When I was about twelve, I sat a maths test. The first question was this: take one, add one, double the result, divide by four. What is the answer?
The answer is one. I knew it almost at once, then sat and stared, certain I had missed a trick, because surely the first question could not be that simple. I kept coming back to it, and each time, unable to accept that a single digit was all that was wanted, I redrew the figure over my answer until it became an inky splodge. To rescue it, I gave the number a flag at the top and a curl at the foot so there could be no doubt it was a one. My teacher read it as a two, and marked it wrong. Nineteen out of twenty, and the mark I lost was the easy one. Not because I got the answer wrong, but because I could not leave a right answer alone.
I have seen the same instinct play out across my career in financial economic crime risk, where the stakes are rather higher than a single mark. The answer is often simpler than we are willing to accept, and we pay for the refusal.
Caution is rational, and that is the problem
It would be easy, and wrong, to put over-caution down to timidity. People are behaving rationally. For two decades the industry has sent one consistent signal: this work is critical, the consequences of failure are severe, and there is now personal, sometimes criminal, liability when it goes wrong. Set against that, no one is ever called to account for having taken something too seriously. The person who over-classifies is safe; the person who under-classifies is exposed. Caution is not a character flaw. It is the rational response to the incentives we have built. Repeated across an organisation, a rational individual choice becomes a structural one.
What over-classification costs
Picture a junior analyst with a borderline file. Low or medium? Medium or high? The incentive is unambiguous: under-rate it and be wrong, and you are exposed; over-rate it, and no one will ever question you. So the borderline call goes up. It almost always goes up.
Multiply that one safe choice across thousands of files. A higher-risk customer base means more enhanced due diligence and shorter review cycles, and usually, though not always, more monitoring work as well. The institution pays for more hands, or asks the same team to work faster to stay afloat. Neither is free, and a team working at pace, under pressure, is more likely to make mistakes. Caution that made sense on a single file becomes, in aggregate, a machine for manufacturing its own backlog.
Caution that made sense on a single file becomes, in aggregate, a machine for manufacturing its own backlog.
Proportionality is not the soft option
Yet this is where it stops being a cost argument. Regulators expect mitigation to be proportionate; the risk-based approach is the foundation a risk management framework is built on. Blanket over-classification is not the cautious, compliant posture it feels like from the inside. It is a quiet departure from the principle the rules are actually built on. Proportionality is a governance obligation: setting controls at a level driven by the institution’s risk profile and appetite. We have convinced ourselves the disproportionate response is the safe one, when the rules ask for the proportionate one.
None of this is an argument for building the wrong things. Much of what looks excessive was built under a consent order, to a standard high enough to satisfy a regulator who had run out of patience, then left running at full intensity long after the emergency passed. The fault is rarely the process. It is how, and at what level, we choose to apply it.
Proportionality is not the absence of rigour. It is rigour aimed correctly: controls set at the level the risk warrants, and competent people given the room to evidence that judgement clearly. The answer, far more often than we let ourselves believe, really is one. The skill, earned over years, is being senior enough to write it down plainly and resist the urge to reach for the calligraphy.