- Learn
- Align
- Perform
- Review
Perform7 min read
The Warning Was Reported. No One Owned It.
By J Damien Scott, Trusted Advisor
Financial institutions already know how to govern a risk they cannot predict. Most have not pointed that machinery at people. Detection is rarely the failure point. Routing is. And routing is a design problem, which means it is ours to fix.
The Low Base Rate Is the Trap, Not the Reassurance
In most workplace violence cases that end badly, someone saw it coming. The question worth asking is not why nobody noticed. It is why the notice did not go anywhere. The research on this is not ambiguous. In its study of mass attacks in public spaces, the U.S. Secret Service National Threat Assessment Center found that 65 percent of attackers had displayed behavior that elicited concern in other people, and that in 57 percent of those cases the behavior caused the observer to fear for someone’s safety (NTAC, 2023). People noticed. They were troubled by what they noticed. The system around them did not convert that concern into a decision.
Banks and other financial institutions occupy an unusual position here. Finance and insurance consistently reports among the lowest recordable injury and illness rates of any private industry sector, well below the 2.3 cases per 100 full-time workers recorded across private industry in 2024 (Bureau of Labor Statistics, 2025). Most executives read that as reassurance. I read it as a warning. Rare events do not build reflexes. A branch manager who encounters one genuinely alarming report in a fifteen-year career has no practiced answer, no muscle memory, and no colleague down the hall who handled a similar one last quarter.
The low rate also conceals something the injury statistics were never built to capture. Financial institutions generate grievance as a byproduct of ordinary, lawful operations: collections activity, foreclosure, account closures and de-risking exits that a customer experiences as an accusation, fraud investigations that name a person, terminations conducted in a high-compensation environment where the loss is large, sudden, and visible to peers. None of that shows up as a recordable injury. All of it is the raw material of a targeted grievance, and the sector produces it at scale.
“Detection is rarely the failure point. Routing is. And routing is a design problem, which means it is ours to fix.”
Why the Report Stalls
Here is the pattern that repeats across organizations of very different sizes. A supervisor hears something troubling. She does the right thing and reports it. Human Resources receives it and reads it as a personnel matter, because that is what Human Resources is built to read. Legal receives it and reads it as exposure, because that is the lens Legal is paid to apply. Security receives it and reads it as a request for additional coverage, because that is the tool Security has closest to hand.
Every one of those readings is defensible inside its own remit. Collectively they produce nothing. Three plausible owners is functionally identical to no owner, and the case drifts until it either resolves on its own or does not. The second cost is worse than the first. The supervisor learns that reporting went nowhere. That lesson is durable, it spreads informally, and it is far harder to undo than it was to cause.
Behavioral threat assessment is the structured evaluation of concerning behavior in context. It is not profiling. It is not prediction. It is not a disciplinary action taken in advance. It is a process for deciding what a concern actually warrants, and for putting that reasoning on the record.
Banks Already Own the Machinery
This is the part that should encourage anyone building such a program inside a financial institution: you are not importing a foreign discipline. You are extending one the institution already runs with real rigor. Consider what happens when a suspicious transaction surfaces. Nobody convenes a meeting to debate who owns it. There is a defined intake channel, a triage standard, an escalation path with documented timelines, a retention requirement, and a named accountable person. The second line challenges the quality of the judgment. The third line provides independent assurance that the framework works as designed.
Examiners expect clearly documented processes, timelines, and accountability for identifying, reporting, investigating, and escalating incidents, and they will say so plainly when those are absent (FFIEC; OCC, 2019). That is precisely the governance a threat management program requires. Financial institutions have simply never pointed it at a person. They have pointed it at transactions, vendors, models, and systems, and left concerning human behavior to be handled by whoever happened to hear about it first.
Four Things to Build This Quarter
One intake channel, not three. If an employee has to decide whether a concern belongs to Human Resources, Security, or their manager, the program has already outsourced its hardest judgment call to the least equipped person in the chain.
A standing team with a named decision owner. The ASIS International workplace violence prevention and intervention standard centers on a Threat Management Team responsible for receiving, triaging, investigating, and resolving reports of concerning behavior through a documented process (ASIS International, n.d.). Standing matters more than the roster. A team assembled after a report arrives is a meeting, not a capability.
A structured framework instead of instinct. Meloy and colleagues identified eight warning behaviors that evidence accelerating risk: pathway, fixation, identification, novel aggression, energy burst, leakage, directly communicated threat, and last resort. Subsequent research has found pathway, identification, and last resort to be the strongest discriminators between attackers and non-attackers (Meloy et al., 2012). A shared vocabulary raises the quality of the assessment and produces a file whose reasoning a regulator, a court, or a successor can follow.
Resolution that means managed, not closed. Administrative closure is an accounting act. It tells you the case left the queue. It tells you nothing about the person.
Measure the Outcome, Not the Intake
Most programs report reports received and cases opened. Those numbers describe the intake, not the program. Three measures tell you considerably more: how long from report to first assessment; what proportion of cases carry a documented decision owner; what proportion resolve with an active monitoring plan rather than a closure note.
One warning for whoever presents these to a risk committee: a functioning program raises reporting volume, often sharply, because people start believing that reports go somewhere. Say this out loud before it happens. Otherwise the first genuinely healthy quarter will be read as a deteriorating one.
There is one more pattern specific to this sector. The person of concern is sometimes also the subject of a fraud, conduct, or insider investigation. Two teams then hold two partial views of the same individual, on two timelines, under two case numbers, and neither is looking at the whole person. If threat management and corporate investigations do not share a case view, the institution is managing half of someone. The seam between those two functions is where the most consequential cases will fall, and it is worth closing before the next one arrives.
Originally published on LinkedIn. Read it there
Field Notes · by email
One email when a new article publishes. Nothing else.
Field notes on converged security from J Damien Scott, Trusted Advisor: the article, its summary, and the phase it belongs to. No digests, no offers, no third party reading over your shoulder.
Email delivery is being set up. The feed carries every article the day it publishes. About Field Notes
Related reading
More from Perform
Perform · 27 July 2026
The Badge Swipe and the Log Entry Belong to the Same Investigation
A badge log and a data loss alert can describe the same person on the same afternoon and still end up in two different case files. Convergence gets endorsed in a mission statement and then quietly reverts to two departments that report through different chains, hold different budgets, and keep different records.
7 min readPerform · 8 May 2026
From Veteran to Project Manager: Why Military Leadership Fits the Business Sector
When examining the leadership principles learned through military service, the alignment with project management discipline is unmistakable. This article demonstrates how Marine Corps leadership principles directly strengthen the functional responsibilities of project management as defined by the PMBOK Guide and GAO best practices.
15 min readPerform · April 2026
Article 2 — Aerial Advance Work: Using Drones for Route Reconnaissance, Venue Assessment, and Movement Overwatch
Aerial advance work is not a replacement for ground-level advance work. It is a complement that addresses the specific limitations of ground-based reconnaissance: the inability to see over obstacles, the time required to physically check extended routes, and the difficulty of maintaining continuous situational awareness during a movement.
9 min read