Conduct Risk: From Individual Behaviour to Customer Harm
Conduct risk rarely starts as a single bad decision — it usually starts as a small, repeated behaviour that compounds until it becomes visible as harm.
Conduct risk is often described abstractly — as a category on a risk register — but it is built entirely out of individual behaviours: how a product is described, how a target is pursued, how a complaint is handled. Understanding the chain from behaviour to harm is what lets staff intervene early, before a pattern becomes a finding.
What Conduct Risk Actually Is
Conduct risk is the risk that the way a firm and its people behave — not just what products they sell — results in poor outcomes for customers or markets. It sits alongside credit risk and operational risk as a distinct category precisely because it can exist even when every individual transaction is technically compliant.
Common Drivers
The same drivers appear repeatedly across conduct risk cases: incentive structures that reward volume over suitability, complex products sold to customers who can't reasonably evaluate them, understaffed complaints teams, and cultures where challenging a senior colleague feels professionally risky. None of these drivers are illegal on their own — the risk comes from how they interact.
From Individual Behaviour to Customer Harm
A single mis-sold product might cause limited harm to one customer. The same behaviour repeated across a sales team, unnoticed because no one is looking at the pattern rather than the individual case, is how conduct risk becomes a systemic customer harm event — the kind that draws regulatory attention and remediation costs far beyond the original transactions.
Market-Level Conduct Risk
Conduct risk isn't limited to retail customers. Poor behaviour in trading, benchmark submission or research can distort markets that many participants rely on, which is why conduct risk frameworks typically cover market integrity alongside customer treatment.
Controls That Actually Interrupt the Chain
Effective controls tend to look for patterns rather than isolated incidents: sales quality monitoring across a whole team, not just individual complaint investigation; product reviews that check outcomes for the target market, not just approval at launch; and management information that surfaces trends early rather than only after a spike in complaints.
When and How to Escalate
Recognising an early conduct risk signal — a colleague under unusual pressure, a spike in a particular type of query, a product performing differently for one customer segment — and escalating it before it becomes a pattern is the single most effective individual action against conduct risk.
Frequently Asked Questions
Is conduct risk only relevant to sales roles? No — operations, product, technology and support functions all shape customer and market outcomes and carry conduct risk exposure.
How is conduct risk measured? Firms typically use a mix of complaint data, sales quality reviews, customer outcome testing and employee surveys, since no single metric captures it fully.
What's the difference between conduct risk and reputational risk? Conduct risk is about the underlying behaviour and harm; reputational risk is one possible consequence of conduct risk becoming visible.
Related reading: Learnsignal's CPD course library and the course on auditor ethics and liability.
A Worked Example
A complaints team notices a small but consistent rise in complaints about a specific add-on product, each one individually resolved without escalation because no single case looks serious on its own. Only when someone looks across cases rather than within them does a pattern emerge suggesting the product's target market has drifted from its original design. This is conduct risk in its clearest form — no single decision was clearly wrong, but the accumulation produced real customer harm that individual case handling never surfaced.
Key Takeaways
Conduct risk lives in patterns, not isolated transactions, which is why controls designed to catch individual bad actors often miss it entirely. Staff closest to repeated customer interactions — sales, service, complaints — are usually the first to notice an emerging pattern, making their willingness to escalate observations, not just resolve individual cases, a critical control in its own right.
How This Fits Into a Broader Compliance Programme
Conduct risk frameworks are usually the layer that connects individual behaviour monitoring to firm-wide risk appetite and regulatory reporting. Staff who understand how their day-to-day behaviour feeds into this bigger picture are more likely to flag early signals that pure transaction monitoring will miss.
Can conduct risk exist without any rule being broken? Yes — this is precisely what makes it distinct from compliance breaches, and why behavioural and outcome monitoring matter alongside rule-based controls.
Building This Into Team Practice
Reducing conduct risk in practice usually depends on connecting data that different teams hold separately — complaints, sales quality, product performance and staff feedback rarely sit in one place. Firms that build a regular cross-functional review of these signals together, rather than each team reviewing its own data in isolation, catch emerging conduct risk patterns considerably earlier than firms relying on any single data source to surface a problem on its own.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team

