Story 323

80% Done. Just Missing the Lines of Defense Structure.

Citi’s Consent Order began in 2020. By the bank’s own account, remediation is near complete.

A Data Risk function in the second line of defense — the independent oversight layer whose entire purpose is to challenge and govern data risk taken by the business — did not exist until spring 2025.

Let that land.

Five years into a regulatory enforcement action predicated on data governance failures, the independent function responsible for overseeing data risk was not yet built.

It was created while the organization was claiming to be in the final stretch. The second line of defense is not a finishing touch. It is a foundational control.

It ought to have been built at the beginning — unless the organization considered independent oversight a feature of normal operations rather than a requirement of remediation.

You know the answer.

Similar Posts

  • Story 58

    I am based in Citigroup’s New York office. While I cannot speak to other business units, the Equities floor regrettably lives up to its longstanding and notorious reputation for dysfunction. A small cadre of MDs and their favored allies effectively dominate the culture, fostering a cliquish environment. Although the Equities division now includes a notable…

  • Story 217

    Coercive control at work is not bad management. It is not a personality clash. It is a pattern of behavior — deliberate, directed, and purposeful. I experienced this at Citi, in USPB Risk Management — under a former “manager” himself working under a known bully and harasser. As a sustained and consistent pattern directed specifically…

  • Story 360

    Re: Story 359 The pattern is identical, even if the players change. In my case, the individual has been at the bank for over 23 years, proving how deeply entrenched this behavior is. A perfect example of this mindset: following a major reorganization, she openly stated she didn’t need to address negative employee survey feedback…

  • Story 124

    The Financial Times is reporting today that Citi’s former head of the family office previously served as Jeffrey Epstein’s personal banker – a detail one might reasonably expect any competent organisation to identify during the most elementary due-diligence checks. The article drily observes, it “begs the question of what Citi’s process actually involves.” This on…

  • Story 314

    When the Coverup Becomes the Crime: A Cautionary Tale from KPMG Last week, the CEO of KPMG Australia resigned without notice. While he wasn’t personally implicated in wrongdoing, how he handled it when others were, precipitated his demise. KPMG partners were found to have inappropriately shared confidential client information internally. A whistleblower raised the alarm….