The Evidence of Governance Failure
Boeing, Wirecard, Silicon Valley Bank, Credit Suisse and the Post Office each failed with a full governance stack in place. This chapter examines the case studies, showing how the same structural defects produced catastrophic outcomes across different sectors, jurisdictions and regulatory regimes.
The three structural defects are not abstractions. They have surfaced repeatedly and observably, in some of the most consequential governance failures of the past two decades.
This section examines five cases: Boeing 737 MAX, Wirecard, Silicon Valley Bank, Credit Suisse and The Post Office Horizon scandal. Each has been subject to public inquiry, regulatory post-mortem, legal proceedings, or some combination of all three. The governance failures in each case are matters of record, not inference.
A note on counterfactuals. This paper does not claim that any governance intervention would have prevented these failures. It claims something more modest and more defensible, that a continuous, adversarial challenge function, operating with independence, access, and a mandate to stress-test assumptions, could have changed the information available to decision-makers, and might have changed the timing and nature of their response. The counterfactual offers option value, not certainty.
Boeing 737 MAX: The Absence of Safety at Board Level
On 29 October 2018, Lion Air Flight 610 crashed into the Java Sea, killing all 189 passengers and crew. Less than five months later, on 10 March 2019, Ethiopian Airlines Flight 302 crashed near Addis Ababa, killing all 157 on board. Both crashes were caused by the same system, the Maneuvering Characteristics Augmentation System, or MCAS, a flight-control software designed to prevent aerodynamic stall by automatically pushing the aircraft’s nose down. In both accidents, MCAS activated erroneously based on data from a single faulty angle-of-attack sensor and pushed the nose down repeatedly, a failure mode that Boeing’s safety analysis had not adequately considered.
A U.S. House Committee investigation [1] found systemic failures in Boeing’s design process and the FAA’s delegation of certification authority. Boeing had been permitted to certify the majority of its own work through the FAA’s Organization Designation Authorization programme, creating an inherent conflict of interest in which the manufacturer was, in effect, its own regulator.
The governance failure.
The Boeing board’s failure was not primarily one of competence. It was a failure of architecture. Prior to August 2019, after both crashes, no Boeing board committee charter assigned responsibility for aircraft safety oversight [1, 2]. Safety, the most mission-critical risk in commercial aviation, sat outside the governance framework entirely. When a Boeing engineer wrote to factory leaders in the summer of 2018, “I’m sorry to say that I’m hesitant about putting my family on a Boeing airplane,” [1] no mechanism existed for that concern to reach the board.
After the first crash, Boeing management waited ten days before notifying the board. The CEO then reported that the 737 MAX was safe. At the February 2019 board meeting, one month before the second crash, the board decided to defer any internal investigation to regulatory processes, even though several directors were aware of internal communications concerning MCAS deficiencies and the withholding of information from the FAA.
The consequences were extraordinary. Three hundred and forty-six people died. Boeing agreed to a $2.5 billion settlement with the U.S. Department of Justice in January 2021 [3], with additional settlements totalling $1.1 billion in 2025. The board paid $237.5 million to settle a Caremark derivative claim [2], the largest Caremark cash settlement in Delaware Chancery Court history, based on the court’s finding that the board had failed to monitor a “mission critical” operational risk.
Mapping to the structural defects.
Episodic engagement. The board engaged with aircraft safety only after catastrophic failure. Between scheduled board meetings, safety-critical concerns, including the engineer’s warning and the MCAS design evolution, were filtered through management channels that had every incentive to minimise them. Oversight was periodic but the risk was continuous.
Consensus dependency. The board deferred to management’s reassurance that the aircraft was safe and to the FAA’s certification process. The consensus, between management, the regulator, and the board, that the 737 MAX was airworthy was accepted without independent, adversarial examination. When the consensus was wrong, 346 people paid the price.
Absence of institutionalised challenge. No function existed to challenge the board’s assumption that safety could be left outside committee charters. No mechanism existed for technical experts to escalate safety concerns directly to the board. No structured process subjected MCAS design assumptions to adversarial review at governance level.
