Risk culture is the system of shared values, attitudes, and behaviors that shapes how people across an organization recognize, discuss, escalate, and act on risk. It sits inside the broader corporate culture, and it decides whether risk policies operate as written or exist only on paper when real decisions get made.
Beginning in 2007, Discover Financial Services classified certain consumer credit cards into its highest commercial pricing tier, overcharging merchants and payment processors on interchange fees for the next 16 years. Thousands of employees touched that pricing engine. The error surfaced publicly in 2023.
The bill arrived all at once. CEO Roger Hochschild stepped down on August 14, 2023 as the board cited compliance lapses, and the FDIC moved on a consent order. The company booked an initial $365 million liability that grew into a settlement worth up to $1.225 billion, granted preliminary court approval on July 30, 2025.
| Risk Culture: Key Takeaways |
| Risk culture is the set of shared values and behaviors that determines how people in an organization actually identify, discuss, escalate, and act on risk, whatever the policies say. |
| The Financial Stability Board’s assessment framework rests on four indicators: tone from the top, accountability, effective communication and challenge, and incentives. |
| Discover misclassified card pricing for 16 years. Disclosure in 2023 cost the CEO his job, brought an FDIC consent order, and ended in a settlement of up to $1.225 billion. |
| Duration is the cultural tell. A control failure that survives 16 years is not a process gap; it is evidence that escalation felt more dangerous than silence. |
| Culture is measurable. Pair an annual survey with behavioral data: near-miss reporting rates, escalation timelines, overdue risk actions, and repeat audit findings. |
| Only 41% of executives rated their board’s effectiveness as excellent or good in 2025 (PwC/The Conference Board), and boards own the tone that culture follows. |
No sophisticated fraud hid that error for 16 years. People either did not look, did not connect what they saw, or did not feel that raising it was their job. That is a risk culture failure, and it is the kind of loss no single control catches.
What Risk Culture Actually Describes
Strip away the consulting language and risk culture describes one observable thing: what people in your organization do about risk when nobody is checking. It covers which risks get identified and written down, which get discussed openly, which get escalated, and which get quietly absorbed because raising them feels career-limiting.
The Institute of Risk Management defines it as the values, beliefs, knowledge, and understanding about risk shared by a group with a common purpose. ISO 31000:2018 builds human and cultural factors into its principles, and COSO’s ERM framework makes governance and culture the first of its five components.
Each body words it differently, and the table below shows how consistently they land on the same substance. Every definition lands on behavior, which is why a strong risk management policy can coexist with a weak culture and lose to it every time.
| Source | How It Frames Risk Culture | The Practical Test |
| FSB (2014) | Norms and traditions of behavior that determine how risk is identified, understood, discussed, and acted on | Watch what gets escalated, and how fast |
| IRM | Values, beliefs, knowledge, and understanding about risk shared by a group with a common purpose | Ask five people what risks worry them; compare answers |
| COSO ERM (2017) | Governance and culture form the first component that all other ERM components depend on | Check whether culture appears on the board agenda |
| ISO 31000:2018 | Human and cultural factors are a stated principle of effective risk management | Test whether the framework survives contact with incentives |
Table 1. Four authorities, one substance: risk culture is what people do, not what documents say.
Why Sixteen Years Beat Every Control at Discover
Discover had the control environment a major card issuer is required to run: compliance staff, internal audit, model governance, and a regulator on site. None of it caught a pricing misclassification that ran from 2007 to 2023. Understanding how is the fastest route to understanding culture. Culture is also one of seven components of a risk management program, and the program guide shows where speak-up channels sit among the other six.

Figure 1. Sixteen years from first error to disclosure, then two years to a $1.225 billion settlement and a sale.
Duration is the diagnostic: a defect that survives one audit cycle is a process gap, while a defect that survives sixteen of them means the surrounding organization had normalized it. Normalization is risk culture doing exactly what it was trained to do. American Banker’s reporting described the exit as following a wave of compliance issues, plural.
Survey data says the conditions behind that silence are common. In the NAVEX 2025 State of Risk & Compliance study, 73% of respondents said senior executives encourage compliance and ethics. Read the remainder: roughly one in ten reported leaders had pushed employees to act unethically to hit a business objective.
Boards do not escape the data either. Only 41% of executives rated their board’s effectiveness as excellent or good in 2025, per a PwC and The Conference Board survey, up from 35% the year before. The tone culture follows is set in that room, which is why culture questions belong on every ERM framework build from day one.

Figure 2. The gap between stated tone and lived pressure, from the NAVEX 2025 and PwC/Conference Board surveys.
