Business Insights · Updated October 2026

Key Compliance Models: 20 compliance, risk and governance models, each explained through a real case.

On this page I explain twenty models that compliance, risk and governance people use every day. They run from the Three Lines Model and COSO to ISO 31000, the Fraud Triangle and conduct risk. You can read each one in about a minute. Every one is built on a real corporate case and ends with a question to put to your own organisation. They all come from my book Key Compliance Models.

How to use this page

Compliance models are usually taught as diagrams. I find a diagram is easier to use next to the case that shows what happens when the model is missing. HSBC had three lines of defence on paper, RBS had a risk function and Wells Fargo had a code of conduct, and each still failed in the way these posts describe. Each post below takes one model and puts it next to the organisation that needed it most.

Read them in any order. If you sit on a board or own the business, start with the Three Lines Model, ISO 37000 and the Risk Appetite Framework. People who run a compliance or risk function will get more from RCSA, key risk indicators and bowtie analysis, which are the working tools. If what worries you is how people behave, read the Fraud Triangle, Just Culture and conduct risk one after the other.

Real companies are named here, so the facts needed care. The figures and the statements about each company were checked in October 2026, against what regulators, courts and official inquiries had published. The sources are listed under each post. Please read the posts as explanation. They are not legal advice.

The 20 models on this page

Pick a card and it takes you to the full post. I add new posts to this page from time to time.

Bowtie Analysis: Threats, barriers and consequences around one event

No. 11

Bowtie Analysis

Threats, barriers and consequences around one event

Just Culture: Support error, coach at-risk habits, hold recklessness to account

No. 19

Just Culture

Support error, coach at-risk habits, hold recklessness to account

The posts in full

The Three Lines Model: Business, compliance and audit: three separate lines. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 01

The Three Lines Model

Business, compliance and audit: three separate lines

Three teams were watching the risk.

All three had gone slack at the same time.

That is the HSBC story in one line.

The business chased the profitable, high-risk work. Compliance was under-resourced and overruled. Audits flagged the problems, and the board did not force the issue.

On paper, three separate lines of protection. In practice, nobody was really watching.

The result: at least 881 million dollars of cartel money moved through the bank, and a 1.9 billion dollar settlement in 2012.

The Three Lines Model exists to stop exactly this.

First line: the business, which owns the risk and runs the controls. Second line: risk and compliance, who set the framework and challenge the first line. Third line: internal audit, independent, telling the board the truth.

The trick most people miss is that the diagram is worthless on its own.

What matters is whether each line is genuinely separate, genuinely funded, and genuinely able to say no.

A second line that can be overruled by the profit centre is not a second line. It is decoration.

Draw your three lines this week. Then ask the harder question: could line two actually stop line one?

If the answer is no, you do not have three lines. You have one, wearing a costume.

Sources: US Department of Justice: HSBC settlement, 2012; US Senate: HSBC money laundering case history report, 2012; IIA: Three Lines Model statement of position.

Longer read: The Three Lines Model, explained without the jargon

↑ All 20 models

COSO Internal Control: Five components of control that must work together. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 02

COSO Internal Control

Five components of control that must work together

WorldCom booked more than 3.5 billion dollars of running costs as investments, inside an accounting fraud that reached around 11 billion.

Losses became profits overnight.

It held up for one reason: the controls that should have caught it were hollow.

A dominant chief executive set the tone. Finance did as it was told. The board did not look hard.

The one part still doing its job was internal audit, working at night, refusing to let go.

COSO Internal Control is the framework built to prevent this.

It says good control is not one check. It is a system of five components that must all work together.

Control environment: the tone at the top. Risk assessment: what could stop us hitting our objectives. Control activities: the actual approvals, reconciliations, separations of duty. Information and communication: the right people getting the right facts. Monitoring: continuously checking the controls still work.

Here is the part people skip.

Control fails from the environment down, not from the checklist up.

You can have a beautiful wall of control descriptions and still collapse, if the tone at the top is rotten.

WorldCom proved it. The environment went first, and everything beneath it followed.

So before you admire your control activities, be honest about one thing.

If your most senior leader wanted to override a control tomorrow, what would actually stop them?

If nothing comes to mind, that is your weakest component. Fix that first.

