Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

COF US Equity

Capital One Financial CorpFinancials · National Commercial Banks · CIK 927628 · FY ends Dec 31
$217.91
+5.43 (+2.56%)
USD · as of 2026-08-21 · marketstack

COF · 10-K · period ended 2020-12-31

← all COF documents
filed 2021-02-25 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1525 of 3,442648k characters rendered

cof-20201231

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

____________________________________

FORM 10-K

____________________________________

For the fiscal year ended December 31, 2020

OR

For the transition period from to

Commission File No. 001-13300

____________________________________

CAPITAL ONE FINANCIAL CORPORATION

(Exact name of registrant as specified in its charter)

____________________________________

1680 Capital One Drive,

(Address of principal executive offices) (Zip Code)

Registrant’s telephone number, including area code: (703) 720-1000

____________________________________

Securities registered pursuant to Section 12(b) of the Act:

Title of Each Class Trading Symbol(s) Name of Each Exchange on Which Registered

Common Stock (par value $.01 per share) COF New York Stock Exchange

0.800% Senior Notes Due 2024 COF24 New York Stock Exchange

1.650% Senior Notes Due 2029 COF29 New York Stock Exchange

Securities registered pursuant to section 12(g) of the Act: None

____________________________________

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer ☒ Accelerated filer ☐

Non-accelerated filer ☐ Smaller reporting company ☐

Emerging growth company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C.7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒

The aggregate market value of the voting stock held by non-affiliates of the registrant as of the close of business on June 30, 2020 was approximately $28.3 billion. As of January 31, 2021, there were 459,236,740 shares of the registrant’s Common Stock outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

1.Portions of the Proxy Statement for the annual meeting of stockholders to be held on May 6, 2021, are incorporated by reference into Part III.

TABLE OF CONTENTS

Page

PART I 4

Item 1. Business 4

Overview 4

Operations and Business Segments 7

Competition 8

Supervision and Regulation 8

Human Capital Resources 19

Additional Information 21

Forward-Looking Statements 22

Item 1A. Risk Factors 23

Item 1B. Unresolved Staff Comments 41

Item 2. Properties 41

Item 3. Legal Proceedings 41

Item 4. Mine Safety Disclosures 41

Item 6. Selected Financial Data 44

Executive Summary and Business Outlook 48

Consolidated Results of Operations 50

Consolidated Balance Sheets Analysis 55

Off-Balance Sheet Arrangements 57

Business Segment Financial Performance 57

Critical Accounting Policies and Estimates 66

Accounting Changes and Developments 70

Capital Management 70

Risk Management 77

Credit Risk Profile 83

Liquidity Risk Profile 96

Market Risk Profile 100

Supplemental Tables 104

Glossary and Acronyms 109

Item 7A. Quantitative and Qualitative Disclosures about Market Risk 115

Item 8. Financial Statements and Supplementary Data 115

Consolidated Statements of Income 121

Consolidated Statements of Comprehensive Income 122

Consolidated Balance Sheets 123

Consolidated Statements of Changes in Stockholders’ Equity 124

Consolidated Statements of Cash Flows 125

1 Capital One Financial Corporation (COF)

Notes to Consolidated Financial Statements 127

Note 1—Summary of Significant Accounting Policies 127

Note 2—Investment Securities 143

Note 5—Variable Interest Entities and Securitizations 158

Note 6—Goodwill and Intangible Assets 162

Note 7—Premises, Equipment and Leases 165

Note 8—Deposits and Borrowings 167

Note 9—Derivative Instruments and Hedging Activities 169

Note 10—Stockholders’ Equity 178

Note 11—Regulatory and Capital Adequacy 182

Note 12—Earnings Per Common Share 184

Note 13—Stock-Based Compensation Plans 185

Note 14—Employee Benefit Plans 187

Note 16—Fair Value Measurement 193

Note 17—Business Segments and Revenue from Contracts with Customers 202

Note 18—Commitments, Contingencies, Guarantees and Others 207

Note 19—Capital One Financial Corporation (Parent Company Only) 211

Note 20—Related Party Transactions 213

Item 9A. Controls and Procedures 214

Item 9B. Other Information 214

Item 10. Directors, Executive Officers and Corporate Governance 215

Item 11. Executive Compensation 215

Item 14. Principal Accountant Fees and Services 215

Item 15. Exhibits, Financial Statement Schedules 216

EXHIBIT INDEX 217

2 Capital One Financial Corporation (COF)

INDEX OF MD&A AND SUPPLEMENTAL TABLES

MD&A Tables: Page

1 Average Balances, Net Interest Income and Net Interest Margin 51

2 Rate/Volume Analysis of Net Interest Income 52

3 Non-Interest Income 53

4 Non-Interest Expense 54

5 Investment Securities 55

6 Loans Held for Investment 56

7 Funding Sources Composition 56

8 Business Segment Results 58

9 Credit Card Business Results 59

9.1 Domestic Card Business Results 61

10 Consumer Banking Business Results 62

11 Commercial Banking Business Results 64

12 Other Category Results 65

13 Capital Ratios Under Basel III 73

14 Regulatory Risk-Based Capital Components and Regulatory Capital Metrics 74

15 Preferred Stock Dividends Paid Per Share 75

16 Portfolio Composition of Loans Held for Investment 84

17 Loan Maturity Schedule 85

18 Credit Card Portfolio by Geographic Region 85

19 Consumer Banking Portfolio by Geographic Region 86

20 Commercial Banking Portfolio by Geographic Region 86

21 Commercial Loans by Industry 87

22 Credit Score Distribution 88

24 Aging and Geography of 30+ Day Delinquent Loans 89

25 90+ Day Delinquent Loans Accruing Interest 90

26 Nonperforming Loans and Other Nonperforming Assets 90

27 Net Charge-Offs 91

28 Troubled Debt Restructurings 93

30 Allowance Coverage Ratios 96

31 Liquidity Reserves 96

32 Deposits Composition and Average Deposits Interest Rates 97

33 Maturities of Large-Denomination Domestic Time Deposits—$100,000 or More 98

34 Long-Term Funding 98

35 Senior Unsecured Long-Term Debt Credit Ratings 99

36 Contractual Obligations 99

37 Interest Rate Sensitivity Analysis 101

Supplemental Tables:

A Loans Held for Investment Portfolio Composition 104

B Performing Delinquencies 104

C Nonperforming Loans and Other Nonperforming Assets 105

D Net Charge-Offs 106

F Reconciliation of Non-GAAP Measures 107

G Selected Quarterly Financial Information 108

3 Capital One Financial Corporation (COF)

Table of Contents

PART I

Item 1. Business

OVERVIEW

General

Capital One Financial Corporation, a Delaware corporation established in 1994 and headquartered in McLean, Virginia, is a diversified financial services holding company with banking and non-banking subsidiaries. Capital One Financial Corporation and its subsidiaries (the “Company” or “Capital One”) offer a broad array of financial products and services to consumers, small businesses and commercial clients through digital channels, branches, Cafés and other distribution channels.

As of December 31, 2020, our principal subsidiaries included:

•Capital One Bank (USA), National Association (“COBNA”), which offers credit and debit card products, other lending products and deposit products; and

•Capital One, National Association (“CONA”), which offers a broad spectrum of banking products and financial services to consumers, small businesses and commercial clients.

The Company is hereafter collectively referred to as “we,” “us” or “our.” COBNA and CONA are collectively referred to as the “Banks.” References to “this Report” or our “2020 Form 10-K” or “2020 Annual Report” are to our Annual Report on Form 10-K for the fiscal year ended December 31, 2020. All references to 2020, 2019, 2018, 2017 and 2016, refer to our fiscal years ended, or the dates, as the context requires, December 31, 2020, December 31, 2019, December 31, 2018, December 31, 2017 and December 31, 2016, respectively. Certain business terms used in this document are defined in the “MD&A—Glossary and Acronyms” and should be read in conjunction with the Consolidated Financial Statements included in this Report.

As one of the nation’s largest banks based on deposits as of December 31, 2020, we service banking customer accounts through digital channels, as well as through branch locations, call centers, ATMs and Cafés. We also operate as one of the largest online direct banks in the United States of America (“U.S.”) by deposits. In addition to bank lending, treasury management and depository services, we offer credit and debit card products, auto loans and other consumer lending products in markets across the U.S. We were the third largest issuer of Visa® (“Visa”) and MasterCard® (“MasterCard”) credit cards in the U.S. based on the outstanding balance of credit card loans as of December 31, 2020.

We also offer products outside of the U.S. principally through Capital One (Europe) plc (“COEP”), an indirect subsidiary of COBNA organized and located in the United Kingdom (“U.K.”), and through a branch of COBNA in Canada. Both COEP and our Canadian branch of COBNA have the authority to provide credit card loans.

Business Developments

We regularly explore and evaluate opportunities to acquire financial products and services as well as financial assets, including credit card and other loan portfolios, and enter into strategic partnerships as part of our growth strategy. We also explore opportunities to acquire technology companies and related assets to improve our information technology infrastructure and to deliver on our digital strategy. We may issue equity or debt to fund our acquisitions. In addition, we regularly consider the potential disposition of certain of our assets, branches, partnership agreements or lines of business.

In the fourth quarter of 2020, we entered into an agreement to sell a partnership credit card loan portfolio of approximately $2.1 billion, which had been transferred to held for sale as of September 30, 2020, resulting in an allowance release of $327 million.

On September 24, 2019, we launched a new credit card issuance program with Walmart Inc. (“Walmart”) and are now the exclusive issuer of Walmart’s cobrand and private label credit card program in the U.S.. On October 11, 2019, we completed the acquisition of the existing portfolio of Walmart’s cobrand and private label credit card receivables, which added approximately $8.1 billion to our domestic credit card loans held for investment portfolio as of the acquisition date.

4 Capital One Financial Corporation (COF)

Table of Contents

Coronavirus Disease 2019 (COVID-19) Pandemic

The COVID-19 pandemic has resulted in a global public-health crisis, disrupting economies and introducing significant volatility into financial markets and uncertainty as to when economic and operating conditions will return to normalcy. This crisis continues to impact individuals, households and businesses in a multitude of ways. Companies in the U.S. and abroad have experienced unprecedented disruptions to normal business operations, including customer-facing interactions, supply chains, office closures, changes in demand for products and services, and others. Financial institutions, including us, have been deemed an essential service and exempted from the myriad of shutdowns across the country. We transformed how we work in order to protect the well-being of our associates and our customers, serve our customers, support our communities, and position ourselves to navigate the challenges ahead.

Since the start of the COVID-19 pandemic, a significant majority of our associates across our workforce have transitioned to working remotely, relying on our technology infrastructure and systems that have been designed for resilience and security. The majority of our associates will continue to work remotely through at least the summer of 2021, as we continue to prioritize their safety while planning our return to the office. We have been able to continue serving customers by successfully managing critical functions and keeping our lines of business operating. We implemented additional paid benefits and flexible attendance policies that are intended to enable our associates to care for their families and loved ones, including increased pay for branch and Café associates working in open locations, associates that perform essential and time-sensitive banking activities that cannot be performed remotely, and other U.S.-based associates in roles instrumental to maintaining essential customer support. We continue to monitor and revise our safety precautions and policies at banking locations as government authorities continue to implement and modify measures to contain the further spread of COVID-19. In our Retail Banking business, nearly all of our Cafés and branches across our network are open with increased safety precautions. We will continue to monitor local conditions to ensure the safety of our associates and customers while providing critical banking services.

We have offered a range of policies and programs to accommodate customer hardship across our lines of business. In our Credit Card and Auto businesses, our customers, who were in need and made a request, received forbearance primarily in the form of short-term payment deferrals or extensions and fee waivers. In our Retail Banking business, we waived select fees for impacted customers and offered short-term payment deferrals for our small business banking customers. We have also been working with our Commercial Banking customers on a more customized basis. In addition, we have participated in the Paycheck Protection Program (“PPP”), established by the Coronavirus Aid, Relief, and Economic Security Act (the “CARES Act”) enacted in March 2020 and implemented by the Small Business Administration. See “MD&A—Credit Risk Profile” for more information about our customer assistance programs, including enrollment volumes and outstandings, customer performance and current program offerings.

We reported net income of $2.7 billion ($5.18 per diluted common share) for 2020, which reflects $5.0 billion in allowance builds in the first and second quarters of 2020 due to expectations of economic worsening as a result of the COVID-19 pandemic. These allowance builds, in combination with the adoption impact of the Current Expected Credit Loss (“CECL”) standard, significantly increased our allowance coverage ratio to 6.19% as of December 31, 2020 from 2.71% as of December 31, 2019. For more information, see “MD&A—Executive Summary and Business Outlook” and “MD&A—Credit Risk Profile.” We have continued to evaluate the potential impact on our goodwill impairment analysis and have incorporated recent market events and trends into our valuations of instruments measured at fair value. See more details in “MD&A—Critical Accounting Policies and Estimates,” “MD&A—Market Risk Profile” and “Note 9—Derivative Instruments and Hedging Activities.” See “MD&A—Liquidity Risk Profile” for information relating to our liquidity reserves as of December 31, 2020.

The COVID-19 pandemic impacted the demand for our products and services throughout 2020. In our Domestic Card business, loan balances, and revenue are down year-over-year, while purchase volume was relatively flat due to higher first and fourth quarter activity substantially offsetting year-over-year volume declines in the second and third quarters. In our Auto business, we saw an increase in origination volumes and loan growth driven by our relationship strategy and digital capabilities that we have developed. In our Retail Banking business, we have seen strong deposit growth throughout the year from increased consumer savings aided by the impact of government stimulus. In our Commercial Banking business, loan balances were relatively flat year-over year, while deposit balances were up significantly, reflecting the impact of the economic environment and government stimulus on our customers.

