Skip to main content

How to Design a Remuneration Policy Aligned With Risk-Adjusted Pay Rules

This guide sets out how to build a remuneration policy that genuinely reflects regulatory expectations on risk-adjusted pay, from governance through to malus and clawback. After reading, you will be able to identify the design choices that most often fail scrutiny and the fixes that produce a policy capable of standing up to board, supervisor, and investor challenge.

A remuneration policy that technically complies with the rulebook but fails to shape behaviour is now the primary target of supervisory challenge. The PRA, FCA, EBA and their international peers have moved beyond checking that deferral percentages and bonus caps are correctly stated. They want evidence that pay outcomes actually move in response to risk, conduct, and capital events, and that the people deciding those outcomes can explain why.

Key Executive Takeaways

  • Risk-adjusted pay stands or falls on the ex-ante and ex-post adjustment mechanics: generic scorecards and discretionary overlays without documented reasoning are the most common failure points.
  • The Remuneration Committee must be able to demonstrate, in writing, how risk, compliance, internal audit and finance input shaped individual outcomes, not just aggregate pools.
  • Material Risk Taker identification, deferral structures, and malus and clawback triggers should be stress-tested against plausible failure scenarios before the policy is signed off, not after an incident forces the question.

Start with the behaviours you are trying to produce

Before drafting a single clause, the RemCo chair and CRO should agree what the policy is meant to discourage and reward. A policy designed in the abstract will produce scorecards that measure what is easy to measure, usually short-term financial performance with a thin layer of risk metrics bolted on. Good policies begin with a written statement of the conduct and risk outcomes the firm wants to see, and work backwards into measurement.

This is also where you decide how much discretion sits with the RemCo. Rules-based formulas feel defensible but produce perverse outcomes when the business model shifts. Pure discretion is vulnerable to challenge on consistency. Most credible policies combine a formulaic starting point with explicit, bounded discretion, and require the RemCo to document the reasoning when it moves away from the formula.

Get Material Risk Taker identification right

MRT scoping is where policies most often come unstuck under supervisory review. The qualitative and quantitative criteria under the dual-regulated firms remuneration rules are not optional filters. If your MRT population has shrunk year on year without a clear structural reason, expect questions. Document the exclusion rationale for anyone who meets a quantitative criterion but is assessed as not having a material impact. The documentation, not the conclusion, is what supervisors test.

Build ex-ante risk adjustment that actually bites

Ex-ante adjustment, the risk-weighting of performance measures before awards are determined, is where most policies are weakest. A scorecard with 20 percent weighting on risk and conduct metrics will not survive scrutiny if those metrics are soft, lagging, or never trigger a reduction. Use forward-looking indicators: control environment assessments, risk appetite breaches, audit findings aged by severity. Calibrate so that a genuinely poor risk year produces a visibly poor pay outcome, not a 5 percent haircut.

Make malus and clawback operable, not theoretical

Most firms have malus and clawback clauses. Few have ever applied them. The test is whether the triggers are specific enough to be activated without a legal fight. Vague references to "material failure of risk management" invite dispute. Better triggers reference defined events: regulatory enforcement, restatement of financials, breach of specified risk limits, upheld conduct findings. Pair each trigger with a documented decision process, including who recommends, who decides, and what evidence is required.

Evidence the control function input

The RemCo minutes should show that risk, compliance, internal audit, HR and finance provided input, what that input said, and how it influenced outcomes. If the CRO's annual report to RemCo says the risk environment deteriorated but variable pool funding rose, the policy is not functioning. Supervisors read these documents together.

Stress-test before sign-off

Before the policy goes to the board, run it through two or three plausible scenarios: a conduct failure in a major business line, a capital event, a significant audit finding against a senior executive. Does the policy produce outcomes the board would be comfortable defending publicly? If not, fix the mechanics now.

Next decision point

Ask your RemCo chair one question at the next meeting: can we show, for each MRT, how risk and conduct considerations changed their award this year? If the answer is no, the policy needs work before the next cycle, not after.