Sources: SEC filing: WorldCom Special Investigative Committee report, 2003; JURIST: Ebbers sentenced over $11 billion WorldCom fraud, 2005; COSO: Internal Control, Integrated Framework guidance.

Longer read: COSO internal control, explained for people who are not accountants

↑ All 20 models

COSO Enterprise Risk Management: One enterprise view of risk, owned at the top. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 03

COSO Enterprise Risk Management

One enterprise view of risk, owned at the top

AIG did not fail because it was writing bad insurance policies.

It nearly took the financial system down because of one small unit almost nobody was watching at the top.

AIG Financial Products had written enormous volumes of credit default swaps.

Each position looked manageable inside its own silo.

Nobody added them up against the whole group and asked what it meant for AIG as a single organisation.

When the calls came in all at once, the parent did not have the cash.

The rescue began in 2008. By 2009 it had reached around 182 billion dollars in committed support.

That is what Enterprise Risk Management is built to prevent.

The essential move is aggregation.

A risk that looks tolerable inside one business unit can be lethal when you add it to everything else, or when several correlate and hit together.

ERM insists on a single, enterprise-level view of risk, owned at the top, tied to strategy and to how much risk you are actually willing to accept.

So here is the question to ask this week.

Name the small unit in your organisation doing the least understood, most unusual work.

Is its worst case aggregated into an enterprise view?

Or does it sit quietly in a silo, looking manageable, right up until it isn’t?

The most dangerous risk is rarely the one everyone is staring at.

It is the one nobody has added up.

Sources: Congressional Research Service: government assistance for AIG; Kellogg Insight: What went wrong at AIG?; COSO: Enterprise Risk Management framework.

↑ All 20 models

The OCEG GRC Capability Model: Learn, Align, Perform, Review: one integrated loop. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 04

The OCEG GRC Capability Model

Learn, Align, Perform, Review: one integrated loop

In 2008, Siemens pleaded guilty to breaking US anti-corruption law. With the German penalties, the bill came to around 1.6 billion dollars. It was one of the largest corruption cases ever brought.

For years, paying bribes to win contracts had been close to a business process, complete with off-the-books accounts.

Compliance was weak, and the controls did not hold.

Then Siemens did the thing almost nobody manages after a scandal.

It rebuilt, and within a few years it was cited as a model of integrated compliance.

The OCEG GRC Capability Model describes the kind of joined-up approach it built.

It runs on a loop of four connected components.

Learn: understand the organisation, its context and its culture. Align: set objectives and the limits of acceptable conduct, and line governance, risk and compliance up behind them. Perform: put the controls, policies, training and incentives into action. Review: measure, and feed what you learn back to the start.

The whole point is one word: integrate.

Compliance is not a department bolted to the side of the business.

It is woven through how the organisation is governed.

That is the difference between Siemens before 2008 and Siemens after.

So ask yourself this.

Do your governance, risk and compliance functions share one picture, or three?

If they never talk to each other, they are leaving gaps between them. And gaps between silos are where the next scandal grows.

Sources: US Department of Justice: Siemens guilty plea, 2008; US Department of Justice: Siemens sentencing memorandum, 2008; OCEG: GRC Capability Model (Red Book).

↑ All 20 models

ISO 37000, Governance of Organizations: Governing for durable value, not for appearances. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 05

ISO 37000, Governance of Organizations

Governing for durable value, not for appearances

Carillion collapsed in January 2018 with around 7 billion pounds of liabilities and barely 29 million pounds of cash.

This was not a sudden market shock.

The board kept raising dividends and chasing acquisitions while debt and a pension deficit grew, propped up by aggressive accounting.

A parliamentary inquiry called it what it was: a governance failure.

Thirty thousand suppliers, huge public projects and a pension scheme were left exposed.

ISO 37000 is the first international standard for what good governance actually looks like.

It starts with one word almost every failing board forgets: purpose.

An organisation exists to generate value in a way that is sustainable over time.

Around that sit the principles a well-governed body lives by. Real oversight. Clear accountability. Ethical conduct. Sound risk governance. Attention to long-term viability and to the people who depend on the organisation.

It is not a checklist. It is a mirror.

It lets a board ask whether it is governing for durable value, or merely managing appearances.

Carillion would not have been saved by a clever trick.

It would have been forced to answer the questions the board kept avoiding.

So here is one for you.

