What You Need to Know About Citi Risk and Controls
Citi risk and controls is one of the most complex and closely watched governance frameworks in global banking. Whether you’re exploring a career in risk management, benchmarking your own compliance program, or trying to understand how a systemically important bank manages its exposures, the key facts are:
- Citi has 216 active “risk and controls” job listings spanning credit, operational, market, compliance, and AI risk functions
- The U.S. Federal Reserve closed formal trading risk management notices against Citi in December 2025, marking a milestone in its multi-year transformation
- Citi’s risk framework is governed at the board level by a Risk Management Committee, last updated February 11, 2026
- The bank organizes risk into seven Level 0 risk categories: credit, market, liquidity, strategic, operational, compliance, and reputation
- Risk roles span four global regions — North America, Asia Pacific, EMEA, and Latin America — with structured job levels from entry-level to executive (C10 to C16)
- Citi uses a three lines of defense model: In-Business Risk (1st line), Independent Risk Management (2nd line), and Internal Audit (3rd line)
Citi employs more than 230,000 people globally, and its risk and control infrastructure is one of the most layered in the industry. Managing risk at this scale means hundreds of specialized roles, proprietary frameworks like the Manager’s Control Assessment (MCA), and board-level oversight that goes far beyond a standard compliance checklist.
For IT leaders and compliance professionals in regulated industries, understanding how Citi structures its risk and control environment offers a rare, practical benchmark. It also reveals just how demanding modern risk governance has become — and why getting it right requires more than good intentions.
Navigating the Modern Landscape of Citi Risk and Controls
The regulatory landscape for global financial institutions is a moving target, demanding constant adaptation and rigorous self-correction. For years, Citigroup operated under intense regulatory scrutiny, navigating complex consent orders and formal warnings from oversight bodies. However, a major turning point occurred on December 17, 2025, when the U.S. Federal Reserve officially closed formal notices requiring Citi to fix weaknesses in its trading risk management.
While this closure represents a massive victory for Citi’s leadership team and validates their extensive remediation efforts, it is only one step in a much larger journey. The bank continues to navigate broader, outstanding regulatory consent orders that require long-term, systemic transformation of its data governance, operational risk controls, and technology infrastructure.
For enterprise leaders looking on, Citi’s journey illustrates a fundamental truth of modern governance: regulatory compliance is not a static destination, but a continuous state of operational readiness. When compliance notices are handed down, they create a ripple effect that forces organizations to fundamentally rethink how they manage risk from the ground up. This dynamic is discussed in detail in resources like the Governance, Risk Management, Compliance Guide 2026.
To successfully navigate this landscape, organizations must transition from a reactive “check-the-box” compliance mindset to a proactive, risk-aware culture. As Citi has demonstrated, resolving deep-seated risk management weaknesses requires a coordinated transformation that spans board-level oversight, specialized job families, and advanced technology.
Board-Level Governance: The Risk Management Committee and Level 0 Risks
At a globally systemically important bank (G-SIB) like Citi, risk management cannot simply be an IT or back-office function. It must be anchored at the very top of the corporate hierarchy. Citi’s risk governance is steered directly by the Board of Directors through its Risk Management Committee (RMC).
The governance requirements for this committee are incredibly strict, dictated in part by federal regulations such as Regulation YY (12 CFR Part 252), which mandates independent risk committees for large financial institutions, as well as the Volcker Rule. According to the CITIGROUP INC. RISK MANAGEMENT COMMITTEE CHARTER As of February 11, 2026 , the committee must:
- Consist of at least three members of the Board of Directors.
- Be composed of a majority of non-management, independent directors.
- Include at least one member with hands-on experience identifying, assessing, and managing risk exposures of large, complex financial firms.
- Meet at least quarterly (and often much more frequently) to review the firm’s risk appetite and control environment.
Defining the Core Pillars of Citi Risk and Controls
The RMC is charged with overseeing what Citi classifies as “Level 0 risks”—the primary categories of exposure that could threaten the bank’s financial stability, operational integrity, or reputation. These seven core pillars include:
- Credit Risk: The risk of loss resulting from a borrower’s failure to repay a loan or meet contractual obligations.
- Market Risk: The risk of losses in on- and off-balance-sheet positions arising from movements in market prices (both trading and non-trading).
- Liquidity Risk: The risk that the bank will be unable to meet its financial obligations as they fall due.
- Strategic Risk: The risk to earnings or capital arising from adverse business decisions or improper implementation of strategic goals.
- Operational Risk: The risk of loss resulting from inadequate or failed internal processes, people, systems, or external events.
