Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

COF US Equity

Capital One Financial CorpFinancials · National Commercial Banks · CIK 927628 · FY ends Dec 31
$217.91
+5.43 (+2.56%)
USD · as of 2026-08-21 · marketstack

COF · 10-K · period ended 2021-12-31

← all COF documents
filed 2022-02-25 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1522 of 3,370621k characters rendered

cof-20211231

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

____________________________________

FORM 10-K

___________________________________

For the fiscal year ended December 31, 2021

OR

For the transition period from to

Commission File No. 001-13300

____________________________________

CAPITAL ONE FINANCIAL CORPORATION

(Exact name of registrant as specified in its charter)

____________________________________

1680 Capital One Drive,

(Address of principal executive offices) (Zip Code)

Registrant’s telephone number, including area code: (703) 720-1000

____________________________________

Securities registered pursuant to Section 12(b) of the Act:

Title of Each Class Trading Symbol(s) Name of Each Exchange on Which Registered

Common Stock (par value $.01 per share) COF New York Stock Exchange

0.800% Senior Notes Due 2024 COF24 New York Stock Exchange

1.650% Senior Notes Due 2029 COF29 New York Stock Exchange

Securities registered pursuant to section 12(g) of the Act: None

____________________________________

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer ☒ Accelerated filer ☐

Non-accelerated filer ☐ Smaller reporting company ☐

Emerging growth company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C.7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒

The aggregate market value of the voting stock held by non-affiliates of the registrant as of the close of business on June 30, 2021 was approximately $68.4 billion As of January 31, 2022, there were 413,661,098 shares of the registrant’s Common Stock outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

1.Portions of the Proxy Statement for the annual meeting of stockholders to be held on May 5, 2022, are incorporated by reference into Part III.

TABLE OF CONTENTS

Page

PART I 4

Item 1. Business 4

Overview 4

Operations and Business Segments 6

Competition 7

Supervision and Regulation 7

Human Capital Resources 17

Additional Information 19

Forward-Looking Statements 20

Item 1A. Risk Factors 21

Item 1B. Unresolved Staff Comments 39

Item 2. Properties 39

Item 3. Legal Proceedings 39

Item 4. Mine Safety Disclosures 40

Item 6. Selected Financial Data 44

Executive Summary and Business Outlook 48

Consolidated Results of Operations 50

Consolidated Balance Sheets Analysis 55

Off-Balance Sheet Arrangements 57

Business Segment Financial Performance 57

Critical Accounting Policies and Estimates 67

Accounting Changes and Developments 71

Capital Management 72

Risk Management 79

Credit Risk Profile 85

Liquidity Risk Profile 98

Market Risk Profile 102

Supplemental Table 107

Glossary and Acronyms 108

Item 7A. Quantitative and Qualitative Disclosures about Market Risk 115

Item 8. Financial Statements and Supplementary Data 116

Consolidated Statements of Income 121

Consolidated Statements of Comprehensive Income 122

Consolidated Balance Sheets 123

Consolidated Statements of Changes in Stockholders’ Equity 124

Consolidated Statements of Cash Flows 125

1 Capital One Financial Corporation (COF)

Notes to Consolidated Financial Statements 127

Note 1—Summary of Significant Accounting Policies 127

Note 2—Investment Securities 143

Note 5—Variable Interest Entities and Securitizations 161

Note 6—Goodwill and Other Intangible Assets 165

Note 7—Premises, Equipment and Leases 168

Note 8—Deposits and Borrowings 170

Note 9—Derivative Instruments and Hedging Activities 172

Note 10—Stockholders’ Equity 181

Note 11—Regulatory and Capital Adequacy 185

Note 12—Earnings Per Common Share 188

Note 13—Stock-Based Compensation Plans 189

Note 14—Employee Benefit Plans 191

Note 16—Fair Value Measurement 197

Note 17—Business Segments and Revenue from Contracts with Customers 206

Note 18—Commitments, Contingencies, Guarantees and Others 211

Note 19—Capital One Financial Corporation (Parent Company Only) 214

Note 20—Related Party Transactions 216

Item 9A. Controls and Procedures 217

Item 9B. Other Information 217

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 217

Item 10. Directors, Executive Officers and Corporate Governance 218

Item 11. Executive Compensation 218

Item 14. Principal Accountant Fees and Services 218

Item 15. Exhibits and Financial Statement Schedules 219

EXHIBIT INDEX 220

2 Capital One Financial Corporation (COF)

INDEX OF MD&A AND SUPPLEMENTAL TABLE

MD&A Tables: Page

1 Average Balances, Net Interest Income and Net Interest Margin 50

2 Rate/Volume Analysis of Net Interest Income 52

3 Non-Interest Income 53

4 Non-Interest Expense 54

5 Loans Held for Investment 56

6 Funding Sources Composition 56

7 Business Segment Results 58

8 Credit Card Business Results 59

8 Domestic Card Business Results 61

9 Consumer Banking Business Results 63

10 Commercial Banking Business Results 64

11 Other Category Results 66

12 Capital Ratios Under Basel III 75

13 Regulatory Risk-Based Capital Components and Regulatory Capital Metrics 76

14 Preferred Stock Dividends Paid Per Share 78

15 Portfolio Composition of Loans Held for Investment 86

16 Loan Maturity Schedule 86

17 Credit Card Portfolio by Geographic Region 87

18 Consumer Banking Portfolio by Geographic Region 88

19 Commercial Real Estate Portfolio by Region 88

20 Commercial Loans by Industry 89

21 Credit Score Distribution 90

23 Aging and Geography of 30+ Day Delinquent Loans 91

24 90+ Day Delinquent Loans Accruing Interest 92

25 Nonperforming Loans and Other Nonperforming Assets 93

26 Net Charge-Offs 94

27 Troubled Debt Restructurings 95

29 Allowance Coverage Ratios for Specified Loan Category 98

30 Liquidity Reserves 98

31 Deposits Composition and Average Deposits Interest Rates 100

32 Amount of Time Deposits in Excess of $250,000 by Contractual Maturity 101

33 Long-Term Debt Funding Activities 101

34 Senior Unsecured Long-Term Debt Credit Ratings 102

35 Interest Rate Sensitivity Analysis 103

36 LIBOR Exposures on Derivatives and Commercial Loans 105

Supplemental Tables:

A Net Charge-Offs 107

B Reconciliation of Non-GAAP Measures 107

3 Capital One Financial Corporation (COF)

Table of Contents

PART I

Item 1. Business

OVERVIEW

General

Capital One Financial Corporation, a Delaware corporation established in 1994 and headquartered in McLean, Virginia, is a diversified financial services holding company with banking and non-banking subsidiaries. Capital One Financial Corporation and its subsidiaries (the “Company” or “Capital One”) offer a broad array of financial products and services to consumers, small businesses and commercial clients through digital channels, branch locations, Cafés and other distribution channels.

As of December 31, 2021, our principal subsidiaries included:

•Capital One Bank (USA), National Association (“COBNA”), which offers credit card products along with other lending products and consumer services; and

•Capital One, National Association (“CONA”), which offers a broad spectrum of banking products and financial services to consumers, small businesses and commercial clients.

The Company is hereafter collectively referred to as “we,” “us” or “our.” COBNA and CONA are collectively referred to as the “Banks.” References to “this Report” or our “2021 Form 10-K” or “2021 Annual Report” are to our Annual Report on Form 10-K for the fiscal year ended December 31, 2021. All references to 2021, 2020 and 2019, refer to our fiscal years ended, or the dates, as the context requires, December 31, 2021, December 31, 2020 and December 31, 2019, respectively. Certain business terms used in this document are defined in the “MD&A—Glossary and Acronyms” and should be read in conjunction with the Consolidated Financial Statements included in this Report.

We were the third largest issuer of Visa® (“Visa”) and MasterCard® (“MasterCard”) credit cards in the U.S. based on the outstanding balance of credit card loans as of December 31, 2021. In addition to credit cards, we also offer debit cards, bank lending, treasury management and depository services, auto loans and other consumer lending products in markets across the U.S. As one of the nation’s largest banks based on deposits as of December 31, 2021, we service banking customer accounts through digital channels, as well as through branch locations, Cafés, call centers and automated teller machines (“ATMs”).

We also offer products and services outside of the U.S. principally through Capital One (Europe) plc (“COEP”), an indirect subsidiary of COBNA organized and located in the United Kingdom (“U.K.”), and through a branch of COBNA in Canada. Both COEP and our Canadian branch of COBNA have the authority to provide credit card loans.

Business Developments

We regularly explore and evaluate opportunities to acquire financial products and services as well as financial assets, including credit card and other loan portfolios, and enter into strategic partnerships as part of our growth strategy. We also explore opportunities to acquire technology companies and related assets to improve our information technology infrastructure and to deliver on our digital strategy. We may issue equity or debt to fund our acquisitions. In addition, we regularly consider the potential disposition of certain of our assets, branches, partnership agreements or lines of business.

4 Capital One Financial Corporation (COF)

Table of Contents

Coronavirus Disease 2019 (COVID-19) Pandemic

The COVID-19 pandemic resulted in a global public-health crisis, disrupting economies and introducing significant volatility into financial markets. We transformed how we work in order to protect the well-being of our associates and our customers, and were able to continue to serve our customers, successfully manage critical functions, and keep our lines of business operating.

Since the start of the COVID-19 pandemic, a significant majority of our associates across our workforce have transitioned to working remotely, relying on our technology infrastructure and systems that have been designed for resilience and security. The majority of our associates continue to work remotely. In the future, we plan to adopt a hybrid work methodology that allows for in-office collaboration while still enabling associates to work remotely. We continue to monitor local conditions to ensure the safety of our associates.

For the extent to which the COVID-19 pandemic impacted our financial results, refer to “Part II—Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”).” The extent to which the COVID-19 pandemic ultimately impacts our business, results of operations, and financial condition will depend on future developments that are still uncertain and cannot be predicted, including the scope and duration of the COVID-19 pandemic and actions taken by governmental authorities and other third parties in response to the COVID-19 pandemic. For more information see “Part I—Item 1A. Risk Factors” under the heading “Our results of operations may be adversely affected by the effects of the COVID-19 pandemic.”

Additional Information

Our common stock trades on the New York Stock Exchange (“NYSE”) under the symbol “COF” and is included in the Standard & Poor’s (“S&P”) 100 Index. We maintain a website at www.capitalone.com. Documents available under “Governance & Leadership” in the Investor Relations section of our website include:

•our Certificate of Incorporation, Bylaws, Corporate Governance Guidelines, and Code of Conduct; and

•charters for the Audit, Compensation, Governance and Nominating, and Risk Committees of the Board of Directors.

These documents also are available in print to any stockholder who requests a copy. We intend to disclose future amendments to our Code of Conduct on the website following the date of the amendment. If applicable, we would publicly disclose any waivers of our Code of Conduct granted to executive officers and directors.

In addition, we make available free of charge through our website all of our U.S. Securities and Exchange Commission (“SEC”) filings, including our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to those reports, as soon as reasonably practicable after electronically filing or furnishing such material to the SEC at www.sec.gov.

5 Capital One Financial Corporation (COF)

Table of Contents

OPERATIONS AND BUSINESS SEGMENTS

Our consolidated total net revenues are derived primarily from lending to consumer and commercial customers net of funding costs associated with our deposits, long-term debt and other borrowings. We also earn non-interest income which primarily consists of interchange income, net of reward expenses, service charges and other customer-related fees. Our expenses primarily consist of the provision for credit losses, operating expenses, marketing expenses and income taxes.

Our principal operations are organized for management reporting purposes into three major business segments, which are defined primarily based on the products and services provided or the types of customers served: Credit Card, Consumer Banking and Commercial Banking. The operations of acquired businesses have been integrated into or managed as a part of our existing business segments. Certain activities that are not part of a segment, such as management of our corporate investment portfolio and asset/liability management by our centralized Corporate Treasury group, are included in the Other category. Other category also includes unallocated corporate expenses that do not directly support the operations of the business segments or for which the business segments are not considered financially accountable in evaluating their performance, such as certain restructuring charges, as well as residual tax expense or benefit to arrive at the consolidated effective tax rate that is not assessed to our primary business segments.

•Credit Card: Consists of our domestic consumer and small business card lending, and international card businesses in Canada and the United Kingdom.

•Consumer Banking: Consists of our deposit gathering and lending activities for consumers and small businesses, and national auto lending.

•Commercial Banking: Consists of our lending, deposit gathering, capital markets and treasury management services to commercial real estate and commercial and industrial customers. Our customers typically include companies with annual revenues between $20 million and $2 billion.

Customer usage and payment patterns, estimates of future expected credit losses, levels of marketing expense and operating efficiency all affect our profitability. In our Credit Card business, we experience fluctuations in purchase volume and the level of outstanding loan receivables due to seasonal variances in consumer spending and payment patterns which, for example, have historically been the highest around the winter holiday season. Net charge-off rates for our credit card loan portfolio also have historically exhibited seasonal patterns as well and generally tend to be the highest in the first quarter of the year.

For additional information on our business segments, including the financial performance of each business, see “Part II—Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”)—Executive Summary and Business Outlook,” “MD&A—Business Segment Financial Performance” and “Note 17—Business Segments and Revenue from Contracts with Customers” of this Report.

6 Capital One Financial Corporation (COF)

Table of Contents

COMPETITION

Each of our business segments operates in a highly competitive environment, and we face competition in all aspects of our business from numerous bank and non-bank providers of financial services.

Our Credit Card business competes with international, national, regional and local issuers of Visa and MasterCard credit cards, as well as with American Express®, Discover Card®, private-label card brands, and, to a certain extent, issuers of debit cards. In general, customers are attracted to credit card issuers largely on the basis of price, credit limit, reward programs and other product features.