Can your board state, in a single sentence, the durable value the organisation exists to create, and name the people who would be harmed if it failed?

If not, you are managing appearances too.

Sources: UK Parliament: Carillion joint committee report, summary, 2018; UK Parliament: Carillion joint committee report, full text; ISO: ISO 37000 Governance of organizations.

↑ All 20 models

COBIT, Governance of Enterprise IT: Evaluate, Direct, Monitor: the board’s governance job. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 06

COBIT, Governance of Enterprise IT

Evaluate, Direct, Monitor: the board’s governance job

In April 2018, TSB moved five million customers onto a new platform over one weekend.

It failed.

Customers were locked out for weeks. Some saw other people’s accounts. Close to two million people were affected.

The board had pressed ahead on assurances that the platform would work, without independent evidence that it was ready.

The regulators fined the bank a combined 48.65 million pounds.

Here is the part that matters. This was not really an IT failure.

It was a governance failure dressed as one.

COBIT is the framework that keeps the two jobs separate.

Governance is the board’s job, and COBIT captures it in three verbs.

Evaluate: what are the options, the risks, the readiness. Direct: set the conditions the programme must meet before it proceeds. Monitor: insist on independent evidence, not management’s own reassurance.

Management then plans, builds and runs, inside that direction.

TSB did not get the management half right either. The regulators found weak planning and weak control of the programme. But the deeper failure was governance.

The board reduced its job to trusting that management had it in hand.

And a migration that was not ready went live anyway.

So before your next big go-live, ask one question.

Will the board see independent evidence of readiness? Or only management’s assurance that it will be fine?

Those are not the same thing. Two million customers found out the hard way.

Sources: FCA: TSB fined £48.65m for operational resilience failings; FCA: Final Notice to TSB Bank plc, 2022; ISACA: introduction to COBIT 2019.

↑ All 20 models

Five Lines of Assurance: Three lines plus external assurance and the board. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 07

Five Lines of Assurance

Three lines plus external assurance and the board

Steinhoff had management, external auditors, a supervisory board and an audit committee.

Four layers, all supposed to catch a problem.

Every one of them existed. Every one leaned on the layer before it.

In December 2017, the accounting fraud surfaced, and around 12 billion dollars of shareholder value vanished in days.

The fraud slipped through the gaps between people who each assumed someone else had it covered.

Five Lines of Assurance is the fix.

It takes the three lines and adds the two that reality demands.

The fourth line: external assurance, such as auditors and regulators. The fifth: the governing body itself, which must direct and receive all the others.

But the deeper idea is coordination.

Having many assurance providers is not the same as being well assured.

Without a map of who assures what, providers pile onto the easy risks and quietly leave the hard ones uncovered, each assuming another has them.

So do this.

List your three biggest risks.

For each, name who provides independent assurance.

Any risk where the honest answer is "no one" is your priority for the week.

Steinhoff had assurance in quantity and none in substance.

Five weak lines are not stronger than three. Coverage is not the same as scrutiny.

Sources: Business Standard (Reuters): Steinhoff loses $12bn in value, 2017; Steinhoff: overview of PwC forensic investigation, 2019; Werksmans Attorneys: review of the King IV Report.

↑ All 20 models

ISO 31000, Risk Management: A living loop: identify, analyse, evaluate, treat. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 08

ISO 31000, Risk Management

A living loop: identify, analyse, evaluate, treat

At UBS in 2011, a trader ran up a loss of around 2.3 billion dollars.

He disguised large positions with fictitious hedges, so the bank’s picture of its own exposure was false.

Here is the uncomfortable part.

The control functions had queried the activity. The systems had flagged anomalies.

The queries were answered away, and the risk kept growing.

In the end, the trader told the bank himself.

ISO 31000 is the international standard for risk management, and UBS shows exactly which part of it failed.

The process is a loop.

Establish context and criteria: what are we protecting. Identify, analyse and evaluate the risks. Treat them: avoid, reduce, share or accept. And running through all of it, two things that never stop: communication with the people who hold the risk, and monitoring and review.

UBS did not lack a process on paper.

What failed was the living part: monitoring that acts on what it sees.

The anomalies were identified, then explained away, so evaluation and treatment never happened.

A process that is not lived is not a control. It is a document.

So walk your own risk process this week and ask one thing.

