Culture & Governance Risk | Insights, Resources & Best Practices

The Cost of Quiet: Why Regulatory Silence Is a Legal Risk Trap

Written by Brenda Boultwood | August 28, 2026

Within enterprise risk management (ERM) frameworks, legal risk occupies a distinct space. Banks manage market risk and credit risk by trading risk for rewards. Conversely, banks traditionally maintain a near-zero tolerance for legal and compliance risk. The large compliance structures that financial institutions built to ensure adherence to regulations relied on the threat of public enforcement actions, heavy civil money penalties, and reputational damage.

The current operating environment disrupts this traditional dynamic. Regulatory enforcement actions have dropped across federal banking agencies. Staffing reductions and administrative directives have slowed the pace of corporate oversight.

Empirical data confirms that total formal enforcement actions across the primary federal banking regulators fell by 23% between the 2017–2019 baseline and the 2023–2025 period. In percentage terms, the Federal Reserve’s decrease was the most significant, at nearly 50%.

This decline creates a false sense of security for bank executives. When supervisory police stop issuing public tickets, internal business units demand speed. However, mistaking temporary enforcement silence for legal repeal is a severe strategic mistake. Chief Risk Officers and Chief Executive Officers must maintain operational discipline. They must recognize that current non-enforcement does not end future legal liability.

Legal Risk in the ERM Framework

Standard ERM frameworks classify legal risk as a core category of operational risk. Legal risk includes exposure to administrative fines, civil money penalties, private litigation damages, and forced operational restructuring. In addition to insider trading and conflict of interest requirements, U.S. bank compliance focuses on federal statutes:

  • Bank Secrecy Act (BSA) / Anti-Money Laundering (AML) mandates Customer Due Diligence (CDD), Know Your Customer (KYC) protocols, and Suspicious Activity Reporting (SAR). It remains the primary tool for prosecuting financial crime.
  • Foreign Corrupt Practices Act (FCPA) prohibits domestic institutions and foreign entities from bribing foreign officials. It triggers legal, financial, and operational risks. The JPMorgan "Sons and Daughters" hiring program settlement demonstrated this coverage. FCPA violations frequently intersect with BSA/AML failures. Regulators routinely charge banks with both failures simultaneously when institutions process tainted funds.
  • Dodd-Frank Wall Street Reform and Consumer Protection Act controls capital reserves, stress testing, and risk management parameters. It also established the Consumer Financial Protection Bureau (CFPB).
  • Community Reinvestment Act (CRA) requires banks to meet credit needs across all local community segments. CRA scores directly dictate expansion and merger approvals.
  • Gramm-Leach-Bliley Act (GLBA) establishes baseline requirements for protecting nonpublic consumer financial privacy.

Supervision priorities may shift across political administrations. Yet, the underlying statutes remain unchanged. A temporary decision by an agency to withhold public enforcement does not alter legal obligations.

The Illusion of Temporal Immunity

ERM frameworks must evaluate risk over multi-year time horizons. A bank that weakens internal controls to capture short-term revenue creates three primary long-term risk and legal enforcement exposures:

Brenda Boultwood

1. Statute of Limitations Exposure: Federal financial statutes feature extended statutes of limitations. Most federal financial crimes carry five- to ten-year legal windows. Conspiracy statutes extend these windows further. Transactions completed during a period of lax enforcement remain fully prosecutable under future administrations.

2. Multijurisdictional and Global Liability: Domestic regulatory pullbacks do not bind foreign supervisory authorities or state attorneys general. U.S. banks operating internationally face oversight from foreign bodies, including the U.K. Serious Fraud Office. Foreign authorities can prosecute illicit cross-border flows independently of U.S. executive posture.

3. Private Civil and Shareholder Litigation: A decline in federal agency enforcement does not eliminate private rights of action. Shareholders, corporate counterparties, and state officials retain the legal standing to sue institutions for legal breaches.

Navigating legal risk during an enforcement pause requires analyzing complex real-world decisions. Here are some examples:

1. Politically Charged AML De-risking: As an example of AML compliance, Capital One closed almost 400 bank accounts tied to a key political figure after internal automated systems flagged elevated AML risks and Politically Exposed Person (PEP) profiles. The account holders subsequently sued the bank, alleging political discrimination. This scenario highlights a direct legal risk trap for Capital One and several of its peers. Strict adherence to baseline AML procedures protected the bank from future money laundering charges. However, it generated immediate civil litigation and public political backlash.

2. Corporate Influence and Transactional FCPA Exposure: During periods of low administrative oversight, commercial entities face pressure to engage in transactional access models. Corporations have provided significant donations, executive gifts, and capital contributions to secure favorable administrative rulings. Examples include corporate contributions toward White House infrastructure projects and specific trade exemptions granted following luxury gifts. Risk managers must evaluate these interactions against FCPA provisions and federal bribery statutes. Executive agencies may overlook transactional policy concessions today. However, future prosecutors can review these exchanges. If a subsequent administration classifies prior access payments as unlawful kickbacks, participating institutions face clawbacks, severe fines, and criminal charges.

