Feature Operational Risk
New Silicon Valley Bank Review: The Seven Supervisory Failures Risk Teams Should Fix
The new Silicon Valley Bank review says supervisors saw risks but failed to act. Here is how banks can repair escalation and decision rights.
Table of Contents
TL;DR
- A new Silicon Valley Bank review says supervisors knew—or should have known—about SVB’s vulnerabilities by March 2022 but did not act promptly and decisively.
- The reported failure chain was specific: unrealized securities losses above capital, 94% uninsured and concentrated deposits, and no operational readiness to use the discount window.
- The sharpest finding is organizational: a culture of risk aversion and unclear decision rights made inaction feel safer than escalation.
- The full underlying report was not public when the findings were announced. Use the seven findings as attributed conclusions from Michelle Bowman’s speech, then update the analysis when the report itself is released.
The latest Silicon Valley Bank review does not describe a dashboard problem. It describes an authority problem.
Federal Reserve Vice Chair for Supervision Michelle Bowman announced seven initial findings on September 18. Her summary says supervisory staff knew—or should have known—about SVB’s vulnerabilities well before the March 2023 failure, yet failed to require timely corrective action. It attributes that delay partly to a culture in which doing nothing felt personally safer than acting without certainty, compounded by confusion over who had authority to decide.
Every risk team should sit with that finding. Metrics, examinations, and findings can all work as designed while the institution still fails if nobody has a clear obligation—and permission—to act.
There is an important source limitation. CNBC reported that Starling Advisory Group’s full report had not been released and that Bowman did not say when the public would receive it. Her speech also states that the views were her own and not necessarily those of other Federal Reserve Board members. This article therefore treats the seven points as findings Bowman attributed to the initial independent review, not as independently verified quotations from a public report.
That caveat does not make the control lessons less useful. It makes source discipline part of the lesson.
The new Silicon Valley Bank review: seven findings, one failure chain
Bowman said the review was designed to answer whether Fed supervisors identified vulnerabilities, why decisive action did not follow, and whether supervisory action or inaction contributed to the failure. Her speech lists seven findings.
| Reported finding | What it means operationally |
|---|---|
| SVB had unrealized securities losses exceeding capital, a 94% uninsured and concentrated deposit base, and no operational readiness to use the discount window | Multiple risk domains were flashing at once, but the signals were not converted into a binding response |
| Supervisors knew or should have known by March 2022 | The issue was not simply late discovery |
| Staff did not promptly require reductions in interest-rate risk or concentration vulnerabilities | Identification and remediation were disconnected |
| Delay was not caused by the 2018 tailoring mandate or a direction from the former Vice Chair for Supervision | The review places responsibility on supervision and execution rather than that statutory explanation |
| A long-standing culture of risk aversion contributed to inaction | Staff reportedly perceived personal downside from acting without certainty |
| Decision rights were unclear | Responsibility, authority, and accountability were separated |
| Social media did not trigger or accelerate the run, according to analysis commissioned for the review | A popular external explanation may have distracted from balance-sheet, funding, and response failures |
The vulnerabilities themselves were not subtle. SVB combined interest-rate exposure with highly concentrated, largely uninsured funding and weak operational readiness for contingent liquidity. The Federal Reserve’s April 2023 review had already documented management and supervisory failures. The new review, as Bowman describes it, pushes harder on why known concerns did not become decisive action.
That is the practitioner angle worth carrying into a risk committee: a known issue without a decision deadline is often just a documented risk acceptance nobody formally approved.
Failure point 1: risk identification did not create action
Organizations routinely confuse these two statements:
- “The risk was identified.”
- “The risk was controlled.”
They are not close.
A credible escalation record should show a straight line from signal to disposition:
- the metric or finding crossed a defined condition;
- an accountable role received it within a set time;
- that role had authority to choose from specified responses;
- the decision and rationale were recorded;
- the action had an owner and deadline;
- completion evidence was independently challenged;
- residual risk was accepted by the correct authority if remediation was incomplete.
If one link is missing, the issue can remain visible for months without becoming manageable.
A practical test for the CRO: select the five highest-rated open liquidity, interest-rate, or concentration issues. For each, ask for the original signal, date identified, first escalation, named decision-maker, decision deadline, action evidence, and current residual-risk approval. If the package contains committee decks but no decision record, the control is not functioning.
