Fiduciary risk behaves differently from every other risk on a bank's balance sheet, and the differences explain why trust departments need a control structure rather than good intentions.
The exposure is not capped by the transaction. A credit loss is bounded by the loan amount. A fiduciary breach is bounded by the harm, which can exceed the account's value and bears no relationship to the fee the bank earned.
The tail is long. Claims arrive when a remainder beneficiary receives an accounting years later, when a trust terminates decades after the decisions being questioned, or when a successor trustee reviews the file. The officer who made the decision has usually left.
There is no provisioning mechanism. Nothing accrues for it, and it surfaces as a loss event or a legal expense with no warning in the financials.
The loss is frequently reputational first. Fiduciary disputes involve families in the bank's own community, and they are discussed.
Our companion post on trust administration covers the duties and the daily administrative acts. This post covers the program that keeps them from failing.
Board oversight of fiduciary activities is an expectation, not a preference. The board or a designated committee approves the fiduciary policies, receives reporting on the activities, and is accountable for the adequacy of oversight — the same structure applied to any other significant activity.
A fiduciary or trust committee with a written charter, a defined membership, a quorum, minutes that record discussion rather than attendance, and specified authority. What distinguishes a committee that functions: it makes decisions the department cannot make alone — account acceptance and resignation, investment authority and exceptions, large or unusual discretionary distributions, unique asset retention, and fee exceptions — and its minutes show it declining things.
Written policies covering account acceptance and closure, investment management and the review cycle, discretionary distributions, conflicts and self-dealing, unique assets, fees, and error handling. The gap most often found is not the absence of policies but the absence of a link between them and evidence they operated.
Independence within a small department. Most community bank trust departments are too small for a separate second line, and the workable answers are a compliance or risk officer outside the department with fiduciary competence, a periodic independent fiduciary review by an outside firm, and internal audit coverage that examines fiduciary activity specifically rather than as a subset of operations. What does not work is a department that reviews only itself.
Fiduciary risk management is largely a set of recurring reviews, and an examiner's assessment tracks closely to whether they occurred and are evidenced.
Account acceptance review. Is the instrument administrable, are the assets ones the department can handle, are there conflicts or existing disputes, does the fee bear a reasonable relationship to the work, and are there imminent deadlines? A department that has never declined an appointment is not performing this review.
Annual investment review of every fiduciary account's holdings, which the fiduciary activities requirements make explicit. Per account, not per model, with a documented conclusion and evidence of who and when.
Administrative review on a defined cycle: is the instrument being followed, are distributions consistent with the standard, is the file complete, are the beneficiaries being informed, is the fee correct, and are unique assets current on valuation and inspection.
Discretionary distribution approval, with authority levels defined by amount and circumstance, so that unusual distributions receive a second judgment before rather than scrutiny after.
Unique asset review on a schedule by asset type — valuation, inspection, insurance verification, and financial information where the trust holds a business interest.
Account closure and termination review, which catches the accounts that should have terminated and did not, and the terminations that were mishandled.
Overdraft and cash management review, since fiduciary account overdrafts raise self-dealing questions in addition to operational ones.
Two properties determine whether the cycle is worth running. Overdue items must be visible and escalated — a review calendar with no aging report becomes a list of intentions. And reviews must be capable of producing findings. A review process that has never generated an exception is a signature exercise.
The area where trust departments most often create their own governance problem.
Fiduciary errors happen: a distribution to the wrong party, a missed tax filing, a trade error, a fee miscalculation, a missed instruction. The correct handling is to make the account whole, document what happened, and record it.
What frequently happens instead is that the department quietly reimburses the account and records nothing, on the reasoning that no harm remains. That reasoning produces three problems: the institution has no data on how often errors occur or why, a pattern of similar errors is invisible, and an undisclosed reimbursement discovered later looks considerably worse than the error itself.
A fiduciary error and loss log — date, account, what happened, root cause, amount, how it was resolved, and who approved — is a small artifact with outsized value. It supplies the root cause analysis that prevents recurrence, and it is the kind of self-identification examiners credit rather than penalize.
The general prohibitions on self-dealing are covered in our trust administration post. The program elements are what belong here:
Personal trading and information controls. Trust staff routinely see material nonpublic information — the financial statements of closely held businesses, the holdings of corporate insiders, pending transactions. A personal trading policy, restricted lists where appropriate, and confidentiality controls are necessary in a way that is easy to overlook in a small department where everyone sees everything.
Gifts and bequests. A grateful client naming the officer who administered their mother's trust is a recurring event, and a department with no policy addresses it under pressure and badly. The policy should be written before it is needed.
Outside activities. Staff serving personally as trustee, executor, or on a board for a client family, which creates conflicts and confusion about capacity.
Affiliate products and services, where use requires specific authority and disclosure and where the compensation flow needs to be understood by whoever approves it.
Bank stock and obligations in fiduciary accounts, and deposit of fiduciary funds with the institution, both governed specifically.
