Story 328
A Managing Director in USCC Risk demonstrated a disturbing pattern of using performance reviews as a tool of retaliation rather than genuine evaluation.
When an employee pushed back on an inaccurate mid-year assessment, the MD responded not by engaging with the substance of the disagreement but by doubling down — praising the Director’s leadership while citing the dissenting employee for allegedly provoking second line of defense relationships.
The reality was exactly the opposite. The employee had built strong, productive Second Line relationships and was actively solving problems the MD and Director themselves had created.
What the MD characterized as provocation was in fact principled boundary-setting and genuine stakeholder engagement — the kind that risk management demands. Her instinct was not to encourage this. It was to suppress it.
Rather than fostering open dialogue with Second Line colleagues, the MD’s approach was to escalate everything covertly to her Group Head for political advantage — treating Second Line engagement as a threat to be managed rather than a discipline to be cultivated.
When a leader lacks the intellectual weight to win an argument on its merits, they resort to exactly this: political maneuvering, back-channeling, and narrative control.
The irony is that the employee she penalized was subsequently praised lavishly by the Second Line for her openness, collaboration, and sophisticated approach to risk management.
That praise made the Director uncomfortable, having failed to elicit the same enthusiasm himself.
What was written up as a development need was in fact a well-honed capability that neither the MD nor the Director possessed.
Performance reviews are meant to be a development tool. When they are used instead to punish employees for competencies their managers lack, they become a form of institutional gaslighting.
More telling still: this MD demonstrated a consistent inability to operate effectively within a three lines of defense framework. She negotiated down Internal Audit findings rather than working through concerns in good faith — an attitude that compromises rather than strengthens internal controls.
For someone in a risk leadership role at a firm under consent order, this is not a minor gap. It is a core competency failure of magnitude.
When a firm is under a consent order — meaning regulators have already found cease-and-desist-level failures — this isn’t just bad management. It is regulatory arson.
Leadership in risk is not about removing people who push back. It is about having the intellectual integrity and technical command to know when pushback is right.
This MD had neither.
Citi Leadership was alerted to the risk she posed.
They have so far chosen to do nothing.