Feature Compliance Strategy
Conduct Risk KRIs: Indicators, Thresholds, and Incentive Blind Spots
Build conduct risk key risk indicators that expose sales pressure, weak overrides, complaints, cancellations, and customer harm before they become findings.
Table of Contents
TL;DR
- Conduct risk key risk indicators should connect commercial pressure, employee behavior, and customer outcomes. A complaint count by itself is too late and too easy to explain away.
- Use rates and segmented peer comparisons, not raw totals. Review by product, channel, team, and manager so enterprise averages do not hide a pocket of harm.
- Treat the thresholds below as starter logic. Calibrate them against clean internal history, then test whether prior complaints, refunds, cancellations, and investigations would have triggered an alert.
A conduct dashboard can stay green while the sales floor is producing the next enforcement order. That happens when the dashboard counts completed training and total complaints but never measures pressure, unusual overrides, early cancellations, or whether one manager’s team behaves differently from everyone else.
Good conduct risk key risk indicators answer a harder question: Where is the operating model creating pressure to produce an outcome that is good for the employee and bad for the customer? The answer rarely lives in one system. It appears when compensation data, sales activity, quality reviews, complaints, refunds, employee signals, and customer outcomes are joined at the right level.
Wells Fargo remains the blunt example. In its September 8, 2016 action, the OCC assessed a $35 million civil money penalty, ordered restitution, and cited the bank’s failure to implement an effective enterprise risk management program to detect and prevent unsafe or unsound sales practices. The practices included unauthorized deposit or credit-card accounts and transfers from authorized accounts to unauthorized accounts. The order required an enterprise-wide sales-practices risk management and oversight program.
That is the job of this KRI set: make pressure and abnormal behavior visible while someone can still investigate it.
What should conduct risk key risk indicators cover?
Build the set across three layers. If one layer is missing, the dashboard tells only part of the story.
| Layer | Question | Example indicators | Primary owner |
|---|---|---|---|
| Pressure | What is pushing employees or partners toward risky behavior? | Variable-pay concentration, steep payout cliffs, target-attainment clustering, manager outlier rates, campaign intensity | Business head with HR/Compensation |
| Behavior | What are people doing differently? | Overrides, manual adjustments, rapid transactions, incomplete disclosures, quality-review failures, unusual after-hours activity | Operations / Sales Quality |
| Outcome | What happened to the customer? | Early cancellations, refunds, fee reversals, repeat contacts, substantiated complaints, remediation, vulnerable-customer harm | Compliance / Customer Operations |
The design principle is supported by the banking agencies’ June 21, 2010 Final Guidance on Incentive Compensation. The Federal Reserve, OCC, OTS, and FDIC said incentive arrangements should take risk into account and remain consistent with safe and sound practices. Their horizontal review found, among other deficiencies, that many firms lacked adequate mechanisms to evaluate whether established practices were actually successful in balancing risk.
A compensation policy can be approved and still fail in operation. The KRI has to show whether the arrangement changes behavior.
A practical conduct-risk KRI library
Do not activate every indicator at once. Select a small linked set for the specific conduct pathway you are monitoring. A deposit-sales program may need account-opening, funding-transfer, dormancy, and complaint indicators. A lending channel may need add-on attachment, decline overrides, fee reversals, early payoff, and affordability-review quality.
The thresholds below are illustrative starting points, not external benchmarks. Replace them after reviewing at least three to six months of clean internal history.