When your systems flag an anomaly, does a human actually evaluate and treat it? Or explain it away and move on?

Sources: FSA: Final Notice to UBS AG, 2012; Channel 4 News: UBS rogue trader trial, 2012; ISO: ISO 31000:2018 Risk management guidelines.

↑ All 20 models

The Risk Appetite Framework: Turning appetite from a slogan into a hard constraint. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 09

The Risk Appetite Framework

Turning appetite from a slogan into a hard constraint

In 2007, at the very top of the market, RBS led a roughly 71 billion euro takeover of ABN AMRO.

The due diligence was famously thin, later described as little more than a couple of folders and a CD.

When the crisis hit, RBS was overstretched, short of capital, and holding assets it barely understood.

October 2008: a UK government rescue began. By the end of 2009 it had reached 45.5 billion pounds, reported at the time as the costliest bailout of any bank in the world.

The regulator’s verdict was brutal. Poor decisions by management and the board, it said, played a major role in the failure.

A risk appetite framework exists so that never happens quietly.

It sits between two ideas.

Risk capacity: the most you could lose before you fail. Risk appetite: the smaller amount you choose to take.

A good framework turns appetite from a slogan into a constraint. Qualitative statements, hard quantitative limits, and a cascade down into the mandates of the business, so a deal that breaches appetite cannot simply proceed.

RBS confused capacity with appetite. Which is another way of saying it was willing to bet its own existence.

A working framework would have made that bet visible, and stoppable, before it was placed.

So here is your test.

Would your appetite limits actually stop your most ambitious executive’s favourite deal?

Or would they be waved through?

If they would be waved through, you have appetite in name only.

Sources: FSA: The failure of the Royal Bank of Scotland, 2011; NPR: RBS becomes costliest bank bailout worldwide, 2009; FSB: Principles for an Effective Risk Appetite Framework.

Longer read: Risk appetite: the sentence most compliance programmes cannot write

↑ All 20 models

Risk and Control Self-Assessment: Self-assessment, with real challenge. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 10

Risk and Control Self-Assessment

Self-assessment, with real challenge

JPMorgan’s London Whale lost around 6.2 billion dollars in 2012.

As the position moved against the bank, the machinery that should have caught it was quietly disarmed.

Risk limits were breached, repeatedly.

Instead of cutting the position, a new model was introduced. One that happened to show far lower risk. And it contained a spreadsheet error.

The people assessing the risk were too close to the people taking it.

Risk and Control Self-Assessment, or RCSA, is the workhorse of operational risk. And this is its weakness in the open.

The idea is sound. Each part of the business assesses its own risks and controls. Inherent risk before controls. Whether the controls actually work. Residual risk after.

Its great strength is that the assessment sits with the people closest to the risk.

That is also its great weakness.

When those same people are under pressure to protect a profitable position, self-assessment becomes self-justification.

Limits become obstacles. The model gets changed until it gives a comfortable answer.

RCSA needs independent challenge, the second line testing the first line’s ratings, or it becomes a mirror that shows the business exactly what it wants to see.

So look at your last self-assessment.

Who challenged the ratings? And did anything actually get marked worse as a result?

If nothing ever gets marked worse, you are not assessing risk. You are confirming comfort.

Sources: US Senate: JPMorgan whale trades hearing and findings, 2013; US Senate: JPMorgan Chase Whale Trades, full report, 2013; BIS: Sound management of operational risk, summary.

↑ All 20 models

Bowtie Analysis: Threats, barriers and consequences around one event. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 11

Bowtie Analysis

Threats, barriers and consequences around one event

On 20 April 2010, the Deepwater Horizon rig suffered a blowout.

Eleven workers died. The largest accidental marine oil spill in history followed.

It was not one failure. It was a sequence of failed barriers.

A poor cement job. A critical pressure test misread as a success. A blowout preventer that did not seal.

Each was a barrier that should have stopped the escalation. Each had a hole. BP’s costs eventually reached around 65 billion dollars.

Bowtie analysis is the tool that would have shown this coming.

Put one dangerous event in the centre, the moment control is lost.

On the left, the threats that could cause it, and the preventive barriers between each threat and the centre.

On the right, the consequences, and the recovery barriers that would reduce them.

Drawn out, it looks like a bowtie. And its power is that it makes your defence in depth visible for one specific event.

