Tales & Co.

Istanbul — San Francisco

Notes

Decision architecture

6 min read

Risk and Compliance Do Not Hold the Same Right

In fintech the two are named in one breath and handed one seat. One of them is answering a question of law and the other is quoting a price, and a single seat gets both of them wrong.

In fintech, risk and compliance are named in one breath and handed one seat.

The question about decision rights between risk, compliance and product usually arrives in a particular shape. A launch took four months longer than it was scoped to take and shipped smaller than it was proposed. Nobody can name a meeting where it was cut. The org chart is not the problem anyone suspects, because the org chart looks tidy: product reports through a chief product officer, risk and compliance report through a chief risk officer, and the second line has a standing slot in every review.

The defect is in that shared slot, and it sits upstream of every argument that follows it. Risk and compliance are not two words for caution. They answer different questions, their answers have different properties, and a governance model that cannot tell them apart will get one of the two wrong in every room it runs.

What each desk is actually answering

  • Compliance answers what is permitted: under this licence, this regulation, this contract with the scheme. The answer is about the boundary.
  • Risk answers what something is expected to cost: fraud loss, chargeback, credit, operational exposure, stated as a number over a volume.
  • Product answers what something is expected to earn, and how much of the cost it is willing to buy to get it.

Two of those are prices. One is not. Everything that goes wrong in a fintech decision forum can be traced to the moment that distinction stopped being visible in the room.

Compliance answers a question of law, and a question of law is not tradeable.

A compliance position has a shape that meetings are bad at handling. It is permitted, or it is not permitted, or it is permitted subject to named conditions. There is no middle for a room to find by talking, and no version of the answer that improves if the proposing function is persuasive. Placed inside a forum where positions are weighed against one another, the compliance answer is the one item on the table with no price, which means the only currency available for moving it is interpretation.

A compliance position belongs upstream of a decision as a constraint on it, not inside the decision as a vote. The distinction is not ceremonial. A constraint is written before the proposal exists and shapes what gets proposed; a vote is cast after, against a proposal someone has already invested three weeks in defending.

Why the seat at the table weakens the function that holds it

The seat looks like influence and behaves like exposure. A function invited to argue can be out-argued, and it learns this quickly. What follows is predictable: the desk starts defending its answers with volume rather than citation, widens them for safety, and begins blocking things that are merely awkward alongside the things that are genuinely impermissible.

A function invited to argue can be out-argued, and a legal answer that loses an argument is still the legal answer.

Product then reads the widened answers as evidence that compliance overreaches, and compliance reads the pressure as evidence that product does not take the licence seriously. Both readings have support. Neither is the cause. The cause is that a boundary was put in a room designed to negotiate prices.

Risk answers with a price, and a price given a veto stops working as a price.

The risk desk's answer is the opposite kind of object. Expected fraud loss on a new payment method, chargeback exposure on a shortened verification flow, credit loss on a widened limit: these are numbers, they move with volume, and they are supposed to be bought against. A company unwilling to spend any of that number to win anything does not have a risk appetite. It has a prohibition operating under a risk desk's name, and the difference matters because a prohibition cannot be planned around.

A risk desk with no stated tolerance cannot price anything, so it defends itself the only way left available, which is by refusing. That refusal then gets read as rigour, and the organisation adds review stages to manage it, which slows the next proposal without changing the underlying gap.

The tell that a price has turned into a veto

  • Risk positions arrive as yes and no rather than as a number with conditions attached.
  • The same proposal comes back three times, each time smaller, and nobody can point to the meeting where it was cut.
  • No one in the room can say what level of loss would have been acceptable, including the desk holding the number.

The third tell is the one that settles it. Where a tolerance exists, the argument is short and arithmetic. Where it does not, the argument is long and about character, and it recurs on every proposal in the class, which is the pattern a checkout roadmap makes visible faster than anything else.

Product's right is to decide inside the boundary and spend against the number.

Once the two second-line answers are separated, product's right becomes narrow and specific, which is what makes it usable. Product does not adjudicate the boundary and does not set the tolerance. It proposes, it decides within what compliance has already ruled permissible, it spends against the loss number risk has published for that class of change, and it carries that number afterwards in its own reporting rather than in someone else's.

What the split looks like written down

Compliance publishes the boundary before the proposal, in writing, with the conditions that make a thing permissible rather than a verdict on one design. Risk publishes a tolerance for the class — not for the individual item — and prices proposals against it. Product decides inside both and owns the outcome, including the part of the outcome that shows up as loss two quarters later.

Written this way, the second line stops being a gate and becomes an input, which is the only arrangement under which either desk can be held to its own answer. A veto cannot be audited. A published boundary and a published tolerance both can, and so can the decisions made against them. The failure mode this replaces is the one where a decision has a named owner who is nonetheless the wrong function to be holding it.

Where this becomes work is in separating the two rights before the next proposal.

The diagnosis runs on material the business already has. Take the last three proposals that changed shape between first review and launch, and mark each cut with the function that caused it and the reason given. The marking sorts quickly: cuts made against a written boundary, cuts made against a stated number, and cuts made against neither. The third pile is the size of the problem, and in most fintech businesses we are asked to look at, it is the largest of the three.

Fixing it is a writing exercise before it is a governance one: one boundary document, one tolerance per class of change, and a decision rule that names product as the decider inside both. No reporting line needs to move, which is usually the objection that would otherwise stall the work for a quarter. Where that thinking becomes work is consulting, and the neighbouring notes in decision architecture cover the same question from the ownership side.