Read time: 3.9 min.
{{First Name | My friend}},
Real stories make an impact. Given how this one has stayed with me, I believe it will also stay with you.
At the start of the timeline I'm about to walk you through, Citigroup held approximately $1.88 trillion in assets and operated across more than 160 countries. That's one of the most heavily overseen financial institutions in the world, with boards, risk committees, compliance functions, and layers of oversight that most organizations will never approach in scale or sophistication.
And yet, what unfolded over the next decade is one of the clearest illustrations I've found of how implicit assumptions govern an organization's decisions when they're never made explicit at the executive level.
What the record shows

In 2013, the Federal Reserve issued Citigroup a consent order. A consent order is a binding regulatory agreement requiring an institution to acknowledge identified deficiencies and commit to remediating them. This one cited deficiencies in Citigroup's anti-money laundering compliance program.1
In 2014, the Fed evaluated Citigroup's capital plan as part of its annual review process. It objected to the plan, citing qualitative deficiencies in governance, internal controls, and the assumptions underlying it.2
In 2015, a second Fed order followed, this time addressing compliance and control infrastructure.
Then in 2020, the OCC and the Fed jointly issued new consent orders alongside a $400 million fine. The explicit basis for the action was that the longstanding deficiencies identified across all prior orders hadn't been adequately remediated.3
In 2024, regulators added another $135.6 million in penalties for failing to meet the remediation milestones set in 2020.4
The through-line that never changed
Across every order and every regulatory body, the documented deficiencies named the same set of conditions: enterprise-wide risk management and controls that weren't functioning consistently across the institution, data governance failures, and internal controls that different parts of the organization were applying differently.
The 2020 OCC consent order specifically required Citigroup to establish enterprise-wide standards. That requirement is worth honing in on. It means that at the time of the order, those standards weren't yet enterprise-wide. Different parts of one of the world's largest financial institutions were operating under different understandings of what risk management required, what compliance meant, and what data governance standards applied.
That's not a technology issue or a staffing issue. It's a clear indicator of a decision architecture gap. And the place to address that gap starts at the top, with the executive team's shared understanding of what those standards actually require.
Where implicit assumptions begin
Enterprise-wide standards don't emerge from compliance functions or business lines on their own. They start with the executive team's shared, explicit understanding of what those standards mean and what they require across the entire organization.
What the Citigroup record suggests is that different functions and business lines were each operating on their own working assumptions about what those standards required. Based on what's publicly available, those assumptions were likely not wrong in isolation. It appears that each part of the organization was doing what it understood to be correct within its own frame of reference. Yet, the record indicates the assumptions were not made explicit across the leadership team, were not reconciled into a shared standard, and were never confirmed to be operating consistently across the institution.
And because they were never made explicit at the executive level, they couldn't be made explicit anywhere else either.
What a decade of regulatory intervention reveals
Here's what keeps turning over in my mind.
Citigroup didn't discover that gap through internal self-examination. The organization didn't surface it through a leadership offsite, a cross-functional review, or a strategic planning cycle. It surfaced through repeated external regulatory intervention, over eleven years, across multiple regulatory bodies, each one documenting the same structural conditions.
That's what happens when implicit assumptions about shared standards are never made explicit at the decision layer. Each part of the organization operates reasonably within its own frame of reference. The gap between those frames often remains just below the level of awareness given the demands of daily execution. It tends to stay imperceptible until something external forces the question, whether that's a regulatory intervention, a failed initiative, or a moment when execution stalls in ways nobody anticipated.
That's the structural condition that well-designed executive decision architecture is built to address. When leadership teams build explicit, shared standards into how their decisions are carried, they don't rely on external pressure to surface what's been operating beneath the surface all along. They find it first.
The implicit assumptions shaping how decisions move through your organization right now are as invisible as Citigroup's were before regulators made them visible.
The difference is that you don't need a consent order to find them.
If you'd like to talk through what it looks like to surface those assumptions before they surface on their own, I'd welcome the conversation. You can schedule time directly here.
Until Next Sunday,
Shawnette Rochelle, MBA, PCC
Founder, Excellence Unbounded
Executive Decision Systems That Drive Organizational Momentum
If you’re curious to learn more about my work with executive teams, you can find it here.
If you want to have a conversation to learn more, schedule it here.
1 https://www.federalreserve.gov/newsevents/pressreleases/files/enf20130326a1.pdf
2 https://www.federalreserve.gov/newsevents/pressreleases/files/ccar_20140326.pdf
3 https://www.sec.gov/Archives/edgar/data/831001/000110465920113933/tm2032793d1_ex99-2.htm
4 https://finance.yahoo.com/news/citigroup-c-faces-136m-penalty-081500479.html

