Skip to content
RiskTemplates · The Daily Brief Friday, August 21, 2026
Wire SEC's Tricolor Fraud Case: The Double-Pledging Controls Lenders Missed AUG 20

Feature Compliance Strategy

Conduct Risk KRIs: Indicators, Thresholds, and Incentive Blind Spots

Build conduct risk key risk indicators that expose sales pressure, weak overrides, complaints, cancellations, and customer harm before they become findings.

By Rebecca Leung · August 21, 2026 ·
Table of Contents

TL;DR

  • Conduct risk key risk indicators should connect commercial pressure, employee behavior, and customer outcomes. A complaint count by itself is too late and too easy to explain away.
  • Use rates and segmented peer comparisons, not raw totals. Review by product, channel, team, and manager so enterprise averages do not hide a pocket of harm.
  • Treat the thresholds below as starter logic. Calibrate them against clean internal history, then test whether prior complaints, refunds, cancellations, and investigations would have triggered an alert.

A conduct dashboard can stay green while the sales floor is producing the next enforcement order. That happens when the dashboard counts completed training and total complaints but never measures pressure, unusual overrides, early cancellations, or whether one manager’s team behaves differently from everyone else.

Good conduct risk key risk indicators answer a harder question: Where is the operating model creating pressure to produce an outcome that is good for the employee and bad for the customer? The answer rarely lives in one system. It appears when compensation data, sales activity, quality reviews, complaints, refunds, employee signals, and customer outcomes are joined at the right level.

Wells Fargo remains the blunt example. In its September 8, 2016 action, the OCC assessed a $35 million civil money penalty, ordered restitution, and cited the bank’s failure to implement an effective enterprise risk management program to detect and prevent unsafe or unsound sales practices. The practices included unauthorized deposit or credit-card accounts and transfers from authorized accounts to unauthorized accounts. The order required an enterprise-wide sales-practices risk management and oversight program.

That is the job of this KRI set: make pressure and abnormal behavior visible while someone can still investigate it.

What should conduct risk key risk indicators cover?

Build the set across three layers. If one layer is missing, the dashboard tells only part of the story.

LayerQuestionExample indicatorsPrimary owner
PressureWhat is pushing employees or partners toward risky behavior?Variable-pay concentration, steep payout cliffs, target-attainment clustering, manager outlier rates, campaign intensityBusiness head with HR/Compensation
BehaviorWhat are people doing differently?Overrides, manual adjustments, rapid transactions, incomplete disclosures, quality-review failures, unusual after-hours activityOperations / Sales Quality
OutcomeWhat happened to the customer?Early cancellations, refunds, fee reversals, repeat contacts, substantiated complaints, remediation, vulnerable-customer harmCompliance / Customer Operations

The design principle is supported by the banking agencies’ June 21, 2010 Final Guidance on Incentive Compensation. The Federal Reserve, OCC, OTS, and FDIC said incentive arrangements should take risk into account and remain consistent with safe and sound practices. Their horizontal review found, among other deficiencies, that many firms lacked adequate mechanisms to evaluate whether established practices were actually successful in balancing risk.

A compensation policy can be approved and still fail in operation. The KRI has to show whether the arrangement changes behavior.

A practical conduct-risk KRI library

Do not activate every indicator at once. Select a small linked set for the specific conduct pathway you are monitoring. A deposit-sales program may need account-opening, funding-transfer, dormancy, and complaint indicators. A lending channel may need add-on attachment, decline overrides, fee reversals, early payoff, and affordability-review quality.

The thresholds below are illustrative starting points, not external benchmarks. Replace them after reviewing at least three to six months of clean internal history.

