Why Frameworks Pass the Audit and Still Fail
Most Indian financial-services failures of the past decade did not happen because policies were absent. The IL&FS group had a documented enterprise risk framework, a board risk committee, and external risk consultants engaged. PMC Bank had RBI-mandated credit policies and internal audit. DHFL had a stated risk-appetite statement. Yes Bank had a chief risk officer reporting to the board. Each entity could produce a binder showing the right policies on the right letterheads.
What each lacked was a working risk culture: the day-to-day pattern of decisions, escalations, and consequences that determines whether the policies are followed when commercial pressure pulls the other way. The RBI Working Group on Internal Audit (2023) and the IRDAI Corporate Governance Guidelines (2024) both now reference culture explicitly, but neither defines it tightly. Defining it is the institution's own job.
What Risk Culture Looks Like in Practice
Risk culture is the set of shared expectations about how risk decisions are taken, who can challenge whom, what gets escalated, and what consequences follow good and bad outcomes. It shows up in observable behaviours, not in stated values.
Indicators of a healthy risk culture include:
- second-line functions (risk, compliance, internal audit) can stop a deal or a product launch without senior management retaliation
- bad news travels upward faster than good news, especially near reporting periods
- the most respected leaders in the organisation can name a deal they walked away from on risk grounds
- whistleblowers receive responses, not just acknowledgements
- consequence management is visible: people are removed for risk failures, not just for missing budget
Indicators of an unhealthy risk culture include:
- the chief risk officer or compliance head changes frequently, with the predecessors leaving on disagreements that are not openly discussed
- internal audit reports are softened in revision, with disagreements between auditor and auditee resolved by the auditor
- the same names appear repeatedly in complaint, whistleblower, and incident logs without consequence
- target-setting is anchored to last year plus a growth percentage, regardless of changed risk conditions
The Indian Failure Patterns
Five culture-failure patterns recur across Indian financial-sector incidents.
First, promoter dominance suppressing second-line voice. In several large failures, the chief risk officer and the auditor reported nominally to the board but practically to a dominant promoter or CEO. Disagreements were resolved by quietly moving the dissenter rather than by elevating the issue.
Second, targets disconnected from risk appetite. Growth targets cascaded down from the board did not translate into proportional risk-capacity uplift. Front-line staff met targets by adjusting risk, not by changing strategy.
Third, selective application of policy. Policies were enforced rigorously for small accounts and routinely waived for large accounts on "strategic" grounds. The waiver pattern, visible in retrospect, was invisible at the time because each exception was minuted in isolation.
Fourth, delayed bad news. Loss events, near-misses, and adverse audit findings travelled slowly upward, often arriving at the board only when external pressure forced disclosure. The result was governance reactive to outside events rather than ahead of them.
Fifth, whistleblower retaliation, formal or informal. The whistleblower mechanism existed on paper, but identification and adverse career outcomes for past whistleblowers were known internally. Subsequent whistleblowers calibrated accordingly.
Measuring Risk Culture
Risk culture cannot be audited the way a control framework can, but it can be measured through a combination of leading indicators and structured assessment.
Leading indicators that should be tracked at the board:
- policy-exception rate for each business line, with trend and outlier review
- risk-event log volume, particularly near-misses, with deliberate attention to under-reporting
- turnover in second-line and audit functions, broken down by voluntary and involuntary
- complaint volumes broken down by source: customers, employees, regulators, whistleblowers
- time from incident to board notification, with explicit tolerance for outliers
Boards That Confront Culture
Boards are the institution's culture in concentrated form. The IRDAI Corporate Governance Guidelines, 2024 and the RBI's Master Direction on Governance, 2024 both expect board oversight of culture, but expect rather than prescribe.
A risk-culture-conscious board does five things consistently.
First, it spends meaningful time with the second-line heads in executive session, without the CEO or management present. The chair sets a pattern of asking what is being decided by management that risk or compliance would not approve.
Second, it tracks the tenure and exit reasons of CROs, compliance heads, internal auditors, and chief actuaries across the institution and its subsidiaries. Frequent exits, especially with non-disclosure agreements, are a red flag.
Third, it treats whistleblower reports as a board-committee agenda item, not as a management report. The audit or risk committee should see every material whistleblower case and the resolution path.
Fourth, it links executive compensation to risk metrics, not just financial metrics. Deferral, clawback, and conduct adjustments should be explicit and applied.
Fifth, it publishes a culture statement that is specific enough to be falsifiable. Generic statements like "we put the customer first" are pre-failed; specific commitments like "we will not approve a product unless the compliance head signs off" can be tracked.
Insurance-Specific Culture Failures
Indian insurance has its own pattern of culture failures, less spectacular than banking collapses but more pervasive. Three are visible in IRDAI enforcement and policyholder ombudsman data.