The Counterfactual A continuous challenge function with a mandate to review governance architecture might have identified the absence of safety from board committee charters as a structural defect before either crash. A red team protocol applied to the MCAS programme might have surfaced the single-sensor dependency and repeated-activation failure mode that Boeing’s own safety analysis missed. None of this guarantees a different outcome, but it changes the information available to decision-makers, and the timing at which it arrives.
The Caremark significance.
The Boeing settlement extended the Caremark doctrine in a direction with profound implications for governance. In In re Caremark (1996) [4], the Delaware Chancery Court established that directors have a duty to implement information and reporting systems. In Marchand v. Barnhill (2019) [5], the Delaware Supreme Court held that the board of ice cream manufacturer Blue Bell had breached its Caremark duties by failing to monitor food safety, a “mission critical” risk. Boeing confirmed the principle [2]: boards can be held liable for failing to build governance architecture around their organisation’s most critical operational risks, an extension beyond traditional compliance monitoring.
The trajectory is clear. Courts are no longer asking whether boards had governance frameworks. They are asking whether those frameworks were designed to address the risks that actually mattered.
Wirecard: When Every Line of Defence Fails Simultaneously
On 18 June 2020, Wirecard AG announced that €1.9 billion in cash balances, purportedly held in trustee accounts in the Philippines, could not be verified. Four days later, the company admitted that the funds “probably never existed.” Three days after that, Wirecard filed for insolvency. The company’s share price, which had peaked at a market capitalisation of approximately €24 billion following its entry to the DAX 30 in September 2018, collapsed to near-zero within days.
Wirecard is the case in which every layer of the governance architecture failed simultaneously. Langenbucher and Leuz [6] identified the collapse of five distinct governance layers, namely internal controls, supervisory board oversight, external audit, auditing oversight bodies, and the market supervisor. The KPMG special investigation [7], commissioned by Wirecard’s own supervisory board, and the subsequent Bundestag parliamentary inquiry [8] documented the scale and mechanism of these failures in detail.
The internal failure.
Wirecard’s fraud was sustained through fictitious “Third-Party Acquiring” partnerships in Asia that generated €1.9 billion in fake revenue over five or more years [7]. Internal controls did not detect the fabrication. Risk management rated the trustee account receipts as low risk. Internal audit did not perform independent verification of overseas partner transactions [8].
The external failure.
EY, Wirecard’s external auditor, accepted screenshots and PDF bank statements as evidence of cash balances for three consecutive audit cycles without requesting independent third-party bank confirmations [7, 8]. BaFin, the German market supervisor, treated Wirecard as a technology company rather than a financial institution, exempting it from banking-level supervisory scrutiny [8]. When the Financial Times published evidence of fraud, sourced from internal whistleblower Pav Gill, BaFin’s response was to file a criminal complaint against the journalists and ban short-selling of Wirecard shares [8].
The suppression of challenge.
In March 2018, more than two years before the collapse, Gill reported evidence of illegal money flows through Wirecard’s Singapore office to COO Jan Marsalek. Marsalek immediately quashed the investigation and removed the whistleblower from the inquiry. Gill was forced to go to external media because internal escalation had been actively suppressed.
Mapping to the structural defects.
Episodic engagement. The supervisory board engaged with Wirecard’s Asian operations on a quarterly and annual cycle, processing management presentations that described a high-growth fintech success story. The board did not establish continuous monitoring of the Third-Party Acquiring partnerships that constituted the fraud’s mechanism.
Consensus dependency. The consensus, shared across the supervisory board, EY, and BaFin, was that Wirecard was a legitimate technology company disrupting the payments industry. Short-seller reports and journalistic investigations were characterised as motivated attacks rather than evidence requiring investigation. The consensus was so strong that the regulator actively punished those who challenged it.
