Strategy Fails Without Communication Clarity

I first saw a particular kind of organisational dysfunction that looks, from the outside, like productivity. People are at their desks. Emails are being answered. Status updates are being filed. If you walked through the office or scrolled through the project management tool, you would see motion everywhere. You would probably leave satisfied that the function was operating as intended. It wasn’t. It was spinning. I have seen this pattern more than once across my career, but the version I encountered in Q1 2022 was the clearest example I have ever had to diagnose and fix. Twelve people. Defined roles. A roadmap that existed as a document. And almost no meaningful forward movement. The organisation had confused activity with execution, and nobody, including the people inside it, could quite articulate why things were not progressing. — The Situation When I inherited that function, my first instinct was that prioritisation was the problem. Too many things on the list, not enough forcing function to separate what matters from what merely feels urgent. I was wrong. Completely, and in a way that cost me several weeks before I understood it. The roadmap was not too long. The roles were not unclear. The team was not under-resourced. What they were was uninformed, not about their tasks, but about the reasoning behind the decisions being made above and around them. They were executing in a context vacuum. So they did what reasonable, conscientious professionals do in that situation: they slowed down. They checked before moving. They escalated questions that should have been within their authority to resolve. They waited for signals that it was safe to proceed. From the outside, this looked like a motivation problem, or possibly a talent problem. It was neither. It was an information architecture problem. The organisation had been accidentally withholding the one input that would have unlocked movement: the reasoning behind the decisions they were being asked to implement. I sat with that for longer than I am proud of. The answer, when it eventually became obvious, was almost embarrassingly simple. — The Analysis **The “why” is not context. It is infrastructure.** Most organisations treat explanation as a courtesy, something you offer when you have time, or when someone asks. A communication style preference of a particular manager. Optional, in other words. That framing is wrong. When people understand why a decision was made, they gain the ability to make hundreds of downstream decisions correctly, without requiring escalation at every step. They know the intent. They can infer the direction. They can course-correct in real time when circumstances shift, because they understand what they are trying to achieve, not just what they have been told to do. Withholding that reasoning does not protect decision-making authority. It undermines execution quality at every level below the decision-maker. The bottleneck most organisations search for, in their processes, their tooling, their structures, often sits inside this gap: information asymmetry between those who set direction and those who carry it out. **Clarity before implementation, not after, changes everything.** The change we made was not structural. We did not redesign the function or rewrite the roadmap. We introduced one practice: before any significant decision was implemented, we held a ten-minute conversation to explain the reasoning, and we explicitly asked what was wrong with it. Not a memo. Not a Slack message. A conversation, before the fact, with an invitation for challenge. The effect was not that people agreed with everything. Some of the pushback was genuinely useful and changed how we proceeded. But the more important effect was that people stopped operating in a state of ambient uncertainty. They knew the thinking. They trusted the direction was considered. And they could move. Execution pace shifted meaningfully within six weeks. The strategy had not changed. The team had not changed. The information available to the team had. **The invitation to challenge is not a vulnerability. It is a signal.** This is the part senior leaders often resist. Asking “What is wrong with this thinking?” feels, if you are not careful, like an admission that you are unsure, and there is a version of leadership culture that treats uncertainty as weakness. That instinct is expensive. In practice, the invitation to challenge a decision before implementation does two things simultaneously: it surfaces the genuine blind spots that the person closest to execution can see, and it signals to the team that their judgment is trusted enough to be heard. Both of these outcomes improve execution quality. Neither of them undermines authority. The executives I have worked with who moved the fastest were not the ones who decided fastest. They were the ones whose teams needed to ask the fewest clarifying questions, because the direction was clear, the reasoning was shared, and people had been given permission, implicitly, to use their own judgment within that frame. — The Implication If your team is busy and results are not moving, resist the temptation to reach for structural solutions first. Before you reorganise, reprioritise, or replace anyone, ask a simpler question: do the people executing our strategy understand why the key decisions were made? Not what was decided. Why. If the honest answer is that you are not sure, or that the reasoning lives only in a few senior heads and has never been made explicit, then you have found your bottleneck. It is not a talent problem. It is not a resource problem. It is a context problem, and context is one of the few things in organisational life that is both genuinely free and genuinely powerful. The teams I have seen operate with real speed and confidence share one quality: they are trusted with the reasoning, not just the instruction. That trust does not slow decisions down. It distributes the capacity to make them well. Context is not what you give people after they ask for it. It is what you owe them before they need to.

