Enterprise Risk Management at Wells Fargo During COVID-19
This paper examines enterprise risk management (ERM) at Wells Fargo during the COVID-19 pandemic. It begins by contrasting ERM with traditional risk management, highlighting ERM's holistic, macro-level approach versus the departmental focus of conventional methods. The paper then analyzes hazard, financial, operational, and strategic risks Wells Fargo faced during the pandemic, followed by a SWOT analysis of the bank. It explores the relationship between organizational culture and ERM, evaluates current and potential profit opportunities, and proposes two ways auditors can incorporate ERM into company audits. The paper also discusses financial derivatives as both risk management and speculative instruments, and concludes by examining how competitor firms — PNC, Goldman Sachs, and JP Morgan — implement ERM practices that Wells Fargo could learn from.
- Introduction: ERM context for Wells Fargo during COVID-19
- ERM vs. Traditional Risk Management: Macro vs. micro risk management approaches compared
- Hazard, Financial, Operational, and Strategic Risks: Four risk categories facing Wells Fargo analyzed
- SWOT Analysis of Wells Fargo: Strengths, weaknesses, opportunities, and threats assessed
- Organizational Culture and ERM: How culture shapes Wells Fargo's risk posture
- Profit Opportunities and Derivatives in Risk Management: Current profits, forbearance concerns, and derivative strategies
- How Leading Companies Implement ERM: PNC, Goldman Sachs, and JP Morgan ERM benchmarking
- Conclusion: ERM gaps and recommendations for Wells Fargo
✍️ How to write this paper — guide, tools & examples ▾
What makes this paper effective
- The paper systematically addresses a multi-part analytical framework — ERM theory, risk categories, SWOT, culture, profit, auditing, derivatives, and competitor benchmarking — and executes each section with specific, well-grounded evidence from Wells Fargo's real conduct.
- The recurring reference to Wells Fargo's ethical failures (the 2016 fake-account scandal, unauthorized forbearance) gives the argument a consistent real-world anchor and prevents the analysis from becoming overly abstract.
- Sources are varied and appropriately matched — academic texts for theory (Kaplan & Mikes, Sweeting), professional publications for practice (Hall, Beasley), and journalism for current events — demonstrating source diversity appropriate to an applied business paper.
Key academic technique demonstrated
The paper effectively uses comparative analysis to build its theoretical argument. By contrasting ERM with traditional risk management across multiple dimensions — scope, orientation, decision-making role, and responsiveness — the author gives readers a clear framework before applying that framework to a specific firm. This technique allows complex institutional concepts to be grounded in observable corporate behavior.
Structure breakdown
The paper opens with a clear multi-point roadmap in the introduction, then proceeds through each promised section in order. Sections on risk types are divided into labeled subsections (Hazard, Financial, Operational, Strategic), keeping dense content organized. The SWOT analysis uses the standard four-quadrant structure. The paper closes with competitor benchmarking before a brief conclusion that calls for improvement — a standard but effective analytical structure for an applied business case study.
Introduction
As Beasley (2020) points out, enterprise risk management (ERM) is especially needed during the COVID-19 pandemic because of the "number of different, but interrelated risks spread all across most organizations" (p. 2). COVID-19 is not just a factor that has impacted one business or industry — it has impacted all businesses and all industries in different ways. Grocery chains like Kroger, for instance, have seen increased demand, while restaurants have seen business dry up due to mandated quarantine orders. Small business owners and large corporations alike have filed for bankruptcy. All of this impacts the banking sector and Wells Fargo specifically, given its role in managing loan products, using interest rates to attract savers, and offering investment advice.
"No single risk associated with the COVID-19 pandemic crisis can be managed in isolation," as Beasley (2020) points out (p. 2). This means that from an ERM perspective, the problem must be approached comprehensively, with risk understood at the macro level. This paper provides: (1) a critical analysis, including a comparison and contrast of ERM versus traditional risk management; (2) a discussion of hazard, financial, operational, and strategic risks; (3) a SWOT analysis of Wells Fargo; (4) an examination of the relationship between organizational culture and ERM; (5) a discussion of risk in terms of current and potential profit opportunities; (6) two specific ways in which auditors can incorporate ERM into the company's audits; (7) a discussion of the role of financial derivatives as both a risk management and a speculative tool; and (8) a discussion of how three leading companies — one domestic and two international — implement enterprise risk management.
