Skip to content
RiskTemplates · The Daily Brief Saturday, September 19, 2026
Wire SEC's $64 Million Croft & Frost Offering Fraud Case: The Warning Email Compliance Teams Cannot Ignore SEP 14

Feature Operational Risk

New Silicon Valley Bank Review: The Seven Supervisory Failures Risk Teams Should Fix

The new Silicon Valley Bank review says supervisors saw risks but failed to act. Here is how banks can repair escalation and decision rights.

By Rebecca Leung · September 19, 2026 ·
Table of Contents

TL;DR

  • A new Silicon Valley Bank review says supervisors knew—or should have known—about SVB’s vulnerabilities by March 2022 but did not act promptly and decisively.
  • The reported failure chain was specific: unrealized securities losses above capital, 94% uninsured and concentrated deposits, and no operational readiness to use the discount window.
  • The sharpest finding is organizational: a culture of risk aversion and unclear decision rights made inaction feel safer than escalation.
  • The full underlying report was not public when the findings were announced. Use the seven findings as attributed conclusions from Michelle Bowman’s speech, then update the analysis when the report itself is released.

The latest Silicon Valley Bank review does not describe a dashboard problem. It describes an authority problem.

Federal Reserve Vice Chair for Supervision Michelle Bowman announced seven initial findings on September 18. Her summary says supervisory staff knew—or should have known—about SVB’s vulnerabilities well before the March 2023 failure, yet failed to require timely corrective action. It attributes that delay partly to a culture in which doing nothing felt personally safer than acting without certainty, compounded by confusion over who had authority to decide.

Every risk team should sit with that finding. Metrics, examinations, and findings can all work as designed while the institution still fails if nobody has a clear obligation—and permission—to act.

There is an important source limitation. CNBC reported that Starling Advisory Group’s full report had not been released and that Bowman did not say when the public would receive it. Her speech also states that the views were her own and not necessarily those of other Federal Reserve Board members. This article therefore treats the seven points as findings Bowman attributed to the initial independent review, not as independently verified quotations from a public report.

That caveat does not make the control lessons less useful. It makes source discipline part of the lesson.

The new Silicon Valley Bank review: seven findings, one failure chain

Bowman said the review was designed to answer whether Fed supervisors identified vulnerabilities, why decisive action did not follow, and whether supervisory action or inaction contributed to the failure. Her speech lists seven findings.

Reported findingWhat it means operationally
SVB had unrealized securities losses exceeding capital, a 94% uninsured and concentrated deposit base, and no operational readiness to use the discount windowMultiple risk domains were flashing at once, but the signals were not converted into a binding response
Supervisors knew or should have known by March 2022The issue was not simply late discovery
Staff did not promptly require reductions in interest-rate risk or concentration vulnerabilitiesIdentification and remediation were disconnected
Delay was not caused by the 2018 tailoring mandate or a direction from the former Vice Chair for SupervisionThe review places responsibility on supervision and execution rather than that statutory explanation
A long-standing culture of risk aversion contributed to inactionStaff reportedly perceived personal downside from acting without certainty
Decision rights were unclearResponsibility, authority, and accountability were separated
Social media did not trigger or accelerate the run, according to analysis commissioned for the reviewA popular external explanation may have distracted from balance-sheet, funding, and response failures

The vulnerabilities themselves were not subtle. SVB combined interest-rate exposure with highly concentrated, largely uninsured funding and weak operational readiness for contingent liquidity. The Federal Reserve’s April 2023 review had already documented management and supervisory failures. The new review, as Bowman describes it, pushes harder on why known concerns did not become decisive action.

That is the practitioner angle worth carrying into a risk committee: a known issue without a decision deadline is often just a documented risk acceptance nobody formally approved.

Failure point 1: risk identification did not create action

Organizations routinely confuse these two statements:

  • “The risk was identified.”
  • “The risk was controlled.”

They are not close.

A credible escalation record should show a straight line from signal to disposition:

  1. the metric or finding crossed a defined condition;
  2. an accountable role received it within a set time;
  3. that role had authority to choose from specified responses;
  4. the decision and rationale were recorded;
  5. the action had an owner and deadline;
  6. completion evidence was independently challenged;
  7. residual risk was accepted by the correct authority if remediation was incomplete.

If one link is missing, the issue can remain visible for months without becoming manageable.

A practical test for the CRO: select the five highest-rated open liquidity, interest-rate, or concentration issues. For each, ask for the original signal, date identified, first escalation, named decision-maker, decision deadline, action evidence, and current residual-risk approval. If the package contains committee decks but no decision record, the control is not functioning.

This complements the process in Contingency Funding Plan KRIs: Metrics That Should Trigger CFP Activation. A threshold that turns red and produces another meeting is not a response. A threshold that requires Treasury to pre-position collateral, test borrowing access, notify ALCO, and report completion by a deadline is.

Failure point 2: responsibility existed without usable authority

Bowman’s summary describes a systemwide “divorcing of responsibility, authority, and accountability.” That phrase names a common governance defect.