We are actively monitoring and responding to developments across the myriad of landscapes affected by the COVID-19 pandemic, including social, financial, legal, regulatory and governmental. As guidance is issued by governments and our regulators, we continue to assess the impacts on us. As government authorities continue to implement, modify and reinstate social distancing and reopening plans and other measures to contain the further spread of COVID-19, including the

5 Capital One Financial Corporation (COF)

Table of Contents

administration of vaccines, we will continue to adjust our business operations, policies and practices, keeping the best interests of our associates, customers and business partners at the forefront.

Cybersecurity Incident

On July 29, 2019, we announced that on March 22 and 23, 2019 an outside individual gained unauthorized access to our systems. This individual obtained certain types of personal information relating to people who had applied for our credit card products and to our credit card customers (the “Cybersecurity Incident”). We retained a leading independent cybersecurity firm that confirmed we correctly identified and fixed the specific configuration vulnerability exploited in the Cybersecurity Incident. We continue to invest significantly in cybersecurity and related risk management activities and expect to make additional investments as we continue to assess our cybersecurity program.

During the year ended December 31, 2020, we incurred $66 million of incremental expenses related to the remediation of and response to the Cybersecurity Incident, offset by $39 million of insurance recoveries. To date, we have incurred $138 million of incremental expenses, offset by $73 million of insurance recoveries pursuant to the cyber risk insurance coverage we carry. These expenses mainly consist of customer notifications, credit monitoring, technology costs, and professional and legal support. We expect any further expenses, net of insurance, to be immaterial in future periods. We carry insurance to cover certain costs associated with a cyber risk event. This insurance has a total coverage limit of $400 million and is subject to a $10 million deductible, which was met in the third quarter of 2019, as well as standard exclusions. The expenses discussed in this paragraph do not include any amounts related to the matters described in “Note 18—Commitments, Contingencies, Guarantees and Others.”

Although the ultimate magnitude and timing of expenses or other impacts to our business or reputation related to the Cybersecurity Incident are uncertain, they may be significant, and some of the costs may not be covered by insurance. However, we do not believe that this incident will materially impact our strategy or our long-term financial health. For more information, see “Note 18—Commitments, Contingencies, Guarantees and Others.”

Additional Information

Our common stock trades on the New York Stock Exchange (“NYSE”) under the symbol “COF” and is included in the Standard & Poor’s (“S&P”) 100 Index. We maintain a website at www.capitalone.com. Documents available under Corporate Governance in the Investor Relations section of our website include:

•our Code of Conduct;

•our Corporate Governance Guidelines; and

•charters for the Audit, Compensation, Governance and Nominating, and Risk Committees of the Board of Directors.

These documents also are available in print to any stockholder who requests a copy. We intend to disclose future amendments to certain provisions of our Code of Conduct, and waivers of our Code of Conduct granted to executive officers and directors, on the website within four business days following the date of the amendment or waiver.

In addition, we make available free of charge through our website all of our U.S. Securities and Exchange Commission (“SEC”) filings, including our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to those reports, as soon as reasonably practicable after electronically filing or furnishing such material to the SEC at www.sec.gov.

6 Capital One Financial Corporation (COF)

Table of Contents

OPERATIONS AND BUSINESS SEGMENTS

Our consolidated total net revenues are derived primarily from lending to consumer and commercial customers net of funding costs associated with our deposits, long-term debt and other borrowings. We also earn non-interest income which primarily consists of interchange income, net of reward expenses, service charges and other customer-related fees. Our expenses primarily consist of the provision for credit losses, operating expenses, marketing expenses and income taxes.

Our principal operations are organized for management reporting purposes into three major business segments, which are defined primarily based on the products and services provided or the types of customers served: Credit Card, Consumer Banking and Commercial Banking. The operations of acquired businesses have been integrated into or managed as a part of our existing business segments. Certain activities that are not part of a segment, such as management of our corporate investment portfolio, asset/liability management by our centralized Corporate Treasury group and residual tax expense or benefit to arrive at the consolidated effective tax rate that is not assessed to our primary business segments, are included in the Other category.

•Credit Card: Consists of our domestic consumer and small business card lending, and international card businesses in Canada and the United Kingdom.

•Consumer Banking: Consists of our deposit gathering and lending activities for consumers and small businesses, and national auto lending.

•Commercial Banking: Consists of our lending, deposit gathering, capital markets and treasury management services to commercial real estate and commercial and industrial customers. Our customers typically include companies with annual revenues between $20 million and $2 billion.

Customer usage and payment patterns, credit quality, levels of marketing expense and operating efficiency all affect our profitability. In our Credit Card business, we experience fluctuations in purchase volume and the level of outstanding loan receivables due to seasonal variances in consumer spending and payment patterns which, for example, have historically been the highest around the winter holiday season. Net charge-off rates for our credit card loan portfolio also have historically exhibited seasonal patterns as well and generally tend to be the highest in the first quarter of the year.

For additional information on our business segments, including the financial performance of each business, see “Part II—Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”)—Executive Summary and Business Outlook,” “MD&A—Business Segment Financial Performance” and “Note 17—Business Segments and Revenue from Contracts with Customers” of this Report.

7 Capital One Financial Corporation (COF)

Table of Contents

COMPETITION

Each of our business segments operates in a highly competitive environment, and we face competition in all aspects of our business from numerous bank and non-bank providers of financial services.

Our Credit Card business competes with international, national, regional and local issuers of Visa and MasterCard credit cards, as well as with American Express®, Discover Card®, private-label card brands, and, to a certain extent, issuers of debit cards. In general, customers are attracted to credit card issuers largely on the basis of price, credit limit, reward programs and other product features.

Our Consumer Banking and Commercial Banking businesses compete with national, state and direct banks for deposits, commercial and auto loans, as well as with savings and loan associations and credit unions for loans and deposits. Our competitors also include automotive finance companies, commercial mortgage banking companies and other financial services providers that provide loans, deposits, and other similar services and products. In addition, we compete against non-depository institutions that are able to offer these products and services.

We also consider new and emerging companies in the digital and mobile payments space and other financial technology providers among our competitors. We compete with many forms of payment mechanisms, systems and products, offered by both bank and non-bank providers.

Our businesses generally compete on the basis of the quality and range of their products and services, transaction execution, innovation and price. Competition varies based on the types of clients, customers, industries and geographies served. Our ability to compete depends, in part, on our ability to attract and retain our associates and on our reputation as well as our ability to keep pace with innovation, in particular in the development of new technology platforms. There can be no assurance, however, that our ability to market products and services successfully or to obtain adequate returns on our products and services will not be impacted by the nature of the competition that now exists or may later develop, or by the broader economic environment. For a discussion of the risks related to our competitive environment, see “Part I—Item 1A. Risk Factors.”

SUPERVISION AND REGULATION

The regulatory framework applicable to banking organizations is intended primarily for the protection of depositors and the stability of the U.S. financial system, rather than for the protection of shareholders and creditors.

As a banking organization, we are subject to extensive regulation and supervision. In addition to banking laws and regulations, we are subject to various other laws and regulations, all of which directly or indirectly affect our operations and management and our ability to make distributions to shareholders. We and our subsidiaries are also subject to supervision and examination by multiple regulators. In addition to laws and regulations, state and federal bank regulatory agencies may issue policy statements, interpretive letters and similar written guidance applicable to us and our subsidiaries. Any change in the statutes, regulations or regulatory policies applicable to us, including changes in their interpretation or implementation, could have a material effect on our business or organization.

Both the scope of the laws and regulations and the intensity of the supervision to which we are subject have increased in recent years, initially in response to the financial crisis, and more recently in light of other factors such as technological, political and market changes. Regulatory enforcement and fines have also increased across the banking and financial services sector.

The descriptions below summarize certain significant state and federal laws to which we are subject. The descriptions are qualified in their entirety by reference to the particular statutory or regulatory provisions summarized. They do not summarize all possible or proposed changes in current laws or regulations and are not intended to be a substitute for the related statues or regulatory provisions.

Banking Regulation

Capital One Financial Corporation is a bank holding company (“BHC”) and a financial holding company (“FHC”) under the Bank Holding Company Act of 1956, as amended (“BHC Act”), and is subject to the requirements of the BHC Act, including approval requirements for investments in or acquisitions of banking organizations, capital adequacy standards and limitations on non-banking activities. As a BHC and FHC, we are subject to supervision, examination and regulation by the Board of Governors of the Federal Reserve System (“Federal Reserve”). Permissible activities for a BHC include those activities that are so closely related to banking as to be a proper incident thereto. In addition, an FHC is permitted to engage in activities

8 Capital One Financial Corporation (COF)

Table of Contents

considered to be financial in nature (including, for example, securities underwriting and dealing and merchant banking activities), incidental to financial activities or, if the Federal Reserve determines that they pose no risk to the safety or soundness of depository institutions or the financial system in general, activities complementary to financial activities.

To become and remain eligible for FHC status, a BHC and its subsidiary depository institutions must meet certain criteria, including capital, management and Community Reinvestment Act (“CRA”) requirements. Failure to meet such criteria could result, depending on which requirements were not met, in restrictions on new financial activities or acquisitions or being required to discontinue existing activities that are not generally permissible for BHCs.

The Banks are national associations chartered under the National Bank Act, and the deposits of which are insured by the Deposit Insurance Fund (“DIF”) of the Federal Deposit Insurance Corporation (“FDIC”) up to applicable limits. The Banks are subject to comprehensive regulation and periodic examination by the Office of the Comptroller of the Currency (“OCC”), the FDIC and the Consumer Financial Protection Bureau (“CFPB”).

We are also registered as a financial institution holding company under the laws of the Commonwealth of Virginia and, as such, we are subject to periodic examination by the Virginia Bureau of Financial Institutions. We also face regulation in the international jurisdictions in which we conduct business. See “Regulation of Businesses by Authorities Outside the United States” below for additional details.

Regulation of Business Activities

The business activities of the Company and the Banks are also subject to regulation and supervision under various laws and regulations.

Regulations of Consumer Lending Activities

The activities of the Banks as consumer lenders are subject to regulation under various federal laws, including, for example, the Truth in Lending Act (“TILA”), the Equal Credit Opportunity Act, the Fair Credit Reporting Act, the CRA, the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 (“Dodd-Frank Act”), the Servicemembers Civil Relief Act and the Military Lending Act, as well as under various state laws. TILA, as amended, imposes a number of restrictions on credit card practices impacting rates and fees, requires that a consumer’s ability to pay be taken into account before issuing credit or increasing credit limits, and imposes revised disclosures required for open-end credit.

Depending on the underlying issue and applicable law, regulators may be authorized to impose penalties for violations of these statutes and, in certain cases, to order banks to compensate customers. Borrowers may also have a private right of action for certain violations. Federal bankruptcy and state debtor relief and collection laws may also affect the ability of a bank, including the Banks, to collect outstanding balances owed by borrowers.

Debit Interchange Fees

The Dodd-Frank Act requires that the amount of any interchange fee received by a debit card issuer with respect to debit card transactions be reasonable and proportional to the cost incurred by the issuer with respect to the transaction. Rules adopted by the Federal Reserve to implement these requirements limit interchange fees per debit card transaction to $0.21 plus five basis points of the transaction amount and provide for an additional $0.01 fraud prevention adjustment to the interchange fee for issuers that meet certain fraud prevention requirements.

Privacy, Data Protection and Cybersecurity

We are subject to multiple federal and state laws concerning privacy, data protection and cybersecurity, such as the Gramm-Leach Bliley Act (“GLBA”). This area has seen an increase in legislative and regulatory activity over the past several years. For example, in 2018, the State of California passed the California Consumer Privacy Act (“CCPA”), which became effective on January 1, 2020. The CCPA and its implementing regulations, as recently amended by the California Privacy Rights Act, create obligations on covered companies to, among other things, share certain information they have collected about individuals who are California residents with those individuals, subject to some exceptions.

In addition, in December 2020, the Federal Reserve, OCC and FDIC (collectively, the “Federal Banking Agencies”) issued a notice of proposed rulemaking that, among other things, would require a banking organization to notify its primary federal regulators within 36 hours after identifying a "computer-security incident" that the banking organization believes in good faith

9 Capital One Financial Corporation (COF)

Table of Contents

could materially disrupt, degrade or impair its business or operations in a manner that would, among other things, jeopardize the viability of its operations, result in customers being unable to access their deposit and other accounts, result in a material loss of revenue, profit or franchise value, or pose a threat to the financial stability of the United States.

We continue to monitor data privacy and cybersecurity legal developments in the jurisdictions in which we do business. For further discussion of privacy, data protection and cybersecurity, and related risks for our business, see “Part I—Item 1A. Risk Factors” under the headings “We face risks related to our operational, technological and organizational infrastructure,” “Theft, loss or misuse of information as a result of a cyber-attack may result in increased costs, reductions in revenue, reputational damage and business disruptions,” and “Potential data protection and privacy incidents, and our required compliance with laws and regulations related to these areas, may increase our costs, result in legal liability, reduce our revenue and limit our ability to pursue business opportunities.”

Anti-Money Laundering and Anti-Terrorism

The Bank Secrecy Act and the USA PATRIOT Act of 2001 (“Patriot Act”) require financial institutions, among other things, to implement a risk-based program reasonably designed to prevent money laundering and to combat the financing of terrorism, including through suspicious activity and currency transaction reporting, compliance, record-keeping and customer due diligence.

The Patriot Act also contains financial transparency laws and provides enhanced information collection tools and enforcement mechanisms to the U.S. government, including due diligence and record-keeping requirements for private banking and correspondent accounts; standards for verifying customer identification at account opening; rules to produce certain records upon request of a regulator or law enforcement agency; and rules to promote cooperation among financial institutions, regulators and law enforcement agencies in identifying parties that may be involved in terrorism, money laundering and other crimes.

The Anti-Money Laundering Act of 2020 (“AML Act”), enacted on January 1, 2021 as part of the National Defense Authorization Act, does not directly impose new requirements on banks, but requires the U.S. Treasury Department to issue National Anti-Money Laundering and Countering the Financing of Terrorism Priorities, and conduct studies and issue regulations that may, over the next few years, significantly alter some of the due diligence, recordkeeping and reporting requirements that the Bank Secrecy Act and Patriot Act impose on banks. The AML Act also contains provisions that promote increased information-sharing and use of technology, and increases penalties for violations of the Bank Secrecy Act and includes whistleblower incentives, both of which could increase the prospect of regulatory enforcement.

