cof-20221231
UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
____________________________________
FORM 10-K
___________________________________
For the fiscal year ended December 31, 2022
OR
For the transition period from to
Commission File No. 001-13300
____________________________________
CAPITAL ONE FINANCIAL CORPORATION
(Exact name of registrant as specified in its charter)
____________________________________
1680 Capital One Drive,
(Address of principal executive offices) (Zip Code)
Registrant’s telephone number, including area code: (703) 720-1000
____________________________________
Securities registered pursuant to Section 12(b) of the Act:
Title of Each Class Trading Symbol(s) Name of Each Exchange on Which Registered
Common Stock (par value $.01 per share) COF New York Stock Exchange
0.800% Senior Notes Due 2024 COF24 New York Stock Exchange
1.650% Senior Notes Due 2029 COF29 New York Stock Exchange
Securities registered pursuant to section 12(g) of the Act: None
____________________________________
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
Large accelerated filer ☒ Accelerated filer ☐
Non-accelerated filer ☐ Smaller reporting company ☐
Emerging growth company ☐
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C.7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements.☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b).☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒
The aggregate market value of the voting and non-voting stock held by non-affiliates of the registrant as of the close of business on June 30, 2022 was approximately $39.6 billion. As of January 31, 2023, there were 381,079,743 shares of the registrant’s Common Stock outstanding.
DOCUMENTS INCORPORATED BY REFERENCE
1.Portions of the Proxy Statement for the annual meeting of stockholders to be held on May 4, 2023, are incorporated by reference into Part III.
TABLE OF CONTENTS
Page
PART I 4
Item 1. Business 4
Overview 4
Operations and Business Segments 6
Competition 7
Supervision and Regulation 7
Human Capital Resources 17
Technology and Intellectual Property 19
Forward-Looking Statements 20
Item 1A. Risk Factors 21
Item 1B. Unresolved Staff Comments 40
Item 2. Properties 40
Item 3. Legal Proceedings 40
Item 4. Mine Safety Disclosures 40
Item 6. [Reserved] 44
Selected Financial Data 45
Executive Summary 48
Consolidated Results of Operations 49
Consolidated Balance Sheets Analysis 54
Off-Balance Sheet Arrangements 56
Business Segment Financial Performance 56
Critical Accounting Policies and Estimates 65
Accounting Changes and Developments 69
Capital Management 70
Risk Management 75
Credit Risk Profile 81
Liquidity Risk Profile 92
Market Risk Profile 97
Supplemental Tables 102
Glossary and Acronyms 104
Item 7A. Quantitative and Qualitative Disclosures about Market Risk 111
Item 8. Financial Statements and Supplementary Data 112
Consolidated Statements of Income 117
Consolidated Statements of Comprehensive Income 118
Consolidated Balance Sheets 119
Consolidated Statements of Changes in Stockholders’ Equity 120
1 Capital One Financial Corporation (COF)
Consolidated Statements of Cash Flows 121
Notes to Consolidated Financial Statements 123
Note 1—Summary of Significant Accounting Policies 123
Note 2—Investment Securities 138
Note 5—Variable Interest Entities and Securitizations 154
Note 6—Goodwill and Other Intangible Assets 158
Note 7—Premises, Equipment and Leases 161
Note 8—Deposits and Borrowings 163
Note 9—Derivative Instruments and Hedging Activities 165
Note 10—Stockholders’ Equity 174
Note 11—Regulatory and Capital Adequacy 177
Note 12—Earnings Per Common Share 179
Note 13—Stock-Based Compensation Plans 180
Note 14—Employee Benefit Plans 182
Note 16—Fair Value Measurement 188
Note 17—Business Segments and Revenue from Contracts with Customers 197
Note 18—Commitments, Contingencies, Guarantees and Others 201
Note 19—Capital One Financial Corporation (Parent Company Only) 204
Note 20—Related Party Transactions 206
Item 9A. Controls and Procedures 207
Item 9B. Other Information 207
Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 207
Item 10. Directors, Executive Officers and Corporate Governance 208
Item 11. Executive Compensation 208
Item 14. Principal Accountant Fees and Services 208
Item 15. Exhibits and Financial Statement Schedules 209
EXHIBIT INDEX 210
2 Capital One Financial Corporation (COF)
INDEX OF MD&A AND SUPPLEMENTAL TABLES
MD&A Tables: Page
1 Average Balances, Net Interest Income and Net Interest Margin 50
2 Rate/Volume Analysis of Net Interest Income 51
3 Non-Interest Income 52
4 Non-Interest Expense 53
5 Loans Held for Investment 54
6 Funding Sources Composition 54
7 Business Segment Results 57
8 Credit Card Business Results 57
8.1 Domestic Card Business Results 59
9 Consumer Banking Business Results 60
10 Commercial Banking Business Results 62
11 Other Category Results 64
12 Capital Ratios Under Basel III 72
13 Regulatory Risk-Based Capital Components and Regulatory Capital Metrics 73
14 Preferred Stock Dividends Paid Per Share 74
15 Portfolio Composition of Loans Held for Investment 82
16 Loan Maturity Schedule 82
17 Credit Card Portfolio by Geographic Region 83
18 Consumer Banking Portfolio by Geographic Region 83
19 Commercial Real Estate Portfolio by Region 84
20 Commercial Loans by Industry 85
21 Credit Score Distribution 85
23 Aging and Geography of 30+ Day Delinquent Loans 87
24 90+ Day Delinquent Loans Accruing Interest 87
25 Nonperforming Loans and Other Nonperforming Assets 88
26 Net Charge-Offs (Recoveries) 89
27 Troubled Debt Restructurings 89
29 Allowance Coverage Ratios for Specified Loan Category 92
30 Liquidity Reserves 92
31 Deposits Composition and Average Deposits Interest Rates 94
32 Amount of Time Deposits in Excess of $250,000 by Contractual Maturity 95
33 Long-Term Debt Funding Activities 95
34 Senior Unsecured Long-Term Debt Credit Ratings 96
35 Interest Rate Sensitivity Analysis 98
36 LIBOR Exposures on Derivatives and Commercial Loans 99
Supplemental Tables:
A Net Charge-Offs 102
B Reconciliation of Non-GAAP Measures 102
3 Capital One Financial Corporation (COF)
Table of Contents
PART I
Item 1. Business
OVERVIEW
General
Capital One Financial Corporation, a Delaware corporation established in 1994 and headquartered in McLean, Virginia, is a diversified financial services holding company with banking and non-banking subsidiaries. Capital One Financial Corporation and its subsidiaries (the “Company” or “Capital One”) offer a broad array of financial products and services to consumers, small businesses and commercial clients through digital channels, branch locations, cafés and other distribution channels.
As of December 31, 2022, Capital One Financial Corporation’s principal operating subsidiary was Capital One, National Association (“CONA”). On October 1, 2022, the Company completed the merger of Capital One Bank (USA), National Association (“COBNA”), with and into CONA, with CONA as the surviving entity (the “Bank Merger”). The Company is hereafter collectively referred to as “we,” “us” or “our.” References to the “Bank” shall mean and refer to (i) CONA from and after the Bank Merger and (ii) CONA and COBNA collectively prior to the Bank Merger.
References to “this Report” or our “2022 Form 10-K” or “2022 Annual Report” are to our Annual Report on Form 10-K for the fiscal year ended December 31, 2022. All references to 2022, 2021 and 2020, refer to our fiscal years ended, or the dates, as the context requires, December 31, 2022, December 31, 2021 and December 31, 2020, respectively. Certain business terms used in this document are defined in the “MD&A—Glossary and Acronyms” and should be read in conjunction with the Consolidated Financial Statements included in this Report.
We were the third largest issuer of Visa® (“Visa”) and MasterCard® (“MasterCard”) credit cards in the U.S. based on the outstanding balance of credit card loans as of December 31, 2022. In addition to credit cards, we also offer debit cards, bank lending, treasury management and depository services, auto loans and other consumer lending products in markets across the U.S. As one of the nation’s largest banks based on deposits as of December 31, 2022, we service banking customer accounts through digital channels and our network of branch locations, cafés, call centers and automated teller machines (“ATMs”).
We also offer products and services outside of the U.S. principally through Capital One (Europe) plc (“COEP”), an indirect subsidiary of CONA organized and located in the United Kingdom (“U.K.”), and through a branch of CONA in Canada. Both COEP and our Canadian branch of CONA have the authority to provide credit card loans.
Business Developments
We regularly explore and evaluate opportunities to acquire financial products and services as well as financial assets, including credit card and other loan portfolios, and enter into strategic partnerships as part of our growth strategy. We also explore opportunities to acquire technology companies and related assets to improve our information technology infrastructure and to deliver on our digital strategy. We may issue equity or debt to fund our acquisitions. In addition, we regularly consider the potential disposition of certain of our assets, branches, partnership agreements or lines of business.
