Summary
- Confirmed fact: The Consumer Financial Protection Bureau determined in 2016 that Wells Fargo employees opened unauthorized deposit accounts, applied for credit cards without consent, enrolled consumers in online banking they had not requested, and ordered or activated debit cards without authorization. The Office of the Comptroller of the Currency separately found unsafe or unsound sales practices and deficient enterprise risk management. Both were consent proceedings in which the bank did not admit or deny the agencies' findings, except for jurisdiction where specified.
- Confirmed fact: Wells Fargo's expanded third-party analysis later reviewed more than 165 million accounts opened from January 2009 through September 2016 and identified about 3.5 million potentially unauthorized consumer and small-business accounts, plus about 528,000 potentially unauthorized online bill-pay enrollments. "Potentially unauthorized" was an intentionally inclusive analytical category, not an adjudication that every flagged account lacked consent.
- Company-admitted fact: In a 2020 deferred prosecution agreement, Wells Fargo admitted a statement of facts describing improper sales practices from 2002 through 2016, unrealistic goals, management pressure, false records, misuse of customer identities, unearned fees and interest, and harm to some customers' credit ratings. That admission is legally different from the earlier consent orders and from later settlements entered without admissions.
- Supported inference: The immediate trigger was an employee opening or enrolling a product without valid customer authorization. The institutional root was that product volume and sales achievement could be credited before reliable consent, actual use and customer benefit were independently established, while adverse signals were divided among business management, investigations, human resources, complaints, risk, audit and regulators.
- Confirmed disposition: Wells Fargo removed retail product sales goals in 2016, changed leadership and compensation, expanded customer review and redress, and was subjected to company, regulatory, civil, securities and criminal resolutions. The OCC terminated its 2016 sales-practices order in 2024; the Federal Reserve removed the 2018 asset-growth restriction in 2025 and terminated the remaining 2018 action in March 2026 after required improvements and third-party reviews.
- Unresolved public question: Those terminations are substantial independent repair evidence. Public materials still do not expose the full current product-authorization rule set, override population, branch-level false-negative testing, complaint-to-control traceability, or a continuous measure showing that every credited retail product has durable, customer-verifiable consent.
The accountability unit was not the account; it was the operating model
An unauthorized account has an identifiable last action. Someone enters customer information, submits an application, creates credentials, moves money, issues a card or enrolls a service. That makes the nearest employee visible. It does not establish that the employee controlled the target, the incentive plan, the staffing level, the product-credit rule, the disciplinary environment, the consent design, the complaint taxonomy, the investigation threshold or the information presented to senior management and the board.
The distinction matters because Wells Fargo initially possessed many signals without assembling them into an institution-level conclusion. Customers complained. Employees used an ethics channel. Internal investigators substantiated misconduct and the company terminated people. Low-quality and unfunded accounts could be measured. Certain regions generated unusually high patterns. Managers challenged goals. External reporting described pressure. Regulators had ongoing access to supervisory material.
Yet the system repeatedly treated these observations as local conduct, human-resources or quality matters rather than evidence that the sales model itself could generate unlawful outcomes.
The CFPB's September 2016 consent order supplies a bounded regulatory finding. For the order's relevant period beginning in 2011, the Bureau determined that employees opened accounts and enrolled services without consumers' knowledge or consent. Wells Fargo's analysis had identified 1,534,280 deposit accounts that might not have been authorized and might have been funded through transfers from customers' existing accounts, as well as 565,443 credit-card applications that might not have been authorized. The order also recorded fee populations. Those figures were screening results, not a final count of proven violations account by account.
The OCC's companion consent order moved the analysis from transactions to governance. The agency found that incentives were not properly aligned with branch traffic, staff turnover or customer demand; the bank lacked an enterprise-wide sales-practices oversight program and a comprehensive customer-complaint monitoring process; Community Bank testing was inadequate; and audit did not cover sales practices with an enterprise-wide view. The bank neither admitted nor denied those findings.
Even with that legal qualification, the order defines the relevant control surface: incentives, complaints, business oversight, independent testing, audit and board-directed remediation.
The accountability unit is therefore the operating model that converted a product opening into sales credit and career consequence. An effective analysis must follow information and authority across that model. It must ask when signals became available, who could change the conditions producing them, which control owner could stop an account before activation, who could aggregate harm after activation, and what evidence was required before management declared the issue contained.
A forensic timeline of warnings, narrowing options and delayed system change
1998-2004: growth became a governing signal before misconduct became a governing risk
The most authoritative broad chronology is the statement of facts attached to Wells Fargo's 2020 agreement with the United States. The Department of Justice's resolution announcement says Wells Fargo admitted that it increased its focus on sales volume and annual sales growth beginning in 1998. The Community Bank grew into the company's largest operating segment and cross-selling became both a management practice and an investor-facing measure of success.
The same admitted chronology shows that the risk was not invisible until 2016. Sales gaming appeared in internal investigations well before the public enforcement event. An internal investigator characterized the problem as severe in 2004, and another warned in 2005 that it was worsening. Those descriptions matter as evidence of early organizational knowledge. They do not prove that every senior executive then knew every method or customer consequence. They do establish that unauthorized or manipulated sales were not a wholly novel anomaly discovered at the end of the period.
This was the widest counterfactual window. A bank seeing repeated misuse of identities, account manipulation or false funding could have required independently verifiable consent for every product, removed volume credit from inactive or rapidly closed accounts, aggregated investigations by manager and region, and tested whether goals exceeded realistic customer demand. The cost of intervention was lowest before sales performance, promotion and investor narratives became deeply tied to cross-sell growth.
2006-2010: ambitious goals and fragmented complaints created measurable exposure
The Community Bank's growth language was operationalized in the push toward eight products per household. The number itself was not an instruction to open an unauthorized account, and cross-selling is not inherently unlawful. The accountability problem was the combination of a high product target with daily performance pressure, incentive thresholds and insufficiently independent confirmation that each product reflected customer need and authorization.
The board's later Sales Practices Investigation Report filed with the SEC described a conflict between stated values and the Community Bank's emphasis on goals. According to that company-commissioned investigation, business leadership tolerated low-quality accounts as a by-product of a sales organization, resisted changing the model and found it more convenient to attribute misconduct to individual wrongdoers and poor field management. This is a formal board investigation with extensive interviews and document review, not a judicial judgment.
Its findings should be attributed to the independent directors and assessed alongside government records.
The OCC's own 2017 lessons-learned review shows that external supervision also had early information. The review identified an enterprise complaint-management matter requiring attention issued in 2010 and aggressive-sales concerns known to examiners. It found that planned incentive sampling was delayed or narrowed, complaint work was incomplete, and the enterprise complaint issue was later closed without full correction and rolled into broader tracking. This is not a bank defense. It is the regulator's documented recognition that supervisory opportunities were missed.
By this stage, the control problem was already dual. Wells Fargo had to identify and stop conduct generated inside its operating model. The OCC had to challenge whether the bank's controls were adequate. Neither responsibility cancels the other. A supervised institution remains responsible for lawful operations; a supervisor remains accountable for using risk signals and examination authority effectively.
2011-2013: complaints, terminations and low-quality accounts rose together
The independent directors' report found that allegations, terminations and resignations associated with sales integrity increased from 2007 and peaked in late 2013. It also linked harder goals with lower account quality. These were not perfect measures. A termination count can rise because misconduct rises, detection improves, policy changes or some combination of those factors. An unfunded account can be legitimate. A complaint may be mistaken. The governance obligation was to combine the indicators, test samples and determine whether a common mechanism explained them.
Instead, control evidence remained divided. Internal Investigations investigated people. Human Resources processed employment outcomes. Business managers tracked sales and account funding. Risk teams assessed programs. Complaints were not yet available through a sufficiently comprehensive enterprise process. Audit coverage did not produce an enterprise view of the same pattern. When signals are separated by owner and taxonomy, each can be discounted as a local exception even when their joint distribution indicates a system failure.
The OCC later reported that examiners knew of internal whistleblower and EthicsLine concerns but found no evidence of in-depth supervisory testing of sales-monitoring controls from 2011 through 2014. A 2013 examination planned to review cross-sell compliance, incentive structure and complaint transactions, but the work remained high level and did not test allegations. Staffing constraints were recorded. Those facts are important because they reveal a second layer of normalization: the bank's incomplete challenge environment met a supervisory process that also postponed decisive transaction testing.
Public reporting in 2013 made branch pressure and unauthorized practices harder to treat as an internal personnel matter. External journalism was a detection channel, but not the origin of the data. The bank already had internal cases, account behavior and employee signals. Public exposure changed the cost of inaction and sharpened attention; it did not create the underlying risk.
2014-2015: the issue reached boards and regulators without a complete risk picture
The independent directors' report says sales practices were first identified to Wells Fargo's board as a noteworthy risk in 2014. By early 2015, management reported that corrective actions were working. The same report later concluded that information provided to the board did not accurately convey scope and that Community Bank presentations were generalized or incomplete. That is a board-commissioned finding about the quality of escalation, not proof that every director possessed the omitted information.
This period illustrates the difference between reporting an issue and reporting a decision-grade risk. A board cannot supervise thousands of branch actions directly. It can require a stable set of indicators: unauthorized-account complaints, substantiated cases, employee terminations, funding and closure anomalies, customer fees, credit-bureau effects, geographic concentrations, manager recurrence, investigation coverage, goal attainment and control overrides. Without denominators, trends and unresolved exceptions, a presentation may mention misconduct while still implying that the model is sound.
The City of Los Angeles filed a civil complaint in May 2015. A complaint is an allegation, not an adjudicated finding. It was nevertheless a material escalation event because a public authority alleged that sales quotas and pressure were driving unauthorized accounts and customer harm. The CFPB and OCC investigations subsequently produced their own administrative findings rather than merely adopting the city's allegations.
The criminal accountability chronology later became more specific. In 2023, DOJ announced that former Community Bank head Carrie Tolstedt had agreed to plead guilty to obstructing a bank examination. According to the official plea announcement, the offense concerned a May 2015 memorandum prepared for the OCC that omitted termination and investigation-coverage information. The announcement says the proactive process investigated only a small fraction of activity flagged by the bank's red-flag method.
The later guilty plea and sentence concerned obstruction of an examination; they were not a conviction for personally opening unauthorized customer accounts.
