Innovation, Risk & Compliance-Every Banker’s Role from the Start

Episode 32 (00:40:17)
Subscribe

Transcript
Nancy Ozawa (00:06): Welcome to Banking Out Loud. I'm Nancy Ozawa, Chief Marketing Officer here at PCBB, and I'm one of the hosts for this podcast. And I'm joined by my co-host, Virginia Robbins, who works closely with community financial institutions, and always brings a great perspective to these conversations. Virginia, it's great to have you with me on this episode. I have to say though, Virginia Robbins (00:28): What, Nancy? Nancy Ozawa (00:30): When we were talking about having an episode on risk and compliance, I could almost hear a few people say, "Mm, maybe this one's not for me. Maybe I'm gonna let the risk officer listen to this one." Was that going through your mind, just me? Virginia Robbins (00:44): You know, Nancy, I think so many people, when they hear about risk, they start to have that reaction. And, you know, or they were thinking, "This is one of those things I should listen to. Maybe I'll wait till, you know, that Friday afternoon when I wanna look like I'm busy." But that's not the point today. We wanna share with everybody how important it is to understand what's happening inside your bank. So, Nancy, what are you thinking about this? Nancy Ozawa (01:10): Well, I, I think you're definitely right. This is one of those conversations that's not just for risk and compliance. This is for all of us. We all should have some knowledge of risk and compliance, whether you're thinking about how the decisions and processes are made across the bank, whether the loans we make as a bank, how those are made, how the credit decisions are made. Everyone has a piece of touching the risk and compliance of the institution. So I think it's important for us to have some general knowledge and be aware of that. Virginia Robbins (01:38): So Nancy, if you're in lending, credit administration, underwriting, branch operations, technology, leadership, wherever you are in the bank, you have a role in helping your bank spot issues early, make sound decisions, and help your customers succeed. Nancy Ozawa (01:56): Absolutely. It's just about asking a few more questions or bringing the right people into the room at the right time, not have these big surprises later on just because you're asking these questions. So I'm looking forward to it. Virginia Robbins (02:08): So Nancy, we've been talking about what happens when risk is not involved. And unfortunately, here in California, we have a recent example with Silicon Valley Bank. Um, Silicon Valley's bank's chief risk officer stepped down in April 2022. The bank went roughly eight months without a CRO before it announced their successor in January 2023. Silicon Valley Bank collapsed on March 10th, just two months later. The bank didn't have a CRO, and of course, we're not suggesting that the absence of the CRO was the cause of the bank's failure, and there were many issues at play. But it does remind us that risk can't sit on the sidelines, and it can't live with just one person at play. So whether it's risk ownership, escalation, decision-making, these all need to be strong across the organization. And a bank that knows and understands that and staffed with folks that understand this is better positioned to recognize and respond to change. Nancy Ozawa (03:11): So Virginia, we're joined by two guests who spent their careers thinking about these issues. First of all, we've got Patty Joiner. She is founder and president of Financial Solutions for the last 36 years, and she brings a wealth of experience in banking and compliance. And we have our very own Radhika Lipton, who is PCBB's chief risk officer, and she has more than 30 years of experience in risk management, compliance, internal audits, both in institutions and fintechs. Patty and Radhika, welcome. Patti Joyner (03:42): Thank you. Thank you. Nancy Ozawa (03:44): Virginia, do you wanna kick us off a little bit? Virginia Robbins (03:46): Thank you, Nancy. So we'll have a chance to have you all share your backgrounds a little bit, but let's jump right into the questions that people often ask. So this is an election year, everything is in flux, and whether it's AI or our economic environment or political environment, we've got interest rates fluctuating, competition over innovation continues. How should our managers prepare for this? How do they protect the bank? How do they continue to serve customers? Radhika Lipton (04:17): Focus. It takes a lot of focus to filter out some of the noise, some of the positioning and the political rhetoric, and we always have to be the ones that say, "Okay, what is still the law? What are the requirements? Not all the noise that's out there, but what are the legal requirements on a statute basis as well as a regulation to implement it?" And then keep our focus there with all the while listening to what's coming, what are the particular strategic directives or hot buttons that the current leadership may find more important than perhaps the prior leadership or the next leadership. So we have to stay the course. So it's almost like a 80 / 20, 80% focused on what is the typical absolutely day-to-day requirement, and then keeping mindful and from a nuance perspective, listening to what are the priorities and enforcement and an examination. (05:15): So it's a little bit of both. Radhika? Patti Joyner (05:17): Totally agree. 