- Compliance Risk: The risk of legal or regulatory sanctions, financial loss, or damage to reputation resulting from failure to comply with laws, regulations, and rules.
- Reputation Risk: The risk that negative publicity, whether true or not, will decline the bank’s customer base, costly litigation, or revenue reductions.
For IT directors and security leaders, aligning internal frameworks with these high-level risk categories is crucial. Operational and compliance risks, in particular, are heavily influenced by how an organization manages its IT infrastructure and digital assets. When these systems are poorly governed, they can introduce operational friction. To streamline this process, organizations can refer to guides such as IT Governance, Risk, and Compliance: Remove the Thorn in Your Side.
The Independent Risk Management Function and CRO Oversight
While the Risk Management Committee provides board-level oversight, the daily execution of Citi’s risk strategy is led by the Chief Risk Officer (CRO) and the Independent Risk Management (IRM) function.
To maintain absolute objectivity, the CRO has a dual-reporting line directly to both the Chief Executive Officer and the Risk Management Committee. The committee is responsible for approving the appointment, compensation, and, if necessary, the removal of the CRO. This structural independence ensures that the CRO can “check and challenge” business decisions without fear of internal political pressure.
Under the CRO’s umbrella, the Credit Risk Review (CRR) function operates as an independent, objective control unit. CRR maintains an administrative reporting line to the CRO but has direct, private communication access to the RMC. The committee holds regular executive sessions with the CRO and the Head of CRR without general management present, ensuring that critical vulnerabilities are escalated transparently.
This model of independent validation and structured escalation is a best practice that any organization can adopt to balance growth with safety. For practical advice on building this balance, organizations can explore resources like 8 Tips for Smarter Risk-Taking in IT.
Inside Citi’s Risk Hierarchy: Job Families and Organizational Structure
To enforce its risk policies across a global footprint, Citi relies on a highly structured internal grading system. This taxonomy spans Management Levels (MS Levels L2 through L9) and New Job Levels (B10 through C16) to define seniority, escalation paths, and decision-making authority.
For example, a Senior Vice President (SVP) typically sits at Job Level C14, while a Vice President (VP) occupies Level C13. This granular hierarchy ensures that every control, attestation, and risk mitigation plan has a clearly defined owner who is accountable for its execution.
| Risk Management Dimension | In-Business Risk (1st Line of Defense) | Independent Risk Management (2nd Line of Defense) |
|---|---|---|
| Primary Objective | Identify, mitigate, and own risks at the point of origin within the business unit. | Establish risk boundaries, set control standards, and provide independent challenge. |
| Key Frameworks Used | Manager’s Control Assessment (MCA), Control Inventory, Quality Control (QC). | Operational Risk Management (ORM) Policy, Compliance Risk Management (CRM) Framework. |
| Reporting Line | Directly to Business Unit Leaders / COO Organization. | Directly to Chief Risk Officer (CRO) / Independent Risk Channels. |
| Core Activities | Daily process monitoring, executing QA/QC, remediating localized control issues. | Reviewing and challenging 1st line self-assessments, policy drafting, regulatory reporting. |
First Line of Defense: In-Business Risk and Control Roles
The first line of defense is where the rubber meets the road. In-Business Risk and Control teams are embedded directly within specific business lines, such as Treasury and Trade Solutions (TTS), Wealth Management, and Markets Operations.
A prominent example of this is the Consumer Business Operational Risk and Control (CBORC) unit, which manages operational risks within customer-facing divisions. Rather than relying on external compliance teams to catch mistakes after the fact, first-line units (FLUs) are responsible for designing and executing controls as part of their daily workflows.
Consider the role of a Business Risk and Control Officer – VP (Hybrid) . This position is responsible for analyzing and reporting on horizontal key control metrics within operational units. These officers perform detailed root-cause analyses on identified control issues, execute Quality Control (QC) before processes run, and run Quality Assurance (QA) post-execution. By embedding these roles directly within operations, Citi ensures that risk management is a proactive, daily habit rather than an annual audit drill.
Career Paths and Compensation in Citi Risk and Controls
Citi’s active recruitment efforts highlight a sustained, industry-wide demand for specialized risk and control professionals. For candidates looking to enter this field, the career paths are highly specialized, structured, and financially rewarding.
For instance, a VP / Business Risk and Control Officer role in Jacksonville, FL commands a salary range of $103,920 to $155,880 per year. Meanwhile, more senior roles, such as the Markets Operations Risk & Control Lead Senior Vice President | Citi Careers based in Getzville, NY, feature salary ranges of $115,840 to $173,760 per year.