The first is target-driven mis-selling in life insurance, particularly through bancassurance and corporate agency. Persistency below 60% at 13 months is a near-certain sign of culture failure, not just product failure. Insurers and bank-partners that allow this without consequence management are propagating the failure across cohorts.
The second is claim repudiation culture in health and motor insurance, where front-line claim handlers are tacitly rewarded for repudiations that hold up against ombudsman or court challenge, regardless of fairness. The IRDAI Master Circular on Health Insurance Business, issued in May 2024, pushes hard against this by setting strict service standards: insurers must decide cashless pre-authorisation requests within one hour of receiving them, grant final discharge authorisation within three hours of the hospital's request (bearing any additional cost of delay themselves), and move toward 100% cashless settlement. The circular also tightened reimbursement timelines and curtailed the practice of repudiating claims on technical grounds after a policy has run for the moratorium period. These are concrete, measurable obligations, but rewards structures and supervisory tone inside the insurer still determine whether handlers treat them as a floor to clear or a target to game. A board that reads only the headline settlement ratio, and not the spread of repudiation reasons and ombudsman reversal rates beneath it, will miss a repudiation culture that is technically compliant.
The third is TPA accountability gaps, where insurer and third-party administrator blame each other for delays and denials, leaving the policyholder caught between them. The culture failure here sits at both ends: insurers that do not invest in TPA oversight, and TPAs whose internal incentives reward throughput over fair adjudication. The IRDAI's grievance data and the Insurance Ombudsman award patterns expose where this is happening, because complaints cluster around specific insurer-TPA combinations rather than spreading evenly.
A fourth, quieter pattern sits in commercial and corporate lines: under-reserving and optimistic loss-ratio reporting to protect quarterly results, and the slow handling of large or contested commercial claims where a fair settlement would dent the period. Here the policyholder is a business, often advised by a broker, and the culture failure shows up as disputed property and liability claims that drag for years. Each of these patterns is visible in data the institution already holds. The question is whether the board chooses to look.
Repairing a Damaged Culture
Repair is harder than prevention because the surviving population has learned to operate in the broken culture. Three interventions consistently move the needle, drawn from post-failure remediation programmes at Indian banks and global insurers.
First, change the consequence pattern visibly. The first 12 months of remediation should include at least one senior departure for risk-culture reasons, communicated internally with enough specificity that staff understand the standard. Quiet exits do not signal change.
Second, promote known dissenters. The institution almost always has staff who flagged the failing behaviour before the failure. Identifying and elevating them, including formally on the executive committee, is the most credible internal signal that the rules have changed.
Third, redesign incentive structures end to end. New variable-pay schemes with deferral, clawback, and risk-adjusted scoring take a full performance cycle to bite. Until they do, staff continue to optimise for the old scheme, which is what got the institution into trouble.
Culture repair is a 24 to 36 month effort even with capable leadership. Boards should sequence the work accordingly and resist the temptation to declare victory on early-cycle metrics.
What This Means for Insurance Buyers and Brokers
Risk culture is not only the regulator's concern; it is a live underwriting and procurement variable for any corporate buyer and the broker advising them. Two practical implications follow.
First, the counterparty's culture is part of the risk you accept. A corporate placing a large property or liability programme is, in effect, buying the claims culture of the insurer behind the wording. Two insurers can offer near-identical policy wordings and premiums and behave very differently at the moment of a contested claim. Brokers earn their fee partly by knowing which insurers honour the spirit of a wording and which litigate every ambiguity, and by steering clients away from carriers whose internal incentives reward repudiation. This intelligence is qualitative and accumulates over many claims; it rarely appears on a price comparison sheet. Tracking declinature reasons, ombudsman reversals, and settlement timelines across the carriers on a panel turns an impression into evidence a risk manager can act on.
Second, a buyer's own risk culture shapes its insurance outcomes. Underwriters increasingly price the quality of a buyer's governance, not just its loss history. A financial institution or large corporate that can show a functioning second line, visible consequence management, and clean whistleblower handling presents a better risk and supports a stronger case at renewal, particularly for directors and officers (D&O) liability, where the insured event is so often a governance or conduct failure of exactly the kind described above. D&O underwriters scrutinise board independence, the tenure of control-function heads, and the institution's track record on disclosure, because these predict claims. A buyer that has done the culture work has a concrete renewal argument; one that has not should expect tighter terms, higher retentions, and closer questioning.
For brokers and risk managers, the operational task is to make this evidence routine rather than anecdotal: maintain a structured record of how each insurer on the panel actually behaves on claims, and translate the client's own governance improvements into the submission the underwriter sees. Sarvada supports brokers in capturing and surfacing this kind of carrier-behaviour and submission intelligence across a panel, so that placement and renewal advice rests on observed conduct rather than memory. Request Access to see how the platform fits a broker's commercial-lines workflow.