Our Consumer Banking and Commercial Banking businesses compete with national, state and direct banks for deposits, commercial and auto loans, as well as with savings and loan associations and credit unions for loans and deposits. Our competitors also include automotive finance companies, commercial mortgage banking companies and other financial services providers that provide loans, deposits, and other similar services and products. In addition, we compete against non-depository institutions that are able to offer these products and services.

We also consider new and emerging companies in digital and mobile payments and other financial technology providers among our competitors. We compete with many forms of payment mechanisms, systems and products, offered by both bank and non-bank providers.

Our businesses generally compete on the basis of the quality and range of their products and services, transaction execution, innovation and price. Competition varies based on the types of clients, customers, industries and geographies served. Our ability to compete depends, in part, on our ability to attract and retain our associates and on our reputation as well as our ability to keep pace with innovation, in particular in the development of new technology platforms. There can be no assurance, however, that our ability to market products and services successfully or to obtain adequate returns on our products and services will not be impacted by the nature of the competition that now exists or may later develop, or by the broader economic environment. For a discussion of the risks related to our competitive environment, see “Part I—Item 1A. Risk Factors.”

SUPERVISION AND REGULATION

General

The regulatory framework applicable to banking organizations is intended primarily for the protection of depositors and the stability of the U.S. financial system, rather than for the protection of shareholders and creditors.

As a banking organization, we are subject to extensive regulation and supervision. In addition to banking laws and regulations, we are subject to various other laws and regulations, all of which directly or indirectly affect our operations and management and our ability to make distributions to shareholders. We and our subsidiaries are also subject to supervision and examination by multiple regulators. In addition to laws and regulations, state and federal bank regulatory agencies may issue policy statements, interpretive letters and similar written guidance applicable to us and our subsidiaries. Any change in the statutes, regulations or regulatory policies applicable to us, including changes in their interpretation or implementation, could have a material effect on our business or organization.

Both the scope of the laws and regulations and the intensity of the supervision to which we are subject have increased, initially in response to the financial crisis, and more recently in light of other factors such as technological, political and market changes. Regulatory enforcement and fines have also increased across the banking and financial services sector.

The descriptions below summarize certain significant federal and state laws, as well as international laws, to which we are subject. The descriptions are qualified in their entirety by reference to the particular statutory or regulatory provisions summarized. They do not summarize all possible or proposed changes in current laws or regulations and are not intended to be a substitute for the related statutes or regulatory provisions.

Banking Regulation

Capital One Financial Corporation is a bank holding company (“BHC”) and a financial holding company (“FHC”) under the Bank Holding Company Act of 1956, as amended (“BHC Act”), and is subject to the requirements of the BHC Act, including approval requirements for investments in or acquisitions of banking organizations, capital adequacy standards and limitations

7 Capital One Financial Corporation (COF)

Table of Contents

on non-banking activities. As a BHC and FHC, we are subject to supervision, examination and regulation by the Board of Governors of the Federal Reserve System (“Federal Reserve”). Permissible activities for a BHC include those activities that are so closely related to banking as to be a proper incident thereto. In addition, a FHC is permitted to engage in activities considered to be financial in nature (including, for example, securities underwriting and dealing and merchant banking activities), incidental to financial activities or, if the Federal Reserve determines that they pose no risk to the safety or soundness of depository institutions or the financial system in general, activities complementary to financial activities.

To become and remain eligible for FHC status, a BHC and its subsidiary depository institutions must meet certain criteria, including capital, management and Community Reinvestment Act (“CRA”) requirements. Failure to meet such criteria could result, depending on which requirements were not met, in restrictions on new financial activities or acquisitions or being required to discontinue existing activities that are not generally permissible for BHCs.

The Banks are national associations chartered under the National Bank Act, and the deposits of which are insured by the Deposit Insurance Fund (“DIF”) of the Federal Deposit Insurance Corporation (“FDIC”) up to applicable limits. The Banks are subject to comprehensive regulation and periodic examination by the Office of the Comptroller of the Currency (“OCC”), the FDIC and the Consumer Financial Protection Bureau (“CFPB”). Subject to obtaining all regulatory approvals, we plan to merge the Banks in the fourth quarter of 2022. There can be no assurance that the merger will take place in this time frame. After the completion of the merger, Capital One will conduct its core banking businesses through one subsidiary bank, Capital One, National Association.

We also are registered as a financial institution holding company under the laws of the Commonwealth of Virginia and, as such, we are subject to periodic examination by the Virginia Bureau of Financial Institutions. We also face regulation in the international jurisdictions in which we conduct business. See “Regulation of Businesses by Authorities Outside the United States” below for additional details.

Regulation of Business Activities

The business activities of the Company and the Banks are also subject to regulation and supervision under various laws and regulations.

Regulations of Consumer Lending Activities

The activities of the Banks as consumer lenders are subject to regulation under various federal laws, including, for example, the Truth in Lending Act (“TILA”), the Equal Credit Opportunity Act, the Fair Credit Reporting Act, the CRA, the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 (“Dodd-Frank Act”), the Servicemembers Civil Relief Act and the Military Lending Act, as well as under various state laws. TILA, as amended, imposes a number of restrictions on credit card practices impacting rates and fees, requires that a consumer’s ability to pay be taken into account before issuing credit or increasing credit limits, and imposes revised disclosures required for open-end credit.

Depending on the underlying issue and applicable law, regulators may be authorized to impose penalties for violations of these statutes and, in certain cases, to order banks to compensate customers. Borrowers may also have a private right of action for certain violations. Federal bankruptcy and state debtor relief and collection laws may also affect the ability of a bank, including the Banks, to collect outstanding balances owed by borrowers.

Debit Interchange Fees

The Dodd-Frank Act requires that the amount of any interchange fee received by a debit card issuer with respect to debit card transactions be reasonable and proportional to the cost incurred by the issuer with respect to the transaction. Rules adopted by the Federal Reserve to implement these requirements limit interchange fees per debit card transaction to $0.21 plus five basis points of the transaction amount and provide for an additional $0.01 fraud prevention adjustment to the interchange fee for issuers that meet certain fraud prevention requirements.

8 Capital One Financial Corporation (COF)

Table of Contents

Privacy, Data Protection and Cybersecurity

We are subject to a variety of continuously evolving and developing laws and regulations in the United States and abroad regarding privacy, data protection and data security, including those related to the collection, storage, handling, use, disclosure, transfer, security, and other processing of personal information. These areas have seen a considerable increase in legislative and regulatory activity over the past several years. For example, in November 2021, the Federal Reserve, OCC, and FDIC (collectively, the “Federal Banking Agencies”) issued a final rule that, among other things, requires a banking organization to notify its primary federal regulators as soon as possible and no later than 36 hours after determining that a significant computer-security incident has occurred.

In addition, significant uncertainty exists as privacy, data protection and data security laws may be interpreted and applied differently from country to country or state to state and may create inconsistent or conflicting requirements. For example, in the United States we are subject to the Gramm-Leach Bliley Act (“GLBA”), among other laws and regulations, at the federal level, and in Canada we are subject to the Personal Information Protection and Electronic Documents Act (“PIPEDA”). In addition, the European Union (“EU”) General Data Protection Regulation (“GDPR”) applies EU data protection laws to companies that process data of EU residents, and we also are subject to the U.K. General Data Protection Regulation (“U.K. GDPR”). At the U.S. state level, we are subject to a number of laws and regulations, such as the California Consumer Privacy Act (“CCPA”), which became effective on January 1, 2020. The CCPA and its implementing regulations, as amended by the California Privacy Rights Act (“CPRA”) (which will take effect in most material respects on January 1, 2023), create obligations on covered companies to, among other things, share certain information they have collected about individuals who are California residents with those individuals, subject to some exceptions. Many other states have also enacted or are considering enactment of state-level privacy, data protection and/or data security laws and regulations, with which we may be required to comply.

We continue to monitor privacy, data protection and data security legal developments in the jurisdictions in which we do business. For further discussion of privacy, data protection and cybersecurity, and related risks for our business, see “Part I—Item 1A. Risk Factors” under the headings “We face risks related to our operational, technological and organizational infrastructure,” “A cyber-attack or other security incident, including one that results in the theft, loss or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions,” and “Our required compliance with applicable laws and regulations related to privacy, data protection and data security may increase our costs, reduce our revenue, increase our legal exposure and limit our ability to pursue business opportunities.”

Anti-Money Laundering and Anti-Terrorism

The Bank Secrecy Act and the USA PATRIOT Act of 2001 (“Patriot Act”) require financial institutions, among other things, to implement a risk-based program reasonably designed to prevent money laundering and to combat the financing of terrorism, including through suspicious activity and currency transaction reporting, compliance, record-keeping and customer due diligence.

The Patriot Act also contains financial transparency laws and provides enhanced information collection tools and enforcement mechanisms to the U.S. government, including due diligence and record-keeping requirements for private banking and correspondent accounts; standards for verifying customer identification at account opening; rules to produce certain records upon request of a regulator or law enforcement agency; and rules to promote cooperation among financial institutions, regulators and law enforcement agencies in identifying parties that may be involved in terrorism, money laundering and other crimes.

The Anti-Money Laundering Act of 2020 (“AML Act”), enacted on January 1, 2021 as part of the National Defense Authorization Act, does not directly impose new requirements on banks, but requires the U.S. Treasury Department to issue National Anti-Money Laundering and Countering the Financing of Terrorism Priorities, which it did in June 2021, and to conduct studies and issue regulations that may, over the next few years, significantly alter some of the due diligence, recordkeeping and reporting requirements that the Bank Secrecy Act and Patriot Act impose on banks. The AML Act also contains provisions that promote increased information-sharing and use of technology, and increases penalties for violations of the Bank Secrecy Act and includes whistleblower incentives, both of which could increase the prospect of regulatory enforcement.

9 Capital One Financial Corporation (COF)

Table of Contents

Funding

Under the Federal Deposit Insurance Corporation Improvement Act of 1991 (“FDICIA”), as discussed in “MD&A—Liquidity Risk Profile,” only well capitalized and adequately capitalized institutions may accept brokered deposits. Adequately capitalized institutions, however, must obtain a waiver from the FDIC before accepting brokered deposits, and such institutions may not pay rates that significantly exceed the rates paid on deposits of similar maturity obtained from the institution’s normal market area or, for deposits obtained from outside the institution’s normal market area, the national rate on deposits of comparable maturity. In December 2020, the FDIC finalized amendments to the brokered deposit regulation that, among other things, generally clarify and narrow the scope of the “deposit broker” definition. The amendments became effective April 1, 2021, with compliance required by January 1, 2022.

The FDIC is authorized to terminate a bank’s deposit insurance upon a finding by the FDIC that the bank’s financial condition is unsafe or unsound or that the institution has engaged in unsafe or unsound practices or has violated any applicable rule, regulation, order or condition enacted or imposed by the bank’s regulatory agency.

Broker-Dealer and Investment Advisory Activities

Certain of our non-bank subsidiaries are subject to regulation and supervision by various federal and state authorities. Capital One Investing, Inc. (formerly known as United Income, Inc.) (“Capital One Investing”) is an investment adviser registered with the SEC and primarily regulated under the Investment Advisers Act of 1940.

Capital One Securities, Inc., KippsDeSanto & Company and TripleTree, LLC are registered broker-dealers regulated by the SEC and the Financial Industry Regulatory Authority. These broker-dealer subsidiaries are subject, among other things, to net capital rules designed to measure the general financial condition and liquidity of a broker-dealer. Under these rules, broker-dealers are required to maintain the minimum net capital deemed necessary to meet their continuing commitments to customers and others, and to keep a substantial portion of their assets in relatively liquid form. These rules also limit the ability of a broker-dealer to transfer capital to its parent companies and other affiliates. Broker-dealers are also subject to regulations covering their business operations, including sales and trading practices, public offerings, publication of research reports, use and safekeeping of client funds and securities, capital structure, record-keeping and the conduct of directors, officers and employees.

Derivatives Activities

Title VII of the Dodd-Frank Act establishes a regulatory framework for the governance of the over-the-counter (“OTC”) derivatives market, including swaps and security-based swaps and the registration of certain market participants as a swap dealer. CONA provisionally registered with the Commodity Futures Trading Commission (the “CFTC”) as a swap dealer in the third quarter of 2020. Registration as a swap dealer subjects CONA to additional regulatory requirements with respect to its swaps and other derivatives activities. As a result of CONA’s swap dealer registration, it is subject to the rules of the OCC concerning capital and margin requirements for swap dealers, including the mandatory exchange of variation margin and initial margin with certain counterparties. Additionally, as a provisionally registered swap dealer, CONA is subject to requirements under the CFTC’s regulatory regime, including rules regarding business conduct standards, recordkeeping obligations, regulatory reporting and procedures relating to swaps trading. CONA’s swaps and other derivatives activities do not require it to register with the SEC as a security-based swap dealer.

Transactions with Affiliates

There are various legal restrictions on the extent to which we and our non-bank subsidiaries may borrow or otherwise engage in certain types of transactions with the Banks. Under the Federal Reserve Act and Federal Reserve regulations, the Banks and their subsidiaries are subject to quantitative and qualitative limits on extensions of credit, purchases of assets, and certain other transactions involving its non-bank affiliates. In addition, transactions between the Banks and their non-bank affiliates are required to be on arm’s length terms and must be consistent with standards of safety and soundness.

Volcker Rule

We and each of our subsidiaries, including the Banks, are subject to the “Volcker Rule,” a provision of the Dodd-Frank Act that contains prohibitions on proprietary trading and certain investments in, and relationships with, covered funds (hedge funds, private equity funds and similar funds), subject to certain exemptions, in each case as the applicable terms are defined in the

10 Capital One Financial Corporation (COF)

Table of Contents

Volcker Rule and the implementing regulations. The implementing regulations also require that we establish and maintain a compliance program designed to ensure adherence with the requirements of the regulations.