2016: the external enforcement trigger finally changed the sales model
In July 2016, the OCC completed examination work and communicated that sales practices were unethical, harmed consumers and had not been addressed promptly. On 8 September, the CFPB, OCC and Los Angeles City Attorney announced coordinated resolutions. The CFPB release described a $100 million Bureau penalty, at least $2.5 million in expected refunds, and separate OCC and city penalties. The OCC release imposed a $35 million penalty and required restitution and an enterprise-wide sales-practices program.
The consent language is essential. The CFPB stated findings and legal conclusions, but Wells Fargo consented without admitting or denying them except as to jurisdiction. The OCC likewise made findings that the bank neither admitted nor denied. These were binding final agency orders, not contested trial judgments. It is accurate to say the agencies determined or found the practices described in their orders. It is not accurate to convert the consent mechanism into a litigated admission by the bank.
The practical response accelerated. Wells Fargo announced the end of retail product sales goals, effective 1 October 2016, and introduced a compensation model weighted more toward base pay, customer experience and relationship measures. John Stumpf retired as chairman and chief executive. The board formed an independent committee, and management and control functions began restructuring. Congressional hearings made unresolved questions about customer numbers, executive knowledge, compensation and regulatory delay public.
The Senate Banking Committee's official hearing record preserves testimony and written responses, but witness statements in that record must be treated as testimony rather than independent findings.
2017: broader review increased the potential population and shifted responsibility upward
The independent directors reported in April 2017 after 100 interviews, review of more than 35 million documents, analysis of more than 1,000 lower-level investigations, and forensic data work. They identified a confluence of sales culture, performance management, decentralization, leadership resistance, constrained control functions and inadequate escalation. The report attributed failures to named leaders and imposed employment and compensation consequences. Those company actions eventually exceeded $180 million in announced forfeitures, clawbacks and adjustments.
They are evidence of internal accountability decisions, though they are not government penalties or court damages.
The report also described concrete control changes: automated messages after checking, savings or credit-card openings; documented consent before credit inquiries; centralized monitoring; mystery shopping; more site visits and conduct reviews; removal of product goals; and revised compensation. These are relevant design claims. Their effectiveness had to be tested against false negatives, workarounds, customer contact accuracy, override behavior and sustained outcomes.
The bank's expanded third-party account analysis added an important numerical correction. Its third-quarter 2017 SEC filing says the review examined more than 165 million accounts opened over nearly eight years and identified approximately 3.5 million potentially unauthorized consumer and small-business accounts. It also identified approximately 528,000 potentially unauthorized online bill-pay enrollments. About 190,000 of the potentially unauthorized accounts had incurred fees or charges. The filing explicitly cautioned that the screening methodology was inclusive and could include authorized accounts whose usage resembled unauthorized ones.
That distinction prevents two opposite errors. Calling all 3.5 million accounts proven fraudulent overstates the analysis. Dismissing the number because it included false positives understates why a bank needed to review such a vast population. The screening result showed the cost of failing to preserve strong consent evidence at account creation: years later, authorization had to be inferred from behavioral patterns rather than demonstrated directly.
Customer recovery also widened beyond initial fee refunds. Wells Fargo supported a proposed class settlement and expanded review periods. An SEC-filed company notice concerning the $142 million class settlement described compensation routes for fees and possible credit-score-related borrowing costs. A settlement fund is not an admission that every claim is valid, and payment design does not by itself establish that every injured customer was found. It is evidence that redress had to address more than direct account fees.
2018-2020: enterprise sanctions and admitted facts replaced the local-misconduct frame
In February 2018, the Federal Reserve imposed an unusual growth restriction. The consent cease-and-desist order required stronger board oversight, an effective and independent firm-wide risk function, better risk identification and escalation, risk-data governance, incentive alignment, customer-remediation review, compliance and operational-risk testing, and two independent third-party reviews. The asset limit tied growth capacity to proof of governance and control improvement. The Fed's public announcement also stated that prior board performance had not met supervisory expectations.
The 2018 action covered broad consumer abuses and compliance breakdowns, not just the unauthorized-account methods described in 2016. That wider scope is relevant because it tests whether control reform was enterprise-wide. It must not be used to assign every later consumer issue to the sales-account scandal or to claim that one defect caused the full asset restriction.
In February 2020, the evidentiary posture changed again. Wells Fargo entered a deferred prosecution agreement and civil settlement with DOJ and an SEC resolution totaling $3 billion across the coordinated matters. The deferred prosecution agreement and admitted statement of facts described a 2002-2016 course of conduct, false records, identity misuse, unearned fees and interest, credit harm, unrealistic goals and leadership knowledge. Unlike the 2016 no-admit/no-deny consent orders, the company accepted responsibility for the statement of facts as part of the agreement.
The DPA did not equal a corporate criminal conviction after trial. It deferred prosecution subject to conditions and preserved possible individual cases. Nor did the $3 billion represent customer restitution alone: it combined a criminal monetary penalty, a FIRREA civil resolution and a $500 million SEC penalty. Legal categories and beneficiaries must not be collapsed into a single damages number.
