It started with applause. In April 2023, the board of a mid-sized Ugandan financial institution (let us call it Eagle Finance Ltd) received a glowing report: “Full compliance achieved with Bank of Uganda risk management guidelines.” The Chief Risk Officer beamed with pride. The Head of Audit nodded. The board chair commended management for “maturity and diligence.”

Two months later, Eagle Finance was in crisis. UGX 3.2 billion had vanished through an internal loan manipulation scheme. The same system that boasted full compliance had been quietly exploited by its own employees.

The anatomy of a silent collapse, Summit Consulting Ltd was called in to investigate. At first glance, everything looked perfect: risk manuals in place, audit charters approved, policies reviewed annually. But beneath the surface was a different story. A culture of tick-the-box management, where compliance reports replaced critical thinking.

Suspect 1, the Head of Credit, had perfected the art of “policy-driven fraud.” He never violated the letter of the policy, only its spirit. Every loan passed due diligence. Every approval had signatures. Every report was reconciled. But each document was crafted to deceive a system that trusted paperwork more than people.

Suspect 2, a branch manager in Mbarara, used her staff’s credentials after hours to originate phantom group loans. The accounts existed only on paper, funded through manipulated internal transfers. The disbursed cash would be withdrawn via mobile money agents, split across four lines registered in relatives’ names.

It worked flawlessly for two years. The fraud was only detected when a new IT officer curious and quietly risk-aware, noticed an anomaly. Loan accounts were created after 8:00 PM every Friday. “It must be system latency,” said the credit department. But his instinct said otherwise. He flagged it to internal audit. That alert led to one of the most complex investigations Summit Consulting had handled that year.

The risk reports had said it all. As Summit’s forensic team dug deeper, one finding stood out, the same pattern had appeared in three consecutive quarterly risk reports.

Each time, the note was there. “High frequency of after-hours data entries, investigation recommended.” Yet, no action was taken. Why? Because the internal audit team feared being “disruptive.” The CRO was a board favourite.

The audit findings were softened in tone before board submission. The board, satisfied that no “major” issues existed, moved on to the next agenda item, a new branch opening. This is how compliance culture kills organisations. Every person did their job. No one did the right thing.

The compliance trap

Ugandan institutions have mastered compliance theatre, a performance where forms are filled, trainings are signed, and risk dashboards glow green. But real risk management is not about green dashboards. It is about grey thinking, the uncomfortable space where questions challenge authority.

Eagle Finance had policies, committees, and reporting templates. What it lacked was risk intelligence; the ability to sense, interpret, and act on weak signals before they explode.

Summit’s team discovered that the mobile money fraud had multiple enablers.

  1. Passwords were shared casually among staff to “beat system slowness.”
  2. Branch overrides were approved verbally during power outages.
  3. Suspicious transaction alerts marked “resolved” without follow-up.
  4. All within policy. All auditable. All fraudulent.

How the board failed; politely

The board’s Risk Committee received quarterly updates, thick with charts and ratios. But not once did they ask: “What are we not seeing in this report?”

That question alone could have saved billions. Instead, the board measured success by the absence of regulatory penalties. As long as the Bank of Uganda had not issued a notice, everything was “okay.”

But regulatory comfort is not organisational safety. By the time the fraud surfaced, whistleblowers were terrified, the credit department was in disarray, and the CEO was defending “a few isolated lapses.” The losses exceeded UGX 3 billion, but the reputational damage was far worse. Several clients withdrew deposits. Staff morale plummeted.

Summit’s forensic reconstruction. Summit Consulting’s investigators rebuilt the trail, transaction by transaction.

Mobile money logs were pulled. Metadata revealed identical device fingerprints across multiple user accounts. Forensic imaging of suspect laptops exposed hidden Excel files with coded allocations: “A1” meant UGX 50m. “B2” meant UGX 20m. Each is linked to a loan batch ID.