You can count every barrier you are relying on.

Then ask the uncomfortable question about each one.

Not "do we have a barrier here." But "have I actually verified this barrier works, or am I just assuming it does."

Deepwater Horizon is a bowtie whose barriers all failed on the same day.

Drawn honestly beforehand, it would have shown how much weight was resting on a handful of barriers nobody had truly checked.

So take your single most catastrophic risk this week.

How many real barriers stand between the threat and disaster? And which have you actually verified this year?

The barrier you are quietly assuming works because it always has is the one to check first.

Sources: Oil & Gas Journal: official Macondo blowout findings, 2011; Maritime Executive: BP spill costs reach $65 billion, 2018; UK Civil Aviation Authority: how bowtie works.

↑ All 20 models

The Risk Matrix and Heat Map: Likelihood and impact, and the honesty of the inputs. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 12

The Risk Matrix and Heat Map

Likelihood and impact, and the honesty of the inputs

In January 2003, a piece of foam struck the wing of the space shuttle Columbia at launch.

Engineers were worried. They asked for imagery to inspect the damage.

The request was turned down. The risk was judged low, in part because foam strikes had happened before without disaster.

On re-entry, the wing failed. All seven astronauts died.

The inquiry found a pattern that the sociologist Diane Vaughan calls normalisation of deviance. A serious risk repeatedly downgraded because it had not yet caused harm.

The risk matrix, the colour-coded heat map, is one of the most widely used risk tools in the world. Columbia shows its fatal flaw.

You rate each risk on two axes, likelihood and impact, and plot it on a grid. Red demands action. Green can be watched. Quick, visual, one page.

But the matrix compresses a complex risk into two subjective judgements. And those judgements can be quietly bent.

A catastrophic but rare risk gets pushed into a comfortable green cell by underrating its likelihood, especially when it has not bitten yet.

The tool did not fail Columbia. The honesty of its inputs did.

So this week, look at your heat map and find the one risk that sits in a comfortable colour mainly because it has not happened yet.

That is where to look hardest.

Never let a heat map be the final word on a risk that could end the organisation. Quantify those separately.

A colour is not a control. It is a judgement, and judgement is exactly what drifts.

Sources: Congressional Research Service: Columbia accident report synopsis; Spaceflight Now: Columbia investigation board summary, 2003; Columbia Magazine: Diane Vaughan and normalisation of deviance.

↑ All 20 models

Key Risk Indicators: Forward-looking metrics tied to pre-agreed actions. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 13

Key Risk Indicators

Forward-looking metrics tied to pre-agreed actions

Northern Rock’s danger was measurable long before the queues formed outside its branches.

The bank funded its mortgages by borrowing heavily on short-term wholesale markets and rolling the borrowing over.

That worked while markets stayed open.

In the summer of 2007, the markets froze. The bank could no longer fund itself.

September 2007: emergency support from the Bank of England, and the first run on a British bank since 1866.

The dependence on short-term funding was a number anyone could track.

Key Risk Indicators are built precisely for this.

A KRI is a forward-looking metric that warns you a risk is building, before it becomes a loss.

It is not a KPI. A KPI tells you how well you are doing. A KRI tells you how exposed you are becoming.

A good one has thresholds, often a traffic light, and each threshold is tied to an action decided in advance.

Northern Rock had a textbook indicator staring at it. It would have been flashing amber, then red, as the funding model stretched.

What was missing was the link from the red light to an action.

A red light nobody is required to respond to is just decoration.

So for your biggest risk, name one indicator that would rise before it hits.

Then ask the real question. What happens automatically when it turns red?

If the answer is "we discuss it," you do not have a control. You have a conversation.

The value of a KRI is never the measuring. It is the response the threshold compels.

Sources: UK Parliament: Treasury Committee, The run on the Rock, 2008; UK Parliament: Treasury Committee, Northern Rock's business model.

↑ All 20 models

Basel Operational Risk: The person who takes a risk never checks it. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 14

Basel Operational Risk

The person who takes a risk never checks it

Barings was Britain’s oldest merchant bank. More than two centuries old.

In 1995, one trader destroyed it.

Nick Leeson, in Singapore, took large unauthorised bets and hid the losses in an error account numbered 88888.