The SEC's 2020 order addressed a separate accountability boundary: investor disclosure. It found that Wells Fargo promoted its cross-sell metric and needs-based sales strategy while the metric included unused, unneeded or unauthorized products. The securities violation was not simply that a branch opened an account without consent. It was that the company used a performance narrative and metric that did not fairly disclose the misconduct and quality problems underlying the reported strategy.
The OCC also moved from institutional remediation toward individual administrative accountability. Its January 2020 announcement combined allegations against five former executives with consent settlements involving others. Allegations in the notice were not final findings against the contesting respondents at that point. By contrast, former CEO John Stumpf's consent order imposed a lifetime banking prohibition and $17.5 million penalty without his admitting or denying wrongdoing. Those procedural differences matter when describing personal responsibility.
2023-2026: individual dispositions and independent closure evidence
The later record provides more finality. Tolstedt consented in 2023 to an OCC prohibition and $17 million penalty without admitting or denying the administrative allegations except as specified in her prior answer. Separately, she pleaded guilty to obstruction of a bank examination. A federal oversight council's 2024 official annual report records the court disposition: three years of probation, six months of home confinement and a $100,000 fine. That is a criminal disposition for obstruction, not a judicial finding that she committed every sales-practices act attributed to the Community Bank.
In January 2025, the OCC issued decisions after contested administrative litigation concerning former risk and audit executives. The agency's final-action summary says the Comptroller found that former Community Bank Group Risk Officer Claudia Russ Anderson failed to credibly challenge incentives, institute effective controls and escalate known risks, and that former audit leaders David Julian and Paul McLinko failed to plan and manage audit work that would detect and document the misconduct. The decision also found an independence failure involving McLinko.
These are agency decisions following a hearing record, not merely a 2020 charging allegation.
Repair evidence developed in parallel. The OCC terminated the 2016 sales-practices order in February 2024. The Federal Reserve removed the asset-growth restriction in June 2025 after reviewing remediation, required third-party assessments and its own evaluation of governance and firm-wide risk management. Other provisions remained then. On 5 March 2026, the Fed terminated the remaining 2018 enforcement action, stating that Wells Fargo had met all required conditions and completed two third-party reviews.
These are the strongest public indicators that the enterprise control program moved beyond promises. They are regulator decisions tied to specified requirements. They still have defined scope: termination means the legal conditions of those actions were satisfied. It does not erase historical findings, adjudicate every private claim, certify every individual account, or guarantee that no future employee can circumvent a control.
Trigger, root cause and contributing conditions
The trigger was the creation or enrollment of a product without affirmative and valid customer authorization. Methods included opening deposit and credit-card accounts, issuing debit cards, enrolling online banking or bill pay, transferring funds to make an account appear funded, altering contact information, and representing products as bundled. The trigger could be committed by an individual and could involve falsification. It therefore required individual investigation and, where proved, discipline or prosecution.
The root cause was not that Wells Fargo had sales goals in the abstract. It was that the operating model made product volume a powerful measure of success while customer authorization, use and benefit were weaker or later signals. A product could generate credit toward a goal before sustained use established value. Managers could press for daily results. Promotions could reward strong sellers. Control owners could investigate cases without compelling a redesign of goals. Senior reporting could frame rising misconduct as individual behavior.
The institution therefore had a production objective with immediate feedback and a customer-consent objective with fragmented evidence.
That root-cause statement is a supported synthesis of the government admissions, regulatory findings and board investigation. It is not a new legal finding. It explains why firing thousands of employees did not end the pattern. If an organization repeatedly removes people for the same misconduct while preserving the incentive and performance system associated with it, terminations become a detective control and labor churn mechanism, not proof that the source has been controlled.
Several contributing conditions intensified the failure:
- Goal difficulty and temporal pressure. Daily, quarterly and campaign-based targets shortened the decision horizon. Customer need is long term; sales credit was immediate.
- Quality tolerated as a cost. Low funding, rapid closure or limited use could indicate weak customer value. Business leaders could fear that stricter quality rules would suppress legitimate sales as well as bad ones.
- Decentralized control functions. Risk and human-resources resources embedded in or deferential to the business had less practical ability to challenge the model that defined business success.
- Fragmented complaint and case data. Customer complaints, employee ethics reports, investigation results, terminations, account analytics and regulatory matters did not initially form one traceable conduct-risk population.
- Thresholded investigation. Red-flag systems that investigated only the most extreme activity could miss widespread lower-intensity conduct and create false assurance from a small reviewed population.
- Weak consent evidence. When authorization could not later be demonstrated directly, remediation depended on behavioral proxies that necessarily produced uncertainty.
- Shared management framing. Describing misconduct as a collection of bad acts by individuals delayed recognition that goals, incentives and control design were common causes.
- Incomplete board and regulator information. High-level summaries, omitted denominators, untested complaints and delayed supervisory work reduced effective challenge even when the subject appeared on an agenda.
- Fear and escalation risk. Employees who believed missing goals threatened compensation, role or employment had incentives to comply with pressure and disincentives to challenge it. Public records document allegations and reviews concerning retaliation, but they do not establish that every adverse employment action was retaliatory.
The scale amplifier was automation and standardized processing. Enterprise software did not invent the incentive. It allowed one employee's access and customer data to create multiple products quickly, post sales credit, trigger downstream cards or online access, assess fees, report performance and populate metrics. An automated process can make authorized service efficient and unauthorized service scalable. Accountability therefore attaches to access rules, consent capture, event logging, manager approval, customer notification, metric eligibility and anomaly detection, not only to a branch employee's final keystroke.