4 Capital One Financial Corporation (COF)
Table of Contents
Additional Information
Our common stock trades on the New York Stock Exchange (“NYSE”) under the symbol “COF” and is included in the Standard & Poor’s (“S&P”) 100 Index. We maintain a website at www.capitalone.com. Documents available under “Governance & Leadership” in the Investor Relations section of our website include:
•our Certificate of Incorporation, Bylaws, Corporate Governance Guidelines, and Code of Conduct; and
•charters for the Audit, Compensation, Governance and Nominating, and Risk Committees of the Board of Directors.
These documents also are available in print to any stockholder who requests a copy. We intend to disclose any future amendments to, or waivers from, our Code of Conduct on the website following the date of any such amendment or waiver.
In addition, we make available free of charge through our website all of our U.S. Securities and Exchange Commission (“SEC”) filings, including our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to those reports, as soon as reasonably practicable after electronically filing or furnishing such material to the SEC at www.sec.gov.
5 Capital One Financial Corporation (COF)
Table of Contents
OPERATIONS AND BUSINESS SEGMENTS
Our consolidated total net revenues are derived primarily from lending to consumer and commercial customers net of funding costs associated with our deposits, long-term debt and other borrowings. We also earn non-interest income which primarily consists of interchange income, net of reward expenses, service charges and other customer-related fees. Our expenses primarily consist of the provision for credit losses, operating expenses, marketing expenses and income taxes.
Our principal operations are organized for management reporting purposes into three major business segments, which are defined primarily based on the products and services provided or the types of customers served: Credit Card, Consumer Banking and Commercial Banking. The operations of acquired businesses have been integrated into or managed as a part of our existing business segments. Certain activities that are not part of a segment, such as management of our corporate investment portfolio and asset/liability management by our centralized Corporate Treasury group, are included in the Other category. The Other category also includes unallocated corporate expenses that do not directly support the operations of the business segments or for which the business segments are not considered financially accountable in evaluating their performance, such as certain restructuring charges, as well as residual tax expense or benefit to arrive at the consolidated effective tax rate that is not assessed to our primary business segments.
•Credit Card: Consists of our domestic consumer and small business card lending, and international card businesses in the United Kingdom and Canada.
•Consumer Banking: Consists of our deposit gathering and lending activities for consumers and small businesses, and national auto lending.
•Commercial Banking: Consists of our lending, deposit gathering, capital markets and treasury management services to commercial real estate and commercial and industrial customers. Our customers typically include companies with annual revenues between $20 million and $2 billion.
Customer usage and payment patterns, estimates of future expected credit losses, levels of marketing expense and operating efficiency all affect our profitability. In our Credit Card business, we generally experience fluctuations in purchase volume and the level of outstanding loan receivables from seasonal variances in consumer spending and payment patterns which, for example, have historically been the highest around the winter holiday season. Net charge-off rates for our credit card loan portfolio also have historically exhibited seasonal patterns as well and generally tend to be the highest in the first quarter of the year.
For additional information on our business segments, including the financial performance of each business, see “Part II—Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”)—Executive Summary,” “Part II—Item 7. MD&A—Business Segment Financial Performance” and “Part II—Item 8. Financial Statements and Supplementary Data—Note 17—Business Segments and Revenue from Contracts with Customers” of this Report.
6 Capital One Financial Corporation (COF)
Table of Contents
COMPETITION
Each of our business segments operates in a highly competitive environment, and we face competition in all aspects of our business from numerous bank and non-bank providers of financial services.
Our Credit Card business competes with international, national, regional and local issuers of Visa and MasterCard credit cards, as well as with American Express®, Discover Card®, private-label card brands, and, to a certain extent, issuers of debit cards. In general, customers are attracted to credit card issuers largely on the basis of price, credit limit, reward programs, customer experience and other product features.
Our Consumer Banking and Commercial Banking businesses compete with national, state and direct banks for deposits, commercial and auto loans, as well as with savings and loan associations and credit unions for loans and deposits. Our competitors also include automotive finance companies, commercial mortgage banking companies and other financial services providers that provide loans, deposits, and other similar services and products. In addition, we compete against non-depository institutions that are able to offer these products and services.
We also consider new and emerging companies in digital and mobile payments and other financial technology providers among our competitors. We compete with many forms of payment mechanisms, systems and products, offered by both bank and non-bank providers.
Our businesses generally compete on the basis of the quality and range of their products and services, transaction execution, innovation and price. Competition varies based on the types of clients, customers, industries and geographies served. Our ability to compete depends, in part, on our ability to attract and retain our associates and on our reputation as well as our ability to keep pace with innovation, in particular in the development of new technology platforms. There can be no assurance, however, that our ability to market products and services successfully or to obtain adequate returns on our products and services will not be impacted by the nature of the competition that now exists or may later develop, or by the broader economic environment. For a discussion of the risks related to our competitive environment, see “Part I—Item 1A. Risk Factors.”
SUPERVISION AND REGULATION
General
The regulatory framework applicable to banking organizations is intended primarily for the protection of depositors and the stability of the U.S. financial system, rather than for the protection of stockholders and creditors.
As a banking organization, we are subject to extensive regulation and supervision. In addition to banking laws and regulations, we are subject to various other laws and regulations, all of which directly or indirectly affect our operations, management and ability to make distributions to stockholders. We and our subsidiaries are also subject to supervision and examination by multiple regulators. In addition to laws and regulations, state and federal bank regulatory agencies may issue policy statements, interpretive letters and similar written guidance applicable to us and our subsidiaries. Any change in the statutes, regulations or regulatory policies applicable to us, including changes in their interpretation or implementation, could have a material effect on our business or organization.
Both the scope of the laws and regulations and the intensity of the supervision to which we are subject have increased, initially in response to the 2007-2008 financial crisis, and more recently in light of other factors such as technological, political and market changes. Regulatory enforcement and fines have also increased across the banking and financial services sector.
The descriptions below summarize certain significant federal and state laws, as well as international laws, to which we are subject. The descriptions are qualified in their entirety by reference to the particular statutory or regulatory provisions summarized. They do not summarize all possible or proposed changes in current laws or regulations and are not intended to be a substitute for the related statutes or regulatory provisions.
Banking Regulation
Capital One Financial Corporation is a bank holding company (“BHC”) and a financial holding company (“FHC”) under the Bank Holding Company Act of 1956, as amended (“BHC Act”), and is subject to the requirements of the BHC Act, including approval requirements for investments in or acquisitions of banking organizations, capital adequacy standards and limitations
7 Capital One Financial Corporation (COF)
Table of Contents
on non-banking activities. As a BHC and FHC, we are subject to supervision, examination and regulation by the Board of Governors of the Federal Reserve System (“Federal Reserve”). Permissible activities for a BHC include those activities that are so closely related to banking as to be a proper incident thereto. In addition, an FHC is permitted to engage in activities considered to be financial in nature (including, for example, securities underwriting and dealing and merchant banking activities), incidental to financial activities or, if the Federal Reserve determines that they pose no risk to the safety or soundness of depository institutions or the financial system in general, activities complementary to financial activities.
To become and remain eligible for FHC status, a BHC and its subsidiary depository institutions must meet certain criteria, including capital, management and Community Reinvestment Act (“CRA”) requirements. Failure to meet such criteria could result, depending on which requirements were not met, in restrictions on new financial activities or acquisitions or being required to discontinue existing activities that are not generally permissible for BHCs.
The Bank is a national association chartered under the National Bank Act, the deposits of which are insured by the Federal Deposit Insurance Corporation (“FDIC”) up to applicable limits. The Bank is subject to comprehensive regulation and periodic examination by the Office of the Comptroller of the Currency (“OCC”), the FDIC and the Consumer Financial Protection Bureau (“CFPB”).
We also are registered as a financial institution holding company under the laws of the Commonwealth of Virginia and, as such, we are subject to periodic examination by the Virginia Bureau of Financial Institutions. We also face regulation in the international jurisdictions in which we conduct business. See “Regulation of Businesses by Authorities Outside the United States” below for additional details.
Regulation of Business Activities
The business activities of the Company and the Bank are also subject to regulation and supervision under various laws and regulations.
Regulations of Consumer Lending Activities
The activities of the Bank as a consumer lender are subject to regulation under various federal laws, including, for example, the Truth in Lending Act (“TILA”), the Equal Credit Opportunity Act, the Fair Credit Reporting Act, the CRA, the Servicemembers Civil Relief Act and the Military Lending Act, as well as under various state laws. TILA, as amended, and together with its implementing rule, Regulation Z, imposes a number of restrictions on credit card practices impacting rates and fees, requires that a consumer’s ability to pay be taken into account before issuing credit or increasing credit limits, and imposes revised disclosures required for open-end credit.
The CFPB recently proposed a rule to amend Regulation Z (the “Proposed CFPB Rule”) to lower the safe harbor amount for past due fees that a credit card issuer can charge on consumer credit card accounts below the amounts that are currently permitted, among other changes that could impact the amount of a past due fee that can be charged.