Absence of institutionalised challenge. Wirecard had no protected mechanism for dissent. When the whistleblower raised evidence of fraud internally, the function that should have escalated it instead suppressed it. The supervisory board had no independent capability to verify the financial claims on which its oversight depended. No adversarial function existed to stress-test the revenue figures, examine the Asian partnerships, or challenge the narrative that made the supervisory board comfortable.
The Counterfactual A continuous, adversarial challenge function operating independently of management might have applied fraud-scenario wargaming to the Third-Party Acquiring revenue stream, asking, before any whistleblower came forward, what evidence would be required to confirm that this revenue was real. A structured challenge process might have asked why €1.9 billion in cash sat in Philippine trustee accounts rather than in directly auditable bank deposits. A function with a mandate to protect dissent might have given Pav Gill a route to the supervisory board rather than to the Financial Times.
Silicon Valley Bank: The Risk That Everyone Saw and Nobody Escalated
Silicon Valley Bank failed on 10 March 2023. The proximate cause was a bank run. Depositors withdrew $42 billion in a single day on 9 March, approximately 25% of total deposits. However, the underlying cause was a governance failure that had been accumulating, visibly, for years. The failure did not remain contained to SVB. Within 48 hours, Signature Bank also failed. First Republic Bank followed in May 2023 with approximately $229 billion in assets, surpassing SVB as the largest U.S. bank failure since Washington Mutual. The cascading crisis spread to Europe, delivering the final blow to Credit Suisse, which became the largest distressed bank rescue in world history [9].
SVB’s business model was built on concentration, with heavy exposure to venture capital deposits, technology-sector clients, and long-duration investment securities. At year-end 2022, the bank held $117 billion in investment securities, approximately 56% of total assets, with roughly $91 billion classified as held-to-maturity, carrying an average duration of approximately six years. [9] [10] This meant that for every 100-basis-point increase in interest rates, the bank faced approximately 6% in unrealised losses on its HTM portfolio. Between March and December 2022, the Federal Reserve raised rates by approximately 425 basis points [10]. By year-end, the bank’s unrealised losses on its securities portfolio had reached approximately $17 billion, exceeding its entire book-value equity capital of $15 billion [9].
The Federal Reserve’s post-failure review was unusually candid [10]. It acknowledged that supervisors “did not fully appreciate the extent of the vulnerabilities” at SVB. Fed examiners had identified interest rate risk deficiencies in the 2020, 2021, and 2022 CAMELS examinations but did not issue a formal supervisory finding until November 2022, four months before the bank failed. SVB had received “satisfactory” ratings on management and governance from 2017 through 2021, despite documented weaknesses [10].
The CRO vacancy.
In April 2022, SVB removed its Chief Risk Officer [10]. The position remained vacant for nine months, from April 2022 to January 2023, during precisely the period in which the Federal Reserve was raising interest rates at the fastest pace in four decades and the bank’s unrealised losses were accumulating at extraordinary speed. During the most critical period of risk exposure in the bank’s history, the function responsible for independent risk oversight had no appointed leader.
Mapping to the structural defects.
Episodic engagement. SVB’s board engaged with risk on a quarterly cycle, though meetings increased to eighteen annually in 2022. The Federal Reserve Bank of San Francisco examined SVB 26 times and its holding company a further 17 times between February 2018 and March 2023 [11]. Neither cadence was sufficient. Between examinations, unrealised losses accumulated continuously. The CRO vacancy meant that no one was continuously monitoring the emerging risk during the most volatile nine months of the bank’s existence. The disconnect extended inside the regulator itself. In June 2022, the Federal Reserve Board’s own surveillance team issued a special topic report identifying SVB as one of the institutions with the highest levels of unrealised losses in the system and placed it on the Systemwide holding company watch list with a “high adverse change probability” warning [11]. Two months later, the San Francisco examiners responsible for day-to-day supervision of SVB issued a supervisory letter describing the bank’s balance sheet structure as mitigating the risks associated with its rapid growth [11]. The Board’s analytical function caught the risk. The examination function, operating on its own periodic cycle, did not act on it.