Detection failed because signals were treated as cases instead of a control population
Detection existed at multiple levels. Customers noticed unknown accounts, cards, transfers, fees or collection activity. Employees reported pressure or misconduct. Internal Investigations substantiated cases. Human Resources saw terminations and turnover. Business analytics could observe funding rates, duplicate products, rapid closures and geographic concentrations. Audit and risk functions received reports. Regulators had complaints, whistleblower cases, examinations and media signals. The issue was not a total absence of sensors. It was failure to convert their combined output into a timely conclusion about the sales model.
An effective conduct-risk detection system requires five properties.
First, it needs a common event identity. A customer complaint, an EthicsLine report, an employee investigation, a product reversal, a fee refund and a credit-bureau correction should be linkable to the relevant product, employee, manager, branch, region, campaign and goal period without exposing customer data unnecessarily.
Second, it needs denominators and coverage. A count of substantiated cases says little without products opened, employees active, alerts generated, alerts investigated and accounts sampled. The Tolstedt criminal record is especially instructive because the admitted obstruction concerned omitted information about terminations and the tiny share of flagged activity selected for proactive investigation.
Third, it needs independent aggregation. A business line should not be the sole owner of the narrative about risks produced by its own performance model. Corporate risk and audit need data access, authority and direct escalation routes. Independence is not established only by an organization chart; it is demonstrated when a control function can challenge goals, require remediation and report contrary conclusions without business approval.
Fourth, detection needs customer-visible confirmation. The 2017 board report described automated post-opening messages. Notification can identify an unauthorized product quickly, but only if contact details have not been altered, the message is understandable, delivery failures are monitored and the customer has a low-friction way to reject the product. A notice is detective, not preventive, unless activation or sales credit remains contingent on customer confirmation.
Fifth, the system needs systemic escalation criteria. Repetition across regions, managers or product types should automatically trigger model review rather than more local discipline. Criteria should include recurring complaint language, threshold gaming, unusual product sequences, same-day multiples, low-use accounts, contact changes near opening, employee turnover, investigation backlogs and control overrides.
The OCC's lessons-learned report demonstrates that regulators need the same discipline. Examination plans must progress from interviews and policy review to transaction sampling and control testing. Matters requiring attention need owners, root causes, board visibility and evidence-based closure. Supervisory deferral is consequential when the institution under review is also deferring model change.
Response and recovery: stopping goals was necessary, identifying harm was harder
The most important containment action was ending retail product sales goals. That changed the immediate reward mechanism, but it did not by itself close unauthorized products, repair credit, refund fees, identify customers whose contact data had been changed, or redesign consent and oversight. Response therefore required parallel workstreams.
Customer containment required stopping questionable enrollment, closing or correcting products at the customer's direction, preventing further fees, suppressing collections, and ensuring that an unauthorized product did not block access to a legitimate account. Financial remediation required refunds with appropriate interest and compensation for consequential harm where supportable. Credit remediation required identifying credit inquiries, tradelines or score effects and coordinating correction. Identity protection mattered because customer information had been used to create products and credentials.
Employee response required fair investigation that distinguished deliberate falsification, obedience to improper pressure, control failure and good-faith reporting.
Retrospective population review was intrinsically uncertain. Wells Fargo's broad methodology intentionally erred toward inclusion, which protected customers from an impossibly high proof burden but created false positives. Strong original consent evidence would have made the review simpler. In its absence, the bank had to infer authorization from usage, funding, contact and other patterns. That is why the 3.5 million figure should be described as "potentially unauthorized" and why customers outside the screened population still needed complaint and settlement channels.
The class settlement addressed fees and possible credit-related borrowing costs. Regulatory restitution overlapped with certain settlement obligations, so gross announced amounts should not be added mechanically as though every dollar represented a separate customer loss. The SEC Fair Fund served investors, not account customers. The SEC's official distribution docket records multiple distributions, including an April 2026 order, but those payments arise from misleading investor disclosures. They should not be presented as unauthorized-account refunds.
Recovery also included leadership change, compensation recoupment, governance restructuring, consent controls, monitoring and years of regulatory validation. Monetary sanctions are consequences; they are not repair evidence on their own. A penalty can coexist with a weak control. Conversely, a regulator's termination after specified validation is stronger evidence of repair than the size of the original fine.