Depending on the underlying issue and applicable law, regulators may be authorized to impose penalties for violations of these statutes and, in certain cases, to order banks to compensate customers. Borrowers may also have a private right of action for certain violations. Federal bankruptcy and state debtor relief and collection laws may also affect the ability of a bank, including the Bank, to collect outstanding balances owed by borrowers.
Debit Card Interchange Fees and Transaction Processing
The Bank is subject to the Federal Reserve’s Regulation II, which limits the amount of interchange fees that can be charged per debit card transaction for debit card issuers with over $10 billion in assets and places certain prohibitions on payment routing restrictions and network exclusivity.
Privacy, Data Protection and Data Security
We are subject to a variety of continuously evolving and developing laws and regulations regarding privacy, data protection and data security, including those related to the collection, storage, handling, use, disclosure, transfer, security and other processing of personal information. These areas have seen a considerable increase in legislative and regulatory activity over the past several years. At the federal level, we are subject to the Gramm-Leach-Bliley Act (“GLBA”), among other laws and regulations. Moreover, the U.S. Congress is currently considering various proposals for more comprehensive privacy, data
8 Capital One Financial Corporation (COF)
Table of Contents
protection and data security legislation, to which we may be subject if passed. For example, in 2022, Congress and the federal agencies sought to institute mandatory reporting of cyber incidents that materially disrupt or degrade operations and systems or might otherwise impact U.S. critical infrastructure or national security. This resulted in enactment of the Cyber Incident Reporting for Critical Infrastructure Act (“CIRCIA”), which, once rulemaking is complete, will require, among other things, certain companies, including Capital One, to report significant cyber incidents to the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (“CISA”) within 72 hours from the time the company reasonably believes the incident occurred, and a proposed rule by the SEC, which would mandate public disclosure of material cybersecurity incidents within four business days of determining that such an incident has occurred.
At the state level, we are subject to a number of laws and regulations, such as the California Consumer Privacy Act and its implementing regulations (as amended by the California Privacy Rights Act, the “CPRA”), which creates obligations on covered companies to, among other things, share certain information they have collected about California residents with those individuals, subject to certain exceptions. Many other states also have enacted or are in the process of enacting state-level privacy, data protection and/or data security laws and regulations, with which we may be required to comply. Significant uncertainty exists as federal and state privacy, data protection and data security laws may be interpreted and applied differently and may create inconsistent or conflicting requirements. For further discussion of privacy, data protection and cybersecurity, and related risks for our business, see “Part I—Item 1A. Risk Factors” under the headings “We face risks related to our operational, technological and organizational infrastructure,” “A cyber-attack or other security incident, including one that results in the theft, loss, manipulation or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions.” and “Our required compliance with applicable laws and regulations related to privacy, data protection and data security may increase our costs, reduce our revenue, increase our legal exposure and limit our ability to pursue business opportunities.”
Anti-Money Laundering and Anti-Terrorism
The Bank Secrecy Act and the USA PATRIOT Act of 2001 (“Patriot Act”) require financial institutions, among other things, to implement a risk-based program reasonably designed to prevent money laundering and to combat the financing of terrorism, including through suspicious activity and currency transaction reporting, compliance, record-keeping and customer due diligence.
The Patriot Act also contains financial transparency laws and provides enhanced information collection tools and enforcement mechanisms to the U.S. government, including due diligence and record-keeping requirements for private banking and correspondent accounts; standards for verifying customer identification at account opening; rules to produce certain records upon request of a regulator or law enforcement agency; and rules to promote cooperation among financial institutions, regulators and law enforcement agencies in identifying parties that may be involved in terrorism, money laundering and other crimes.
The Anti-Money Laundering Act of 2020 (“AML Act”), enacted as part of the National Defense Authorization Act, requires the U.S. Treasury Department to issue National Anti-Money Laundering and Countering the Financing of Terrorism Priorities, which it did in June 2021, and to conduct studies and issue regulations that may alter some of the due diligence, recordkeeping and reporting requirements that the Bank Secrecy Act and Patriot Act impose on banks. The AML Act also promotes increased information-sharing and use of technology, and increases penalties for violations of the Bank Secrecy Act and includes whistleblower incentives, both of which could increase the prospect of regulatory enforcement.
Deposit Funding
Under the Federal Deposit Insurance Corporation Improvement Act of 1991 (“FDICIA”), only well capitalized and adequately capitalized institutions may accept “brokered deposits,” as defined by FDIC regulations. Adequately capitalized institutions, however, must obtain a waiver from the FDIC before accepting brokered deposits, and such institutions may not pay rates that significantly exceed the rates paid on deposits of similar maturity obtained from the institution’s normal market area or, for deposits obtained from outside the institution’s normal market area, the national rate on deposits of comparable maturity. See “Part II一Item 7. MD&A一Liquidity Risk Profile” for additional information.
The FDIC is authorized to terminate a bank’s deposit insurance upon a finding by the FDIC that the bank’s financial condition is unsafe or unsound or that the institution has engaged in unsafe or unsound practices or has violated any applicable rule, regulation, order or condition enacted or imposed by the bank’s regulatory agency.
9 Capital One Financial Corporation (COF)
Table of Contents
Broker-Dealer Activities
Certain of our non-bank subsidiaries are subject to regulation and supervision by various federal and state authorities. Capital One Securities, Inc., KippsDeSanto & Company and TripleTree, LLC are registered broker-dealers regulated by the SEC and the Financial Industry Regulatory Authority (“FINRA”). These broker-dealer subsidiaries are subject to, among other things, net capital rules designed to measure the general financial condition and liquidity of a broker-dealer. Under these rules, broker-dealers are required to maintain the minimum net capital deemed necessary to meet their continuing commitments to customers and others, and to keep a substantial portion of their assets in relatively liquid form. These rules also limit the ability of a broker-dealer to transfer capital to its parent companies and other affiliates. Broker-dealers are also subject to regulations covering their business operations, including sales and trading practices, public offerings, publication of research reports, use and safekeeping of client funds and securities, capital structure, record-keeping and the conduct of directors, officers and employees.
Derivatives Activities
Title VII of the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 (“Dodd-Frank Act”) establishes a regulatory framework for the governance of the over-the-counter (“OTC”) derivatives market, including swaps and security-based swaps and the registration of certain market participants as a swap dealer. CONA provisionally registered with the Commodity Futures Trading Commission (“CFTC”) as a swap dealer in 2020. Registration as a swap dealer subjects CONA to additional regulatory requirements with respect to its swaps and other derivatives activities. As a result of CONA’s swap dealer registration, it is subject to the rules of the OCC concerning capital and margin requirements for swap dealers, including the mandatory exchange of variation margin and initial margin with certain counterparties. Additionally, as a provisionally registered swap dealer, CONA is subject to requirements under the CFTC’s regulatory regime, including rules regarding business conduct standards, recordkeeping obligations, regulatory reporting and procedures relating to swaps trading. CONA’s swaps and other derivatives activities do not require it to register with the SEC as a security-based swap dealer.
Transactions with Affiliates
There are various legal restrictions on the extent to which we and our non-bank subsidiaries may borrow or otherwise engage in certain types of transactions with the Bank. Under the Federal Reserve Act and Federal Reserve regulations, the Bank and its subsidiaries are subject to quantitative and qualitative limits on extensions of credit, purchases of assets, and certain other transactions involving non-bank affiliates. In addition, transactions between the Bank and its non-bank affiliates are required to be on arm’s length terms and must be consistent with standards of safety and soundness.
Volcker Rule
We and each of our subsidiaries, including the Bank, are subject to the “Volcker Rule,” a provision of the Dodd-Frank Act that contains prohibitions on proprietary trading and certain investments in, and relationships with, covered funds (hedge funds, private equity funds and similar funds), subject to certain exemptions, in each case as the applicable terms are defined in the Volcker Rule and the implementing regulations. The implementing regulations also require that we establish and maintain a compliance program designed to ensure adherence with the requirements of the regulations.
Capital and Liquidity Regulation
The Company and the Bank are subject to capital adequacy guidelines adopted by the Federal Reserve and OCC respectively. For a further discussion of the capital adequacy guidelines, see “Part II—Item 7. MD&A—Capital Management,” “Part II—Item 7. MD&A—Liquidity Risk Profile” and “Part II—Item 8. Financial Statements and Supplementary Data—Note 11—Regulatory and Capital Adequacy.”
Basel III and U.S. Capital Rules
The Company and the Bank are subject to regulatory capital requirements established by the Federal Reserve and the OCC, respectively (“Basel III Capital Rules”). The Basel III Capital Rules implement certain capital requirements published by the Basel Committee on Banking Supervision (“Basel Committee”), along with certain provisions of the Dodd-Frank Act and other capital provisions.
As a BHC with total consolidated assets of at least $250 billion but less than $700 billion and not exceeding any of the applicable risk-based thresholds, the Company is a Category III institution under the Basel III Capital Rules.