It was not genius. It was negligence dressed as compliance. Summit’s final report to the board was brutal. “The fraud was not a failure of systems. It was a failure of culture.” Lessons for Uganda’s boardrooms

Compliance is reactive; intelligence is predictive. Compliance ensures you meet minimum standards. Risk intelligence ensures you see tomorrow’s threats today. Policies do not protect; people do.

The most effective control is a vigilant culture. When staff fear speaking up, your policies are merely wallpaper.

The board must ask better questions.

Do not ask, “Are we compliant?” Ask, “What keeps you awake at night?” Do not ask, “Did we close all audits?” Ask, “What did we learn from near misses?”

Reward foresight, not firefighting. In risk-intelligent cultures, the person who spots a risk early is celebrated, not sidelined.

Invest in digital visibility. Most frauds hide in fragmented systems. Integrate data analytics, automated red-flag detection, and independent risk dashboards.

The recovery. With Summit’s guidance, Eagle Finance rebuilt its risk culture. The new CRO restructured the function of risk officers embedded in operations, not isolated in offices. The board received a Risk Intelligence Dashboard showing early-warning metrics, not just compliance scores.

Every employee underwent “Speak up without Fear” training. Internal audit was rebranded from policing to insight generation. The board adopted a risk appetite framework linking financial exposure to strategic goals; moving from “risk avoidance” to “risk mastery.”

Within 12 months, the institution regained stability. But the scars remain, a painful reminder that risk management without intelligence is like a seatbelt worn after the crash.

In Uganda’s evolving corporate landscape, the next frontier is not compliance; it is consciousness.

Your policies may please the regulator, but your culture decides your survival. The question every board must now ask: “Are we merely compliant, or are we truly risk intelligent?”

Because compliance protects you from the past. But risk intelligence prepares you for the future.

Tone at the top: How leadership shapes organisational risk culture

In 2023, a financial institution lost a lot of money through a single “relationship manager” who approved fraudulent overdrafts over two years. Every audit flagged the weak controls, every quarterly report mentioned it, but nobody acted. When asked why, one senior executive said, “We did not want to embarrass the branch manager. He was close to a board member.”

That sentence explains more about the bank’s risk culture than any policy, framework, or risk appetite statement ever could. Because tone at the top is not what leaders say. It is what they tolerate. Risk culture begins in silence, not in strategy documents

Every organisation has two cultures

  1. The one printed on banners and PowerPoint slides.
  2. The one people live when no one is watching.

The latter is what determines your risk exposure. If the board tolerates missed deadlines, ignored controls, and unchallenged decisions, that becomes the tone at the top. It trickles down through silence, not speech.

At one manufacturing firm, Summit Consulting investigated, staff joked that “controls are for interns.” Why? Because senior management routinely bypassed procurement policies “to move faster.” Within 18 months, that “speed” created a UGX 3.2 billion loss in fake supplier payments.

Leadership had unknowingly trained employees to believe that risk management was optional.

How leaders signal risk appetite

The real risk culture of any organisation is set in three ways, all subconscious:

  1. What leaders reward? If only revenue targets are rewarded, expect corners to be cut.
  2. What leaders ignore, A single unaddressed policy breach does more damage than 100 emails on ethics.
  3. What leaders rationalise, “He meant well,” “we’ll handle it internally,” “this time it’s different”; are all cultural permissions for risk escalation.

At Summit Consulting, when assessing Risk Culture Index (RCI) across local institutions, one metric predicts all others, whether the CEO publicly acts on audit findings or “delegates them quietly.” Leaders who act visibly create a ripple of seriousness across the enterprise.

Leadership and hypocrisy are the silent destroyers

When senior management drives in with unlogged fuel cards, manipulates per diem claims, or bypasses procurement for “trusted vendors,” every staff member learns that controls are flexible for the powerful.

No amount of training can undo that damage. Employees do not mimic policies; they mimic leaders. When a CEO overrules a compliance decision, even for a good reason, the message received is not “strategic urgency.” It is “risk discipline is negotiable.”