35 years in banking, I've seen that pendulum swing in multiple directions, and I've never really managed risk from, you know, what have you done for me lately mentality. So to your point, Patty, you know, not just policy, procedure, technology, resources, everything, but most importantly, since I manage risk here at PCBB and we talk a lot about enterprise risk, what is the risk your bank is willing to accept? Whether or not it's, you know, we are reducing reputational risk or not, reputational risk may be from a regulatory exam perspective, but not from a client deposit perspective. So read into it per your bank's risk profile. Read into how it could show up in other areas. I'd like to look at what will keep us safe and sound. Virginia Robbins (06:08): So risk and compliance are two radically different concepts. I love how you both came to that question. Patty, talk a little bit about compliance and then Radhika, let's talk a little bit about more risk. And again, I'm sitting in the bank. How do I approach these things? Radhika Lipton (06:25): That's a great question. And one of the things that we're challenged with daily, right? So from a compliance standpoint, consider the simple question, and this is what I always talk to boards and CEOs and for senior management C-suite that wants to pretend they don't have to think about compliance, is would you go play golf or pickleball or football with any of your friends and not know the rules of the game? How long do you think you would be tolerated if you didn't respect the simple structure and the basic rules of the game? And most of us recognize it wouldn't last very long, right? You, you would be kicked off the team or kicked off the course and be asked to keep your little merry self at home next time. And so it's important to understand that a financial institution is highly regulated in everything that we do. (07:17): So compliance permeates everything from the way we have signage outside and on the internet and in our advertisements and business development efforts to originating loans and opening deposit accounts. There are compliance technicalities that are based on customer protection, whether consumer or commercial customers on protecting those entities and individuals from the bad players that created the need for these complex regulations in the past. And we need to understand that everything we do typically has a regulatory or a statutory basis and respect that. I don't think compliance should ever drop the bus, but I certainly think it's intended to keep us out of the ditches. And if I don't pay attention to the basic rules, why would I not expect a penalty flag? Why would I not expect a civil money penalty when I've arrogantly disregarded the very, uh, highly publicized and highly, um, enforced and litigated rules of the road? (08:21): Why would I expect that I would be any different? So to me, compliance is a vital part of that infrastructure. And then of course, as Radhika will mention, you know, risk is that umbrella that then looks at it from more of a strategic and a higher level position. But one or the other missing means the roof is gonna be off the building and we're gonna be absolutely just running around like compliant hits, you know, of a chicken, uh, or we're gonna actually be able to strategically move in the right direction. So compliance is the, the conscience, if you will, of the organization and making sure that we're doing all the right things in all the right ways on a daily basis. Virginia Robbins (09:02): Yeah. Patty, I love what you said about going into the ditch because if you expect to be playing baseball and you show up at a bowling alley - Radhika Lipton (09:09): Exactly. You Virginia Robbins (09:10): Know, not only are you playing with the wrong size ball, but you absolutely are gonna get that in the ditch. Radhika Lipton (09:16): And as we would say in the South, bless your heart, Moron, what did you expect? You know, sorry, just had to throw that in. That's the first thing that came to mind. Virginia Robbins (09:25): There you go. Patty, I loved what you said about compliance and understanding the rules and foundations. And thank you so much for queuing up that next discussion for Radhika in terms of overlaying risk. So Radhika, talk a little bit more about the risk discussion and when we look at the rules and the foundation of those rules. Patti Joyner (09:44): Well, Patty captured it perfectly. You know, to me, compliance is asking, are we following the rule? And risk is that umbrella. Risk, um, as we know, is just one part of it. There's, you know, credit, there's reputational, there's legal, there's strategic. There's a variety of risk. So when we look at risk, it's not just the policy, it's not just the procedure, is what is the outcome and how can this hurt our bank? But risk is looking at the whole picture. What