Conduct Risk in Financial Services: Mis-selling, Suitability and Redress
Conduct Risk in Financial Services is the risk that a bank, insurer or intermediary behaves in a way that produces unfair outcomes for customers or damages market integrity — even when the process worked and no rule was technically broken. In the IIBF Risk in Financial Services (RFS) paper, conduct risk in financial services is treated as a distinct exposure because the loss event is a customer outcome: a mis-sold policy, an unsuitable fund, a charge the buyer never understood.
That distinction is exactly what examiners probe. Credit risk asks "will the borrower repay?" Conduct risk asks "should we have sold this to this person at all?" Everything else in this article — drivers, mis-selling patterns, suitability gates, metrics, ownership and redress — follows from that single question.
🎯 What Conduct Risk Is, and Why It Is Not Operational or Compliance Risk
Conduct risk entered mainstream risk taxonomy after the Global Financial Crisis, when supervisors realised that firms with clean capital ratios were still generating enormous customer-detriment losses. The regulatory rebuild you study in Global Financial Crisis and Basel III fixed solvency; it did not fix selling behaviour. The concept of conduct risk in financial services was the supervisory answer to that gap.
Students routinely collapse conduct risk into operational risk because Basel's operational-risk event types include "clients, products and business practices". That mapping is a capital convention, not a management one. Operational risk is about failure — a system crashes, a clerk fingers the wrong amount, a vendor misses an SLA. Conduct risk can occur when every system works perfectly and every field is keyed correctly; the failure is in the intent, incentive or information gap behind the sale.
Compliance risk is narrower still. It is the risk of breaching a specific law, regulation, or supervisory direction, and it is tested against a rulebook. Conduct risk is tested against outcomes and the principles behind the rulebook — most visibly the RBI Charter of Customer Rights, whose five rights (fair treatment, transparency and fair dealing, suitability, privacy, and grievance redress with compensation) are the conduct spine of Indian retail banking. A sale can be fully rule-compliant and still fail the suitability right.
The taxonomy question is worth revisiting alongside the general framework in Risk Management, because conduct sits at the junction of operational, reputational, legal and strategic risk rather than inside any one of them.
| Dimension | Conduct Risk | Operational Risk | Compliance Risk |
|---|---|---|---|
| Primary loss event | Unfair customer outcome | Failed people, process, system or external event | Breach of a specific law or direction |
| Is a rule breach necessary? | ❌ No | ❌ No | ✅ Yes |
| Tested against | Outcomes, fairness, suitability | Loss data, incident logs, KRIs | Rulebook, circulars, directions |
| Typical lead indicator | Complaints, persistency, churn | Near-misses, downtime, error rates | Audit findings, regulatory observations |
| Typical remedy | Redress, remediation, incentive redesign | Process fix, control build, capacity | Policy update, training, attestation |
💡 Exam Tip: If a question describes a transaction that was correctly processed, fully documented and rule-compliant but left the customer worse off than a plainer product would have, the answer is conduct risk — not operational risk.
⚙️ The Four Drivers Examiners Keep Testing
Conduct risk in financial services is rarely the work of a rogue individual. It is manufactured by structures, and RFS questions almost always trace back to one of four drivers.
Incentive design
Front-loaded commission, volume-linked variable pay, and league tables reward the sale rather than the outcome. When an insurance policy pays a large first-year commission and a small trail, the economics push the seller toward fresh sales and replacements instead of servicing existing policyholders. Deferral, clawback and quality-linked gates on variable pay are the standard mitigants.
Sales targets
Targets become a conduct driver when they are set top-down, cascaded to individual branch staff, tied to job security, and measured only in units or premium. The classic failure pattern is a quarter-end spike followed by a first-anniversary lapse spike — visible in data long before a single complaint is filed.
Product complexity
Unit-linked policies, structured notes, credit-linked debentures and hybrid schemes bundle protection, investment and charges into one wrapper. Complexity raises conduct risk mechanically: the more assumptions a payoff depends on, the more likely the buyer misunderstands it. This is the same reason a mutual fund risk management framework puts so much weight on standardised risk labelling and disclosure.
Information asymmetry
The seller knows the charge structure, surrender penalty, exit load and expected persistency; the buyer usually does not. Digital journeys can widen this gap — pre-ticked consents, buried key-facts screens and default add-ons are conduct failures created by design choices, which is why the controls discussed in Technology Risk now carry an explicit fairness dimension.

🏦 Mis-selling Through Bank Channels
Bancassurance and third-party product distribution concentrate conduct risk because the customer's trust is in the bank, while the product risk and the payout sit with an insurer or asset manager. The bank earns fee income with no balance-sheet exposure, and that asymmetry is the root of most Indian mis-selling cases.
