What Makes a Decision Defensible to Regulators: A Practical Guide
This guide explains what regulators actually look for when they test whether a decision was sound, and how to build that evidence before you need it. After reading, you will know how to structure, document, and stress-test decisions so they hold up under supervisory scrutiny or enforcement review.
What Makes a Decision Defensible to Regulators
A defensible decision is not one that turned out well. It is one that a reasonable regulator, reviewing the record cold, concludes was made by competent people who understood the risks, considered the alternatives, tested their assumptions, and acted within their authority. Outcome is almost irrelevant. Process, evidence, and judgement are everything.
If you are a board member, executive, or senior risk owner, the question is not whether your decision was right in hindsight. It is whether the contemporaneous record shows you would make the same call again with the same information, and whether that call was reasonable at the time.
The Four Tests Regulators Actually Apply
Supervisors and enforcement teams tend to probe four things, whatever the formal framework:
1. Was the right question asked? Many bad decisions start with a poorly framed problem. If the paper going to the risk committee asks "should we approve product X" rather than "what are the customer harm scenarios and how do we mitigate them," the framing itself is a weakness.
2. Was the evidence base adequate and challenged? Regulators look for signs of confirmation bias: single-source data, no dissent recorded, no consideration of contrary views, external advice used selectively. They notice when the challenge function signed off in ninety seconds.
3. Were the risks understood, including the ones you chose to accept? Accepting risk is legitimate. Not seeing it is not. The record must show that the downside cases were named, quantified where possible, and consciously accepted by someone with authority to accept them.
4. Was the decision made by the right people, with the right information, under the right governance? Delegated authority, quorum, conflicts, and the audit trail of who saw what and when. This is where firms most often fall apart under examination.
What Good Looks Like in the Record
The contemporaneous paper trail is the decision, as far as a regulator is concerned. Two years later, memories are unreliable and self-serving. The documents are not.
Good records show:
- A clear statement of the decision being made, the authority under which it is made, and the alternatives considered.
- The assumptions, and what would have to be true for the decision to be wrong.
- Named dissent or reservations, not smoothed-over consensus. If Legal, Risk, or Compliance had concerns, those concerns should appear in the minutes, along with how they were resolved.
- Sensitivity analysis or scenario testing where the decision depends on forecasts or models.
- A conscious statement of the customer, market, or prudential impact, and how it was weighed.
Minutes that say "the committee discussed and approved" are not evidence of a decision. They are evidence of a rubber stamp.
Where Firms Most Often Get This Wrong
Reverse-engineering the rationale
When a decision is challenged, teams often reconstruct the reasoning to fit. Regulators can spot this. Document reasoning at the time, in the meeting papers, not in a follow-up memo drafted after the query letter arrives.
Treating challenge as friction
The second line exists so the first line can defend its decisions. If Risk and Compliance are seen as obstacles to route around, the firm loses its best defence. The record should show robust challenge treated as valuable, not tolerated.
Confusing legal sign-off with defensibility
Legal advice that a decision is lawful is not the same as evidence that it was reasonable, proportionate, and in line with the firm's stated risk appetite and customer outcomes framework. Regulators care about the latter.
Forgetting the customer or market outcome
Even prudential decisions have conduct dimensions. If your record does not show you considered who could be harmed and how, expect that gap to be the first thing raised.
The Pre-Mortem Discipline
Before any significant decision is finalised, run this test: if this decision appears in an enforcement notice in three years, what will the regulator say we should have done differently? Write down the answer. Then either address it or record why you consciously accepted it.
This is uncomfortable. It is also the single most effective habit for building a defensible record.
Your Next Move
Pick the three most consequential decisions your board or executive committee has taken in the last twelve months. Ask an independent reviewer, internal audit, external counsel, or a trusted non-executive, to read only the contemporaneous papers and minutes and tell you what a supervisor would conclude. If the answer is uncomfortable, fix the process before you need to defend the next one.
Polar Insight helps senior leaders in financial services understand what their key stakeholders actually think before significant decisions are made.
Book a conversation