other consequence does this project task requirement not speaking to, not addressing, not being evaluated? To me, performing compliance work is a little bit like looking back at the past, like looking at our transactions, you know, it's like testing as, as we say. To me, risk is forward-looking. What do we need to anticipate? What do we need to think about across the bank? (10:40): What is our exit strategy? So it's a more broader look of what we're trying to propose, not just one aspect of it. Radhika Lipton (10:48): Who do we wanna be? Who do we want the marketplace to feel that we are? Who are we trying to serve? You know, you can't serve everybody. You can Patti Joyner (10:56): Obviously Radhika Lipton (10:57): Not, you know, be a master by everyone, but you, you can find that niche and that, uh, personality and that community and that geographic market that speaks to you. And, and then you've gotta decide who I wanna be. And then we can build the infrastructure to fulfill that dream. I love that approach. Virginia Robbins (11:16): So, so let's talk about what this looks like inside a bank. Many of us have worked in banks that have been in existence for quite a while. They have established cultures or established procedures. If I'm sitting in my bank and I'm thinking about how to apply what I'm hearing here, what are the kinds of things that I need to do? What does this look like in a bank, um, that's more focused on a holistic approach? Radhika Lipton (11:42): I think it's important that you decide, obviously, once we've got the strategy and the vision down, which products and services do we want to offer, all right? And then you functionally, and from a business unit standpoint, have to decide, here's what we're gonna stand up to provide these services. So once we've made the product or service decision, let's say a product, and we're gonna take that product, let's say a mortgage, and we wanna offer that to our community, then you decide, okay, how many people do we need? What functionality? What systems are gonna be required? And that is all driven by which regulations are going to apply, which laws mandate what we can and can't do. So you have the vision of the product or service that creates the business unit and the departments to be able to deliver that. And then you've gotta build the infrastructure that's gonna say, "Here's the laws that set the g - you know, the boundaries." Let's say it designs the basic architecture of the building. (12:42): So it designs that, and then how we furnish it and how we deliver it and, and how polished or how down to earth we want to deliver that then is still within the boundary and the framework of what's allowed. Who are we trying to protect? What are we trying to protect them from? What disclosures do they need? And then of course, how are we gonna market to them? How are we gonna speak to them? How are we gonna service them over the long term? If we need to terminate someone from a product or service or, uh, the bank from offering that product or service, terminate us in general, you know, we gotta have a vision of what that looks like. And that requires knowing your people and what their capabilities are, what type of systems will deliver the functionality. We want it to still have the human touch to say, "Whoop, get out of the ditch." You know, we want to be able to, to master from harnessing all the automation and the AI possibilities, but still be who we want it to be. (13:42): So it's building from the ground up and it's function by function, disclosure by disclosure, you know, servicing option and core system with ancillary vendor, um, relations. So it, it's just marrying all of that, but you have to start with who do you wanna be? If you let your products and services and all the details drop the bus, God knows where you're gonna end up. So you want to be able to say, "Here's where I wanna end up. Here's what I wanna be. Here's the products and services." My grandfather had a great saying, you've all heard it all your lives and it still resonates with me, "How do you eat an elephant?" And he said, "How do you eat an elephant?" And I'm like, "What the what? Are we eating elephant too? I gotta get outta here," you know? But it's that whole mindset of don't let anything overwhelm you. (14:27): How do you eat an elephant? One bite at a time. And so you have to see the vision, and that's risk. And then you have to figure out how do we flesh it out? How do we make sure that we follow product by product, service by service, touchpoint by touchpoint, taking care of our customer? Little graphic, but true. Virginia Robbins (14:46): So Radhika and Patty, when you think about I'm a manager of a division, I'm a branch manager, maybe I'm head of a department, you know, I'm busy enough trying to keep the lights on, keeping my customers happy, meeting my P&L. I think you're asking me to do more. Am I hearing right? How do I get this done along with my day-to-day work? Radhika Lipton (15:09): I'm asking you to do it right the first time. There needs to be buy-in on the process. There needs to be buy-in on the procedures. Your compliance