Consensus dependency. The consensus, shared between SVB management, the board, and the Federal Reserve, was that SVB’s concentration in venture capital deposits was a strategic advantage rather than a systemic risk. Management’s assurance that interest rate risk was manageable through liability management was accepted without independent verification. The FDIC’s subsequent civil lawsuit against 17 former SVB directors and officers alleges that this was not passive complacency. According to the FDIC’s complaint, management “repeatedly breached its own interest-rate risk policies and metrics” and then “manipulated assumptions in one of the risk models to cover up the breaches” [12, 13]. The complaint further alleges that management removed interest-rate hedges on the securities portfolio to boost short-term profits, increasing the bank’s exposure at the precise moment rates were rising, and approved dividends to the parent company months before the bank failed [12]. Neither the board nor the regulator challenged any of these actions. If the allegations are substantiated, the consensus provided cover for the active concealment of internal policy violations.
Absence of institutionalised challenge. During the nine-month CRO vacancy, no formal mechanism existed for independent risk escalation to the board. Fed examiners identified the interest rate risk deficiency three years running but did not escalate their findings to a formal supervisory action until it was too late. The cost to the FDIC’s Deposit Insurance Fund was an estimated $16.1 billion.
The quantified regulatory record makes the absence of challenge measurable. The Basel Committee’s interest-rate risk in the banking book (IRRBB) standard, implemented in the United Kingdom, Canada, and the Euro area but never fully adopted in the United States, would have identified SVB’s asset-liability strategy as an outlier requiring remedial action ten quarters before the bank failed [14]. The liquidity coverage ratio (LCR), from which U.S. regulators had explicitly exempted banks of SVB’s size, would have required the bank to hold tens of billions of dollars more liquidity four quarters before failure. Had SVB been subject to the Basel Committee’s total loss-absorbing capacity (TLAC) standard, the FDIC would have saved an estimated $13.6 billion [14]. The risk was quantifiably actionable more than two years before the bank collapsed, under standards that peer jurisdictions already applied.
The Counterfactual A continuous challenge function might have identified the CRO vacancy as a governance defect requiring immediate board escalation, rather than allowing it to persist for nine months. A pre-mortem diagnostic applied to SVB’s interest rate exposure might have asked: “If rates rise 400 basis points in twelve months, what happens to this portfolio?” A structured adversarial review with access to internal risk reports might have identified what the FDIC now alleges, namely that management removed interest-rate hedges not to manage risk but to boost short-term earnings, and that subsequent changes to risk model assumptions were concealing, rather than correcting, breaches of the bank’s own policies [12]. The risk was visible in SVB’s own financial statements, quantifiably actionable under established Basel standards more than two years before failure [14], and flagged by the Federal Reserve’s own surveillance team eight months before the collapse [11]. What was missing was a function mandated to ensure that visible risks received commensurate governance attention.
Credit Suisse: The Limits of Internal Reform
On 19 March 2023, Credit Suisse ceased to exist as an independent institution after 167 years. The Swiss government, the Swiss National Bank, and FINMA negotiated a forced merger with UBS over a single weekend, mobilising CHF 259 billion in liquidity support and loss guarantees to prevent uncontrolled failure.
The proximate cause was a deposit run. In the fourth quarter of 2022, clients withdrew CHF 138 billion in deposits from a base of approximately CHF 370 billion held at the end of Q3, the largest share leaving in October as media speculation and loss of client confidence reinforced each other [15]. Over the same three months, the wealth and asset management businesses recorded CHF 111 billion in net asset outflows, closing a year that totalled CHF 123 billion in AUM outflows. A few short months later, the bank was gone.