Funding

Under the Federal Deposit Insurance Corporation Improvement Act of 1991 (“FDICIA”), as discussed in “MD&A—Liquidity Risk Profile,” only well capitalized and adequately capitalized institutions may accept brokered deposits. Adequately capitalized institutions, however, must obtain a waiver from the FDIC before accepting brokered deposits, and such institutions may not pay rates that significantly exceed the rates paid on deposits of similar maturity obtained from the institution’s normal market area or, for deposits obtained from outside the institution’s normal market area, the national rate on deposits of comparable maturity. In December 2020, the FDIC finalized amendments to the brokered deposit regulation that, among other things, generally clarify and narrow the scope of the "deposit broker" definition. The amendments become effective April 1, 2021.

The FDIC is authorized to terminate a bank’s deposit insurance upon a finding by the FDIC that the bank’s financial condition is unsafe or unsound or that the institution has engaged in unsafe or unsound practices or has violated any applicable rule, regulation, order or condition enacted or imposed by the bank’s regulatory agency.

Broker-Dealer and Investment Advisory Activities

Certain of our non-bank subsidiaries are subject to regulation and supervision by various federal and state authorities. United Income, Inc. is an investment adviser registered with the SEC and primarily regulated under the Investment Advisers Act of 1940. Capital One Securities, Inc. and KippsDeSanto & Company are registered broker-dealers regulated by the SEC and the Financial Industry Regulatory Authority. These broker-dealer subsidiaries are subject, among other things, to net capital rules designed to measure the general financial condition and liquidity of a broker-dealer. Under these rules, broker-dealers are required to maintain the minimum net capital deemed necessary to meet their continuing commitments to customers and others, and to keep a substantial portion of their assets in relatively liquid form. These rules also limit the ability of a broker-dealer to

10 Capital One Financial Corporation (COF)

Table of Contents

transfer capital to its parent companies and other affiliates. Broker-dealers are also subject to regulations covering their business operations, including sales and trading practices, public offerings, publication of research reports, use and safekeeping of client funds and securities, capital structure, record-keeping and the conduct of directors, officers and employees.

Derivatives Activities

Title VII of the Dodd-Frank Act establishes a regulatory framework for the governance of the over-the-counter (“OTC”) derivatives market, including swaps and security-based swaps and the registration of certain market participants as a swap dealer. CONA provisionally registered with the Commodity Futures Trading Commission (the “CFTC”) as a swap dealer in the third quarter of 2020. Registration as a swap dealer subjects CONA to additional regulatory requirements with respect to its swaps and other derivatives activities. As a result of CONA’s swap dealer registration, it is subject to the rules of the OCC concerning capital and margin requirements for swap dealers, including the mandatory exchange of variation margin and initial margin with certain counterparties. Additionally, as a provisionally registered swap dealer, CONA is subject to requirements under the CFTC’s regulatory regime, including rules regarding business conduct standards, recordkeeping obligations, regulatory reporting and procedures relating to swaps trading. CONA’s swaps and other derivatives activities do not require it to register with the SEC as a security-based swap dealer.

Transactions with Affiliates

There are various legal restrictions on the extent to which we and our non-bank subsidiaries may borrow or otherwise engage in certain types of transactions with the Banks. Under the Federal Reserve Act and Federal Reserve regulations, the Banks and their subsidiaries are subject to quantitative and qualitative limits on extensions of credit, purchases of assets, and certain other transactions involving its non-bank affiliates. In addition, transactions between the Banks and their non-bank affiliates are required to be on arm’s length terms and must be consistent with standards of safety and soundness.

Volcker Rule

We and each of our subsidiaries, including the Banks, are subject to the “Volcker Rule,” a provision of the Dodd-Frank Act that contains prohibitions on proprietary trading and certain investments in, and relationships with, covered funds (hedge funds, private equity funds and similar funds), subject to certain exemptions, in each case as the applicable terms are defined in the Volcker Rule and the implementing regulations. The implementing regulations also require that we establish and maintain a compliance program designed to ensure adherence with the requirements of the regulations.

Capital and Liquidity Regulation

The Company and the Banks are subject to capital adequacy guidelines adopted by the Federal Reserve and OCC respectively. For a further discussion of the capital adequacy guidelines, see “MD&A—Capital Management,” “MD&A—Liquidity Risk Profile” and “Note 11—Regulatory and Capital Adequacy.”

Basel III and United States Capital Rules

The Company and the Banks are subject to the regulatory capital requirements established by the Federal Reserve and the OCC respectively (the “Basel III Capital Rules”). The Basel III Capital Rules implement certain capital and liquidity requirements published by the Basel Committee on Banking Supervision (“Basel Committee”), along with certain Dodd-Frank Act and other capital provisions. Under the Basel III Capital Rules, we must maintain a minimum common equity Tier 1 (“CET1”) capital ratio of 4.5%, a Tier 1 capital ratio of 6.0%, and a total capital ratio of 8.0%, in each case in relation to risk-weighted assets. In addition, we must maintain a minimum leverage ratio of 4% and a minimum supplementary leverage ratio of 3%. We are also subject to the capital conservation buffer and countercyclical capital buffer requirements, as described below.

In July 2019, the Federal Banking Agencies finalized certain changes to the Basel III Capital Rules for institutions not subject to the Basel III Advanced Approaches (“Capital Simplification Rule”). These changes, effective January 1, 2020, generally raised the threshold above which a covered institution such as the Company must deduct certain assets from its CET1 capital, including certain deferred tax assets, mortgage servicing assets, and investments in unconsolidated financial institutions.

In October 2019, the Federal Banking Agencies amended the Basel III Capital Rules to provide for tailored application of certain capital requirements across different categories of banking institutions (“Tailoring Rules”). These categories are determined primarily by an institution’s asset size, with adjustments to a more stringent category possible if the institution exceeds certain risk-based thresholds. As a BHC with total consolidated assets of at least $250 billion that does not exceed any

11 Capital One Financial Corporation (COF)

Table of Contents

of the applicable risk-based thresholds, we are a Category III institution under the Tailoring Rules. Therefore, effective January 1, 2020, we were no longer subject to the Basel III “Advanced Approaches” framework and certain associated capital requirements, such as the requirement to include certain elements of accumulated other comprehensive income (“AOCI”) in our regulatory capital. We remain subject to the countercyclical capital buffer requirement (which is currently set at 0%) and supplementary leverage ratio requirement, which were previously required only for Basel III Advanced Approaches institutions. Effective as of the first quarter of 2020, we excluded certain elements of AOCI from our regulatory capital as permitted by the Tailoring Rules. The Tailoring Rules and Capital Simplification Rule have, taken together, decreased our capital requirements.

Global systemically important banks (“G-SIBs”) that are based in the U.S. are subject to an additional CET1 capital requirement (“G-SIB Surcharge”). We are not a G-SIB based on the most recent available data and thus we are not subject to a G-SIB Surcharge.

Stress Capital Buffer Rule

The Basel III Capital Rules also require banking institutions to maintain a capital conservation buffer, composed of CET1 capital, above the regulatory minimum ratios. The capital conservation buffer for BHCs was previously fixed at 2.5%. In March 2020, the Federal Reserve issued a final rule to implement the stress capital buffer requirement (“Stress Capital Buffer Rule”). The stress capital buffer requirement is institution-specific and replaces the fixed 2.5% capital conservation buffer for BHCs.

Pursuant to the Stress Capital Buffer Rule, the Federal Reserve will use the results of its supervisory stress test to determine the size of a BHC’s stress capital buffer requirement. In particular, a BHC’s stress capital buffer requirement will equal, subject to a floor of 2.5%, the sum of (i) the difference between the BHC’s starting CET1 capital ratio and its lowest projected CET1 capital ratio under the severely adverse scenario of the Federal Reserve’s supervisory stress test plus (ii) the ratio of the BHC’s projected four quarters of common stock dividends (for the fourth to seventh quarters of the planning horizon) to the projected risk-weighted assets for the quarter in which the BHC’s projected CET1 capital ratio reaches its minimum under the supervisory stress test.

Under the Stress Capital Buffer Rule framework, the Company’s new “standardized approach capital conservation buffer” includes its stress capital buffer requirement (which will be recalibrated every year based on the Company’s supervisory stress test results), any G-SIB surcharge (which is not applicable to us) and the countercyclical capital buffer requirement (which is currently set at 0%). Any determination to increase the countercyclical capital buffer generally would be effective twelve months after the announcement of such an increase, unless the Federal Banking Agencies set an earlier effective date.

The Stress Capital Buffer Rule does not apply to the Banks. The capital conservation buffer for the Banks continues to be fixed at 2.5%.

If we fail to maintain our capital ratios above the minimum capital requirements plus the applicable buffer requirements, we will face increasingly strict automatic limitations on capital distributions and discretionary bonus payments to certain executive officers.

Under the Basel III Capital Rules, if a banking institution’s capital ratios fall within its buffer requirements, the maximum amount of capital distributions and discretionary bonus payments it can make is a function of its eligible retained income. In March 2020, the Federal Banking Agencies revised the definition of “eligible retained income” in their respective capital rules. Under the revised definition of “eligible retained income,” any such automatic limitations on capital distributions would apply in a less severe and more gradual manner than would otherwise have occurred under the previous definition of that term. This change was made in response to the COVID-19 pandemic to support banking organizations that choose to use their capital and liquidity buffers to lend and undertake other actions that support economic activity in a safe and sound manner.

CECL TransitionRule

As part of the response to the COVID-19 pandemic, the Federal Banking Agencies adopted a final rule (“2020 CECL Transition Rule”) that provides banking institutions an optional five-year transition period to phase in the impact of the CECL standard on their regulatory capital (the “2020 CECL Transition Election”).

Pursuant to the 2020 CECL Transition Rule, a banking institution may elect to delay the estimated impact of adopting CECL on its regulatory capital through December 31, 2021 and then phase in the estimated cumulative impact from January 1, 2022 through December 31, 2024. For the “day 2” ongoing impact of CECL during the initial two years, the Federal Banking Agencies use a uniform “scaling factor” of 25% as an approximation of the increase in the allowance under the CECL standard

12 Capital One Financial Corporation (COF)

Table of Contents

compared to the prior incurred loss methodology. Accordingly, from January 1, 2020 through December 31, 2021, electing banking institutions are permitted to add back to their regulatory capital an amount equal to the sum of the after-tax “day 1” CECL adoption impact and 25% of the increase in the allowance since the adoption of the CECL standard. Beginning January 1, 2022 through December 31, 2024, the after-tax “day 1” CECL adoption impact and the cumulative “day 2” ongoing impact will be phased in to regulatory capital at 25% per year. The following table summarizes the capital impact delay and phase in period on our regulatory capital from years 2020 to 2025.

Capital Impact Delayed Phase In Period

We adopted the CECL standard (for accounting purposes) as of January 1, 2020, and made the 2020 CECL Transition Election (for regulatory capital purposes) in the first quarter of 2020.

Temporary Exclusions for Supplementary Leverage Ratio

In addition, in April 2020, as part of the response to the COVID-19 pandemic, the Federal Reserve issued an interim final rule that temporarily excludes U.S. Treasury securities and deposits at Federal Reserve Banks from the calculation of the supplementary leverage ratio for BHCs. These exclusions became effective on April 1, 2020, and will remain in effect through March 31, 2021.

Subsequently, in May 2020, the Federal Banking Agencies issued an interim final rule that provides an option for depository institutions to make similar exclusions to the calculation of the supplementary leverage ratio. If a depository institution elects to make such exclusions, it must request prior approval from its primary federal banking regulator before making capital distributions, such as paying dividends to its parent company, for as long as the exclusions are in effect. Neither CONA nor COBNA elected to make such exclusions.

Market Risk Rule

The “Market Risk Rule” supplements the Basel III Capital Rules by requiring institutions subject to the Market Risk Rule to adjust their risk-based capital ratios to reflect the market risk in their trading portfolios. The Market Risk Rule generally applies to institutions with aggregate trading assets and liabilities equal to the lesser of 10% or more of total assets or $1 billion or more. The Company and CONA are subject to the Market Risk Rule. See “MD&A—Market Risk Profile” below for additional information.

FDICIA and Prompt Corrective Action

The FDICIA requires the Federal Banking Agencies to take “prompt corrective action” for banks that do not meet minimum capital requirements. The FDICIA establishes five capital ratio levels: well capitalized; adequately capitalized; undercapitalized; significantly undercapitalized; and critically undercapitalized. The three undercapitalized categories are based upon the amount by which a bank falls below the ratios applicable to an adequately capitalized institution. The capital categories relate to the FDICIA’s prompt corrective action (“PCA”) provisions, and such capital categories may not constitute an accurate representation of the Banks’ overall financial condition or prospects.

The Basel III Capital Rules updated the PCA framework to reflect new, higher regulatory capital minimums. For an insured depository institution to be well capitalized, it must maintain a total risk-based capital ratio of 10% or more; a Tier 1 capital ratio of 8% or more; a CET1 capital ratio of 6.5% or more; and a leverage ratio of 5% or more. An adequately capitalized depository institution must maintain a total risk-based capital ratio of 8% or more; a Tier 1 capital ratio of 6% or more; a CET1 capital ratio of 4.5% or more; a leverage ratio of 4% or more; and, for Category III and certain other institutions under the Tailoring Rules, a supplementary leverage ratio of 3% or more. The PCA provisions also authorize the Federal Banking Agencies to reclassify a bank’s capital category or take other action against banks that are determined to be in an unsafe or unsound condition or to have engaged in unsafe or unsound banking practices.