Responsibility control map
| Control domain | Practical controller during the failure period | Public evidence of failure or exposure | Required repair evidence | Current public assessment |
|---|---|---|---|---|
| Sales targets and product credit | Community Bank leadership and performance-management owners | Board investigation, DOJ admitted facts and OCC findings link unrealistic goals and pressure to misconduct | Goals tied to customer value and risk; no credit before verified consent; monitoring for target substitution | Product sales goals were removed in 2016; public evidence does not show every current metric and anti-gaming test |
| Product-opening authorization | Product, branch-operations, identity, access and technology owners | Unauthorized accounts, cards, online services and simulated funding described in agency orders | Affirmative consent artifact, controlled activation, independent notification, immutable event history and sampled replay | Design changes were reported; detailed current rule coverage and override results are not public |
| Branch and regional management | Regional, district and branch leaders | Pressure, ranking, duplicate-account and quality concerns in the board investigation | Balanced scorecards, manager conduct indicators, escalation duty and consequences for pressure | Leadership and compensation changed; branch-level performance data are not public |
| Customer complaints and redress | Enterprise complaint, operations, legal and remediation owners | OCC found no comprehensive complaint-monitoring process | Unified taxonomy, product linkage, systemic trend triggers, timely refunds and traceable closure | Regulatory orders were later terminated; current complaint-to-control traceability is not disclosed |
| Employee reporting and investigations | Ethics, investigations, human resources, legal and line management | Repeated reports and terminations did not force timely model change | Protected escalation, independent triage, anti-retaliation testing, case aggregation and root-cause thresholds | Governance was centralized; complete historical and current outcome data remain private |
| First-line conduct risk | Community Bank risk and business control owners | Company investigation and later OCC decisions describe inadequate challenge and escalation | Independent stature within the line, authority to halt goals or products, direct second-line escalation | 2018 Fed requirements and 2026 termination support substantial improvement |
| Independent risk | Chief risk function and enterprise risk committees | Decentralization and business deference constrained enterprise challenge | Separate reporting, data access, risk appetite, aggregate conduct indicators and stop authority | Fed found required governance and firm-wide risk conditions satisfied by 2026 |
| Internal audit | Chief auditor, audit leadership and board audit committee | OCC order found enterprise coverage inadequate; 2025 decisions found planning, escalation and independence failures | Risk-based end-to-end audits, transaction testing, model challenge, issue validation and board reporting | Individual administrative decisions are final agency evidence; current detailed audit work remains confidential |
| Executive management | CEO and operating committee | Board report, admitted DOJ facts and individual regulatory dispositions show delayed or inadequate challenge | Clear accountability for strategy within risk capacity; complete escalation and compensation consequences | Leadership changed, compensation was recouped and long-running actions were closed after review |
| Board oversight | Full board and relevant committees | Fed said prior oversight did not meet expectations; board report found incomplete management reporting | Direct risk reporting, independent expertise, challenge records, remediation milestones and sustainability evidence | Fed completed its assessment and terminated the 2018 action in 2026 |
| Prudential supervision | OCC and Federal Reserve examination and enforcement teams | OCC's own review documented missed testing and follow-up opportunities | Timely transaction testing, documented MRAs, board communication, independent closure and cross-agency coordination | OCC published lessons and later enforced against institution and individuals |
The map prevents responsibility from collapsing onto either front-line employees or the board. Front-line staff controlled their own conduct and could cause direct harm. They did not set enterprise goals or define control architecture. Business leaders controlled performance expectations and practical consequences. Risk and audit controlled challenge and assurance within their mandates. Executives controlled strategy and resource allocation. Directors controlled oversight, executive accountability and information demands. Regulators controlled examination scope and enforcement timing, not the bank's daily operations.
Responsibility also changes over time. The person who creates an unauthorized product owns the immediate act. The manager who rewards it or ignores indicators owns a different layer. A control function that receives repeated evidence but fails to aggregate or escalate owns assurance failure. A board receiving incomplete information cannot be assigned knowledge it did not possess, but it can be assessed on whether it demanded the evidence required for oversight. A regulator that misses testing opportunities does not become the operator; it remains accountable for supervisory effectiveness.
Legal and regulatory boundaries
The public record includes different legal instruments with different meanings.
The 2015 Los Angeles complaint alleged violations and triggered litigation. Allegations are party claims until admitted, settled with agreed facts, or adjudicated. It is evidence of public notice and the city's theory, not a judgment proving every allegation.
The 2016 CFPB and OCC orders are final and enforceable consent orders. The agencies made findings and imposed obligations, penalties and restitution. Wells Fargo did not admit or deny the substantive findings under the terms cited. The article can rely on the agencies' findings while preserving the bank's stipulated posture.
The 2017 independent-director report is a company governance investigation. Its interview and document base makes it highly probative about internal structure and communications. It was not produced by a court, and named findings should remain attributed to the independent directors rather than converted into criminal conclusions.
Congressional hearing records establish what witnesses and members said, what documents were entered, and which questions were asked. They do not transform every statement into an adjudicated fact. They are useful for contemporaneous notice, management representations and regulatory explanations.
The 2018 Federal Reserve order was issued upon consent before formal fact adjudication. It imposed binding governance, risk-management, review and growth conditions. Its 2025 partial relief and 2026 termination are official determinations that specified conditions were met, not declarations that historical conduct did not occur.
The 2020 DOJ agreement contains company admissions in an attached statement of facts. A deferred prosecution agreement is not a trial conviction. It conditions non-prosecution on performance and cooperation. The FIRREA component was civil. The SEC component addressed securities disclosure and investor harm. The coordinated $3 billion payment cannot be labeled a single criminal fine or customer-remediation fund.
Individual OCC matters include both consent orders and contested decisions. Stumpf and Tolstedt accepted prohibitions and penalties without admitting or denying wrongdoing under their administrative agreements. The 2025 decisions concerning Anderson, Julian and McLinko followed litigation and contain final agency findings. The procedural status determines whether a statement should be called an allegation, settlement term or finding.