ERM vs. Traditional Risk Management
ERM is a plan-based business strategy whose purpose is to identify, evaluate, and reduce the impact of potential dangers, threats, and challenges that could be catastrophic or damaging for the organization. ERM allows the firm to reduce exposure to these risks by preparing for them through safety mechanisms, altering strategy to avoid them, or developing a plan to meet these challenges directly. The aim of ERM is to address risk holistically, comprehensively, and from the macro perspective, enabling the firm to pursue its goals and objectives without unnecessary constraint (Sweeting, 2017). Managing risk effectively depends upon an organization's ability to identify and deal with relevant risks while simultaneously understanding and preparing for accepted risks that cannot be avoided if the organization is going to implement its business plan. From this perspective, strategic risk is accepted risk that comes with the opportunity to do business (Kaplan & Mikes, 2012).
ERM is essentially an extension of traditional risk management. In traditional risk management, risk is analyzed and monitored departmentally within an organization. With ERM, risk is analyzed and monitored from an organizational standpoint, and all the risk factors an organization faces are interpreted from this comprehensive macro viewpoint. In traditional risk management, the focus is on pure risk and every risk is viewed as its own separate and distinct problem. With ERM, risk is more comprehensively addressed as part of an overall strategy (Ogutu, Bennett & Olawoyin, 2018).
Traditional risk management looks at the micro; ERM looks at the macro. Traditional risk management issues might include missed opportunities with service partners or lack of innovation. ERM focuses more on linking operational risk with strategic risk management and must emphasize transparency, communication among departmental heads, and collaboration. This is one reason why organizational silos are so damaging from an ERM perspective: they create walls and barriers, foster distinct subcultures, and generate a spirit of contention and distrust where collaboration and communication are needed (Lundqvist, 2014).
As Kaplan and Mikes (2012) point out, ERM examines the mission, values, and boundaries of the organization in order to assess and manage risk. It is not simply a matter of the shipping department looking at suppliers or the accounting department reviewing the audit board. It requires the various departments to work together, discussing plans and assisting organizational leaders in identifying strengths and weaknesses and in determining how best to utilize resources. In the case of Wells Fargo, there have been many occasions when the company should have taken a macro view of risk before initiating a strategy. Its attempt to collect commission fees from customers without their knowledge was a quick way to enhance revenue, but an ERM manager would have quickly recognized this as short-sighted, unethical, and highly risky. Once customers realized how they were being taken advantage of, the company faced severe liability. Its brand appeal was damaged, and the firm's future guidance, share price, and reputation declined. ERM looks beyond the risks a single department faces and considers the organization as a whole.
With traditional risk management, risk is not the driver of decision-making at the executive and strategic levels. Instead, other inputs are analyzed to create strategy, which is then passed down to lower-level department heads who must tailor their operations accordingly. Risk management in this case is reactionary rather than proactive. In ERM, risk management is proactive and used to drive strategy development at the upper levels of organizational management.
ERM therefore adopts a more comprehensive view of risk. Instead of treating each risk as separate and distinct, it examines the interconnected nature of risk and considers how one response impacts other parts of the organization. Traditional risk management adapts risk mitigation plans to the strategy; ERM adapts the strategy to risk mitigation plans. The scope of ERM is larger and more holistic.
Hazard, Financial, Operational, and Strategic Risks
Hazard Risk
The concept of moral hazard holds that an action may be taken as long as the associated risk can be transferred to a third party. Hazard risk in the financial industry has historically been associated with mortgage-backed securities, collateralized debt obligations, and credit default swaps. The risk of writing loans to high-risk home buyers was mitigated as long as the loans could be bundled and sold to investors — a dynamic that helped fuel the home-buying spree leading up to the 2008 global economic crisis. The bubble burst when borrowers began defaulting on loans and the price of credit default swaps skyrocketed. Moral hazard came back to harm a number of high-profile banks that were left holding billions in mortgage-backed securities for which there was no longer any market (Lewis, 2010).
