Conduct Risk
Conduct risk is the risk that the way a firm or the people acting on its behalf behave causes harm to customers, investors, or other stakeholders. It is often discussed in the context of financial institutions, where the actions of employees and other associated individuals can damage customers or the wider market. It is generally treated as a form of business risk tied to potential misconduct.
Conduct risk is typically defined as the risk that the behaviour of a firm, and of the individuals acting on its behalf, causes detriment to customers, investors, or other stakeholders. It is commonly characterized as a form of business risk arising from potential misconduct of individuals associated with a firm, including employees. In practice, conduct risk is often incorporated as a component when setting risk appetite and cascading limits and tolerances to business units, and it is a subject of internal audit assurance activity that assesses ethical behaviour, compliance, and related risk controls. The scope, framing, and regulatory emphasis of conduct risk generally vary by jurisdiction, sector, and entity type, and it is most frequently addressed in a financial services context.
Why it matters
Conduct risk matters because the behaviour of a firm and the individuals acting on its behalf can cause direct harm to customers, investors, and the wider market, even where technical compliance with specific rules may appear intact. It is most frequently addressed in a financial services context, where the actions of employees and other associated individuals can damage customers or undermine confidence in a market. Because the consequences of misconduct extend to trust, reputation, and stakeholder outcomes, conduct risk is generally treated as a form of business risk rather than a purely operational or legal concern.
Unlike some risk categories that can be quantified with relative precision, conduct risk is shaped by culture, incentives, and individual decision-making, which makes it harder to observe and measure. This is one reason it is commonly integrated into how firms set risk appetite and cascade tolerances to business units, so that expectations around behaviour are made explicit rather than left implicit. Left unaddressed, patterns of misconduct can accumulate below the surface until they surface as customer detriment, regulatory attention, or market harm.
The scope, framing, and regulatory emphasis of conduct risk vary by jurisdiction, sector, and entity type. This entry is educational and not legal, compliance, or audit advice; how conduct risk applies to a specific firm depends on its facts, its regulatory environment, and the professional judgment of those responsible for it.
Who it's relevant to
Inside Conduct Risk
Common questions
Answers to the questions practitioners most commonly ask about Conduct Risk.