Custody Services Myth-Buster: The Hidden Revenue Story

Back-Office in Name Only: Why Your Custody Relationship Is a Capital Decision I’ve seen an expensive mistake that never appears on a risk register. It’s not a loss event. It’s not a failed audit. It’s revenue that simply doesn’t exist because nobody with the authority to ask for it ever did. Custody services are the most persistent example of this in institutional finance. The industry narrative has always been comfortable: a custodian holds your assets, settles your trades, and sends you a report at month-end. Passive. Reliable. Boring. The kind of thing you hand to someone competent and sensible and then stop thinking about. That narrative is wrong. Not partially wrong, structurally wrong. And the cost of believing it is not abstract. It shows up in yield you didn’t earn, capital you didn’t deploy efficiently, and withholding tax you paid and never reclaimed. The custodian wasn’t hiding these opportunities. Most of the time, nobody was asking. — The Founder I Got Wrong Eighteen months ago, I wrote a post that touched on this. It landed reasonably well, which meant people agreed with the surface observation: founders and senior executives often don’t know what revenue they’re leaving inside their custody relationships. Securities lending sitting dormant. Collateral fragmented across trading desks. Tax reclaim processes still manual, still slow, still leaking. I framed it as a discovery problem. Executives weren’t aware. Once they knew, they would act. I was half right. Half right in a way that cost the argument its real point. Last month, I went back to that same founder. Eighteen months on. They had, in fact, renegotiated the custody relationship. Securities lending was activated. Collateral had been consolidated. The withholding tax reclaim process, cross-border dividends, treaty benefits, the entire machinery, was finally automated. Material improvement across all three. I asked what had actually changed internally to make it happen. He said: “We had to stop treating it as the CFO’s problem.” I sat with that for a moment. Because what he meant was not that the CFO had been failing. He meant the relationship had been categorised as operational, handed down the chain to people with competence but without authority, and quietly left there. Nobody at principal level was asking the economics question. So nobody answered it. The custodian wasn’t withholding anything. The client had simply decided, implicitly, without ever actually deciding, that this was a back-office matter. I got it wrong in 2024 because I diagnosed the symptom instead of the condition. Awareness was never the constraint. Ownership was. — What Custody Services Actually Are Let me be precise about what is sitting inside these relationships, because the vocabulary matters. **Securities lending** is the most straightforward and the most underused. When you hold equity positions you’re not actively trading, a custodian can lend those securities to short sellers and other market participants in exchange for collateral and a fee. The asset remains economically yours. The yield is incremental. For funds with meaningful long positions, this is not a rounding error, it’s a deliberate revenue line. Treated as operational, it goes unreviewed. Treated as a capital decision, it gets optimised. **Collateral management** is where the complexity compounds. Firms running multiple trading desks, derivative positions, and financing arrangements are often posting collateral inefficiently, either concentrating high-quality assets where lower-quality ones would satisfy requirements, or failing to recycle collateral across the enterprise in any coherent way. A custodian with tri-party collateral management capability can transform this. But only if someone at the table has both the authority to restructure the arrangement and the mandate to ask whether the current setup is optimal. Most of the time, that person doesn’t exist in the conversation. **Tax reclamation on cross-border dividends** is the least glamorous and possibly the most consistently mismanaged. When a fund receives dividends from foreign equities, withholding tax is typically deducted at source. Many jurisdictions have treaty arrangements that reduce or eliminate that liability, but reclaiming it requires documentation, timing, and process. Automated, this is recoverable value. Manual and deprioritised, it leaks quietly for years. I’ve seen organisations leave meaningful basis points on the table annually, not because the process was complicated, but because no one had made it anyone’s responsibility to care. — The Ownership Problem Is an Organisational Problem Here’s the counter-intuitive part. The custodian almost always knows what is being left unrealised. They have the data. They can see the lending pool, the collateral inefficiency, the unclaimed reclaims. The better custodians will raise it. Some will raise it repeatedly. But a conversation initiated by a service provider and received by an operations team produces a very specific kind of outcome: it produces a note in a file, a polite acknowledgement, and continued inaction. Not because the operations team is incompetent. Because they don’t have the authority to restructure a commercial relationship, and they know it. The decision to activate securities lending, renegotiate collateral terms, or invest in tax reclaim automation is a capital allocation decision. It requires someone who owns the P&L implication, has the authority to engage the custodian at a principal level, and has set aside time to actually review the economics, not just the operational SLAs. Back-office decisions made at back-office levels produce back-office outcomes. This is not a criticism of operations professionals. It’s a structural observation about where certain categories of decision need to live. — What This Means in Practice If your custody relationship doesn’t have a named senior owner reviewing the economics quarterly, you don’t have a custody strategy. You have a contract. Those are genuinely not the same thing. This applies equally to asset managers, fintech platforms with balance sheet exposure, family offices, and corporate treasuries with cross-border holdings. The specifics vary. The pattern doesn’t. And if you’re building or advising on the infrastructure layer, as I’ve written about in the context of cyber risk and human decision-making, the lesson is the same: the technical capability is rarely the constraint. The governance around it usually is. The founder I spoke to