13 Capital One Financial Corporation (COF)

Table of Contents

As an additional means to identify problems in the financial management of depository institutions, the FDICIA required the Federal Banking Agencies to establish certain non-capital safety and soundness standards. The standards adopted by the Federal Banking Agencies relate generally to operations and management, asset quality, interest rate exposure and executive compensation. The Federal Banking Agencies are authorized to take action against institutions that fail to meet such standards.

Basel III and United States Liquidity Rules

The Basel Committee has published a liquidity framework that includes two standards for liquidity risk supervision. One standard, the liquidity coverage ratio (“LCR”), seeks to promote short-term resilience by requiring organizations to hold sufficient high-quality liquid assets (“HQLAs”) to survive a stress scenario lasting for 30 days. The other standard, the net stable funding ratio (“NSFR”), seeks to promote longer-term resilience by requiring sufficient stable funding over a one-year period based on the liquidity characteristics of the organization’s assets and activities.

The Company and the Banks are subject to the LCR standard as implemented by the Federal Reserve and OCC (the “LCR Rule”). The LCR Rule requires the Company and each of the Banks to hold an amount of eligible HQLA that equals or exceeds 100% of its respective projected adjusted net cash outflows over a 30-day period, each as calculated in accordance with the LCR Rule. The LCR Rule requires us to calculate our LCR daily. In addition, the Company is required to make quarterly public disclosures of its LCR and certain related quantitative liquidity metrics, along with a qualitative discussion of its LCR.

Under the Tailoring Rules, as a Category III institution with less than $75 billion in weighted average short-term wholesale funding, the Company’s and the Banks’ total net cash outflows are multiplied by an outflow adjustment percentage of 85%. Although the Banks may hold more HQLA than they need to meet their LCR requirements, the LCR Rule restricts the amount of such excess HQLA held at the Banks (referred to as “Trapped Liquidity”) that can be included in the Company’s HQLA amount. Because we typically manage the Banks’ LCRs to levels well above 100%, the amount of Trapped Liquidity will also increase as the Banks’ total net cash outflows are reduced by the outflow adjustment percentage of 85%.

In October 2020, the Federal Banking Agencies finalized a rule to implement the NSFR in the United States (the “NSFR Rule”). The NSFR Rule requires the Company and each of the Banks to maintain an amount of available stable funding, which is a weighted measure of a company’s funding sources over a one-year time horizon, calculated by applying standardized weightings to equity and liabilities based on their expected stability, that is no less than the amount of required stable funding, which is calculated by applying standardized weightings to assets, derivatives exposures and certain other items based on their liquidity characteristics. As a Category III institution, the Company and the Banks are subject to an NSFR requirement equal to 85% of the full NSFR requirement. The NSFR Rule will become effective as of July 1, 2021 and will apply to the Company and each of the Banks. The NSFR Rule includes a semi-annual disclosure requirement, with the first public disclosure required after June 30, 2023.

Enhanced Prudential Standards and Other Related Requirements

We are subject to certain enhanced prudential standards under the Dodd-Frank Act, as amended by the Economic Growth, Regulatory Relief, and Consumer Protection Act (“EGRRCPA”) and implemented by various regulations issued by the Federal Banking Agencies. The Financial Stability Oversight Council (“FSOC”) may also issue recommendations to the Federal Reserve or other primary financial regulatory agencies to apply new or enhanced standards to certain financial activities or practices.

As part of the enhanced prudential standards, the Company is required to implement resolution planning for orderly resolution in the event it faces material financial distress or failure. The FDIC issued similar rules regarding resolution planning applicable to the Banks. In addition, the OCC has issued rules requiring banks with assets of $250 billion or more to develop recovery plans detailing the actions they would take to remain a going concern when they experience considerable financial or operational stress, but have not deteriorated to the point that resolution is imminent.

The enhanced prudential standards also include supervisory and company-run stress testing requirements (also known as the “DFAST stress testing requirements”). In particular, the Federal Reserve is required to conduct annual stress tests on certain covered companies, including us, to ensure that the covered companies have sufficient capital to absorb losses and continue operations during adverse economic conditions. Under the stress capital buffer framework, the result of our supervisory stress test will be used to determine our stress capital buffer requirement. As a covered company that is a Category III institution under the Tailoring Rules, we are also required to conduct our own stress tests and publish the results of such tests on our website or other public forum. The Company must disclose the results of its company-run stress test on a biennial basis. The

14 Capital One Financial Corporation (COF)

Table of Contents

OCC has adopted a similar stress test rule requiring banks with at least $250 billion in assets, including CONA, to conduct their own company-run stress tests. Under that OCC rule, CONA must also disclose the results of its stress test on a biennial basis.

In addition, the Company is required to meet liquidity risk management standards, conduct internal liquidity stress tests, and maintain a 30-day buffer of highly liquid assets, in each case, consistent with the requirements of the enhanced prudential standards. These requirements are in addition to the LCR and NSFR Rules, discussed above in “Basel III and United States Liquidity Rules.” The enhanced prudential standards also require that the Company comply with, and hold capital commensurate with, the requirements of, any regulations adopted by the Federal Reserve relating to capital planning and stress tests. Stress testing and capital planning regulations are discussed further below under “Dividends, Stock Repurchases and Transfers of Funds.” Finally, the Company is also required to establish and maintain an enterprise-wide risk management framework that includes a risk committee and a chief risk officer.

Although not a requirement of the Dodd-Frank Act, the OCC established regulatory guidelines (“Heightened Standards Guidelines”) that apply heightened standards to the governance and risk management practices of large institutions subject to its supervision, including the Banks. The Heightened Standards Guidelines establish standards for the development and implementation by the Banks of a risk governance framework.

Dividends, Stock Repurchases and Transfers of Funds

Under the Federal Reserve’s capital planning rules (commonly referred to as Comprehensive Capital Analysis and Review or “CCAR” requirements), a “covered BHC,” such as the Company, must submit a capital plan to the Federal Reserve on an annual basis that contains a description of all planned capital actions, including dividends or stock repurchases, over a nine-quarter planning horizon beginning with the first quarter of the calendar year the capital plan is submitted (“CCAR cycle”).

The DFAST stress testing requirements, described above in “Enhanced Prudential Standards and Other Related Requirements,” is a complementary exercise to CCAR. It is a forward-looking exercise conducted by the Federal Reserve and each covered company to help assess whether a company has sufficient capital to absorb losses and continue operations during adverse economic conditions.

Pursuant to the CCAR requirements, the Company must file its capital plan and stress testing results with the Federal Reserve by April 5 of each year (unless the Federal Reserve designates a later date), using data as of the end of the prior calendar year. The Federal Reserve will conduct its supervisory stress test in the second quarter and determine the Company’s stress capital buffer by June 30 of that year. The Company will have two business days from receipt of its stress capital buffer to make any necessary adjustments to its planned capital distributions. The Federal Reserve will then finalize the stress capital buffer requirement for the Company based on its adjusted planned capital distributions and confirm the Company’s planned capital distributions by August 31 of that year. The Company’s final stress capital buffer requirement will be effective from the fourth quarter of the year the capital plan is submitted through the third quarter of the following year. The Company may make the planned capital distributions confirmed by the Federal Reserve. In addition, under the Stress Capital Buffer Rule, the Company is no longer required to seek prior approval of the Federal Reserve to make capital distributions in excess of those included in its capital plan so long as the Company is otherwise in compliance with the capital rule’s automatic limitations on capital distributions.

In December 2018, the Federal Reserve announced that it would maintain its pre-CECL framework for calculating allowances on loans in the supervisory stress test for the 2020 and 2021 cycles until the impact of CECL is better known and understood. The Federal Reserve stated further that, although BHCs required to perform company-run stress tests will be required to incorporate CECL into those stress tests starting in the 2020 cycle, it will not issue supervisory findings on those BHCs’ allowance estimations in the CCAR exercise through 2021.

Historically, dividends from the Company’s direct and indirect subsidiaries have represented a major source of the funds we have used to pay dividends on our capital stock, make payments on our corporate debt securities and meet our other obligations. There are various federal law limitations on the extent to which the Banks can finance or otherwise supply funds to the Company through dividends and loans. These limitations include minimum regulatory capital requirements, federal banking law requirements concerning the payment of dividends out of net profits or surplus, provisions of Sections 23A and 23B of the Federal Reserve Act and Regulation W governing transactions between an insured depository institution and its affiliates, as well as general federal regulatory oversight to prevent unsafe or unsound practices. In general, federal and applicable state banking laws prohibit insured depository institutions, such as the Banks, from making dividend distributions without first

15 Capital One Financial Corporation (COF)

Table of Contents

obtaining regulatory approval if such distributions are not paid out of available earnings or would cause the institution to fail to meet applicable capital adequacy standards.

In June 2020, in light of the COVID-19 pandemic, the Federal Reserve required all CCAR participating BHCs, including us, to update and resubmit their capital plans in the fourth quarter of 2020. In addition, the Federal Reserve required all participating BHCs, including us, to preserve capital by suspending share repurchases and capping common stock dividend payments for the third and fourth quarters of 2020 to the lower of (i) the amount paid in the second quarter of 2020 and (ii) an amount equal to the average net income earned across the four preceding calendar quarters. Scheduled payments on additional Tier 1 and Tier 2 capital instruments, such as preferred stock and subordinated debt, were not similarly restricted.

We conducted a second round of stress tests and submitted our updated capital plan to the Federal Reserve on November 2, 2020. On December 18, 2020, the Federal Reserve released the results of its second round of supervisory stress tests. The Federal Reserve did not recalculate our stress capital buffer requirement at that time, but reserved its ability to do so until March 31, 2021. Finally, the Federal Reserve extended the capital distribution restrictions for all participating BHCs through at least the first quarter of 2021, with certain modifications. In particular, for the first quarter of 2021, participating BHCs may resume share repurchases, but the aggregate amount of common stock dividend payments and share repurchases shall not exceed an amount equal to the average net income earned across the four preceding calendar quarters. In addition, common stock dividend payments for the first quarter of 2021 continue to be capped at the amount paid in the second quarter of 2020.

Investment in the Company and the Banks

Certain acquisitions of our capital stock may be subject to regulatory approval or notice under federal or state law. Investors are responsible for ensuring that they do not, directly or indirectly, acquire shares of our capital stock in excess of the amount that can be acquired without regulatory approval, including under the BHC Act and the Change in Bank Control Act (“CIBC Act”).

Federal law and regulations prohibit any person or company from acquiring control of the Company or the Banks without, in most cases, prior written approval of the Federal Reserve or the OCC, as applicable. Control under the BHC Act exists if, among other things, a person or company acquires more than 25% of any class of our voting stock or otherwise has a controlling influence over us. A rebuttable presumption of control arises under the CIBC Act for a publicly traded BHC such as ourselves if a person or company acquires more than 10% of any class of our voting stock.

Additionally, COBNA and CONA are “banks” within the meaning of Chapter 13 of Title 6.1 of the Code of Virginia governing the acquisition of interests in Virginia financial institutions (“Financial Institution Holding Company Act”). The Financial Institution Holding Company Act prohibits any person or entity from acquiring, or making any public offer to acquire, control of a Virginia financial institution or its holding company without making application to, and receiving prior approval from, the Virginia Bureau of Financial Institutions.

Deposit Insurance Assessments

Each of CONA and COBNA, as an insured depository institution, is a member of the DIF maintained by the FDIC. Through the DIF, the FDIC insures the deposits of insured depository institutions up to prescribed limits for each depositor. The FDIC sets a Designated Reserve Ratio (“DRR”) for the DIF. To maintain the DIF, member institutions may be assessed an insurance premium, and the FDIC may take action to increase insurance premiums if the DRR falls below its required level.

As of June 30, 2020, the DIF reserve ratio fell to 1.30 percent. The FDIC, as required under the Federal Deposit Insurance Act, established a plan in September 2020, to restore the DIF reserve ratio to meet or exceed 1.35 percent within eight years. The FDIC’s restoration plan projects the reserve ratio to exceed 1.35 percent without increasing the deposit insurance assessment rate, subject to ongoing monitoring over the next eight years.

Source of Strength and Liability for Commonly Controlled Institutions

Under regulations issued by the Federal Reserve, a BHC must serve as a source of financial and managerial strength to its subsidiary banks (the so-called “source of strength doctrine”). The Dodd-Frank Act codified this doctrine.

Under the “cross-guarantee” provision of the Financial Institutions Reform, Recovery and Enforcement Act of 1989 (“FIRREA”), insured depository institutions such as the Banks may be liable to the FDIC with respect to any loss incurred, or reasonably anticipated to be incurred, by the FDIC in connection with the default of, or FDIC assistance to, any commonly

16 Capital One Financial Corporation (COF)

Table of Contents

controlled insured depository institution. The Banks are commonly controlled within the meaning of the FIRREA cross-guarantee provision.

FDIC Orderly Liquidation Authority

The Dodd-Frank Act provides the FDIC with liquidation authority that may be used to liquidate non-bank financial companies and BHCs if the Treasury Secretary, in consultation with the President and based on the recommendation of the Federal Reserve and other appropriate Federal Banking Agencies, determines that doing so is necessary, among other criteria, to mitigate serious adverse effects on U.S. financial stability. Upon such a determination, the FDIC would be appointed receiver and must liquidate the company in a way that mitigates significant risks to financial stability and minimizes moral hazard. The costs of a liquidation of the company would be borne by shareholders and unsecured creditors and then, if necessary, by risk-based assessments on large financial companies. The FDIC has issued rules implementing certain provisions of its liquidation authority and may issue additional rules in the future.

COVID-19 Activities

In response to disruptions in economic conditions caused by the COVID-19 pandemic, federal and state governments and agencies and government‐sponsored enterprises have taken a variety of actions to support people and entities affected by the pandemic, including the passage of the Coronavirus Aid, Relief, and Economic Security Act (the “CARES Act”) in March 2020. The CARES Act, among other provisions, authorized a number of lending programs to support the flow of credit to consumers and businesses. For example, the CARES Act established several programs with the Small Business Administration, including the PPP, to provide loans to small businesses.