people are there to support you and to figure out the details. And then you've got to make sure that you understand how to do it. If I set it up well, then my processes and my procedures support the compliance requirements and they support the vision of the strategy. You're not gonna be doing anything but taking care of your customers and have the processes support you. If I build crappy systems, then expect to stumble and fall and let your customer suffer. But if I build it right, respecting that everything we do has regulatory requirements to it rather than trying to pretend they don't exist and fit that in at the last minute. It's all about the importance of building it right from the first time, then I'm gonna support you in supporting your customers. (16:03): But if you fight me the whole way and you try to force it in the last minute, expect to have issues and problems and inconsistencies. Radhika, I'd love to hear your, your call on that. Patti Joyner (16:13): 100%. I think the term I wanna use here is an old term that we all know, delegate. Virginia, I know you've got a lot on your plate, but lean on your partners within the institution, you know, bring them in early. We've talked about this already. And from the prior discussion, it's not just the regulation. So don't come into my office and say, "Okay, I wanna launch this new product. You know, what regulation applies?" It's not just that. It's the regulation. It's the policy. It's the procedure. It's the systems we're going to use. It's the employee that's gonna have to face the customer on Tuesday after we kick it off on Monday, right? So nobody has ever gotten written up because they misread the regulation. They've been written up because they didn't follow one of the other requirements that are in the process. So open it up to your colleagues, you know, saying, "You know what? (17:06): I've got this new project. This is our new strategy. We wanna bring this to, to the forefront. What are all the things I need to consider?" And let everybody work with you. Kind of the old phrase, you know, work smarter, not harder, delegate, lean on your, you know, subject matter experts within your institution, trust their advice, right? Trust by verify, and include that in the process. That goes back to the whole umbrella philosophy of enterprise risk, right? Radhika Lipton (17:35): I feel so strongly about this. I'm about to burst and, and I, I totally agree with what Radhika just said. What, what we fail at so many times as an industry is placing a lower priority on operationalizing the requirements in the laws and the regs. And I use that word so much. I, I probably should just go ahead and have it tattooed on my forehead. But operationalizing is where everybody's like, "Ugh, we'll worry about that later." Or, "Oh, give that to Nancy. She'll run with the details later and I don't wanna know anything about it." Shut the front door. If we don't operationalize things well, and if we don't know how we're gonna do what we're gonna do, there's no way that I can say what I'm gonna do and do what I say. And that's the key to UDAP, that's the key to just consistency with your strategy and your risk vision is making sure that we don't, you know, load up with our mouth all the things we wanna do and deliver and don't have a system to support it. (18:36): And then they've got 85 workarounds and wonder why the heck we're in trouble, you know? So, I mean, that's just dumb. All right? Let's admit it. We've all seen it throughout our, our careers. The definition of insanity is doing the same thing over and over and expecting a different outcome. So if we don't operationalize heavily, once we've got that vision set of what we wanna do, then we're not going to smooth sail through this whole process and expect bumps in the road. But if we do it right from the first, if we really give people time quickly to set up all the things, make the good decisions about the processes, then the customer really can be keen. And, and that's what people don't expect to hear from a compliance person like me. But if we don't serve our customers, there's no reason to be here. (19:26): So you have to keep that in mind and we have to be who we said we wanted to be. Operationalize. Patti Joyner (19:32): I love that term because although I believe postmortem of any situation is important, I believe that if you operationalize, as you mentioned, Patty, in the beginning, a lot of those consequences may have been evaluated and understood before the financial losses in the postmortem, before a lack of procedure. As long as you put everything up, as you said, operationalize every possible outcome is critical. Mm-hmm. It may not all apply, but at least you've thought about it and discussed it. Virginia Robbins (20:01): I love what you both are saying and personally, completely support it. And yet, I'm thinking about those bank operations managers who sometimes are invited into the room after the client's already agreed - Yes, thanks. Or after the rest has already agreed. So how can you - Radhika Lipton (20:22): After we've published the first ad. \ Virginia Robbins (20:24): After the customer, after the CEO or someone has said, "Great, we're going to do X. Now make it happen." So how can we help them educate their leaders, other decision makers in the organization, maybe people who are in a completely different area of the bank? How can we help them? How can we help our great folks in operations educate others as to what the true cost is to just maybe slowing down a little bit and doing things right? Radhika Lipton (20:55): Exactly what you're doing right here. Trying to speak to an audience that's broader than just the risk people, just the compliance people, but to just understand at the board level, at the highest level of the organization, all the way permeating throughout the organization, we have to build things within the constraints. And none of us as entrepreneurs. I've had my own company for 36 years, so I'm, I'm very independent. I'm redheaded through and through. I am absolutely wanna do the things I way that I wanna do them. But if you're going to succeed in a financial services market, respecting that there are some boundaries that are defined by law, what can I push? What can I bend? What is unbendable? What do I have to rigidly follow? That's a finesse and an art and a management leadership skill that is absolutely fundamentally important as a bank leader. (21:56): And the day that you decide that that doesn't matter, and I don't need to talk to the operationals people, I don't need to talk to compliance with them before I launch this big strategy or this big product, expect to pay for that. Pay me now, pay me later. And if you pay me later, you're gonna pay me a lot more, exponentially more to fix the crap that we could have avoided from the beginning. So it's fundamentally important in their mindset. And a lot of times we have board members that are so valuable coming in from other industries that may not be as heavily regulated. I've run into that a lot, is to get that mindset of understand that there are certain things we can do and certain things we can't do. And if I can accept that as a fiery little southerner who likes to do things my own way, then you can accept that as a good business leader. (22:48): That doesn't mean we're not gonna figure out how flexible we can be, how far we can push the edge of the envelope, but to do something that borders on illegal or sets us up for a certain civil money penalty, that's just crazy. And so we need to make sure that we get that mindset of, "I want to do this. I wanna support. I'm not compliance the committee of no, but I wanna make sure that I support your vision." And there may be times when I say, "We can do it, but we gotta do it this way," or, "We can't do that at all, but we can do this." I wanna be part of the solution. And, and so it's important for us as compliance people and professionals to lead with that, "I want to support you because that is our job. You're my customer. You're my internal customer. (23:36): And as a result, I wanna support you." And by showing leadership that we can work together and realizing that if we move that operationalizing and that compliance and, and strategy and risk marriage upfront, that we're going to do this right and we're going to excel. It's great for the bottom line. It's great for our reputation risk. Reputation risk may not exist in the manual anymore, but all of us would be insane if we don't recognize that reputation risk is our life every day in the communities we serve. Then we've got an opportunity to succeed and do it right the first time and not pay for mistakes that could have been easily avoided. So Virginia Robbins (24:19): Speaking about products and innovation, Patty and Radhika, let's talk stablecoin. If you were giving advice to a bank's CEO or a risk committee, excited or concerned about stablecoins or AI right now, either one of the new changes that are coming through, based on what you've seen gone wrong at other institutions or perhaps what you've seen gone right, what would that be? Radhika Lipton (24:44): I'll tell you, my opinion on stablecoin is we need to take it very serious, personally and professionally. The biggest risk to our organizations is that we act like it doesn't exist. Stablecoin has been estimated to take anywhere from three to 10 to 15. I mean, everybody's just kind of guessing at this point, of our core deposits away from our institutions. So stablecoins being the one-to-one backing by a highly liquid asset of a crypto option to make sure that people can spend money from my wallet to your wallet immediately with lesser fees and that the whole thing is it'll be faster and less expensive. We'll see. Um, what kind of controls are out there? I can't help it. I'm an old control person. But the stablecoin issue and trying to offer this more stable one-to-one backing by liquid assets so we don't see the fluctuation that we have in the marketplace today on stocks and things, is providing people supposedly a cheaper and a faster option to make payments. (25:51): So we're going to see some movement of our core deposits away into this option, into this payment realm. So in doing so, then we know, oh, wait