These compensation packages reflect the high stakes associated with these positions. When a partner, client, or regulator demands better risk controls, those requirements often influence the broader operational ecosystem. This interconnected compliance dynamic is analyzed in The Compliance Ripple Effect: Why Your Partner’s Requirements Become Your Reality.
While Citi recruits globally to fill its 216 open risk roles, local talent in regions like Silicon Valley can find robust opportunities closer to home. For example, there are active listings such as the Personal Banker SAFE Act, Santa Clara Pruneridge Branch , alongside hundreds of other listings found via the 737 Citi Full Time jobs in Santa Clara directory. This local presence underscores the reality that even localized banking services are deeply connected to the bank’s broader global risk and control standards.
Emerging Frontiers: AI Governance, Model Risk, and Data Controls
As financial institutions increasingly adopt machine learning and automated systems, the definition of “operational risk” is expanding rapidly. Citi is at the forefront of this shift, establishing dedicated governance structures to manage the unique risks associated with algorithmic decision-making.
A prime example of this proactive stance is Citi’s recruitment for roles like the Artificial Intelligence Risk and Control Controls Officer – VP . This specialized function is tasked with establishing controls around AI models and “non-model” algorithmic processes. Because AI systems can exhibit bias, drift over time, or ingest poisoned data, they require a specialized “check and challenge” framework that traditional model risk management (MRM) systems were not built to handle.
Simultaneously, data governance has emerged as a critical regulatory battlefield. Roles like the Markets Data Risk Controls Lead, North America, Senior … are responsible for ensuring that the data feeding trading platforms, regulatory reports, and risk dashboards is accurate, complete, and secure.
For any enterprise deploying AI or managing large data lakes, the lessons from Citi’s focus on data controls are clear:
- Establish AI Inventory Tracking: You cannot govern what you do not catalog. Maintain a centralized registry of all AI and machine learning models.
- Implement Non-Model Reviews: Traditional models aren’t the only risk; simple automated scripts and heuristic algorithms can also fail catastrophically and require independent validation.
- Enforce Data Lineage: Ensure you can trace data from its point of origin to its final report destination to satisfy regulatory audit requirements.
Frequently Asked Questions
What is the Manager’s Control Assessment (MCA) at Citi?
The Manager’s Control Assessment (MCA) is Citi’s proprietary framework for Risk & Control Self-Assessment (RCSA). Executed in accordance with the bank’s Operational Risk Management (ORM) Policy, the MCA requires business managers to systematically identify, assess, monitor, and report on the operational risks and controls within their units.
The MCA operates on a continuous cycle of monthly, quarterly, semi-annual, and annual attestations. Through tools like “Quest,” managers document their control inventory, perform quality control testing, and flag emerging issues for remediation. This self-assessment process is then subjected to “credible challenge” by second-line risk teams to ensure that self-reporting is accurate and rigorous.
What are Citi’s Level 0 risks?
Citi defines its Level 0 risks as the foundational, high-level categories of risk that have the potential to materially impact the entire enterprise. As outlined in the Risk Management Committee charter, these seven risks are:
- Credit Risk
- Market Risk
- Liquidity Risk
- Strategic Risk
- Operational Risk
- Compliance Risk
- Reputation Risk
Every sub-category of risk—whether it is cybersecurity, fraud, model drift, or third-party vendor risk—is mapped back to one of these seven primary pillars to ensure comprehensive board-level oversight.
How does Citi’s risk management compare to industry standards?
Citi’s risk management framework heavily aligns with global banking standards, including the Basel III accords and the Sarbanes-Oxley (SOX) Act. By utilizing the “three lines of defense” model, Citi maintains a clear separation of duties between those who take risk (the business units), those who oversee risk (Independent Risk Management), and those who provide independent assurance (Internal Audit).
Additionally, Citi’s approach to model risk management and fraud policy is highly structured, utilizing independent validation utilities to audit internal compliance controls. This multi-layered defense model represents the industry gold standard for managing complex, systemic risks in highly regulated environments.
Conclusion
Managing citi risk and controls at scale is an incredibly complex undertaking, requiring thousands of specialized professionals, rigorous board-level charters, and sophisticated self-assessment frameworks. However, organizations of all sizes can apply these structural principles to build robust digital resilience without requiring a global banking budget.
Achieving this level of governance involves focusing on alignment over complexity, reducing operational burdens, and addressing tool sprawl. By treating resilience as an enabler, organizations can ensure they are both compliant and prepared for secure growth and emerging technologies like AI.
For organizations seeking to evaluate their current posture and implement structured frameworks, resources such as DataEndure Risk Management Solutions provide methodologies for aligning security, compliance, and operational risk management. Establishing a resilient foundation requires continuous assessment, clear ownership, and a commitment to proactive risk governance.