The recurring patterns you should be able to name in an exam answer:
- Deposit substitution — a single-premium or short-pay life policy pitched to a depositor as a "better fixed deposit", concealing the multi-year premium commitment and surrender penalty.
- Tying and bundling — insurance presented as a precondition for a loan, locker or account upgrade, when it is legally optional.
- Senior-citizen targeting — long-tenor or unit-linked products sold to customers whose horizon and liquidity needs cannot support them.
- Churning and twisting — persuading a policyholder to surrender and replace an in-force policy, or switching a fund portfolio, primarily to regenerate commission.
- Signature-only onboarding — forms filled by staff, need-analysis completed as a formality, and the customer signing without reading.
- Retirement product mismatch — an annuity or pension product chosen without matching the payout option to the customer's dependants, a theme covered in depth under pension fund risk management.
Indian safeguards are structural rather than merely advisory: a free-look window under the IRDAI policyholder-protection framework lets a buyer exit a new policy with a refund net of prescribed deductions; standardised benefit illustrations and key-features documents force charge disclosure; and trail-based, no-upfront-commission economics in mutual funds deliberately blunt the churn incentive. Each control targets a specific driver rather than conduct risk in financial services as a whole.
⚠️ Common Mistake: Treating "the customer signed the declaration" as a defence. Conduct risk is assessed on the outcome and on whether the customer genuinely understood; a signature obtained on a pre-filled needs-analysis form is evidence of a weak process, not of informed consent.
🧭 Suitability and Appropriateness: Two Different Gates
These two words are the highest-yield definitional pair in the conduct syllabus, and candidates lose marks by using them interchangeably.
Appropriateness is the lower gate. It asks a single question: does this customer have the knowledge and experience to understand the risks of this product? It applies where the customer approaches the firm on an execution-only basis, without advice. If the answer is no, the firm must warn the customer; it is not required to construct a portfolio.
Suitability is the higher gate and applies whenever advice or a recommendation is given. It requires the firm to assess three things together — the customer's financial situation and capacity to bear loss, their investment objectives and time horizon, and their knowledge, experience and risk tolerance — and then to demonstrate that the recommended product fits all three. Suitability is a positive, documented obligation; appropriateness is largely a warning obligation.
In Indian practice, suitability is embedded in the RBI Charter's Right to Suitability, in board-approved suitability policies at insurers, and in the risk-profiling requirements applied to portfolio management and advisory relationships. The operational proof is the file: a dated need-analysis, a recorded risk profile, the rationale for the recommendation, the alternatives considered, and the disclosure the customer actually received.
A practical drafting rule for descriptive answers: appropriateness protects the customer from a product they cannot understand; suitability protects the customer from a product they can understand but should not own.
📌 Remember: No-advice, execution-only sale → appropriateness test. Advice, recommendation or "bank told me to buy it" → suitability test, with a documented rationale on file.

📊 Measuring Conduct Risk: Complaints, Persistency, Churn, Mystery Shopping
Conduct risk in financial services cannot be measured with a single value-at-risk number, so firms triangulate from behavioural indicators. Four families of metrics carry the load.
Complaints analytics. Raw complaint volume is a weak indicator because it depends on how easy the firm makes complaining. What matters is complaints per thousand accounts or policies, sliced by product, branch, seller and root cause; the ratio of mis-selling-coded complaints to total; escalation rate to the ombudsman; and the proportion decided against the firm. A branch with zero complaints and a high lapse rate is a red flag, not a star.
Persistency. The 13th-, 25th-, 37th-, 49th- and 61st-month persistency ratios measure the share of policies still in force after those durations. Thirteenth-month persistency is the single best early conduct indicator available in insurance distribution: a policy that lapses immediately after the first anniversary usually means the buyer never wanted or could not sustain it. Persistency read at seller and branch level exposes mis-selling clusters that complaints data alone will miss.
Churn and switching. Replacement rates, surrender-and-repurchase patterns, unusually high portfolio turnover, and switching concentrated near commission-qualifying dates all indicate that the transaction served the seller.
Mystery shopping and call-quality review. Incognito visits and scripted scenarios test what is actually said at the counter, not what the manual says should be said. Combined with welcome-call verification, voice-log sampling and post-sale confirmation, mystery shopping is the only method that captures oral mis-representation, which never appears in any document.

🛡️ Three Lines of Defence, Remediation and Board Reporting
Ownership is a favourite question, and the answer is unambiguous: the first line — the business, the branch, the relationship manager and their supervisors — owns conduct risk. Sales leadership sets targets and incentives, so it owns the consequences. Conduct cannot be outsourced to a control function.
The second line — risk and compliance — designs the conduct-risk framework, sets the appetite and tolerance statements, defines the metrics, runs product-approval and governance forums, and challenges the first line's self-assessment. It also feeds conduct into the firm-wide view described in an enterprise risk management framework, so conduct exposures are aggregated with credit, market and operational exposures rather than reported in a silo.
