Evidence from the record · What it means for leaders
Silicon
Valley
Bank
The test that kept being changed.
A regulator investigating itself, in public
Silicon Valley Bank failed on 10 March 2023. Seven weeks later, the Federal Reserve published a review of what went wrong—written by its own Vice Chair for Supervision and unusually willing to find against the institution that commissioned it.
That is what makes this case worth your time. Most failure records are produced by outsiders looking for fault. This one was produced by insiders examining their own conduct, and it names supervisory delay, cultural timidity and regulatory choices as contributing causes alongside the bank’s own decisions.
It also contains the clearest documented example of a mechanism every organisation is capable of: when the measurement said no, the measurement was changed.
The bank changed its
risk assumptions to reduce
how risks were measured.
Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, April 2023. The report states that this was done rather than fully addressing the underlying risks, and elsewhere that changing model assumptions is not an appropriate way to restore compliance with limits.
Decades of growth.
Two days of collapse.
Seven weeks to examine why.
Founded; by 2023 a central institution of the technology economy
Days between the bank announcing a fix and being closed
Weeks from failure to the regulator publishing its self-review
Separate official reviews reached broadly the same conclusion
What happened
A bank that grew very fast, in one sector, funded by deposits that could leave in an afternoon.
Extraordinary growth, one customer type
Deposits surge with the technology boom. The bank’s business model becomes highly concentrated and heavily reliant on uninsured deposits—money that has no reason to stay if confidence goes.
Moved into closer supervision, slowly
The bank enters the supervisory portfolio for large organisations. It arrives with a default assessment of satisfactory, and examiners wait to accumulate evidence before lowering its rating.
Hedges removed to protect short-run profits
Senior management manages interest-rate risk with a focus on short-term earnings and protection against rates falling, removing hedges that would have helped if rates rose. Multiple breaches of long-term interest-rate risk limits are recorded and not acted on.
The bank fails its own stress tests
Internal liquidity stress testing shows modelled shortfalls of roughly $18 billion at the thirty-day point and roughly $23 billion at the ninety-day point.
The assumptions are made less conservative
Rather than change the liquidity position, the bank changes the assumptions that determine what the position needs to be. The timing coincides with the periods of severe modelled shortfall.
Supervisors circle, but do not land
Concerns are raised about unsupported deposit-outflow assumptions. A downgrade is under consideration. The governance rating is not lowered, in part because financial performance still looks satisfactory.
The restructuring is announced
The bank announces a balance-sheet restructuring—the real fix, arriving at the worst possible moment and read by depositors as an admission.
Closed
The deposits leave. The bank fails before the supervisory downgrade it was heading for can even be finalised.
The size of what the tests
were saying.
These were not marginal breaches or technical amber flags. The bank’s own models, run by its own people, were reporting shortfalls in the tens of billions.
Position as at 31 August 2022
Position as at 30 September 2022
A modelled shortfall means the bank’s own test said it would run out of money it could access under a stress scenario it had itself designed.
The bank did not lack information. It generated the information itself, on schedule, and it was unambiguous.
The question this case answers is what an organisation does next when the number it produced disagrees with the strategy it has already committed to.
Good results held the rating up
A downgrade of the bank’s governance and control rating was supported by fundamental weaknesses that supervisors had identified.
It did not happen, in part because financial performance was still considered satisfactory—so the risk-management deficiencies were not treated as threatening the bank’s soundness.
Strong results were taken as evidence that the controls were adequate. They were evidence of nothing except that the risk had not yet arrived.
The exposure never moved
There are only ever two ways to resolve a failed test. Change the thing being measured, or change the measurement.
Only one of them is cheap this quarter. Only one of them is real.
Exposure breaches the limit
The bank’s actual exposure sits above the limit established by its own test.
The limit moves above the exposure
The exposure is unchanged, but the revised measure now declares it compliant.
The red bar is identical in both panels. Nothing about the bank’s actual position changed.