The Hidden Revenue Engine in Custody Banking

Custody Is Not a Warehouse. It Never Was. A category of assumption in financial services never gets challenged because it lives in the wrong part of the conversation. Not strategy. Not risk. Operations. Because it lives there, it quietly costs firms money for years without anyone noticing, or, more precisely, without anyone deciding to notice. Custody is one of those assumptions. Ask most senior executives what their custodian does, and you’ll get some variation of the same answer: they hold the assets, settle the trades, keep everything safe. Which is true. It’s also roughly as complete as saying a CFO’s job is to count the money. Safety and settlement are the entry requirements, not the service ceiling. What sits above them, and what most firms are systematically failing to access, is an entirely different conversation. — The Situation In 2021, I reviewed the cost structure of a mid-tier asset manager. Standard work. The kind of exercise where you expect to find a few contract renewals overdue, some vendor consolidation opportunities, the usual operational drift. Custody appeared in the analysis as a line item under operational overhead. No flag. No red circle. Just another fixed cost being paid on time every quarter, which apparently meant there was nothing to discuss. I pushed to look at the actual relationship, not just the invoice. The operations lead looked mildly confused. “We haven’t had any issues,” he said. That sentence, I’ve learned over the years, is the one that should worry you most. What we found when we looked properly wasn’t a disaster. It was something subtler and, in some ways, worse: a slow, systematic bleed that had been running unexamined for three years. Securities lending revenue was sitting uncollected, the programme existed in theory, but the commercial terms had never been optimised and monitoring had lapsed. Collateral was being posted inefficiently across three trading desks that were operating independently, each solving its own problem without any view of the aggregate drag. And withholding tax reclaims on European dividends, treaty benefits the firm was legally entitled to, had not been filed in eighteen months. The money wasn’t lost. It was just sitting unclaimed inside a process nobody had thought to run. I’ll be honest about what I felt when we quantified it. Not vindicated. Uncomfortable. Because the operations team were competent people who hadn’t been negligent, they’d been under-resourced, under-informed about what was available, and operating inside an unspoken organisational assumption that custody was a settled, closed question. Nobody had told them otherwise. And I’d been in enough boardrooms to know that nobody was going to volunteer that conversation upward unprompted. — What Custody Actually Is **Securities lending is not a passive income stream.** The mechanics are familiar enough: the custodian lends holdings to counterparties in exchange for collateral and a fee. But the difference between a well-run securities lending programme and a poorly managed one isn’t marginal. It depends on the split negotiated with the custodian, the demand profile of the underlying securities, the quality of counterparty selection, and whether the programme is being actively monitored against market benchmarks. Dormant assets, equities held through a long-only strategy, bonds held to maturity, are not dormant from a lending perspective. They are inventory. Whether that inventory earns anything depends entirely on whether someone is paying attention. Most firms I’ve reviewed aren’t. **Collateral management is where capital efficiency lives or dies.** When trading desks operate independently, which they almost always do, collateral decisions get made locally without visibility into the portfolio-wide position. The result is duplication: the same eligible assets being used multiple times across margin calls and counterparty obligations, but not optimised for where they create the least drag. A custodian with proper collateral management infrastructure sees the whole picture and can route assets to minimise capital consumption. The firms using this well have a structural cost advantage over the ones still running the three-spreadsheets-in-parallel model. This isn’t a sophisticated observation. It’s just one that requires someone senior enough to demand the conversation and junior enough to actually sit in the operational detail. That overlap is rarer than it should be. **Tax reclamation is money most firms don’t know they’re owed.** Cross-border dividend payments are subject to withholding tax under domestic rules, but double taxation treaties between countries create entitlement to reclaim the difference. The process is administrative: filings, deadlines, documentation requirements that vary by jurisdiction. It’s also the kind of work that falls between the custodian’s scope and the internal tax team’s awareness if the relationship isn’t actively managed. Eighteen months of uncollected reclaims on a European equity allocation isn’t an edge case. I’ve seen it more than once, in organisations that would describe their tax function as sophisticated. Automation exists. Treaty entitlements exist. The gap is almost always governance, specifically, who owns the question. — What This Means Practically The organisations that treat custody as infrastructure, as something to be reviewed, not just paid, have a measurable advantage that shows up in net returns. This isn’t about switching custodians or renegotiating contracts as an annual performance. It’s about establishing a regular discipline of asking what value is available inside the existing relationship and whether it’s being accessed. That means someone with enough authority to sit outside the operational team’s comfort zone and ask the questions that feel impolite: What is our current split on securities lending? When did we last file a reclaim? What is our aggregate collateral utilisation and who owns it? The relationship with a custodian is not unlike the one I described in [when cyber risk becomes a human failure rather than a technical one](https://lakshvaswani.com/when-firewalls-fail-the-human-side-of-cyber-risk/), the exposure is often not in the event that gets escalated, it’s in the assumption that has never been examined. And as I’ve argued in the context of [regulatory expectations across different jurisdictions](https://lakshvaswani.com/the-trust-deficit-why-transparency-empathy-and-execution-are-the-future-of-compliance-leadership/), the cost of oversight is almost never as high as the cost of its absence. The most expensive service you can buy is one you’re already paying for and not using.

AI did not create the fear inside companies. It exposed it.

I have sat in that silence more times than I would like. After a while, you stop hearing it as silence and start hearing it as data. — The Situation In Q1 2022, I was brought in to assess why an enterprise AI deployment had stalled at eleven percent adoption after six months. Let me be precise about what eleven percent means in practice. The system was live, the training had been delivered, the dashboards were accessible, and nine out of ten people who were supposed to be using it had found creative ways not to. Some cited technical friction. Some said the interface was unclear. One memorable response, delivered entirely without irony, was that the tool “did not integrate well with existing workflows,” by which the person meant Microsoft Excel, which they had been using since 2009 and had no intention of replacing. The technology was credible. The vendor was serious. The business case, built over eighteen months, was robust. This was not a situation where a CISO had approved a toy and called it transformation. So I did what I usually do when the obvious answers have already been ruled out: I stopped asking about the technology and started asking about the people. I ran structured sessions with front-line teams and middle management. Not surveys, actual conversations, one level removed from senior leadership so people had some room to be honest. What emerged had almost nothing to do with AI. People were afraid. Not of the AI specifically. They were afraid of being seen to be wrong, afraid that using a new tool meant producing outputs that could be scrutinised, compared, questioned. They had spent years in an environment where errors were punished swiftly and questions were absorbed slowly or not at all. The culture had taught them, with considerable consistency, that visibility was risk. The AI had not introduced that fear. It had simply given it a new surface to sit on. I will be honest: I did not see it immediately. My first instinct, arriving with the brief I had been given, was to look at the implementation, the change management plan, the training quality, the communication cascade. I spent the first week in the wrong territory entirely. The moment I understood what was actually happening came midway through week two, in a conversation with a mid-level analyst who said, quietly, that she would rather do the work manually and be wrong on her own terms than use the system and have the wrong answer attributed to her in a log. That is not a technology problem. That is a decade of learned behaviour, dressed up as a UI complaint. — The Analysis The first thing to understand is that AI systems, by design, make work legible. They create records, trails, decision logs. They answer questions with timestamps attached. In an organisation where accountability has historically flowed downward and rarely upward, that legibility is not experienced as efficiency. It is experienced as exposure. This is the counter-intuition that most AI change programmes miss: the resistance is not irrational. It is a perfectly rational response to an environment where being seen has historically been dangerous. When you introduce a tool that makes every decision more visible, you are not simply adding technology. You are changing the terms on which people have learned to survive professionally. The silence before that resistance sets in is the same silence that kills projects long before any consultant is called in to diagnose them. The second insight is that money spent on AI change management cannot do the work that cultural repair needs to do. I have watched organisations invest heavily in adoption programmes, comms campaigns, lunch-and-learns, executive sponsorship videos, gamified dashboards showing which teams had hit their usage targets, and seen adoption numbers remain stubborn, because none of those interventions addressed what the people in those rooms had actually learned about what happens when you make a mistake in front of the wrong person. You cannot train away a culture. You can only build a different one over time, with evidence. The third point is the one that is most uncomfortable for leadership to hear: if your AI rollout has stalled, the diagnosis is sitting in your own management behaviour, not in the vendor’s implementation. The organisations I have seen successfully deploy AI at scale share one characteristic that has nothing to do with the sophistication of the model or the quality of the data architecture. Senior leaders in those organisations are visibly, repeatedly, publicly comfortable with being wrong. They use the tools themselves, in front of people, and say, “That gave me a result I did not expect, let me work through why.” That one behaviour, modelled consistently, does more for adoption than any change management framework I have encountered. — The Implication If you are leading an AI programme, or sitting on a board that is overseeing one, the question worth asking is not “What is our adoption rate?” The question is: “What does it cost someone in this organisation to be visibly wrong?” If the honest answer is “More than it costs to quietly underperform,” no implementation plan will save you. The technology will land. The adoption will not. And eighteen months from now, someone like me will be brought in to explain why a credible tool with a sound business case is sitting at eleven percent. The answer will be the same answer it always is: the AI was fine. The culture had work to do before the first model was ever deployed. — Closing Organisations do not fear AI. They fear what AI makes visible about the way they have always operated. Fix that first, and the adoption numbers will take care of themselves. AI does not create fear in organisations. It inherits it.

