Skip to main content

When Employees Fear Retaliation: Governance Lessons from the FDIC

The workplace-culture reviews of the United States Federal Deposit Insurance Corporation (FDIC) illustrate why "tone at the top" is not merely a leadership concept; it is part of the control environment. Formal values, training and complaint channels can lose credibility when employees fear retaliation, senior leaders are perceived to receive different treatment, or management cannot produce reliable information about complaints and disciplinary outcomes.

The case also demonstrates that culture reform requires more than a new policy. Reporting arrangements must be trusted, investigations must be independent, consequences must be consistent, and boards or equivalent oversight bodies must receive enough information to identify patterns that individual cases may conceal.

Scope of the case brief

This brief examines official reviews published between 2020 and 2025, remediation measures subsequently reported by the FDIC, and the status of relevant Office of Inspector General recommendations through September 2026. It does not determine individual legal liability. Its purpose is to identify governance and internal-control lessons that boards, executives, internal auditors, HR teams and compliance professionals can apply in other organisations.

What the official reviews found

Warning signs existed before the public crisis

A 2020 FDIC Office of Inspector General evaluation reported signs of underreporting. Among respondents who said they had experienced sexual harassment, 38 percent said they did not report the incident because they feared retaliation. Nearly 40 percent of respondents did not know, or were unsure, how to report an allegation. These findings mattered because low complaint numbers could not safely be read as evidence that misconduct was rare.

The independent review identified systemic weaknesses

In May 2024, an independent review conducted by Cleary Gottlieb and overseen by a special committee of the FDIC Board concluded that, for too many employees and for too long, the FDIC had failed to provide a workplace safe from sexual harassment, discrimination and other interpersonal misconduct. More than 500 current and former employees shared their experiences. The review also found that management's responses and the conditions that allowed misconduct to persist had been insufficient and ineffective.

The control system did not support trusted reporting

A July 2024 OIG evaluation found that the FDIC had not implemented an effective sexual-harassment prevention programme and had not always investigated and addressed allegations promptly and effectively. The OIG cited insufficient leadership commitment and accountability, an ineffective programme structure, inadequate complaint tracking, weak procedures and insufficient training.

The survey evidence was especially important. In the more recent survey, 49 percent of respondents who had experienced sexual harassment and 51 percent of those who had observed it said they did not report it because they feared retaliation. The OIG cautioned that leadership conduct over time, rather than policy statements alone, would demonstrate whether the organisation had changed.

The experience was not uniform

The December 2024 OIG special inquiry added necessary balance. A majority of survey respondents said they felt safe, valued and respected, and generally viewed their colleagues and immediate managers positively. However, more than one-third reported that they had experienced or personally witnessed harassment. The OIG's case and settlement review also supported perceptions that some managers had failed to protect complainants and had retaliated against employees who filed complaints.

The same inquiry found incomplete disciplinary records, inconsistent documentation of decision-making, and no central system that tracked complaints from receipt to resolution. Executives therefore had different levels of knowledge about workplace misconduct. Those information gaps were governance weaknesses because leaders and the Board could not readily assess trends, consistency or repeated concerns.

Concerns involving senior officials required independent scrutiny

In July 2025, the OIG reported on investigations involving five senior officials. Although the scope and severity varied, the OIG found evidence that each had engaged in some degree of inappropriate workplace conduct. It also found evidence that three officials assisted one another in resolving complaints made against them discreetly and quickly. The OIG said certain actions had not protected victims or aligned consistently with the FDIC's stated values of accountability, fairness and integrity.

What changed after the reviews

The FDIC reports that it created two offices independent of its other operating units to receive and investigate complaints. It revised its anti-harassment and anti-retaliation policies, introduced confidential and anonymous reporting, implemented scenario-based training, updated leadership performance standards, improved the communication of misconduct data, and retained an independent monitor. The agency was using an interim complaint-tracking solution and expected a new case-management system in 2026.

As of 8 September 2026, the OIG's current public list of unimplemented recommendations did not include the workplace-culture reports discussed here. That is evidence that the specific recommendation-tracking position had advanced. It is not, by itself, proof that employee trust or organisational culture had been restored. Those outcomes require continued measurement.

FGL practical interpretation

  1. Tone at the top operates as a control: Leadership messages matter only when appointments, incentives, investigations and disciplinary decisions reinforce them. Weak tone can disrupt risk identification, communication and remediation.
  2. Low reporting may signal fear rather than safety: Boards should compare complaint data with employee surveys, exit information, turnover and settlements. A low number of reports is reassuring only when employees also understand the channels and trust the response.
  3. Retaliation risk tests whether a speak-up system works: A hotline cannot compensate for adverse treatment after a report. Whistleblowing processes must be independent, confidential and permit reporting without fear of retribution.
  4. Senior-leader complaints need independent handling: An investigation is vulnerable when the subject can influence the investigator, the evidence or the outcome. Boards should define a route for complaints involving senior executives that bypasses ordinary management and reports to an independent committee or external investigator.
  5. Case information is governance information: A central register should record allegations, risk classifications, investigators, elapsed time, outcomes, disciplinary decisions, repeat subjects and retaliation concerns. Aggregate reporting should allow the board to see trends and inconsistent treatment.
  6. Remediation must be tested over time: Policies, new offices and training are necessary inputs. Boards should also measure reporting confidence, response times, repeat incidents, consistency of consequences, and whether corrective actions remain effective after initial scrutiny recedes.