Consider a realistic hypothetical. The Asset-Liability Management team sees market-value losses rising, Risk sees uninsured deposit concentration, and Treasury has not completed a live operational test of a contingent facility. Each team owns a piece. None can require a balance-sheet change, restrict concentration growth, or compel a funding test. The matter goes to a committee where discussion is collective and decision authority is implied.

The committee did not necessarily ignore the risk. The operating model made it easy for everyone to participate without anyone being accountable for the result.

A decision-rights matrix should specify more than “Responsible, Accountable, Consulted, Informed.” For each material risk condition, document:

DecisionRecommendsDecidesExecutesChallengesMaximum decision time
Increase contingent liquidityTreasurerCFO or ALCO under delegated authorityTreasury OperationsIndependent RiskDefined in the CFP by severity tier
Reduce interest-rate exposureALMALCO or delegated executiveTreasuryMarket RiskDefined by limit-breach policy
Restrict concentrated deposit growthBusiness and TreasuryExecutive Risk CommitteeBusiness OperationsCRODefined by concentration tier
Activate contingency funding planTreasurer or CRONamed CFP authorityIncident/CFP teamRisk and Internal Audit after actionImmediate upon specified trigger
Accept delayed remediationIssue ownerAuthority set by residual-risk tierIssue ownerIndependent RiskBefore original due date expires

Do not copy the “maximum decision time” from an example article. Calibrate it to the institution’s actual ability to deteriorate, using internal runoff history, stress results, facility mechanics, and escalation testing. Then tabletop the matrix. A document saying the CFO decides is worthless if the weekend protocol cannot reach the CFO.

Failure point 3: operational readiness was assumed

Bowman said SVB lacked operational readiness to borrow from the discount window when needed. That is different from lacking theoretical borrowing capacity.

A contingency source is not available merely because a policy lists it. Treasury should be able to prove:

  • legal agreements are current;
  • collateral is identified, eligible, valued, and positioned correctly;
  • authorized users and approvers have current credentials;
  • contact details work outside normal business hours;
  • the transaction can be initiated in the required window;
  • accounting and regulatory reporting treatments are documented;
  • a test produced evidence, exceptions, and remediation.

The human wrinkle is that teams resist live or operational tests because they are inconvenient, sensitive, or may reveal a problem. That is exactly why the test is a control. A facility that has never been exercised is an assumption wearing a procedure number.

Treasury should maintain a funding-source readiness register with last-test date, test type, available amount, collateral status, operational lead time, exception owner, and next test date. Risk should challenge stale tests and reconcile the register to the contingency funding plan.

Failure point 4: culture rewarded certainty over speed

“Culture” can become a soft explanation that nobody can remediate. Here, the reported behavior is concrete: staff felt safer taking no action unless certain the action was exactly right.

That can be controlled.

Create an escalation-safe-harbor process for material uncertainty:

  • An employee can raise a concern without first proving a violation or loss.
  • The concern receives a tracking ID and timestamp.
  • A designated executive decides within a risk-based window whether to investigate, mitigate, accept, or close it.
  • Closure for “insufficient evidence” requires a written rationale and independent concurrence for high-severity matters.
  • Risk reports aging, reopened items, and decisions that exceeded the required window.
  • Internal Audit samples request-to-ticket mapping so management cannot improve metrics by keeping concerns out of the system.

The Federal Reserve’s revised Statement of Supervisory Operating Principles is relevant context. Bowman said the Fed now requires examination teams to submit monthly reports identifying concerns where examiners were uncertain whether the standard for action was met or whether action aligned with leadership expectations. For supervised institutions, the comparable internal control is a visible uncertainty queue with a named resolver—not a side conversation that disappears when the meeting ends.

For more on how those principles affect self-identified issues and MRA treatment, see The Fed Changed the Math on Self-Disclosure.

The social-media finding needs careful handling

Bowman said Charles River Associates analyzed whether social media fueled the run and found no evidence that it triggered or accelerated it. She also reported that 96% of social-media chatter appeared after failure was inevitable. Reuters described the review’s broader conclusion as a finding that risk-averse culture hindered oversight.

Do not turn the social-media point into “digital run risk is fake.” The safer conclusion is narrower: according to Bowman’s summary of this review, social media was not the causal explanation for SVB’s failure. Funding concentration, balance-sheet losses, operational readiness, and delayed action remain the core control issues.

Risk teams should preserve both ideas:

  • Do not use a vivid external narrative to excuse internal control failures.
  • Continue modeling rapid outflows and communications effects because digital channels can affect execution speed even when they are not the root cause.

When the underlying Starling report becomes public, review its methodology, definition of “inevitable,” data window, platform coverage, and distinction between triggering and accelerating the run before changing scenario assumptions.

Five checks for Monday morning

1. Pull one material issue end to end

Owner: Chief Risk Officer

Trace signal, escalation, decision, action, evidence, challenge, and closure. Record every handoff where authority becomes ambiguous.