Capital and Liquidity Regulation

The Company and the Banks are subject to capital adequacy guidelines adopted by the Federal Reserve and OCC respectively. For a further discussion of the capital adequacy guidelines, see “MD&A—Capital Management,” “MD&A—Liquidity Risk Profile” and “Note 11—Regulatory and Capital Adequacy.”

Basel III and United States Capital Rules

The Company and the Banks are subject to the regulatory capital requirements established by the Federal Reserve and the OCC respectively (the “Basel III Capital Rules”). The Basel III Capital Rules implement certain capital requirements published by the Basel Committee on Banking Supervision (“Basel Committee”), along with certain provisions of the Dodd-Frank Act and other capital provisions.

Under the Basel III Capital Rules, we must maintain a minimum common equity Tier 1 (“CET1”) capital ratio of 4.5%, a Tier 1 capital ratio of 6.0%, and a total capital ratio of 8.0%, in each case in relation to risk-weighted assets. In addition, we must maintain a minimum leverage ratio of 4.0% and a minimum supplementary leverage ratio of 3.0%. We are also subject to the capital conservation buffer and countercyclical capital buffer requirements, as described below.

Following amendments to the Basel III Capital Rules in October 2019 to provide for tailored application of certain capital requirements across different categories of banking institutions (the “Tailoring Rules”), the Company, as a BHC with total consolidated assets of at least $250 billion but less than $700 billion and not exceeding any of the applicable risk-based thresholds, is a Category III institution.

The Banks, as subsidiaries of a Category III institution, are Category III banks. Moreover, the Banks, as insured depository institutions, are subject to prompt corrective action (“PCA”) capital regulations, as further described below.

As a Category III institution, effective January 1, 2020, we are no longer subject to the Basel III Advanced Approaches framework and certain associated capital requirements, and we have elected to exclude certain elements of accumulated other comprehensive income (“AOCI”) from our regulatory capital as permitted for a Category III institution. We remain subject to the countercyclical capital buffer requirement (which is currently set at 0%) and supplementary leverage ratio requirement of 3.0%.

Global systemically important banks (“G-SIBs”) that are based in the U.S. are subject to an additional CET1 capital requirement known as the “G-SIB Surcharge”. We are not a G-SIB based on the most recent available data and thus we are not subject to a G-SIB Surcharge.

Stress Capital Buffer Rule

The Basel III Capital Rules require banking institutions to maintain a capital conservation buffer, composed of CET1 capital, above the regulatory minimum ratios. In March 2020, the Federal Reserve issued a final rule to implement the stress capital buffer requirement (the “Stress Capital Buffer Rule”). The stress capital buffer requirement is institution-specific and replaces the fixed 2.5% capital conservation buffer previously in place for BHCs.

Pursuant to the Stress Capital Buffer Rule, the Federal Reserve uses the results of its supervisory stress test to determine the size of a BHC’s stress capital buffer requirement. In particular, a BHC’s stress capital buffer requirement equals, subject to a floor of 2.5%, the sum of (i) the difference between the BHC’s starting CET1 capital ratio and its lowest projected CET1 capital ratio under the severely adverse scenario of the Federal Reserve’s supervisory stress test plus (ii) the ratio of the BHC’s projected four quarters of common stock dividends (for the fourth to seventh quarters of the planning horizon) to the projected risk-weighted assets for the quarter in which the BHC’s projected CET1 capital ratio reaches its minimum under the supervisory stress test.

Under the Stress Capital Buffer Rule framework, the Company’s “standardized approach capital conservation buffer” includes its stress capital buffer requirement (which will be recalibrated every year based on the Company’s supervisory stress test results), any G-SIB Surcharge (which is not applicable to us) and the countercyclical capital buffer requirement (which is currently set at 0%). Any determination to increase the countercyclical capital buffer generally would be effective twelve months after the announcement of such an increase, unless the Federal Banking Agencies set an earlier effective date.

11 Capital One Financial Corporation (COF)

Table of Contents

Based on the Company’s 2021 supervisory stress testing results, the Company’s stress capital buffer requirement for the period beginning on October 1, 2021 through September 30, 2022 is 2.5%. Therefore, the Company’s minimum capital requirements plus the standardized approach capital conservation buffer for CET1 capital, Tier 1 capital and total capital ratios under the stress capital buffer framework are 7.0%, 8.5% and 10.5%, respectively, for the period from October 1, 2021 through September 30, 2022.

The Stress Capital Buffer Rule does not apply to the Banks. The capital conservation buffer for the Banks continues to be fixed at 2.5%. Accordingly, each Bank’s minimum capital requirements plus its capital conservation buffer for CET1 capital, Tier 1 capital and total capital ratios are 7.0%, 8.5% and 10.5% respectively.

If the Company or any of the Banks fails to maintain its capital ratios above the minimum capital requirements plus the applicable capital conservation buffer requirements, it will face increasingly strict automatic limitations on capital distributions and discretionary bonus payments to certain executive officers.

See also “Dividends, Stock Repurchases and Transfers of Funds” below for more information about the stress capital buffer determination timeline and process.

CECL TransitionRule

The Federal Banking Agencies adopted a final rule (the “CECL Transition Rule”) that provides banking institutions an optional five-year transition period to phase in the impact of the current expected credit losses (“CECL”) standard on their regulatory capital (the “CECL Transition Election”). We adopted the CECL standard (for accounting purposes) as of January 1, 2020, and made the CECL Transition Election (for regulatory capital purposes) in the first quarter of 2020.

Pursuant to the CECL Transition Rule, a banking institution could elect to delay the estimated impact of adopting CECL on its regulatory capital through December 31, 2021 and then phase in the estimated cumulative impact from January 1, 2022 through December 31, 2024. For the “day 2” ongoing impact of CECL during the initial two years, the Federal Banking Agencies used a uniform “scaling factor” of 25% as an approximation of the increase in the allowance under the CECL standard compared to the prior incurred loss methodology. Accordingly, from January 1, 2020 through December 31, 2021, electing banking institutions were permitted to add back to their regulatory capital an amount equal to the sum of the after-tax “day 1” CECL adoption impact and 25% of the increase in the allowance since the adoption of the CECL standard. From January 1, 2022 through December 31, 2024, the after-tax “day 1” CECL adoption impact and the cumulative “day 2” ongoing impact are being phased in to regulatory capital at 25% per year. The following table summarizes the capital impact delay and phase in period on our regulatory capital from years 2020 to 2025.

Capital Impact Delayed Phase In Period

Market Risk Rule

The “Market Risk Rule” supplements the Basel III Capital Rules by requiring institutions subject to the rule to adjust their risk-based capital ratios to reflect the market risk in their trading book. The Market Risk Rule generally applies to institutions with aggregate trading assets and liabilities equal to 10% or more of total assets or $1 billion or more. As of December 31, 2021, the Company and CONA are subject to the Market Risk Rule. See “MD&A—Market Risk Profile” for additional information.

FDICIA and Prompt Corrective Action

The FDICIA requires the Federal Banking Agencies to take “prompt corrective action” for banks that do not meet minimum capital requirements. The FDICIA establishes five capital ratio levels: well capitalized; adequately capitalized; undercapitalized; significantly undercapitalized; and critically undercapitalized. The three undercapitalized categories are based upon the amount by which a bank falls below the ratios applicable to an adequately capitalized institution. The capital categories relate to the FDICIA’s PCA provisions, and such capital categories may not constitute an accurate representation of the Banks’ overall financial condition or prospects.

12 Capital One Financial Corporation (COF)

Table of Contents

The Basel III Capital Rules updated the PCA framework to reflect new, higher regulatory capital minimums. For an insured depository institution to be well capitalized, it must maintain a total risk-based capital ratio of 10% or more; a Tier 1 capital ratio of 8% or more; a CET1 capital ratio of 6.5% or more; and a leverage ratio of 5% or more. An adequately capitalized depository institution must maintain a total risk-based capital ratio of 8% or more; a Tier 1 capital ratio of 6% or more; a CET1 capital ratio of 4.5% or more; a leverage ratio of 4% or more; and, for Category III and certain other institutions under the Tailoring Rules, a supplementary leverage ratio of 3% or more. The PCA provisions also authorize the Federal Banking Agencies to reclassify a bank’s capital category or take other action against banks that are determined to be in an unsafe or unsound condition or to have engaged in unsafe or unsound banking practices.

As an additional means to identify problems in the financial management of depository institutions, the FDICIA required the Federal Banking Agencies to establish certain non-capital safety and soundness standards. The standards adopted by the Federal Banking Agencies relate generally to operations and management, asset quality, interest rate exposure and executive compensation. The Federal Banking Agencies are authorized to take action against institutions that fail to meet such standards.

Basel III and United States Liquidity Rules

The Basel Committee has published a liquidity framework that includes two standards for liquidity risk supervision. One standard, the liquidity coverage ratio (“LCR”), seeks to promote short-term resilience by requiring organizations to hold sufficient high-quality liquid assets (“HQLAs”) to survive a stress scenario lasting for 30 days. The other standard, the net stable funding ratio (“NSFR”), seeks to promote longer-term resilience by requiring sufficient stable funding over a one-year period based on the liquidity characteristics of the organization’s assets and activities.

The Company and the Banks are subject to the LCR standard as implemented by the Federal Reserve and OCC (the “LCR Rule”). The LCR Rule requires the Company and each of the Banks to hold an amount of eligible HQLA that equals or exceeds 100% of its respective projected adjusted net cash outflows over a 30-day period, each as calculated in accordance with the LCR Rule. The LCR Rule requires us to calculate our LCR daily. In addition, the Company is required to make quarterly public disclosures of its LCR and certain related quantitative liquidity metrics, along with a qualitative discussion of its LCR.

Under the Tailoring Rules, as a Category III institution with less than $75 billion in weighted average short-term wholesale funding, the Company’s and the Banks’ total net cash outflows are multiplied by an outflow adjustment percentage of 85%. Although the Banks may hold more HQLA than they need to meet their LCR requirements, the LCR Rule restricts the amount of such excess HQLA held at the Banks (referred to as “Trapped Liquidity”) that can be included in the Company’s HQLA amount. Because we typically manage the Banks’ LCRs to levels well above 100%, the result is additional Trapped Liquidity as the Banks’ net cash outflows are reduced by the outflow adjustment percentage of 85%.

In October 2020, the Federal Banking Agencies finalized a rule to implement the NSFR in the United States (the “NSFR Rule”). The NSFR Rule requires the Company and each of the Banks to maintain an amount of available stable funding, which is a weighted measure of a company’s funding sources over a one-year time horizon, calculated by applying standardized weightings to equity and liabilities based on their expected stability, that is no less than a specified percentage of its required stable funding, which is calculated by applying standardized weightings to assets, derivatives exposures and certain other items based on their liquidity characteristics. As a Category III institution, the Company and the Banks are each required to maintain available stable funding in an amount at least equal to 85% of its required stable funding. The NSFR Rule became effective on July 1, 2021 and applies to the Company and each of the Banks. The NSFR Rule includes a semi-annual public disclosure requirement, with the first disclosure due 45 days after the end of the second quarter of 2023.

Enhanced Prudential Standards and Other Related Requirements

We are subject to certain enhanced prudential standards under the Dodd-Frank Act, as amended by the Economic Growth, Regulatory Relief, and Consumer Protection Act (“EGRRCPA”) and implemented by various regulations issued by the Federal Banking Agencies. The Financial Stability Oversight Council (“FSOC”) may also issue recommendations to the Federal Reserve or other primary financial regulatory agencies to apply new or enhanced standards to certain financial activities or practices.

As part of the enhanced prudential standards, the Company is required to implement resolution planning for orderly resolution in the event it faces material financial distress or failure. The FDIC issued similar rules regarding resolution planning applicable to the Banks. In addition, the OCC has issued rules requiring banks with assets of $250 billion or more to develop recovery

13 Capital One Financial Corporation (COF)

Table of Contents

plans detailing the actions they would take to remain a going concern when they experience considerable financial or operational stress, but have not deteriorated to the point that resolution is imminent.

The enhanced prudential standards also include supervisory and company-run stress testing requirements (also known as the “DFAST stress testing requirements”). In particular, the Federal Reserve is required to conduct annual stress tests on certain covered companies, including us, to ensure that the covered companies have sufficient capital to absorb losses and continue operations during adverse economic conditions, as well as to determine the Company’s stress capital buffer requirement as described above. As a covered company that is a Category III institution under the Tailoring Rules, we are also required to conduct our own stress tests and publish the results of such tests on our website or other public forum. The Company must disclose the results of its company-run stress test on a biennial basis. The OCC has adopted a similar stress test rule requiring banks with at least $250 billion in assets, including CONA, to conduct their own company-run stress tests. Under that OCC rule, CONA must also disclose the results of its stress test on a biennial basis.

In addition, the Company is required to meet liquidity risk management standards, conduct internal liquidity stress tests, and maintain a 30-day buffer of highly liquid assets, in each case, consistent with the requirements of the enhanced prudential standards. These requirements are in addition to the LCR and NSFR Rules, discussed above in “Basel III and United States Liquidity Rules.” The enhanced prudential standards also require that the Company comply with, and hold capital commensurate with, the requirements of, any regulations adopted by the Federal Reserve relating to capital planning and stress tests. Stress testing and capital planning regulations are discussed further below under “Dividends, Stock Repurchases and Transfers of Funds.” Finally, the Company is also required to establish and maintain an enterprise-wide risk management framework that includes a risk committee and a chief risk officer.