The Federal Reserve had also taken extraordinary efforts in response to the pandemic, including, among other actions, the establishment of a Main Street Lending Program that is intended to support lending to eligible small and midsize businesses. The Federal Banking Agencies had also encouraged banking organizations to take certain additional actions to support the financial services needs of their customers in a prudent and safe and sound manner, including through loan modifications. Further, banking organizations had been provided with certain accounting, supervisory and regulatory relief during this period, including relief that is intended to allow banking organizations to enter into loan modifications without certain accounting and regulatory capital consequences. For example, the CARES Act gave banking organizations an option to temporarily suspend the determination of certain qualified loans modified as a result of the COVID-19 pandemic as being troubled debt restructurings (“TDRs”). See “MD&A—Credit Risk Profile—COVID-19 Customer Assistance Programs and Loan Modifications” for additional information. The CARES Act also amended the Fair Credit Reporting Act to impose new, temporary reporting requirements on furnishers of information to consumer reporting agencies related to accounts of consumers in payment accommodation programs in light of the COVID-19 pandemic.

The Consolidated Appropriations Act, 2021, which was enacted in December 2020, extends certain relief provided by the CARES Act while also modifying or clarifying certain other provisions. Among other amendments to the CARES Act, the Consolidated Appropriations Act, 2021, extends the relief related to TDRs until January 1, 2022 and the PPP until March 31, 2021. In addition, the Consolidated Appropriations Act, 2021, rescinds certain funds that were appropriated to the U.S. Treasury to provide loans, loan guarantees, and make other investments in programs or facilities established by the Federal Reserve, and prohibits the Federal Reserve from making any new investments, loans or loan guarantees, or extensions of credit through those rescinded funds after December 31, 2020. Congress could determine to reauthorize these programs in future legislative packages. Federal Reserve programs and facilities that were not established using CARES Act funding are not affected by the Consolidated Appropriations Act, 2021.

For a discussion of the risks associated with the impact of the COVID-19 pandemic and related public health measures, see “Part I—Item 1A. Risk Factors” under the heading “The COVID-19 pandemic has adversely impacted our business, operations and financial results, and the extent to which the pandemic and measures taken in response to the pandemic could materially and adversely impact our business, operations, financial condition, liquidity, capital and results of operations will depend on future developments, which are highly uncertain and are difficult to predict.”

Regulation of Businesses by Authorities Outside the United States

COBNA is subject to regulation in foreign jurisdictions where it operates, currently in the United Kingdom (“U.K.”) and Canada.

17 Capital One Financial Corporation (COF)

Table of Contents

United Kingdom

In the United Kingdom, COBNA operates through COEP, which was established in 2000 and is an authorized payment institution regulated by the Financial Conduct Authority (“FCA”) under the Payment Services Regulations 2017 and the Financial Services and Markets Act 2000. COEP’s indirect parent, Capital One Global Corporation, is wholly-owned by COBNA and is subject to regulation by the Federal Reserve as an “agreement corporation” under the Federal Reserve’s Regulation K.

Previously, the FCA set a deadline of August 29, 2019 (“the Deadline”) for the submission of complaints to firms (including COEP) that had previously sold Payment Protection Insurance (“PPI”) to its customers. In order to ensure complainants are treated fairly, the FCA closely supervises all large lenders (including COEP). COEP has now finished handling almost all complaints it received prior to the Deadline and is in the process of finalizing all remaining complaints, through continued discussions with third parties. Escalations to the Financial Ombudsman Service (“FOS”) are permitted to take place until the first quarter of 2021.

Canada

In Canada, COBNA operates as an authorized foreign bank pursuant to the Bank Act (Canada) (“Bank Act”) and is permitted to conduct its credit card business in Canada through its Canadian branch, Capital One Bank (Canada Branch) (“Capital One Canada”). The primary regulator of Capital One Canada is the Office of the Superintendent of Financial Institutions. Other regulators include the Financial Consumer Agency of Canada (“FCAC”), the Office of the Privacy Commissioner of Canada, and the Financial Transactions and Reports Analysis Centre of Canada. Capital One Canada is subject to regulation under various Canadian federal laws, including the Bank Act and its regulations, the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and the Personal Information Protection and Electronic Documents Act.

On December 13, 2018, Bill C-86, Budget Implementation Act, 2018, No. 2 was passed by Parliament. Among other things, Bill C-86 amends the Bank Act (Canada) to consolidate and strengthen provisions that apply to banks and authorized foreign banks in the areas of consumer protection, corporate governance, business practices, public reporting, disclosure of information and access to basic banking services. Bill C-86 also amends the FCAC Act to enhance the role and powers of the FCAC by increasing the maximum penalty for a violation of the consumer protection provisions of the Bank Act from 50,000 Canadian dollars (“CAD”) for natural persons and 500,000 CAD in the case of financial institutions or a payment card network to 1 million CAD and 10 million CAD, respectively. We are continuing to analyze the impacts of Bill C-86 and the final regulations related thereto in order to determine its applicability and impact to our business.

In August 2018, the Government of Canada announced new voluntary commitments from Visa Canada and MasterCard Canada, which took effect when the original commitments ended in 2020. As part of their new commitments, Visa and Mastercard will further reduce interchange fees for consumer credit cards by approximately 10 basis points to an annual average effective rate of 1.4% for a period of five years. Visa and Mastercard will also narrow the range of interchange rates (lowest vs. highest fee) charged to businesses.

18 Capital One Financial Corporation (COF)

Table of Contents

HUMAN CAPITAL RESOURCES

Our culture is rooted in putting people first with a focus on building and maintaining a workforce which fosters an inclusive environment based on diversity of our people, ideas and the merit of our work. Our workforce is our largest and one of our most valuable assets. We prioritize the recruitment, development, recognition, and retention of the 51,985 employees worldwide that we had as of December 31, 2020, whom we refer to as “associates.” The following disclosures provide information on our human capital resources, including certain human capital objectives and measures that we focus on in managing our business.

Governance of Human Capital

Our full Board of Directors oversees our human capital management, including strategies, policies and practices, and diversity, inclusion and belonging (“DIB”), and is assisted by our Board’s Compensation Committee and Governance and Nominating Committee. Our Executive Committee, a committee of senior management which includes our Chief Human Resources Officer, advises, assists and makes recommendations to our Chief Executive Officer and Board of Directors on human capital matters such as human resource practices and programs, including general employee benefits and compensation programs. Our Chief Diversity, Inclusion and Belonging Officer (“Chief DIB Officer”) provides an annual update on the progress, success and challenges on workforce representation, trends and programs to the Board of Directors and Executive Committee.

Hiring, Retention and Development

We employ a comprehensive people strategy that includes significant investments in recruiting, sourcing, and associate development to attract and retain top talent from all backgrounds to help drive our business’ long-term success. We recruit through a variety of channels, including professional partnerships, job fairs, online platforms, on-campus recruiting, diversity-related recruiting events and initiatives, and internship and rotational programs, among others. We empower our associates to learn new skills, meet personalized development goals, and grow their careers. Investment in associate training and professional development is critical to maintaining our talent competitiveness. Our internal enterprise learning and development team blends multiple approaches to learning to support associate development across lines of business, levels, and roles, including online and live classroom training. In addition to formal programming provided by learning professionals, including regulatory compliance, role-specific topics and others, our peer-to-peer learning strategy empowers associates to be both learners and teachers, further enhancing a culture of learning. We also focus on cultivating talent with leadership development courses, cohort-based programs, network building, and coaching.

On a quarterly basis, we review our ability to attract and retain talent needed to deliver on our strategic business objectives. Each line of business and staff group reviews hiring, tenure and attrition metrics as part of this assessment, and they implement mitigation plans when needed.

Diversity, Inclusion and Belonging

We continuously strive to empower our associates to do great work by creating an inclusive workplace and a culture of belonging that values diverse perspectives, fosters collaboration and encourages innovative ideas. We aim to create a place where associates of all backgrounds can thrive by bringing their best, most authentic selves to work. Our diversity and inclusion efforts are overseen by our Chief DIB Officer. This culture of belonging rests at the heart of our DIB efforts. Central to this effort are our business resource groups, associate-led organizations which deepen our understanding of different cultures, people and experiences, and enable associates to build connections, invest in their professional development, and support our commitment to attract, develop and retain a diverse workforce. In addition, our Chief Executive Officer and the Executive Committee engage with leaders of our business resource groups to identify opportunities to further our DIB agenda, enact positive change and build on existing initiatives designed to nurture our culture and workplace environment.

Growing the diversity of our workforce at all levels, with an emphasis on leader and executive roles, is an important component of our comprehensive DIB strategy. As of December 31, 2020, key measures of our workforce representation include:

•Of the 11 members of our Board of Directors, 4 are women and 3 are people of color;

•In the U.S., of the associates who are vice president level and above, approximately 32% are women and 21% are people of color;

•In the U.S., approximately 50% of associates are people of color; and

19 Capital One Financial Corporation (COF)

Table of Contents

•Worldwide, approximately 52% of associates are women, 47% of associates are men, and 1% of associates are undisclosed/other.

Our corporate website contains additional information regarding programs and other information integral to our philosophy of diversity, inclusion and belonging. We believe in the importance of transparency and will also provide on our website the 2020 Consolidated EEO-1 Report upon submission to the U.S. Equal Employment Opportunity Commission.

Compensation and Wellness

We are committed to providing a competitive total compensation package that will attract, retain and motivate talent to help drive our business’ long-term success. Our benefits, including competitive parental leave, on-site health centers, flexible work solutions, company contributions to associates’ 401(k) plans, educational assistance and other health, wellness, and financial benefits, are all designed to help associates grow and develop inside and outside of the workplace and empower them in their lives. Furthermore, pay equity has long been a core tenet of our pay philosophy and is central to our values. We annually evaluate base pay and incentive pay for all of our associates globally. This review and evaluation may occur more frequently as deemed necessary and prudent. We review groups of associates in similar roles, adjusting for factors that appropriately explain differences in pay such as job location and experience. Based on our analysis, our aggregated adjusted pay gap results show that we pay women 100% of what men are paid, and we pay racial and ethnic minorities in the U.S. 100% of what non-minorities are paid. We use statistical modeling to understand what drives pay gaps, instill new practices to eliminate them in the future, and if we find unexplained pay gaps, we close them.

In 2020, a significant majority of our associates across our workforce have transitioned to working remotely as we prioritize the safety of our associates during the COVID-19 pandemic. For more information on our response to the pandemic, please refer to Part I—Item 1.—Business—Overview—Coronavirus Disease 2019 (COVID-19) Pandemic.

Communication and Connection

We communicate with our associates regularly to understand their perspectives and to hear their voices. Our senior leaders and Chief Executive Officer also communicate directly on societal events impacting our associates. To assess and improve associate retention and engagement, the Company surveys associates on a periodic basis with the assistance of third-party consultants, and takes actions to address areas of associate concern. We encourage full participation and use the results to effect change and promote transparency.

20 Capital One Financial Corporation (COF)

Table of Contents

ADDITIONAL INFORMATION

Technology/Systems

We leverage information and technology to achieve our business objectives and to develop and deliver products and services that satisfy our customers’ needs. A key part of our strategic focus is the development and use of efficient, flexible computer and operational systems, such as cloud technology, to support complex marketing and account management strategies, the servicing of our customers, and the development of new and diversified products. We believe that the continued development and integration of these systems is an important part of our efforts to reduce costs, improve quality and security and provide faster, more flexible technology services. Consequently, we continuously review capabilities and develop or acquire systems, processes and competencies to meet our unique business requirements.

As part of our continuous efforts to review and improve our technologies, we may either develop such capabilities internally or rely on third-party outsourcers who have the ability to deliver technology that is of higher quality, lower cost, or both. We continue to rely on third-party outsourcers to help us deliver systems and operational infrastructure. These relationships include (but are not limited to): Amazon Web Services, Inc. (“AWS”) for our cloud infrastructure, Total System Services LLC (“TSYS”) for consumer and commercial credit card processing services for our North American and U.K. portfolios, Fidelity Information Services (“FIS”) for certain of our banking systems and International Business Machines Corporation for mainframe managed services.

We are committed to safeguarding our customers’ and our own information and technology, implementing backup and recovery systems, and generally require the same of our third-party service providers. We take measures that mitigate against known attacks and use internal and external resources to scan for vulnerabilities in platforms, systems, and applications necessary for delivering our products and services. For a discussion of the risks associated with our use of technology systems, see “Part I—Item 1A. Risk Factors” under the headings “We face risks related to our operational, technological and organizational infrastructure” and “Increased costs, reductions in revenue, reputational damage and business disruptions can result from the theft, loss or misuse of information, including as a result of a cyber-attack.”

Intellectual Property

As part of our overall and ongoing strategy to protect and enhance our intellectual property, we rely on a variety of protections, including copyrights, trademarks, trade secrets, patents and certain restrictions on disclosure, solicitation and competition. We also undertake other measures to control access to, or distribution of, our other proprietary information. Despite these precautions, it may be possible for a third party to copy or otherwise obtain and use certain intellectual property or proprietary information without authorization. Our precautions may not prevent misappropriation or infringement of our intellectual property or proprietary information. In addition, our competitors and other third parties also file patent applications for innovations that are used in our industry. The ability of our competitors and other third parties to obtain patents may adversely affect our ability to compete and our financial results. Conversely, our ability to obtain patents may increase our competitive advantage, preserve our freedom to operate, and allow us to enter into licensing (e.g., cross-licenses) or other arrangements with third parties. There can be no assurance that we will be successful in such efforts, or that the ability of our competitors to obtain such patents may not adversely impact our financial results. For a discussion of risks associated with intellectual property, see “Part I—Item 1A. Risk Factors” under the heading “If we are not able to protect our intellectual property, our revenue and profitability could be negatively affected.”