The silent killer in projects

The Space Between the Contracts 2021, I signed off on a data transformation project involving four vendors. Each was technically capable. Each came with credentials, references, and a delivery team that could hold a room. The contracts were tight-I spent considerable time with legal to ensure that. Milestone charts glowed amber-to-green across the programme dashboard. On paper and on screen, everything was moving. What I didn’t model was the space between them. I’ve spent twenty years in financial services-across risk, compliance, regulatory technology, and now AI infrastructure. In that time, I’ve seen projects fail for the reasons you’d expect: bad data, underqualified teams, scope creep, budget overruns. But the failure mode that has cost me and the organisations I’ve worked with the most is quieter, harder to name, and almost never appears on a risk register. It lives in the ungoverned gaps between parties who are each individually performing-and collectively, silently, coming apart. — The Situation By month four of the 2021 programme, something felt off. Not catastrophically off. Just the low-grade friction that experienced programme leads learn to read: slightly defensive status updates, meetings that ended without clear owners, a vendor delivery lead who had started cc’ing more people than necessary on emails. When I pulled the thread, this is what unravelled. Vendor A had been claiming credit in steering committee for work that Vendor B had actually delivered. Not maliciously-they genuinely believed the integration work fell within their remit. Vendor B said nothing, partly because they didn’t want to cause friction, and partly because they had problems of their own. Vendor C was six weeks behind schedule and had told no one. Not their internal team lead, not the programme manager, not me. They carried the delay quietly, hoping to recover it before anyone noticed. And Vendor D-the one I want to linger on-was waiting on a dependency that no one had formally assigned. That’s when it stopped me. Vendor D’s dependency wasn’t hidden. It wasn’t classified. It was simply sitting in the ungoverned space between two statements of work, belonging clearly to neither, assumed by everyone to be someone else’s problem. When I traced it back through the documentation, I could see exactly how it happened. Each contract had been written precisely. Each party had agreed to their scope. And in the clean borders between those scopes, this dependency had fallen, silently, into nothing. The programme wasn’t technically failing. Every individual status report looked reasonable in isolation. The programme was failing relationally-in the assumptions, the silences, and the incentive structures that made it easier for each vendor to manage their own position than to flag an inconvenient truth. I had governed each contract. I hadn’t governed the trust between them. — Three Things I Understood Afterwards **The risk register captures what vendors agreed to measure-not what is actually happening.** This sounds obvious when written down. It isn’t obvious when you’re twelve weeks into a programme and every RAG status is green. Risk registers in multi-vendor programmes are a product of negotiation. What gets tracked is what parties consented to track. What doesn’t get tracked-the informal dependency, the missed handshake, the assumption left unverified-is invisible to the register by design. The absence of a red flag isn’t the same as the absence of a problem. I’ve written about related blind spots in AI and data governance [in this piece on AI deployment challenges in banking](https://lakshvaswani.com/post-of-ai-deployment-issues-as-senior-banking-executive-in-grc-space-how-we-overcame-them-going-beyond-pocs-real-issues-and-solutions-humor-engagement-and-end-with-laksh-vaswani-so-it-will-com/). The pattern is consistent. Systems optimised to report compliance aren’t optimised to surface failure. **The greatest risk in multi-vendor transformation isn’t technical-it’s the misalignment of incentives.** Each vendor in a complex programme is optimising for their own commercial outcome. That isn’t a moral failing; it’s rational behaviour. Vendor A had every incentive to claim the integration work-it strengthened their renewal case. Vendor C had every incentive to stay quiet about the delay-admitting it early would have triggered penalty clauses. None of them had a commercial incentive to flag the problem in the white space between their scopes, because that white space wasn’t in their contract, and solving it wasn’t in their interest. The irony, which I fully appreciate, is that I spent months negotiating contracts to create accountability-and the contracts themselves created the conditions for strategic silence. Tighter legal language doesn’t solve a misalignment of incentives. It can make it worse, by giving each party more to protect. **The person with no commercial reason to flag the problem is your real early warning system.** This is what I’d tell my 2020 self. Before a multi-vendor programme begins, map the dependencies-not the technical ones in the architecture document, but the human ones. Who is relying on whom? Where does one vendor’s success depend on another’s delivery? Then ask, for each of those dependencies: who has a commercial interest in flagging a problem here, and who doesn’t? The person with no incentive to raise the flag is exactly the person you need to build a direct line to. That might be a junior integration tester. It might be a mid-level project manager on a fixed-price contract. It will almost never be a vendor account director. — What This Means for Your Organisation If you’re running a transformation programme-or sitting above one-the question to ask isn’t “are all vendors delivering against their milestones?” The question is: who in this programme has both the visibility to see a cross-vendor problem and absolutely no commercial reason to surface it? If you can’t name that person, you don’t have an early warning system. You have a reporting structure. Those aren’t the same thing, and in month eight, when the gap you missed in month three becomes impossible to ignore, the distinction will matter considerably. The same principle applies, by the way, to internal programme governance-something I touch on in a broader reflection on executive accountability [here](https://lakshvaswani.com/test-post-from-london/). The structure that makes you feel in control isn’t always the structure that tells you the truth. — The risk that kills programmes doesn’t live inside the contracts. It lives in the