Although not a requirement of the Dodd-Frank Act, the OCC established regulatory guidelines (“Heightened Standards Guidelines”) that apply heightened standards to the governance and risk management practices of large institutions subject to its supervision, including the Banks. The Heightened Standards Guidelines establish standards for the development and implementation by the Banks of a risk governance framework.

Dividends, Stock Repurchases and Transfers of Funds

Under the Federal Reserve’s capital planning rules and related supervisory process (commonly referred to as Comprehensive Capital Analysis and Review or “CCAR” requirements), a “covered BHC,” such as the Company, must submit a capital plan to the Federal Reserve on an annual basis that contains a description of all planned capital actions, including dividends or stock repurchases, over a nine-quarter planning horizon beginning with the first quarter of the calendar year the capital plan is submitted (“CCAR cycle”).

The DFAST stress testing requirements, described above in “Enhanced Prudential Standards and Other Related Requirements,” is a complementary exercise to CCAR. It is a forward-looking exercise conducted by the Federal Reserve and each covered company to help assess whether a company has sufficient capital to absorb losses and continue operations during adverse economic conditions.

Pursuant to the capital planning rules, the Company must file its capital plan with the Federal Reserve by April 5 of each year (unless the Federal Reserve designates a later date), using data as of the end of the prior calendar year. The Federal Reserve will release the results of the supervisory stress test and notify the Company of its stress capital buffer requirement by June 30 of that year. The Company will have two business days from receipt of its stress capital buffer requirement to make any necessary adjustments to its planned capital distributions. The Federal Reserve will then finalize the stress capital buffer requirement for the Company and confirm the Company’s planned capital distributions by August 31 of that year. The Company’s final stress capital buffer requirement will be effective from the fourth quarter of the year the capital plan is submitted through the third quarter of the following year. The Company may make the planned capital distributions confirmed by the Federal Reserve. In addition, under the Stress Capital Buffer Rule, the Company is no longer required to seek prior approval of the Federal Reserve to make capital distributions in excess of those included in its capital plan so long as the Company is otherwise in compliance with the capital rule’s automatic limitations on capital distributions.

The Federal Reserve has announced that it would maintain its pre-CECL framework for calculating allowances on loans in the supervisory stress test through the 2023 cycle until the impact of CECL is better known and understood.

Dividends from the Company’s direct and indirect subsidiaries represent a major source of the funds we use to pay dividends on our capital stock, make payments on our corporate debt securities and meet our other obligations. There are various federal law

14 Capital One Financial Corporation (COF)

Table of Contents

limitations on the extent to which the Banks can finance or otherwise supply funds to the Company through dividends and loans. These limitations include minimum regulatory capital requirements, federal banking law requirements concerning the payment of dividends out of net profits or surplus, provisions of Sections 23A and 23B of the Federal Reserve Act and Regulation W governing transactions between an insured depository institution and its affiliates, as well as general federal regulatory oversight to prevent unsafe or unsound practices. In general, federal and applicable state banking laws prohibit insured depository institutions, such as the Banks, from making dividend distributions without first obtaining regulatory approval if such distributions are not paid out of available earnings or would cause the institution to fail to meet applicable capital adequacy standards.

Investment in the Company and the Banks

Certain acquisitions of our capital stock may be subject to regulatory approval or notice under federal or state law. Investors are responsible for ensuring that they do not, directly or indirectly, acquire shares of our capital stock in excess of the amount that can be acquired without regulatory approval, including under the BHC Act and the Change in Bank Control Act (“CIBC Act”).

Federal law and regulations prohibit any person or company from acquiring control of the Company or the Banks without, in most cases, prior written approval of the Federal Reserve or the OCC, as applicable. Control under the BHC Act exists if, among other things, a person or company acquires more than 25% of any class of our voting stock or otherwise has a controlling influence over us. A rebuttable presumption of control arises under the CIBC Act for a publicly traded BHC such as ourselves if a person or company acquires more than 10% of any class of our voting stock.

Additionally, COBNA and CONA are “banks” within the meaning of Chapter 7 of Title 6.2 of the Code of Virginia governing the acquisition of interests in Virginia financial institutions (“Financial Institution Holding Company Act”). The Financial Institution Holding Company Act prohibits any person or entity from acquiring, or making any public offer to acquire, control of a Virginia financial institution or its holding company without making application to, and receiving prior approval from, the Virginia Bureau of Financial Institutions.

Deposit Insurance Assessments

Each of CONA and COBNA, as an insured depository institution, is a member of the DIF maintained by the FDIC. Through the DIF, the FDIC insures the deposits of insured depository institutions up to prescribed limits for each depositor. The FDIC sets a Designated Reserve Ratio (“DRR”) for the DIF. To maintain the DIF, member institutions may be assessed an insurance premium, and the FDIC may take action to increase insurance premiums if the DRR falls below its required level.

As of June 30, 2020, the DIF reserve ratio fell to 1.30 percent. The FDIC, as required under the Federal Deposit Insurance Act, established a plan in September 2020, to restore the DIF reserve ratio to meet or exceed 1.35 percent within eight years. The FDIC’s restoration plan projects the reserve ratio to exceed 1.35 percent without increasing the deposit insurance assessment rate, subject to ongoing monitoring over the next eight years.

Source of Strength and Liability for Commonly Controlled Institutions

Under regulations issued by the Federal Reserve, a BHC must serve as a source of financial and managerial strength to its subsidiary banks (the so-called “source of strength doctrine”). The Dodd-Frank Act codified this doctrine.

Under the “cross-guarantee” provision of the Financial Institutions Reform, Recovery and Enforcement Act of 1989 (“FIRREA”), insured depository institutions such as the Banks may be liable to the FDIC with respect to any loss incurred, or reasonably anticipated to be incurred, by the FDIC in connection with the default of, or FDIC assistance to, any commonly controlled insured depository institution. The Banks are commonly controlled within the meaning of the FIRREA cross-guarantee provision.

FDIC Orderly Liquidation Authority

The Dodd-Frank Act provides the FDIC with liquidation authority that may be used to liquidate non-bank financial companies and BHCs if the Treasury Secretary, in consultation with the President and based on the recommendation of the Federal Reserve and other appropriate Federal Banking Agencies, determines that doing so is necessary, among other criteria, to mitigate serious adverse effects on U.S. financial stability. Upon such a determination, the FDIC would be appointed receiver and must liquidate the company in a way that mitigates significant risks to financial stability and minimizes moral hazard. The costs of a liquidation of the company would be borne by shareholders and unsecured creditors and then, if necessary, by risk-

15 Capital One Financial Corporation (COF)

Table of Contents

based assessments on large financial companies. The FDIC has issued rules implementing certain provisions of its liquidation authority and may issue additional rules in the future.

COVID-19 Developments

In response to disruptions in economic conditions caused by the COVID-19 pandemic, federal and state governments and agencies and government‐sponsored enterprises (“GSE”) have taken a variety of actions to support people and entities affected by the pandemic, including the passage of the Coronavirus Aid, Relief, and Economic Security Act (the “CARES Act”) in March 2020, the Paycheck Protection Program and Health Care Enhancement Act in April 2020, the Consolidated Appropriations Act, 2021 in December 2020 and the American Rescue Plan Act of 2021 in March 2021, among others. For example, the CARES Act established several programs with the Small Business Administration, including the Paycheck Protection Program (“PPP”), to provide loans to small businesses. The CARES Act also gave banking organizations an option to temporarily suspend the determination of certain qualified loans modified as a result of the COVID-19 pandemic as being troubled debt restructurings (“TDRs”), which was extended by the Consolidated Appropriations Act, 2021 and expired on January 1, 2022.

For a discussion of the risks associated with the impact of the COVID-19 pandemic and related public health measures, see “Part I—Item 1A. Risk Factors” under the heading “Our results of operations may be adversely affected by the effects of the COVID-19 pandemic.”

Climate-related Developments

Climate change and the risks it may pose to financial institutions is an area of increased focus by the Federal Banking Agencies as well as federal and state legislative bodies. In the future, new regulations or guidance may be issued, or other regulatory or supervisory actions may be taken, in this area by the Federal Banking Agencies or other regulatory agencies, or new statutory requirements may be adopted. For example, on December 16, 2021, the OCC requested feedback on draft principles designed to support the identification and management of climate-related financial risks at OCC-regulated institutions with more than $100 billion in total consolidated assets. The OCC plans to use this feedback to inform any future guidance with respect to climate-related financial risk.

Regulation of Businesses by Authorities Outside the United States

COBNA is subject to laws and regulations in foreign jurisdictions where it operates, currently in the United Kingdom (“U.K.”) and Canada. In the U.K., COBNA operates through COEP, which was established in 1999 and is an authorized payment institution regulated by the Financial Conduct Authority (“FCA”). COEP’s indirect parent, Capital One Global Corporation, is wholly-owned by COBNA and is subject to regulation by the Federal Reserve as an “agreement corporation” under the Federal Reserve’s Regulation K. COEP does not take deposits. In Canada, COBNA operates as an authorized foreign bank and is permitted to conduct its credit card business in Canada through its Canadian branch, Capital One Bank (Canada Branch) (“Capital One Canada”). Capital One Canada does not take deposits. The primary regulator of Capital One Canada is the Office of the Superintendent of Financial Institutions. The foreign legal and regulatory requirements to which COBNA’s non-U.S. operation are subject include, among others, those related to consumer protection, business practices, privacy, data protection and limits on interchange fees. For more information on foreign privacy and data protection requirements, please see above “Regulation of Business Activities—Privacy, Data Protection and Cybersecurity.” For more information on foreign regulatory activity concerning interchange fees, please see “Part I—Item 1A. Risk Factors” under the heading “Our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit and debit card networks and by legislation and regulation impacting such fees.”

16 Capital One Financial Corporation (COF)

Table of Contents

HUMAN CAPITAL RESOURCES

Our culture is rooted in putting people first with a focus on building and maintaining a workforce which fosters an inclusive environment based on diversity of our people, ideas and the merit of our work. Our workforce is our largest and one of our most valuable assets. We prioritize the recruitment, development, recognition and retention of the 50,767 employees worldwide that we had as of December 31, 2021, whom we refer to as “associates.” The following disclosures provide information on our human capital resources, including certain human capital objectives and measures that we focus on in managing our business.

Governance of Human Capital

Our full Board of Directors oversees our human capital management, including strategies, policies and practices, and diversity, inclusion and belonging (“DIB”), and is assisted by our Board’s Compensation Committee and Governance and Nominating Committee. Our Executive Committee, a committee of senior management which includes our Chief Human Resources Officer, advises, assists and makes recommendations to our Chief Executive Officer and Board of Directors on human capital matters such as human resource practices and programs, including general employee benefits and compensation programs. Our Chief Diversity, Inclusion and Belonging Officer (“Chief DIB Officer”) provides an update, at least annually, on the progress, success and challenges on workforce representation, trends and programs to the Board of Directors and Executive Committee.

Hiring, Retention and Development

We employ a comprehensive people strategy that includes significant investments in recruiting, sourcing and associate development to attract and retain top talent from all backgrounds to help drive our business’ long-term success. We recruit through a variety of channels, including professional partnerships, job fairs, online platforms, on-campus recruiting, diversity-related recruiting events and initiatives, and internship and rotational programs, among others. We empower our associates to learn new skills, meet personalized development goals, and grow their careers. Investment in associate training and professional development is critical to maintaining our talent competitiveness. Our internal enterprise learning and development team blends multiple approaches to learning to support associate development across lines of business, levels, and roles, including online and live classroom training. In addition to formal programming provided by learning professionals, including regulatory compliance, role-specific topics and others, our peer-to-peer learning strategy empowers associates to be both learners and teachers, further enhancing a culture of learning. We also focus on cultivating talent with leadership development courses, cohort-based programs, network building and coaching.

On a quarterly basis, we review our ability to attract and retain talent needed to deliver on our strategic business objectives. Each line of business and staff group reviews hiring, tenure and attrition metrics as part of this assessment, and they implement mitigation plans when needed.

Diversity, Inclusion and Belonging

We continuously strive to empower our associates to do great work by creating an equitable and inclusive workplace with a culture of belonging that values diverse perspectives, fosters collaboration and encourages innovative ideas. We aim to create a place where associates of all backgrounds can thrive by bringing their best, most authentic selves to work. Our diversity and inclusion efforts are overseen by our Chief DIB Officer. This culture of belonging rests at the heart of our DIB efforts. Central to this effort are our business resource groups, associate-led organizations which deepen our understanding of different cultures, backgrounds and experiences, and enable associates to build connections, invest in their professional development, and support our commitment to attract, develop and retain a diverse workforce. In addition, our Chief Executive Officer and the Executive Committee engage with leaders of our business resource groups to identify opportunities to further our DIB agenda, enact positive change and build on existing initiatives designed to nurture our culture and workplace environment.

Growing the diversity of our workforce at all levels, with an emphasis on leader and executive roles, is an important component of our comprehensive DIB strategy. As of December 31, 2021, key measures of our workforce representation include:

•Of the 13 members of our Board of Directors, 4 are women and 3 are people of color;

•In the U.S., of the associates who are vice president level and above, approximately 33% are women and 24% are people of color;

•In the U.S., approximately 50% of associates are people of color; and

17 Capital One Financial Corporation (COF)

Table of Contents

•Worldwide, approximately 52% of associates are women and 48% of associates are men.

Our corporate website contains additional information regarding programs and other information integral to our philosophy of diversity, inclusion and belonging. We believe in the importance of transparency and will also provide on our website the Consolidated EEO-1 Report in addition to submitting to the U.S. Equal Employment Opportunity Commission.

