---
title: Cara Williams Shares Takeaways from the ABA’s First-Ever Risk and Compliance Virtual Conference
description: Regulatory Compliance and Risk Management practice lead Cara Williams shares her thoughts and key takeaways from the 2020 ABA Risk & Compliance Virtual Conference.
image: https://www.spinnakerconsultinggroup.com/hubfs/Risk%20and%20Compliance%20Virtual%20Conference.jpg
---

[![Spinnaker Consulting Logo](https://www.spinnakerconsultinggroup.com/hubfs/spinnaker-logo.svg "Spinnaker Consulting Logo")](https://spinnakerconsultinggroup.com)

[tel:804.510.0768](tel:804.510.0768) Menu

- [Culture](https://www.spinnakerconsultinggroup.com/culture)
- [Work](https://www.spinnakerconsultinggroup.com/work)
- [Differentiators](https://www.spinnakerconsultinggroup.com/differentiators)
- [Insights](https://www.spinnakerconsultinggroup.com/insights)
- [Experts](https://www.spinnakerconsultinggroup.com/experts)
- [Contact Us](https://www.spinnakerconsultinggroup.com/contact)

 Customer Channels & Operations Management, Data & Analytics, Risk Management & Regulatory Compliance

 4 minute read

# Cara Williams Shares Takeaways from the ABA’s First-Ever Risk and Compliance Virtual Conference

Aug 14, 2020

Written by: Cara Williams

- Share Post:
- [mailto:?subject=Spinnaker%20Consulting:%20Cara%20Williams%20Shares%20Takeaways%20from%20the%20ABA’s%20First-Ever%20Risk%20and%20Compliance%20Virtual%20Conference&body=Here%20are%20some%20insights%20from%20Spinnaker%20Consulting%20I%20think%20you%20should%20check%20out:%20https://www.spinnakerconsultinggroup.com/insights/blog/cara-aba-risk-compliance-virtual-conference](mailto:?subject=Spinnaker%20Consulting:%20Cara%20Williams%20Shares%20Takeaways%20from%20the%20ABA’s%20First-Ever%20Risk%20and%20Compliance%20Virtual%20Conference&body=Here%20are%20some%20insights%20from%20Spinnaker%20Consulting%20I%20think%20you%20should%20check%20out:%20https://www.spinnakerconsultinggroup.com/insights/blog/cara-aba-risk-compliance-virtual-conference)
- <https://www.linkedin.com/sharing/share-offsite/?url=https://www.spinnakerconsultinggroup.com/insights/blog/cara-aba-risk-compliance-virtual-conference>

Late last month, I had the pleasure of attending and facilitating a couple of on-demand panels for the American Banking Association’s (ABA’s) first-ever Risk and Compliance Virtual Conference.

Needless to say, there were quite a few differences from attending in person – namely the missed opportunity to spend time with industry friends and fellow risk and compliance enthusiasts. And while there’s no re-creating the power of face-to-face interaction, the ABA did a phenomenal job of pulling together topics and experts on a very condensed timeline. 

In “normal” times, the Risk Management Conference and Regulatory Compliance Conference are two separate conferences, held at different times of the year. For as long as I can remember, the former was historically a broad-ranging event (with a smaller, targeted audience) that focused more heavily on financial risk and, in recent years, began to branch out to include more sessions on non-financial risk types – like operational risk. The latter was a larger event (growing larger and larger each year) that was hyper-focused on compliance risk.

As I attended this year’s combined virtual conference, I started to think about how appropriate it was to combine the two, since more and more often we’re seeing the convergence of compliance risk program elements with operational risk and other non-financial risk types, such as reputation risk and strategic risk. This is in large part due to companies’ increasing focus on building and maintaining enterprise risk management programs – and it makes a lot of sense, based on my own experience. Banks typically tend to have more mature compliance risk programs, as compared to operational risk, so I can see a clear opportunity to leverage elements of one to fortify the other.

As these risk types begin to converge, it’s critical to establish common taxonomies. In some cases, risk programs have been built in silos and are often managed in disparate systems. Banks should be working toward system-wide reporting and creating an aggregated, holistic view of their risk profile. But this effort becomes labor intensive if you don’t have a risk-type-neutral framework in place to establish the shared risk classification.

