Last Updated on 24/07/2026 by 75385885
Case limitation and analytical disclaimer
This article uses publicly available disclosures by JPMorgan Chase & Co. concerning historical deficiencies in internal controls and internal audit as the basis for a conceptual governance analysis. The public information does not provide sufficient detail to reconstruct the underlying events, determine individual responsibilities or identify which operational data were available to management at the time.
The observations relating to Governance Control Navigator (GCN) are therefore hypothetical. They illustrate the types of governance patterns that a data-driven Governance Intelligence capability might analyse if appropriate operational data were available. This article does not claim that GCN would have prevented the regulatory issue, detected misconduct or reached the conclusions ultimately reached by regulators.
A Highly Controlled Bank Can Still Experience Governance Drift
When one of the world’s largest financial institutions discloses potential regulatory action relating to historical weaknesses in internal controls, the immediate reaction is often predictable.
How could this happen?
Surely an institution of this size possesses some of the world’s most sophisticated governance systems.
In reality, that assumption is almost certainly correct.
JPMorgan Chase operates in one of the most highly regulated industries in the world. It manages trillions of dollars in assets, serves millions of customers and operates across investment banking, commercial banking, consumer banking and asset management. Such an organisation depends upon extensive governance structures, enterprise-wide risk management, multiple lines of defence, Internal Audit, compliance functions, regulatory reporting and highly developed control frameworks. According to its third-quarter 2020 filing, the bank reported approximately $3.2 trillion in total assets, employed more than 256,000 people and operated through four major business segments.
No serious governance professional would suggest that an organisation of this scale operates without robust Governance, Risk & Compliance (GRC).
Yet, despite that maturity, JPMorgan disclosed that a regulator was considering enforcement action relating to historical deficiencies in internal controls and internal audit associated with certain advisory and other activities. The bank also stated that the relevant controls had since been enhanced and that discussions with the regulator were continuing.
That disclosure raises an interesting governance question.
Not whether governance existed.
But whether even excellent Governance Design can gradually become disconnected from operational reality.
This distinction lies at the heart of Governance Intelligence.
Traditional GRC evaluates whether governance controls are appropriately designed and operating as intended.
Governance Intelligence asks an additional question:
Is the organisation still behaving in the way those controls were originally designed to support?
Those are fundamentally different perspectives.
One evaluates controls.
The other evaluates organisational behaviour.
Read more at CNBC.com: JPMorgan Chase pays $250 million penalty over weak controls in its wealth management division.
What the Public Disclosures Actually Tell Us
Cases involving major financial institutions often attract extensive commentary, speculation and hindsight analysis. That makes it particularly important to separate established facts from governance interpretation.
The publicly available information concerning JPMorgan is, in fact, relatively limited.
The disclosure confirms that a regulatory authority was considering possible action relating to historical deficiencies in internal controls and Internal Audit affecting certain advisory and related activities. It also confirms that JPMorgan had already implemented improvements to those controls and was cooperating with the regulatory process.
Equally important is what the disclosure does not tell us.
It does not explain precisely which controls were deficient.
It does not describe the underlying operational processes.
It does not identify individual decisions or management responsibilities.
Nor does it reveal which operational indicators may—or may not—have been available before the issues became regulatory findings.
These limitations matter.
They prevent any responsible analyst from claiming that a particular governance technology would have prevented the situation or identified it at an earlier stage.
For that reason, this article deliberately avoids reconstructing the historical events.
Instead, it asks a broader conceptual question that is relevant to every large organisation, regardless of industry.
If a mature governance environment later reveals historical control deficiencies, what additional governance questions could management have asked while organisational behaviour was still evolving?
That is not a question about JPMorgan alone.
It is a question for every board, every Audit Committee and every Chief Risk Officer.
See the Form 10-Q published by JP Morgan Chase & Co for the quartely period ended September 30, 2020.
Traditional GRC Did Not Fail by Definition
One of the greatest mistakes in governance discussions is the tendency to present new concepts as replacements for established practice.
Governance Control Navigator should not be positioned that way.
Traditional GRC remains one of the most significant developments in modern corporate governance.
It provides organisations with structured risk management, documented controls, policy management, issue tracking, remediation programmes, Segregation of Duties, compliance monitoring and governance reporting.
These capabilities have transformed governance over the past three decades.

In a financial institution such as JPMorgan, traditional GRC would typically evaluate questions such as:
- Are governance controls properly documented?
- Have key controls been executed?
- Were control owners identified?
- Were deficiencies reported?