The fatal weakness was structural. He controlled both the trading desk and the back office meant to check him.

No independent eye. The hidden losses reached around 827 million pounds, more than the bank’s entire capital.

Barings was sold to ING for one pound.

The Basel operational risk principles insist on the plainest control there is, and the one Barings did not have.

Segregation of duties.

The person who takes a risk is never the person who checks it.

Basel breaks operational risk into recognisable categories, internal fraud, external fraud, process failures, systems failures, and presses hard on those basic disciplines.

Its deeper message is worth remembering. The most dangerous losses often come not from the market moving against you, but from your own broken processes and unwatched people.

There was no clever market bet at Barings. There was a person who both placed the trades and checked them, which meant nobody checked them.

So here is the question that never goes out of date.

Where in your organisation does one person both take a risk and check it?

That is a Barings waiting to happen. Find it this week.

Sources: Reserve Bank of Australia: lessons of the Barings collapse, 1995; BIS: Sound management of operational risk, summary; FDIC: Supervisory Insights, operational risk management, 2006.

↑ All 20 models

Monte Carlo Risk Quantification: Thousands of runs to reveal the full range of outcomes. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 15

Monte Carlo Risk Quantification

Thousands of runs to reveal the full range of outcomes

Long-Term Capital Management had two Nobel laureates and models that said its losses were near-impossible.

The positions were diversified. The maths was elegant. The leverage was enormous.

In 1998, Russia defaulted, markets panicked, and the diversification the models relied on simply vanished.

Everything moved the same way at once. The improbable and the catastrophic arrived together.

The Federal Reserve Bank of New York organised a recapitalisation of around 3.6 billion dollars.

Monte Carlo risk quantification is one of the most powerful risk tools there is. LTCM is its warning.

Instead of a single best guess, you represent uncertain inputs as probability distributions, then run the model thousands of times.

The result is not one answer. It is the full range of possible outcomes, including the tail, the rare and severe results a single estimate would never reveal.

Used well, it shows you the shape of what might happen.

Used carelessly, it produces confident, precise-looking numbers built on assumptions that do not hold.

LTCM’s models assumed roughly normal distributions and stable correlations.

Both held in ordinary times. Both shattered in a crisis, as correlations jumped to one.

So for your most quantified risk, ask this.

What does the model assume about correlations in a crisis? And what happens to the answer if everything moves together?

Read the tail, not the average.

A Monte Carlo model is only as honest as its distributions and its correlation assumptions, and those are exactly what break when you need them most.

Sources: Federal Reserve History: near failure of LTCM; Winter Simulation Conference: simulation in finance, 2002.

↑ All 20 models

The Fraud Triangle: Pressure, opportunity and rationalisation. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 16

The Fraud Triangle

Pressure, opportunity and rationalisation

Some Wells Fargo staff said they faced targets of up to twenty products a day.

Miss the numbers, and you were coached, then written up, then gone.

So staff made the numbers.

Around 1.5 million deposit accounts and over half a million credit cards that customers may never have asked for. Later estimates reached 3.5 million potentially unauthorised accounts.

The bank fired roughly 5,300 people, mostly the junior staff at the windows. The targets that drove it stayed in place until October 2016.

The bill included 185 million dollars in 2016, then a further 3 billion in 2020.

The Fraud Triangle explains exactly how ordinary, honest people ended up doing this.

Donald Cressey found three conditions, all present, whenever a previously honest person commits fraud.

Pressure: the motive. A target you cannot hit honestly. Opportunity: the open door. A weak control, a gap in supervision. Rationalisation: the story you tell yourself. Everyone does it. The customer probably wants it anyway.

Here is the uncomfortable message for leaders.

You often cannot remove pressure entirely, and you can never control the stories in people’s heads.

But opportunity is yours to close.

And if you crank up pressure and leave opportunity open, you are not unlucky when fraud appears.

You built the conditions for it.

So look at your most aggressive target this week.

Can it be hit honestly by everyone expected to hit it? Or does it quietly require corners to be cut?

Wells Fargo answered that question with up to 3.5 million accounts.

Sources: US Department of Justice: Wells Fargo $3 billion settlement, 2020; CFPB: Wells Fargo fined over unauthorised accounts, 2016; SEC filing: Wells Fargo expanded account review, 2017.