Watch for the warning signs that a risk culture is absorbing risk instead of surfacing it. Each of the four below is cheap to monitor, and every one of them was visible in hindsight at Discover, which is precisely what makes them worth a standing slot on the dashboard:
- Near-miss and incident reports trend down while the business grows, which usually means reporting stopped, and the risk did not.
- The same root cause appears in consecutive audit cycles under different finding titles.
- Risk items enter the register scored, then sit without owners, triggers, or funded responses.
- Bad news reaches executives polished, late, and pre-summarized, never raw.
The Four Indicators Regulators Actually Test
After the 2008 crisis, supervisors stopped accepting culture as an abstraction. The Financial Stability Board’s 2014 guidance on supervisory interaction with financial institutions gave examiners a concrete framework, and it remains the reference point US banking supervisors and the OCC’s heightened standards work from.

Figure 3. The FSB’s four indicators of a sound risk culture, from its April 2014 assessment framework.
The four indicators work as a system, and weakness in one corrodes the rest. Incentives are the one boards most often leave untouched. If pay and promotion reward hitting the number regardless of how, tone-from-the-top speeches change nothing, because employees answer to the scoreboard.
| FSB Indicator | What Sound Looks Like | What Failure Looks Like |
| Tone from the top | Leaders act on the risk appetite they approved; they fund and staff the second line | Appetite statement approved, then overridden the first quarter it binds |
| Accountability | Every material risk has a named owner; escalation is an obligation with a stated channel | Risks owned by departments, so owned by nobody; issues age silently |
| Effective challenge | Alternative views are requested in decisions; the second line can stop a deal | Challenge is read as disloyalty; meetings end in unanimous agreement, always |
| Incentives | Risk behavior shows up in scorecards, pay, and promotion decisions | Revenue heroes are untouchable; control functions are cost centers |
Table 2. The FSB’s four indicators translated into observable states.
Risk Culture vs Risk Appetite and Corporate Culture
These three terms travel together and get merged constantly, so the boundaries are worth drawing sharply. A risk appetite statement records how much risk the organization chooses to take. Risk culture determines whether anyone honors that statement when it conflicts with a revenue target.
| Concept | What It Is | Relationship to the Others |
| Corporate culture | The full set of shared values and behaviors across the organization | The container; risk culture is one dimension of it |
| Risk culture | Shared behaviors specifically about identifying, discussing, and acting on risk | Decides whether appetite and policy operate in practice |
| Risk appetite | The amount and type of risk the board chooses to accept in pursuit of strategy | A written choice; culture is what enforces or ignores it |
| Risk tolerance | Quantified boundaries around appetite for specific risk types | Thresholds that only bind where culture escalates breaches |
Table 3. Culture is the enforcement layer; appetite and tolerance are the written intent.
The full quantitative chain from appetite through tolerance to capacity is mapped in our risk appetite vs risk tolerance vs risk capacity guide. The short version: the documents state intent, and the culture supplies or withholds the follow-through. Discover had every document.
How to Measure Risk Culture Without Fooling Yourself
Culture feels unmeasurable, and vendors exploit that feeling. In practice, triangulate it with instruments you already own, provided the survey stays one input among several. Surveys capture what people say; behavioral data captures what they do, and the gap between the two is itself a finding.
| Instrument | What It Reveals | Cadence | The Trap |
| Culture survey | Perceived safety to speak up, clarity of appetite, trust in leaders | Annual | Anonymity doubts inflate scores |
| Focus groups | The stories and folklore behind the survey numbers | Semi-annual | Dominated by the loudest voice |
| Behavioral metrics | Actual reporting, escalation, and remediation conduct | Monthly | Gaming once metrics become targets |
| Root-cause reviews | Whether culture contributed to real incidents | Per incident | Stopping at the technical cause |
| Exit interviews | What people would not say while employed | Ongoing | Ignoring them as sour grapes |
Table 4. A measurement mix; no single instrument survives contact with a defensive culture.
On the behavioral side, a handful of key risk indicators cover most of the signal. Track near-miss reporting volume, the median age of open risk actions, escalation-to-decision time, and repeat findings. Falling report volume in a growing business is the single most reliable red flag.

Figure 4. A one-page culture dashboard: two healthy indicators, three that warrant a conversation.
Score each indicator against a target the board has seen, then review the panel quarterly alongside the register in your risk management lifecycle cadence. Treat every amber as a question about behavior; a tidy explanation today is an incident later. The dashboard’s job is to start arguments early, while they are still cheap.