- Were remediation actions implemented?
- Were regulatory obligations satisfied?
- Were Internal Audit recommendations addressed?
- Were issues escalated appropriately?
These are precisely the questions that boards and regulators expect organisations to answer.
Nothing about the JPMorgan disclosure suggests that these questions have become irrelevant.
On the contrary.
They remain indispensable.
However, Governance Control Navigator starts from a different premise.
Rather than asking only whether controls have been performed, GCN asks whether the organisation itself is gradually changing in ways that those controls may not immediately reveal.
For example:
- Are manual interventions becoming more common?
- Are exceptions increasingly concentrated within particular teams?
- Are operational workarounds becoming routine?
- Are approval patterns slowly changing?
- Is organisational behaviour evolving differently from historical norms?
These are not compliance questions.
They are Governance Intelligence questions.
Importantly, they do not replace traditional control testing.
They provide an additional perspective that becomes increasingly valuable as organisations become larger, more digital and more operationally complex.
That is why Governance Control Navigator should never be viewed as an alternative to GRC.
It should be understood as the next governance layer—one that helps management understand not only whether governance controls appear to operate effectively, but also whether organisational reality continues to reflect the Governance Design that those controls were intended to achieve.
Also read other GRC versus GCN blogs here: Weak Internal Controls or Weak Governance Intelligence? regarding an article based on publicly available reporting regarding the City of Rocky Mount, North Carolina.
From Control Evidence to Behavioural Evidence
Traditional Governance, Risk & Compliance is built around evidence.
Did a control take place?
Was the approval documented?
Was the review completed?
Was an exception escalated?
These questions are fundamental because they provide assurance that the governance framework is functioning as management intended.
Governance Control Navigator starts one step earlier.
Instead of looking first at individual controls, it observes how the organisation behaves while those controls are operating.
This distinction is subtle but important.
A single manual intervention is rarely significant. Every large financial institution processes transactions that require judgement, professional interpretation or exceptional handling. Likewise, an occasional override of a standard procedure is not necessarily a governance concern. Complex organisations deliberately build flexibility into their control frameworks because business reality cannot always be reduced to standardised workflows.
The governance question therefore is not whether an exception exists.
It is whether exceptions gradually begin to exhibit a different behavioural pattern.
Governance Intelligence focuses on these evolving patterns.
Imagine an advisory business in which manual interventions slowly become more frequent over several reporting periods. Each intervention is individually justified and approved. None of them, viewed in isolation, indicates a failure of governance.
However, if manual interventions steadily increase while post-transaction corrections also become more common, review times lengthen and similar exceptions begin to cluster around particular activities, management may wish to understand why organisational behaviour is changing.
Traditional GRC would quite correctly continue evaluating whether the documented controls were executed.
GCN introduces an additional management question:
Why is the operational environment gradually requiring more exceptions than it did before?
That question concerns organisational dynamics rather than compliance.
It reflects the transition from control evidence to behavioural evidence.
Behavioural evidence does not replace audit evidence.
Instead, it provides management with an earlier opportunity to understand how operational reality is evolving before those changes eventually become formal governance findings.
The Difference Between an Exception and a Pattern
One of the greatest strengths of modern governance is its ability to accommodate legitimate exceptions.
Policies are not intended to eliminate professional judgement.
In financial institutions, unusual customer transactions, complex advisory engagements or exceptional commercial circumstances frequently require deviations from standard processing. Experienced managers expect this and governance frameworks are designed to accommodate such flexibility.
For that reason, Governance Control Navigator deliberately avoids interpreting individual exceptions as indicators of governance weakness.
An isolated override may simply reflect good judgement.
An unusual approval sequence may arise because specialist expertise was required.
A delayed review may result from temporary workload pressures.
Viewed individually, none of these observations necessarily warrants concern.
Governance becomes more interesting when isolated exceptions begin to resemble one another.
Suppose that over several quarters management observes that similar advisory exceptions increasingly occur within particular organisational areas. Approval patterns become more concentrated. Certain controls require repeated manual intervention. Operational workarounds become progressively more common, even though every individual case remains properly documented and authorised.
Nothing in this scenario proves that governance has failed.
Yet something important may be changing.
The organisation may gradually be adapting its behaviour in response to commercial pressures, operational complexity, technology limitations or changing customer expectations.
Individually, these adaptations are entirely understandable.
Collectively, they may indicate that operational reality is slowly diverging from the governance architecture originally designed to support it.
This phenomenon can be described as Collective Governance Behaviour.
It represents the aggregate outcome of thousands of entirely reasonable decisions made by experienced professionals over extended periods.
No individual decision appears problematic.
The pattern, however, may deserve management attention.
Traditional GRC is exceptionally effective at evaluating individual controls.
Governance Intelligence complements this by helping management recognise when individually acceptable exceptions begin forming collectively meaningful behavioural trends.
Also read more in our blog on: Internal Control in the Age of AI – When Governance Moves from Paper to Code.
What Governance Intelligence Might Analyse
Because the public disclosures concerning JPMorgan provide only limited factual information, it would be inappropriate to speculate about the specific operational indicators available to management at the time.
Instead, it is more useful to consider the kinds of governance observations that a behavioural governance platform might analyse in a comparable advisory environment.
Such observations could include:
- a gradual increase in manually processed advisory transactions;
- recurring exceptions requiring senior approval;
- concentrations of overrides within particular business activities;
- increasing volumes of post-approval amendments;
- repeated reliance on compensating controls;
- operational processes requiring progressively more supervisory intervention;
- longer intervals between execution, review and remediation;
- recurring control adjustments following Internal Audit recommendations.
None of these observations would constitute evidence of misconduct.
Nor would they demonstrate ineffective governance.
Each would simply represent an objective operational trend.
The real value emerges when these independent observations begin pointing in the same direction.
Rather than generating an alert stating that governance has failed, Governance Control Navigator might instead produce an observation such as:
Operational exception patterns within selected advisory activities have increased over successive reporting periods. Manual interventions, supervisory approvals and post-transaction adjustments are becoming progressively more concentrated. Management may wish to assess whether current Governance Design continues to reflect operational reality.
Notice the language.

No conclusions.
No accusations.
No suggestion of fraud.
Only an evidence-based governance question supported by observable organisational behaviour.
That distinction is fundamental.
Governance Intelligence should stimulate informed management discussion rather than replace professional judgement.
Internal Audit and Governance Intelligence Observe Different Layers
The relationship between Governance Control Navigator and Internal Audit is perhaps best understood as complementary rather than competitive.
Internal Audit performs an essential independent assurance function.
Auditors assess whether governance controls are appropriately designed, consistently executed and operating effectively within the established governance framework. Where weaknesses are identified, they evaluate root causes, recommend corrective actions and monitor remediation.
This role remains indispensable.
Governance Intelligence addresses a different layer of organisational understanding.
Instead of determining whether a control deficiency exists, it examines whether operational behaviour is gradually moving towards conditions in which such deficiencies may become more likely.
This distinction may appear subtle, yet it has significant implications for boards and executive management.
Internal Audit might ultimately conclude that a review process was inconsistently applied or that supervisory oversight proved insufficient.
Governance Intelligence, by contrast, may have observed much earlier that manual interventions, operational exceptions and supervisory workload had all been increasing over an extended period.
Neither perspective is superior.
They simply answer different governance questions.
Internal Audit asks:
Did governance controls operate effectively?
Governance Intelligence asks:
Is organisational behaviour evolving in ways that deserve management attention before governance weaknesses become formally observable?
Together these perspectives create a richer understanding of organisational governance than either discipline could achieve independently.
That is precisely why Governance Control Navigator should be viewed not as a replacement for existing Governance, Risk & Compliance frameworks, but as the next evolution in helping organisations understand the increasingly complex relationship between Governance Design and organisational reality.
From Remediation to Governance Alignment
One of the most encouraging aspects of the JPMorgan disclosure is that the bank stated it had already enhanced the relevant internal controls while discussions with the regulator were continuing. Like any mature organisation, JPMorgan responded to identified weaknesses by strengthening its governance framework.
That response reflects good governance.
When deficiencies are identified, organisations should analyse root causes, redesign controls where necessary, improve oversight and monitor implementation. Traditional GRC provides an excellent structure for managing that remediation process.
Yet remediation raises another governance question that is rarely discussed.
How does management know that organisational behaviour has changed—not merely that the documented control framework has changed?
Closing an audit finding is an administrative milestone.
Changing organisational behaviour is a governance outcome.
Those two events are not always identical.
A control may be redesigned, new policies issued and additional reviews introduced. Audit recommendations may be implemented on schedule and regulators may acknowledge the remediation programme.
However, if employees continue relying on informal workarounds, if manual interventions remain unusually frequent or if operational pressure continues to generate the same behavioural responses, then Governance Reality may still differ from Governance Design.
Traditional GRC is designed to monitor whether remediation activities have been completed.
Governance Intelligence asks whether remediation has genuinely restored alignment between the intended governance model and day-to-day organisational behaviour.
That distinction becomes increasingly important in large, complex organisations where behavioural change often develops gradually rather than immediately.
Large Organisations Rarely Lack Data
Discussions about governance frequently begin with the assumption that organisations require more information.
In reality, the opposite is often true.
Global financial institutions generate extraordinary volumes of operational data every day.
Transaction systems record millions of events.
Workflow systems capture approvals.
Human Resources systems monitor organisational structures.
Finance systems document financial movements.
Risk systems record incidents.
Compliance systems track regulatory obligations.
Internal Audit documents observations and remediation activities.
Customer systems generate service data.
Technology platforms record system events.
The governance challenge is therefore seldom the absence of information.
The challenge is that every governance function naturally views the organisation through its own professional lens.
Compliance examines regulatory obligations.
Internal Audit evaluates control effectiveness.
Operational Risk analyses incidents.
Finance monitors financial performance.
Business management focuses on commercial execution.
Human Resources considers organisational capability.
Each discipline performs its own role extremely well.
Yet no individual function necessarily observes how all these operational signals gradually combine into broader patterns of organisational behaviour.
Governance Control Navigator is intended to complement—not replace—these existing governance disciplines.
Rather than introducing another control framework, it seeks to integrate evidence that organisations already possess but traditionally evaluate separately.
Governance Intelligence therefore becomes less about producing additional reports and more about connecting existing governance observations into a coherent picture of organisational reality.
Understanding the Three Governance Realities™
The JPMorgan case provides a useful illustration of the Three Governance Realities™, a model developed to distinguish between governance as it is designed, governance as it is executed and governance as it is collectively experienced within an organisation.
The first reality is Governance Design.
This includes governance policies, control frameworks, approval structures, Internal Audit programmes, compliance requirements, risk methodologies and documented responsibilities. Governance Design represents management’s intended operating model.
The second reality is Governance Execution.
This concerns the practical application of those policies by employees, managers, compliance professionals, Internal Audit and executive leadership. Governance Execution reflects whether the documented framework is actually implemented.
The third reality is Collective Governance Behaviour.
This is the organisational pattern that emerges from thousands of daily decisions, approvals, exceptions, overrides, corrections, escalations and operational adaptations.
No single decision defines Collective Governance Behaviour.
Rather, it develops gradually as individual actions accumulate over time.
The significance of this third reality is that it often changes long before formal governance documentation does.
Commercial pressures evolve.
Technology changes.
Customer expectations shift.
Operational complexity increases.
Employees adapt.
Processes evolve.
The governance framework may remain formally unchanged while organisational behaviour steadily develops in new directions.
This does not automatically indicate poor governance.
Indeed, many behavioural changes are entirely appropriate and represent healthy organisational adaptation.
The governance challenge is simply to determine whether Governance Design and Collective Governance Behaviour remain sufficiently aligned.
That is precisely the additional perspective Governance Intelligence seeks to provide.
The Questions Boards Should Begin Asking
The JPMorgan disclosure should not primarily be viewed as a story about one financial institution.
It illustrates a governance challenge faced by every large and complex organisation.
Boards increasingly receive detailed reporting on risk, compliance, Internal Audit findings, remediation programmes and regulatory developments.
These reports remain essential.
However, modern governance may benefit from asking a complementary set of questions.
For example:
- Which operational behaviours are changing faster than our governance framework?
- Where are exceptions becoming increasingly concentrated?
- Which controls require progressively more manual intervention?
- Are similar operational patterns emerging across different business units?
- Has remediation measurably changed organisational behaviour, or merely updated documentation?
- Can we demonstrate that Governance Design, Governance Execution and Collective Governance Behaviour remain aligned?
These questions do not replace traditional governance reporting.
They enrich it.
They encourage management to look beyond individual control assessments and consider governance as a dynamic organisational system rather than a collection of independent control activities.
Governance Intelligence as the Next Layer of Governance
The public disclosures surrounding JPMorgan do not demonstrate the absence of governance.
If anything, they demonstrate the opposite.

Only organisations with mature governance frameworks identify deficiencies, implement remediation programmes and openly engage with regulators regarding historical control improvements.
That is exactly how sound governance should function.
The broader lesson is therefore not that traditional Governance, Risk & Compliance has reached its limits.
Traditional GRC remains indispensable because it establishes Governance Design, documents controls, allocates responsibilities, supports Internal Audit, enables regulatory compliance and provides structured assurance.