21 Capital One Financial Corporation (COF)

Table of Contents

FORWARD-LOOKING STATEMENTS

From time to time, we have made and will make forward-looking statements, including those that discuss, among other things, strategies, goals, outlook or other non-historical matters; projections, revenues, income, returns, expenses, capital measures, capital allocation plans, accruals for claims in litigation and for other claims against us; earnings per share, efficiency ratio, operating efficiency ratio, or other financial measures for us; future financial and operating results; our plans, objectives, expectations and intentions; and the assumptions that underlie these matters.

To the extent that any such information is forward-looking, it is intended to fit within the safe harbor for forward-looking information provided by the Private Securities Litigation Reform Act of 1995.

Forward-looking statements often use words such as “will,” “anticipate,” “target,” “expect,” “estimate,” “intend,” “plan,” “goal,” “believe,” “forecast,” “outlook” or other words of similar meaning. Any forward-looking statements made by us or on our behalf speak only as of the date they are made or as of the date indicated, and we do not undertake any obligation to update forward-looking statements as a result of new information, future events or otherwise. For additional information on factors that could materially influence forward-looking statements included in this Report, see the risk factors set forth under “Part I—Item 1A. Risk Factors” in this report. You should carefully consider the factors discussed above, and in our Risk Factors or other disclosure, in evaluating these forward-looking statements.

Numerous factors could cause our actual results to differ materially from those described in such forward-looking statements, including, among other things:

•the impact of the COVID-19 pandemic and related public health measures on our business, financial condition and results of operations, including the increased estimation and forecast uncertainty as a result of the pandemic on our estimates of lifetime expected credit losses in our loan portfolios required in computing our allowance for credit losses;

•general economic and business conditions in our local markets, including conditions affecting employment levels, interest rates, tariffs, collateral values, consumer income, creditworthiness and confidence, spending and savings that may affect consumer bankruptcies, defaults, charge-offs and deposit activity;

•an increase or decrease in credit losses, or increased delinquencies, including increases due to a worsening of general economic conditions in the credit environment, and the impact of inaccurate estimates or inadequate reserves;

•compliance with new and existing laws, regulations and regulatory expectations including the implementation of a regulatory reform agenda;

•our ability to manage adequate capital or liquidity levels, which could have a negative impact on our financial results and our ability to return capital to our stockholders;

•the extensive use, reliability, disruption, and accuracy of the models and data we rely on;

•increased costs, reductions in revenue, reputational damage, legal liability and business disruptions that can result from data protection or privacy incidents or the theft, loss or misuse of information, including as a result of a cyber-attack;

•developments, changes or actions relating to any litigation, governmental investigation or regulatory enforcement action or matter involving us;

•the amount and rate of deposit growth and changes in deposit costs;

•our ability to execute on our strategic and operational plans;

•our response to competitive pressures;

•our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit card networks and by legislation and regulation impacting such fees;

•our success in integrating acquired businesses and loan portfolios, and our ability to realize anticipated benefits from announced transactions and strategic partnerships;

22 Capital One Financial Corporation (COF)

Table of Contents

•our ability to maintain a compliance, operational, technology and organizational infrastructure suitable for the nature of our business;

•the success of our marketing efforts in attracting and retaining customers;

•our risk management strategies;

•changes in the reputation of, or expectations regarding, the financial services industry or us with respect to practices, products or financial condition;

•increases or decreases in interest rates and uncertainty with respect to the interest rate environment, including the possibility of a prolonged low-interest rate environment or of negative interest rates;

•uncertainty regarding, and transition away from, the London Interbank Offering Rate;

•our ability to attract, retain and motivate skilled employees;

•our assumptions or estimates in our financial statements;

•limitations on our ability to receive dividends from our subsidiaries;

•the soundness of other financial institutions and other third parties; and

•other risk factors identified from time to time in our public disclosures, including in the reports that we file with the SEC.

We expect that the effects of the COVID-19 pandemic will heighten the risks associated with many of these factors.

Item 1A. Risk Factors

This section highlights significant factors, events, and uncertainties that make an investment in our securities risky. The events and consequences discussed in these risk factors could, in circumstances we may not be able to accurately predict, recognize, or control, have a material adverse effect on our business, growth, reputation, prospects, financial condition, operating results, cash flows, liquidity, and stock price. These risk factors do not identify all risks that we face; our operations could also be affected by factors, events, or uncertainties that are not presently known to us or that we currently do not consider to present significant risks to our operations. In addition, the global economic and political climate may amplify many of these risks.

Summary of Risk Factors

Below is a summary of the principal factors that make an investment in our securities risky. This summary does not address all of the risks that we face. Additional discussion of the risks summarized in this risk factor summary, and other risks that we face, can be found below and should be carefully considered, together with other information in this Form 10-K and our other filings with the SEC, before making an investment decision regarding our common stock.

•The COVID-19 pandemic has adversely impacted our business and financial results, and the extent to which the pandemic and measures taken in response to the pandemic could materially and adversely impact our business, financial condition, liquidity, capital and results of operations will depend on future developments, which are highly uncertain and are difficult to predict.

•Changes and instability in the macroeconomic environment, consumer confidence and customer behavior may adversely affect our business.

•Financial market instability and volatility could adversely affect our business.

•We may experience increased delinquencies, credit losses, inaccurate estimates and inadequate reserves.

•We may not be able to maintain adequate capital or liquidity levels, which could have a negative impact on our financial results and our ability to return capital to our stockholders.

•We face risks related to our operational, technological and organizational infrastructure.

23 Capital One Financial Corporation (COF)

Table of Contents

•Theft, loss or misuse of information as a result of a cyber-attack may result in increased costs, reductions in revenue, reputational damage and business disruptions.

•Potential data protection and privacy incidents, and our required compliance with regulations related to these areas, may increase our costs, reduce our revenue and limit our ability to pursue business opportunities.

•Compliance with new and existing laws, regulations and regulatory expectations is costly and complex.

•Our businesses are subject to the risk of increased litigation, government investigations and regulatory enforcement.

•We face intense competition in all of our markets.

•Our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit card networks and by legislation and regulation impacting such fees.

•If we are not able to invest successfully in and introduce digital and other technological developments across all our businesses, our financial performance may suffer.

•We may fail to realize all of the anticipated benefits of our mergers, acquisitions and strategic partnerships.

•Reputational risk and social factors may impact our results and damage our brand.

•If we are not able to protect our intellectual property, our revenue and profitability could be negatively affected.

•Our risk management strategies may not be fully effective in mitigating our risk exposures in all market environments or against all types of risk.

•Fluctuations in market interest rates or volatility in the capital markets could adversely affect our income and expense, the value of assets and obligations, our regulatory capital, cost of capital or liquidity.

•Uncertainty regarding, and transition away from, LIBOR may adversely affect our business.

•Our business could be negatively affected if we are unable to attract, retain and motivate skilled employees.

•We face risks from unpredictable catastrophic events.

•We face risks from the use of or changes to assumptions or estimates in our financial statements.

•Limitations on our ability to receive dividends from our subsidiaries could affect our liquidity and ability to pay dividends and repurchase common stock.

•The soundness of other financial institutions and other third parties could adversely affect us.

General Economic and Market Risks

The COVID-19 pandemic has adversely impacted our business and financial results, and the extent to which the pandemic and measures taken in response to the pandemic could materially and adversely impact our business, financial condition, liquidity, capital and results of operations will depend on future developments, which are highly uncertain and are difficult to predict.

Global health concerns relating to the COVID-19 pandemic and related government actions taken to reduce the spread of the virus have impacted the macroeconomic environment, significantly increased economic uncertainty and reduced economic activity. The pandemic has also caused governmental authorities to implement numerous measures to try to contain the virus, including travel bans and restrictions, quarantines, shelter-in-place orders, and business limitations and shutdowns. These measures have negatively impacted and may further negatively impact consumer and business payment and spending patterns.

The COVID-19 pandemic has adversely impacted, and may continue to adversely impact, our business, operations, financial condition, capital and results of operations. The extent of these impacts depends on future developments, which are highly uncertain and difficult to predict, including, but not limited to, the duration and magnitude of the pandemic, the actions taken to contain the virus or treat its impact, the effectiveness of economic stimulus measures in the United States, and how quickly and

24 Capital One Financial Corporation (COF)

Table of Contents

to what extent economic and operating conditions and consumer and business spending can return to their pre-pandemic levels. As of December 31, 2020, several vaccines have been authorized for limited distribution. The plan for larger community-based distribution is being developed and may begin during the second quarter of 2021. However, the timing and extent of any such widespread distribution of vaccines remains uncertain. As a result of this uncertainty, our purchase volume, loan growth and the overall demand for our products and services may be significantly impacted, which could adversely affect our revenue and other results of operations. In addition, we could experience higher credit losses in our loan portfolios and increases in our allowance for credit losses beyond current levels. For example, as a result of the significant uncertainty due to the COVID-19 pandemic, we realized a substantial build in our allowance for credit losses for the first two quarters of 2020. We could also experience impairments of other financial assets and other negative impacts on our financial position, including possible constraints on liquidity and capital, as well as higher costs of capital. Even after the COVID-19 pandemic has subsided, we may continue to experience adverse impacts to our business and results of operations, which could be material, as a result of the macroeconomic impact and any recession that has occurred or may occur in the future.

The spread of COVID-19 has caused us to modify our business practices and operations, including providing a range of forbearance options to our customers in certain circumstances, which could impact our credit metrics, financial condition, capital and results of operations. We may need to further modify our practices and operations as this event unfolds. We have also implemented work-from-home policies for a vast majority of our employees, and social distancing plans for our employees who are working from Capital One facilities. Nearly all of our Cafés and bank branches across our network are open with increased safety precautions. We will continue to monitor local conditions to ensure the safety of our associates and customers while providing critical banking services. These measures could impair our ability to perform critical functions and may adversely impact our results of operations. In addition, these measures and other changes in consumer behavior as a result of the COVID-19 pandemic may require changes to retail distribution strategies and adversely impact our investments in our bank premises and equipment and other retail distribution assets, leading to increased costs and exposure to additional risks. We may take further actions as required by government authorities or that we otherwise determine are in the best interests of our customers, employees and business partners.

Federal, state, local and foreign governmental authorities have enacted, and may enact in the future, legislation, regulations and protocols in response to the COVID-19 pandemic, including governmental programs intended to provide economic relief to businesses and individuals. We have participated in certain of these programs, including participating as an eligible lender in the Small Business Administration’s Paycheck Protection Program. Our participation in and execution of any such programs may cause operational, compliance, reputational and credit risks, which could result in litigation, governmental action or other forms of loss. The extent of these impacts, which may be substantial, will depend on the degree of our participation in these programs. There remains significant uncertainty regarding the measures that authorities will enact in the future and the ultimate impact of the legislation, regulations and protocols that have been and will be enacted. Moreover, we expect that the effects of the COVID-19 pandemic will heighten many of the other known risks described herein. See Part I—Item 1.—Business—Overview—Coronavirus Disease 2019 (COVID-19) Pandemic.

Changes and instability in the macroeconomic environment, consumer confidence and customer behavior may adversely affect our business.

We offer a broad array of financial products and services to consumers, small businesses and commercial clients. A prolonged period of economic volatility, slow growth, or a significant deterioration in economic conditions, in the U.S., Canada or the U.K., could have a material adverse effect on our financial condition and results of operations as customers default on their loans, maintain lower deposit levels or, in the case of credit card accounts, carry lower balances and reduce credit card purchase activity.

Some of the risks we face in connection with adverse changes and instability in the macroeconomic environment, including changes in consumer confidence levels and behavior, include the following:

•Changes in payment patterns, increases in delinquencies and default rates, decreased consumer spending, lower demand for credit and shifts in consumer payment behavior towards avoiding late fees, finance charges and other fees;

•Increases in our charge-off rate caused by bankruptcies and reduced ability to recover debt that we have previously charged-off;

•Decreased reliability of the process and models we use to estimate our allowance for loan and lease losses, particularly if unexpected variations in key inputs and assumptions cause actual losses to diverge from the projections of our models

25 Capital One Financial Corporation (COF)

Table of Contents

and our estimates become increasingly subject to management’s judgment. See “We face risks resulting from the extensive use of models and data.”

The U.K. and the European Union agreed to a free trade deal at the end of 2020 relating to the U.K.’s exit from the European Union (“Brexit”). While this deal provides greater near-term stability, the on-going impact of Brexit and its full effects on the U.K. economy and our business related thereto remain uncertain. We continue to consider and monitor the potential impacts, and other factors, including the COVID-19 pandemic, that could also impact U.K. economic performance.

Financial market instability and volatility could adversely affect our business.

Our ability to borrow from other financial institutions or to engage in funding transactions on favorable terms or at all could be adversely affected by disruptions in the capital markets or other events, including actions by rating agencies and deteriorating investor expectations, which could limit our access to funding. In addition, fluctuations in interest rates, credit spreads and other market factors could negatively impact our results of operations. Both shorter-term and longer-term interest rates remain below long-term historical averages and the yield curve has been relatively flat compared to past periods. A flat yield curve combined with low interest rates generally leads to lower revenue and reduced margins because it tends to limit our ability to increase the spread between asset yields and funding costs. Sustained periods of time with a flat yield curve coupled with low interest rates, or an inversion of the yield curve, could have a material adverse effect on our net interest margin and earnings.

In response to the economic consequences of the COVID-19 pandemic, the Federal Reserve lowered its target for the federal funds rate to a range of 0% to 0.25%. Such low rates increase the risk in the U.S. of a negative interest rate environment in which interest rates drop below zero, either broadly or for some types of instruments. For example, yields on one-month and three-month Treasuries briefly dropped below zero in March 2020. Such an occurrence would likely further reduce the interest we earn on loans and other interest-earning assets, while also likely requiring us to pay to maintain our deposits with the Federal Reserve. Our systems may not be able to handle adequately a negative interest rate environment and not all variable rate instruments are designed for such a circumstance. We cannot predict the nature or timing of future changes in monetary policies in response to the COVID-19 pandemic or the precise effects that they may have on our activities and financial results.

Credit Risk

We may experience increased delinquencies, credit losses, inaccurate estimates and inadequate reserves.