↑ All 20 models

The Fraud Diamond: The triangle plus the insider’s capability. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 17

The Fraud Diamond

The triangle plus the insider’s capability

Société Générale lost around 4.9 billion euros to the trading of one man, Jérôme Kerviel.

He built enormous bets and hid them behind fictitious offsetting trades.

What made him so effective was not nerve alone.

Before moving to the trading desk, Kerviel had worked in the bank’s middle and back office. The very functions meant to check the traders.

He knew exactly how the surveillance worked. And therefore exactly how to slip past it.

The Fraud Diamond adds the piece the Triangle underplays.

Pressure, opportunity and rationalisation set the stage. But a large, sustained fraud also needs one more thing: capability.

The position, the knowledge, the confidence and the skill to exploit an opportunity and, crucially, to conceal it over time.

This is why the same open door leads to fraud in one person’s hands and not another’s.

Opportunity is a feature of the system. Capability is a feature of the person.

The most dangerous frauds happen when a capable insider, someone who understands the controls from the inside, meets an opportunity a less knowledgeable person could not have exploited.

Controls designed for the average employee can be transparent to the insider who helped build them.

So ask this.

Who in your organisation has moved from a control function into a risk-taking role?

And do your controls quietly assume they do not know how the controls work?

For your highest-risk role, is there any check that does not rely on the same system knowledge the insider already has?

If not, you are watching them with a mirror they can see around.

Sources: Risk.net: Back-office savvy aided SG fraud, 2008; NBC News (AP): Kerviel convicted over SocGen losses, 2010; The CPA Journal: The Fraud Diamond, Wolfe and Hermanson.

↑ All 20 models

Kohlberg’s Stages of Moral Development: Three levels of moral reasoning, in people and cultures. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 18

Kohlberg’s Stages of Moral Development

Three levels of moral reasoning, in people and cultures

Enron had a code of ethics.

It ran to sixty-four pages.

The company was celebrated for innovation, and its executives spoke fluently about values.

In 2001 it collapsed in one of the largest accounting frauds in history, wiping out around 74 billion dollars of shareholder value and taking its auditor down with it.

The document existed. The moral reasoning underneath it did not.

Enron’s real, lived question was never "is this right." It was "will we be caught."

Kohlberg mapped how moral reasoning develops in a person, in three broad levels. The same lens works on whole cultures.

Pre-conventional: right and wrong are about consequences to yourself. Avoid punishment. Chase reward. Conventional: follow the rules because they are the rules. Post-conventional: do the right thing because it is right, and challenge a rule that produces a wrong outcome.

A culture stuck at the pre-conventional level obeys only to avoid getting caught, and will break any rule it thinks it can hide.

Enron was a pre-conventional culture wearing a conventional costume.

The sixty-four page code was a rules-level artefact. It was worthless, because the reasoning beneath it never rose above "will we be caught."

Here is the lesson, and it is a hard one.

You cannot document your way to an ethical culture.

If the lived question is about getting caught, no code, however long, will change the answer.

So ask yourself.

When a decision is borderline in your organisation, what question does everyone really ask? Will we be caught, is it allowed, or is it right?

The honest answer tells you your real ethics, no matter what the code says.

Sources: US Senate: Role of the Board in Enron's Collapse, 2002; US Department of Justice: Arthur Andersen verdict, 2002; Britannica: Kohlberg's stages of moral development.

↑ All 20 models

Just Culture: Support error, coach at-risk habits, hold recklessness to account. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 19

Just Culture

Support error, coach at-risk habits, hold recklessness to account

At Mid Staffordshire, a drive to hit targets and cut costs produced appalling patient care.

Staff could see it. But raising concerns was unwelcome and unsafe.

The Francis inquiry in 2013 described a culture that put targets and reputation ahead of patients, and left staff afraid to speak up.

The failure was not a shortage of rules.

It was a culture in which the truth could not travel upward.

Just Culture answers a hard question. When something goes wrong, how do you respond so people keep telling you the truth, while still holding genuine recklessness to account?

A blame culture drives problems underground. Report an error, get punished. A blame-free culture lets real recklessness off the hook.

Just culture threads between them, sorting behaviour into three kinds.

Honest human error, the slip anyone could make: met with support and a fix to the system. At-risk behaviour, a bad habit nobody saw the danger in: met with coaching. Reckless behaviour, a conscious disregard of obvious, serious risk: held to account.