The effort to create one is necessary, though, because it’s imperative that your risk programs are able to “talk” to one another. The alternative opens up a whole new set of risks: first, an inability to produce meaningful, actionable reporting; and second, aggregating risk across the enterprise becomes cumbersome, leading to difficulties in adequately identifying, measuring and controlling your risk.

As I reflect on this year’s wonderful live and on-demand sessions, a few key themes are resonating with me. In many ways, the pandemic has desensitized us to words and terms like “unprecedented,” “record-breaking,” “new normal,” and “shifting priorities” – they’ve become part of our everyday vernacular.  But as I look at those words in reflection to the work I love, they can and should be applied to the way we think about existing risk and compliance management programs.  

It’s a paradigm we must adjust to meet the demands of this “new normal.” While many organizations shifted their focus at the beginning of this crisis, we’ve reached a point where it’s time for all of us to address key issues and continue to ensure compliance, manage risk, and keep the business going. Right now, I’m looking at this through a few lenses:

- How do we adjust to prolonged remote work? And what processes and procedures need to be put in place for organizations that are ready to transition back into an office setting? The answers will be different depending on whether you’re talking about a corporate office or, in the case of our FI partners, a branch location. But the sheer fact that we’re asking customers to wear masks inside our facilities is an illustration of just how far we’ve come – and a sign of necessary progress yet to occur – before this pandemic comes to an end (or is at least manageable).
- Given this environment, risk is evolving at a rapid pace. With that in mind, it’s important for banks to review their risk appetite as well as supporting models and adjust accordingly. Strategy and strategic risk factors should also be on the table for ongoing discussion. If we’ve learned anything from the past few months of quarantine, it’s that even after you establish and align on these elements, they should be revisited on a regular basis – at least quarterly – to ensure they remain appropriate for your institution.
- As we ease into our new way of working and regulatory bodies have the framework in place for safe remote inspection, it’s important to have a solid, documented and repeatable root cause analysis framework in place to ensure remediation and issue management efforts pass review and don’t reoccur. With that in mind, take the proper time and care now to fully understand root causes before you start active remediation planning. You’re sure to see a big return on investment on that effort, as it will save a significant amount of time in the long run.

Technology particularly in the regtech/fintech spaces will continue to play an increased role in our risk programs as we explore opportunities to migrate from manual processes and controls toward automation. Ultimately, this will provide a huge lift in efficiency and risk mitigation. I see real opportunity for this in the monitoring and testing spaces.

Automated monitoring allows for real-time insights, which will help financial institutions identify issues sooner and make remote teams more nimble. Automation also will make testing more representative, enabling banks to move away from small samplings to a situation where they could test an entire population, leading to increased accuracy and greater coverage by no longer relying on just representative populations.

As a first step in this transformation, it’s imperative that organizations take the time to find a single source of truth for their data. As operational risk and compliance risk converge and we move toward enterprise risk management programs, organizations must ensure they have a single source of information to support the various elements of their risk management program (i.e., key performance and key risk indicators).

In these uncertain and unprecedented times, it’s easy to get overwhelmed. I had so many great takeaways from the virtual conference that added to all the thoughts already swirling in my mind … but you can’t tackle everything all at once. No matter where you are in your risk management program journey, it’s crucial to review your existing framework now and ensure it’s in order and as strong as it can be. Only then can you start your renovations and prepare for what’s next in this “new normal.”

 

 

 

- Share This Post
- [mailto:?subject=Spinnaker%20Consulting:%20Cara%20Williams%20Shares%20Takeaways%20from%20the%20ABA’s%20First-Ever%20Risk%20and%20Compliance%20Virtual%20Conference&body=Here%20are%20some%20insights%20from%20Spinnaker%20Consulting%20I%20think%20you%20should%20check%20out:%20https://www.spinnakerconsultinggroup.com/insights/blog/cara-aba-risk-compliance-virtual-conference](mailto:?subject=Spinnaker%20Consulting:%20Cara%20Williams%20Shares%20Takeaways%20from%20the%20ABA’s%20First-Ever%20Risk%20and%20Compliance%20Virtual%20Conference&body=Here%20are%20some%20insights%20from%20Spinnaker%20Consulting%20I%20think%20you%20should%20check%20out:%20https://www.spinnakerconsultinggroup.com/insights/blog/cara-aba-risk-compliance-virtual-conference)
- <https://www.linkedin.com/sharing/share-offsite/?url=https://www.spinnakerconsultinggroup.com/insights/blog/cara-aba-risk-compliance-virtual-conference>