Compensation and Wellness

We are committed to providing a competitive total compensation package that will attract, retain and motivate talent to help drive our business’ long-term success. Our benefits, including competitive parental leave, on-site health centers, flexible work solutions, company contributions to associates’ 401(k) plans, educational assistance and other health, wellness, and financial benefits, are all designed to help associates grow and develop inside and outside of the workplace and empower them in their lives. Furthermore, pay equity has long been a core tenet of our pay philosophy and is central to our values. We annually evaluate base pay and incentive pay for all of our associates globally. This review and evaluation may occur more frequently as deemed necessary and prudent. We review groups of associates in similar roles, adjusting for factors that appropriately explain differences in pay such as job location and experience. Based on our analysis, our aggregated adjusted pay gap results show that we pay women 100% of what men are paid, and we pay people of color in the U.S. 100% of what white associates are paid. We use statistical modeling to understand what drives pay gaps, instill new practices to eliminate pay gaps in the future, and if we find unexplained pay gaps, we close them.

Communication and Connection

We communicate with our associates regularly to understand their perspectives and to hear their voices. Our senior leaders and Chief Executive Officer also communicate directly on societal events impacting our associates. To assess and improve associate retention and engagement, the Company surveys associates on a periodic basis with the assistance of third-party consultants and takes actions to address areas of associate concern. We encourage full participation and use the results to effect change and promote transparency.

18 Capital One Financial Corporation (COF)

Table of Contents

ADDITIONAL INFORMATION

Technology/Systems

We leverage information and technology to achieve our business objectives and to develop and deliver products and services that satisfy our customers’ needs. A key part of our strategic focus is the development and use of efficient, flexible computer and operational systems, such as cloud technology, to support complex marketing and account management strategies, the servicing of our customers, and the development of new and diversified products. We believe that the continued development and integration of these systems is an important part of our efforts to reduce costs, improve quality and security and provide faster, more flexible technology services. Consequently, we continuously review capabilities and develop or acquire systems, processes and competencies to meet our unique business requirements.

As part of our continuous efforts to review and improve our technologies, we may either develop such capabilities internally or rely on third-party outsourcers who have the ability to deliver technology that is of higher quality, lower cost, or both. We continue to rely on third-party outsourcers to help us deliver systems and operational infrastructure. These relationships include (but are not limited to): Amazon Web Services, Inc. (“AWS”) for our cloud infrastructure, Total System Services LLC (“TSYS”) for consumer and commercial credit card processing services for our North American and U.K. portfolios and Fidelity Information Services (“FIS”) for certain of our banking systems.

We are committed to safeguarding our customers’ and our own information and technology, implementing backup and recovery systems, and generally require the same of our third-party service providers. We take measures that mitigate against known attacks and use internal and external resources to scan for vulnerabilities in platforms, systems, and applications necessary for delivering our products and services. For a discussion of the risks associated with our use of technology systems, see “Part I—Item 1A. Risk Factors” under the headings “We face risks related to our operational, technological and organizational infrastructure” and “A cyber-attack or other security incident, including one that results in the theft, loss or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions.”

Intellectual Property and Other Proprietary Information

As part of our overall and ongoing strategy to protect and enhance our intellectual property, we rely on a variety of protections, including copyrights, trademarks, trade secrets, patents and certain restrictions on disclosure, solicitation and competition. We also undertake other measures to control access to, or distribution of, our other proprietary information. Despite these precautions, it may be possible for a third party to copy or otherwise obtain and use certain intellectual property or proprietary information without authorization. Our precautions may not prevent misappropriation or infringement of our intellectual property or proprietary information. In addition, our competitors and other third parties also file patent applications for innovations that are used in our industry. The ability of our competitors and other third parties to obtain patents may adversely affect our ability to compete and our financial results. Conversely, our ability to obtain patents may increase our competitive advantage, preserve our freedom to operate, and allow us to enter into licensing (e.g., cross-licenses) or other arrangements with third parties. There can be no assurance that we will be successful in such efforts, or that the ability of our competitors to obtain such patents may not adversely impact our financial results. For a discussion of risks associated with intellectual property, see “Part I—Item 1A. Risk Factors” under the heading “If we are not able to protect our intellectual property, our revenue and profitability could be negatively affected.”

19 Capital One Financial Corporation (COF)

Table of Contents

FORWARD-LOOKING STATEMENTS

From time to time, we have made and will make forward-looking statements, including those that discuss, among other things: strategies, goals, outlook or other non-historical matters; projections, revenues, income, returns, expenses, capital measures, capital allocation plans, accruals for claims in litigation and for other claims against us; earnings per share, efficiency ratio, operating efficiency ratio or other financial measures for us; future financial and operating results; our plans, objectives, expectations and intentions; and the assumptions that underlie these matters.

To the extent that any such information is forward-looking, it is intended to fit within the safe harbor for forward-looking information provided by the Private Securities Litigation Reform Act of 1995.

Forward-looking statements often use words such as “will,” “anticipate,” “target,” “expect,” “estimate,” “intend,” “plan,” “goal,” “believe,” “forecast,” “outlook” or other words of similar meaning. Any forward-looking statements made by us or on our behalf speak only as of the date they are made or as of the date indicated, and we do not undertake any obligation to update forward-looking statements as a result of new information, future events or otherwise. For additional information on factors that could materially influence forward-looking statements included in this Report, see the risk factors set forth under “Part I—Item 1A. Risk Factors” in this Report. You should carefully consider the factors discussed above, and in our Risk Factors or other disclosure, in evaluating these forward-looking statements.

Numerous factors could cause our actual results to differ materially from those described in such forward-looking statements, including, among other things:

•the impact of the COVID-19 pandemic on our business, financial condition and results of operations may persist for an extended period or worsen, including labor shortages and disruption of global supply chains, and could impact our estimates of lifetime expected credit losses in our loan portfolios required in computing our allowance for credit losses;

•general economic and business conditions in our local markets, including conditions affecting employment levels, interest rates, tariffs, collateral values, consumer income, creditworthiness and confidence, spending and savings that may affect consumer bankruptcies, defaults, charge-offs and deposit activity;

•an increase or decrease in credit losses, or increased delinquencies, including increases due to a worsening of general economic conditions in the credit environment, and the impact of inaccurate estimates or inadequate reserves;

•compliance with new and existing laws, regulations and regulatory expectations including the implementation of a regulatory reform agenda;

•limitations on our ability to receive dividends from our subsidiaries;

•our ability to manage adequate capital or liquidity levels, which could have a negative impact on our financial results and our ability to return capital to our stockholders;

•the extensive use, reliability, disruption, and accuracy of the models and data on which we rely;

•increased costs, reductions in revenue, reputational damage, legal liability and business disruptions that can result from data protection or privacy incidents or a cyber-attack or other similar incidents, including one that results in the theft, loss or misuse of information;

•developments, changes or actions relating to any litigation, governmental investigation or regulatory enforcement action or matter involving us;

•the amount and rate of deposit growth and changes in deposit costs;

•our ability to execute on our strategic and operational plans;

•our response to competitive pressures;

•our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit and debit card networks and by legislation and regulation impacting such fees;

20 Capital One Financial Corporation (COF)

Table of Contents

•our success in integrating acquired businesses and loan portfolios, and our ability to realize anticipated benefits from announced transactions and strategic partnerships;

•our ability to maintain a compliance, operational, technology and organizational infrastructure suitable for the nature of our business;

•the success of our marketing efforts in attracting and retaining customers;

•our risk management strategies;

•changes in the reputation of, or expectations regarding, the financial services industry or us with respect to practices, products or financial condition;

•increases or decreases in interest rates and uncertainty with respect to the interest rate environment, including the possibility of a prolonged low-interest rate environment or of negative interest rates;

•the transition away from the London Interbank Offered Rate;

•our ability to attract, retain and motivate skilled employees;

•climate change manifesting as physical or transition risks;

•our assumptions or estimates in our financial statements;

•the soundness of other financial institutions and other third parties; and

•other risk factors identified from time to time in our public disclosures, including in the reports that we file with the SEC.

We expect that the effects of the COVID-19 pandemic will heighten the risks associated with many of these factors.

Item 1A. Risk Factors

This section highlights significant factors, events, and uncertainties that make an investment in our securities risky. The events and consequences discussed in these risk factors could, in circumstances we may not be able to accurately predict, recognize, or control, have a material adverse effect on our business, growth, reputation, prospects, financial condition, operating results, cash flows, liquidity, and stock price. These risk factors do not identify all risks that we face; our operations could also be affected by factors, events, or uncertainties that are not presently known to us or that we currently do not consider to present significant risks to our operations. In addition, the global economic and political climate may amplify many of these risks.

Summary of Risk Factors

Below is a summary of the principal factors that make an investment in our securities risky. This summary does not address all of the risks that we face. Additional discussion of the risks summarized in this risk factor summary, and other risks that we face, can be found below and should be carefully considered, together with other information in this Form 10-K and our other filings with the SEC, before making an investment decision regarding our common stock.

•Our results of operations may be adversely affected by the effects of the COVID-19 pandemic.

•Changes and instability in the macroeconomic environment, consumer confidence and customer behavior may adversely affect our business.

•Financial market instability and volatility could adversely affect our business.

•We may experience increased delinquencies, credit losses, inaccurate estimates and inadequate reserves.

•We may not be able to maintain adequate capital or liquidity levels, which could have a negative impact on our financial results and our ability to return capital to our stockholders.

21 Capital One Financial Corporation (COF)

Table of Contents

•Limitations on our ability to receive dividends from our subsidiaries could affect our liquidity and ability to pay dividends and repurchase common stock.

•We face risks related to our operational, technological and organizational infrastructure.

•A cyber-attack or other security incident, including one that results in the theft, loss or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions.

•Our required compliance with applicable laws and regulations related to privacy, data protection and data security may increase our costs, reduce our revenue, increase our legal exposure and limit our ability to pursue business opportunities.

•We face risks resulting from the extensive use of models and data.

•Compliance with new and existing laws, regulations and regulatory expectations is costly and complex.

•Our businesses are subject to the risk of increased litigation, government investigations and regulatory enforcement.

•We face intense competition in all of our markets.

•Our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit and debit card networks and by legislation and regulation impacting such fees.

•If we are not able to invest successfully in and introduce digital and other technological developments across all our businesses, our financial performance may suffer.

•We may fail to realize the anticipated benefits of our mergers, acquisitions and strategic partnerships.

•Reputational risk and social factors may impact our results and damage our brand.

•If we are not able to protect our intellectual property, our revenue and profitability could be negatively affected.

•Our risk management strategies may not be fully effective in mitigating our risk exposures in all market environments or against all types of risk.

•Fluctuations in market interest rates or volatility in the capital markets could adversely affect our income and expense, the value of assets and obligations, our regulatory capital, cost of capital or liquidity.

•The transition away from London Interbank Offered Rate (“LIBOR”) may adversely affect our business.

•Our business could be negatively affected if we are unable to attract, retain and motivate skilled employees.

•We face risks from unpredictable catastrophic events.

•Climate change manifesting as physical or transition risks could adversely affect our operations, businesses and customers.

•We face risks from the use of or changes to assumptions or estimates in our financial statements.

•The soundness of other financial institutions and other third parties could adversely affect us.

General Economic and Market Risks

Our results of operations may be adversely affected by the effects of the COVID-19 pandemic.

Although the global economy has begun to recover from the COVID-19 pandemic and many health and safety restrictions have been lifted and vaccine distribution has increased, certain adverse consequences of the pandemic, especially as a result of the emergence of the Omicron variant in late 2021, continue to impact the macroeconomic environment and may persist for some time. Such adverse consequences include labor shortages and disruptions of global supply chains. The growth in economic activity and demand for goods and services, alongside labor shortages and supply chain complications, has also contributed to rising inflationary pressures and could adversely affect our business. Should these ongoing effects of the pandemic continue for

22 Capital One Financial Corporation (COF)

Table of Contents

an extended period or worsen, our purchase volume, loan balances and the overall demand for our products and services may be significantly impacted, which could adversely affect our revenue and other results of operations. In addition, we could experience higher credit losses in our loan portfolios and increases in our allowance for credit losses beyond current levels. We could also experience impairments of other financial assets and other negative impacts on our financial position, including possible constraints on liquidity and capital, as well as higher costs of capital. Even after the COVID-19 pandemic has subsided, we may continue to experience adverse impacts to our business and results of operations, which could be material, as a result of the macroeconomic impact and any recession that has occurred or may occur in the future.

The COVID-19 pandemic caused us to modify our business practices and operations, including providing a range of forbearance options to our customers in certain circumstances. We may need to further modify our practices and operations as the pandemic remains dynamic and the emergence of variants resistant to existing vaccines remains uncertain. We also implemented work-from-home policies for a vast majority of our employees, and social distancing plans for our employees who are working from Capital One facilities. Nearly all of our Cafés and bank branches across our network are open with increased safety precautions. We will continue to monitor local conditions to ensure the safety of our associates and customers while providing critical banking services. These measures could impair our ability to perform critical functions and may adversely impact our results of operations. In addition, these measures and other changes in consumer behavior as a result of the COVID-19 pandemic may require changes to retail distribution strategies and adversely impact our investments in our bank premises and equipment and other retail distribution assets, leading to increased costs and exposure to additional risks. We may take further actions as required by government authorities or that we otherwise determine are in the best interests of our customers, employees and business partners.