Why it happens
It never feels indefensible at the time
Described plainly, changing the measure instead of the exposure sounds indefensible. At the time, it feels like a technical correction by people who understand the model better than the model does.
There is nearly always a genuine argument that the old assumption was too conservative.
Every organisation that moves a threshold has a good reason for moving it.
How to tell
the difference.
Assumptions genuinely do need revising. Models drift, businesses change, and a measure calibrated for one era can be actively misleading in the next.
So the question is not whether an organisation ever changes its own tests. It is how to distinguish a legitimate recalibration from an evasion. The regulator’s report supplies the test almost in passing: look at the timing, and look at the direction.
Look at the timing
When was it changed? If the revision coincides with the period in which the measure was failing, that is not a coincidence and should not be treated as one.
Look at the direction
Legitimate recalibration goes in both directions over time.
An organisation whose assumptions only ever become less conservative is not refining its model. It is negotiating with it.
The board was not told enough to intervene
The Federal Reserve found that the bank’s directors did not receive adequate information about the vulnerabilities building underneath them, and did not hold management accountable for the failure to manage those risks.
This is the same join that failed elsewhere in this series. A board that only sees the output of the measurement, and never the history of how the measurement was set, has no way to spot this happening.
What was missing
The Shortboard model describes twelve attributes an organisation builds across three cumulative waves.
Wave One is Lean Dependability—the ability to do what you say you will do, honestly and without drama. Wave Two enables scalable growth. Wave Three creates perpetual relevance.
Capabilities in the later waves cannot hold when Wave One is hollow, because there is nothing underneath them to take the weight.
The regulator’s own summary described foundational and widespread managerial weaknesses. Read against the twelve attributes, that is precisely what appears: the whole of Wave One, in an institution forty years old and growing beautifully.
Lean Dependability
Scrappy resourcefulness
Using limited resources deliberately while understanding and evidencing how the operation performs.
Healthy
conflict
Surfacing disagreement early and allowing evidence to challenge authority before decisions are made.
Ruthless consolidation
Choosing what to stop so attention, money and capacity remain focused on what matters most.
Distributed ownership
Placing authority and accountability close to the people with the knowledge required to act.
New Growth
Continuous reinvention
Continually renewing propositions instead of treating current success as permanent.
Structural fluidity
Reconfiguring people and resources rapidly around emerging priorities and opportunities.
Strategic optionality
Maintaining several credible paths rather than committing too early to a single answer.
Platform thinking
Building reusable capabilities that make future growth faster, easier and less expensive.
Perpetual Relevance
Pioneer sanctuaries
Protecting emerging ideas from the demands and assumptions of the established organisation.
The awe-driven mindset
Remaining curious about what is becoming possible instead of defending what is already known.
The pioneer’s leap
Acting decisively when evidence is incomplete but the cost of waiting is greater.
Supply-driven optionality
Creating new possibilities from emerging capabilities before established demand is visible.
Growth was never the problem
Silicon Valley Bank was extremely good at the thing it was famous for. It understood its market, served it better than anyone, and grew accordingly. None of that was an illusion.
Wave One is not a stage you pass through and leave behind. It is a floor that has to keep holding weight—and the faster the growth above it, the more weight it is asked to hold.
The four
Wave One gaps.
Each of these is drawn from the published reviews, not inferred from the outcome.
Scrappy resourcefulness
An organisation can only be resourceful about a reality it is willing to look at. Once a measurement becomes something you can adjust, it stops being information and becomes an output to be managed. The models were capable. They were treated as negotiable, which destroyed their value entirely.
Healthy conflict
Multiple breaches of long-term risk limits were recorded and not acted on. Supervisors raised concerns and were absorbed rather than answered. There was no point at which someone with standing was able to say “the plan is wrong” and have that stick.
Ruthless consolidation
A highly concentrated business model, one customer sector, and heavy reliance on deposits that could leave at will. The concentration was known and named by everyone involved. It was treated as a characteristic of the bank rather than a limit to be held, and nothing was ever trimmed to reduce it.