Fees, which are a conflict at the margin: a fee calculated on assets creates an interest in retaining assets and in valuations, which is precisely why unique asset valuations need to be independent and current.
Structured coverage is available through the Certificate in Fiduciary Principles and Ethics, the Certificate in Fiduciary Relationship Management, the Certificate in Core Concepts and Ethics for Fiduciary Advisors, and the Certificate in Operational Risk Management.
Modern fiduciary law generally permits a trustee to delegate investment and management functions — and conditions the permission on the trustee exercising reasonable care in selecting the agent, in establishing the scope and terms of the delegation, and in periodically reviewing the agent's performance and compliance with the terms.
That converts the use of outside investment managers, sub-advisers, and third-party platforms from a convenience into a governed activity. The practical requirements:
Documented selection, with the basis for choosing the manager recorded rather than inherited.
A defined mandate, so performance can be assessed against something.
Periodic review of performance, adherence to the mandate, fees, and the manager's own organizational stability — evidenced, on a schedule.
Attention to layered fees, since the client pays both the bank and the manager and the total needs to be reasonable and disclosed.
The same discipline extends to the department's other vendors — the trust accounting system, custodians and subcustodians, appraisers, and tax preparers — which belong in the institution's third-party risk program as described in our vendor management post. The trust accounting system in particular is a concentration: it holds the record of every account, produces the statements and tax reporting, and would be extraordinarily difficult to replace.
Because claims arrive years later, the department's defense is built now.
Contemporaneous documentation. The decision recorded at the time, with the reasoning, is worth more than any reconstruction. The operating principle is that in a fiduciary dispute the file is the only witness available, since memories will be old and the people involved may be gone.
Retention that outlasts the account. Fiduciary records need to survive the account's termination and the limitations period, which for trust matters can run far longer than a standard retention schedule contemplates.
Preservation on notice. Once a claim or dispute is reasonably anticipated, ordinary destruction has to stop — a discipline that requires someone to actually issue the instruction.
Communication records. Much of what beneficiaries later dispute is what they were told. Notes of significant conversations, and written confirmation of significant decisions, resolve a large share of these disputes before they develop.
Fiduciary liability coverage and errors and omissions coverage respond to these events, and the financial institution bond covers others. Three questions worth answering before a claim rather than during one: does the coverage respond to this type of allegation, what is the retention relative to a plausible claim, and what notice does the policy require — since several policies require notification within a short period of becoming aware of a circumstance, and late notice can void coverage.
Insurance transfers financial consequence. It does not transfer the breach, the beneficiary relationship, or the examination finding.
Trust departments are small and knowledge-intensive, which produces the most predictable operational risk in the area: one person understands the difficult accounts.
The mitigations are unglamorous and effective: instrument summaries maintained for every account, decision rationale written in the file rather than held in memory, cross-coverage assigned and exercised rather than nominal, and succession planning for the department's senior officer. A department where one officer's departure would create genuine uncertainty about several accounts has an unaddressed risk regardless of how well those accounts are currently administered.
Capacity itself is a risk indicator. Accounts per officer growing without staffing, review backlogs, and chronic overtime in a fiduciary function are early signals of the failures described throughout this post.
Reporting that supports oversight rather than filling a packet:
The summary a trust department head can act on: fiduciary risk is managed almost entirely through recurring reviews that produce findings and through contemporaneous documentation of decisions. Neither is expensive. Both are visible to an examiner in an afternoon, and both are what stands between a defensible judgment and an indefensible one when the question arrives ten years late.
Because the exposure is not capped by the transaction, the claims arrive years or decades after the decisions, nothing accrues for it in the financials, and the damage is frequently reputational within the bank's own community. Those properties mean the defense has to be built at the time of the decision rather than assembled when the claim appears.
Through a compliance or risk officer outside the department with fiduciary competence, a periodic independent fiduciary review by an outside firm, and internal audit coverage that addresses fiduciary activity specifically rather than as part of general operations. A department that reviews only its own work has no second line.
Yes. Quietly reimbursing an account and recording nothing leaves the institution with no data on error frequency or cause, makes patterns invisible, and creates a worse problem if the undisclosed reimbursement is discovered later. An error and loss log recording date, account, cause, amount, and resolution is a small artifact that supports root cause analysis and reads as self-identification.
No. Delegation is generally permitted and conditioned on exercising reasonable care in selecting the agent, establishing the scope and terms, and periodically reviewing performance and compliance with those terms. Documented selection, a defined mandate, scheduled review, and attention to layered fees are what satisfy that.
Overdue reviews by type, with aging. It reveals whether the control cycle is actually operating, and it is the fastest indicator that capacity has fallen behind the department's account load.
Because a grateful client naming the officer who administered a family member's trust is a recurring event, not an exotic one. A department without a written policy confronts the question under pressure, with an officer's personal interest already engaged, and handles it badly.