Since the inception of the COVID-19 pandemic, federal, state, local and foreign governmental authorities enacted regulations and protocols in response to the COVID-19 pandemic, including governmental programs intended to provide economic relief to businesses and individuals. We participated in certain of these programs, including participating as an eligible lender in the Small Business Administration’s Paycheck Protection Program. Our participation in and execution of any such programs may cause operational, compliance, reputational and credit risks, which could result in litigation, governmental action or other forms of loss. The extent of these impacts, which may be substantial, depends, in part, on the degree of our participation in these programs. There remains significant uncertainty regarding the measures that authorities will enact in the future and the ultimate impact of the legislation, regulations and protocols that have been and will be enacted. Moreover, we expect that the effects of the COVID-19 pandemic will heighten many of the other known risks described herein. See “Part I—Item 1.—Business—Overview—Coronavirus Disease 2019 (COVID-19) Pandemic”.

The extent to which the consequences of the COVID-19 pandemic affect our businesses, results of operations and financial condition, as well as our regulatory capital and liquidity ratios and our ability to take capital actions, will depend on future developments that remain uncertain, including, for example, the rate of distribution and administration of vaccines globally, the severity and duration of any resurgence of COVID-19 variants, future actions taken by governmental authorities, central banks and other third parties in response to the pandemic, and the effects on our customers, counterparties, employees and third-party service providers.

Changes and instability in the macroeconomic environment, consumer confidence and customer behavior may adversely affect our business.

We offer a broad array of financial products and services to consumers, small businesses and commercial clients. A prolonged period of economic volatility, slow growth, or a significant deterioration in economic conditions, in the U.S., Canada or the U.K., could have a material adverse effect on our financial condition and results of operations as customers default on their loans, maintain lower deposit levels or, in the case of credit card accounts, carry lower balances and reduce credit card purchase activity.

Some of the risks we face in connection with adverse changes and instability in the macroeconomic environment, including changes in consumer confidence levels and behavior, include the following:

•Changes in payment patterns, increases in delinquencies and default rates, decreased consumer spending, inflation, lower demand for credit and shifts in consumer payment behavior towards avoiding late fees, finance charges and other fees;

•Increases in our charge-off rate caused by bankruptcies and reduced ability to recover debt that we have previously charged-off;

23 Capital One Financial Corporation (COF)

Table of Contents

•Decreased reliability of the process and models we use to estimate our allowance for loan and lease losses, particularly if unexpected variations in key inputs and assumptions cause actual losses to diverge from the projections of our models and our estimates become increasingly subject to management’s judgment. See “We face risks resulting from the extensive use of models and data.”

The U.K. and the European Union agreed to a free trade deal at the end of 2020 relating to the U.K.’s exit from the European Union. Although this deal provides greater near-term stability, there is still some degree of uncertainty as to the relationship between the U.K and the European Union, which may increase volatility in the regional and global financial markets. We continue to consider and monitor the potential impacts, and other factors that could also impact U.K. economic performance.

Financial market instability and volatility could adversely affect our business.

Our ability to borrow from other financial institutions or to engage in funding transactions on favorable terms or at all could be adversely affected by disruptions in the capital markets or other events, including actions by rating agencies and deteriorating investor expectations. In addition, fluctuations in interest rates, credit spreads and other market factors could negatively impact our results of operations. Both shorter-term and longer-term interest rates remain below long-term historical averages and the yield curve has been relatively flat compared to past periods. A flat yield curve combined with low interest rates generally leads to lower revenue and reduced margins because it can decrease the spread between asset yields and funding costs. Sustained periods of time with a flat yield curve coupled with low interest rates, or an inversion of the yield curve, could have a material adverse effect on our net interest margin and earnings.

Credit Risk

We may experience increased delinquencies, credit losses, inaccurate estimates and inadequate reserves.

Like other lenders, we face the risk that our customers will not repay their loans. A customer’s ability and willingness to repay us can be adversely affected by decreases in the income of the borrower or increases in their payment obligations to other lenders, whether as a result of higher debt levels or rising interest rates, by rising levels of inflation, or by restricted availability of credit generally. We may fail to quickly identify and reduce our exposure to customers that are likely to default on their payment obligations, whether by closing credit lines or restricting authorizations. Our ability to manage credit risk also is affected by legal or regulatory changes (such as restrictions on collections, bankruptcy laws, minimum payment regulations and re-age guidance), competitors’ actions and consumer behavior, and depends on the effectiveness of our collections staff, techniques and models.

Rising losses or leading indicators of rising losses (such as higher delinquencies, higher rates of nonperforming loans, higher bankruptcy rates, lower collateral values, elevated unemployment rates or changing market terms) may require us to increase our allowance for credit losses, which would decrease our profitability if we are unable to raise revenue or reduce costs to compensate for higher losses. In particular, we face the following risks in this area:

•Missed Payments: Our customers may miss payments. Loan charge-offs (including from bankruptcies) are generally preceded by missed payments or other indications of worsening financial condition for our customers. Historically, customers are more likely to miss payments during an economic downturn or prolonged periods of slow economic growth. In addition, we face the risk that consumer and commercial customer behavior may change (for example, an increase in the unwillingness or inability of customers to repay debt, which may be heightened by increasing interest rates or levels of consumer debt), causing a long-term rise in delinquencies and charge-offs.

•Incorrect Estimates of Expected Losses: The credit quality of our portfolio can have a significant impact on our earnings. We allow for and reserve against credit risks based on our assessment of expected credit losses in our loan portfolios. This process, which is critical to our financial condition and results of operations, requires complex judgments, including forecasts of economic conditions. We may underestimate our expected losses and fail to hold an allowance for credit losses sufficient to account for these losses. Incorrect assumptions could lead to material underestimations of expected credit losses and an inadequate allowance for credit losses.

•Inaccurate Underwriting: Our ability to accurately assess the creditworthiness of our customers may diminish, which could result in an increase in our credit losses and a deterioration of our returns. See “Our risk management strategies may not be fully effective in mitigating our risk exposures in all market environments or against all types of risk.”

24 Capital One Financial Corporation (COF)

Table of Contents

•Business Mix: We engage in a diverse mix of businesses with a broad range of potential credit exposure. Because we originate a relatively greater proportion of consumer loans in our loan portfolio compared to other large bank peers and originate both prime and subprime credit card accounts and auto loans, we may experience higher delinquencies and a greater number of accounts charging off compared to other large bank peers, which could result in increased credit losses, operating costs and regulatory scrutiny. Additionally, a change in this business mix over time to include proportionally more consumer loans or subprime credit card accounts or auto loans could adversely affect the credit quality of our portfolio.

•Increasing Charge-off Recognition/Allowance for Credit Losses: We account for the allowance for credit losses according to accounting and regulatory guidelines and rules, including Financial Accounting Standards Board (“FASB”) standards and the Federal Financial Institutions Examination Council (“FFIEC”) Account Management Guidance. Effective as of January 1, 2020, we adopted the CECL standard which is based on expected lifetime losses rather than incurred losses. Adoption of the CECL standard has resulted and may continue to result in an increase to our reserves for credit losses on financial instruments with a resulting adverse impact on our financial condition. The continued impact of CECL on our results will depend on the characteristics of our financial instruments, economic conditions, and our economic and loss forecasts. The application of the CECL standard requires us to increase reserves faster and to a higher level in an economic downturn, resulting in greater impact to our results and our capital ratios than we would have experienced in similar circumstances prior to the adoption of CECL. In addition, because credit cards represent a significant portion of our product mix, we could be disproportionately affected by use of the CECL standard, as compared to our large bank peers with a different product mix.

•Insufficient Asset Values: The collateral we have on secured loans could be insufficient to compensate us for credit losses. When customers default on their secured loans, we attempt to recover collateral where permissible and appropriate. However, the value of the collateral may not be sufficient to compensate us for the amount of the unpaid loan, and we may be unsuccessful in recovering the remaining balance from our customers. Decreases in real estate and other asset values adversely affect the collateral value for our commercial lending activities, while the auto business is similarly exposed to collateral risks arising from the auction markets that determine used car prices. Borrowers may be less likely to continue making payments on loans if the value of the property used as collateral for the loan is less than what the borrower owes, even if the borrower is still financially able to make the payments. In that circumstance, the recovery of such property could be insufficient to compensate us for the value of these loans upon a default. In our auto business, business and economic conditions that negatively affect household incomes, housing prices and consumer behavior, as well as technological advances that make older cars obsolete faster, could decrease (i) the demand for new and used vehicles and (ii) the value of the collateral underlying our portfolio of auto loans, which could cause the number of consumers who become delinquent or default on their loans to increase.

•Geographic and Industry Concentration: Although our consumer lending is geographically diversified, approximately 45% of our commercial real estate loan portfolio is concentrated in the Northeast region. The regional economic conditions in the Northeast affect the demand for our commercial products and services as well as the ability of our customers to repay their commercial real estate loans and the value of the collateral securing these loans. An economic downturn or prolonged period of slow economic growth in, or a catastrophic event that disproportionately affects, including as a result of climate change, the Northeast region could have a material adverse effect on the performance of our commercial real estate loan portfolio and our results of operations. In addition, our Commercial Banking strategy includes an industry-specific focus. If any of the industries that we focus on experience changes, we may experience increased credit losses and our results of operations could be adversely impacted.

Capital and Liquidity Risk

We may not be able to maintain adequate capital or liquidity levels, which could have a negative impact on our financial results and our ability to return capital to our stockholders.

Financial institutions are subject to extensive and complex capital and liquidity requirements, which are subject to change. These requirements affect our ability to lend, grow deposit balances, make acquisitions and distribute capital. Failure to maintain adequate capital or liquidity levels, whether due to adverse developments in our business or the economy or to changes in the applicable requirements, could subject us to a variety of remedies available to our regulators. These include limitations on the ability to pay dividends and/or repurchase shares and the issuance of a capital directive to increase capital. Such limitations or capital directive could have a material adverse effect on our business and results of operations.

25 Capital One Financial Corporation (COF)

Table of Contents

We consider various factors in the management of capital, including the impact of both internal and supervisory stress scenarios on our capital levels as determined by both our internal modeling and the Federal Reserve’s modeling of our capital position in supervisory stress tests. There can be significant differences between our modeling and the Federal Reserve’s projections for a given supervisory stress scenario and between the capital needs suggested by our internal stress scenarios relative to the supervisory scenarios. Therefore, although our estimated capital levels under stress disclosed as part of the stress testing processes may suggest that we have a particular capacity to return capital to stockholders and remain well capitalized under stress, the Federal Reserve’s modeling, our internal modeling of another scenario and/or other factors related to our capital management process may reflect a lower capacity to return capital to stockholders than that indicated by the projections released in the stress testing processes. This in turn, could lead to restrictions on our ability to pay dividends and engage in share repurchases. See “Part I—Item 1. Business—Supervision and Regulation” for additional information.

We also consider various factors in the management of liquidity, including maintaining sufficient liquid assets to meet the requirements of several internal and regulatory stress tests. There can be significant differences in estimated liquidity needs between internal and regulatory stress testing, and liquidity resources required to meet regulatory requirements, such as applicable LCR and NSFR requirements, may exceed what would otherwise be required to satisfy internal liquidity metrics and stress testing. Regulatory liquidity stress testing and regulatory liquidity requirements may, therefore, require us to take actions to increase our liquid assets or alter our activities or funding sources, which could negatively affect our financial results or our ability to return capital to our stockholders. See “Part I—Item 1. Business—Supervision and Regulation” for additional information.

In response to economic uncertainty due to the COVID-19 pandemic, the Federal Reserve required certain large BHCs, including us, to suspend share repurchases and cap common stock dividends and subsequently extended the restrictions into the first half of 2021 with certain modifications to permit resumptions of share repurchases. Although these temporary restrictions on our capital actions ended on June 30, 2021, it is possible that the Federal Reserve could impose similar restrictions in the future. Further changes to applicable capital and liquidity requirements could result in unexpected or new limitations on our ability to pay dividends and engage in share repurchases.

Limitations on our ability to receive dividends from our subsidiaries could affect our liquidity and ability to pay dividends and repurchase common stock.

We are a separate and distinct legal entity from our subsidiaries, including the Banks and our broker-dealer subsidiaries. Dividends to us from these direct and indirect subsidiaries have represented a major source of funds for us to pay dividends on our common and preferred stock, repurchase common stock, make payments on corporate debt securities and meet other obligations. There are various federal law limitations on the extent to which the Banks can finance or otherwise supply funds to us through dividends and loans. These limitations include minimum regulatory capital requirements, federal banking law requirements concerning the payment of dividends out of net profits or surplus, Sections 23A and 23B of the Federal Reserve Act and Regulation W governing transactions between an insured depository institution and its affiliates, as well as general federal regulatory oversight to prevent unsafe or unsound practices. Our broker-dealer subsidiaries are also subject to laws and regulations, including net capital requirements, that may limit their ability to pay dividends or make other distributions to us. If our subsidiaries’ earnings are not sufficient to make dividend payments to us while maintaining adequate capital levels, our liquidity may be affected and we may not be able to make dividend payments to our common or preferred stockholders, repurchase our common stock, make payments on outstanding corporate debt securities or meet other obligations, each and any of which could have a material adverse impact on our results of operations, our financial position or the perception of our financial health. See “Part I—Item 1. Business—Supervision and Regulation” for additional information regarding dividend limitations applicable to us and the Banks.

Operational Risk

We face risks related to our operational, technological and organizational infrastructure.

Our ability to retain and attract customers depends on our ability to develop, operate, and adapt our technology and organizational infrastructure in a rapidly changing environment. In addition, we must accurately process, record and monitor an increasingly large number of complex transactions. Digital technology, data and software development are deeply embedded into our business model and how we work.

Similar to other large corporations, we are exposed to operational risk that can manifest itself in many ways, such as errors in execution, inadequate processes, inaccurate models, faulty or disabled technological infrastructure, malicious disruption and

26 Capital One Financial Corporation (COF)

Table of Contents

fraud by employees or persons outside of our company, whether through attacks on Capital One directly or on our customers. In addition, we are heavily dependent on the security, capability and continuous availability of the technology systems that we use to manage our internal financial and other systems, monitor risk and compliance with regulatory requirements, provide services to our customers, develop and offer new products and communicate with stakeholders. We also face risk of adverse customer impacts and business disruption arising from the execution of strategic initiatives we may pursue across our operations.

