Half of top US banks have ‘inadequate’ operational risk management

A US regulator has reportedly found that half of the major banks it oversees have weak or insufficient operational risk management in place.

People familiar with the matter told Bloomberg that the Office of the Comptroller of the Currency (OCC) uncovered inadequate risk management in areas such as cyber-attacks or employee mistakes at 11 of the 22 banks it oversees.

In a statement, the US watchdog said that acting comptroller Michael Hsu has "consistently discussed the need for banks to guard against complacency and actively manage their risks in order to build and maintain trust in the federal banking system."

The news comes days after a global IT outage saw banks experience disruption around the world, with some consumers unable to access their digital app services.

In May, the Bank of England (the Bank) urged UK firms involved in facilitating payments to do more ahead of the March 2025 deadline for its new operational resilience rules.

In a speech at the London Institute of Banking and Finance, executive director of financial market infrastructure at the Bank Sasha Mills said that Financial Market Infrastructures (FMIs), those that form part of the network of systems that make payments possible, still have a lot of work to be done.

The Bank’s upcoming operational resilience policy is designed to protect the wider financial sector and UK economy from the impact of operational disruptions.

Mills said that the Bank expects these firms to “accelerate” their efforts over the next year to ensure they are in a position to tolerate the negative impacts of disruption on their important business services, including mapping the key people, processes, technology, facilities, and information needed to deliver them in times of crisis.



Share Story:

Recent Stories


Banking's GenAI evolution: Beyond the hype, building the future
In the first episode of a three-part video podcast series sponsored by HCLTech, Sudip Lahiri, Executive Vice President & Head of Financial Services for Europe & UKI at HCLTech explores how financial institutions can navigate the transformative potential of Generative AI while building lasting foundations for innovation.

Beyond compliance: Transforming document management into a strategic advantage for financial institutions
In this exclusive fireside chat, John Rockliffe, Pre-Sales Manager at d.velop, discusses the findings of Adapting to a Digital-Native World: Financial Services Document Management Beyond 2025 and explores how FSIs can turn document workflows into a competitive advantage.

Sanctions evasion in an era of conflict: Optimising KYC and monitoring to tackle crime
The ongoing war in Ukraine and resulting sanctions on Russia, and the continuing geopolitical tensions have resulted in an unprecedented increase in parties added to sanctions lists.

Achieving operational resilience in the financial sector: Navigating DORA with confidence
Operational resilience has become crucial for financial institutions navigating today's digital landscape riddled with cyber risks and challenges. The EU's Digital Operational Resilience Act (DORA) provides a harmonised framework to address these complexities, but there are key factors that financial institutions must ensure they consider.