Tolstedt's criminal case produced a guilty plea and sentence for obstruction of a bank examination. It did not adjudicate criminal liability for every unauthorized account, and it did not establish criminal culpability of other executives. Individual accountability must be offense-specific.
Later standards and reforms cannot be applied retroactively as though they were binding rules during every year of the misconduct period. The 2018 Fed requirements and later control designs are useful benchmarks for remediation. Historical conduct should be judged under the laws, orders, policies and duties applicable at the time, while supported inference can identify controls that would have reduced the risk.
The same precision applies to numbers. The initial approximately 2.1 million and later approximately 3.5 million populations used different periods and refined methods; they are not additive. Potentially unauthorized accounts are not all proven unauthorized. Fee counts are not equal to total affected customers. Penalties, restitution, class settlements, compensation clawbacks and investor distributions serve different purposes and may overlap. A defensible accountability analysis keeps each ledger separate.
Counterfactuals: controls that could have broken the chain
Counterfactual analysis is not a claim that a later practice was legally mandatory in 2002. It asks whether a feasible control, applied at a particular decision point, would probably have interrupted the observed mechanism.
Counterfactual 1: sales credit only after customer-controlled confirmation. Suppose a new checking account, card or bill-pay enrollment did not count toward performance and could not assess a fee until the customer confirmed through a channel the employee could not edit. Simulated funding or false contact details would not be enough. This would have reduced immediate reward and created a customer-held authorization record. Residual risk would remain for coerced or misleading consent, shared devices and inaccessible channels.
Counterfactual 2: quality-adjusted metrics with hard risk gates. Suppose product credit decayed when an account was rapidly closed, never meaningfully funded, unused, disputed or linked to a complaint, and manager compensation was reduced for repeated consent failures. That would have aligned the performance measure more closely with durable customer value. It might also have encouraged concealment or delayed closure, so independent monitoring would still be necessary.
Counterfactual 3: an enterprise conduct graph. Suppose complaints, investigations, terminations, product events, fees, contact changes and management hierarchy were linked. Clusters in Los Angeles, Arizona or under recurring managers could have triggered review before national remediation was required. Privacy and fairness controls would be essential, because anomaly data are indicators rather than proof against an employee.
Counterfactual 4: model-change threshold after repeated terminations. Suppose a set number or rate of substantiated cases automatically required the incentive owner, independent risk and audit committee to reassess the underlying goal. This would have prevented the institution from treating recurring dismissals as evidence that enforcement alone worked.
Counterfactual 5: independent risk authority over goals. Suppose the second line could reject a sales plan that exceeded branch traffic and customer-demand assumptions, and could require pilots, conduct limits and cancellation criteria. The OCC's 2016 findings specifically identified misalignment with traffic, turnover and demand. Challenge would then concern the model before harm, not only case handling afterward.
Counterfactual 6: transaction testing by audit and supervisors. Interviews and policy review can miss routine workarounds. Sampling duplicate openings, unfunded accounts, rapid contact changes, online enrollments and employee-linked funding would have tested actual outcomes. The OCC's lessons-learned report shows that planned testing was narrowed or postponed. Earlier execution could have accelerated a systemic conclusion.
Counterfactual 7: complete board conduct dashboard. A board package showing absolute counts, rates, trends, geographic concentration, investigation coverage, recurrence, customer harm and goal pressure would have made a "few bad actors" explanation testable. The board would still need to challenge assumptions and demand independent validation. Data alone do not create oversight.
Counterfactual 8: redress-by-design. Every product should retain a consent artifact, opening channel, employee and manager identifiers, customer notifications, delivery status and subsequent disputes. If harm occurs, the bank can identify the population and reverse fees without relying primarily on years-later behavioral inference. This control reduces recovery uncertainty even when prevention fails.
These counterfactuals are strongest in combination. Customer confirmation attacks unauthorized activation. Quality-adjusted metrics reduce incentive. Conduct aggregation improves detection. Independent challenge changes decisions. Audit and supervisory sampling validate reality. Board reporting allocates accountability. Redress records limit residual harm. No single email, training course or penalty supplies all six functions.
Repair evidence: from announced changes to regulatory closure
Repair claims should be assessed on an evidence ladder.
Level 1: policy and leadership change. Wells Fargo ended product sales goals, replaced leaders, separated chair and chief executive roles, centralized functions and changed compensation. These actions addressed causes identified by the board. They demonstrate intent and structural change, but not operating effectiveness.
Level 2: control implementation. The company reported automated account-opening notifications, documented credit-card consent, mystery shopping, site visits and centralized monitoring. Those controls map to authorization and detection. Public descriptions do not reveal delivery-failure handling, employee access to contact fields, override rights or false-negative rates.
Level 3: population review and redress. Third-party analysis covered more than 165 million accounts, and settlements and complaint channels expanded remediation. This demonstrates serious retrospective effort. The need to use an inclusive proxy also exposes the historical absence of decisive consent records.
Level 4: internal accountability. Leadership changes, terminations and more than $180 million in announced compensation actions moved consequences above branch staff. Internal accountability is meaningful when it addresses control ownership and incentives. It is less probative about current effectiveness than live control testing.
Level 5: regulatory and legal accountability. Penalties, orders, the DPA, SEC findings, individual prohibitions, the criminal disposition and contested OCC decisions produced enforceable consequences. They clarify duties and facts but do not automatically repair a product workflow.
Level 6: order-specific independent validation. OCC termination of the sales-practices order in 2024 is direct evidence that the agency concluded the action could end. The Fed's 2025 asset-cap removal followed review of remediation and required third-party assessments. Its 2026 termination followed demonstration of effective governance and risk-management improvements and two third-party reviews. This is the strongest public institutional repair evidence because relief was conditional on regulator assessment rather than a company deadline.
Wells Fargo's 2025 annual report filed with the SEC describes continued investment in risk, controls, technology and talent and treats the asset-cap removal as validation of transformation work. That is a management account and includes forward-looking framing. The Federal Reserve's independent decisions carry greater assurance weight for the requirements they covered.
The evidence supports a balanced conclusion. It would be wrong to say the institution merely announced reform and received no independent validation. It would also be wrong to say regulatory termination proves every account-opening path is infallible. A control environment can satisfy an order and still face future incidents, product changes, staff turnover and metric drift. Durable accountability requires continuous evidence after formal actions end.
The most useful ongoing measures would include the share of products activated only after customer-controlled confirmation; notification delivery and rejection rates; consent-artifact completeness; disputed openings per thousand products; time to freeze and remediate; manager and region recurrence; alert investigation coverage; override rate and age; false-negative results from independent sampling; complaint linkage to control defects; employee escalation outcomes; and the time from a systemic threshold breach to goal or process change.
Public disclosure need not expose customer data, fraud rules or confidential supervisory information. Wells Fargo could publish bounded assurance: control objectives, population coverage, independent-test scope, trend ranges, material exceptions and the governance route for unresolved issues. That would let customers, employees, investors and small businesses distinguish a closed order from a static declaration of safety.
What remains unresolved in the public record
Several questions remain open even after the 2026 Federal Reserve termination.
Current consent architecture. Public sources do not map every checking, savings, credit-card, debit-card, online-banking and bill-pay path to a required consent artifact, activation rule and customer-controlled confirmation.
Metric substitution. Removing product goals reduces the historical incentive, but any service, relationship, referral, balance or experience metric can be gamed if career consequences are strong and quality controls weak. Current anti-gaming test results are not public.
Override governance. Banks need exceptions for accessibility, outages, assisted service and unusual customer circumstances. Public evidence does not show who can override authorization controls, how often, for how long or how overrides are independently sampled.
False negatives. Regulator termination shows required program effectiveness, but the public record does not disclose branch-level blind testing against seeded unauthorized-account scenarios or the proportion of actual customer disputes missed by automated monitoring.
Complaint traceability. It is not publicly demonstrated that every consent complaint links to the relevant product event, employee, manager, control version, notification delivery and remediation outcome.
Employee challenge outcomes. Policies may prohibit retaliation, but public data do not show reporting volumes, substantiation rates, adverse-action reviews, investigation time, recurrence or whether reporters viewed channels as safe.
Complete customer economic harm. Fees and certain credit effects were addressed through multiple programs, but opportunity cost, time, identity risk, delayed borrowing and small-business disruption are difficult to reconstruct. Announced payment totals do not equal a complete social-cost ledger.
Sustainability after closure. Formal orders create external milestones. Their end tests whether business-as-usual governance can maintain the controls without the same enforcement cadence. That question can only be answered over time.
These gaps do not negate the regulator decisions. They define the difference between sufficient evidence to terminate specified legal actions and enough public evidence to independently certify every customer-consent pathway.
Conclusion
Wells Fargo's unauthorized-account episode became an accountability test because authority and evidence were separated. Employees could open products; managers could impose goals; business leaders could preserve the model; risk and audit could receive partial signals; executives and directors could receive incomplete summaries; regulators could defer testing; and customers could discover harm only after activation. Each layer had a different opportunity to stop the chain.
The historical evidence supports a clear causal hierarchy. Unauthorized entry was the trigger. The root was a sales and performance system that gave product volume immediate institutional value without equally strong proof of customer consent and benefit. Fragmented complaints, limited investigation coverage, decentralized controls, weak challenge, incomplete escalation and delayed supervisory testing allowed the model to persist. Later records moved accountability upward through company admissions, board findings, regulatory decisions, compensation consequences, prohibitions and one offense-specific criminal disposition.
The repair record is also substantial. Product goals ended, consent and notification controls were added, customer populations were reviewed, redress expanded, governance changed, individuals faced consequences, and independent regulators eventually terminated the central sales-practices and governance actions. The 2024 OCC termination and 2026 Federal Reserve termination are stronger evidence than corporate assurances alone.
The final standard, however, is operational rather than rhetorical. A bank should be able to show that no product receives sales or performance value before valid customer authorization; that consent cannot be manufactured by the person receiving credit; that complaints, employee reports and account anomalies converge into systemic review; that risk and audit can stop the model; that the board sees decision-grade evidence; and that a harmed customer can be found and repaired without a decade-later inference exercise.
That is how an institution proves the incentive system was repaired: customer consent becomes the control that creates the sale, not evidence sought after the count has already been booked.