The paradox of tone: risk aversion vs risk intelligence

Weak boards confuse risk management with risk avoidance. They prefer “no news” over “bad news.” But that mindset kills innovation.

A mature tone at the top does not suppress risk; it defines it. Smart leaders create an environment where

  1. Reporting risk is rewarded, not punished.
  2. Mistakes are dissected, not hidden.
  3. Decisions are documented, not whispered.

In short, a culture of psychological safety drives better governance than fear of compliance.

The red flags of toxic risk culture

When Summit Consulting conducts fraud or cyber investigations, five patterns keep repeating:

  1. Fear of speaking up, “I saw it but couldn’t report; the person involved is powerful.”
  2. Hero culture, one or two “untouchables” handle everything, unchecked.
  3. Tick-box compliance, Risk reports full of activity, not accountability.
  4. Audit fatigue, Management responses copy-pasted year after year.

Moral rationalisation: “Everyone benefits, so it is not theft.”

These are not control weaknesses; they are cultural weaknesses.

Our Summit Consulting model: Measuring tone at the top

We use a four-dimensional assessment, the RACE Model, to evaluate how leadership drives or destroys risk culture:

Dimension Description Observable Evidence
R, Role modelling Do executives live the values or merely recite them? CEO adherence to policies, expense approvals, and ethical examples.
A, Accountability Are breaches addressed at the top level? Evidence of sanctions, board actions, and audit follow-ups.
C, Communication How is risk discussed internally? Leadership language in town halls, circulars, and minutes.
E, Engagement Do staff feel safe reporting issues? Whistleblowing trends, survey results, and turnover data.

Institutions with weak Role Modelling and Accountability almost always experience fraud escalation within 18 - 24 months.

Leadership sets the boundaries of loss

In one parastatal, a well-meaning MD often signed cheques “in good faith” for community donations that never reached beneficiaries. Over time, staff realised they could channel “phantom outreach” projects through shell NGOs. Loss: UGX 1.9 billion.

No policy change. The tone did. Because leadership kindness, without control, becomes a fraud magnet.

Building a strong tone at the top: Five irreversible habits

  1. Walk the policy. No exceptions. The CEO must follow the same travel and procurement rules as staff.
  2. Public accountability. When a senior person breaches controls, act visibly. Discipline loses its deterrent power when it hides behind HR doors.
  3. Risk appetite ownership. Boards must define in numbers what they can lose and what they cannot. “We are risk-averse” means nothing without metrics.
  4. Embed consequence management. Tie KPIs and bonuses to risk behaviour, not just performance.
  5. Set a feedback loop. Measure risk culture quarterly, use heatmaps to show where tone is deteriorating.

A cultural warning to boards. Many boards assume that having a risk policy is equal to having a risk culture. It does not. Policies define rules, culture defines reflexes. A company’s real risk culture is revealed when pressure mounts, when targets are missed, funding is delayed, or audits bite. That’s when the “tone at the top” is either tested or exposed.

Summit Consulting’s 2025 survey across 60 organisations as part of the iShield 360 project frontline revealed a striking pattern. 68% of major frauds began with ignored red flags.

Not because systems failed, but because leaders looked away. When we reconstructed one internal fraud worth UGX 4.7 billion in a government agency, the first red flag appeared 15 months earlier, a whistleblower email marked “confidential.” It was forwarded, unread, to the person being reported.

Tone at the top is not only about what leaders say, it is about what they protect. Final verdict. The board owns the tone. If leadership is weak, no control system can save the organisation. If leadership is strong, even imperfect systems survive crises.

Boards must ask:

  1. Are we rewarding honesty or results?
  2. Are we hearing the truth or what’s convenient?
  3. Are we building compliance out of fear or conviction?

Because every fraud, every cyber breach, every regulatory scandal starts as a tone problem, not a control problem.

As the locals say, “when the chief holds a child by the hand, others follow.” That is the essence of tone at the top. Risk culture does not begin in the risk department. It begins in the mirror of the boardroom.