AI Implementation Success: An OCC Compliance Story

When the OCC Said Yes: What a §17f-1 Fix Taught Me About AI in Regulated Finance Regulators do not applaud. They document, they question, they reserve judgement, and occasionally-very occasionally-they express satisfaction. That last phrase, in OCC examination language, is roughly equivalent to a standing ovation from a Scandinavian audience. Last year, when I heard it, I did not celebrate immediately. I went back through the file to check whether we had missed something. We had not. But the reason we had not is more instructive than the outcome itself. — The Situation The custody bank came to me with a §17f-1 problem that had quietly compounded for longer than anyone wanted to admit. Fourteen custodial accounts. Manual reconciliation spread across three jurisdictions-the US, Luxembourg, and a Cayman structure that generated its own particular brand of administrative joy. The average lag between identifying a securities fail and reporting it to the OCC examiner’s desk was eleven days. Eleven days is not a compliance gap. It is a liability with a bow on it. Here is the moment I do not enjoy recounting. In the first working session with the internal operations team, I asked to see the reconciliation workflow. What I expected was a documented process with some inefficiencies. What I found was a spreadsheet. A colour-coded, lovingly maintained, deeply human spreadsheet-owned by one person, checked on her schedule, dependent entirely on her being in the office on a Friday afternoon and not having a migraine. She was excellent at her job. She was also the single point of failure for a regulated function that the OCC takes seriously enough to have its own numbered rule. I had seen versions of this before-in Bahrain, in Mumbai, in London-but something about seeing it at a US custody bank in 2024 still caught me. The gap between what institutions tell regulators about their controls and what actually runs their controls is, in my experience, almost always a person with a spreadsheet and good intentions. We needed to close that gap with something more durable than intention. — The Build The surveillance layer we constructed pulled directly from the core custody ledger-integrated via structured API connections into the bank’s existing custody management infrastructure, which in this case sat on a platform familiar to most mid-tier US custodians. The exception logic ran continuously, not on a schedule. Every identified fail triggered an automated escalation path, timestamped at the moment of detection. SAR-adjacent flagging narratives were auto-drafted and queued for human review before anyone had to open a ticket or send a message. The tooling itself was not exotic. Structured data pipelines, rule-based exception engines layered with a classification model, and a reporting stack that wrote directly to the audit trail in a format the OCC’s examination teams could read without interpretation. Platforms like Nasdaq’s Surveillance infrastructure, Broadridge’s reconciliation and regulatory reporting suite, and AxiomSL (now part of Adenza / Nasdaq) exist precisely for this class of problem. The architecture principles are well understood. What is less understood is why so many institutions still do not implement them until an examiner forces the question. When the OCC review team arrived, they saw real-time audit trails. Timestamped escalation paths. Zero documentation gaps between identification and reporting. The eleven-day lag was gone. The process was no longer dependent on a person remembering to check something. They expressed satisfaction. — Three Things That Were Actually True **First:** the technology was not the differentiator. Every vendor in that room had technology. The differentiator was that the bank finally had a single source of truth-one that did not require a human to remember, to be available, or to interpret ambiguous data under time pressure. The OCC was not impressed by AI. They were impressed by accuracy. AI made accuracy repeatable. That is a meaningfully different claim, and most sales decks in this space get it backwards. **Second:** the eleven-day lag was a symptom, not the disease. The real problem was that no one had priced the exposure correctly. Eleven days of unreported lost or stolen securities is eleven days of regulatory, reputational, and counterparty risk sitting off the risk register. Until you can see the gap in real time, you cannot price it. Until you cannot price it, you will not fix it. Visibility is not a compliance nicety-it is the precondition for every risk decision that follows. This connects to something I wrote about separately: the structural danger hiding inside AI-native clearing approvals, where boards are signing off on automated systems they do not fully understand, compounding the very exposures they believe they are managing. **Third-and this is the one most organisations get wrong-the examiner is not your adversary.** Build for the examiner who assumes the worst. Give them audit trails so clean they have nothing left to question. The institutions that treat regulatory examination as an adversarial event spend enormous energy managing the optics of their controls. The institutions that treat it as a transparency exercise spend that same energy making their controls actually work. One of those strategies scales. The other one ends badly in year three. — What This Means for Your Organisation If your reconciliation workflow depends on a person, a schedule, or a spreadsheet-however capable the person, however reliable the schedule-you are one absence, one error, or one examiner visit away from an eleven-day problem of your own. The technology to close that gap is not emerging. It is available, it is implementable, and in most custody environments it is not even particularly expensive relative to the exposure it eliminates. The question is not whether you can afford to build the surveillance layer. The question is whether you can afford to keep explaining to an examiner why you have not. I have written before about what it looks like when a team holds together under that kind of pressure-the thirty-six-hour stretches, the decisions made at 3am that determine whether the morning looks manageable. None of that replaces the upstream work of building systems

36 Hours Straight: A Team Story in Financial Services

What Happens at Hour Thirty-Six There is a particular quality of silence that only exists when thirty-six hours of noise suddenly stops. Not peaceful silence. Not relieved silence. The silence of eleven people who have been in the same room since Thursday morning, across four time zones, held together by a shared problem and one very patient coffee machine – and who have just watched the fix land. Nobody moved. Nobody said anything. For a full minute, we just sat with it. The kind of silence that a team earns, not one that settles on them by accident. I have been in enough war rooms to know that the technical resolution is rarely the moment that stays with you. What stays is the human texture of the hours that built toward it. This weekend gave me more of that texture than I expected. — The Situation We were forty-eight hours into what had started as a manageable incident on Thursday morning. I say “manageable” because that is what the first assessment suggested. It was not manageable. It was the kind of problem that presents politely, shakes your hand, and then halfway through the introduction mentions it has brought several cousins. You solve the first layer, and it introduces you to a second. You solve the second, and a third emerges with a quietly baffling root cause that nobody had a clean precedent for. At some point around hour twenty, I stopped asking “how much further?” and started asking “who needs a break and who needs coffee?” Here is the moment I will not forget: it was sometime around 2am on Saturday. One of our engineers – someone who had been heads-down for hours, barely speaking – looked up from their screen and said, flatly, “I don’t actually think this is the problem anymore. I think we’ve been solving the wrong thing.” The room went quiet in a different way. Not the good quiet. The kind where everyone does a rapid internal calculation of how much work that statement might just have invalidated. I felt it too – that brief, cold drop of “please don’t let that be true.” It was true. And saying it out loud was the thing that turned the corner. We had been six hours into a technically correct solution to the wrong diagnosis. The engineer who said it had known for some time, I think – had been sitting with it, testing their own certainty before naming it in a room full of tired, invested people. That moment of honesty, offered quietly and without drama, was worth more than everything that came before it. I have been in transformation programmes where that observation would never have been made aloud. Where the cost of being the person who says “we’ve been solving the wrong thing” is too high – socially, politically, professionally. This weekend, it cost nothing. That is not an accident. That is a culture. — Three Things I Have Carried Out of That Room **The teams that hold together under pressure have usually done the work before the pressure arrives.** There was no team-building exercise that produced what I saw this weekend. There was months of working alongside each other, small acts of reliability, the accumulated evidence that when you say you’ll pick something up, you pick it up. Trust is not built in a crisis. It is *revealed* by one. What the war room showed us was simply what had already been true. **Fatigue is an honesty accelerator.** By hour thirty, the energy required to perform competence – to manage your image, to frame your uncertainty carefully – is simply no longer available. People stop polishing their contributions and start handing each other raw information. The humour gets darker because it stops being a social tool and starts being a genuine release valve. The observations get sharper because there is no bandwidth left for softening them. I have sat in two-hour steering committees where less truth was exchanged than in the last six hours of this incident. Organisations should find this alarming and instructive in equal measure. **The people who show up at 3am are not doing it for the SLA.** This is the insight that sat with me longest, and it is not a comfortable one for anyone who has spent time building incentive frameworks, performance structures, or engagement metrics. The engineer who reframed our diagnosis at 2am was not motivated by a KPI. The colleague who quietly took over so someone else could rest was not making a career calculation. There is a category of professional commitment that exists entirely outside the reward architecture – and the organisations that understand this tend to be the ones that keep their best people. You cannot manufacture it. You can only create conditions where it survives. — What This Means Beyond This Weekend If you lead a team, or a function, or a programme of any meaningful scale, I would ask you one question: would your team tell you at 2am that you have been solving the wrong problem? Not hypothetically. Specifically. In the room. With six hours of work already on the board and an audience of tired, invested colleagues. If the answer is uncertain, that is the work. Not the governance framework. Not the roadmap. The thing that makes transformation either survive contact with reality or quietly collapse under it is whether the people in the room will tell you the true thing when it is inconvenient and late and expensive to hear. Technical incidents are, in a strange way, gifts. They compress months of organisational dynamics into hours. They show you – quickly, clearly, without the usual insulation of process – what your culture actually is. Not what it says it is. What it does when nobody is watching the clock. We updated the runbook. We scheduled the post-mortem. We will find the systemic gaps and we will close them, methodically, the way you are supposed to. But the thing I

Agentic AI and the OCC Regulatory Stance in 2026

When the Regulator Starts Using the Tool It Is Regulating I’ve seen the moment in any technology cycle when the institution designed to oversee a thing starts becoming the thing. We’re at that moment with AI in banking. The OCC isn’t watching from a distance anymore. It’s inside the machine, learning how it works, trying to understand what it’s being asked to supervise. That should make every bank executive stop and think. Not because it’s threatening. Because it tells you something about where this is going – and how fast. I want to be clear about what I’m not saying. This isn’t a regulatory alarm piece. I’ve written enough of those, and so has everyone else. This is something more specific: an observation about a signal that’s easy to misread if you’re only skimming supervisory documents. — The Document That Stopped Me Last quarter I was working through the OCC’s supervisory posture on agentic AI in banking operations. Not a summary, not a briefing note someone handed me – the actual document. I do this the slow way because the slow way is the only way to catch what the fast way misses. Two things stopped me cold. First, the OCC’s explicit support for agentic AI in automated, compliant banking operations. Not a cautious conditional endorsement wrapped in seventeen qualifications. A directional signal. A federal banking regulator saying: this is the direction, and we’re behind it. In the language regulators actually use, that’s a significant statement. Regulators don’t use words like “support” casually. They have lawyers for that. Second, the same document named both sides of the AI-and-cybersecurity equation in the same breath: AI strengthens cyber defenses and AI sharpens the attacks against the very institutions deploying it. They said both things, explicitly, without softening either one. That kind of candor in regulatory language isn’t standard. Regulatory documents are usually careful to the point of saying nothing. This one said something. Then I found the part about the OCC’s Solutions Lab. GenAI, being used internally, to help the OCC supervise AI-driven tools inside the banks it oversees. I sat with that for a while. The regulator isn’t waiting to understand what it’s regulating. It’s building the capability now, from inside, before the gap becomes uncrossable. I’ll be honest: my first reaction was mild surprise, which immediately became embarrassment at my own surprise. Why would I assume regulators would be passive while the entire sector restructured itself around a technology they barely had working definitions for? Of course they’re building capability. The question is whether they’re building it fast enough – and whether the banks are asking themselves the same question with anything like the same urgency. — What the OCC Is Actually Telling You Agentic AI is no longer experimental in the regulatory view. The OCC’s endorsement of agentic AI for automated, compliant operations is a turning point. It moves AI in banking from the category of innovation-to-be-watched into the category of infrastructure-to-be-governed. That distinction matters enormously. When something is experimental, you can manage it at arm’s length. When something is infrastructure, it has to be understood at depth, by the people responsible for it, not delegated to a team and reviewed quarterly. The OCC has made a judgment that agentic AI is infrastructure. Every board should be making the same judgment about their own posture. The dual-use candor isn’t an accident. Naming both the defensive and offensive implications of AI in a single supervisory document is a deliberate framing choice. It tells banks: we won’t accept the selective narrative. You can’t present AI as a cyber enhancement story while quietly ignoring that the same capabilities are being turned against your systems. The OCC is signaling that it expects integrated thinking – the kind that holds two uncomfortable truths at once without retreating to whichever one is more convenient for the quarterly presentation. The gap that kills institutions is never the technology. I’ve sat in enough post-incident reviews, enough enforcement discussions, enough conversations with executives who genuinely couldn’t explain what their own systems were doing, to know what the real failure mode looks like. It isn’t the AI making a bad decision. It’s the distance between what the tool does and what the leadership team understands about what the tool does. The OCC closing that gap for itself – building internal capability, running its own GenAI in a supervised environment – is the right instinct. It’s the instinct that every bank should be acting on. Not because the regulator said so. Because it’s the only way to govern something you don’t understand yourself. — What This Means for Your Institution A version of AI governance looks correct from a distance. The policies exist. The AI committee meets. The risk register has a section. The vendor attestations are on file. That version of AI governance won’t survive a competent supervisory examination from a regulator that’s now building internal capability to look underneath the surface. The question worth asking – in the next leadership discussion, not the next strategy cycle – is whether your institution’s understanding of its own AI keeps pace with what that AI is actually doing. Not the vendor’s answer to that question. Yours. The OCC is building the capability to ask that question properly. The banks that are ready for it are the ones that asked it first. Understanding your own AI isn’t a governance checkbox. It’s the one audit you can’t outsource.

The Unspoken Moment in a High-Stakes Board Meeting

What the Room Didn’t Say A particular kind of silence sounds like agreement. It fills the space after a decision gets made with confidence. It follows the dominant voice in the room when that voice doesn’t pause long enough for a reply. It shows up in the meeting notes as “team aligned” – and it’s one of the most expensive fictions in organisational life. I saw it again today. A decision made quickly. No visible hesitation from the person calling it. Twelve people in the room, or on the call – depending on how you count the ones whose cameras were off. The agenda moved through the moment like it was already settled. And in one sense, it was. I’d made the decision before the meeting started. The meeting was, functionally, a notification. But I was watching the faces. — The Moment I Started Watching Faces I learned to do this the hard way, in 2016, during a product review meeting I ran. We were eighteen months into a compliance platform build. I asked the room whether the data architecture would hold under the regulatory reporting load we projected for the following year. The room said yes. Nods. No objections. One person said, “I think we’re in good shape.” We weren’t in good shape. Six months later, the architecture failed exactly where I’d asked about. When I went back and had the honest conversations – the ones that should have happened in that meeting – I found two engineers had known about a structural problem. They hadn’t said anything because the project director had been emphatic, the timeline was fixed, and the cost of raising a concern felt higher than the cost of hoping it would work out. They’d done the math quietly, at the table, in real time. And they’d decided to stay silent. That’s when I stopped treating silence as neutral data. It isn’t neutral. It’s the sound of a calculation being made. — Three Things I’ve Learned About What Silence Actually Means **First: Silence in authority-heavy rooms is almost never passive.** It looks passive. It feels passive if you’re the one speaking. But the people not speaking are actively doing something – they’re calculating. They’re weighing the cost of saying what they actually think against the cost of staying quiet. In most senior meetings, in most organisations, the cost of speaking is higher. Not because people are cowards. Because they’ve learned, through experience or observation, what happens to the person who says the uncomfortable thing in front of the wrong audience. The decision gets logged as unanimous. The dissent gets filed internally, under “not my problem anymore.” **Second: The tell is almost never verbal.** In the meeting today, I noticed it first in a glance – two people who looked at each other for about half a second before looking away. That’s a full conversation. It means: *Did you just see what I saw?* It isn’t disagreement, exactly. It’s shared uncertainty that has decided, in real time, not to become a spoken objection. The person who looked at the table was different. That one is usually more specific. Looking down is often the body language of someone who knows something and has just decided not to say it. I’ve been wrong about this. But I’ve been right about it more often than I expected, in rooms across four countries and multiple industries. If you run meetings, watch for the people who disengage physically at the moment a decision lands. They’re rarely uninterested. They’re usually the most interested – and the most troubled. **Third: What gets swallowed does not disappear. It relocates.** This is the part that costs organisations the most. The concern that didn’t surface in the meeting doesn’t vanish. It shows up in execution, in the small decisions made by people who didn’t fully believe in the direction but went along anyway. It surfaces as slow drag, as low-grade resistance, as the compliance audit eighteen months later that reveals a risk everyone around the table vaguely knew about but never said out loud. I wrote about a version of this in a [different context](https://lakshvaswani.com/i-managed-a-team-of-500-and-felt-less-informed-than-when-i-managed-a-team-o/) – how managing a team of 500 left me less informed than when I managed a team of 5, precisely because the information architecture around me had become performative rather than functional. Silence in meetings is the same problem operating at the individual level. The information exists. It just never reaches the decision. — What This Means If You Are the One Making the Call There’s a practical version of this, and it’s not complicated. If you’re in authority in the room – if you’re the one whose confidence is calibrating everyone else’s willingness to speak – you carry a specific responsibility. You have to create the gap deliberately, because it won’t appear on its own. A two-second pause isn’t enough. A direct question to the person who looked at the table is uncomfortable and worth it. “You looked uncertain – what are you thinking?” is a sentence that has saved me from bad decisions more than once, and it has the added effect of telling your team that you actually want the real answer, not the performed one. It also changes the culture over time. Rooms where the leader has asked the awkward question a few times start to produce the awkward question organically. People calibrate to what is safe to say, and when they learn that honesty is safe – genuinely safe, not just stated in a values document – they use it. The organisations I’ve seen handle crises best aren’t the ones with the most rigorous processes. They’re the ones where someone in a room, months or years earlier, felt safe enough to say the thing that didn’t fit the narrative. — The Close Unanimity is easy to manufacture. Consensus that holds under pressure isn’t. The difference is almost always visible in the room – if you’re watching for it. Silence in a meeting is data. The question