| Indicator | Calculation | Why it matters | Illustrative alert logic | Evidence to retain |
|---|---|---|---|---|
| Variable-pay concentration | At-risk incentive pay ÷ total cash compensation | A high share of pay tied to volume can amplify pressure | Amber when a role or team rises materially above its approved compensation design; red when coupled with a customer-outcome breach | Approved plan, payroll extract, role mapping, change approvals |
| Target-attainment clustering | Employees finishing within a narrow band immediately above a payout threshold ÷ eligible employees | A pile-up just over a payout cliff can indicate timing, allocation, or booking manipulation | Review when clustering exceeds the team’s rolling baseline by two standard deviations; require a minimum population before using statistical logic | Transaction-level production, payout table, manager adjustments |
| Manager outlier rate | Team’s risk-adjusted sales or approval rate compared with like-for-like peer teams | Conduct problems often cluster under one manager | Amber for two consecutive periods outside the peer range; red if paired with quality failures or complaints | Peer-group rules, product/channel mix, manager hierarchy |
| Manual override rate | Manual overrides ÷ eligible decisions | Overrides may be legitimate, but concentration can reveal pressure or weak challenge | Amber above the product’s historical 90th percentile; red for missing reason codes or prohibited override types | Decision log, original result, override reason, approver |
| Early cancellation rate | Products cancelled within the defined cooling-off or early-life window ÷ products opened | Early exits can indicate misunderstanding, unsuitable sales, or unwanted products | Compare by employee and channel; investigate a statistically stable outlier and any repeat pattern linked to one manager | Open date, cancel date, reason, customer contact record |
| Fee reversal/refund rate | Conduct-related reversals and refunds ÷ active accounts or transactions | Reversals can be an early proxy for customer friction or inappropriate charging | Alert on material movement from baseline or concentration in one product, team, or reason code | General-ledger record, case ID, root-cause code, approver |
| Quality-review critical-fail rate | Reviews with a customer-harm or disclosure failure ÷ completed reviews | Averages hide defects that should stop the process | Red for any confirmed prohibited practice; rate threshold for other critical failures based on back-testing | Sampling frame, recording/document, test script, reviewer conclusion |
| Repeat-contact rate | Customers contacting the firm again for the same issue within a defined period ÷ resolved contacts | A “closed” first contact may not mean the problem was fixed | Compare by reason, product, and resolution team; alert on sustained movement beyond baseline | Contact IDs, reason taxonomy, resolution, linked complaint |
| Substantiated complaint rate | Substantiated conduct complaints ÷ relevant accounts, sales, or transactions | Counts punish large units and protect small risky ones; rates create comparability | Zero-tolerance for specified severe themes; trend and peer thresholds for other themes | Complaint narrative, taxonomy, investigation, disposition, remediation |
| Employee speak-up signal | Relevant ethics reports, grievances, or exit themes per 100 employees | Staff may see pressure before customers complain | Investigate corroborated themes and concentration by manager; never treat a low report count as proof of low risk | Restricted case metadata, theme, location, substantiation status |
The point is linkage. An override spike with no customer effect may reflect a process change. Early cancellations without override movement may point to disclosures or channel quality. Both moving under the same manager deserves immediate review.
For broader indicator design mechanics, use the KRI examples and threshold guide before adding the conduct-specific joins above.
How do you set thresholds without inventing a benchmark?
A threshold should identify a decision point, not decorate a dashboard.
1. Clean the denominator
Confirm what belongs in the eligible population. If the override denominator excludes vendor-originated decisions while the numerator includes only employee overrides, comparisons between channels will be nonsense. Reconcile a sample of source transactions to the KRI extract and from the extract back to source.
2. Segment before calculating
Split by product, channel, tenure band, geography, and manager where those factors change expected behavior. Compare employees handling similar work. A mortgage team and a deposit contact center should not share one cancellation baseline.
3. Establish internal history
Use three to six months as a workable starting window only if the process and data definitions were stable. Longer history is useful when volumes are seasonal. Flag policy changes, campaigns, migrations, acquisitions, and taxonomy changes so they do not quietly reset the baseline.
4. Back-test known events
Take prior substantiated complaints, refunds, quality failures, employee reports, and investigations. Ask: Would this threshold have fired before or during the event? If no indicator moves, either the KRI is poorly chosen or the source data is too aggregated.
5. Define the action with the color
A threshold without a response owner is just formatting.
| Status | Required response | Decision owner | Proof it happened |
|---|---|---|---|
| Green | Routine monitoring and data-quality checks | Conduct Risk Analyst | Monthly reconciliation and dashboard sign-off |
| Amber | Segmented analysis, targeted file review, manager challenge | Compliance Monitoring Lead | Analysis pack, sample results, documented disposition |
| Red | Preserve evidence, open investigation, assess customer harm and compensation implications | CCO or delegated Conduct Risk Officer | Case ID, legal/compliance assessment, remediation decision |
This is where a general KRI policy needs a conduct playbook. The KRI library versus build-from-scratch guide explains the trade-off between adopting a structured catalog and maintaining bespoke definitions.