Like other lenders, we face the risk that our customers will not repay their loans. A customer’s ability and willingness to repay us can be adversely affected by increases in their payment obligations to other lenders, whether as a result of higher debt levels or rising interest rates, by restricted availability of credit generally, or by the revenue and income of the borrower. We may fail to quickly identify and reduce our exposure to customers that are likely to default on their payment obligations, whether by closing credit lines or restricting authorizations. Our ability to manage credit risk also is affected by legal or regulatory changes (such as restrictions on collections, bankruptcy laws, minimum payment regulations and re-age guidance), competitors’ actions and consumer behavior, and depends on the effectiveness of our collections staff, techniques and models.

Rising losses or leading indicators of rising losses (such as higher delinquencies, higher rates of nonperforming loans, higher bankruptcy rates, lower collateral values, elevated unemployment rates or changing market terms) may require us to increase our allowance for credit losses, which may degrade our profitability if we are unable to raise revenue or reduce costs to compensate for higher losses. In particular, we face the following risks in this area:

•Missed Payments: Our customers may miss payments. Loan charge-offs (including from bankruptcies) are generally preceded by missed payments or other indications of worsening financial condition for our customers. Historically, customers are more likely to miss payments during an economic downturn or prolonged periods of slow economic growth. In addition, we face the risk that consumer and commercial customer behavior may change (for example, an increase in the unwillingness or inability of customers to repay debt, which may be heightened by increasing interest rates or levels of consumer debt), causing a long-term rise in delinquencies and charge-offs.

•Incorrect Estimates of Expected Losses: The credit quality of our portfolio can have a significant impact on our earnings. We allow for and reserve against credit risks based on our assessment of expected credit losses in our loan portfolios. This process, which is critical to our financial condition and results of operations, requires complex judgments, including forecasts of economic conditions. We may underestimate our expected losses and fail to hold an allowance for credit losses sufficient to account for these losses. Incorrect assumptions could lead to material underestimations of expected credit losses and an inadequate allowance for credit losses.

26 Capital One Financial Corporation (COF)

Table of Contents

•Inaccurate Underwriting: Our ability to accurately assess the creditworthiness of our customers may diminish, which could result in an increase in our credit losses and a deterioration of our returns. See “Our risk management strategies may not be fully effective in mitigating our risk exposures in all market environments or against all types of risk.”

•Business Mix: We engage in a diverse mix of businesses with a broad range of potential credit exposure. Because we originate a relatively greater proportion of consumer loans in our loan portfolio compared to other large bank peers and originate both prime and subprime credit card accounts and auto loans, we may experience higher delinquencies and a greater number of accounts charging off compared to other large bank peers, which could result in increased credit losses, operating costs and regulatory scrutiny. Additionally, a change in this business mix over time to include proportionally more consumer loans or subprime credit card accounts or auto loans could adversely affect the credit quality of our portfolio.

•Increasing Charge-off Recognition/Allowance for Credit Losses: We account for the allowance for credit losses according to accounting and regulatory guidelines and rules, including Financial Accounting Standards Board (“FASB”) standards and the Federal Financial Institutions Examination Council (“FFIEC”) Account Management Guidance. Effective as of January 1, 2020, we adopted the CECL standard which is based on expected lifetime losses rather than incurred losses. Adoption of the CECL standard has resulted and may continue to result in an increase to our reserves for credit losses on financial instruments with a resulting adverse impact on our financial condition. The continued impact of CECL on our future results will depend on the characteristics of our financial instruments, economic conditions, and our economic and loss forecasts. The application of the CECL standard requires us to increase reserves faster and to a higher level in an economic downturn, resulting in greater impact to our results and our capital ratios than we would have experienced in similar circumstances prior to the adoption of CECL. In addition, because credit cards represent a significant portion of our product mix, we could be disproportionately affected by use of the CECL standard, as compared to our large bank peers with a different product mix. See “MD&A—Accounting Changes and Developments” for additional information.

•Insufficient Asset Values: The collateral we have on secured loans could be insufficient to compensate us for credit losses. When customers default on their secured loans, we attempt to recover collateral where permissible and appropriate. However, the value of the collateral may not be sufficient to compensate us for the amount of the unpaid loan, and we may be unsuccessful in recovering the remaining balance from our customers. Decreases in real estate and other asset values adversely affect the collateral value for our commercial lending activities, while the auto business is similarly exposed to collateral risks arising from the auction markets that determine used car prices. Borrowers may be less likely to continue making payments on loans if the value of the property used as collateral for the loan is less than what the borrower owes, even if the borrower is still financially able to make the payments. In that circumstance, the recovery of such property could be insufficient to compensate us for the value of these loans upon a default. In our auto business, business and economic conditions that negatively affect household incomes, housing prices and consumer behavior, as well as technological advances that make older cars obsolete faster, could decrease (i) the demand for new and used vehicles and (ii) the value of the collateral underlying our portfolio of auto loans, which could cause the number of consumers who become delinquent or default on their loans to increase.

•Geographic and Industry Concentration: Although our consumer lending is geographically diversified, approximately 27% of our commercial loan portfolio is concentrated in the tri-state area of New York, New Jersey and Connecticut. The regional economic conditions in the tri-state area affect the demand for our commercial products and services as well as the ability of our customers to repay their commercial loans and the value of the collateral securing these loans. An economic downturn or prolonged period of slow economic growth in, or a catastrophic event that disproportionately affects, the tri-state area could have a material adverse effect on the performance of our commercial loan portfolio and our results of operations. In addition, our Commercial Banking strategy includes an industry-specific focus. If any of the industries that we focus on experience changes, we may experience increased credit losses and our results of operations could be adversely impacted. For example, as of December 31, 2020, healthcare and healthcare-related real estate loans represented approximately 19% of our total commercial loan portfolio. If healthcare-related industries or any of the other industries that we focus on experience adverse changes, we may experience increased credit losses and our results of operations could be adversely impacted.

27 Capital One Financial Corporation (COF)

Table of Contents

Capital and Liquidity Risk

We may not be able to maintain adequate capital or liquidity levels, which could have a negative impact on our financial results and our ability to return capital to our stockholders.

Financial institutions are subject to extensive and complex capital and liquidity requirements. These requirements affect our ability to lend, grow deposit balances, make acquisitions and make most capital distributions. Failure to maintain adequate capital or liquidity levels, whether due to adverse developments in our business or the economy or to changes in the applicable requirements, could subject us to a variety of remedies available to our regulators. These include limitations on the ability to pay dividends, repurchase shares and the issuance of a capital directive to increase capital. Such limitations could have a material adverse effect on our business and results of operations.

We consider various factors in the management of capital, including the impact of stress on our capital levels, as determined by both our internal modeling and the Federal Reserve’s modeling of our capital position in supervisory stress tests and CCAR. There can be significant differences between our modeling and the Federal Reserve’s estimates for a given scenario and between the capital needs suggested by our internal bank holding company scenarios relative to the supervisory scenarios. Therefore, although our estimated capital levels under stress disclosed as part of the CCAR or DFAST processes may suggest that we have substantial capacity to return capital to stockholders and remain well capitalized under stress, the Federal Reserve’s modeling, our internal modeling of another scenario or other factors related to our capital management process may result in a materially lower capacity to return capital to stockholders than that indicated by the projections released in the CCAR or DFAST processes. This in turn, could lead to restrictions on our ability to pay dividends and engage in share repurchase transactions. See “Part I—Item 1. Business—Supervision and Regulation” for additional information.

In addition, the current capital and liquidity requirements are subject to change. The Federal Banking Agencies finalized the Tailoring Rule in the fourth quarter of 2019. Under the Tailoring Rule, we are a Category III institution, and are no longer subject to the Basel III Advanced Approaches and associated capital requirements, but we continue to be subject to the countercyclical capital buffer and supplementary leverage ratio. In March 2020, the Federal Reserve issued a final rule to implement the stress capital buffer requirement. This final rule became effective in May 2020. Pursuant to the Stress Capital Buffer Rule, the Federal Reserve will use the results of its supervisory stress test to determine the size of a large banking institution’s stress capital buffer requirement, which replaces the previous 2.5% capital conservation buffer under the Basel III Standardized Approach. Our stress capital buffer requirement is 5.6% for the period from October 1, 2020 through September 30, 2021, at which point a revised stress capital buffer requirement will be applicable to us based on our 2021 stress testing results. In addition, on June 25, 2020 the Federal Reserve introduced measures to ensure that large BHCs maintained a high level of capital resilience. Specifically, the Federal Reserve required certain large BHCs, including us, to suspend share repurchases and cap common dividends during the third and fourth quarters of 2020. Consistent with the Federal Reserve’s capital distribution restrictions, we reduced our quarterly dividend on our common stock from $0.40 per share to $0.10 per share for the third quarter of 2020, which we maintained into the fourth quarter of 2020. The Federal Banking Agencies also finalized rules to implement the NSFR in October 2020. The NSFR is designed to ensure that banking organizations maintain a stable, long-term funding profile in relation to their asset composition and off-balance sheet activities and its requirements will become effective as of July 1, 2021. On December 18, 2020, the Federal Reserve extended the capital distribution restrictions for all participating BHCs to the first quarter of 2021, with certain modifications. In particular, for the first quarter of 2021, participating BHCs may resume share repurchases however the aggregate amount of dividend payments and share repurchases will be limited to an amount based on net income earned in the preceding four calendar quarters. See “Part I—Item 1. Business—Supervision and Regulation” for additional information. Further changes to applicable capital and liquidity requirements could result in unexpected or new limitations on our ability to pay dividends and engage in share repurchases.

Operational Risk

We face risks related to our operational, technological and organizational infrastructure.

Our ability to retain and attract customers depends on our ability to develop, operate, and adapt our technology and organizational infrastructure in a rapidly changing environment. In addition, we must accurately process, record and monitor an increasingly large number of complex transactions. Digital technology, data and software development are deeply embedded into our business model and how we work.

Similar to other large corporations, we are exposed to operational risk that can manifest itself in many ways, such as errors in execution, inadequate processes, inaccurate models, faulty or disabled technological infrastructure, and fraud by employees or

28 Capital One Financial Corporation (COF)

Table of Contents

persons outside of our company. In addition, we are heavily dependent on the security, capability and continuous availability of the technology systems that we use to manage our internal financial and other systems, monitor risk and compliance with regulatory requirements, provide services to our customers, develop and offer new products and communicate with stakeholders. We also face risk of adverse customer impacts and business disruption arising from the execution of strategic initiatives we may pursue across our operations.

If we do not maintain the necessary operational, technological and organizational infrastructure to operate our business, including to maintain the security of that infrastructure, our business and reputation could be materially adversely affected. We also are subject to disruptions to our operating systems arising from events that are wholly or partially beyond our control, which may include computer viruses, electrical or telecommunications outages, design flaws in foundational components or platforms, availability and quality of vulnerability patches from key vendors, cyber-attacks (including Distributed Denial of Service (“DDOS”) and other attacks on our infrastructure as discussed below), natural disasters, other damage to property or physical assets, or events arising from local or larger scale politics, including terrorist acts. Any failure to maintain our infrastructure or disruption of our operating systems and applications could diminish our ability to operate our businesses, service customer accounts and protect customers’ information, or result in potential liability to customers, reputational damage, regulatory intervention and customers’ loss of confidence in our businesses, any of which could result in a material adverse effect.

We also rely on the business infrastructure and systems of third parties with which we do business and to whom we outsource the operation, maintenance and development of our information technology and communications systems. We have migrated substantially all, and intend to migrate all, of our core information technology systems and customer-facing applications to third-party cloud infrastructure platforms, principally AWS. If we do not complete the transition or fail to administer these new environments in a well-managed, secure and effective manner, or if AWS platforms become unavailable or do not meet their service level agreements for any reason, we may experience unplanned service disruption or unforeseen costs which could result in material harm to our business and results of operations. We must successfully develop and maintain information, financial reporting, disclosure, data-protection and other controls adapted to our reliance on outside platforms and providers. In addition, AWS, or other service providers, could experience system breakdowns or failures, outages, downtime, cyber-attacks, adverse changes to financial condition, bankruptcy, or other adverse conditions, which could have a material adverse effect on our business and reputation. Thus, the substantial amount of our infrastructure that we outsource to AWS or to other third parties may increase our risk exposure.

Any disruptions, failures or inaccuracies of our operational and technology systems and models, including those associated with improvements or modifications to such systems and models, could cause us to be unable to market and manage our products and services, manage our risk, meet our regulatory obligations or report our financial results in a timely and accurate manner, all of which could have a negative impact on our results of operations. In addition, our ongoing investments in infrastructure, which are necessary to maintain a competitive business, integrate acquisitions and establish scalable operations, may increase our expenses. As our business develops, changes or expands, additional expenses can arise as a result of a reevaluation of business strategies, management of outsourced services, asset purchases or other acquisitions, structural reorganization, compliance with new laws or regulations, or the integration of newly acquired businesses, or the prevention or occurrence of data security incidents. If we are unable to successfully manage our expenses, our financial results will be negatively affected. Changes to our business, including as a result of our strategic objectives, also requires robust governance to ensure that our objectives are executed as intended without adversely impacting our customers, associates, operations or financial performance. Ineffective change management oversight and governance over the execution of our strategic objectives could expose us to operational, strategic and reputational risk and could negatively impact customers or our financial performance.

Theft, loss or misuse of information as a result of a cyber-attack may result in increased costs, reductions in revenue, reputational damage and business disruptions.

Our products and services involve the gathering, authenticating, managing, processing, and the storing and transmission of sensitive and confidential information regarding our customers and their accounts, our employees and third parties with which we do business. Our ability to provide such products and services, many of which are web-based, depends upon the management and safeguarding of information, software, methodologies and business secrets. To provide these products and services to, as well as communicate with, our customers, we rely on information systems and infrastructure, including software and data engineering, and information security personnel, digital technologies, computer and email systems, software, networks and other web-based technologies. We also have arrangements in place with third parties through which we share and receive information about their customers who are or may become our customers.