For Wells Fargo, hazard associated with the coronavirus pandemic arises from the same premise: loans made to high-risk consumers or businesses that have since shuttered their doors have caused a rise in defaults and an accumulation of unwanted derivatives and securities. For many homeowners, the pandemic led to unemployment, with millions filing for government assistance as the U.S. economy shut down for two months and remained uncertain throughout the remainder of 2020. Mortgage payments have stopped in many cases, and government relief has been insufficient to address the needs of many families. In response to coronavirus-caused late payments, Wells Fargo began "granting 90-day forbearance to any mortgage customer who requests assistance. Customers who contact them for assistance won't be charged late fees or have their credit report impacted by the suspension," according to the bank's investor relations team (Steffenhagen, 2020). However, the critical question remains: what happens when the 90 days are up? There is no clear indication of how many homeowners will default completely on home loans or how over-leveraged borrowers have become.
Even before the pandemic, Wells Fargo had a poor record of managing moral hazard. The company created fake PIN numbers and email accounts to enroll customers in online banking services in order to collect a commission — without the customers' knowledge. The bank was protected against risk, but the counterparty was incurring costs unknowingly. The bank was fined for this egregious violation of its fiduciary duty, and its reputation was severely tarnished, requiring a major public relations initiative to rebuild the firm's brand.
Financial Risk
The pandemic led to the CARES government bailout program, which allowed borrowers to take out loans that would be forgiven if used for payroll. However, banks like Wells Fargo determined that these loans carried significant financial risk. One major concern was that "lenders will be responsible for preventing fraudulent claims by verifying borrower eligibility, which is determined by a few measures including the borrower's number of employees and its average monthly payroll costs" (Schroeder, 2020). Wells Fargo, in particular, was concerned about facing regulatory penalties down the road if money lent under the government program went to fraudulent borrowers.
Wells Fargo was therefore extra cautious in how it disbursed money under the program, requiring borrowers to apply directly through the bank. For this reason, it is not surprising that watchdog groups criticized Wells Fargo for granting only one loan to a Black-owned business under the program — an outcome that raised concerns about racially discriminatory lending practices (Derysh, 2020). As Olenick (2020) points out, the average loss on subprime loans during the 2008 crisis was 73%, so Wells Fargo was understandably hesitant to repeat past mistakes. From the bank's point of view, "mitigating loss is a legal requirement and it's also a good business practice" (Olenick, 2020). To emerge from the pandemic without a major financial loss, the bank adopted stricter lending standards — even at the cost of criticism from progressive groups.
Operational Risk
Operational risk involves overseeing fiduciary and investment risk, external fraud, transaction processing and execution (TPE) risk, safety and physical security (SPS) risk, payments risk, implementation risk, and data management risk. In the face of the coronavirus pandemic, Wells Fargo faced operational risk in terms of investment risk — loans still on the firm's books that may not be repaid — and payment risk. Liquidity shortages were already a factor in the lending markets leading up to the March 2020 shutdown, and Wells Fargo was forced to cut its dividend following the Federal Reserve's stress test in 2020 (English, 2020). Operational risk areas recognized by Wells Fargo include:
Capital adequacy risk — the risk of holding insufficient capital to absorb unexpected losses under stress or to support future business growth. This was the risk the Federal Reserve identified as most pressing for Wells Fargo during the pandemic, which is why the central bank required the firm to reduce its dividend payments to shareholders as a means of preserving sufficient capital.
New business initiatives risk — risks associated with a product change or significant business growth initiatives pursued to grow the business and serve new and existing customers. Because of the pandemic, Wells Fargo was forced to pause such initiatives given the high degree of economic uncertainty.
Strategic Risk
Strategic risk at Wells Fargo refers to "the risk to earnings, capital, or liquidity arising from adverse business decisions, improper implementation of strategic initiatives or inadequate responses to changes in the external operating environment" (Wells Fargo, 2020). This risk can include strategic corporate transaction risk — "risks associated with mergers and acquisitions, joint ventures, and divestitures resulting from inadequate decision making, lack of due diligence, failure to align the transaction with the strategic plan, and lack of an effective transition of the acquired or divested business" (Wells Fargo, 2020). It can also include strategic planning risk, defined as risks associated with the firm's potential inability to engage in effective strategic decision making, such as decisions on offering new products, entering new business models or geographies, or addressing changes in the competitive market environment. Poor strategic decisions can lead to "decline in market share or profit" (Wells Fargo, 2020). The firm's attempt to collect unauthorized fees from customers was a major strategic error, costing the firm billions in fines and reputational damage. The strategic risk linked to COVID-19 has made the bank more careful about monitoring loan recipients in accordance with its capital requirements — in short, the firm is engaging in more robust ERM this time around.