The underlying cause was not a 2023 event. The Swiss Financial Market Supervisory Authority’s post-failure review [15] traces the failure to a decade of governance reform that could not establish substance. Successive interventions, new chief executives, new chief risk officers, new chairs, new committee structures, did not change how Credit Suisse made decisions. By the fourth quarter of 2022, eleven of the thirteen members of the Executive Board had been newly appointed within a short period. Senior management was unable, FINMA concludes, “to reinforce the risk culture throughout the bank in a significant and sustainable manner.” [15] Repeated changes in senior personnel had not successfully addressed the shortcomings of the underlying architecture.
The governance failure.
FINMA identifies a cluster of structural defects. Risk appetite limits and accountability for risks taken were “often not clear enough, namely in the allocation between the front-office units and the control functions” [15]. The corporate structure was complex enough to prevent “clear allocation of responsibilities and thus rigorous decision-making.” The Chair of the Risk Committee departed in April 2021, leaving an interim dual-reporting arrangement that contributed to documented breaches of supervisory obligations across the Archegos, Greensill, and Mozambique exposures [15].
The pattern is consistent across each documented loss event. Risk was visible inside the firm. Internal challenge functions reported into the same chain of authority that had created the exposure. The architecture preserved the form of governance, the committees, the charters, the reporting lines, while the substance, the willingness and capacity to challenge consensus, eroded. By the time market confidence broke in October 2022, the governance machinery had been failing for years.
Mapping to the structural defects.
Episodic engagement. Credit Suisse engaged with risk through scheduled board cycles and the supervisory cycle imposed by FINMA. Between cycles, exposures accumulated and warning signals propagated through internal channels that had every incentive to filter them. The Archegos and Greensill events were not failures of risk identification at the desk level; they were failures of escalation and accountability at the architecture level. Each event, examined post-hoc, surfaced structural weaknesses that had been visible to internal participants long before they reached the board.
Consensus dependency. The consensus, sustained across two decades of management changes, was that Credit Suisse’s governance challenges were a personnel problem. New chief executives, new chief risk officers, and new chairs were appointed on the expectation that fresh leadership would restore discipline. FINMA’s finding contradicts the premise. The issue was not the people occupying the roles but the architecture that determined what the roles could achieve. The consensus that internal reform would suffice survived every operational loss until the deposit run made it unsustainable.
Absence of institutionalised challenge. Credit Suisse had a Risk Committee, internal audit, compliance, a Chief Risk Officer, and external auditors. None operated outside the chain of authority they were meant to challenge. When the Risk Committee Chair departed in April 2021, the interim arrangement created the very dual-reporting opacity that FINMA later identified as a contributing factor to the supervisory breaches at Archegos, Greensill, and Mozambique. No function existed at board level whose mandate was independent challenge, independent of management, independent of the chain of appointments, and independent of the consensus its presence was meant to test.
The Credit Suisse case is the clearest illustration in this paper of the limit of internal reform. Twelve years and four chief executives could not establish what FINMA calls “tone from the top” because the function tasked with tone was always inside the organisation it was meant to challenge.
Post Office Horizon: Twenty Years of Institutional Consensus Against Individual Evidence
The Post Office Horizon scandal is the longest-running governance failure examined in this paper, and arguably the most instructive. It demonstrates what happens when institutional consensus is maintained, unchallenged, for two decades, and when the people who could have broken that consensus had no route to decision-makers.
Beginning in 1999, Fujitsu’s Horizon IT system was deployed across Post Office branches throughout the United Kingdom. The system contained software bugs that caused discrepancies in branch accounts. These discrepancies were attributed not to the technology but to the sub-postmasters who operated the branches. Between 1999 and 2015, over 900 sub-postmasters were prosecuted for theft, fraud, and false accounting, approximately 700 of those prosecutions conducted by The Post Office itself [16]. At least 236 individuals were imprisoned.
The human cost defies summary. Sub-postmasters lost their livelihoods, their homes, and their reputations. Families were destroyed. At least thirteen people took their own lives [16].
The Criminal Cases Review Commission [17] subsequently described the Horizon cases as the “most widespread miscarriage of justice” in its history, the largest single series of wrongful convictions in British legal history. In May 2024, Parliament passed the Post Office (Horizon System) Offences Act 2024 [18], quashing convictions en masse. As of March 2026, over £1.44 billion in compensation had been paid out, with more than 11,300 individual claimants identified.
The governance failure.
The Post Office board did not establish independent verification of the Horizon system’s reliability despite accumulating reports of errors. It accepted management’s assurance that the system was robust without commissioning independent technical audit. It had no mechanism to review criminal prosecution decisions. The authority to prosecute sub-postmasters was delegated to an operations team with a financial incentive to preserve the Horizon narrative, since the cost of admitting system failure would have been enormous.
Fujitsu’s role compounded the failure. Fujitsu employees gave evidence in court that the Horizon system was “robust” and “could not have caused” the shortfalls for which sub-postmasters were being prosecuted, despite internal knowledge of software bugs dating to the system’s deployment. The Post Office Horizon System Inquiry [16], chaired by Sir Wyn Williams, documented systematic failures spanning more than two decades across Post Office management, legal counsel, Fujitsu, and government oversight.
Mapping to the structural defects.
Episodic engagement. The Post Office board engaged with the Horizon system at its initial deployment and thereafter episodically, through annual reports and management summaries rather than through continuous monitoring of system reliability. No real-time feedback mechanism existed between the sub-postmasters who used the system daily and the board responsible for overseeing it. For twenty years, the board’s understanding of Horizon was mediated entirely through management.
Consensus dependency. The organisational consensus, that the system was reliable and that discrepancies were caused by dishonest individuals, was shared across management, the board, legal counsel, the external auditor, and the government department responsible for Post Office oversight. This consensus held for more than two decades despite hundreds of sub-postmasters independently reporting the same types of errors. The pattern was not invisible. It was visible and dismissed. The ITV drama Mr Bates vs The Post Office, broadcast in January 2024, generated the first sustained public attention the scandal had received in twenty-five years, a measure of how effectively institutional consensus can suppress individual evidence.
Absence of institutionalised challenge. No function existed within The Post Office to independently verify the Horizon system’s accuracy. No protected mechanism existed for sub-postmasters to escalate system errors to the board. No independent technical committee assessed system reliability. Complaints were filtered through management channels with every incentive to suppress them. The legal function, rather than protecting the accused’s right to challenge system reliability, actively supported the prosecution narrative.
The Counterfactual A continuous challenge function might have identified, within the first years of deployment, that hundreds of independent operators reporting identical types of shortfalls constituted a statistical anomaly requiring investigation rather than prosecution. A structured adversarial review of the Horizon system might have asked: “What evidence exists that this system is accurate, independent of the vendor’s own assertions?” A function with a mandate to provide adversarial challenge might have given sub-postmasters concerns more visibility to the board. The Post Office scandal is the clearest illustration in this paper of the cost of consensus without challenge, twenty years of institutional certainty, and the lives broken by it.
Patterns Across the Evidence
Five cases spanning aviation, financial technology, US regional banking, Swiss systemic banking, and public services. Four jurisdictions, five industries, and, in each case, the same three structural defects operating in recognisable patterns.
| Boeing 737 MAX | Wirecard | Silicon Valley Bank | Credit Suisse | Post Office Horizon | |
|---|---|---|---|---|---|
| Episodic Engagement | Safety not monitored between board cycles; engineer’s warning filtered through management | Quarterly engagement; no real-time monitoring of Asian partnerships that constituted the fraud | Annual/quarterly exams insufficient; nine-month CRO vacancy during peak risk period | Scheduled cycles only; Archegos and Greensill exposures escalated late through filtered internal channels | Initial deployment then episodic annual oversight; no continuous feedback from system users |
| Consensus Dependency | Board deferred to management and FAA consensus; “aircraft is safe” accepted without challenge | Board, EY, and BaFin shared consensus; short-sellers punished for dissent | Fed and board consensus: “satisfactory” ratings despite documented weaknesses (2017–2021) | Two-decade consensus that governance failure was a personnel problem; survived every operational loss until the deposit run | System “robust” consensus held for 20+ years; hundreds of individual reports dismissed |
| Absence of Challenge | No committee charter covered safety; no escalation channel for engineers | Whistleblower suppressed; no adversarial review of revenue claims | No independent escalation during CRO vacancy; Fed findings not escalated as urgent | All challenge functions internal to the chain of authority; Risk Committee Chair gap from April 2021 | No independent technical audit; no protected channel for sub-postmasters or staff |
| Consequences | 346 deaths; >$3.8 billion in settlements; $237.5M Caremark claim | €1.9B fabricated; €24B market value destroyed; criminal proceedings ongoing | $42B bank run; $16.1B FDIC cost; second-largest US bank failure at the time; third after First Republic (May 2023) | CHF 138B Q4 deposit run; CHF 123B annual AUM outflow; CHF 259B state support; forced merger with UBS | 900+ wrongful prosecutions; 236+ imprisoned; £1B+ in compensation; 13+ suicides |
Several observations emerge from this mapping.
First, every organisation that failed had a governance framework. Boeing had board committees. Wirecard had a supervisory board, external auditors, and a market regulator. SVB was supervised by the Federal Reserve. Credit Suisse was supervised by FINMA and operated a Risk Committee, internal audit, compliance, and a Chief Risk Officer. The Post Office was overseen by a government department. In every case, the architecture existed and was insufficient to surface the risks that destroyed value, lives, or both.
Second, the warnings existed. In each case, information that could have changed the trajectory was available before catastrophe struck. Boeing’s engineers raised concerns. Wirecard’s whistleblower reported fraud. SVB’s interest rate exposure was visible in its public filings. Credit Suisse’s risk culture failures were documented across the Archegos, Greensill, and Mozambique exposures. Hundreds of sub-postmasters reported Horizon errors over two decades. The problem was not that the signals did not exist, it was that no function was mandated to receive them, analyse them adversarially, and escalate them to decision-makers with the authority to act.
Third, consensus was the mechanism of failure. In each case, the prevailing narrative (“the aircraft is safe,” “the company is a fintech success,” “the bank’s model is sound,” “the new leadership will restore discipline,” “the system is robust”) was maintained by consensus long after evidence to the contrary was available. Consensus is not inherently dangerous, but without a structured mechanism for challenge, consensus becomes the means by which organisations convince themselves that what is comfortable is also true.
Fourth, the cost of inaction dwarfs the cost of challenge. The cumulative direct financial cost of these five cases exceeds $50 billion, before accounting for the CHF 259 billion in Swiss state intervention required to prevent uncontrolled failure of Credit Suisse, the human cost of 346 aviation deaths, the destruction of over 900 livelihoods, and the broader systemic effects. The cost of a continuous, adversarial challenge function operating at board level is a fraction of the value at risk.
Fifth, these cases are the extremes, not the norm. The failures examined here sit at the catastrophic end of a distribution. As Section 2 established, the more common manifestation of the same structural defects is strategic drift, the failed acquisition that was never stress-tested, the technological pivot that the board discussed but never mandated, the slow erosion of competitive position that no function was tasked with challenging. The Hunziker et al. data confirms that eight in ten value-destroying corporate crises originate in strategy and external-risk categories, not in the preventable-risk space that compliance governance targets. The case studies above demonstrate what unchecked structural defects produce at their terminal extreme. For most organisations, the defects operate at lower amplitude but with the same mechanism, namely episodic oversight that misses evolving risk, consensus that suppresses challenge, and an absence of any function mandated to ask whether the current strategy still holds. The economic case (Section 11) is built on both, the catastrophic tail and the chronic middle.