3. Insider Trading in Deregulated Capital Markets: Changes in federal policy create substantial market volatility and information asymmetry. Executive directives regarding industry deregulation, tariff adjustments, and contract awards generate rapid stock movements. Corporate executives and market participants with advance knowledge of these policy shifts face significant insider trading temptations.

During enforcement lulls, market oversight appears minimal. Frontline traders may view policy-driven insider trading as low risk. However, securities laws prohibit trading on material nonpublic government information. Trading records persist indefinitely. Automated market surveillance systems archive all transactional data. When political leadership changes, SEC enforcement attorneys and federal prosecutors routinely audit historical trades. They can prosecute past insider trading transactions years after their execution.

4. Anti-Money Laundering Enforcement and Capacity Destruction: Changes in administrative enforcement can extend from regulatory leniency to dismantling investigative infrastructure. The Treasury Department’s Financial Crimes Enforcement Network issued a final rule August 11 to remove for U.S. entities the requirement for reporting shell-company ownership, along with previously collected data. Without this database, law enforcement loses a vital anti-corruption tool to trace illicit financial flows, effectively shielding money laundering, tax evasion, and trafficking activities across political cycles.

For risk managers, the erasure of public oversight mechanisms exponentially increases long-term latent liability. Financial institutions that loosen internal due diligence during enforcement lulls remain fully exposed when future administrations re-examine historical transactions.

5. Political Contributions and Regulatory Rollbacks: Corporate political engagement during periods of regulatory pullback can generate severe long-term legal and reputational exposure. Amid a national cyclospora outbreak across 47 states, the FDA delayed its food traceability rule, while the CDC scaled down parasite tracking systems and closed research facilities. These regulatory concessions coincided closely with major political donations by produce supplier Taylor Farms’ parent company to presidential political action committees (PACs).

While all parties deny wrongdoing, congressional scrutiny highlights the severe risks of transactional access. Institutions that exploit temporary regulatory rollbacks face significant future liability, shareholder lawsuits, and prosecution under subsequent political administrations.

Paradoxes for the Chief Risk Officer

Operating in an environment of low regulatory enforcement presents three structural paradoxes for bank risk management leadership.

1. The Latent Liability Paradox. Lowering internal compliance standards to exploit temporary supervisory inactivity exponentially increases long-term tail risk. When regulatory agencies issue fewer formal enforcement actions, internal business units argue that compliance budgets should be cut. The paradox is clear. Bending a rule today appears inexpensive because immediate punishment is low. However, accumulating unmonitored legal breaches creates compounding latent liability. The CRO must treat temporary supervisory silence as a period of heightened long-term risk.

2. The Defensive Compliance Paradox. Executing mandatory legal duties can trigger immediate civil retaliation, while failing to execute them guarantees future criminal prosecution. Standard operational risk management requires filing SARs and offboarding high-risk clients. In a polarized climate, executing these legal duties can trigger political attacks, litigation, or loss of local business. The CRO faces a sharp trade-off. The bank must choose between immediate operational friction and severe future prosecution.

3. The Competitive Disadvantage Paradox. Maintaining strict legal compliance penalizes sound institutions while rewarding non-compliant competitors during an enforcement lull. When rival banks cut compliance staff, streamline due diligence, or process high-risk transactions without penalty, compliant institutions lose market share. Non-compliant firms capture higher short-term margins. The CRO must convince the board of directors to accept short-term yield penalties. The bank must sacrifice temporary revenue to ensure long-term solvency.

Parting Thoughts

Enterprise risk management requires temporal discipline and an apolitical mindset. Political leadership and regulatory enforcement appetites shift on short cycles. Financial institutions are built for multi-decade survival. The CRO must protect the bank across changing political regimes.

The true test of risk governance occurs when external enforcement pressures disappear. Maintaining robust legal compliance during an era of regulatory silence is not a passive operational task. It is the core mechanism for preserving enterprise value.

 

 

Brenda Boultwood is the Distinguished Visiting Professor, Admiral Crowe Chair, in the Economics Department at the United States Naval Academy. The views expressed in this article are her own and should not be attributed to the United States Naval Academy or the U.S. Department of Defense.

She is the former Director of the Office of Risk Management at the International Monetary Fund. She has previously served as a board member at both the Committee of Chief Risk Officers (CCRO) and GARP, and is also the former senior vice president and chief risk officer at Constellation Energy. She held a variety of business, risk management, and compliance roles at JPMorgan Chase and Bank One.