The third line — internal audit — independently tests whether the first two lines actually work, using sampling, file reviews and thematic assignments. The risk-based audit planning approach in Risk Based Internal Audit is what directs audit effort toward the highest-conduct-risk products and branches.
Remediation and redress follow detection. Remediation fixes the cause — withdraw or redesign the product, rewrite the incentive, retrain or exit the seller, tighten the sales process. Redress makes the customer whole through refund of premium or charges, reversal of fees, cancellation without penalty, or compensation for loss. A firm that pays redress but never remediates will simply reproduce the same detriment next quarter.
Where internal redress fails, the customer escalates. For banks and regulated entities under RBI, the RB-IOS 2026 scheme took effect on 1 July 2026: the complaint window is 90 days from the entity's reply or from the lapse of its response period, the award ceiling is Rs 30 lakh, and compensation for consequential loss such as time, agony and expense is capped at Rs 3 lakh. Insurance complaints run through the Insurance Ombudsman mechanism and securities complaints through SEBI's grievance and online dispute-resolution route. Monitoring how these external frameworks evolve is part of managing regulatory risk in banks.
Board reporting should be short and decision-grade: appetite versus actual on each conduct metric, top three products and branches by detriment, redress paid and provisioned, remediation status with owners and dates, and forward-looking items from product approvals and horizon scanning. Boilerplate complaint counts are precisely what supervisors criticise.
🧠 Practice MCQs: Conduct Risk and Mis-selling
Q1. A bank sells a 10-year unit-linked policy to a 72-year-old depositor seeking liquid savings. All forms are complete, KYC is valid and no regulation is breached. This is primarily: (a) Operational risk (b) Compliance risk (c) Conduct risk (d) Legal risk
Answer: (c) — No process failed and no rule was breached; the detriment arises from an unsuitable outcome, which is the definition of conduct risk.
Q2. Which metric is the earliest reliable warning of insurance mis-selling at a branch? (a) 13th-month persistency ratio (b) Total complaint volume (c) Claims settlement ratio (d) Solvency margin
Answer: (a) — A drop in 13th-month persistency shows policies lapsing right after the first anniversary, which typically means the buyer never wanted or could not sustain the product.
Q3. A customer approaches a broker on an execution-only basis with no advice sought. The firm must primarily apply: (a) A full suitability assessment (b) A solvency assessment (c) A credit appraisal (d) An appropriateness test
Answer: (d) — Without advice, the firm's duty is to check whether the customer has the knowledge and experience to understand the product's risks, and to warn if not.
Q4. Under RB-IOS 2026, effective 1 July 2026, the limit on compensation for consequential loss such as time lost, agony and expenses is: (a) Rs 1 lakh (b) Rs 3 lakh (c) Rs 20 lakh (d) Rs 30 lakh
Answer: (b) — RB-IOS 2026 caps consequential-loss compensation at Rs 3 lakh, separate from the overall award ceiling of Rs 30 lakh.
Q5. In the three-lines-of-defence model, day-to-day ownership of conduct risk in a bancassurance sales channel rests with: (a) Internal audit (b) The compliance department (c) The business and its sales supervisors (d) The external auditor
Answer: (c) — The first line owns the risk it creates; risk and compliance set the framework and challenge, while internal audit independently tests both.
Want chapter-wise mock tests with 100+ MCQs? Start practising free →
❓ Frequently Asked Questions
Is conduct risk the same as reputational risk?
No. Conduct risk is the cause; reputational damage is one of its consequences, alongside redress cost, remediation expense, supervisory action and lost future business. A conduct failure can be settled quietly and still cost heavily even if reputation is untouched.
Does conduct risk attract a separate regulatory capital charge?
There is no standalone conduct-risk capital charge. Conduct losses are generally captured within the operational-risk event type covering clients, products and business practices for capital purposes, but they are managed, measured and reported as a distinct risk category.
How is churning different from twisting?
Both regenerate commission at the customer's cost. Twisting usually means inducing a policyholder to surrender an existing policy and buy a replacement, often with the same insurer; churning is the broader pattern of repeated switching or excessive portfolio turnover driven by seller economics rather than customer need.
What documents prove a suitable sale if a complaint is raised later?
A dated needs analysis and risk profile, the recorded rationale linking the recommendation to that profile, evidence of alternatives discussed, the benefit illustration or key-features document actually given, and a welcome-call or post-sale confirmation record.
Conduct risk in financial services is examined as a management discipline, not a slogan: identify the driver, name the metric that would have caught it, place ownership in the right line of defence, and separate remediation from redress. Work through the wider reading on risk in financial services, then test yourself under exam conditions with the chapter-wise banks in the CAIIB and certificate course library before you sit the paper.
Practice this topic
Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.
Keep reading