Skip to main content
Category: Ethics and Conduct

Conduct Risk

Simply put

Conduct risk is the risk that the way a firm or the people acting on its behalf behave causes harm to customers, investors, or other stakeholders. It is often discussed in the context of financial institutions, where the actions of employees and other associated individuals can damage customers or the wider market. It is generally treated as a form of business risk tied to potential misconduct.

Formal definition

Conduct risk is typically defined as the risk that the behaviour of a firm, and of the individuals acting on its behalf, causes detriment to customers, investors, or other stakeholders. It is commonly characterized as a form of business risk arising from potential misconduct of individuals associated with a firm, including employees. In practice, conduct risk is often incorporated as a component when setting risk appetite and cascading limits and tolerances to business units, and it is a subject of internal audit assurance activity that assesses ethical behaviour, compliance, and related risk controls. The scope, framing, and regulatory emphasis of conduct risk generally vary by jurisdiction, sector, and entity type, and it is most frequently addressed in a financial services context.

Why it matters

Conduct risk matters because the behaviour of a firm and the individuals acting on its behalf can cause direct harm to customers, investors, and the wider market, even where technical compliance with specific rules may appear intact. It is most frequently addressed in a financial services context, where the actions of employees and other associated individuals can damage customers or undermine confidence in a market. Because the consequences of misconduct extend to trust, reputation, and stakeholder outcomes, conduct risk is generally treated as a form of business risk rather than a purely operational or legal concern.

Unlike some risk categories that can be quantified with relative precision, conduct risk is shaped by culture, incentives, and individual decision-making, which makes it harder to observe and measure. This is one reason it is commonly integrated into how firms set risk appetite and cascade tolerances to business units, so that expectations around behaviour are made explicit rather than left implicit. Left unaddressed, patterns of misconduct can accumulate below the surface until they surface as customer detriment, regulatory attention, or market harm.

The scope, framing, and regulatory emphasis of conduct risk vary by jurisdiction, sector, and entity type. This entry is educational and not legal, compliance, or audit advice; how conduct risk applies to a specific firm depends on its facts, its regulatory environment, and the professional judgment of those responsible for it.

Who it's relevant to

Boards and board committees
Boards and relevant committees typically exercise oversight of conduct risk as part of their broader risk oversight responsibilities, including satisfying themselves that the firm's culture and risk appetite address behaviour that could harm customers, investors, or the market. Their role is generally oversight rather than day-to-day management, and the precise expectations vary by jurisdiction and entity type.
Risk officers and management
Management and risk functions are generally responsible for identifying, framing, and managing conduct risk within the business, including incorporating it as a component when setting risk appetite and cascading limits and tolerances to business units.
Compliance officers
Compliance functions are often engaged with conduct risk given its connection to misconduct by individuals associated with a firm and its emphasis on preventing detriment to customers and stakeholders. The specific compliance obligations depend on the applicable regulatory regime, which varies by jurisdiction and sector.
Internal auditors
Internal audit may provide independent assurance over conduct risk, including assessing ethical behaviour, compliance, and related risk controls. This assurance role is distinct from the management role of owning and operating those controls.
Financial services firms
Conduct risk is most frequently addressed in a financial services context, where the actions of firms or individuals can be detrimental to customers or the wider financial market. Its scope and regulatory emphasis nonetheless vary by jurisdiction, sector, and entity type.

Inside Conduct Risk

Definition and Scope
Conduct risk generally refers to the risk that the behavior of an organization or its employees toward customers, counterparties, markets, or other stakeholders results in harm, unfair outcomes, or damage to market integrity. Its precise scope varies by jurisdiction and sector, and it is particularly emphasized in financial services regulatory regimes, though the concept is applied more broadly in practice.
Culture and Behavioral Drivers
A significant component is the organizational culture, incentives, and behavioral norms that shape how individuals act. Conduct risk analysis typically examines whether remuneration structures, performance targets, and 'tone from the top' encourage or discourage behavior that could harm customers or markets.
Customer and Market Outcomes
Conduct risk focuses on outcomes such as fair treatment of customers, suitability of products and advice, transparency of disclosures, and avoidance of market abuse or manipulation. It is often framed around the outcomes experienced by external parties rather than solely internal process compliance.
Relationship to Compliance and Operational Risk
Conduct risk overlaps with but is distinct from narrow compliance risk (breach of specific rules) and operational risk (loss from failed processes or systems). Conduct risk can arise even where technical rules are followed, because it concerns the fairness and integrity of behavior, which may be governed by principles-based standards rather than prescriptive rules.
Governance and Accountability Structures
Managing conduct risk involves clear allocation of responsibility across the board, its committees, senior management, and assurance functions. In some jurisdictions, individual accountability regimes assign named responsibilities to senior individuals, though the specifics depend on the applicable legal framework and entity type.
Three Lines Context
Ownership of conduct risk typically sits with the business (first line), with compliance and risk functions providing oversight, challenge, and monitoring (second line), and internal audit providing independent assurance (third line). Accountability for outcomes generally remains with the first line and senior management, not the assurance functions.

Common questions

Answers to the questions practitioners most commonly ask about Conduct Risk.