29 Capital One Financial Corporation (COF)

Table of Contents

Technologies, systems, networks and devices of Capital One or our employees, service providers or other third parties with whom we interact may continue to be the subject of attempted unauthorized access, mishandling or misuse of information, denial-of-service attacks, computer viruses, website defacement, hacking, malware, ransomware, phishing or other forms of social engineering, and other forms of cyber-attacks designed to obtain confidential information, destroy data, disrupt or degrade service, sabotage systems or cause other damage, and other events. These threats, such as the Cybersecurity Incident, may derive from error, fraud or malice on the part of our employees, insiders or third parties or may result from accidental technological failure. Any of these parties may also attempt to fraudulently induce employees, customers or other third-party users of our systems to disclose sensitive information in order to gain access to our data or that of our customers or third parties with whom we interact, or to unlawfully obtain monetary benefit through misdirected or otherwise improper payment. Further, cyber and information security risks for large financial institutions like us continue to increase due to the proliferation of new technologies, the use of the internet to conduct financial transactions, and the increased sophistication and activities of organized crime, perpetrators of fraud, hackers, terrorists, activists, formal and informal instrumentalities of foreign governments and other external parties. In addition, our customers access our products and services using computers, smartphones, tablets and other mobile devices that are beyond our security control systems.

The methods and techniques employed by perpetrators of fraud and others to attack, disable, degrade or sabotage platforms, systems and applications change frequently, are increasingly sophisticated and often are not fully recognized or understood until after they have occurred, and some techniques could occur and persist for an extended period of time before being detected. For example, although we immediately fixed the configuration vulnerability that was exploited in the Cybersecurity Incident once we discovered the unauthorized access, a period of time elapsed between the occurrence of the unauthorized access and the time when we discovered it. In other circumstances, we and our third-party service providers and partners may be unable to anticipate or identify certain attack methods in order to implement effective preventative measures or mitigate or remediate the damages caused in a timely manner. We may also be unable to hire and develop talent capable of detecting, mitigating or remediating these risks. Although we seek to maintain a robust suite of authentication and layered information security controls, including our cyber threat analytics, data encryption and tokenization technologies, anti-malware defenses and vulnerability management program, any one or combination of these controls could fail to detect, mitigate or remediate these risks in a timely manner. We will likely face an increasing number of attempted cyber-attacks as we expand our mobile and other internet-based products and services, as well as our usage of mobile and cloud technologies and as we provide more of these services to a greater number of retail clients.

A disruption or breach, including as a result of a cyber-attack such as the Cybersecurity Incident, or media reports of perceived security vulnerabilities at Capital One or at our third-party service providers, could result in significant legal and financial exposure, regulatory intervention, litigation and remediation costs, card reissuance, supervisory liability, damage to our reputation or loss of confidence in the security of our systems, products and services that could adversely affect our business. We and other U.S. financial services providers continue to be targeted with evolving and adaptive cybersecurity threats from sophisticated third parties. We are continuing to assess the impact of the Cybersecurity Incident and there can be no assurance that additional unauthorized access or cyber incidents will not occur or that we will not suffer material losses in the future. Unauthorized access or cybersecurity incidents could occur more frequently and on a more significant scale. If future attacks like these are successful or if customers are unable to access their accounts online for other reasons, it could adversely impact our ability to service customer accounts or loans, complete financial transactions for our customers or otherwise operate any of our businesses or services. In addition, a breach or attack affecting one of our third-party service providers or partners could harm our business even if we do not control the service that is attacked.

In addition, the increasing prevalence and the evolution of cyber-attacks and other efforts to breach or disrupt our systems or those of our partners, retailers or other market participants has led, and will likely continue to lead, to increased costs to us with respect to preventing, mitigating and remediating these risks, as well as any related attempted fraud. In order to address ongoing and future risks, including from the Cybersecurity Incident, we must expend significant resources to support protective security measures, investigate and remediate any vulnerabilities of our information systems and infrastructure and invest in new technology designed to mitigate security risks. The Cybersecurity Incident, or successful cyber-attacks at other large financial institutions or other market participants (whether or not we are impacted), could lead to a general loss of customer confidence in financial institutions that could negatively affect us, including harming the market perception of the effectiveness of our security measures or the financial system in general which could result in reduced use of our financial products. We have insurance against some cyber-risks and attacks, including insurance that is expected to cover certain costs associated with the Cybersecurity Incident; nonetheless, our insurance coverage may not be sufficient to offset the impact of a material loss event, and such insurance may increase in cost or cease to be available on commercial terms in the future.

30 Capital One Financial Corporation (COF)

Table of Contents

Potential data protection and privacy incidents, and our required compliance with regulations related to these areas, may increase our costs, reduce our revenue and limit our ability to pursue business opportunities.

A breach, failure or other disruption of our information systems or infrastructure or data management processes, or those of our customers, partners, service providers or other market participants, could lead, depending on the nature of the incident, to the unauthorized or unintended access to and release, gathering, monitoring, misuse, loss or destruction of personal or confidential data about our customers, employees or other third parties in our possession. Any party that obtains this personal or confidential data through a breach or disruption may use this information for ransom, to be paid by us or a third-party, as part of a fraudulent activity that is part of a broader criminal activity, or for other illicit purposes. Further, such disruption or breach could also result in unauthorized access to our proprietary information, intellectual property, software, methodologies and business secrets and in unauthorized transactions in Capital One accounts or unauthorized access to personal or confidential information maintained by those entities. There has been a significant proliferation of consumer information available on the internet resulting from breaches of third-party entities, including personal information, log-in credentials and authentication data. While we were not directly involved in these third-party breach events, the stolen information can create a vulnerability for our customers if their Capital One log-in credentials are the same as or similar to the credentials that have been compromised on other sites. This vulnerability could include the risk of unauthorized account access, data loss and fraud. The use of artificial intelligence, “bots” or other automation software, can increase the velocity and efficacy of these types of attacks.

We are continuing to assess the impact of the Cybersecurity Incident. The Cybersecurity Incident, other data security incidents we may experience in the future, or media reports of perceived security vulnerabilities at Capital One or at third-party service providers, could result in significant legal and financial exposure, regulatory intervention, remediation costs, card reissuance, supervisory liability, damage to our reputation or loss of confidence in the security of our systems, products and services that could adversely affect our business.

We are subject to a variety of continuously evolving and developing laws and regulations in the United States and abroad regarding privacy, data protection and data security, including those related to the collection, storage, handling, use, disclosure, transfer and security of personal data. Significant uncertainty exists as privacy and data protection laws may be interpreted and applied differently from country to country and may create inconsistent or conflicting requirements. For example, in Canada we are subject to the Personal Information Protection and Electronic Documents Act (“PIPEDA”). In addition, the General Data Protection Regulation (“GDPR”) applies EU data protection law to all companies processing data of EU residents, regardless of the company’s location. More recently, on January 1, 2020, the CCPA went into effect for companies doing business in California. These laws impose strict requirements regarding the collection, storage, handling, use, disclosure, transfer and security of personal data, which may have adverse consequences, including severe monetary penalties. Our efforts to comply with PIPEDA, GDPR, CCPA and other privacy and data protection laws entail substantial expenses, may divert resources from other initiatives and projects, and could limit the services we are able to offer. Furthermore, enforcement actions and investigations by regulatory authorities related to data security incidents and privacy violations continue to increase. The enactment of more restrictive laws, rules, regulations, or future enforcement actions or investigations could impact us through increased costs or restrictions on our business, and noncompliance could result in monetary or other penalties and significant legal liability.

We face risks resulting from the extensive use of models and data.

We rely on quantitative models, and our ability to manage data and aggregate data in an accurate and timely manner, assess and manage our various risk exposures, estimate certain financial values and manage compliance with required regulatory capital requirements. Models may be used in such processes as determining the pricing of various products, grading loans and extending credit, measuring interest rate and other market risks, predicting deposit levels or loan losses, assessing capital adequacy and calculating economic and regulatory capital levels, estimating the value of financial instruments and balance sheet items, and other operational functions. Our risk reporting and management, including business decisions based on information incorporating models, depend on the effectiveness of our models and our policies, programs, processes and practices governing how data is acquired, validated, stored, protected, processed and analyzed. Any issues with the quality or effectiveness of our data aggregation and validation procedures, as well as the quality and integrity of data inputs, formulas or algorithms, could result in inaccurate forecasts, ineffective risk management practices or inaccurate risk reporting. In addition, models based on historical data sets might not be accurate predictors of future outcomes and their ability to appropriately predict future outcomes may degrade over time. While we continuously update our policies, programs, processes and practices, many of our data management, aggregation and implementation processes are manual and subject to human error or system failure. Failure to manage data effectively and to aggregate data in an accurate and timely manner may limit our ability to

31 Capital One Financial Corporation (COF)

Table of Contents

manage current and emerging risk, to produce accurate financial, regulatory and operational reporting as well as to manage changing business needs. If our risk management framework is ineffective, we could suffer unexpected losses which could materially adversely affect our results of operation or financial condition. Also, any information we provide to the public or to our regulators based on poorly designed or implemented models could be inaccurate or misleading. Some of the decisions that our regulators make, including those related to capital distribution to our stockholders, could be affected adversely due to the perception that the quality of the models used to generate the relevant information is insufficient.

Legal and Regulatory Risk

Compliance with new and existing laws, regulations and regulatory expectations is costly and complex.

We are subject to extensive regulatory oversight by the federal banking regulators to ensure that we build systems and processes that are commensurate with the nature of our business and that meet the risk management and prudential standards issued by our regulators. A wide array of banking and consumer lending laws apply to almost every aspect of our business. Failure to comply with these laws and regulations could result in financial, structural and operational penalties, including significant fines and criminal sanctions, and/or damage to our reputation with regulators, our customers or the public. Hiring, training and retaining qualified compliance and legal personnel, and establishing and maintaining compliance-related systems, infrastructure and processes, is difficult and these efforts could limit our ability to invest in other business opportunities. Furthermore, applicable rules and regulations may affect us in an unforeseen manner, or may have a disproportionate impact on us as compared to our competitors. Over the last several years, state and federal regulators have focused on compliance with the Bank Secrecy Act and anti-money laundering (“AML”) laws, data integrity and security, use of service providers, fair lending and other consumer protection issues. For example, in July 2015, Capital One entered into a consent order with the OCC to address concerns about our AML program and in October 2018, Capital One paid a civil monetary penalty assessed by the OCC relating to our AML program. The OCC lifted the AML consent order in November 2019. In addition, in August 2020 we entered into consent orders with the Federal Reserve and the OCC resulting from regulatory reviews of the Cybersecurity Incident and relating to ongoing enhancements of our cybersecurity and operational risk management processes, and we paid a civil monetary penalty as part of the OCC agreement. In January 2021, we also paid a civil monetary penalty assessed by the Financial Crimes Enforcement Network (“FinCEN”) against CONA in connection with our AML program. Failure to maintain compliance with laws and regulations could result in significant additional governmental fines or penalties.

We have a large number of customer accounts in our credit card and auto lending businesses and we have made the strategic choice to originate and service subprime credit card and auto loans, which typically have higher delinquencies and charge-offs than prime customers. As a result, we have significant involvement with credit bureau reporting and the collection and recovery of delinquent and charged-off debt, primarily through customer communications, the filing of litigation against customers in default, the periodic sale of charged-off debt and vehicle repossession. These activities are subject to enhanced legal and regulatory scrutiny from regulators, courts and legislators. Any future changes to our business practices in these areas, including our debt collection practices, whether mandated by regulators, courts, legislators or otherwise, or any legal liabilities resulting from our business practices, including our debt collection practices, could have a material adverse impact on our financial condition.

The legislative and regulatory environment is beyond our control, may change rapidly and unpredictably and may negatively influence our revenue, costs, earnings, growth, liquidity and capital levels. In addition, some rules and regulations may be subject to litigation or other challenges that delay or modify their implementation and impact on us. Adoption of new technologies, such as distributed ledger technologies, artificial intelligence and machine learning technologies, can present unforeseen challenges in applying and relying on existing compliance systems.

Certain laws and regulations, and any interpretations and applications with respect thereto, are generally intended to protect consumers, borrowers, depositors, the DIF, the U.S. banking and financial system, and financial markets as a whole, but not stockholders. Our success depends on our ability to maintain compliance with both existing and new laws and regulations. For a description of the material laws and regulations to which we are subject, see “Part I—Item 1. Business—Supervision and Regulation.”

Our businesses are subject to the risk of increased litigation, government investigations and regulatory enforcement.

Our businesses are subject to increased litigation, government investigations and other regulatory enforcement risks as a result of a number of factors and from various sources, including the highly regulated nature of the financial services industry, the focus of state and federal prosecutors on banks and the financial services industry and the structure of the credit card industry.

32 Capital One Financial Corporation (COF)

Table of Contents

Given the inherent uncertainties involved in litigation, government investigations and regulatory enforcement decisions, and the very large or indeterminate damages sought in some matters asserted against us, there can be significant uncertainty as to the ultimate liability we may incur from these kinds of matters. The finding, or even the assertion, of substantial legal liability against us could have a material adverse effect on our business and financial condition and could cause significant reputational harm to us, which could seriously harm our business. The Cybersecurity Incident has resulted in litigation, government investigations and other regulatory enforcement inquiries.

In addition, financial institutions, such as ourselves, face significant regulatory scrutiny, which can lead to public enforcement actions or non-public supervisory actions. We and our subsidiaries are subject to comprehensive regulation and periodic examination by, among other regulatory bodies, the Federal Reserve, the SEC, OCC, FDIC and CFPB. We have been subject to enforcement actions by many of these and other regulators and may continue to be involved in such actions, including governmental inquiries, investigations and enforcement proceedings, including by the OCC, Department of Justice, FinCEN and state Attorneys General.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2020-12-31, filed 2021-02-25 · accession 0000927628-21-000094

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 21 headings are on that chain and 15 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.