When Risk Frameworks Become Obsolete: An MRA Story

The Friday I Signed Off on a Risk Framework I Knew Was Broken There’s a particular kind of exhaustion that sets in on a Friday afternoon in Q3 when an OCC examination cycle looms. It’s not the clean tiredness of hard work finished. It’s the grubby, low-grade fatigue of a problem you’ve been managing rather than solving for the better part of a year. Everything on your desk is a version of the same question: how long can we hold this position? In Q3 2021, I found out exactly how long. The answer was four months. We had an open MRA – a Matter Requiring Attention – that had been sitting on the books for eleven months. For anyone outside the OCC’s regulatory world: an MRA isn’t a fine, it isn’t a public censure, but it’s a formal signal that the examiner has found something structurally wrong with your risk management practices and expects you to fix it. It’s the regulator telling you, in careful institutional language, that they’re watching. What we submitted that Friday addressed every word of the finding. It didn’t address the condition that had produced it. I knew this when I signed. — The Decision I Made in That Room The framework we built was technically responsive. That’s the exact right phrase. It answered the question as written rather than the question being asked. We’d brought in outside counsel, run it through the risk committee, and produced something that looked, on paper, like a serious institutional response. It had the right headings. It cited the right regulations. It mapped to the MRA’s specific language with the kind of precision that signals effort. What it didn’t do was account for the direction our risk environment was moving. The original finding had been written against conditions from early 2020. By the time we submitted the remediation framework in 2021, those conditions had shifted materially: vendor concentration had increased, a key operational process had been restructured, and two of the control owners named in the original framework had left the organisation. The framework we submitted was already ageing before the ink dried. I knew this. The head of my risk team knew this. We submitted it anyway, because the examination window was closing and an open MRA going into the next cycle felt like a worse outcome. That’s the calculation that leads you to the wrong decision in a very calm and rational way. The examiner accepted the framework. For approximately four months. Then the follow-up review arrived, and what had been an MRA became an MRA with a deadline. In OCC language, that’s the last door before formal enforcement action. We had to rebuild the entire framework under significant pressure, on a compressed timeline, with an examiner who now had a documented record of our previous submission sitting in the file. We hadn’t bought ourselves time. We’d borrowed it at an interest rate nobody quoted us at closing. — What Regulatory Time-Buying Actually Costs The first thing to understand is that OCC examiners have institutional memory that outlasts personnel changes on both sides of the table. Examination files follow an institution. When you resolve an MRA with a framework that’s already structurally compromised, that’s noted – not always in the formal finding, but in the examiner’s working papers, in the tone of the next examination, in the questions that surface two cycles later about the same underlying risk area. Regulators track patterns, not just incidents. A technically compliant response followed by a material lapse reads, to an experienced examiner, as a pattern. The second thing is that the goodwill cost is real and hard to recover. Regulated institutions often underestimate how much of the OCC examination relationship runs on examiner judgement – judgement about whether management genuinely understands its risk environment, whether leadership takes findings seriously, whether the organisation has a credible culture of risk management or a credible performance of one. That judgement is formed over multiple examination cycles. When you trade a substantive response for a timely one, you’re spending a currency you don’t get back by submitting the next framework on schedule. The third insight, and the one that cost me the most to learn: the MRA itself isn’t the problem. It’s a signal about the condition underneath. This sounds obvious until you’re the person sitting across the table from a Friday afternoon examination deadline with an open finding, at which point it stops being obvious and starts being inconvenient. Most MRA remediation work I’ve reviewed – and I’ve reviewed a substantial amount, at enough institutions to recognise the pattern – is designed around closing the finding rather than resolving the condition. Those aren’t the same activity. The finding is a description of a symptom at a point in time. The condition is a structural feature of how risk is identified, escalated, and owned inside the organisation. You can resolve the former without touching the latter. Banks do it regularly. The examiners know. This same dynamic appears in how organisations manage third-party risk. A vendor who fails a due diligence review is a finding. The governance gap that allowed the vendor relationship to become operationally critical before due diligence was completed is the condition. I’ve written separately about how third-party risk frameworks often suffer from exactly this confusion – treating relationship incidents as the unit of analysis when the control environment is the actual problem. — What This Means for Your Organisation If you’re managing an open MRA right now, the practical implication is this: build the remediation framework for where your risk environment will be in eighteen months, not where it was when the finding was written. That means the control owners named in the framework need to be current. The risk scenarios need to reflect your actual operational configuration, not the one that existed at examination time. The governance structure underpinning the framework needs to have real teeth – real escalation paths, real accountability, real testing cycles – because an OCC examiner