Building a Culture Change Program That Sticks
Most culture programs die as poster campaigns, while the ones that work change consequences, because behavior follows consequences and culture follows behavior. That means wiring culture into the five core risk management steps people already perform. A parallel initiative with its own committee and slide deck stalls by year end.
A workable change program runs four moves over roughly a year. None of them requires new software or an outside framework, but each one requires an executive willing to change a consequence when publishing a value statement would be easier, which is where most programs quietly stall:
- Baseline honestly (months 1-2). Run the survey and pull the behavioral metrics before announcing anything. You need the unflattered starting point.
- Fix the consequences (months 3-6). Put risk behavior into scorecards and promotion criteria, and publicly back the first person who escalates something expensive.
- Equip the middle (months 6-9). Train line managers to receive bad news well; they are the layer where escalations die.
- Re-measure and report (month 12). Same survey, same metrics, board-level readout, gaps owned by named executives.
The most powerful act in culture change costs nothing: how leadership treats the next messenger. One well-handled escalation, visibly rewarded, teaches more than a year of training. One punished messenger undoes all of it, and the value the whole risk program claims to add quietly evaporates with the silence that follows.
Common Pitfalls in Risk Culture Work
| Pitfall | Why It Fails | What to Do Instead |
| Poster-and-pledge campaigns | Signals effort while consequences stay unchanged | Change scorecards and promotion criteria first |
| Survey-only measurement | Captures stated attitudes, misses behavior | Pair every survey with behavioral metrics |
| Blaming the front line | The front line copies what leadership tolerates | Start remediation at the executive committee |
| One-off assessment | Culture drifts; a snapshot ages in months | Annual survey, quarterly behavioral panel |
| Zero-tolerance theater | Drives risk underground instead of surfacing it | Reward disclosure; punish concealment |
| Ignoring incentives | Pay outweighs every stated value | Audit what actually gets people promoted |
Table 5. Six ways culture programs fail, each avoidable at design time.
Frequently Asked Questions
What is risk culture in simple terms?
Risk culture is what people in an organization actually do about risk when no one is watching: what they report, what they escalate, and what they quietly ignore. It is the behavioral layer that decides whether written policies and appetite statements operate in real decisions or exist only on paper.
What are the four indicators of a sound risk culture?
The Financial Stability Board’s 2014 framework names four: tone from the top, accountability, effective communication and challenge, and incentives. Supervisors treat them as a system. Weak incentives undermine strong tone, and missing accountability lets both decay, which is why examiners test all four together rather than scoring them separately.
What is the difference between risk culture and risk appetite?
Risk appetite is a written choice: the amount and type of risk the board accepts in pursuit of strategy. Risk culture is the shared behavior that enforces or ignores that choice. An organization can hold a precise appetite statement and still breach it routinely if its culture rewards hitting targets over honoring limits.
How do you measure risk culture in an organization?
Triangulate an annual perception survey against behavioral data: near-miss reporting volume, escalation-to-decision time, overdue risk actions, and repeat audit findings. The gap between what people say and what the metrics show is itself a finding about the risk culture. Review the combined panel quarterly at executive level.
Who is responsible for risk culture?
The board owns the tone and the incentives; executives transmit both through what they fund, promote, and tolerate; line managers determine whether escalations survive first contact. Risk functions can measure and report culture, but they cannot own it, because culture is set by the people who control consequences.
What does a poor risk culture look like day to day?
Falling incident reports in a growing business, risks logged without owners or funded responses, unanimous meetings, repeat audit findings under new names, and bad news that arrives late and polished. Discover’s 16-year misclassification is the canonical example: thousands of people near an error, and no escalation that stuck.
Where Risk Culture Is Heading Next
Supervisory patience is shortening. The FSB framework gave examiners a common vocabulary in 2014, and enforcement since has priced culture failure in billions. Discover’s arc from disclosure to CEO exit to consent order to a settlement approved in July 2025 compressed into two years what once took a decade.
Measurement is also getting harder to fake. Protiviti’s Top Risks survey for 2026 keeps talent, culture, and conduct concerns in its executive top ten, and boards increasingly ask for the behavioral evidence beneath the survey averages. The organizations ahead of this are the ones treating culture data with the same rigor as credit or operational risk data.
The practical starting point has not changed: baseline what your people actually do, fix the incentives that contradict your stated appetite, and make the next escalation a good career move. Everything else in your risk management process inherits its effectiveness from that foundation.
If your register is full and your escalations are empty, culture is the gap to close first. Our risk advisory services baseline culture with survey and behavioral evidence and build the change program with your executives; contact us to scope it. Sixteen years is what silence costs.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.