10 Capital One Financial Corporation (COF)
Table of Contents
The Bank, as a subsidiary of a Category III institution, is a Category III bank. Moreover, the Bank, as an insured depository institution, is subject to prompt corrective action (“PCA”) capital regulations, as further described below.
Under the Basel III Capital Rules, we must maintain a minimum common equity Tier 1 (“CET1”) capital ratio of 4.5%, a Tier 1 capital ratio of 6.0%, and a total capital ratio of 8.0%, in each case in relation to risk-weighted assets. In addition, we must maintain a minimum leverage ratio of 4.0% and a minimum supplementary leverage ratio of 3.0%. We are also subject to the capital conservation buffer requirement and countercyclical capital buffer requirement (which is currently set at 0%), as described below. Our capital and leverage ratios are calculated based on the Basel III standardized approach framework.
We have elected to exclude certain elements of accumulated other comprehensive income (“AOCI”) from our regulatory capital as permitted for a Category III institution.
Global systemically important banks (“G-SIBs”) that are based in the U.S. are subject to an additional CET1 capital requirement known as the “G-SIB Surcharge.” We are not a G-SIB based on the most recent available data and thus we are not subject to a G-SIB Surcharge.
Stress Capital Buffer Rule
The Basel III Capital Rules require banking institutions to maintain a capital conservation buffer, composed of CET1 capital, above the regulatory minimum ratios. Under the Federal Reserve’s final rule to implement the stress capital buffer requirement, (the “Stress Capital Buffer Rule”), the Company’s “standardized approach capital conservation buffer” includes its stress capital buffer requirement (as described below), any G-SIB Surcharge (which is not applicable to us) and the countercyclical capital buffer requirement (which is currently set at 0%). Any determination to increase the countercyclical capital buffer generally would be effective twelve months after the announcement of such an increase, unless the Federal Reserve, OCC and the FDIC (collectively, “Federal Banking Agencies”) set an earlier effective date.
The Company’s stress capital buffer requirement is recalibrated every year based on the Company’s supervisory stress test results. In particular, the Company’s stress capital buffer requirement equals, subject to a floor of 2.5%, the sum of (i) the difference between the Company’s starting CET1 capital ratio and its lowest projected CET1 capital ratio under the severely adverse scenario of the Federal Reserve’s supervisory stress test plus (ii) the ratio of the Company’s projected four quarters of common stock dividends (for the fourth to seventh quarters of the planning horizon) to the projected risk-weighted assets for the quarter in which the Company’s projected CET1 capital ratio reaches its minimum under the supervisory stress test.
Based on the Company’s 2022 supervisory stress test results, the Company’s stress capital buffer requirement for the period beginning on October 1, 2022 through September 30, 2023 is 3.1%. Therefore, the Company’s minimum capital requirements plus the standardized approach capital conservation buffer for CET1 capital, Tier 1 capital and total capital ratios under the stress capital buffer framework are 7.6%, 9.1% and 11.1%, respectively, for the period from October 1, 2022 through September 30, 2023.
The Stress Capital Buffer Rule does not apply to the Bank. The capital conservation buffer for the Bank continues to be fixed at 2.5%. Accordingly, the Bank’s minimum capital requirements plus its capital conservation buffer for CET1 capital, Tier 1 capital and total capital ratios are 7.0%, 8.5% and 10.5% respectively.
If the Company or the Bank fails to maintain its capital ratios above the minimum capital requirements plus the applicable capital conservation buffer requirements, it will face increasingly strict automatic limitations on capital distributions and discretionary bonus payments to certain executive officers.
See also “Dividends, Stock Repurchases and Transfers of Funds” below for more information about the stress capital buffer determination timeline and process.
CECL Transition Rule
The Federal Banking Agencies adopted a final rule (“CECL Transition Rule”) that provides banking institutions an optional five-year transition period to phase in the impact of the current expected credit losses (“CECL”) standard on their regulatory capital (“CECL Transition Election”). We adopted the CECL standard (for accounting purposes) as of January 1, 2020, and made the CECL Transition Election (for regulatory capital purposes) in the first quarter of 2020.
11 Capital One Financial Corporation (COF)
Table of Contents
Pursuant to the CECL Transition Rule, a banking institution could elect to delay the estimated impact of adopting CECL on its regulatory capital through December 31, 2021 and then phase in the estimated cumulative impact from January 1, 2022 through December 31, 2024. For the “day 2” ongoing impact of CECL during the initial two years, the Federal Banking Agencies used a uniform “scaling factor” of 25% as an approximation of the increase in the allowance under the CECL standard compared to the prior incurred loss methodology. Accordingly, from January 1, 2020 through December 31, 2021, electing banking institutions were permitted to add back to their regulatory capital an amount equal to the sum of the after-tax “day 1” CECL adoption impact and 25% of the increase in the allowance since the adoption of the CECL standard. From January 1, 2022 through December 31, 2024, the after-tax “day 1” CECL adoption impact and the cumulative “day 2” ongoing impact are being phased in to regulatory capital at 25% per year. The following table summarizes the capital impact delay and phase in period on our regulatory capital from years 2020 to 2025.
Capital Impact Delayed Phase In Period
Market Risk Rule
The “Market Risk Rule” supplements the Basel III Capital Rules by requiring institutions subject to the rule to adjust their risk-based capital ratios to reflect the market risk in their trading book. The Market Risk Rule generally applies to institutions with aggregate trading assets and liabilities equal to 10% or more of total assets or $1 billion or more. As of December 31, 2022, the Company and CONA are subject to the Market Risk Rule. See “Part II一Item 7. MD&A一Market Risk Profile” for additional information.
FDICIA and Prompt Corrective Action
FDICIA requires the Federal Banking Agencies to take PCA for banks that do not meet minimum capital requirements. FDICIA establishes five capital ratio levels: well capitalized; adequately capitalized; undercapitalized; significantly undercapitalized; and critically undercapitalized. The three undercapitalized categories are based upon the amount by which a bank falls below the ratios applicable to an adequately capitalized institution. The capital categories relate to FDICIA’s PCA provisions, and such capital categories may not constitute an accurate representation of the Bank’s overall financial condition or prospects.
The Basel III Capital Rules updated the PCA framework to reflect new, higher regulatory capital minimums. For an insured depository institution to be well capitalized, it must maintain a total risk-based capital ratio of 10% or more; a Tier 1 capital ratio of 8% or more; a CET1 capital ratio of 6.5% or more; and a leverage ratio of 5% or more. An adequately capitalized depository institution must maintain a total risk-based capital ratio of 8% or more; a Tier 1 capital ratio of 6% or more; a CET1 capital ratio of 4.5% or more; a leverage ratio of 4% or more; and, for Category III and certain other institutions, a supplementary leverage ratio of 3% or more. The PCA provisions also authorize the Federal Banking Agencies to reclassify a bank’s capital category or take other action against banks that are determined to be in an unsafe or unsound condition or to have engaged in unsafe or unsound banking practices.
As an additional means to identify problems in the financial management of depository institutions, the Federal Banking Agencies established certain non-capital safety and soundness standards as required by FDICIA. The standards relate generally to operations and management, asset quality, interest rate exposure and executive compensation. The Federal Banking Agencies are authorized to take action against institutions that fail to meet such standards.
Basel III and United States Liquidity Rules
The Basel Committee has published a liquidity framework that includes two standards for liquidity risk supervision. One standard, the liquidity coverage ratio (“LCR”), seeks to promote short-term resilience by requiring organizations to hold sufficient high-quality liquid assets (“HQLAs”) to survive a stress scenario lasting for 30 days. The other standard, the net
12 Capital One Financial Corporation (COF)
Table of Contents
stable funding ratio (“NSFR”), seeks to promote longer-term resilience by requiring sufficient stable funding over a one-year period based on the liquidity characteristics of the organization’s assets and activities.
The Company and the Bank are subject to the LCR standard as implemented by the Federal Reserve and OCC (the “LCR Rule”). The LCR Rule requires each of the Company and the Bank to hold an amount of eligible HQLA that equals or exceeds 100% of its respective projected adjusted net cash outflows over a 30-day period, each as calculated in accordance with the LCR Rule. The LCR Rule requires each of the Company and the Bank to calculate its respective LCR daily. In addition, the Company is required to make quarterly public disclosures of its LCR and certain related quantitative liquidity metrics, along with a qualitative discussion of its LCR.
As a Category III institution with less than $75 billion in weighted average short-term wholesale funding, the Company’s and the Bank’s total net cash outflows are multiplied by an outflow adjustment percentage of 85%. Although the Bank may hold more HQLA than it needs to meet its LCR requirements, the LCR Rule restricts the amount of such excess HQLA held at the Bank (referred to as “Trapped Liquidity”) that can be included in the Company’s HQLA amount. Because we typically manage the Bank’s LCR to levels well above 100%, the result is additional Trapped Liquidity as the Bank’s net cash outflows are reduced by the outflow adjustment percentage of 85%.