IndicatorCalculationWhy it mattersIllustrative alert logicEvidence to retain
Variable-pay concentrationAt-risk incentive pay ÷ total cash compensationA high share of pay tied to volume can amplify pressureAmber when a role or team rises materially above its approved compensation design; red when coupled with a customer-outcome breachApproved plan, payroll extract, role mapping, change approvals
Target-attainment clusteringEmployees finishing within a narrow band immediately above a payout threshold ÷ eligible employeesA pile-up just over a payout cliff can indicate timing, allocation, or booking manipulationReview when clustering exceeds the team’s rolling baseline by two standard deviations; require a minimum population before using statistical logicTransaction-level production, payout table, manager adjustments
Manager outlier rateTeam’s risk-adjusted sales or approval rate compared with like-for-like peer teamsConduct problems often cluster under one managerAmber for two consecutive periods outside the peer range; red if paired with quality failures or complaintsPeer-group rules, product/channel mix, manager hierarchy
Manual override rateManual overrides ÷ eligible decisionsOverrides may be legitimate, but concentration can reveal pressure or weak challengeAmber above the product’s historical 90th percentile; red for missing reason codes or prohibited override typesDecision log, original result, override reason, approver
Early cancellation rateProducts cancelled within the defined cooling-off or early-life window ÷ products openedEarly exits can indicate misunderstanding, unsuitable sales, or unwanted productsCompare by employee and channel; investigate a statistically stable outlier and any repeat pattern linked to one managerOpen date, cancel date, reason, customer contact record
Fee reversal/refund rateConduct-related reversals and refunds ÷ active accounts or transactionsReversals can be an early proxy for customer friction or inappropriate chargingAlert on material movement from baseline or concentration in one product, team, or reason codeGeneral-ledger record, case ID, root-cause code, approver
Quality-review critical-fail rateReviews with a customer-harm or disclosure failure ÷ completed reviewsAverages hide defects that should stop the processRed for any confirmed prohibited practice; rate threshold for other critical failures based on back-testingSampling frame, recording/document, test script, reviewer conclusion
Repeat-contact rateCustomers contacting the firm again for the same issue within a defined period ÷ resolved contactsA “closed” first contact may not mean the problem was fixedCompare by reason, product, and resolution team; alert on sustained movement beyond baselineContact IDs, reason taxonomy, resolution, linked complaint
Substantiated complaint rateSubstantiated conduct complaints ÷ relevant accounts, sales, or transactionsCounts punish large units and protect small risky ones; rates create comparabilityZero-tolerance for specified severe themes; trend and peer thresholds for other themesComplaint narrative, taxonomy, investigation, disposition, remediation
Employee speak-up signalRelevant ethics reports, grievances, or exit themes per 100 employeesStaff may see pressure before customers complainInvestigate corroborated themes and concentration by manager; never treat a low report count as proof of low riskRestricted case metadata, theme, location, substantiation status

The point is linkage. An override spike with no customer effect may reflect a process change. Early cancellations without override movement may point to disclosures or channel quality. Both moving under the same manager deserves immediate review.

For broader indicator design mechanics, use the KRI examples and threshold guide before adding the conduct-specific joins above.

How do you set thresholds without inventing a benchmark?

A threshold should identify a decision point, not decorate a dashboard.

1. Clean the denominator

Confirm what belongs in the eligible population. If the override denominator excludes vendor-originated decisions while the numerator includes only employee overrides, comparisons between channels will be nonsense. Reconcile a sample of source transactions to the KRI extract and from the extract back to source.

2. Segment before calculating

Split by product, channel, tenure band, geography, and manager where those factors change expected behavior. Compare employees handling similar work. A mortgage team and a deposit contact center should not share one cancellation baseline.

3. Establish internal history

Use three to six months as a workable starting window only if the process and data definitions were stable. Longer history is useful when volumes are seasonal. Flag policy changes, campaigns, migrations, acquisitions, and taxonomy changes so they do not quietly reset the baseline.

4. Back-test known events

Take prior substantiated complaints, refunds, quality failures, employee reports, and investigations. Ask: Would this threshold have fired before or during the event? If no indicator moves, either the KRI is poorly chosen or the source data is too aggregated.

5. Define the action with the color

A threshold without a response owner is just formatting.

StatusRequired responseDecision ownerProof it happened
GreenRoutine monitoring and data-quality checksConduct Risk AnalystMonthly reconciliation and dashboard sign-off
AmberSegmented analysis, targeted file review, manager challengeCompliance Monitoring LeadAnalysis pack, sample results, documented disposition
RedPreserve evidence, open investigation, assess customer harm and compensation implicationsCCO or delegated Conduct Risk OfficerCase ID, legal/compliance assessment, remediation decision

This is where a general KRI policy needs a conduct playbook. The KRI library versus build-from-scratch guide explains the trade-off between adopting a structured catalog and maintaining bespoke definitions.

The blind spots that make a conduct dashboard look healthier than reality

Enterprise averages

A company-wide complaint rate can improve while one partner, branch, or manager deteriorates. Require the dashboard to surface the worst stable segments, not just the blended result.

