The Paradox of Safety: Why External Frameworks Fail When It Matters Most
Disasters often strike quick as a flash, with the force of a typhoon. And this can precipitate a familiar decline into chaos. Putting aside for a moment how financial crises can eat up institutions unprepared for unforeseeable events, let's remember The Great Fire of London (1666): it spread with relentless ferocity, feeding on the city’s vulnerabilities. We may perceive that many of the external and internal factors that fueled the fire mirror the dynamics of systemic risk in banking. These patterns perpetuate crises that cause much harm:
Ignition (Initial Shock): The bakery fire, much like a specific financial shock (e.g., the Volcker rate rises in the early 1980s), was the starting point. On its own, it might have been contained, but other factors allowed it to escalate.
Fuel (Hidden Risks Accumulate): The city’s wooden buildings and narrow streets acted as fuel, enabling the fire to spread rapidly. Similarly, in banking, excessive risk-taking (e.g., over-leveraging; lending into markets one is not knowledgeable about; extending maturuity mismatch duration to maximise NII, etc) builds up under the surface, awaiting a catalyst before implosion.
Wind (External Accelerants): Strong winds carried embers across the city, igniting fresh fires elsewhere, making containment nearly impossible. In financial crises, external accelerants—such as regulatory blind spots or investor panic—can magnify losses and spread contagion across markets.
Delayed Response (Failure to Recognise the Crisis): Initially, authorities underestimated the fire’s severity, reacting too slowly (the initial response of the Mayor is unprintable here! :-)) Just as in banking crises, decision-makers (at firm-level or higher policy-level) may not grasp the full implications until it’s too late.
Cascading Failure (Systemic Collapse): The fire ultimately consumed much of London’s infrastructure, overwhelming firefighting efforts. Similarly, financial crises, once they reach a tipping point, can no longer be contained by traditional risk management or regulatory measures, leading to widespread economic damage.
Rebuilding and Regulation (Post-Crisis Reform): After the fire, London introduced stricter building codes, including mandatory brick and stone construction to prevent recurrence. In finance, post-crisis reforms (such as capital requirements and stress testing) emerge; quite understandably these are heavily influened by past failures rather than future unknowns.
How banking stress unfolds...
History offers another stark lesson in the South Sea Bubble of 1720. What began as speculative enthusiasm led to financial mania, inflated asset prices, and ultimately, a dramatic collapse, exposing deep structural weaknesses in investor behavior and corporate governance. Similarly, within banks, over-reliance on compliance-driven risk practices can create blind spots, leaving institutions vulnerable when market sentiment shifts.
Consider a bank liquidity run. Externally, this can be compounded by environmental conditions; perhaps a sharp decline in consumer confidence during a recession causing businesses to default; or a sudden (1980) or steady (2022) increase in interest rates by central banks to combat inflation, causing - well, causing its own problems!
The Challenge of Volatile Interest Rate Movements (Sigh...)
Within a bank, the unforeseen crisis may have been preceded by an over-reliance on compliance-driven risk practice, where meeting regulatory baselines substitutes for genuine understanding of balance sheet vulnerabilities at the senior exec level. Northern Rock got a clean bill of health in its "ILAA" in, if memory serves me right, June or July 2007; SVB ticked its regulatory boxes satisfactorily in 2022. Such an approach risks creating blind spots, leaving banks more at risk from escalating threats.
Internally, the ability to respond can be further hindered by a delayed realisation of what is happening (hands up those who remember this chap: “As long as the music is playing, you’ve got to get up and dance. We’re still dancing”...?!).
Problems can be exacerbated by an over-reliance on a tick-box approach to bureaucratic processes, without sufficient human judgment or adaptive strategies that are designed by the bank based on its own recognised risk appetite and risk tolerance. In The Moorad Choudhry Anthology, I noted that:
If a working environment is open and honest about mistakes, and operates without a blame culture, then the entire organisation will learn. Sadly, actively seeking feedback is not necessarily a commonly observed trait amongst senior executives in the finance industry. —Preface, xxvi, Anthology, Past, Present and Future Principles of Banking and Finance
The Bank of Scotland Thrived—Until It Didn’t: A 250-Year Paradox
The history of the Bank of Scotland is worth studying by every bank risk practitioner. The bank was founded in 1695. It was a genuine innovator (e.g., in the early 18th century it was the first bank in the world to introduce the Notice Deposit Account. Recognising quite early on that if all its depositors wanted their money out on the same day the bank would be sunk, it offered customers a higher interest rate deposit product provided they accepted that upon request they would have to wait 7 days to withdraw their funds. Excellent! That’s about 215 years before the UK regulator published guidance on “Pillar 2” liquidity risk 🙂. If a bank in the 18th century can recognise funding concentration risk and address it through product diversification, is there any excuse for a bank in the 21st century to fail to do so?!).
For over 250 years, this venerable institution navigated genuine national and global crises—from the Napoleonic Wars to the Boer War to the Great War to the Great Depression and World War II—without any kind of formal regulatory oversight. Its longevity lay in its own robust internal framework that prioritised prudent risk management and long-term stability.
Centuries of Stability, Until...
This self-regulation model allowed the bank to weather external disruptions, earning trust as a cornerstone of Scotland’s economy. However, the post-World War II era marked a shift. By the later 20th century, regulatory frameworks were introduced globally to standardise and safeguard banking practices (quite understandably, in response to contagion risk arising from failures such as Herstatt Bank in 1974). Ironically, it was under the kind of supervision framework that we recognise today (from Basel I onwards) that the Bank of Scotland, now merged with Halifax Bank to become HBOS, came a cropper in 2008.