Is conduct risk just another name for compliance risk?
No. Compliance risk generally refers to the risk of failing to adhere to applicable laws, regulations, and internal policies, and is typically owned in part by the compliance function as a second-line activity. Conduct risk is broader: it concerns the risk that the behaviour of an organisation and its people produces poor outcomes for customers, market integrity, or the firm itself, even where no specific rule has been breached. In many jurisdictions and under certain regulatory approaches, conduct risk emphasises outcomes and behaviours rather than technical rule-following alone. The two overlap but are not interchangeable, and treating conduct risk purely as a compliance monitoring exercise tends to understate its cultural and behavioural dimensions. This entry is educational and not legal, audit, or compliance advice.
Does managing conduct risk sit solely with the compliance department?
Generally not. Because conduct risk arises from behaviour across the business, accountability for managing it typically rests first with the first line, the business units and management who own the activities that generate the risk. Second-line functions such as compliance and risk often set frameworks, provide challenge, and monitor, while internal audit may provide independent assurance over the effectiveness of those arrangements. Boards and relevant committees generally hold an oversight role, including over culture, rather than an operational one. Attributing conduct risk management entirely to compliance can blur these distinctions and weaken first-line ownership. The precise allocation depends on the entity's structure, sector, and jurisdiction, and this entry does not constitute professional advice.
How can an organisation begin to identify where its conduct risks arise?
A common starting point is to map activities, products, and processes to the points where behaviour could produce poor outcomes for customers, counterparties, markets, or the firm. Organisations often consider incentive structures, sales and remuneration practices, complaints and whistleblowing data, and areas involving conflicts of interest or information asymmetry. The aim is generally to distinguish inherent conduct risk from the residual risk remaining after controls. What is relevant will vary by sector, business model, and jurisdiction, and identification typically depends on the professional judgment of those close to the activity. This is educational content, not a prescribed methodology.
How does conduct risk relate to an organisation's risk appetite?
Many organisations articulate a conduct risk appetite that expresses, often in qualitative terms, the behaviours and outcomes they are and are not willing to accept. This can be more challenging than for quantifiable risks, since conduct outcomes may not lend themselves to simple metrics. It is generally useful to keep the distinction between appetite (the level of risk an organisation is willing to take in pursuit of its objectives), tolerance (acceptable variation around that), and capacity (the maximum the organisation could bear) clear when framing conduct expectations. How this is expressed and cascaded depends on the entity and its governance arrangements, and no single approach is universally mandated.
What kinds of indicators are used to monitor conduct risk?
Organisations frequently draw on a mix of quantitative and qualitative indicators, which may include complaints trends, breaches, whistleblowing reports, employee and customer feedback, product and sales data, and cultural indicators. Because behaviour can be difficult to measure directly, many firms use a combination of lagging and leading indicators and treat them as signals requiring judgment rather than definitive conclusions. It is generally important to distinguish whether monitoring is testing control design or operating effectiveness. The relevant indicators depend heavily on the business and the applicable regulatory context, and this entry does not prescribe specific metrics.
What is the board's role in overseeing conduct risk?
The board's role is typically one of oversight rather than day-to-day management. This can include setting the tone from the top, overseeing organisational culture, reviewing conduct risk information, and challenging management on outcomes and behaviours. In many governance frameworks, aspects of this oversight may be delegated to a risk, audit, or dedicated committee, while accountability for the framework itself remains with the board as a whole. The board generally relies on management and assurance functions for information and should avoid taking on operational responsibilities that belong to the first or second line. Specific expectations vary by jurisdiction, sector, and applicable codes or regulations, and this is educational content, not legal advice.

Common misconceptions

Conduct risk is the same as compliance risk, so following all the rules eliminates it.
The two are related but distinct. Conduct risk can materialize even where an organization technically complies with specific rules, because it concerns the fairness and integrity of behavior and outcomes, which in many regimes are assessed against principles-based expectations rather than prescriptive requirements. Rule compliance reduces but does not necessarily eliminate conduct risk.
Conduct risk is owned and managed by the compliance function.
Under a typical three-lines model, the business (first line) owns and manages conduct risk in its day-to-day activities, while compliance and risk functions (second line) provide oversight, challenge, and monitoring. Attributing ownership solely to compliance conflates operational responsibility with oversight, and accountability for outcomes generally rests with the first line and senior management.
Conduct risk is only relevant to regulated financial institutions.
While the term is most developed within financial services regulatory regimes, the underlying concern about behavior that harms customers, counterparties, or market integrity is applied more broadly in practice. The specific regulatory expectations and any binding obligations, however, depend heavily on jurisdiction, sector, and entity type.

Best practices

Assign clear ownership of conduct risk to the first-line business, with the second-line risk and compliance functions providing independent challenge and monitoring, and reserve independent assurance for internal audit; document where accountability sits rather than defaulting it to the compliance function.
Assess incentive structures, remuneration, and performance targets for behaviors they may encourage, and escalate to the board or the relevant committee where these could drive outcomes harmful to customers or markets.
Frame conduct risk metrics around customer and market outcomes (such as fairness, suitability, and transparency) rather than relying solely on rule-breach counts, recognizing that principles-based expectations may go beyond specific legal requirements.
Distinguish conduct risk from adjacent operational and narrow compliance risks in the risk taxonomy so that risks arising from behavior, even where rules are met, are captured and not overlooked.
Ensure the board sets and articulates cultural expectations ('tone from the top') and receives regular management information on conduct outcomes, while leaving the operational management of conduct to the business.
Confirm the specific legal and regulatory obligations that apply to your jurisdiction, sector, and entity type before treating any conduct-risk expectation as binding, and seek qualified professional advice where the treatment depends on the facts.