Argus Pro

There before you need us

  • Platforms
    • Aegis Compass
    • NexEdge
    • Argus Pro Assess
  • Frameworks
    • AFC
    • CDOR
    • AI Governance
    • ESG (coming soon)
  • Sectors
    • Banking & Financial Services
    • Insurance & Reinsurance
    • Legal
    • Professional Services
    • Crypto & Digital Assets
      • CASP MiCA Readiness
    • Football & Sport
    • Other Regulated Sectors
  • Culture & People Risk
    • Workshop Suite
  • Insights
    • Future-Fit Crypto Compliance
  • About
    • About Argus Pro
    • Our Partners
    • Contact
  • Platforms
    • Aegis Compass
    • NexEdge
    • Argus Pro Assess
  • Frameworks
    • AFC
    • CDOR
    • AI Governance
    • ESG (coming soon)
  • Sectors
    • Banking & Financial Services
    • Insurance & Reinsurance
    • Legal
    • Professional Services
    • Crypto & Digital Assets
      • CASP MiCA Readiness
    • Football & Sport
    • Other Regulated Sectors
  • Culture & People Risk
    • Workshop Suite
  • Insights
    • Future-Fit Crypto Compliance
  • About
    • About Argus Pro
    • Our Partners
    • Contact

Culture Is a Compliance Control. Is Yours Working?

Every major compliance failure of the last decade exposes the same blind spot: culture and people risk. Firms wrote the policies, built the frameworks, ran the training. Yet between the rule and the moment someone had to act on it, something still broke down.

That is a people problem. And it is the most underestimated risk in your compliance environment.

Read Our Latest Insights
Speak with a Partner

$17.25bn

413 operational and non-financial risk loss events totalling US$17.25bn in 2024. In 2025, conduct remained both the most frequent and the most severe risk type.

ORX

 

£100bn+

Estimated annual cost of money laundering to the UK economy

National Crime Agency

$4.3bn

Criminal penalty paid by Binance after regulators concluded it had prioritised growth over compliance.

US DoJ

The question is not whether your organisation can afford to invest in culture. It is whether it can afford not to.

Culture and People Risk: When Controls Fail

Across financial crime, cybersecurity, operational resilience and ESG, the enforcement record tells one story. Internal controls existed. Concerns were raised. The culture did not allow those concerns to land. By the time the regulator arrived, the cost had already been paid.

Here is the pattern at a glance.

Wells Fargo

$3bn+ in penalties

Performance at all costs. Thousands who raised concerns were dismissed. Internal reports flagged the pressure to cheat as early as 2004.

Binance

$4.3bn criminal penalty

Growth prioritised over compliance. More than 100,000 suspicious transactions went unreported, including links to ransomware and sanctions breaches.

CrowdStrike

$5.4bn estimated impact

Engineers flagged rushed releases for more than a year. A single faulty update took down 8.5 million devices in July 2024.

DWS

$19mn + €25mn in fines

The chief sustainability officer raised concerns internally. She was dismissed. Regulators eventually listened.

In each of these cases, the written framework was not the problem. The culture around it was. Controls do not fail in isolation. They fail when the people responsible for running them cannot, or will not, act on what they see.

The Human Factor in Every Compliance Failure

Culture and people risk shows up first as a question of psychological safety. In other words, people will raise concerns only if they feel safe doing so. This is not a soft issue. It is the setting in which every compliance control either works or fails.

Think about what culture really decides in your organisation:

  • Whether an AML analyst flags a transaction that their manager seems comfortable with;
  • How quickly a compliance officer escalates findings that embarrass a profitable business line;
  • The engineer who pushes back on a release that is not ready.
  • An ESG lead challenging a commitment that the data cannot support.

In each case, the decision is shaped not by policy, but by culture.

Culture and people risk

Meanwhile, inclusion sits alongside psychological safety. One is about whether people feel safe to speak. The other is about whether colleagues listen when they do.

As a result, diverse teams spot anomalies, challenge accepted narratives and catch patterns that homogeneous teams miss. However, where leaders routinely dismiss their concerns, organisations quietly weaken their own early warning systems.

The Data Behind the Silence

  • 43% of frauds were detected by tips.
  • More than half of all tips come from employees. (ACFE, 2024)
  • The FCA received 1,131 new whistleblowing reports in 2024/25.
  • Culture ranked as the fourth most common issue.
  • Over half of completed reviews led to direct regulatory action. (FCA Prescribed Persons Annual Report 2024/25)

High reporting volumes, in a culture where people feel safe, are not a sign of dysfunction.
They are a sign of organisational health.

Regulators Are Watching Culture

UK financial services firms should be in no doubt. Culture and people risk now sits inside the regulatory perimeter, and the perimeter is widening.

First, SM&CR created personal accountability for senior leaders. Then, Consumer Duty elevated culture as a supervisory lens. Most recently, the FCA has begun treating non-financial misconduct, including bullying, harassment and inaction on concerns, as a red flag for deeper cultural failure. As a result, supervisory cases tagged to non-financial misconduct have risen every year: 123 in 2022, 168 in 2023, 229 in 2024.