The NSFR rule requires the Company and the Bank to maintain an amount of available stable funding, which is a weighted measure of a company’s funding sources over a one-year time horizon, calculated by applying standardized weightings to equity and liabilities based on their expected stability, that is no less than a specified percentage of its required stable funding, which is calculated by applying standardized weightings to assets, derivatives exposures and certain other items based on their liquidity characteristics. As a Category III institution, the Company and the Bank are each required to maintain available stable funding in an amount at least equal to 85% of its required stable funding. The NSFR rule includes a semi-annual public disclosure requirement, with the first disclosure due 45 days after the end of the second quarter of 2023.
Enhanced Prudential Standards and Other Related Requirements
We are subject to certain enhanced prudential standards under the Dodd-Frank Act, as amended by the Economic Growth, Regulatory Relief, and Consumer Protection Act (“EGRRCPA”) and implemented by various regulations issued by the Federal Banking Agencies. The Financial Stability Oversight Council (“FSOC”) may also issue recommendations to the Federal Reserve or other primary financial regulatory agencies to apply new or enhanced standards to certain financial activities or practices.
As part of the enhanced prudential standards, the Company is required to implement resolution planning for orderly resolution in the event it faces material financial distress or failure. The FDIC issued similar rules regarding resolution planning applicable to the Bank. In addition, the OCC has issued rules requiring banks with assets of $250 billion or more to develop recovery plans detailing the actions they would take to remain a going concern when they experience considerable financial or operational stress, but have not deteriorated to the point that resolution is imminent.
The enhanced prudential standards also include supervisory and company-run stress testing requirements (also known as the “DFAST stress testing requirements”). In particular, the Federal Reserve is required to conduct annual stress tests on certain covered companies, including us, to ensure that the covered companies have sufficient capital to absorb losses and continue operations during adverse economic conditions, as well as to determine the Company’s stress capital buffer requirement as described above. As a Category III institution, we are also required to conduct our own stress tests and publish the results of such tests on our website or other public forum. The Company must disclose the results of its company-run stress test on a biennial basis. The OCC has adopted a similar stress test rule requiring banks with at least $250 billion in assets, including the Bank, to conduct their own company-run stress tests. Under that OCC rule, the Bank must also disclose the results of its stress test on a biennial basis.
In addition, the Company is required to meet liquidity risk management standards, conduct internal liquidity stress tests, and maintain a 30-day buffer of highly liquid assets, in each case, consistent with the requirements of the enhanced prudential standards. These requirements are in addition to the LCR and NSFR rules, discussed above in “Basel III and United States Liquidity Rules.” The enhanced prudential standards also require that the Company comply with, and hold capital commensurate with, the requirements of, any regulations adopted by the Federal Reserve relating to capital planning and stress tests. Stress testing and capital planning regulations are discussed further below under “Dividends, Stock Repurchases and Transfers of Funds.” Finally, the Company is also required to establish and maintain an enterprise-wide Risk Management Framework (“Framework”) that includes a risk committee and a chief risk officer.
13 Capital One Financial Corporation (COF)
Table of Contents
Although not a requirement of the Dodd-Frank Act, the OCC established regulatory guidelines (“Heightened Standards Guidelines”) that apply heightened standards to the governance and risk management practices of large institutions subject to its supervision, including the Bank. The Heightened Standards Guidelines establish standards for the development and implementation by the Bank of a risk governance framework.
Dividends, Stock Repurchases and Transfers of Funds
Under the Federal Reserve’s capital planning rules and related supervisory process (commonly referred to as Comprehensive Capital Analysis and Review or “CCAR” requirements), a “covered BHC,” such as the Company, must submit a capital plan to the Federal Reserve on an annual basis that contains a description of all planned capital actions, including dividends or stock repurchases, over a nine-quarter planning horizon beginning with the first quarter of the calendar year the capital plan is submitted (“CCAR cycle”).
The DFAST stress testing requirements, described above in “Enhanced Prudential Standards and Other Related Requirements,” is a complementary exercise to CCAR. It is a forward-looking exercise conducted by the Federal Reserve and each covered company to help assess whether a company has sufficient capital to absorb losses and continue operations during adverse economic conditions.
Pursuant to the capital planning rules, the Company must file its capital plan with the Federal Reserve by April 5 of each year (unless the Federal Reserve designates a later date), using data as of the end of the prior calendar year. The Federal Reserve will release the results of the supervisory stress test and notify the Company of its stress capital buffer requirement by June 30 of that year. The Company will have two business days from receipt of its stress capital buffer requirement to make any necessary adjustments to its planned capital distributions. The Federal Reserve will then finalize the stress capital buffer requirement for the Company and confirm the Company’s planned capital distributions by August 31 of that year. The Company’s final stress capital buffer requirement will be effective from the fourth quarter of the year the capital plan is submitted through the third quarter of the following year. The Company may make the planned capital distributions confirmed by the Federal Reserve. In addition, under the Stress Capital Buffer Rule, the Company is no longer required to seek prior approval of the Federal Reserve to make capital distributions in excess of those included in its capital plan so long as the Company is otherwise in compliance with the capital rule’s automatic limitations on capital distributions.
The Federal Reserve has announced that it would maintain its pre-CECL framework for calculating allowances on loans in the supervisory stress test through the 2023 cycle until the impact of CECL is better known and understood.
Dividends from the Company’s direct and indirect subsidiaries represent a major source of the funds we use to pay dividends on our capital stock, make payments on our corporate debt securities and meet our other obligations. There are various federal law limitations on the extent to which the Bank can finance or otherwise supply funds to the Company through dividends and loans. These limitations include minimum regulatory capital requirements, federal banking law requirements concerning the payment of dividends out of net profits or surplus, provisions of Sections 23A and 23B of the Federal Reserve Act and Regulation W governing transactions between an insured depository institution and its affiliates, as well as general federal regulatory oversight to prevent unsafe or unsound practices. In general, federal and applicable state banking laws prohibit insured depository institutions, such as the Bank, from making dividend distributions without first obtaining regulatory approval if such distributions are not paid out of available earnings or would cause the institution to fail to meet applicable capital adequacy standards.
Investment in the Company and the Bank
Certain acquisitions of our capital stock may be subject to regulatory approval or notice under federal or state law. Investors are responsible for ensuring that they do not, directly or indirectly, acquire shares of our capital stock in excess of the amount that can be acquired without regulatory approval, including under the BHC Act and the Change in Bank Control Act (“CIBC Act”).
Federal law and regulations prohibit any person or company from acquiring control of the Company or the Bank without, in most cases, prior written approval of the Federal Reserve or the OCC, as applicable. Control under the BHC Act exists if, among other things, a person or company acquires more than 25% of any class of our voting stock or otherwise has a controlling influence over us. A rebuttable presumption of control arises under the CIBC Act for a publicly traded BHC such as ourselves if a person or company acquires more than 10% of any class of our voting stock.
Additionally, the Bank is a “bank” within the meaning of Chapter 7 of Title 6.2 of the Code of Virginia governing the acquisition of interests in Virginia financial institutions (“Virginia Financial Institution Holding Company Act”). The Virginia
14 Capital One Financial Corporation (COF)
Table of Contents
Financial Institution Holding Company Act prohibits any person or entity from acquiring, or making any public offer to acquire, control of a Virginia financial institution or its holding company without making application to, and receiving prior approval from, the Virginia Bureau of Financial Institutions.
Deposit Insurance Assessments
The Bank, as an insured depository institution, is a member of the Deposit Insurance Fund (“DIF”) maintained by the FDIC. Through the DIF, the FDIC insures the deposits of insured depository institutions up to prescribed limits for each depositor. The FDIC sets a Designated Reserve Ratio (“DRR”) for the DIF. To maintain the DIF, member institutions may be assessed an insurance premium, and the FDIC may take action to increase insurance premiums if the DRR falls below its required level.
As of June 30, 2020, the DIF reserve ratio fell to 1.30 percent. The FDIC, as required under the Federal Deposit Insurance Act, established a plan in September 2020, to restore the DIF reserve ratio to meet or exceed 1.35 percent within eight years. On October 18, 2022, the FDIC finalized a rule that increases the initial base deposit insurance assessment rate schedules by 2 basis points for all insured depository institutions to improve the likelihood that the DIF reserve ratio reaches 1.35 percent by the statutory deadline of September 30, 2028. The rule took effect on January 1, 2023 and this increase will be reflected in the Bank’s first quarterly assessment in 2023.
Source of Strength
Federal Reserve rules require a BHC to serve as a source of financial and managerial strength to its subsidiary banks (the so-called “source of strength doctrine”). In addition, the Dodd-Frank Act requires a BHC to serve as a source of financial strength to its subsidiary banks and requires the Federal Banking Agencies to jointly adopt new rules implementing this requirement. Such rules have not yet been proposed.
