Skip to main content
NFRisk Non-Financial Risk advisory Start a Conversation
NFR-0002 Evidence-controlled risk scenario

Wells Fargo

When misconduct signals reached leadership, why did the sales model remain?

Wells Fargo agreed to a $3 billion 2020 resolution over sales practices between 2002 and 2016. The DOJ statement of facts says leadership knew as early as 2002 that unlawful and unethical practices were increasing because of onerous goals and management pressure, while more than 23,000 employees were referred for investigation between 2011 and 2016.

Conduct & Governance Risk Data & Control Integrity Financial Crime & Control Integrity Conduct risk Sales incentives Organisational culture Customer harm Management information Root cause

Documented impact

$3bn Combined criminal and civil resolution
$500m SEC penalty within the combined resolution
23,000 employees (more than) Employees referred for sales-practices investigations
5,300 employees (more than) Employees terminated for customer-facing sales ethics violations

Authoritative findings

The documented event

On 21 February 2020, Wells Fargo agreed to pay $3 billion to resolve criminal and civil matters concerning sales practices from 2002 to 2016. The DOJ statement of facts describes a volume-based sales model, aggressive growth plans and goals that, by about 2010, were regarded in parts of the Community Bank as too high to meet by selling products customers wanted, needed or would use. It states that senior leadership knew as early as 2002 that unlawful and unethical practices were increasing because of onerous goals and management pressure. Between 2011 and 2016, the company referred more than 23,000 employees for sales-practices investigations and terminated more than 5,300; almost all terminations and resignations were at branch level rather than among managers outside branches or senior leadership. The SEC separately imposed a $500 million penalty within the combined resolution for misleading investors about the cross-sell strategy.

Hypothetical institutional scenario

How might the same control pattern appear?

A sales or performance target is repeatedly missed through legitimate activity. Complaints, investigations, disciplinary cases and quality exceptions rise across locations, but each case is handled as individual misconduct. Leadership reporting emphasises completed disciplinary action and the continued success of the target metric. No control aggregates the signals to test whether the target, incentive design and management pressure are the common cause.

Stress-test questions

Questions for challenge and assurance

  1. Board

    Who independently determines whether a performance target is ethically achievable, separate from the executives accountable for delivering it?

  2. Risk committee

    At what volume or pattern do complaints, investigations and staff exits trigger a challenge to the sales model rather than more individual discipline?

  3. Audit

    Can assurance reconcile reported sales success with product usage, reversals, customer complaints and disciplinary data by location and manager?

  4. Operations

    Does root-cause analysis test target and incentive design, or stop once a frontline employee and a policy breach have been identified?

NFRisk practitioner interpretation

Control implication

A large volume of individual misconduct can be evidence of a system-level control failure. Conduct governance should connect target achievability, complaints, product use, investigation referrals, staff exits and customer remediation. The owner accountable for delivering the target should not be the only authority deciding whether it is ethically achievable. When enforcement concentrates at the frontline while the business model remains unchanged, the root-cause assessment itself requires challenge.

Framework relevance

Explicitly labelled analytical mappings

Source-stated

DOJ root-cause lens: sales goals and management pressure

The DOJ statement of facts attributes increasing unlawful and unethical practices to onerous sales goals and management pressure and describes leadership awareness from 2002. This is a source-stated causal finding, not NFRisk inference.

Wells Fargo sales-practices Statement of Facts · US Department of Justice
NFRisk analytical mapping

COSO ERM lens: Governance & Culture

NFRisk maps target design, incentive pressure and the failure to aggregate misconduct signals to COSO's Governance & Culture component. COSO did not assess Wells Fargo in this source.

Enterprise Risk Management - Integrating with Strategy and Performance · Committee of Sponsoring Organizations of the Treadway Commission (COSO)

Evidence register

Primary and supporting sources

  1. US Department of Justice

    Wells Fargo Agrees to Pay $3 Billion to Resolve Criminal and Civil Investigations into Sales Practices (opens in a new tab) 21 February 2020 · Authoritative primary source
  2. US Department of Justice

    Wells Fargo Deferred Prosecution Agreement - Exhibit A, Statement of Facts (opens in a new tab) 21 February 2020 · Authoritative primary source
  3. US Securities and Exchange Commission

    Wells Fargo to Pay $500 Million for Misleading Investors About the Success of Its Largest Business Unit (opens in a new tab) 21 February 2020 · Authoritative primary source
  4. COSO

    Enterprise Risk Management - Integrating with Strategy and Performance (opens in a new tab) 1 June 2017 · Authoritative primary source

Publication note

A documented external event—not an NFRisk client engagement.

The named organisations are included because authoritative sources document the event. Their inclusion does not imply that they are or were NFRisk clients, that they endorse this analysis, or that NFRisk participated in the event or response. Framework relevance and NFRisk practitioner interpretation are analytical layers applied after the event.

Return to the Risk Scenario Library

From scenario to mandate

Test the equivalent control assumption in your environment.

NFRisk can use this scenario as a starting point for a focused structural diagnostic, risk-architecture review or delivery-assurance discussion.

Start a conversation