## Related Articles

### [6 Big Myths (and Truths) about Compliant Loan Advertising Nov 5, 2020 The Big Picture Pick up recent copies of The Wall Street Journal or American Banker, and you’ll see headline after headline about consent orders and hefty fines issued by the Consumer Financial Protection Bureau to mortgage companies caught using deceptive advertising practices. This summer alone, eight have been issued. Two things immediately strike me when I see these stories: Many of these cases didn’t have to happen. And while these particular consent orders were concentrated in the mortgage sector, similarly problematic issues are most certainly occurring in other lending segments across the financial services industry. After a hundred years or so, you’d think we would know how to follow regulatory rules –particularly those put in place to protect consumers. Indeed, the first such laws were framed by the states before World War I – although the first meaty federal law, the Truth in Lending Act, wasn’t passed until 1968. Every new regulation layered in since then largely continues to further shield consumers from unfair practices – which often start with glossy ad campaigns designed to get them in the physical or digital door. The reasons why we’re still struggling with compliance aren’t too difficult to understand: turnover within organizations, competing priorities, a lack of sound controls, new staffers who are unfamiliar with existing regulations, and a never-ending list of new ones, including Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) and the Mortgage Acts and Practices (MAP) – Advertising Rule. There’s also often a gap between the intent of any new regulation and how marketing teams interpret it. The risks of not crossing every “t” and dotting every “i” are significant, as evidenced by these recent consent orders. Doing things the wrong way also can mean costly penalties, time-consuming regulatory remediation, and loss of customer trust – which can translate into higher complaint volumes and even lawsuits. Let’s explore some long-lingering myths about how banks advertise their lending products – and, more importantly, what your financial institution should be doing. MYTH: Legal and Compliance don’t need to review my ad since I’m the expert in marketing. FACT: This is the biggest myth that persists in financial services marketing and advertising. Every word you use to communicate has specific and nuanced meanings, and your legal and compliance teams have a responsibility to protect your company and consumers alike. No external ads or marketing materials should be released until you get signoff from your legal or compliance team. It’s not any more complicated than that. MYTH: Our marketing team knows what Legal and Compliance have told us. We get it, but we need leeway to make our ads eye-catching and even a bit sexy so we can get business in the door. One little word change doesn’t really make a difference. FACT: Remember how former President Bill Clinton faced legal drilling over his interpretation of the word “is”? You’d be surprised at exactly what a bank must validate before it advertises anything as “free.” That word “free” – and countless more – are triggers, often requiring specific disclosures on how they apply to what you’re advertising right at that moment. Ideally, your marketing and advertising teams should collaborate almost daily with your legal and compliance teams. Of course there’s going to be some friction between the advertising folks, who see in every color of the rainbow, and the legal and compliance folks, who typically only see in black and white. The important thing is to build processes and procedures that enable effective and efficient reviews of all advertising and marketing materials, and that begins with concepts. When you involve those responsible with compliance up front, they can help rethink an approach in ways that ensure the final ad meets regulatory requirements. Also, try taking their early “no” to mean “not yet” and be open to ideas on what could translate into an easy reframing. But go to them at the end with an ad that fails on every compliance front, and their “no” will be just that. When I was at a bank that now has more than $30 billion in assets, my compliance team worked diligently to become a strategic partner to the marketing team. It took some time, but our peers came to see that we never aimed to derail their vision. As our relationship evolved, so did our interactions. In fact, we created a desktop resource that allowed marketers to easily look up the latest laws or match sales terms with the necessary disclosures, delivering a self-service tool that also empowered them to create responsibly and expedite the review process. Rest assured, the goal of your bank’s lawyers and compliance officers is not to thwart creativity, but to ensure that amazing ad concepts give consumers precise, clear information about the company’s products and services, allowing them to make smart financial decisions. Believe me: Compliance teams want powerful, compelling and even award-winning advertising that brings more revenue in the door, because when you have that, everyone benefits. MYTH: Our market competitor ran an ad just like that. If they got away with it, then it’s OK and the legal and compliance team is overreacting. FACT: This is the corporate version of your mother asking you, “If everyone was jumping off a cliff, would you do it, too?” The only truth here is that your competitor ran an ad. You don’t really know if that financial institution “got away with it.” In fact, you might learn not too far down the road that your competitor actually got caught red-handed with a compliance violation. After all, the underlying premise of advertising is to spread the word, and regulators are paying close attention. Frankly, you should be analyzing what your competitors are doing, but I’m not talking about their advertising. Take a good look at every consent order or other regulatory action you hear about and compare it to what’s happening in your shop. Are you doing things the right way? Are you identifying and avoiding the possible risks in your process? In other words, consider that the teacher has given you every answer to the test, and you don’t want to fail down the road. MYTH: The bank’s advertising agency developed that campaign – not our internal team – so we’re not going to get in any trouble. FACT: Time and time again, oversight organizations stress that any third-party vendor – whether it’s an ad agency or a cross-sell phone queue – is a seamless extension of your financial institution. If they get it wrong, so do you. You don’t outsource the compliance responsibility along with the work. MYTH: All of that applies to my bank or mortgage company – not to me as a loan officer. I’ll post a special offer on my social channels just for my customers. FACT: Your very title of “loan officer” means you’re an officer of your financial institution, and the same exact requirements apply to you. Without question, the growing influence of social media makes consumer outreach easy, but the brevity and ease of these same platforms also make it more difficult to keep your team members from going rogue. The same compliance standards apply to all of your advertising, including any unsanctioned materials. Every employee needs to understand this responsibility. (BTW, don’t forget about old-fashioned tactics, such as a quick sales flyer that a teller might create and post in a branch. Whether that flyer meets your advertising brand standards is the least of your worries, because you’re most likely out of regulatory compliance.) MYTH: Getting an internal review takes so much time that we’re losing competitive advantage. FACT: Doing it right takes a fraction of the time needed to fix things – particularly if you’re cited for a regulatory infraction – and maintains your institution’s reputation. Yes, a legal or compliance review is another step in your marketing process, but it’s a short blip in the lifetime of a successful business. In my previous role, I was intentional about building interactions with the marketing team that served everyone’s needs as efficiently as possible. If a federal agency comes at you with a consent order or Matter Requiring Attention, you’re going to spend significantly more time finding the root issue, solving for your misstep, gaining regulatory signoff and getting back to work. You also can’t rebuild consumer confidence overnight – even with the most attractive offers in your marketplace. After all, if your customers know you’ve been under scrutiny before, do you think they’re going to trust that you’re being straight with them this time around? Risk Management & Regulatory Compliance, Compliance, Risk Management 5 minute read](https://www.spinnakerconsultinggroup.com/insights/blog/deceptive_loan_advertising)