FDIC Orderly Liquidation Authority
The Dodd-Frank Act provides the FDIC with liquidation authority that may be used to liquidate non-bank financial companies and BHCs if the Treasury Secretary, in consultation with the President and based on the recommendation of the Federal Reserve and other appropriate Federal Banking Agencies, determines that doing so is necessary, among other criteria, to mitigate serious adverse effects on U.S. financial stability. Upon such a determination, the FDIC would be appointed receiver and must liquidate the company in a way that mitigates significant risks to financial stability and minimizes moral hazard. The costs of a liquidation of the company would be borne by shareholders and unsecured creditors and then, if necessary, by risk-based assessments on large financial companies. The FDIC has issued rules implementing certain provisions of its liquidation authority and may issue additional rules in the future.
Climate-related Developments
Climate change and the risks it may pose to financial institutions is an area of increased focus by the Federal Banking Agencies as well as federal and state legislative bodies. In the future, new regulations or guidance may be issued, or other regulatory or supervisory actions may be taken, in this area by the Federal Banking Agencies or other regulatory agencies, or new statutory requirements may be adopted. For example, each of the Federal Banking Agencies has requested feedback on its respective draft principles designed to support the identification and management of climate-related financial risks at regulated institutions with more than $100 billion in total consolidated assets. The Federal Banking Agencies plan to use this feedback to inform future guidance with respect to climate-related financial risk.
Regulation of Businesses by Authorities Outside the United States
The Bank is subject to laws and regulations in foreign jurisdictions where it operates, currently in the U.K. and Canada. In the U.K., the Bank operates through COEP, which was established in 1999 and is an authorized payment institution regulated by the Financial Conduct Authority (“FCA”). COEP’s parent, Capital One Global Corporation, is wholly owned by the Bank and is subject to regulation by the Federal Reserve as an “agreement corporation” under the Federal Reserve’s Regulation K. COEP does not take deposits. In Canada, the Bank operates as an authorized foreign bank and is permitted to conduct its credit card business in Canada through its Canadian branch, Capital One Bank (Canada Branch) (“Capital One Canada”). Capital One Canada does not take deposits. The primary regulator of Capital One Canada is the Office of the Superintendent of Financial Institutions.
15 Capital One Financial Corporation (COF)
Table of Contents
The foreign legal and regulatory requirements to which the Company’s non-U.S. operation are subject include, among others, those related to consumer protection, business practices, and data security and limits on interchange fees. For more information on foreign regulatory activity concerning interchange fees, please see “Part I一Item 1A.Risk Factors” under the heading “Our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit and debit card networks and by legislation and regulation impacting such fees.”
The Company also is subject to foreign legal and regulatory requirements regarding privacy, data protection and data security. For example, in Canada and the U.K,. we are subject to the Personal Information Protection and Electronic Documents Act and the U.K. General Data Protection Regulation, respectively. In addition, subject to certain limited exceptions, the European Union (“EU”) General Data Protection Regulation applies EU data protection laws to companies controlling or processing personal data of EU residents. These laws and regulations, and domestic laws and regulations that govern similar topics, may be interpreted and applied differently from country to country and may create inconsistent or conflicting requirements. For more information on privacy, data protection and data security requirements, please see “Privacy, Data Protection and Data Security.”
16 Capital One Financial Corporation (COF)
Table of Contents
HUMAN CAPITAL RESOURCES
Our culture is rooted in putting people first with a focus on building and maintaining a workforce which fosters an inclusive environment based on diversity of our people, ideas and the merit of our work. We prioritize the recruitment, development, recognition and retention of the 55,943 employees worldwide that we had as of December 31, 2022, whom we refer to as “associates.” The following disclosures provide information on our human capital resources, including certain human capital objectives and measures that we focus on in managing our business.
Governance of Human Capital
Our full Board of Directors oversees our human capital management, including strategies, policies and practices, and diversity, inclusion and belonging (“DIB”), and is assisted by our Board’s Compensation Committee and Governance and Nominating Committee. Our Executive Committee, a committee of senior management which includes our Chief Human Resources Officer, advises, assists and makes recommendations to our Chief Executive Officer and Board of Directors on human capital matters such as human resource practices and programs, including general employee benefits and compensation programs. Our Chief Diversity, Inclusion and Belonging Officer (“Chief DIB Officer”) provides an update, at least annually, on the progress, success and challenges on workforce representation, trends and programs to the Board of Directors and Executive Committee.
Hiring, Retention and Development
We employ a comprehensive people strategy that includes significant investments in recruiting, sourcing and associate development to attract and retain top talent from all backgrounds to help drive our business’ long-term success. We recruit through a variety of channels, including professional partnerships, job fairs, online platforms, on-campus recruiting, diversity-related recruiting events and initiatives, and internship and rotational programs, among others. We empower our associates to learn new skills, meet personalized development goals, and grow their careers. Investment in associate training and professional development is critical to maintaining our talent competitiveness. Our internal enterprise learning and development team blends multiple approaches to learning to support associate development across lines of business, levels, and roles, including online and live classroom training. In addition to formal programming provided by learning professionals, including regulatory compliance, role-specific topics and others, our peer-to-peer learning strategy empowers associates to be both learners and teachers, further enhancing a culture of learning. We also focus on cultivating talent with leadership development courses, cohort-based programs, network building and coaching.
On a quarterly basis, we review our ability to attract and retain talent needed to deliver on our strategic business objectives. Each line of business and staff group reviews hiring, tenure and attrition metrics as part of this assessment, and they implement mitigation plans when needed.
Diversity, Inclusion and Belonging
We continuously strive to empower our associates to do great work by creating an equitable and inclusive workplace with a culture of belonging that values diverse perspectives, fosters collaboration and encourages innovative ideas. We aim to create a place where associates of all backgrounds can thrive by bringing their best, most authentic selves to work. Our diversity and inclusion efforts are overseen by our Chief DIB Officer. This culture of belonging rests at the heart of our DIB efforts. Central to this effort are our business resource groups, associate-led organizations which deepen our understanding of different cultures, backgrounds and experiences, and enable associates to build connections, invest in their professional development, and support our commitment to attract, develop and retain a diverse workforce. In addition, our Chief Executive Officer and the Executive Committee engage with leaders of our business resource groups to identify opportunities to further our DIB agenda, enact positive change and build on existing initiatives designed to nurture our culture and workplace environment.
Growing the diversity of our workforce at all levels, with an emphasis on leader and executive roles, is an important component of our comprehensive DIB strategy. As of December 31, 2022, key measures of our workforce representation include:
•Of the 12 members of our Board of Directors, 3 are women and 3 are people of color;
•In the U.S., of the associates who are vice president level and above, approximately 33% are women and 28% are people of color;
•In the U.S., approximately 52% of associates are people of color; and
17 Capital One Financial Corporation (COF)
Table of Contents
•Worldwide, approximately 51% of associates are women and 49% of associates are men.
Our corporate website contains additional information regarding programs and other information integral to our philosophy of diversity, inclusion and belonging. We believe in the importance of transparency and will also provide on our website the Consolidated EEO-1 Report in addition to submitting to the U.S. Equal Employment Opportunity Commission.
Compensation and Wellness
We are committed to providing a competitive total compensation package that will attract, retain and motivate talent to help drive our business’ long-term success. Our benefits, including competitive parental leave, on-site health centers, flexible work solutions, company contributions to associates’ 401(k) plans, educational assistance and other health, wellness, and financial benefits, are all designed to help associates grow and develop inside and outside of the workplace. Furthermore, pay equity has long been a core tenet of our pay philosophy and is central to our values. We annually evaluate base pay and incentive pay for all of our associates globally. This review and evaluation may occur more frequently as deemed necessary and prudent. We review groups of associates in similar roles, adjusting for factors that appropriately explain differences in pay such as job location and experience. Based on our analysis, our aggregated adjusted pay gap results show that we pay women 100% of what men are paid, and we pay people of color in the U.S. 100% of what white associates are paid. We use statistical modeling to understand what drives pay gaps, instill new practices to eliminate pay gaps in the future, and if we find unexplained pay gaps, we close them.
Communication and Connection
We communicate with our associates regularly to understand their perspectives and to hear their voices. Our senior leaders and Chief Executive Officer also communicate directly on societal events impacting our associates. To assess and improve associate retention and engagement, the Company surveys associates on a periodic basis with the assistance of third-party consultants and takes actions to address areas of associate concern. We encourage full participation and use the results to effect change and promote transparency.
18 Capital One Financial Corporation (COF)
Table of Contents
TECHNOLOGY AND INTELLECTUAL PROPERTY
Technology/Systems
We leverage information and technology to achieve our business objectives and to develop and deliver products and services that satisfy our customers’ needs. A key part of our strategic focus is the development and use of efficient, flexible computer and operational systems, such as cloud technology, to support complex marketing and account management strategies, the servicing of our customers, and the development of new and diversified products. We believe that the continued development and integration of these systems is an important part of our efforts to reduce costs, improve quality and security and provide faster, more flexible technology services. Consequently, we frequently consider our capabilities and develop or acquire systems, processes and competencies to meet our unique business requirements.