This complements the process in Contingency Funding Plan KRIs: Metrics That Should Trigger CFP Activation. A threshold that turns red and produces another meeting is not a response. A threshold that requires Treasury to pre-position collateral, test borrowing access, notify ALCO, and report completion by a deadline is.
Failure point 2: responsibility existed without usable authority
Bowman’s summary describes a systemwide “divorcing of responsibility, authority, and accountability.” That phrase names a common governance defect.
Consider a realistic hypothetical. The Asset-Liability Management team sees market-value losses rising, Risk sees uninsured deposit concentration, and Treasury has not completed a live operational test of a contingent facility. Each team owns a piece. None can require a balance-sheet change, restrict concentration growth, or compel a funding test. The matter goes to a committee where discussion is collective and decision authority is implied.
The committee did not necessarily ignore the risk. The operating model made it easy for everyone to participate without anyone being accountable for the result.
A decision-rights matrix should specify more than “Responsible, Accountable, Consulted, Informed.” For each material risk condition, document:
| Decision | Recommends | Decides | Executes | Challenges | Maximum decision time |
|---|---|---|---|---|---|
| Increase contingent liquidity | Treasurer | CFO or ALCO under delegated authority | Treasury Operations | Independent Risk | Defined in the CFP by severity tier |
| Reduce interest-rate exposure | ALM | ALCO or delegated executive | Treasury | Market Risk | Defined by limit-breach policy |
| Restrict concentrated deposit growth | Business and Treasury | Executive Risk Committee | Business Operations | CRO | Defined by concentration tier |
| Activate contingency funding plan | Treasurer or CRO | Named CFP authority | Incident/CFP team | Risk and Internal Audit after action | Immediate upon specified trigger |
| Accept delayed remediation | Issue owner | Authority set by residual-risk tier | Issue owner | Independent Risk | Before original due date expires |
Do not copy the “maximum decision time” from an example article. Calibrate it to the institution’s actual ability to deteriorate, using internal runoff history, stress results, facility mechanics, and escalation testing. Then tabletop the matrix. A document saying the CFO decides is worthless if the weekend protocol cannot reach the CFO.
Failure point 3: operational readiness was assumed
Bowman said SVB lacked operational readiness to borrow from the discount window when needed. That is different from lacking theoretical borrowing capacity.
A contingency source is not available merely because a policy lists it. Treasury should be able to prove:
- legal agreements are current;
- collateral is identified, eligible, valued, and positioned correctly;
- authorized users and approvers have current credentials;
- contact details work outside normal business hours;
- the transaction can be initiated in the required window;
- accounting and regulatory reporting treatments are documented;
- a test produced evidence, exceptions, and remediation.
The human wrinkle is that teams resist live or operational tests because they are inconvenient, sensitive, or may reveal a problem. That is exactly why the test is a control. A facility that has never been exercised is an assumption wearing a procedure number.
Treasury should maintain a funding-source readiness register with last-test date, test type, available amount, collateral status, operational lead time, exception owner, and next test date. Risk should challenge stale tests and reconcile the register to the contingency funding plan.
Failure point 4: culture rewarded certainty over speed
“Culture” can become a soft explanation that nobody can remediate. Here, the reported behavior is concrete: staff felt safer taking no action unless certain the action was exactly right.
That can be controlled.
Create an escalation-safe-harbor process for material uncertainty:
- An employee can raise a concern without first proving a violation or loss.
- The concern receives a tracking ID and timestamp.
- A designated executive decides within a risk-based window whether to investigate, mitigate, accept, or close it.
- Closure for “insufficient evidence” requires a written rationale and independent concurrence for high-severity matters.
- Risk reports aging, reopened items, and decisions that exceeded the required window.
- Internal Audit samples request-to-ticket mapping so management cannot improve metrics by keeping concerns out of the system.
The Federal Reserve’s revised Statement of Supervisory Operating Principles is relevant context. Bowman said the Fed now requires examination teams to submit monthly reports identifying concerns where examiners were uncertain whether the standard for action was met or whether action aligned with leadership expectations. For supervised institutions, the comparable internal control is a visible uncertainty queue with a named resolver—not a side conversation that disappears when the meeting ends.
For more on how those principles affect self-identified issues and MRA treatment, see The Fed Changed the Math on Self-Disclosure.