Distributed ownership
The board did not receive adequate information about the risks building beneath it, and did not hold management to account. Supervisors saw problems and waited to accumulate more evidence. At every level, the person who could see was not the person who could act.
Foundational and widespread, in the regulator’s own phrase.
And entirely compatible with forty years of success—right up until the specific conditions arrived that the floor was supposed to protect against.
Forty-eight hours,
and then the system
The gap between the bank publicly doing the right thing and the bank ceasing to exist was two days.
That is the part worth sitting with. The restructuring announced on 8 March was a genuine attempt to fix the underlying problem. By then it could only be read as confirmation that the problem existed, and the deposits it was meant to protect left faster than any balance sheet could be repaired.
Delayed corrections do not arrive late. They arrive as evidence against you.
Failure
Followed within days by a second bank failure and emergency measures to contain the spread.
The self-review
The Federal Reserve publishes its review. A separate state regulator’s report follows.
Independent agreement
The Federal Reserve’s own inspector general reports independently and broadly agrees.
The system changes
The supervisory approach and the tailoring of rules for mid-sized banks are reopened.
The reviews did not confine themselves to the bank.
They found that the supervisory approach was too deliberative, too consensus-driven, and too willing to keep gathering evidence rather than act on what it already had.
They also found that earlier regulatory changes had reduced the standards the bank would otherwise have faced during its fastest growth.
Both sides were waiting for more evidence
The bank waited to act on its stress tests. The supervisors waited to act on their findings. Both waits were individually reasonable and professionally defensible.
Nobody in this story was reckless. The failure was built entirely out of decisions to wait a little longer for a clearer picture, made by careful people on both sides of the table.
Which one you change is
the whole of your culture.
When the number disagrees with the plan, one of them has to move. Which one you move is the answer.
Every organisation eventually produces a measurement that contradicts a commitment it has already made. What happens in that moment is not a technical question, and it is not usually decided at board level.
It is decided by whoever owns the model, under pressure, in a week when the alternative is expensive.
And it is almost never recorded as a decision at all. Nobody minutes “we chose not to face this.” They minute an assumption update.
When one of our numbers last contradicted the plan, did we change the plan or the number?
Who has the authority to change how a risk is measured here, and who reviews that change?
What is currently within limits only because the limit was revised?
Keep a change log for your measures
Not the numbers. The definitions.
Every time a target, threshold, assumption or method of calculation changes, record what changed, when, who approved it and why.
Then read the log once a year and check the direction of travel. If every revision over five years made things look better, you have found something more important than any individual metric.
How we know this,
and what we don’t.
These studies are only worth reading if the evidence behind them is stated plainly, including where it is weak.
A regulator’s review of its own supervision, drawing on the confidential supervisory record.
This included examination findings, ratings decisions and internal correspondence that was not otherwise public.
It was corroborated within months by the Federal Reserve’s own inspector general and by a state regulator, working separately. Three reviews, broadly one account.
It is candid about institutional failings, including cultural ones, which is rare in a self-assessment.
It was written quickly, within weeks of the failure.
That speed has been criticised by people who argue that it left little time to weigh the evidence or test root causes.
It was produced by an institution with an interest in how its own supervision—and the earlier loosening of rules—would be judged. Its recommendations point towards stronger regulation, which was also its author’s known position.
It is not a court judgment. Nothing in it was cross-examined.
An outlier, by the regulator’s own account
The review describes the bank as unusual in the extent of its concentration, its interest-rate exposure and its reliance on uninsured deposits. That matters: this is not a portrait of how banks behave generally.
The mechanism, though, is not specialised at all. Adjusting a measure rather than the thing it measures requires no balance sheet, and happens in organisations of every size.
Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, Board of Governors of the Federal Reserve System, April 2023 · Accompanying congressional testimony, May 2023 · Federal Reserve Office of Inspector General report, September 2023 · California Department of Financial Protection and Innovation review, 2023.
Subscribe to Notes from the Water
Our weekly newsletter brings readers the latest insights, studies, and observations relating to institutional judgement and the business design