As part of our frequent consideration of our technologies, we may either develop such capabilities internally or rely on third-party service providers who have the ability to deliver technology that is of higher quality, lower cost, or both. We continue to rely on third-party service providers to help us deliver systems and operational infrastructure. These relationships include (but are not limited to): Amazon Web Services, Inc. (“AWS”) for our cloud infrastructure, Total System Services LLC (“TSYS”) for consumer and commercial credit card processing services for our North American and U.K. portfolios and Fidelity Information Services (“FIS”) for certain of our banking systems.
We are committed to implementing safeguards designed to protect our customers’ information, as well as our own information and technology. We implement backup and recovery systems, and we generally require the same of our third-party service providers. We take measures designed to mitigate against known attacks and use internal and external resources to scan for vulnerabilities in platforms, systems, and applications necessary for delivering our products and services. For a discussion of the risks associated with our use of technology systems, see “Part I—Item 1A. Risk Factors” under the headings “We face risks related to our operational, technological and organizational infrastructure” and “A cyber-attack or other security incident, including one that results in the theft, loss, manipulation or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions.”
Intellectual Property and Other Proprietary Information
As part of our overall and ongoing strategy to protect and enhance our intellectual property, we rely on a variety of protections, including copyrights, trademarks, trade secrets, patents and certain restrictions on disclosure, solicitation and competition. We also undertake other measures to control access to, or distribution of, our other proprietary and confidential information. Any patents we may obtain may increase our competitive advantage, preserve our freedom to operate, and allow us to enter into licensing (e.g., cross-licenses) or other arrangements with third parties. For a discussion of risks associated with intellectual property, see “Part I—Item 1A. Risk Factors” under the heading “If we are not able to protect our intellectual property, our revenue and profitability could be negatively affected.”
19 Capital One Financial Corporation (COF)
Table of Contents
FORWARD-LOOKING STATEMENTS
From time to time, we have made and will make forward-looking statements, including those that discuss, among other things: strategies, goals, outlook or other non-historical matters; projections, revenues, income, returns, expenses, capital measures, capital allocation plans, accruals for claims in litigation and for other claims against us; earnings per share, efficiency ratio, operating efficiency ratio or other financial measures for us; future financial and operating results; our plans, objectives, expectations and intentions; and the assumptions that underlie these matters.
To the extent that any such information is forward-looking, it is intended to fit within the safe harbor for forward-looking information provided by the Private Securities Litigation Reform Act of 1995.
Forward-looking statements often use words such as “will,” “anticipate,” “target,” “expect,” “estimate,” “intend,” “plan,” “goal,” “believe,” “forecast,” “outlook” or other words of similar meaning. Any forward-looking statements made by us or on our behalf speak only as of the date they are made or as of the date indicated, and we do not undertake any obligation to update forward-looking statements as a result of new information, future events or otherwise. For additional information on factors that could materially influence forward-looking statements included in this Report, see the risk factors set forth under “Part I—Item 1A. Risk Factors.” You should carefully consider the factors discussed above, and in our Risk Factors or other disclosures, in evaluating these forward-looking statements.
Numerous factors could cause our actual results to differ materially from those described in such forward-looking statements, including, among other things:
•general economic and business conditions in our local markets, including conditions affecting employment levels, interest rates, collateral values, consumer income, creditworthiness and confidence, spending and savings that may affect consumer bankruptcies, defaults, charge-offs and deposit activity;
•increases or fluctuations in credit losses and delinquencies and the impact of inaccurate estimates or inadequate reserves;
•the impact of the COVID-19 pandemic on our business, financial condition and results of operations may persist for an extended period or worsen, including labor shortages, disruption of global supply chains and inflationary pressures, and could impact our estimates of credit losses in our loan portfolios required in computing our allowance for credit losses;
•compliance with new and existing laws, regulations and regulatory expectations;
•limitations on our ability to receive dividends from our subsidiaries;
•our ability to maintain adequate capital or liquidity levels or to comply with revised capital or liquidity requirements, which could have a negative impact on our financial results and our ability to return capital to our stockholders;
•the extensive use, reliability, and accuracy of the models and data on which we rely;
•increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions that can result from data protection or security incidents or a cyber-attack or other similar incidents, including one that results in the theft, loss, manipulation or misuse of information, or the disabling of systems and access to information critical to business operations;
•developments, changes or actions relating to any litigation, governmental investigation or regulatory enforcement action or matter involving us;
•the amount and rate of deposit growth and changes in deposit costs;
•our ability to execute on our strategic and operational plans;
•our response to competitive pressures;
•our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit and debit card networks and by legislation and regulation impacting such fees;
20 Capital One Financial Corporation (COF)
Table of Contents
•our success in integrating acquired businesses and loan portfolios, and our ability to realize anticipated benefits from announced transactions and strategic partnerships;
•our ability to develop, operate, and adapt our operational, technology and organizational infrastructure suitable for the nature of our business;
•the success of our marketing efforts in attracting and retaining customers;
•our risk management strategies;
•changes in the reputation of, or expectations regarding, us or the financial services industry with respect to practices, products or financial condition;
•fluctuations in market interest rates or volatility in the capital markets;
•the transition away from the London Interbank Offered Rate (“LIBOR”);
•our ability to attract, retain and motivate key senior leaders and skilled employees;
•climate change manifesting as physical or transition risks;
•our assumptions or estimates in our financial statements;
•the soundness of other financial institutions and other third parties;
•our ability to invest successfully in and introduce digital and other technological developments across all our businesses;
•our ability to manage risks from catastrophic events;
•compliance with applicable laws and regulations related to privacy, data protection and data security;
•our ability to protect our intellectual property; and
•other risk factors identified from time to time in our public disclosures, including in the reports that we file with the SEC.
Item 1A. Risk Factors
The following discussion sets forth what management currently believes could be the material risks and uncertainties that could impact our businesses, results of operations and financial condition. The events and consequences discussed in these risk factors could, in circumstances we may not be able to accurately predict, recognize, or control, have a material adverse effect on our business, growth, reputation, prospects, financial condition, operating results, cash flows, liquidity, and stock price. These risk factors do not identify all risks that we face; our operations could also be affected by factors, events, or uncertainties that are not presently known to us or that we currently do not consider to present significant risks to our operations. In addition, the global economic and political climate may amplify many of these risks.
Summary of Risk Factors
The following is a summary of the Risk Factors disclosure in this Item 1A. This summary does not address all of the risks that we face. Additional discussion of the risks summarized in this risk factor summary, and other risks that we face, can be found below and should be carefully considered, together with other information in this Form 10-K and our other filings with the SEC, before making an investment decision regarding our securities.
•Changes and instability in the macroeconomic environment, consumer confidence and customer behavior may adversely affect our business.
•Fluctuations in market interest rates or volatility in the capital markets could adversely affect our business.
•Our results of operations may be adversely affected by the effects of the COVID-19 pandemic.
21 Capital One Financial Corporation (COF)
Table of Contents
•We may experience increases or fluctuations in delinquencies and credit losses, inaccurate estimates and inadequate reserves.
•We may not be able to maintain adequate capital or liquidity levels or may become subject to revised capital or liquidity requirements, which could have a negative impact on our financial results and our ability to return capital to our stockholders.
•Limitations on our ability to receive dividends from our subsidiaries could affect our liquidity and ability to pay dividends and repurchase common stock.
•We face risks related to our operational, technological and organizational infrastructure.
•A cyber-attack or other security incident, including one that results in the theft, loss, manipulation or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions.
•Our required compliance with applicable laws and regulations related to privacy, data protection and data security may increase our costs, reduce our revenue, increase our legal exposure and limit our ability to pursue business opportunities.
•We face risks resulting from the extensive use of models and data.
•Compliance with new and existing laws, regulations and regulatory expectations is costly and complex.
•Our businesses are subject to the risk of increased litigation, government investigations and regulatory enforcement.
•We face intense competition in all of our markets.
•Our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit and debit card networks and by legislation and regulation impacting such fees.
•If we are not able to invest successfully in and introduce digital and other technological developments across all our businesses, our financial performance may suffer.
•We may fail to realize the anticipated benefits of our mergers, acquisitions and strategic partnerships.
•Reputational risk and social factors may impact our results and damage our brand.
•If we are not able to protect our intellectual property, our revenue and profitability could be negatively affected.
•Our risk management strategies may not be fully effective in mitigating our risk exposures in all market environments or against all types of risk.
•The transition away from London Interbank Offered Rate may adversely affect our business.
•Our business could be negatively affected if we are unable to attract, retain and motivate key senior leaders and skilled employees.
•We face risks from catastrophic events.
•Climate change manifesting as physical or transition risks could adversely affect our businesses, operations and customers.
•We face risks from the use of or changes to assumptions or estimates in our financial statements.
•The soundness of other financial institutions and other third parties could adversely affect us.
22 Capital One Financial Corporation (COF)
Table of Contents
General Economic and Market Risks
Changes and instability in the macroeconomic environment, consumer confidence and customer behavior may adversely affect our business.