The social-media finding needs careful handling
Bowman said Charles River Associates analyzed whether social media fueled the run and found no evidence that it triggered or accelerated it. She also reported that 96% of social-media chatter appeared after failure was inevitable. Reuters described the review’s broader conclusion as a finding that risk-averse culture hindered oversight.
Do not turn the social-media point into “digital run risk is fake.” The safer conclusion is narrower: according to Bowman’s summary of this review, social media was not the causal explanation for SVB’s failure. Funding concentration, balance-sheet losses, operational readiness, and delayed action remain the core control issues.
Risk teams should preserve both ideas:
- Do not use a vivid external narrative to excuse internal control failures.
- Continue modeling rapid outflows and communications effects because digital channels can affect execution speed even when they are not the root cause.
When the underlying Starling report becomes public, review its methodology, definition of “inevitable,” data window, platform coverage, and distinction between triggering and accelerating the run before changing scenario assumptions.
Five checks for Monday morning
1. Pull one material issue end to end
Owner: Chief Risk Officer
Trace signal, escalation, decision, action, evidence, challenge, and closure. Record every handoff where authority becomes ambiguous.
2. Test a contingent funding source operationally
Owner: Treasurer
Use the institution’s approved test method. Verify people, credentials, collateral, cutoffs, accounting, and evidence—not just contractual capacity.
3. Map decision rights for a fast-moving breach
Owner: Corporate Secretary or Enterprise Risk
Choose one interest-rate, liquidity, or concentration trigger. Identify who can decide at 2 p.m. on Tuesday and who can decide at 2 a.m. on Saturday.
4. Audit the uncertainty queue
Owner: Internal Audit
Sample concerns raised through email, committee minutes, hotline channels, and risk meetings. Reconcile them to tracked issues. Investigate gaps where a concern was discussed but never logged.
5. Separate status reporting from decision reporting
Owner: Board Risk Committee chair and CRO
A status report says what changed. A decision report states what approval is required, the deadline, options, recommendation, dissent, and consequence of delay. Require the second format for material breaches.
The control lesson
The new Silicon Valley Bank review is newsworthy because it shifts attention from whether risk was visible to whether anyone could act on it. The reported facts describe a bank with interacting vulnerabilities and a supervisory process that did not convert knowledge into timely intervention.
Do not respond by adding three KRIs to the dashboard. Pick one material issue and prove the institution can move from warning to authorized action before the next committee cycle.
If the weak point is the handoff from finding to owned remediation, the Issues Management Tracker & Template provides a structured place to capture decision owners, deadlines, evidence, and independent closure.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What did the new Silicon Valley Bank review find?
What were Silicon Valley Bank's main vulnerabilities?
Did social media cause the Silicon Valley Bank run?
What should bank risk teams change after the 2026 SVB review?
How is the 2026 independent SVB review different from the Federal Reserve's 2023 review?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Operational Risk
The Basel III Endgame Re-Proposal Slashed Op Risk Capital. Here's What Your Operational Risk Program Still Has to Do.
On March 19, 2026, the Fed, OCC, and FDIC formally rescinded the 2023 Basel III proposal and issued a dramatically different re-proposal that delivers net capital relief after industry feedback identified operational risk as the single largest driver of inflated RWA. Here's what changed, what didn't, and what your op risk program needs to do before 2027 implementation.
Sep 18, 2026
Operational Risk
NACHA Just Approved a $10 Million Same Day ACH Limit. Your Fraud Controls Were Built for $1 Million.
NACHA approved a $10 million per-transaction limit for Same Day ACH in April 2026, effective September 2027. That's a 10x increase from the current $1 million cap. Most financial institution fraud controls, velocity limits, and risk-based monitoring thresholds weren't built for that exposure. Here's what needs to change before the September 2027 effective date.
Sep 13, 2026
Operational Risk
FinCEN Hit UBS With a Record $125 Million 'Willful' BSA Fine — and FINRA Added $20 Million More. What the Double-Barrel Enforcement Action Means for Your AML Program.
FinCEN's $125 million penalty against UBS Financial Services — the largest BSA fine ever imposed on a broker-dealer — combined with FINRA's simultaneous $20 million fine creates a $145 million enforcement landmark. Both actions trace back to the same root cause: UBS knew its transaction monitoring had gaps, promised to fix them after a 2018 settlement, and didn't. Here's what 'reasonably designed' AML monitoring actually requires.
Sep 8, 2026