If we do not maintain the necessary operational, technological and organizational infrastructure to operate our business, including to maintain the resiliency and security of that infrastructure, our business and reputation could be materially adversely affected. We also are subject to disruptions to our systems arising from events that are wholly or partially beyond our control, which may include computer viruses, electrical or telecommunications outages, design flaws in foundational components or platforms, availability and quality of vulnerability patches from key vendors, cyber-attacks and other security incidents (including Distributed Denial of Service (“DDOS”) and other attacks on our infrastructure as discussed below), natural disasters, other damage to property or physical assets, or events arising from local or larger scale politics, including terrorist acts. Any failure to maintain our infrastructure or disruption of our systems and applications could diminish our ability to operate our businesses, service customer accounts and protect customers’ information, or result in potential liability to customers, reputational damage, regulatory intervention and customers’ loss of confidence in our businesses, any of which could result in a material adverse effect.

We also rely on the business infrastructure and systems of third parties with which we do business and to whom we outsource the operation, maintenance and development of our information technology and communications systems. We have migrated substantially all aspects of our core information technology systems and customer-facing applications to third-party cloud infrastructure platforms, principally AWS. If we fail to administer these new environments in a well-managed, secure and effective manner, or if such platforms become unavailable or do not meet their service level agreements for any reason, we may experience unplanned service disruption or unforeseen costs which could result in material harm to our business and results of operations. We must successfully develop and maintain information, financial reporting, disclosure, privacy, data-protection, data security and other controls adapted to our reliance on outside platforms and providers. In addition, AWS, or other service providers, could experience system breakdowns or failures, outages, downtime, cyber-attacks and other security incidents, adverse changes to financial condition, bankruptcy, or other adverse conditions, which could have a material adverse effect on our business and reputation. Thus, the substantial amount of our infrastructure that we outsource to AWS or to other third parties may increase our risk exposure.

Any disruptions, failures or inaccuracies of our operational processes, technology systems and models, including those associated with improvements or modifications to such technology systems and models, could cause us to be unable to market and manage our products and services, manage our risk, meet our regulatory obligations or report our financial results in a timely and accurate manner, all of which could have a negative impact on our results of operations. In addition, our ongoing investments in infrastructure, which are necessary to maintain a competitive business, integrate acquisitions and establish scalable operations, may increase our expenses. As our business develops, changes or expands, additional expenses can arise as a result of a reevaluation of business strategies, management of outsourced services, asset purchases or other acquisitions, structural reorganization, compliance with new laws or regulations, the integration of newly acquired businesses, or the prevention or occurrence of cyber-attacks and other security incidents. If we are unable to successfully manage our expenses, our financial results will be negatively affected. Changes to our business, including those resulting from our strategic objectives, also requires robust governance to ensure that our objectives are executed as intended without adversely impacting our customers, associates, operations or financial performance. Ineffective change management oversight and governance over the execution of our strategic objectives could expose us to operational, strategic and reputational risk and could negatively impact customers or our financial performance.

A cyber-attack or other security incident, including one that results in the theft, loss or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions.

Our ability to provide our products and services, many of which are web-based, and communicate with our customers, depends upon the management and safeguarding of information systems and infrastructure, networks, software, data engineering, technology, methodologies and business secrets, including those of our service providers. Our products and services involve the collection, authentication, management, usage, storage, transmission and eventual destruction of sensitive and confidential information, including personal information, regarding our customers and their accounts, our employees, our partners and other

27 Capital One Financial Corporation (COF)

Table of Contents

third parties with which we do business. We also have arrangements in place with third parties through which we share and receive information about their customers who are or may become our customers.

Technologies, systems, networks, and other devices of Capital One, as well as those of our employees, service providers, partners and other third parties with whom we interact, have been and may continue to be the subject of cyber-attacks and other security incidents, including DDOS attacks, computer viruses, hacking, malware, ransomware, credential stuffing, or phishing or other forms of social engineering. Such cyber-attacks and other security incidents are designed to lead to various harmful outcomes, such as unauthorized transactions in Capital One accounts, unauthorized or unintended access to or release, gathering, monitoring, disclosure, loss, destruction, corruption, disablement, encryption, misuse, modification or other processing of confidential or sensitive information (including personal information), intellectual property, software, methodologies or business secrets, disruption, sabotage or degradation of service, systems or networks, or other damage. These threats may derive from, among other things, error, fraud or malice on the part of our employees, insiders, or third parties or may result from accidental technological failure. Any of these parties may also attempt to fraudulently induce employees, service providers, customers, partners or other third-party users of our systems or networks to disclose confidential or sensitive information (including personal information) in order to gain access to our systems, networks or data or that of our customers, partners, or third parties with whom we interact, or to unlawfully obtain monetary benefit through misdirected or otherwise improper payment. For example, any party that obtains our confidential or sensitive information (including personal information) through a cyber-attack or other security incident may use this information for ransom, to be paid by us or a third party, as part of a fraudulent activity that is part of a broader criminal activity, or for other illicit purposes.

For example, on July 29, 2019, we announced that on March 22 and 23, 2019 an outside individual gained unauthorized access to our systems (the “Cybersecurity Incident”). This individual obtained certain types of personal information relating to people who had applied for our credit card products and to our credit card customers. While the Cybersecurity Incident has been remediated, it has resulted in fines, litigation, government investigations and other regulatory enforcement inquiries, as well as consent orders with certain regulatory agencies. Cyber and information security risks for large financial institutions like us continue to increase due to the proliferation of new technologies, the industry-wide shift to reliance upon the internet to conduct financial transactions, and the increased sophistication and activities of malicious actors, organized crime, perpetrators of fraud, hackers, terrorists, activists, formal and informal instrumentalities of foreign governments and other external parties. In addition, our customers access our products and services using personal devices that are necessarily external to our security control systems. There has also been a significant proliferation of consumer information available on the internet resulting from breaches of third-party entities, including personal information, log-in credentials and authentication data. While we were not directly involved in these third-party breach events, the stolen information can create a vulnerability for our customers if their Capital One log-in credentials are the same as or similar to the credentials that have been compromised on other sites. This vulnerability could include the risk of unauthorized account access, data loss and fraud. The use of artificial intelligence, “bots” or other automation software can increase the velocity and efficacy of these types of attacks. The ongoing COVID-19 pandemic also increases the risk that we may experience cyber incidents as a result of our employees, service providers, partners and other third parties with which we interact working remotely on systems, networks and environments over which we have less control.

The methods and techniques employed by malicious actors change frequently, are increasingly sophisticated and often are not fully recognized or understood until after they have occurred, and some techniques could occur and persist for an extended period of time before being detected. For example, although we immediately fixed the configuration vulnerability that was exploited in the Cybersecurity Incident once we discovered the unauthorized access, a period of time elapsed between the occurrence of the unauthorized access and the time when we discovered it. In other circumstances, we and our service providers and other third parties with which we interact may be unable to anticipate or identify certain attack methods in order to implement effective preventative measures or mitigate or remediate the damages caused in a timely manner. We may also be unable to hire and develop talent capable of detecting, mitigating or remediating these risks. Although we seek to maintain a robust suite of authentication and layered information security controls, any one or combination of these controls could fail to detect, mitigate or remediate these risks in a timely manner. We will likely face an increasing number of attempted cyber-attacks as we expand our mobile and other internet-based products and services, as well as our usage of mobile and cloud technologies and as we provide more of these services to a greater number of retail clients.

A disruption or breach, including as a result of a cyber-attack such as the Cybersecurity Incident, or media reports of perceived security vulnerabilities at Capital One or at our service providers, could result in significant legal and financial exposure, regulatory intervention, litigation, remediation costs, card reissuance, supervisory liability, damage to our reputation or loss of confidence in the security of our systems, products and services that could adversely affect our business. There can be no assurance that unauthorized access or cyber incidents similar to the Cybersecurity Incident will not occur or that we will not

28 Capital One Financial Corporation (COF)

Table of Contents

suffer material losses in the future. If future attacks are successful or if customers are unable to access their accounts online for other reasons, it could adversely impact our ability to service customer accounts or loans, complete financial transactions for our customers or otherwise operate any of our businesses or services. In addition, a breach or attack affecting one of our service providers or other third parties with which we interact could harm our business even if we do not control the service that is attacked.

Further, our ability to monitor our service providers’ cybersecurity practices is limited. Although we generally have agreements relating to cybersecurity and data privacy in place with our service providers, we cannot guarantee that such agreements will prevent a cyber incident impacting our systems or information or enable us to obtain adequate or any reimbursement from our service providers in the event we should suffer any such incidents. However, due to applicable laws and regulations or contractual obligations, we may be held responsible for cyber incidents attributed to our service providers as they relate to the information we share with them.

In addition, the increasing prevalence and the evolution of cyber-attacks and other efforts to breach or disrupt our systems or networks or those of our customers, service providers, partners or other third parties with which we interact has led, and will likely continue to lead, to increased costs to us with respect to preventing, mitigating and remediating these risks, as well as any related attempted fraud. In order to address ongoing and future risks, we must expend significant resources to support protective security measures, investigate and remediate any vulnerabilities of our information systems and infrastructure and invest in new technology designed to mitigate security risks. Further, high profile cyber incidents at Capital One or other large financial institutions could lead to a general loss of customer confidence in financial institutions that could negatively affect us, including harming the market perception of the effectiveness of our security measures or the financial system in general, which could result in reduced use of our financial products. We have insurance against some cyber risks and attacks; nonetheless, our insurance coverage may not be sufficient to offset the impact of a material loss event (including if our insurer denies coverage as to any particular claim in the future), and such insurance may increase in cost or cease to be available on commercially reasonable terms, or at all, in the future.

Our required compliance with applicable laws and regulations related to privacy, data protection and data security may increase our costs, reduce our revenue, increase our legal exposure and limit our ability to pursue business opportunities.

We are subject to a variety of continuously evolving and developing laws and regulations in the United States at the federal, state and local level regarding privacy, data protection and data security, including those related to the collection, storage, handling, use, disclosure, transfer, security and other processing of personal information. For example, at the federal level, we are subject to the GLBA, among other laws and regulations. In addition, in November 2021, the Federal Reserve, OCC, and FDIC issued a final rule that, among other things, requires all banking organizations in the United States to notify their primary federal regulators of certain material computer-security incidents as soon as possible and no later than 36 hours after determining that the incident has occurred. At the state level, the CCPA went into effect on January 1, 2020 and covers certain companies that process personal information of California residents. The CCPA was recently amended by the CPRA, which will become effective in most material respects on January 1, 2023. Numerous other states have also enacted or are in the process of enacting state-level privacy, data protection and/or data security laws and regulations.

We also are, or may become, subject to continuously evolving and developing laws and regulations in other jurisdictions regarding privacy, data protection and data security. For example, in Canada we are subject to the Personal Information Protection and Electronic Documents Act (“PIPEDA”). In addition, the EU GDPR applies EU data protection law to all companies processing data of EU residents, regardless of the company’s location. We also are subject to the U.K. GDPR (which is how GDPR has been implemented into U.K. law). These laws and regulations, and similar laws and regulations in other jurisdictions, impose strict requirements regarding the collection, storage, handling, use, disclosure, transfer, security and other processing of personal information, which may have adverse consequences, including significant compliance costs and severe monetary penalties for non-compliance. Significant uncertainty exists as privacy, data protection, and data security laws may be interpreted and applied differently from country to country and may create inconsistent or conflicting requirements.

Further, we make public statements about our use, collection, disclosure and other processing of personal information through our privacy policies, information provided on our website and press statements. Although we endeavor to comply with our public statements and documentation, we may at times fail to do so or be alleged to have failed to do so. The publication of our privacy policies and other statements that provide promises and assurances about privacy, data protection and data security can subject us to potential government or legal action if they are found to be deceptive, unfair or misrepresentative of our actual practices.

29 Capital One Financial Corporation (COF)

Table of Contents

Our efforts to comply with PIPEDA, GLBA, GDPR, U.K. GDPR, CCPA, CPRA and other privacy, data protection and data security laws and regulations, as well as our posted privacy policies, and related contractual obligations to third parties, entail substantial expenses, may divert resources from other initiatives and projects, and could limit the services we are able to offer. Furthermore, enforcement actions and investigations by regulatory authorities related to data security incidents and privacy, data protection and data security violations continue to increase. The enactment of more restrictive laws or regulations, or future enforcement actions or investigations, could impact us through increased costs or restrictions on our business, and any noncompliance or perceived noncompliance could result in monetary or other penalties, harm to our reputation and significant legal liability.

We face risks resulting from the extensive use of models and data.

