discount window access could incentivize banks to take greater financial risks than if they owned all the liabilities. However, there is no such incentive when buying IT systems or designing cyber defenses. Banks understand those risks and fully internalize them. While some banking systems are critical infrastructures for the US economy, so, too, are telecommunications and power networks, yet government examiners do not draft manuals to define how they should manage those risks and examine them constantly for compliance.
Second, are banks really as bad at managing operational risks as examiners are claiming? Recall that at the outset of the COVID pandemic in 2020, the banking industry seamlessly transitioned to an out-of-office environment with no service interruptions. Major outages of payment and other important systems have been rare, and when they have occurred, they have generally had no economic or systemic impacts. The recent CrowdStrike-Microsoft episode disrupted many industries, but bank customers were largely unaffected. Ask anyone in the national-security world which industry has invested the most, organized the best and is the most resilient against cyberattacks, and they will tell you it is the banking industry. It is difficult to understand how that translates into the findings that large banks are poorly managed because they have failed to manage those risks.
Third, do examinations do anything to lessen those risks? When it comes to cyber defense, there appears to be one major potential source of weakness at all large US banks. Last year, we conducted a survey of their chief information security officers. They reported that they spent 30-50 percent of their time on compliance and examiner management; their teams spent 70 percent of their time on those functions. They reported, on average, more than 100 requests for information leading up to an average examination, with anywhere from 75 to 100 supplemental requests during the exam. And 25 percent of examination requests duplicated requests from other agencies. They also reported morale problems and resulting attrition as good employees moved to other industries where they could simply do their jobs. Of course, the banking agency’s examiners submitting those hundreds of requests are not National Security Agency (NSA) veterans spotting malicious codes in bank systems overlooked by the hundreds or even thousands of cyber professionals the banks retain for that purpose; rather, they are auditors ensuring compliance with manuals and handbooks. Thus, it seems that the presence of cyber examiners at the largest US banks is currently doing more harm than good.
The answers here are important—and not just because of the deadweight costs and management and board distractions produced by government management consulting. Under the secret enforcement regimes operated by banking agencies, examination ratings have significant consequences. Those banks given unsatisfactory ratings by the OCC or the Fed are now likely restricted from M&A (mergers and acquisitions) activities, paying higher deposit insurance premiums (DIPs) and being subjected to other secret sanctions. One can also be sure that massive resources are being dedicated to remediating whatever problems generated the adverse ratings—distracting management, increasing costs and slowing innovation.
Regulators have rightly noted that cyber risks are rising and that widespread reliance on certain key vendors presents new risks. (Ironically, one reason banks tend to use the same vendors is because only the largest vendors can afford the compliance burdens that come with bank examinations; also, examiners generally prefer an established company to a start-up.) However, the severity of those risks is not grounds for saying that banks are ignoring or managing those risks badly and need to be punished for it.
The more we learn about the secret examination regimes operated by US banking agencies, the more reason there is for concern. Recent news is no exception.
References
1 Reuters: “US regulator privately finds weak risk-management at half of large banks, Bloomberg reports,” July 21, 2024.
2 Becker Friedman Institute for Research in Economics/University of Chicago: “How (in)effective was bank supervision during the 2022 Monetary Tightening?” Yadav Gopalan and João Granj, September 29, 2023, Pages 18-19.