a minute, that's going to diminish my ability to loan because we have to have deposits, banking 101. We have to have deposits to be able to make loans. And the stablecoin backing, that one-to-one assurance and guarantee cannot be used for any other purposes. So I can't dual track it for it's gonna back the stablecoin to keep its value up and it can also be used to loan out to. I can't. It's, it's over here and it's isolated, right? And so that core deposit runoff is where we've gotta make a decision. Do we want to keep that customer in the fold in our family, or do we want to see them go with a stablecoin somewhere else to another provider? (26:50): Oh, and then what does that other provider also offer? So do I not only see some, uh, runoff of my core deposits, but have I now lost Nancy or Virginia to a competing organization that's gonna offer all of those things, you know, because there will be many financial institutions that will adopt this as another business line, if you will, uh, for sake of, of, of better term, but as another offering and an option, am I gonna lose those depositors? Yes, some of that runoff, but am I in a much bigger picture gonna lose that customer because they're gonna find other innovative and things, and they wanna keep everything in one place. So I, I think it is definitely, without question here, it's a matter of how are we gonna respond to it, and then how do we bring clarity, pun intended, how do we bring, bring clarity to this whole process and make sure that we do have the customer protections and things there? (27:53): And we've got to remember that at this point, stablecoins are not able to provide yields, and we definitely as banks want to make sure that that is not gonna be a huge competitive barrier for us. And then also the fact that they're not FDIC insured. Stablecoins are not gonna be FDIC insured. So we've got to balance that message and to balance that message and to make sure we retain our portion, we have to fully understand how it works, what is a competitive value, what is the competitive con, you know, it's not FDIC insured. And no, it is gonna be faster and it's gonna be less expensive, supposedly, than what you can do with a wire transfer or other, um, wallet exchange today, but you don't have the protection as well. I can sometimes recall a wire. Once I send that money to Nancy's wallet, it's gone, baby, you can call her and say, "Girl, give me that money back," but she, you know, she doesn't have to. (28:49): So there's a trade-off, and we are gonna have to be telling our own version of an accurate story on that to make sure we retain what we wanna retain, and how much are we willing to let go. Virginia Robbins (29:03): So it's not unlike what we saw 40 years ago when, uh, mutual funds first came in. Radhika Lipton (29:10): Exactly. Virginia Robbins (29:11): And the money moved permanently from the FDIC insured deposits to other entities. Customers retained with their bank, but the share of wallet with the banks - uh-huh. Materially declined forever in many cases. So, Radhika, when you think of Stablecoin and you think about how banks should approach this, what are the thoughts that come to your mind? Patti Joyner (29:33): I think putting your head in the sand and thinking it's gonna go away is not the posture that financial institutions need to take. And I think they also need to consider that there may not be ROI for a while. It is more so I think what Patty was talking about, a service that our clients are asking for. Who's gonna spend a $40 on a wire when they can send a payment for maybe $2 at record speed, right? So - Again, the things that I would think about as a risk officer is exactly that. The deposit insurance perspective, the FDIC commentary, your BSA AML program, which is significant, is now on a shared ledger. How are you gonna reconcile things internally? Do you have to have a whole different core or, or a light core or wherever you want, you know, sidecar, whatever you wanna call it? (30:22): Um, how are you gonna address intraday liquidity? Um, these are additional risk things. Um, and then the framework. I think the biggest thing here is, you know, we, we punt about clarity or the, the Genius Act. There's no regulatory clarity here in terms of, of where to go. However, I don't think this is a, a green light, red light situation. I think this is a yellow light. I think it's proceed with caution, understand that it's here to stay. I think we've danced around this for years. Is it gonna be here? Is it not gonna be here? You know, but I think it's here to stay. And so not understanding that as a community financial institution when the big companies are already, um, engaged in it. I mean, there's, what, five big financial institutions already offering this service? One of the things I heard in a conference a couple years ago was relevance. (31:16): How relevant is your bank? Is your community bank? This is one of those items where you need to come to the table and talk about it. Is this something that's gonna make you relevant or irrelevant? Virginia Robbins (31:27): Right. And while I threw out