We rely on quantitative models, our ability to manage and aggregate data in an accurate and timely manner, assess and manage our various risk exposures, estimate certain financial values and manage compliance with regulatory capital requirements. Models may be used in such processes as determining the pricing of various products, grading loans and extending credit, measuring interest rate and other market risks, predicting deposit levels or loan losses, assessing capital adequacy and calculating managerial and regulatory capital levels, estimating the value of financial instruments and balance sheet items, and other operational functions. Our risk reporting and management, including business decisions based on information incorporating models, depend on the effectiveness of our models and our policies, programs, processes and practices governing how data is acquired, validated, stored, protected, processed and analyzed. Any issues with the quality or effectiveness of our data aggregation and validation procedures, as well as the quality and integrity of data inputs, formulas or algorithms, could result in inaccurate forecasts, ineffective risk management practices or inaccurate risk reporting. In addition, models based on historical data sets might not be accurate predictors of future outcomes and their ability to appropriately predict future outcomes may degrade over time. While we continuously update our policies, programs, processes and practices, many of our data management, aggregation and implementation processes are manual and subject to human error or system failure. Failure to manage data effectively and to aggregate data in an accurate and timely manner may limit our ability to manage current and emerging risk, to produce accurate financial, regulatory and operational reporting as well as to manage changing business needs. If our risk management framework is ineffective, we could suffer unexpected losses which could materially adversely affect our results of operation or financial condition. Also, any information we provide to the public or to our regulators based on poorly designed or implemented models could be inaccurate or misleading. Some of the decisions that our regulators make, including those related to capital distribution to our stockholders, could be affected adversely due to the perception that the quality of the models used to generate the relevant information is insufficient.

Legal and Regulatory Risk

Compliance with new and existing laws, regulations and regulatory expectations is costly and complex.

A wide array of laws and regulations, including banking and consumer lending laws and regulations, apply to almost every aspect of our business. We and our subsidiaries are also subject to supervision and examination by multiple regulators, and the manner in which our regulators interpret applicable laws and regulations may affect how we comply with them. Failure to comply with these laws and regulations, even if the failure was inadvertent or reflects a difference in interpretation, could subject us to restrictions on our business activities, fines, criminal sanctions and other penalties, and/or damage to our reputation with regulators, our customers or the public. Hiring, training and retaining qualified compliance and legal personnel, and establishing and maintaining risk management and compliance-related systems, infrastructure and processes, is difficult and may lead to increased expenses. These efforts and the associated costs could limit our ability to invest in other business opportunities.

Applicable rules and regulations may affect us disproportionately compared to our competitors or in an unforeseen manner. For example, we have a large number of customer accounts in our credit card and auto lending businesses and we have made the strategic choice to originate and service subprime credit card and auto loans, which typically have higher delinquencies and charge-offs than prime customer accounts. As a result, we have significant involvement with credit bureau reporting and the collection and recovery of delinquent and charged-off debt, primarily through customer communications, the filing of litigation against customers in default, the periodic sale of charged-off debt and vehicle repossession. These activities are subject to enhanced legal and regulatory scrutiny from regulators, courts and legislators. Any future changes to or legal liabilities resulting from our business practices in these areas, including our debt collection practices, whether mandated by regulators, courts, legislators or otherwise, could have a material adverse impact on our financial condition.

30 Capital One Financial Corporation (COF)

Table of Contents

The legislative and regulatory environment is beyond our control, may change rapidly and unpredictably, and may negatively influence our revenue, costs, earnings, growth, liquidity and capital levels. For example, there may be future rulemaking in emerging regulatory areas such as climate-related risks and new technologies, including distributed ledger technology and cryptocurrencies. In addition, some rules and regulations may be subject to litigation or other challenges that delay or modify their implementation and impact on us. Adoption of new technologies, such as distributed ledger technologies, tokenization, cloud computing, artificial intelligence and machine learning technologies, can present unforeseen challenges in applying and relying on existing compliance systems.

Certain laws and regulations, and any interpretations and applications with respect thereto, are generally intended to protect consumers, borrowers, depositors, the DIF, the U.S. banking and financial system, and financial markets as a whole, but not stockholders. Our success depends on our ability to maintain compliance with both existing and new laws and regulations. For a description of the material laws and regulations to which we are subject, see “Part I—Item 1. Business—Supervision and Regulation.”

Our businesses are subject to the risk of increased litigation, government investigations and regulatory enforcement.

Our businesses are subject to increased litigation, government investigations and other regulatory enforcement risks as a result of a number of factors and from various sources, including the highly regulated nature of the financial services industry, the focus of state and federal prosecutors on banks and the financial services industry and the structure of the credit card industry.

Given the inherent uncertainties involved in litigation, government investigations and regulatory enforcement decisions, and the very large or indeterminate damages sought in some matters asserted against us, there can be significant uncertainty as to the ultimate liability we may incur from these kinds of matters. The finding, or even the assertion, of substantial legal liability against us could have a material adverse effect on our business and financial condition and could cause significant reputational harm to us, which could seriously harm our business. The Cybersecurity Incident has resulted in litigation, government investigations and other regulatory enforcement inquiries.

In addition, financial institutions, such as ourselves, face significant regulatory scrutiny, which can lead to public enforcement actions or nonpublic supervisory actions. We and our subsidiaries are subject to comprehensive regulation and periodic examination by, among other regulatory bodies, the Federal Banking Agencies, SEC, CFTC and CFPB. We have been subject to enforcement actions by many of these and other regulators and may continue to be involved in such actions, including governmental inquiries, investigations and enforcement proceedings, including by the OCC, Department of Justice, Financial Crimes Enforcement Network (“FinCEN”) and state Attorneys General.

Over the last several years, federal and state regulators have focused on compliance with AML and sanctions laws, privacy, data protection and data security, use of service providers, fair lending and other consumer protection issues. In August 2020, we entered into consent orders with the Federal Reserve and the OCC resulting from regulatory reviews of the Cybersecurity Incident and relating to ongoing enhancements of our cybersecurity and operational risk management processes, and we paid a civil monetary penalty as part of the OCC agreement. In January 2021, we also paid a civil monetary penalty assessed by FinCEN against CONA in connection with our AML program. Regulatory scrutiny is expected to continue in these areas, including as a result of implementation of the AML Act of 2020.

We expect that regulators and governmental enforcement bodies will continue taking formal enforcement actions against financial institutions in addition to addressing supervisory concerns through nonpublic supervisory and enforcement actions or findings, which could involve restrictions on our activities, or our ability to make acquisitions or otherwise expand our business, among other limitations that could adversely affect our business. In addition, a violation of law or regulation by another financial institution is likely to give rise to an investigation by regulators and other governmental agencies of the same or similar practices by us. Furthermore, a single event may give rise to numerous and overlapping investigations and proceedings. These and other initiatives from governmental authorities and officials may subject us to further judgments, settlements, fines or penalties, or cause us to restructure our operations and activities or to cease offering certain products or services, all of which could harm our reputation or lead to higher operational costs. Litigation, government investigations and other regulatory actions could generally subject us to significant fines, increased expenses, restrictions on our activities and damage to our reputation and our brand, and could adversely affect our business, financial condition and results of operations. For additional information regarding legal and regulatory proceedings to which we are subject, see “Note 18—Commitments, Contingencies, Guarantees and Others.”

31 Capital One Financial Corporation (COF)

Table of Contents

Other Business Risks

We face intense competition in all of our markets.

We operate in a highly competitive environment across all of our lines of business, whether in making loans, attracting deposits or in the global payments industry, and we expect competitive conditions to continue to intensify with respect to most of our products particularly in our credit card and consumer banking business. We compete on the basis of the rates we pay on deposits and the rates and other terms we charge on the loans we originate or purchase, as well as the quality and range of our customer service, products, innovation and experience. This increasingly competitive environment is primarily a result of changes in technology, product delivery systems and regulation, as well as the emergence of new or significantly larger financial services providers, all of which may affect our customers’ expectations and demands. In addition to offering competitive products and services, we invest in and conduct marketing campaigns to attract and inform customers.

Some of our competitors, including new and emerging competitors in the digital and mobile payments space and other financial technology providers, are not subject to the same regulatory requirements or legislative scrutiny to which we are subject, which also could place us at a competitive disadvantage, in particular in the development of new technology platforms or the ability to rapidly innovate. We compete with many forms of payments offered by both bank and non-bank providers, including a variety of new and evolving alternative payment mechanisms, systems and products, such as aggregators and web-based and wireless payment platforms or technologies, digital or cryptocurrencies, prepaid systems and payment services targeting users of social networks, communications platforms and online gaming. If we are unable to continue to keep pace with innovation, do not effectively market our products and services or are prohibited from or unwilling to enter emerging areas of competition, our business and results of operations could be adversely affected.

Some of our competitors are substantially larger than we are, which may give those competitors advantages, including a more diversified product and customer base, the ability to reach more customers and potential customers, operational efficiencies, broad-based local distribution capabilities, lower-cost funding and larger existing branch networks. Many of our competitors are also focusing on cross-selling their products and developing new products or technologies, which could affect our ability to maintain or grow existing customer relationships or require us to offer lower interest rates or fees on our lending products or higher interest rates on deposits. Competition for loans could result in origination of fewer loans, earning less on our loans or an increase in loans that perform below expectations.

We operate as an online direct bank in the United States. While direct banking provides a significant opportunity to attract new customers that value greater and more flexible access to banking services at reduced costs, we face strong and increasing competition in the direct banking market. Aggressive pricing throughout the industry may adversely affect the retention of existing balances and the cost-efficient acquisition of new deposit funds and may affect our growth and profitability. Customers could also close their online accounts or reduce balances or deposits in favor of products and services offered by competitors for other reasons. These shifts, which could be rapid, could result from general dissatisfaction with our products or services, including concerns over pricing, online security or our reputation. The potential consequences of this competitive environment are exacerbated by the flexibility of direct banking and the financial and technological sophistication of our online customer base.

In our credit card business, competition for rewards customers may result in higher rewards expenses, or we may fail to attract new customers or retain existing rewards customers due to increasing competition for these consumers. As of December 31, 2021, we have a number of large partnerships in our credit card loan portfolio. The market for key business partners, especially in the credit card business, is very competitive, and we may not be able to grow or maintain these partner relationships. Additionally, partners themselves may face changes in their business, including market factors and ownership changes, that could impact the partnership. We face the risk that we could lose partner relationships, even after we have invested significant resources into acquiring and developing the relationships. The loss of any of our key business partners could have a negative impact on our results of operations, including lower returns, excess operating expense and excess funding capacity.

We depend on our partners to effectively promote our co-brand and private label products and integrate the use of our credit cards into their retail operations. The failure by our partners to effectively promote and support our products as well as changes they may make in their business models could adversely affect card usage and our ability to achieve the growth and profitability objectives of our partnerships. In addition, if our partners do not adhere to the terms of our program agreements and standards, or otherwise diminish the value of our brand, we may suffer reputational damage and customers may be less likely to use our products.

32 Capital One Financial Corporation (COF)

Table of Contents

Some of our competitors have developed, or may develop, substantially greater financial and other resources than we have, may offer richer value propositions or a wider range of programs and services than we offer, or may use more effective advertising, marketing or cross-selling strategies to acquire and retain more customers, capture a greater share of spending and borrowings, attain and develop more attractive co-brand card programs and maintain greater merchant acceptance than we have. We may not be able to compete effectively against these threats or respond or adapt to changes in consumer spending habits as effectively as our competitors.

In such a competitive environment, we may lose entire accounts or may lose account balances to competing firms, or we may find it more costly to maintain our existing customer base. Customer attrition from any or all of our lending products, together with any lowering of interest rates or fees that we might implement to retain customers, could reduce our revenues and therefore our earnings. Similarly, unexpected customer attrition from our deposit products, in addition to an increase in rates or services that we may offer to retain deposits, may increase our expenses and therefore reduce our earnings.

Our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit and debit card networks and by legislation and regulation impacting such fees.

Interchange fees are generally one of the largest components of the costs that merchants pay in connection with the acceptance of credit and debit cards and are a meaningful source of revenue for our credit and debit card businesses. Interchange fees are the subject of significant and intense global legal, legislative and regulatory focus, and the resulting decisions, legislation and regulation may have a material adverse impact on our overall business, financial condition and results of operations.

Legislative and regulatory bodies in a number of countries are seeking to reduce interchange fees through legislation, competition-related regulatory proceedings, voluntary agreements, central bank regulation and/or litigation. For credit transactions, interchange reimbursement rates in the United States are set by credit card networks such as MasterCard and Visa. For debit transactions, Federal Reserve rules place limits on the interchange fees we may charge. For more information on these rules, including the Federal Reserve’s proposed amendments, please see “Part I—Item 1. Business—Supervision and Regulation.” In some jurisdictions, such as Canada and certain countries in Europe, including the U.K., interchange fees and related practices are subject to regulatory activity, including in some cases, imposing caps on permissible interchange fees. Our international card businesses have been impacted by these restrictions. For example, in the U.K., interchange fees are capped for both credit and debit card transactions. In addition, in Canada, Visa and Mastercard payment networks have, since 2014, entered into voluntary agreements with the Department of Finance Canada to maintain an agreed upon average interchange rate. Lowering interchange fees remains an area of domestic and international governmental focus. Legislators and regulators around the world are aware of each other’s approaches to the regulation of the payments industry. Consequently, a development in one country, state or region may influence regulatory approaches in another, such as our primary market, the United States.

In addition to this regulatory activity, merchants are also seeking avenues to reduce interchange fees. During the past few years, merchants and their trade groups have filed numerous lawsuits against Visa, MasterCard, American Express and their card-issuing banks, claiming that their practices toward merchants, including interchange and similar fees, violate federal antitrust laws. In 2005, a number of entities filed antitrust lawsuits against MasterCard and Visa and several member banks, including our subsidiaries and us, alleging among other things, that the defendants conspired to fix the level of interchange fees. In December 2013, the U.S. District Court for the Eastern District of New York granted final approval of the proposed class settlement. The settlement provided, among other things, that merchants would be entitled to join together to negotiate lower interchange fees. The settlement was appealed to the Second Circuit Court of Appeals, which rejected the settlement in June 2016; a revised settlement was reached in the second half of 2018, and the trial court issued its final approval of the settlement in December 2019. See “Note 18—Commitments, Contingencies, Guarantees and Others” for further details.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2021-12-31, filed 2022-02-25 · accession 0000927628-22-000106

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 22 headings are on that chain and 16 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.