Organizational Culture and ERM
Organizational culture is the heart and soul of any business, and its relationship to ERM is therefore critical. ERM is about adopting the macro perspective to manage risk, and culture inherently plays a part in shaping that perspective. This can be seen clearly in Wells Fargo's fraudulent services scandal, in which the bank charged unsuspecting customers for services they had not requested. The pervasive "get rich quick" culture at Wells Fargo at the time was reminiscent of Enron's culture before that energy company collapsed. Wells Fargo has since had to redevelop its organizational culture in an effort to root out the unethical spirit that had taken hold in its management system.
When an organizational culture is grounded in sound ethical principles and promotes moral conduct, the company will naturally develop a more robust ERM framework. ERM is, in this sense, an extension of the firm's organizational culture. This can again be seen with Wells Fargo. Since its 2016 scandal, the company has adopted a more thoughtful and deliberate posture. When the federal government pressured banks to distribute PPP loans rapidly in response to COVID-19, Wells Fargo chose a holistic approach informed by its macro perspective: disbursing loans indiscriminately could result in hundreds of millions of dollars in losses if applications proved fraudulent or borrowers turned out to be uncreditworthy. The company therefore adopted a careful and cautious approach, making only loans it could verify in order to reduce risk. The "get rich quick" culture that led to the 2016 scandal had been replaced by one emphasizing prudence and consideration — and this shift was visible in the pragmatic way the bank approached lending under the CARES program.
Conclusion
Wells Fargo's approach to ERM could stand to improve significantly. The bank lacks adequate assessment of reputation risk and fiduciary risk, as demonstrated by its continued exposure to scandals such as the 2016 fraud case and its ongoing exploitative use of forbearance. Wells Fargo could use derivatives to protect against numerous categories of risk and should pursue that option rather than continue risking its reputation by acting against the interests of its customers. Adopting a genuinely holistic ERM framework — one that treats ethical conduct and reputational integrity as core risk factors — is essential if the bank is to build lasting trust and long-term financial stability.
References
Beasley, M. (2020). How to leverage ERM principles to better respond to COVID-19-related risks. ERM Professional Insights.
Derysh, I. (2020). Watchdog questions why Wells Fargo reported giving only one large PPP loan to a Black-owned business. Salon.
English, C. (2020). Wells Fargo forced to cut its dividend after Fed stress test. Here's what other banks did. Barron's.
Hall, J. (2007). Internal auditing and ERM: Fitting in and adding value. The Institute of Internal Auditors.
Kaplan, R. & Mikes, A. (2012). Managing risks: A new framework. Harvard Business Review, 3.
Lewis, M. (2010). The Big Short. W. W. Norton.
Lundqvist, S. (2014). Abandoning silos for integration: Implementing enterprise risk management and risk governance. Lund University.
Morgenson, G. (2020). More Wells Fargo customers say the bank decided to pause their mortgage payments without asking. NBC News.
Ogutu, J., Bennett, M. & Olawoyin, R. (2018). Closing the gap. Professional Safety, April 2018.
Olenick, M. (2020). How banks can avoid a repeat of the 2008 foreclosure crisis. Harvard Business Review.
Riley, P. (2009). ERM — capturing the upside. Actuaries Institute of Australia.
Sartor, P. & Dall, C. (2020). ERM. PNC Financial Services.
Schroeder, P. (2020). Banks cite liability risks, may not participate in coronavirus lending plan. Insurance Journal.
Steffenhagen, M. (2020). How to stop paying your mortgage during the pandemic. Salon.
Sweeting, P. (2017). Financial enterprise risk management. Cambridge University Press.
Wells Fargo. (2020). Risk management framework.
Create your account
Always verify citation format against your institution’s current style guide requirements.