stablecoin, this also applies for tokenized deposits and the other digital assets that may likely are, are going to evolve over the next few years. So, you know, again, I'm back in my bank. I'm thinking about my day-to-day and my customers and the rest of this. You know, how can I help my management think about the risks involved? Or how can I ask questions from our compliance managers or maybe perhaps from, um, my peers, uh, from how they're looking at this? How should I be approaching this as I work to see what is of interest to either my market, my customers, how my bank's approaching this? What would you suggest? Radhika Lipton (32:09): Active listening. Patti Joyner (32:10): And a seat at the table, knowing that your chief risk officer is not an obstacle, but knowing that that person is there, like I've said in many meetings, my answer is not no, it's give me the information and let's work through it. So communication, honesty, including compliance and risk in the very beginning. And then you may not see compliance and risk after the next couple of steps of your project and then they come back. So it's not something that, you know, is gonna be part of your everyday discussion, but it needs to be there at the beginning. Radhika Lipton (32:44): I think Virginia, staying in tune with what your competitors are doing, um, listening to your customers. I said active listening literally in that, you know, what are our competitors doing? Uh, as a risk manager, as a compliance manager, I should be listening to and, and being involved in that just as much as my marketing and business development and all, because I need to be ready for what's around the corner, right? And, and sometimes even bring it up in discussion, "Hey, what are we gonna do about this? Have y'all thought about it yet?" Maybe they've had some conversations but haven't brought me into that yet because they're still so early on. Well, interject yourself in a supportive way. I hear that our competitors in the national market are doing this, and I've heard a little bit about some of what our local competitors are doing. How do y'all wanna position ourselves? (33:34): You know, are we thinking about it? What do we. And that conversation, number one, after they get off the floor from passing out that compliance was that market driven and asking those questions in that way and not being the committee of note, I think that proves that you're trying to be a part of the solution and allows you in that conversation earlier. I hate it when a compliance officer tells me all the time, "Well, nobody asks me." Well, you have a mouth? Go ask them. You know, what's going on? What are you people doing? Uh, let me be part of this. How can I help? I brought donuts. You know, for God's sake, interject yourself in a positive and in a supportive way and expect then to be invited to the conversation instead of, oh, Lord, don't bring her in. You know, it's just gonna be awful. (34:20): And it's gonna be, no. You know, I want to be part of the solution. Here's what I'm hearing. What are we gonna do about it? I think that's a big thing. And prepping ourselves. I mean, I'm reading all the time now on all the different, the Genius Act, the Clarity Act, the, all the, um, missives on artificial intelligence and the warnings about AI is gonna kill us all in 10 years so it won't matter. I mean, all of those things, you know, you keep hearing in the marketplace. And it's my job to take all that in. And from a compliance standpoint to figure out, do I know enough right now that if we have to pivot quickly and if we have a new strategic direction, am I ready? You know, if I just wait to say, well, when Virginia says we're interested in it, then I'll start researching it. (35:05): Go home. You know, get off the field, all right? Because you're already behind. So just be preparing yourself and ask and listen and, and really keep an ear to what's going on in your competitors. I can't emphasize that enough. Virginia Robbins (35:20): So Patty, stay ever curious is what we're saying here. Radhika Lipton (35:23): Absolutely. Stay ever curious and stay again. Never get complacent. Virginia Robbins (35:27): As we wrap up, many of our listeners don't work in a formal risk role. But as we've talked about today, risk and compliance is involved in everything that they do. What can each of them do now to stay ahead of this involving areas and what can they do to simply make sure that they don't react? Radhika Lipton (35:45): Understand the why behind everything we do. That is not a request that should be overwhelming or overburdening. Empowering your people by understanding the why of what we're doing allows us to build and pivot as a collective and collaborative effort rather than Radhika and I sitting in a room and mandating checklist and forms and things. Empower your people. Give them buy-in authority and do that by educating them about why we do what we do. And the how comes from that mission. I'm a big believer in building that because then we can pivot and we can grow and we can react together going in the same direction rather than pulling in separate