The blind spots that make a conduct dashboard look healthier than reality
Enterprise averages
A company-wide complaint rate can improve while one partner, branch, or manager deteriorates. Require the dashboard to surface the worst stable segments, not just the blended result.
Raw counts
Ten complaints may be severe for 200 transactions and noise for two million. Use an exposure denominator and preserve the count. The rate supports comparison; the count shows workload and customer impact.
Self-reported reason codes
If employees choose the cancellation or override reason that drives the KRI, expect the taxonomy to drift toward harmless categories. Compare notes, call recordings, transaction behavior, and downstream complaints against the selected reason.
Threshold hovering
Teams learn dashboard rules. Review repeated values just below amber, end-of-period reversals, delayed complaint classification, manual exclusions, and changes in denominator logic. Map dashboard rows back to case and transaction IDs so Internal Audit can reproduce the number.
Complaint counts without operations data
The CFPB’s public Consumer Complaint Database is useful for themes, but an internal program needs more than submitted complaints. Join complaints to repeat contacts, refunds, cancellations, sales, employees, managers, products, and channels. The complaint-management program guide covers the case-level foundation needed before complaints can support a reliable KRI.
Training as the main measure
Training completion proves attendance, not behavior. Keep it as a control-performance measure. Do not let 99% completion offset rising override, cancellation, or substantiated-complaint rates.
What should happen after a conduct KRI breaches?
Use a short, evidence-driven sequence:
- Validate the number. Reconcile source data, confirm the denominator, inspect exclusions, and verify that a system or taxonomy change did not create the movement.
- Localize the pattern. Cut the result by manager, employee, product, channel, tenure, campaign, and customer cohort.
- Review linked signals. Pull compensation, quality, override, cancellation, complaint, refund, and speak-up data for the same population and period.
- Test cases. Select targeted records from the outlier population plus a comparison sample. Retain recordings, disclosures, decisions, approvals, and customer communications.
- Assess harm. Determine whether customers paid fees, received unwanted products, lost access to funds, received inaccurate information, or were otherwise disadvantaged.
- Decide remediation. Address customer redress, employee or manager action, compensation adjustment, process changes, enhanced monitoring, and control validation.
- Track recurrence. Keep the KRI and case linked until the corrective action is independently validated.
The Department of Justice’s 2020 Wells Fargo resolution required the bank to pay $3 billion to resolve criminal and civil investigations into sales practices. That outcome did not begin with a dashboard color. It grew from an operating model where pressure, behavior, and harm were not interrupted effectively.
So what?
This week, pick one high-pressure customer journey and build a six-column trace: pressure signal → employee behavior → customer outcome → source system → owner → breach action. Start with one manager-level view. Reconcile ten records back to source. Then back-test the proposed thresholds against known complaints and refunds.
If the team cannot trace a red metric to the affected transactions and the person who must act, the KRI is not ready for committee reporting.
Need a structured starting catalog with owners, data sources, thresholds, and escalation fields? The KRI Library (132 Key Risk Indicators) gives you the operating structure; calibrate every threshold to your own history before use.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are conduct risk key risk indicators?
Which conduct risk KRI should a financial institution implement first?
How should conduct risk KRI thresholds be set?
Are customer complaints a leading or lagging conduct indicator?
How can a compliance team detect KRI gaming?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Compliance Strategy
Five Statutes Generated 75% of All FDIC Compliance Violations in 2025. Here's What They Are.
The FDIC's 2026 Consumer Compliance Supervisory Highlights identified 1,155 violations in 2025 exams. Five statutes — TILA, EFTA, the Flood Act, TISA, and HMDA — drove three-quarters of them. Here is what examiners actually cited and what your compliance program needs to test.
Aug 18, 2026
Compliance Strategy
CFPB and CFTC Self-Reporting Policies: A 2026 Decision Guide
Compare the CFPB and CFTC self-reporting policies, penalty-credit rules, and evidence needed for a defensible disclosure decision.
Aug 17, 2026
Compliance Strategy
FTC Debanking Warning Letters: What PayPal and Stripe Were—and Were Not—Told
The FTC Chair sent warning letters to PayPal, Stripe, Visa, and Mastercard. They flag potential Section 5 risk but do not adjudicate a violation.
Aug 12, 2026