The aim is a culture where people feel safe to report, because that is the only way an organisation learns before harm.

Mid Staffordshire is that culture’s absence, in its most painful form.

Fear and blame meant the honest reporting that could have exposed failing care never reached the people who could fix it.

So when something went wrong in your organisation last, ask this.

Did you respond to the behaviour, or to the outcome? Would an honest reporter have felt safe?

One unjust punishment can silence an entire organisation. People are always watching how you react to bad news.

Sources: UK Government: Francis inquiry executive summary, 2013; AHRQ PSNet: in conversation with David Marx on just culture.

↑ All 20 models

The Conduct Risk Framework: From “did we break a rule” to “is this a fair outcome”. Illustrated card from Key Compliance Models.

Key Compliance Models · No. 20

The Conduct Risk Framework

From “did we break a rule” to “is this a fair outcome”

British banks sold payment protection insurance for years.

It was hugely profitable. It was also mis-sold on an industrial scale.

Sold to people who would never be able to claim on it. Who did not need it. Who did not even realise they had been signed up.

Everything about the sales process pushed the product. Almost nothing checked whether it was right for the customer.

The redress became the largest consumer compensation exercise in British history. Banks paid out over 38 billion pounds.

Conduct risk is the framework that would have caught PPI before it became a scandal.

It makes one crucial shift. From a narrow question, did we break a rule, to a broader one, is this a fair outcome for the customer.

A firm can comply with the letter of every rule and still treat its customers badly. Conduct regulation exists to close that gap.

It looks at the drivers of behaviour, not just the paperwork. The incentives. The culture. The design of the product. And above all, the actual outcome the customer experiences.

PPI had every driver pointing the wrong way. Incentives rewarded the sale. The product was hard to claim on. The culture prized volume.

And the customer outcome, the thing conduct risk puts at the centre, was poor for millions.

So for your most profitable product, ask the question the PPI sales floors never did.

What is the real outcome for the least sophisticated customer who buys it?

If your incentives ever reward a sale that is not in the customer’s interest, that is your conduct risk.

Name it before a regulator does.

Sources: FCA: PPI complaints deadline final report; FCA: monthly PPI refunds and compensation; Gowling WLG: is your conduct risk framework FCA compatible?.

↑ All 20 models

From the book

All books →
Cover of Key Compliance Models by Stefan Gauci Scicluna

Compliance and risk

Key Compliance Models

The book covers fifty-eight models of governance, risk and compliance. Every one comes with a real case and its sources. What you see on this page are short versions of twenty of them.

View on Amazon →

Related

If one of these models describes a gap you recognise, this is where to go next.

Service

Compliance management

I build compliance and risk frameworks to ISO 37301 and ISO 31000. I recommend starting with a Diagnostic of two or three days.

Insights

Business Insights

Both sets of posts start here. All forty models are listed on the one page.

Enquire

Start a conversation

Tell me who you are and what is pressing on you. I will reply on whether I can help and what it would involve.

Common questions

What is a compliance model?

It is a set way of organising how a business meets its obligations and keeps its risks under control. Some models say who is responsible for what. The Three Lines Model is one of those. Some describe a whole system, as COSO does for internal control and ISO 31000 does for managing risk. Others, like the Fraud Triangle and Just Culture, explain why people behave as they do.

Which compliance model should a small or mid-sized organisation start with?

This is my opinion. Begin with two. The first is the Three Lines Model. Use it and you have to name the owner of every risk, and name whoever checks on that owner. The second is the loop in ISO 31000. You identify a risk, analyse it, evaluate it and treat it. Follow it and you end up with a risk register that people use. Most of the other models build on those two.

Are the company cases real?

Yes. Each case names a real organisation. The figures were checked in October 2026. Wherever a regulator, a prosecutor, a parliamentary committee or an official inquiry had published on the case, that document was the one used. You will find the links under each post.

Is this legal advice?

No. The posts explain how the models work and what the cases show. They do not replace your regulator’s guidance or the advice of a lawyer.

These posts are written by Stefan Gauci Scicluna and reflect his own analysis, with sources shown. They are general explanation and not advice on your situation. Company cases are described from published sources as they stood when checked in October 2026.

Make an enquiry