Frequently Asked Questions

How much discretion should the RemCo retain over formulaic outcomes?

Enough to adjust for events the formula cannot capture, but bounded by a documented framework. Unlimited discretion is as problematic as none. Set a range, require written reasoning for any adjustment, and report aggregate use of discretion to the board annually.

What is the most common failure in malus and clawback design?

Triggers that are too vague to apply without legal challenge. Specific, event-based triggers tied to defined thresholds are far more operable than general references to risk management failure or reputational damage.

How should we handle risk adjustment for control function staff?

Their variable pay must not depend on the performance of the business areas they oversee. Measure them on the quality and independence of their control activity. This is a frequent area of supervisory challenge.

Does the policy need to address non-financial misconduct?

Yes. Both the FCA and PRA have made clear that non-financial misconduct is relevant to fitness and propriety and should feed into remuneration decisions. Build it into conduct metrics and malus triggers explicitly.

How often should the policy be reviewed?

Annually at minimum, with a deeper review every three years or when the business model changes materially. Document what changed and why, including where you considered a change and decided against it.

Frequently asked questions

How much discretion should the RemCo retain over formulaic outcomes?

Enough to adjust for events the formula cannot capture, but bounded by a documented framework. Unlimited discretion is as problematic as none. Set a range, require written reasoning for any adjustment, and report aggregate use of discretion to the board annually.

What is the most common failure in malus and clawback design?

Triggers that are too vague to apply without legal challenge. Specific, event-based triggers tied to defined thresholds are far more operable than general references to risk management failure or reputational damage.

How should we handle risk adjustment for control function staff?

Their variable pay must not depend on the performance of the business areas they oversee. Measure them on the quality and independence of their control activity. This is a frequent area of supervisory challenge.

Does the policy need to address non-financial misconduct?

Yes. Both the FCA and PRA have made clear that non-financial misconduct is relevant to fitness and propriety and should feed into remuneration decisions. Build it into conduct metrics and malus triggers explicitly.

How often should the policy be reviewed?

Annually at minimum, with a deeper review every three years or when the business model changes materially. Document what changed and why, including where you considered a change and decided against it.

Related guides

Boards, Governance & Defensibility

How to Design a Whistleblowing Framework That Meets FCA and SMCR Expectations

This guide sets out how to build a whistleblowing framework that genuinely works, satisfying SYSC 18, SMCR accountability requirements, and FCA supervisory expectations. After reading, you will know how to structure governance, train the organisation, handle disclosures credibly, and demonstrate effectiveness to the board and the regulator.

Regulatory changeRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

Stakeholder Risk Management for FCA Regulated Firms: A Practical Guide

This guide explains how FCA regulated firms should identify, assess and manage stakeholder risk in a way that stands up to supervisory scrutiny and board challenge. After reading, senior leaders will know how to build a stakeholder risk framework that connects to Consumer Duty, SMCR accountability and operational resilience obligations.

Regulatory changeRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

Stakeholder Risk Management for FCA Regulated Firms: A Practical Guide

This guide sets out how FCA regulated firms should identify, assess, and act on stakeholder risks in a way that meets Consumer Duty, SM&CR, and operational resilience expectations. After reading, senior leaders will know how to build a stakeholder risk process that stands up to board scrutiny and regulatory challenge.

Regulatory changeRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

How to Build Real Board Accountability in Regulated Industries

This guide sets out what board accountability actually requires in regulated financial services firms, from information rights to individual responsibility. After reading, you will be able to test whether your board is genuinely accountable or only appears to be.

Regulatory changeBoardsRegulators
4 min readRead guide →
Boards, Governance & Defensibility

How to Structure a Basel 3.1 Board Paper That Secures Approval

This guide sets out how to write a Basel 3.1 implementation board paper that wins approval without softening the capital impact numbers. Read it to sharpen your framing, sequencing, and stakeholder handling before the paper goes to committee.

Regulatory changeBoardsRegulators
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity