MIT Golub Center for Finance and Policy

Beyond Capital: A Trust- and Culture-Based Regulatory Framework for the Next Banking Crisis

Pier Augusto (Piero) Novelli MIT GCFP - Briefs and Blogs

The abrupt demise of Credit Suisse shows that capital and liquidity buffers alone can't salvage an institution that has exhausted the market's reservoir of trust.

The global financial crisis (GFC) produced the most comprehensive rebuild of bank regulation in modern history. The Basel III framework raised capital quality and quantity, introduced liquidity coverage and stable funding ratios, and layered systemic surcharges on the world's largest banks. By every formal metric, the post-2008 banking system was safer than the one that failed.

Fifteen years later, Credit Suisse—a globally systemically important bank, compliant with Basel III capital and liquidity requirements days before its collapse—ceased to exist as an independent institution in a matter of hours. It was not undercapitalized. It was not, on paper, illiquid. It was untrusted. Its failure, and Silicon Valley Bank's failure days earlier, exposed a gap in the regulatory paradigm: Capital and liquidity buffers are set on the assumption that confidence erodes slowly enough for them to matter. But in a digital, socially networked banking system, that assumption no longer holds.

This article proposes a future regulatory framework that treats trust—and the corporate culture that either sustains or erodes it—as a governable variable in its own right, alongside capital and liquidity.

The Missing Trust Dimension

Post-GFC regulation was built to answer one question: Does the bank have enough capital and liquidity to survive a stress scenario? That question remains necessary but is no longer sufficient. It implicitly assumes a bank's formal metrics will visibly deteriorate before its market and client relationships do.

Credit Suisse inverted that assumption. Its liquidity coverage ratio stood comfortably above the regulatory minimum ten weeks before its failure, and its capital ratios were compliant. What had already deteriorated, largely invisibly to formal supervision, was the market's and clients' belief that the institution remained a going concern worth staying with. Trust functioned as an invisible buffer sitting above the regulatory one—and by the time it was exhausted, the formal compliance with ratios could no longer safeguard confidence in the bank.

A future framework must treat trust erosion as a distinct category of risk to be identified before it becomes a liquidity event, not merely as a downstream consequence to be managed once it appears.

Trust Erodes Long Before Capital or Liquidity Ratios Show It

Trust is not lost in a weekend; it is depleted over years by events that each look survivable in isolation. Credit Suisse's chronology illustrates the pattern, marked by a decentralization strategy that weakened its global risk oversight from 2015, the Archegos and Greensill control failures of 2021, high turnover in senior leadership and control functions, a boardroom surveillance scandal, and a 2022 restructuring plan the market judged wholly inadequate. No single event breached a regulatory threshold; collectively, they exhausted the market's benefit of the doubt.

This is the central diagnostic failure of a purely capital- and liquidity-focused regime: It measures the wrong variable at the wrong time. By the time outflows show up in liquidity metrics, the trust those metrics proxy for has often already been spent. A future framework needs not only lagging indicators of stress but also leading indicators of confidence—treating repeated "manageable" conduct failures as cumulative depletions of a finite resource, not isolated incidents.

Related Articles

After SVB, what’s next for regional banks? 3 takeaways from MIT Sloan
Who will regulate crypto and fintech in the US?

Trust in the Digital Era

Two structural shifts have compressed to near zero the timespan between a loss of confidence once trust buffers have been fully eroded and a liquidity event: the advent of social media, which can turn a rumor into a coordinated narrative within hours, and the penetration of mobile banking, which lets a depositor act on such a rumor instantly and at scale. Credit Suisse and SVB were both first-generation digital-speed bank runs—deposit flight that outran the assumptions embedded in Basel III's thirty-day liquidity survival horizon.

The practical implication is severe: Regulation premised on buying an institution time to communicate, recapitalize, or find a buyer is fighting the last war. In Credit Suisse's final week, a CHF 50 billion emergency liquidity facility was exhausted within roughly three days. The only intervention that actually stopped the run was the takeover by UBS—an institution the market already trusted, absorbing one it no longer did. Time-based tools did not restore confidence; a credible new counterparty did.

Corporate Culture as the Foundation for Conduct and Trust

If trust is the resource that determines survival, corporate culture is the mechanism that builds or depletes it, decision by decision. Culture is not a values statement on a website; it is the accumulated pattern of choices employees and executives make not only in cases where no rule specifically applies but also about which rules and process to adopt, which risks to take, and how to report a near miss—along with how leadership responds to such reports.

Credit Suisse's history illustrates both the strength and danger of this dynamic. Its entrepreneurial, highly risk-tolerant profile dating to 1856 was a genuine source of value creation for over a century, but post-2015 the bank's governance evolved unchecked into a decentralized structure that no longer had the central capacity to contain risk. Archegos, Greensill, and a surveillance scandal targeting a departing executive were individually explainable but collectively corrosive to the trust of clients, employees, and regulators alike—each signaling that conduct was governed by a decentralized structure in which no single center of gravity was accountable.

A future framework needs to recognize culture as a core element of banking stability, positioned as the foundation beneath every other pillar:

  • Toward shareholders, culture governs whether capital allocation decisions favor long-term franchise value or short-term revenue capture.
  • Toward clients and counterparties, culture governs whether risk limits and escalation channels are treated as binding or negotiable.
  • Toward employees, culture governs whether internal dissent can be raised without retaliation—the surveillance scandal was as much a cultural signal as a compliance failure.
  • Toward regulators, culture governs whether the relationship is a genuine partnership or a perimeter to be tested.
  • Toward broader society, culture governs whether an institution internalizes the systemic consequences of its own failure or treats itself as insulated until it's too late.

Because trust compounds over years, culture cannot be supervised through point-in-time checks—it requires continuous monitoring of turnover and conduct-incident patterns, with boards prioritizing cultural drift as a standing agenda item rather than in response to crises.

A Framework for Measuring and Governing Trust

Trust and culture are harder to quantify than capital ratios, but "hard to measure" isn't "unmeasurable." A future framework should track deposit and asset flow trends independent of headline liquidity ratios; credit default swap (CDS) spreads and price-to-tangible book trends as forward-looking confidence proxies; senior management and control function turnover—measured explicitly as a key risk taker turnover (KRT) key performance indicator (KPI) across the first line (risk-originating business units), second line (risk and compliance), and third line (internal audit); the frequency of conduct incidents; litigation and supervisory findings; and the gap between announced targets and delivered execution.

The objective of these indicators isn't to replace capital and liquidity regulation but to give boards, management, and supervisors an early warning system for franchise credibility. This requires governance changes as much as measurement: Capital should go to businesses that reinforce strategic identity and control discipline, not opportunistic activity; compensation should reward long-horizon execution over short-term returns achieved by drawing down trust; and boards should treat frequent strategic pivots and turnover of key personnel as risk signals requiring explicit review.

Implications for Management, Boards, and Regulators—and the Threats Ahead

Capital and liquidity buffers remain necessary; no credible framework should weaken them. But Credit Suisse demonstrated that a bank can be adequately capitalized and still fail, because capital was never the variable that determined its survival—trust was, and culture was what had quietly eroded it for years.

For management and boards, trust and culture must become board-level risk topics, reviewed with the same rigor as capital and liquidity, with clear ownership for monitoring leading indicators. For regulators, trust cannot be directly regulated, but the conditions that support it can be—through robust public backstops, consistent enforcement without case-by-case concessions, transparent disclosure, and strong recovery planning. A competitive regulatory environment can be more conducive to financial stability than higher capital and liquidity requirements, which, at best, buy only a little extra time.

This framework must also give an eye to the threats that will define the next crisis:

  • AI-accelerated misinformation and deepfakes, capable of manufacturing a solvency rumor faster and more credibly than the organic dynamics that damaged Credit Suisse.
  • Cyber risk and operational resilience, where an infrastructure attack could trigger a confidence collapse with no underlying capital problem at all.
  • Nonbank financial intermediation and shadow banking, where contagion increasingly originates outside the bank regulation perimeter, as Archegos demonstrated.
  • Stablecoins and crypto-linked contagion, which create faster channels for depositor flight than existed in 2023.
  • Geopolitical fragmentation, which can suddenly convert an anchor-investor relationship into a source of instability, as it did with Credit Suisse's largest shareholder.

A regulatory framework built only for the GFC's threat—insufficient capital against credit and market losses—will remain necessary but permanently insufficient. The next Credit Suisse–style failure is unlikely to begin with a breached ratio. It is far likelier to begin, as this one did, with a slow, cumulative loss of trust—rooted in a culture that no longer reliably governed the institution's conduct toward its stakeholders—that capital and liquidity regulation was never designed to see coming and higher buffers are ill suited to prevent. 

  • Authors’ Disclosures: The authors report no conflicts of interest. 
  • The views expressed in this article are those of the authors and do not necessarily reflect the views of the MIT Golub Center for Finance and Policy, MIT Sloan, or the Massachusetts Institute of Technology.

About the Author

Pier Augusto (Piero) Novelli

Pier Augusto (Piero) Novelli

Senior Lecturer, Finance, MIT Sloan

Piero Novelli chairs Euronext NV's Supervisory Board (appointed 2021, reappointed 2025 for a second four-year term). Previously Co-President of UBS's Investment Bank and a UBS Group Executive Board member (2018–2021), he earlier led UBS's Global M&A and held senior roles at Nomura and Merrill Lynch across a 27-year investment banking career, having led many large and complex M&A transactions across all sectors and geographies. He is a lecturer at MIT Sloan and Imperial College London.

Read more
MIT Dome

Insights on finance and policy, from MIT.

Subscribe to our newsletter

For more info Simone Cavallaro Executive Director, MIT Golub Center for Finance & Policy (617) 258-8052