2. Test a contingent funding source operationally

Owner: Treasurer

Use the institution’s approved test method. Verify people, credentials, collateral, cutoffs, accounting, and evidence—not just contractual capacity.

3. Map decision rights for a fast-moving breach

Owner: Corporate Secretary or Enterprise Risk

Choose one interest-rate, liquidity, or concentration trigger. Identify who can decide at 2 p.m. on Tuesday and who can decide at 2 a.m. on Saturday.

4. Audit the uncertainty queue

Owner: Internal Audit

Sample concerns raised through email, committee minutes, hotline channels, and risk meetings. Reconcile them to tracked issues. Investigate gaps where a concern was discussed but never logged.

5. Separate status reporting from decision reporting

Owner: Board Risk Committee chair and CRO

A status report says what changed. A decision report states what approval is required, the deadline, options, recommendation, dissent, and consequence of delay. Require the second format for material breaches.

The control lesson

The new Silicon Valley Bank review is newsworthy because it shifts attention from whether risk was visible to whether anyone could act on it. The reported facts describe a bank with interacting vulnerabilities and a supervisory process that did not convert knowledge into timely intervention.

Do not respond by adding three KRIs to the dashboard. Pick one material issue and prove the institution can move from warning to authorized action before the next committee cycle.

If the weak point is the handoff from finding to owned remediation, the Issues Management Tracker & Template provides a structured place to capture decision owners, deadlines, evidence, and independent closure.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did the new Silicon Valley Bank review find?
According to Federal Reserve Vice Chair for Supervision Michelle Bowman's September 18, 2026 summary, the independent review found seven issues, including known or knowable vulnerabilities by March 2022, delayed supervisory action, a culture of risk aversion, unclear decision rights, and no evidence that social media triggered or accelerated the run. The underlying initial report was not publicly available when CNBC reported on the announcement, so the findings should be attributed to Bowman's summary rather than treated as independently reviewed public text.
What were Silicon Valley Bank's main vulnerabilities?
Bowman said the review identified unrealized securities losses exceeding capital, a deposit base that was 94% uninsured and concentrated in venture-capital-backed technology companies, and a lack of operational readiness to borrow from the discount window. These vulnerabilities interacted: market losses weakened confidence, concentrated uninsured funding increased run risk, and untested contingency funding reduced response capacity.
Did social media cause the Silicon Valley Bank run?
Bowman said Charles River Associates, working at the independent reviewer's request, found no evidence that social media triggered or accelerated the run and found that 96% of social-media chatter appeared after failure was inevitable. Because the underlying report was not yet public, risk teams should cite this as a reported finding from Bowman's speech, not as a standalone universal conclusion about digital bank-run risk.
What should bank risk teams change after the 2026 SVB review?
Banks should define decision rights for material risk escalation, impose time-bound action requirements, test discount-window and other contingent funding access, connect concentration metrics to mandatory responses, and track management commitments through independently validated closure. The key control is not another dashboard; it is a documented path from signal to authorized action.
How is the 2026 independent SVB review different from the Federal Reserve's 2023 review?
The Federal Reserve published its own review in April 2023. The 2026 work was commissioned from Starling Advisory Group and presented as independent of Federal Reserve System staff and principals. Bowman's September 18 speech announced initial findings and said the report was the first in a series, while CNBC reported that the full report had not yet been released.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

◆ Keep reading

Related posts.

Operational Risk

The Basel III Endgame Re-Proposal Slashed Op Risk Capital. Here's What Your Operational Risk Program Still Has to Do.

On March 19, 2026, the Fed, OCC, and FDIC formally rescinded the 2023 Basel III proposal and issued a dramatically different re-proposal that delivers net capital relief after industry feedback identified operational risk as the single largest driver of inflated RWA. Here's what changed, what didn't, and what your op risk program needs to do before 2027 implementation.

Sep 18, 2026

Operational Risk

NACHA Just Approved a $10 Million Same Day ACH Limit. Your Fraud Controls Were Built for $1 Million.

NACHA approved a $10 million per-transaction limit for Same Day ACH in April 2026, effective September 2027. That's a 10x increase from the current $1 million cap. Most financial institution fraud controls, velocity limits, and risk-based monitoring thresholds weren't built for that exposure. Here's what needs to change before the September 2027 effective date.

Sep 13, 2026

Operational Risk

FinCEN Hit UBS With a Record $125 Million 'Willful' BSA Fine — and FINRA Added $20 Million More. What the Double-Barrel Enforcement Action Means for Your AML Program.

FinCEN's $125 million penalty against UBS Financial Services — the largest BSA fine ever imposed on a broker-dealer — combined with FINRA's simultaneous $20 million fine creates a $145 million enforcement landmark. Both actions trace back to the same root cause: UBS knew its transaction monitoring had gaps, promised to fix them after a 2018 settlement, and didn't. Here's what 'reasonably designed' AML monitoring actually requires.

Sep 8, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.