FCA Consumer Duty (2023)

Firms must deliver good outcomes, not just document processes. Culture is a supervisory lens.

SM&CR

Personal accountability for senior leaders for the cultures they create and the conduct they enable.

FCA Non-Financial Misconduct

Bullying and harassment treated as red flags for broader cultural failure. NFM rules extend to non-banks from September 2026.

EU AI Act

Human oversight, bias controls and accountable AI governance now regulated. Penalties up to €35m or 7% of global turnover.

From the Content Library

The articles and white paper below develop this narrative in depth. Each examines a different dimension of culture as a compliance control.

Argus Pro Recognised in the 2026 Global State of RegTech Report
AFC AI Governance CDOR Crypto Culture IFR Legal

Argus Pro Recognised in the 2026 Global State of RegTech Report

13 May 2026

The Global State of RegTech 2026 by Parker & Lawrence Research and RegTech Analyst has named Argus Pro a leader in Compliance …

Read more
Culture Is Compliance: Why Inclusion and Psychological Safety Are Your Best Defences Against Financial Crime
AFC Culture White Paper

Culture Is Compliance: Why Inclusion and Psychological Safety Are Your Best Defences Against Financial Crime

9 May 2026

  Guest Article by Jen Davidson  |  Culture and Inclusion Expert Inclusion and psychological safety sit at the heart of every effe…

Read more
Financial Crime Compliance Culture: Why Systems Fail When Culture Does Not Hold
AFC Culture

Financial Crime Compliance Culture: Why Systems Fail When Culture Does Not Hold

7 May 2026

    Financial crime compliance culture sits at the heart of every major control failure I have seen. After two decades on some of …

Read more
Whistleblowing in Financial Services: When Speaking Up Falls Short
Culture

Whistleblowing in Financial Services: When Speaking Up Falls Short

7 May 2026

    Whistleblowing in financial services depends on far more than a written policy. Most regulated firms run a speak-up channel. H…

Read more
Culture in Regulated Organisations: What Recent Exam Fraud Cases Really Reveal
Culture

Culture in Regulated Organisations: What Recent Exam Fraud Cases Really Reveal

7 May 2026

    Culture in regulated organisations is what fines actually expose, even when headlines focus on numbers. Regulatory fines have …

Read more
Rules and Guidance Will Never Be Enough
Culture

Rules and Guidance Will Never Be Enough

29 July 2024

Without CultureOver the last decade, many organisations have faced high-profile cases of non-compliance with financial regulations…

Read more

No insights found in this category yet.

How Argus Pro Manages Culture and People Risk

Thought Leadership

Rigorous, practitioner-led analysis of culture as a compliance control across anti-financial crime, cybersecurity, operational resilience and ESG. Content that connects enforcement history to practical action.

Read our Insights

Workshops

Seven specialist one-day workshops for regulated financial services firms. From foundational culture awareness to board-level governance. Open cohort and in-house formats.

Explore the Workshop Suite

 

Regulatory Intelligence

Our compliance frameworks cover Anti-Financial Crime (AFC), Cybersecurity & Digital Operational Resilience (CDOR), and AI Governance. Culture sits at the intersection of all of them, and assessment findings can directly inform your workshop priorities.

Explore our Frameworks

Meet the Experts

Jen Davidson  |  Culture and Inclusion Expert

Jen Davidson is a specialist in organisational culture, inclusion, and psychological safety, with a particular focus on how these disciplines intersect with compliance, risk, and financial crime prevention. Jen works with leadership teams, boards, and compliance functions to help organisations move beyond policy and build the cultural conditions in which people genuinely feel safe to speak, challenge, and act with integrity. Her work bridges the often-siloed worlds of DEI and financial crime, making the case that the two are not separate agendas, but deeply and consequentially connected.

Mike Falvey | Partner, Argus Pro LLP

Mike brings more than 25 years of senior leadership across financial services, government and regulated industries. He is the former Chief People Officer and Director General at HMRC, and was formerly a KPMG Partner with a client portfolio spanning FTSE 100 and public-sector organisations. He has advised UK and overseas Ministers on compliance culture and the behaviours that protect organisations from regulatory failure. Mike is the strategic and board-level voice behind Argus Pro’s Culture & People Risk capability.

Mike Falvey Partner Argus Pro

Start the Conversation

Whether you are building a speak-up culture from the ground up, addressing a gap identified in a regulatory review, or preparing your board to take culture and people risk seriously, we can help.

Speak with a Partner
Contact Us

Email: info@arguspro.co.uk

Call: 020 3996 3161

27 Old Gloucester St, London, WC1N 3AX

48 West George St, Glasgow, G2 1BP

Follow Us

Data Policy

Copyright © 2026 All Rights Reserved.

Website designed by FirstFound

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT