An Inspection Is Not an Assurance

Identifying vulnerabilities in a financial institution is the responsibility of those running the institution, not those inspecting it

Article related image
istock
Author
By Rahul Ghosh

Rahul Ghosh is a banking and risk expert who advises banks, corporates, and central banks, and builds tech solutions for risk management. He authored two books on risk.

October 5, 2026 at 8:54 AM IST

“If it is not mandatory, it is not necessary.”

Discussions on strengthening risk management in banks and NBFCs often begin with a practical question: what do the regulations require? A capability becomes a priority only when a regulator makes it compulsory. Until then, things can wait.

A related defence is equally troubling – ‘the regulator inspected us and raised no objection, so our practices must be acceptable’. This treats supervisory silence as a certificate of sound management. It also transfers responsibility for identifying weaknesses from those running the institution to those inspecting it.

The familiar maxim, “If it ain’t broke, don’t fix it”, acquires a dangerous qualification: nothing is broken until the supervisor says so. A recent American judgment illustrates why that assumption can prove costly.

Following Silicon Valley Bank’s collapse in March 2023, its former parent’s successor, SVB Financial Trust, pursued a claim against the Federal Deposit Insurance Corporation over deposits held with the bank. The dispute ultimately concerned approximately $1.7 billion. The FDIC argued that losses attributable to the parent’s role in imprudent management exceeded that claim.

In her August 2026 decision, US District Judge Beth Labson Freeman rejected reliance on favourable supervisory findings as proof that management had met its duty of care. She also noted that supervisors had, in fact, identified serious deficiencies. Citing an earlier precedent, the judgment observed: “Bank examinations are not beacons to light the path of erring directors.” Supervisors protect the banking and deposit-insurance systems; responsibility for running a bank remains with its management.

That reasoning recalls an encounter I witnessed in India during the corporate derivatives controversy of 2008.

In the first half of that year, corporate clients suffered substantial losses on derivatives sold by banks. Companies alleged mis-selling and breaches of regulatory requirements, sought intervention from the RBI, and disputed their payment obligations. Banks contested those allegations.

I attended a tense meeting chaired by a leading Mumbai solicitor. Corporate heads and their lawyers sat on one side of a long table; bank lawyers sat on the other. Among the banks’ arguments was a familiar proposition: successive regulatory inspections had not identified wrongdoing in the transactions under dispute. How, then, could the regulator subsequently allege non-compliance or impose sanctions?

The solicitor answered with a story. An intruder made it to the barracks twice without being detected. On his third attempt, the officers apprehended him. The intruder protested that, because the officers had failed to detect him on the previous occasions, they had no right to act now.

The point was unmistakable. A failure to detect wrongdoing earlier does not legitimise it or prevent its later discovery and imposition of sanctions. The analogy did not establish that any particular bank had mis-sold a product. It exposed the weakness of treating earlier inspections as immunity from subsequent scrutiny.

The two episodes involve different risks - SVB concerned balance-sheet management, particularly interest-rate and liquidity risk while India’s derivatives disputes concerned product suitability, customer understanding, disclosure and alleged mis-selling - nor does an American judgment determine Indian law. The common lesson is nevertheless compelling: supervisory findings cannot substitute for management’s own assessment of its responsibilities.

For Indian banks and NBFCs, this demands more than a change in legal strategy. Boards must ask whether risks are understood, measured and challenged before asking whether an inspection has criticised them. Managements must examine whether products serve customers’ needs, whether controls remain effective as business grows, and whether incentives reward risks the institution cannot sustain.

Compliance is essential. But a checklist cannot answer every question of prudence, suitability or care. An institution may satisfy a reporting requirement while leaving a significant vulnerability unresolved. Its management should be able to explain why a decision was reasonable when taken, supported by evidence and effective oversight.

Waiting for a supervisory objection makes risk management reactive. Waiting for losses or litigation makes it expensive. The better discipline is to identify and repair weaknesses while there is still time to act.

Banks should fix vulnerabilities before they become failures. An inspection report is an input into that responsibility, never a replacement for it.