Raw counts

Ten complaints may be severe for 200 transactions and noise for two million. Use an exposure denominator and preserve the count. The rate supports comparison; the count shows workload and customer impact.

Self-reported reason codes

If employees choose the cancellation or override reason that drives the KRI, expect the taxonomy to drift toward harmless categories. Compare notes, call recordings, transaction behavior, and downstream complaints against the selected reason.

Threshold hovering

Teams learn dashboard rules. Review repeated values just below amber, end-of-period reversals, delayed complaint classification, manual exclusions, and changes in denominator logic. Map dashboard rows back to case and transaction IDs so Internal Audit can reproduce the number.

Complaint counts without operations data

The CFPB’s public Consumer Complaint Database is useful for themes, but an internal program needs more than submitted complaints. Join complaints to repeat contacts, refunds, cancellations, sales, employees, managers, products, and channels. The complaint-management program guide covers the case-level foundation needed before complaints can support a reliable KRI.

Training as the main measure

Training completion proves attendance, not behavior. Keep it as a control-performance measure. Do not let 99% completion offset rising override, cancellation, or substantiated-complaint rates.

What should happen after a conduct KRI breaches?

Use a short, evidence-driven sequence:

  1. Validate the number. Reconcile source data, confirm the denominator, inspect exclusions, and verify that a system or taxonomy change did not create the movement.
  2. Localize the pattern. Cut the result by manager, employee, product, channel, tenure, campaign, and customer cohort.
  3. Review linked signals. Pull compensation, quality, override, cancellation, complaint, refund, and speak-up data for the same population and period.
  4. Test cases. Select targeted records from the outlier population plus a comparison sample. Retain recordings, disclosures, decisions, approvals, and customer communications.
  5. Assess harm. Determine whether customers paid fees, received unwanted products, lost access to funds, received inaccurate information, or were otherwise disadvantaged.
  6. Decide remediation. Address customer redress, employee or manager action, compensation adjustment, process changes, enhanced monitoring, and control validation.
  7. Track recurrence. Keep the KRI and case linked until the corrective action is independently validated.

The Department of Justice’s 2020 Wells Fargo resolution required the bank to pay $3 billion to resolve criminal and civil investigations into sales practices. That outcome did not begin with a dashboard color. It grew from an operating model where pressure, behavior, and harm were not interrupted effectively.

So what?

This week, pick one high-pressure customer journey and build a six-column trace: pressure signal → employee behavior → customer outcome → source system → owner → breach action. Start with one manager-level view. Reconcile ten records back to source. Then back-test the proposed thresholds against known complaints and refunds.

If the team cannot trace a red metric to the affected transactions and the person who must act, the KRI is not ready for committee reporting.

Need a structured starting catalog with owners, data sources, thresholds, and escalation fields? The KRI Library (132 Key Risk Indicators) gives you the operating structure; calibrate every threshold to your own history before use.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are conduct risk key risk indicators?
Conduct risk key risk indicators are measures that warn when employee, manager, channel, or product behavior may produce unfair customer outcomes. Useful indicators connect pressure signals such as incentive concentration and overrides with outcome signals such as early cancellations, substantiated complaints, refunds, and remediation.
Which conduct risk KRI should a financial institution implement first?
Start with a paired view: one pressure indicator, such as compensation concentration or target attainment clustering, and one customer-outcome indicator, such as early cancellation or complaint rates. Choose measures supported by reliable source data and segment them by team, manager, product, and channel.
How should conduct risk KRI thresholds be set?
Use at least three to six months of clean internal history, compare like-for-like peer groups, and back-test proposed thresholds against known complaints, refunds, and investigations. The example thresholds in this article are starter logic, not industry benchmarks.
Are customer complaints a leading or lagging conduct indicator?
Complaints are usually lagging because the customer has already experienced a problem. Complaint themes can become earlier warning signals when combined with first-contact resolution, repeat-contact, cancellation, override, and incentive data.
How can a compliance team detect KRI gaming?
Reconcile source transactions to the KRI population, review exclusions and manual adjustments, track activity just below thresholds, compare linked measures, and require documented approval for logic changes. A clean dashboard is not persuasive if the underlying population is incomplete.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

KRI Library (132 Key Risk Indicators)

132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.