Questions for boards and management

  • Can employees report concerns outside their direct management line, confidentially or anonymously where appropriate?
  • Who investigates allegations involving the chief executive, board members or other senior officials?
  • Does the oversight body receive trend information on complaints, retaliation, investigation time and outcomes?
  • Do promotion, remuneration and succession decisions consider substantiated misconduct and failures to act?
  • Can management explain why comparable cases produced different disciplinary outcomes?
  • Does internal audit provide assurance on the design and operation of the reporting system without taking over management's investigative responsibility?

Practical takeaway: The FDIC case shows that culture becomes a governance issue when leadership behaviour, reporting arrangements, information systems and accountability no longer support the organisation's stated values. A speak-up mechanism is credible only when employees understand it, trust it and can use it without suffering retaliation. Boards and executives should therefore test culture through evidence: how leaders behave, which matters reach oversight bodies, how complaints are investigated, whether decisions are documented, and whether consequences apply consistently regardless of seniority.

Primary sources and further reading

Jurisdiction: United States
Source period: 2020-September 2026
Last reviewed: 22 September 2026

Professional-use note: This article is provided for educational and professional discussion. It does not make findings concerning individual legal liability and should not be treated as legal or employment advice.

Free tools

Use an FGL calculator

Open the calculator directly instead of navigating through a separate tools page.

Continue with FGL

Practical resources
Discussion

Questions, corrections or another perspective?

Join the conversation below. Keep comments constructive, relevant and free of confidential information.

Popular posts from this blog

Ernst & Young v URA: VAT on Imported Services and the UGX 3.48 Billion Assessment

Jurisdiction: Uganda · Decision: Commercial Court, Civil Appeal No. 26 of 2022 · Judgment date: 11 June 2026 · FGL review: September 2026 Uganda's Commercial Court has upheld a VAT assessment of UGX 3,482,492,210 against Ernst & Young Uganda in a dispute over services received from non-resident group entities and other foreign service providers. The decision is important because it gives businesses a current judicial example of how Uganda's imported-services VAT rules can apply to cross-border support, technology and professional-service arrangements. What the case was about In Ernst and Young v Uganda Revenue Authority , Civil Appeal No. 26 of 2022, the dispute concerned services obtained from entities outside Uganda, including members of the wider EY network and third-party foreign suppliers. URA treated the services as imported services and assessed VAT for the period January 2014 to June 2018. EY challenged the treatment, including arguments about where the s...

Stanbic-URA Transfer-Pricing Dispute: What Finance Teams Should Learn While the Case Is Pending

Jurisdiction: Uganda · Topic: Transfer pricing and tax dispute management · Status: Pending before the Tax Appeals Tribunal at the time of this FGL review · FGL review: 21 September 2026 Stanbic Bank Uganda Limited and Stanbic Uganda Holdings Limited are contesting a major transfer-pricing assessment by the Uganda Revenue Authority (URA). Public reporting places the working dispute figure at approximately UGX 117.8 billion , and the Tax Appeals Tribunal listed TAT Application No. 170 of 2025 for conferencing in June 2026. This article does not attempt to decide who is right. The dispute is still being litigated. Instead, it uses the publicly available record to explain what finance teams can learn about related-party charges, evidence, tax governance and the management of unresolved assessments. What the dispute is about The dispute arises from URA's review of related-party transactions involving Stanbic's Ugandan operations and entities within the wider...

Reconciling ERP Sales, EFRIS, VAT and Income Tax Returns: A Practical Guide

Scope: Uganda · Topic: Revenue reconciliation across ERP, EFRIS, VAT and income tax · FGL review: September 2026 Sales should be explainable across every system a business uses, but they will not always be numerically identical. An ERP may record invoices and journals, EFRIS records fiscal documents, VAT follows statutory supply rules, financial statements apply accounting standards, and the income-tax return applies tax rules to annual business income. The control objective is therefore not to force all four numbers to match. It is to build a documented bridge that explains why they differ, whether each difference is valid, and what evidence supports it. Why the numbers can legitimately differ A difference can arise from timing, classification, system configuration or tax treatment. Common examples include advance billings, deferred income, unbilled revenue, credit notes, exempt or zero-rated supplies, manual journals, foreign-currency treatment, customer-contra...