directions. Virginia Robbins (36:36): I love that. Radhika, what are your thoughts? Patti Joyner (36:38): I'm going to position it from the other perspective and that's the top down. So many times we see boards of community banks and members that have never seen a safety and soundness, never participated in a safety and soundness. Uh, they may be pillars of the community financially, but it's not a good representation of everything that goes on in a financial institution. But I would also start at the top and make sure your board is representative of what you're trying to achieve. So if you're a technology forward institution, you better have someone with a strong technology program on, on the board. If you are a financial institution that has a higher risk profile, then make sure your board has someone with significant risk and compliance experience. Have a diverse board that can help you. Now, I always say, you know, eyes in but hands out, right? (37:36): For a board member, right, not to become part of management, but it really helps direct the tone. It helps direct the setting, what the board is willing to accept as responsibility, as risk, as strategy, and then give those tools, you know, and those recommendations to management to execute and give them, to Patty's point, empower them to execute those strategies. Virginia Robbins (37:59): Awesome. Well, thank you both. Uh, Nancy, I'm gonna turn this back over to you. Nancy Ozawa (38:04): A few items to me, this is some of the takeaways to remember, is that everyone should be participating in this. Risk is not the only one who owns this. They're not the only one department or one title that owns this. So whether you're a lender, an underwriter, a credit admin, an operations professional, a technology team member, risk shows up in the decisions and processes that you touch every day. And the earlier the people raise questions, share information and bring in the right partners, the more resilient your institution will be. And I love, Patty, what you said is do it right from the very beginning. You know, we kind of touched on stablecoin and AI, not that every bank is going to offer that, but that is a great opportunity to have that conversation about what your risk appetite is now and to develop your business plan around it accordingly. (38:58): If you are gonna go out into the market with this, do it from the very beginning, bring risk conversations in. If you're not, you still have risk conversations to have. So that was some of what I took away from this conversation. Here at PCBB, we're committed to helping you think through and understand the trends that are shaping banking and to think through how that approach is gonna change over time in a more thoughtful and responsible way. Our goal with thinking out loud is to bring you practical ideas, useful language, and real world perspectives that you can take back to your entire team. To make sure you don't miss future episodes, subscribe to Banking Out Loud on your favorite podcast platform, including iHeartRadio, Apple Podcasts, or any others. Or you can go to our website, pcbb.com/podcast and subscribe there and you can get an email when we drop the next episode. (39:49): And hey, if you've got a topic for us or you would like to join us as a guest, we would love to hear from you. Please reach out to us at thinkingoutloud@pcbb.com. Thanks again for listening. Until next time, have a great day.

Key Takeaways:
  • Risk management is not limited to one executive or department. Clear ownership, timely escalation, and informed decisions across the organization can help a community financial institution respond to change sooner.
  • Don’t wait until a product is built, an agreement is signed, or a campaign launches to involve risk, compliance, operations, and other experts. Early collaboration can help avoid rework, inconsistent processes, and customer issues. 
  • Compliance professionals can help teams identify what is possible, what needs adjustment, and what may introduce unacceptable risk. Their role is not simply to say no — it is to help the community financial institution meet its objectives responsibly. 
In this episode of Banking Out Loud, hosts Nancy Ozawa and Virginia Robbins discuss why risk and compliance are shared responsibilities across a community financial institution. Joined by Patti Joyner, Founder and President of Financial Solutions, and PCBB Chief Risk Officer Radhika Lipton, they explore how compliance provides guardrails while risk management takes a broader, forward-looking view.

The conversation examines how community financial institutions can navigate change, from launching new products to evaluating stablecoins and AI. Patti and Radhika emphasize engaging the right stakeholders early, building strong processes before launch, and viewing risk and compliance as strategic partners that help institutions serve customers, manage change, and move forward responsibly.

Guests:

Patti Joyner
President
Financial Solutions
Radhika Lipton
SVP, Chief Risk Officer
PCBB

Hosts:

Nancy Ozawa
Chief Marketing Officer
PCBB

Virginia Robbins
EVP, Chief Solutions Officer
PCBB