Despite complying with banking regulation, the bank succumbed to excessive risk-taking (in this case more corporate and commercial real-estate lending than “sub-prime” mortgage lending, but if one exceeds risk tolerance it ceases to matter too much what exact product has caused one’s downfall!), compounded by insufficient understanding and oversight at the Board level. Arguably the bank’s reliance on external frameworks at the expense of its historically rigorous internal governance framework contributed to its demise.
This paradox serves as a cautionary tale: external compliance cannot replace internal discipline. In the years leading up to the 2008 crisis, HBOS leadership exhibited a serious lack of awareness of external market dynamics, whilst neglecting the core principles of risk management and due diligence.
For senior finance professionals, these examples should be a stark reminder that while external frameworks and tools are essential, they are no substitute for the expertise, foresight, and accountability that lie at the heart of sound leadership. As Gertrude Stein said:
“Everybody gets so much information all day long that they lose their common sense.”
Lessons shared
Internal expertise is irreplaceable: A proactive, internally driven governance framework, rooted in self-regulation, is the cornerstone of sustainable banking. Regulations alone are not enough to prevent individual bank failures when deeper issues go unchecked.
Backup systems matter: The banking industrys failure to anticipate the full-scale implications of a global credit crunch highlighted a critical vulnerability—reliance on external systems without robust internal contingency plans. All the failed banks of 2007-09 exhibited, in their own way, an inability to devise a response to a simultaneous collapse in liquidity alongside their own heavy credit default losses. A great lesson in illustrating the danger of assuming that established systems will always function as expected, particularly in times of systemic stress.
Banks may still fail even when following the rules
Banks have always had to observe a delicate balance between growth-driven generation and prudence and regulatory adherence. This is their business, it’s what they are paid to do. There is no alternative approach to this balancing act and no absolving of individual responsibility. Plato might have been writing for today’s bankers when he said:
“No law or ordinance is mightier than understanding.”
The job of the asset-liability committee in a bank has always been to tread this 50-50 fine line between P&L and risk management. The ALCO is discussed in Chapter 10 of Anthology, while the following chapter, (pp. 763-766) provides a recommended ALCO governance framework.
From the Balance Sheet to the Boardroom - and vice-versa!
The traditional ALCO op model is regulatory-compliant; but despite its crucial role, ALCOs are too often sidelined in decision-making, their insights diluted by distance from the Board and other executive functions. This disconnect weakens their ability to shape strategic balance sheet decisions—precisely where their expertise is needed most.
"While all of these committees have an element of responsibility for the bank’s balance sheet, it is the ALCO that is responsible solely for this and nothing else. It alone has the bandwith to discharge this responsibility effectively and to help ensure that the balance sheet shape and structure are long-term viable." —Chapter 11, Bank Asset–Liability Management (ALM) and 'Strategic ALM’, Ibid
But I digress…(yes, spare us another ALCO rant Moorad! 😂)
It is an imperative that all bank boards today be governance bodies possessing sufficient real-time, granular understanding of their institutions’ balance sheet risks, to enable them to make timely informed decisions. This is discussed in Chapter 17 of the Anthology, which examines lessons learned for Board governance frameworks since the 2008 crash.
"Perhaps the real lesson learned from 2008 is the simplest of all: banks are the custodians of other people’s funds and should act in a manner that is consistent with this simple fact. To put these funds at significant risk is simply immoral, and effective governance structures, policies, and procedures play a key role in making sure that we limit the risk associated with funds entrusted to banks." —Chapter 17, Present and Future Principles of Governance and Culture, Ibid
Regulation is influenced by past failures, sometimes more so than emerging risks
Regulatory frameworks are to an extent reactive, understandably influenced by response to past crises. While they aim to prevent recurrence, they can lag behind emerging risks such as technological disruptions, cybersecurity threats, or novel financial products. For example, the 2008 financial crisis led to reforms like Recovery Planning and Centralised Clearing Counterparties , but these regulations did little to foresee or prevent recent collapses like Silicon Valley Bank and Credit Suisse, which stemmed from good ol’ fashioned ALM mismanagement (former) and a consistently poor risk culture over many years (latter).
Regulation is an absolutely necessary requirement for safe markets. However robust internal governance enables banks to address their unique exposures, whether stemming from geopolitical instability in emerging markets or technological disruptions in established economies. If you’re thinking, that’s all well and good, but I’d like to hear from another chap on the subject - how about this quote from Will Rogers:
“You can't legislate intelligence and common sense into people.”
Here is my over-arching Conclusion: the key to bank survivability is maintaining robust internal management standards of one's own, such that the regulatory regime in place doesn’t make the bank any safer - because it's ALREADY SAFE.
Going forward….
It can be challenging to bridge the gap between financial theory and practical, actionable strategies. A attempt to combine academic rigour with practical application is contained in The Moorad Choudhry Anthology, aimed at bankers, auditors, regulators, and anyone aspiring to senior or influential roles within the financial industry. The book follows a pragmatic approach, supported by real-world templates and policy guidelines, presenting senior execs with tools to steer their institutions toward sustainable banking practice. In essence it's a guide for those seeking to understand both the art and science of modern finance:
“The Moorad Choudhry Anthology is an extremely thorough and readable book on asset–liability management and bank risk management. It covers such a wide spectrum of topics affecting a treasury and risk function that this is always the first resource I look into if I have to brush up my knowledge or look up something properly in any particular area. I find this book very authentic and relevant as it covers the latest issues in the market and is written by a practitioner who is very well regarded in the industry.” —Nehal Saghir Head of Asset and Liability Management, Mizuho Capital Markets (UK) Ltd, London
For beginners and veterans alike, this book will act as a reference point, guide and friend.