### [Fintechs Must Plan for their Second Act Apr 28, 2022 The number of new fintechs continues to increase and regulators have made it clear they have their eye on this exploding industry. With increasing consumer protection regulations on the horizon for banks, we are starting to see the cloud of regulatory oversight moving closer and closer to fintechs. So fintechs, it is time to consider the next step. Risk Management & Regulatory Compliance, Business Strategy, Change Management, Governance & Policy 5 minute read](https://www.spinnakerconsultinggroup.com/insights/blog/fintech_second_act)

### [Cultivate a Risk-Aware Culture to Ready Your Bank for Change Jul 20, 2021 Change is about the only constant in banking today. Inside the organization, you’re processing a steady stream of requests for new products or customer services. Coming from the outside are regulatory updates and unpredicted pressures, such as the COVID-19 pandemic. Risk Management & Regulatory Compliance, Program Build Out, Change Management, Risk Management 2 minute read](https://www.spinnakerconsultinggroup.com/insights/blog/aba_podcast_culture_cultivation)

- Let's **Talk**
- [804.510.0768](tel:804.510.0768)
- [info@spinnakerconsultinggroup.com](mailto:info@spinnakerconsultinggroup.com)

- [mailto:info@spinnakerconsultinggroup.com](mailto:info@spinnakerconsultinggroup.com)
- <https://www.linkedin.com/company/2876732>

#### Subscribe To Our Blog

Like how we think? Subscribe to have our articles delivered direct to your inbox each month.

**Headquarters:** [8000 Franklin Farms Drive, Suite 100, Richmond, VA 23229](https://www.google.com/maps?ll=37.60197,-77.545775&z=17&t=m&hl=en&gl=US&mapclient=embed&cid=10375661570052893047)

 ©2026 Spinnaker Consulting Group. All rights reserved.

- [Privacy Policy](https://www.spinnakerconsultinggroup.com/privacy-policy)

![](https://px.ads.linkedin.com/collect/?pid=552770&fmt=gif)