Story 330

What Citi’s transformation narrative is built to obscure

You could tell this story as a mere list of process failures—bad methodology, weak leadership, an underused tool. That version is true, but it misses the point.

The story is what those failures have in common: an organization that is asking how to demonstrate that remediation is real – not asking whether it is real.

Those are different undertakings. One produces genuine change, slowly, with setbacks visible along the way. The other produces a narrative — and requires the gap between performance and substance to stay hidden.

That is not a culture in transition. It is a culture that has found a more sustainable way to live with the problem than to fix it.

Here is what that looks like from the inside.

The foundation everyone has agreed to set aside

You cannot manage risk without the data to do it. Citi-specific data — actual exposures, actual positions, actual concentrations. Not industry-level risk types. Not market proxies standing in for the real thing.

That data infrastructure did not exist yet. It was supposed to. Instead, the risk and data work streams were split apart, so each consent order could be closed on its own schedule.

Which means the risk identification underway is a stage performance of it — meetings, templates, inadequate inputs.

Nobody senior will admit to this. The milestones get checked anyway.

A methodology that was not thorough

Risk identification was defined as bottom-up: business units identifying their own risks.

They were not given a consistent way to do it. So they didn’t. Exposure numbers got added that cannot mathematically be added. Risk descriptions were written that aren’t actually risk statements. Scope was quietly narrowed to financial risks only, because that was the version that could plausibly be finished on time.

A polite request by first line to address strategic risk — the explicit subject of a regulatory finding — was turned down flat. Operational risk was simply deferred.

When a senior person pointed out that any of this failed to accomplish real risk identification, the answer was a lecture about how long transformation takes: past the actual date regulators expect sign-off.

First-line teams asking for basic methodological guidance were told: “If I have to tell you, I don’t need you.”

That line is the whole operating philosophy in nine words.

And the unspoken part is the moment this consent order closes, the upgrade work stops. The regulatory deadline is the finish line.

Built tools nobody is taught how to use

The Stress Testing function considers its job finished the moment a tool ships — not when business units are actually using it to make decisions.

Risk ID never made stress testing an input to its own work. Business units say they only execute what second line directs, and second line never directed anything consistently.

So: Stress Testing points to Risk ID. Risk ID points to the business. The business points to the top. This endless circle of blame isn’t a byproduct of the system—fragmentation is the system.

When something fails, there is no single point of accountability — functions point at each other, ownership dissolves, and the structure itself becomes the excuse.

The Commercial Banking director responsible for ERM implementation was not a risk manager — an argument she readily volunteered when pressed on execution, as if the fact of her own misplacement absolved her of any obligation to lead.

It did. MDs in the room noted the attitude with mild dismay, shrugged and moved on.

Nobody named it for what it was: a person put in charge of a remediation she was unqualified to run, responding to that gap with aggression and deflection, and an organization with no intention to treat that as a misfit worth correcting.

Why nobody owns it

This is not a new failure. It is the original failure — the one the consent order was issued to fix — running inside the remediation program itself.

The pattern repeats wherever accountability might otherwise land.

In Tech and Data, senior leaders tried to keep information from Internal Audit — information that would have shown technology had started building before the business had even said what it needed. Technology setting its own agenda, audited only when it couldn’t avoid it.

Internal Audit called it what it was: a poor controls mindset.

The CRO sets the agenda. He has never been heard discussing the consent order in specific terms — what it actually requires, where delivery has fallen short, what has to change.

That conversation gets delegated to MDs who have neither the skill set nor the institutional will to force resolution across functions that don’t report to each other.

Below him, the appointments tell the rest of the story without anyone having to say it out loud.

Head of Risk Appetite went to the Head of Risk Analytics and Stress Testing — a function that had defined its own job as building tools, not making sure anyone used them. He hadn’t made progress on his own remediation work. He got the bigger title anyway.

When he left the firm, the role went to the Head of Risk Identification — a person peers have described as unable to get his own team to execute — who was promoted into the combined position. Not on merit. Because the org chart looked cleaner that way.

The consent order requires senior leadership accountability and subject matter know-how. What it gets is reshuffles from lifers with underdeveloped skills.

The part that doesn’t get said in any deck

The OCC and the Fed issued these consent orders because Citi could not embed risk management into how it actually operates.

Nothing in what’s described here suggests that has changed.

That is not a foundation for transformation. It is the condition that made the consent order necessary the first time.

Left alone, it is the condition that makes the next one inevitable.

“The appearance of doing something is a substitute for the thing itself.” — Citi design principle, ante 2020 Consent Order, never formally retired

Similar Posts

  • Story 36

    I am an ethnic minority female millennial whom worked in the Citi London office for 4 years at analyst level in the 2010s. After being in my original team for 1.5 years, I was asked if I would like to move into another team in the same department which was to support a new fast…

  • Story 58

    I am based in Citigroup’s New York office. While I cannot speak to other business units, the Equities floor regrettably lives up to its longstanding and notorious reputation for dysfunction. A small cadre of MDs and their favored allies effectively dominate the culture, fostering a cliquish environment. Although the Equities division now includes a notable…

  • Story 98

    I was pregnant and was the only person to have ever been pregnant at the dba that I worked at under Northwestern Mutual. I was told that there was no maternity leave policy and while helping my boss with something on his computer I found a folder with all of the dates of my doctors…

  • Story 132

    Sexual harassment allegations in the Private banking sector of a leading Asian financial hub that enables Family office setups is increasingly portrayed as evidence of systemic protection for those in power. Survivors and advocacy groups allege that law enforcement, regulatory bodies, and other authorities have suppressed complaints for too long to safeguard institutional standing and…