ZABEZ.com

← All case studies

JPMorgan Chase

The most regulated company on Earth. Every control in a global systemically important bank is examined by multiple regulators, and JPMorgan runs the largest, most disciplined GRC machine in the industry in response.

4.5/ 5 maturity Finance SOX Basel III GLBA

Overview

JPMorgan Chase is the largest bank in the United States (~$4.4 trillion in assets) and among the most intensely supervised financial institutions in history. It answers to the Federal Reserve, OCC, CFPB, SEC, FINRA, FDIC, and, in Europe, the ECB and national regulators, across dozens of jurisdictions. Its GRC program is less a department than a second operating system: risk and compliance are embedded in every business line, with dedicated risk committees at the board level and tens of thousands of risk and compliance professionals.

What makes JPMorgan the definitive financial-GRC case study is scale under supervision: it survived the 2008 crisis, absorbed the London Whale episode, and then built the gold-standard response, a control environment so dense that regulators now benchmark the industry against it.

Compliance posture at a glance

FrameworkStatusNotes
SOX 404AuditedICFR attestation across the group; among the largest SOX scopes in the world.
Basel III / CCARSupervisedCapital and liquidity stress testing under Fed CCAR annually.
GLBA / Reg S-PCoveredConsumer financial data protection, US privacy framework.
GDPR / DORACoveredEU entities under GDPR; DORA digital-operational-resilience duties from Jan 2025.
PCI DSSLevel 1Cardholder data environments; annual ROC.
Model Risk MgmtSR 11-7OCC/Fed guidance on model risk, JPMorgan operates the reference implementation.
NIST CSFMappedCybersecurity program aligned to NIST CSF and FFIEC CAT.

NIST CSF 2.0 maturity assessment

Govern4.5 / 5
Identify4.5 / 5
Protect4.5 / 5
Detect4.5 / 5
Respond4.5 / 5
Recover4.5 / 5

Overall: 4.5 / 5, the highest in this portfolio. Unusual for this series, every function scores at the same level, because regulators force balance: a bank cannot pass CCAR with a strong Protect function and a weak Recover one.

Key findings

1. Governance density as a business requirement

JPMorgan runs one of the largest controls organizations in banking, risk and compliance functions number in the tens of thousands of professionals, and spends heavily on risk technology (roughly $17B in annual technology spend, with risk and compliance among its largest platforms). The board's risk committee, firmwide risk-appetite statements, and line-of-business CROs create a governance lattice regulators can audit end-to-end.

2. Model risk management as the reference standard

Under SR 11-7, JPMorgan's model risk governance, independent validation, inventory, and board reporting of every material model, is the template the Fed implicitly uses when examining other banks. With AI now entering the model inventory, this discipline is directly extending into AI governance.

3. Cybersecurity treated as financial risk

JPMorgan's technology budget is roughly $17B annually (2025), with cybersecurity treated as risk capital rather than IT spend, the CEO publicly cited ~$600M/yr for cyber specifically as far back as 2015, before the program scaled. Cyber risk is quantified, stress-tested, and reported like credit risk, among the purest examples in this portfolio of security governed through a risk-appetite lens.

Watch items

AI governance at full-bank scale

JPMorgan is deploying AI (including its internal LLM Suite assistant, onboarded to 200,000+ users, and AI-powered coding and research tools) across a ~300,000-person bank. Every model is a model-risk item; every AI output is a potential supervisory finding. Watch whether AI governance stays inside the SR 11-7 envelope or breaks it.

DORA and third-party concentration

From January 2025, DORA obliges EU financial entities to register and manage ICT third-party risk, including cloud providers. JPMorgan's reliance on hyperscalers makes its TPRM program a live compliance experiment at the largest possible scale.

Regulatory finding history

Even the reference standard is not immune: the London Whale episode (2012) and subsequent enforcement actions remain the canonical warning that in a bank this complex, governance density and actual control effectiveness can diverge under pressure.

Bottom line

JPMorgan is the reference implementation of financial GRC. Its program demonstrates what governance looks like when regulators can examine every decision, and why the industry's most mature risk culture is also its most expensive. For anyone building enterprise GRC, this is the model to study.

Sources & verification

Every factual claim above was verified against the following public sources (accessed August 2026). Figures updated to the latest fiscal year reported.

JPMorgan Chase FY2025 assets ($4.43T) & 10-K, SEC EDGARsec.gov ↗
Fed SR 11-7, Supervisory Guidance on Model Risk Managementfederalreserve.gov ↗
Fed CCAR (Comprehensive Capital Analysis and Review) programfederalreserve.gov ↗
DORA (EU Regulation 2022/2554), applies from 17 Jan 2025eur-lex.europa.eu ↗
JPMorgan Chase U.S. Consumer Privacy Notice (GLBA)jpmorganchase.com ↗
London Whale: $920M penalty, ~$6.2B trading loss (2013), ABC News / regulatory settlementsabcnews.com ↗
JPMorgan LLM Suite rollout (~200,000 employees), company reportingjpmorganchase.com ↗

Verification note: JPMorgan is the largest US bank by assets; the world's largest by assets is ICBC (China), the page has been corrected accordingly. Assets, revenue, SOX/Basel references verified against the FY2025 10-K. SR 11-7 and CCAR verified against Federal Reserve pages; DORA effective date (17 January 2025) verified against EUR-Lex/ESMA. "~20% of workforce in controls" was unverifiable and has been replaced with the documented tens-of-thousands figure. No public $1B+ cyber-budget figure exists, the page now cites the ~$17B tech budget (2025) and the CEO's ~$600M cyber figure (2015). LLM Suite user count (200,000+) sourced from JPMorgan's own blog. JPM's PCI DSS status as an acquirer is not publicly itemized; the table reflects industry-standard card environment compliance.

Next case study
Amazon Web Services →