Sixth, the establishment voice now confirms the pattern. The Committee of Sponsoring Organizations of the Treadway Commission, the consortium that authored the dominant ERM framework cited above, conceded the diagnosis directly in 2026 [19]. A global survey of risk leaders reported in COSO’s From Guidance to Action found that 54% of ERM programmes are perceived as compliance or assurance functions, 28% as strategic partners, only 7% are fully integrated into strategy decisions, and 98% of respondents believe ERM should play a more strategic role. COSO frames the recurring failure mode as “scoring theater” and reports that registers, heat maps, and self-assessments consume significant effort without affecting choices. The case studies in this section are the catastrophic terminus of that pattern. The COSO data quantifies the chronic middle, the organisations operating on the same defective architecture without yet generating a public failure event.
The next sections turn from evidence to response, examining the regulatory convergence and the value gap that together create the structural space for a new function.
References
- U.S. House Committee on Transportation & Infrastructure. (2020). Final Committee Report: The Boeing 737 MAX: A Failure of Management, Engineering Culture, and the FAA's Aircraft Certification Process. U.S. House of Representatives.
- Delaware Court of Chancery. (2022). In re The Boeing Company Derivative Litigation.
- U.S. Department of Justice. (2021). Deferred Prosecution Agreement: United States of America v.\ The Boeing Company.
- Delaware Court of Chancery. (1996). In re Caremark International Inc.\ Derivative Litigation.
- Delaware Supreme Court. (2019). Marchand v.\ Barnhill.
- Katja Langenbucher & Christian Leuz. (2020). Wirecard Scandal: When All Lines of Defence Against Corporate Fraud Fail. https://blogs.law.ox.ac.uk/business-law-blog/blog/2020/11/wirecard-scandal-when-all-lines-defense-against-corporate-fraud-fail
- KPMG. (2020). Report Concerning the Independent Special Investigation, Wirecard AG, Munich. KPMG. https://web.archive.org/web/20220307204458/https://www.wirecard.com/uploads/Bericht_Sonderpruefung_KPMG_EN_200501_Disclaimer.pdf
- 3.\ Untersuchungsausschuss Deutscher Bundestag. (2021). Abschlussbericht des Dritten Untersuchungsausschusses (Wirecard). Deutscher Bundestag.
- Andrew Metrick. (2024). The Failure of Silicon Valley Bank and the Panic of 2023. Journal of Economic Perspectives. https://doi.org/10.1257/jep.38.1.133
- Michael S. Barr. (2023). Review of the Federal Reserve's Supervision and Regulation of Silicon Valley Bank. Board of Governors of the Federal Reserve System. https://www.federalreserve.gov/publications/files/svb-review-20230428.pdf
- Board of Governors of the Federal Reserve System Office of Inspector General. (2023). Material Loss Review of Silicon Valley Bank. Board of Governors of the Federal Reserve System. https://oig.federalreserve.gov/reports/board-material-loss-review-silicon-valley-bank-sep2023.pdf
- Federal Deposit Insurance Corporation. (2025). Federal Deposit Insurance Corporation v.\ Becker et al..
- Elizabeth Warren. (2025). Letter to Chair Jerome Powell Regarding Federal Reserve Accountability for Silicon Valley Bank Failures.
- Greg Feldberg et al.. (2025). How US Bank Regulation Failed SVB and Its Supervisors. Journal of Financial Crises. https://doi.org/10.17132/2693-3179.1658
- Swiss Financial Market Supervisory Authority (FINMA). (2023). FINMA Report: Lessons Learned from the CS Crisis. Swiss Financial Market Supervisory Authority (FINMA). https://www.finma.ch/en/news/2023/12/20231219-mm-lehren-aus-der-cs-krise/
- Sir Wyn Williams. (2025). Post Office Horizon IT Inquiry: Final Report. Post Office Horizon IT Inquiry. https://www.postofficehorizoninquiry.org.uk/
- Criminal Cases Review Commission. (2021). Post Office Horizon Cases: CCRC Statement.
- United Kingdom Parliament. (2024). Post Office (Horizon System) Offences Act 2024.
- Ryan Luttenton et al.. (2026). From Guidance to Action: Exploring Practical Enterprise Risk Management. Committee of Sponsoring Organizations of the Treadway Commission (COSO).