Governance Control Navigator does not seek to replace those capabilities.
It introduces an additional governance perspective.
One that examines whether organisational behaviour continues to reflect the governance architecture that management originally intended.
Traditional GRC indicates whether governance controls appear to be operating as designed.
Governance Control Navigator helps management understand whether organisational reality remains aligned with that governance design.
For boards, regulators and executive management, this may become one of the defining governance questions of the coming decade.
Not because governance frameworks are becoming weaker.
But because organisations themselves are becoming more complex, more digital and more dynamic than ever before.
In that environment, governance is no longer only about understanding controls.
It is increasingly about understanding behaviour.
And perhaps the most important question every board should periodically ask is not:
“Are our controls operating?”
But rather:
“Is our organisation still behaving in the way those controls were designed to achieve?”
That is the essence of Governance Intelligence.
FAQ’s – Governance Intelligence
1. What does the JPMorgan internal controls case teach boards about governance?
The JPMorgan case demonstrates that even one of the world’s largest and most sophisticated financial institutions can report historical deficiencies in internal controls. This should not be interpreted as evidence that governance was absent. Rather, it illustrates that mature governance frameworks must continually adapt to changing organisational behaviour.
Traditional GRC provides assurance that controls are documented, executed and monitored, while Governance Intelligence asks whether day-to-day organisational behaviour still reflects the original Governance Design.
Boards should therefore look beyond individual control effectiveness and periodically assess whether operational reality is gradually diverging from intended governance structures. The case highlights the importance of complementing existing assurance functions with behavioural governance insights rather than replacing established governance practices.
Traditional Governance, Risk & Compliance focuses on policies, risks, controls, compliance activities, remediation programmes and audit evidence. Governance Control Navigator (GCN) does not replace these disciplines. Instead, it introduces an additional analytical layer that examines organisational behaviour over time.
Rather than asking only whether controls have operated effectively, GCN evaluates whether behavioural patterns, operational exceptions and governance trends remain aligned with Governance Design. It provides management with Governance Intelligence that complements traditional assurance.
This allows boards to observe long-term behavioural developments without making assumptions about fraud, misconduct or individual performance.
3. Does Governance Intelligence detect fraud?
No. Governance Intelligence is not designed as a fraud detection system and should not be presented as one. Its purpose is to identify behavioural patterns, operational trends and governance developments that may deserve management attention.
Individual observations are not interpreted as evidence of wrongdoing.
Instead, Governance Intelligence examines whether collections of operational indicators gradually form meaningful governance patterns.
Human judgement, Internal Audit, Compliance and management remain responsible for evaluating the significance of those observations. Governance Intelligence supports decision-making by providing additional context rather than replacing existing governance responsibilities.
4. Why is organisational behaviour important for corporate governance?
Every organisation evolves continuously. Employees adapt processes, managers introduce workarounds, customer expectations change and technology develops. Over time, these individual decisions create Collective Governance Behaviour.
While each decision may be reasonable on its own, the combined behavioural pattern may gradually differ from the Governance Design originally established by management.
Traditional GRC evaluates controls, whereas Governance Intelligence evaluates whether organisational behaviour still reflects the governance architecture.
Understanding this relationship enables boards to discuss governance proactively instead of responding only after formal deficiencies have been identified.
5. Can Governance Intelligence replace Internal Audit?
No. Internal Audit and Governance Intelligence perform fundamentally different functions. Internal Audit provides independent assurance regarding governance, risk management and internal controls. It evaluates whether controls are appropriately designed and operating effectively.
Governance Intelligence analyses behavioural developments within organisational processes and identifies patterns that may warrant management attention. These perspectives are complementary.
Internal Audit provides independent assurance, while Governance Intelligence provides continuous organisational insight. Together they offer boards a richer understanding of governance than either discipline can provide independently.
6. Why is the JPMorgan case relevant beyond the banking sector?
Although the JPMorgan case arose within a global financial institution, the underlying governance lessons apply to every complex organisation. Manufacturing companies, healthcare providers, government agencies, energy companies and technology firms all depend upon Governance Design, operational execution and organisational behaviour.
Every organisation experiences operational change, increasing complexity and evolving business practices. The central governance question therefore extends far beyond banking: does actual organisational behaviour remain aligned with the governance framework that management originally intended?
Governance Intelligence offers boards an additional perspective for addressing this universal governance challenge alongside existing Governance, Risk & Compliance frameworks.