JPMorgan Chase
The most regulated company on Earth. Every control in a global systemically important bank is examined by multiple regulators, and JPMorgan runs the largest, most disciplined GRC machine in the industry in response.
Overview
JPMorgan Chase is the largest bank in the United States (~$4.4 trillion in assets) and among the most intensely supervised financial institutions in history. It answers to the Federal Reserve, OCC, CFPB, SEC, FINRA, FDIC, and, in Europe, the ECB and national regulators, across dozens of jurisdictions. Its GRC program is less a department than a second operating system: risk and compliance are embedded in every business line, with dedicated risk committees at the board level and tens of thousands of risk and compliance professionals.
What makes JPMorgan the definitive financial-GRC case study is scale under supervision: it survived the 2008 crisis, absorbed the London Whale episode, and then built the gold-standard response, a control environment so dense that regulators now benchmark the industry against it.
Compliance posture at a glance
| Framework | Status | Notes |
|---|---|---|
| SOX 404 | Audited | ICFR attestation across the group; among the largest SOX scopes in the world. |
| Basel III / CCAR | Supervised | Capital and liquidity stress testing under Fed CCAR annually. |
| GLBA / Reg S-P | Covered | Consumer financial data protection, US privacy framework. |
| GDPR / DORA | Covered | EU entities under GDPR; DORA digital-operational-resilience duties from Jan 2025. |
| PCI DSS | Level 1 | Cardholder data environments; annual ROC. |
| Model Risk Mgmt | SR 11-7 | OCC/Fed guidance on model risk, JPMorgan operates the reference implementation. |
| NIST CSF | Mapped | Cybersecurity program aligned to NIST CSF and FFIEC CAT. |
NIST CSF 2.0 maturity assessment
Overall: 4.5 / 5, the highest in this portfolio. Unusual for this series, every function scores at the same level, because regulators force balance: a bank cannot pass CCAR with a strong Protect function and a weak Recover one.
Key findings
1. Governance density as a business requirement
JPMorgan runs one of the largest controls organizations in banking, risk and compliance functions number in the tens of thousands of professionals, and spends heavily on risk technology (roughly $17B in annual technology spend, with risk and compliance among its largest platforms). The board's risk committee, firmwide risk-appetite statements, and line-of-business CROs create a governance lattice regulators can audit end-to-end.
2. Model risk management as the reference standard
Under SR 11-7, JPMorgan's model risk governance, independent validation, inventory, and board reporting of every material model, is the template the Fed implicitly uses when examining other banks. With AI now entering the model inventory, this discipline is directly extending into AI governance.
3. Cybersecurity treated as financial risk
JPMorgan's technology budget is roughly $17B annually (2025), with cybersecurity treated as risk capital rather than IT spend, the CEO publicly cited ~$600M/yr for cyber specifically as far back as 2015, before the program scaled. Cyber risk is quantified, stress-tested, and reported like credit risk, among the purest examples in this portfolio of security governed through a risk-appetite lens.
Watch items
AI governance at full-bank scale
JPMorgan is deploying AI (including its internal LLM Suite assistant, onboarded to 200,000+ users, and AI-powered coding and research tools) across a ~300,000-person bank. Every model is a model-risk item; every AI output is a potential supervisory finding. Watch whether AI governance stays inside the SR 11-7 envelope or breaks it.
DORA and third-party concentration
From January 2025, DORA obliges EU financial entities to register and manage ICT third-party risk, including cloud providers. JPMorgan's reliance on hyperscalers makes its TPRM program a live compliance experiment at the largest possible scale.
Regulatory finding history
Even the reference standard is not immune: the London Whale episode (2012) and subsequent enforcement actions remain the canonical warning that in a bank this complex, governance density and actual control effectiveness can diverge under pressure.
Bottom line
JPMorgan is the reference implementation of financial GRC. Its program demonstrates what governance looks like when regulators can examine every decision, and why the industry's most mature risk culture is also its most expensive. For anyone building enterprise GRC, this is the model to study.
Sources & verification
Every factual claim above was verified against the following public sources (accessed August 2026). Figures updated to the latest fiscal year reported.
Verification note: JPMorgan is the largest US bank by assets; the world's largest by assets is ICBC (China), the page has been corrected accordingly. Assets, revenue, SOX/Basel references verified against the FY2025 10-K. SR 11-7 and CCAR verified against Federal Reserve pages; DORA effective date (17 January 2025) verified against EUR-Lex/ESMA. "~20% of workforce in controls" was unverifiable and has been replaced with the documented tens-of-thousands figure. No public $1B+ cyber-budget figure exists, the page now cites the ~$17B tech budget (2025) and the CEO's ~$600M cyber figure (2015). LLM Suite user count (200,000+) sourced from JPMorgan's own blog. JPM's PCI DSS status as an acquirer is not publicly itemized; the table reflects industry-standard card environment compliance.