We offer a broad array of financial products and services to consumers, small businesses and commercial clients. A prolonged period of economic volatility, slow growth, or a significant deterioration in economic conditions, in the U.S., Canada or the U.K., could have a material adverse effect on our financial condition and results of operations as customers default on their loans, maintain lower deposit levels or, in the case of credit card accounts, carry lower balances and reduce credit card purchase activity.
Some of the risks we face in connection with adverse changes and instability in the macroeconomic environment and changes in consumer confidence levels and behavior, include the following:
•Monetary policies and actions taken by the Federal Reserve and other central banks or governmental authorities;
•Economic deterioration due to escalation of military hostilities or other geopolitical instabilities;
•Changes in payment patterns, increases or fluctuations in delinquencies and default rates, decreased consumer spending, inflation, fluctuation in interest rates, lower demand for credit and shifts in consumer behavior, including deposits and payments;
•Increases in our charge-off rate caused by bankruptcies and reduced ability to recover debt that we have previously charged-off;
•Recent changes in usage of commercial real estate, which may have a sustained negative impact on utilization rates and values;
•Decreased reliability of the process and models, including those we use to estimate our allowance for credit losses, particularly if unexpected variations in key inputs and assumptions cause actual losses to diverge from the projections of our models and our estimates become increasingly subject to management’s judgment. See “We face risks resulting from the extensive use of models and data.”
The U.K. and the EU agreed to a free trade deal at the end of 2020 relating to the U.K.’s exit from the EU. Although this deal has provided greater near-term stability, there is still some degree of uncertainty as to the relationship between the U.K and the EU, which may increase volatility in the regional and global financial markets. In addition, the global economy, including economic conditions in the U.K., has been negatively impacted by the war between Russia and Ukraine. Continued escalation of geopolitical tensions related to the war, including increased trade barriers or restrictions on global trade, could further deteriorate international economic conditions. We continue to consider and monitor the potential impacts of the relationship between the U.K. and EU, as well as the war between Russia and Ukraine.
Fluctuations in market interest rates or volatility in the capital markets could adversely affect our business.
Like other financial institutions, our business is sensitive to interest rate movements and the performance of the capital markets.
We rely on access to the capital markets to fund our operations and to grow our business. Our ability to borrow from other financial institutions or to engage in funding transactions on favorable terms or at all could be adversely affected by disruptions, uncertainty or volatility in the capital markets or other events, including changing credit rating agency requirements. For example, a credit rating downgrade could affect our ability to access the capital markets, increase our funding costs and have a negative impact on our results of operations. Additionally, increased charge-offs, rising interest rates and other events may cause our securitization transactions to amortize earlier than scheduled or reduce the value of the securities that we hold for liquidity purposes, which could accelerate our need for additional funding from other sources.
Additionally, changes in interest rates could adversely affect the results of our operations and financial condition. For example, we borrow money from other institutions and depositors, which we use to make loans to customers and invest in debt securities and other interest-earning assets. We earn interest on these loans and assets and pay interest on the money we borrow from institutions and depositors. In response to inflationary pressures, the Federal Reserve has reversed its policy of maintaining the low benchmark federal funds interest rate over the last several years. In March 2022, the Federal Reserve began increasing the benchmark federal funds interest rate and has signaled its intention to continue to raise interest rates in an effort to tame
23 Capital One Financial Corporation (COF)
Table of Contents
inflation. Thus, the amount of interest that we pay on certain borrowings has increased and could increase further. Additionally, a shrinking yield premium between short-term and long-term market interest rates and in the relationship between our funding basis rate and our lending basis rate and inflation could affect our profitability.
We assess our interest rate risk by estimating the effect on our earnings, economic value and capital under various scenarios that differ based on assumptions about the direction and the magnitude of interest rate changes. We take risk mitigation actions based on those assessments. We face the risk that changes in interest rates could materially reduce our net interest income and our earnings, especially if actual conditions turn out to be materially different than those we assumed. See “Part II—Item 7. MD&A—Market Risk Profile” for additional information.
Furthermore, interest rate fluctuations and competitor responses to those changes may affect the rate of customer prepayments for auto and other term loans and may affect the balances customers carry on their credit cards and their balances in the deposits accounts they have with us. For example, increases in interest rates increase debt service requirements for some of our borrowers, which may adversely affect those borrowers’ ability to pay as contractually obligated. This could result in additional or fluctuating delinquencies or charge-offs and negatively impact our results of operations. These changes can reduce the overall yield on our interest-earning asset portfolio. An inability to attract or maintain deposits could materially affect our ability to fund our business and our liquidity position. Many other financial institutions have increased their reliance on deposit funding and, as such, we expect continued competition in the deposit markets. We cannot predict how this competition will affect our costs. If we are required to offer higher interest rates to attract or maintain deposits, our funding costs will be adversely impacted. Changes in valuations in the debt and equity markets could have a negative impact on the assets we hold in our investment portfolio. Such market changes could also have a negative impact on the valuation of assets for which we provide servicing.
Our results of operations may be adversely affected by the effects of the COVID-19 pandemic.
Although the global economy has begun to recover from the COVID-19 pandemic, certain adverse consequences of the pandemic, including labor shortages, disruptions of global supply chains and inflationary pressures, continue to impact the macroeconomic environment and could adversely affect our business. Should these ongoing effects of the pandemic continue for an extended period or worsen, our purchase volume, loan balances and the overall demand for our products and services may be significantly impacted, which could adversely affect our financial condition and other results of operations. In addition, we could experience higher credit losses in our loan portfolios and increases in our allowance for credit losses beyond current levels. We could also experience impairments of other financial assets and other negative impacts on our financial position, including possible constraints on liquidity and capital, as well as higher costs of capital. Long-term consequences of the COVID-19 pandemic on our business, results of operations and financial condition, as well as our capital and liquidity ratios and our ability to take capital actions, will depend on future developments that remain uncertain, including, for example, future actions taken by governmental authorities, central banks and other third parties in response to the pandemic and the effects on our customers, counterparties, associates and third-party service providers.
In the third quarter of 2022, we moved our associates to a hybrid work model. As a result we may experience increased costs and/or disruption as we experiment with hybrid work models, in addition to potential effects on our ability to operate effectively and maintain our corporate culture. We will continue to monitor local conditions to ensure the safety of our associates and customers while providing critical banking services. We may take further actions as required by government authorities or that we otherwise determine are in the best interests of our customers, associates and business partners. These measures could impair our ability to perform critical functions and may adversely impact our results of operations.
Credit Risk
We may experience increases or fluctuations in delinquencies and credit losses, inaccurate estimates and inadequate reserves.
Like other lenders, we face the risk that our customers will not repay their loans. A customer’s ability and willingness to repay us can be adversely affected by decreases in the income of the borrower or increases in their payment obligations to other lenders, whether as a result of higher debt levels or rising interest rates, by rising levels of inflation, or by restricted availability of credit generally. We may fail to quickly identify and reduce our exposure to customers that are likely to default on their payment obligations, whether by closing credit lines or restricting authorizations. Our ability to manage credit risk also is affected by legal or regulatory changes (such as restrictions on collections, bankruptcy laws, minimum payment regulations and
24 Capital One Financial Corporation (COF)
Table of Contents
re-age guidance), competitors’ actions and consumer behavior, and depends on the effectiveness of our collections staff, techniques and models.
Rising losses or leading indicators of rising losses (such as higher delinquencies, charge-offs, higher rates of nonperforming loans, higher bankruptcy rates, lower collateral values, elevated unemployment rates or changing market terms) may require us to increase our allowance for credit losses, which would decrease our profitability if we are unable to raise revenue or reduce costs to compensate for higher losses. In particular, we face the following risks in this area:
•Missed Payments: Our customers may miss payments. Loan charge-offs (including from bankruptcies) are generally preceded by missed payments or other indications of worsening financial condition for our customers. Historically, customers are more likely to miss payments during an economic downturn, recession, periods of high unemployment, or prolonged periods of slow economic growth. In addition, we face the risk that consumer and commercial customer behavior may change (for example, an increase in the unwillingness or inability of customers to repay debt, which may be heightened by increasing interest rates or levels of consumer debt), causing a long-term rise or fluctuations in delinquencies and charge-offs.
•Incorrect Estimates of Expected Losses: The credit quality of our portfolio can have a significant impact on our earnings. We allow for and reserve against credit risks based on our assessment of expected credit losses in our loan portfolios. This process, which is critical to our financial condition and results of operations, requires complex judgments, including forecasts of economic conditions. We may underestimate our expected losses and fail to hold an allowance for credit losses sufficient to account for these losses. Incorrect assumptions could lead to material underestimations of expected credit losses and an inadequate allowance for credit losses. See “We face risks resulting from the extensive use of models and data.”
•Inaccurate Underwriting: Our ability to accurately assess the creditworthiness of our customers may diminish, which could result in an increase in our credit losses and a deterioration of our returns. See “Our risk management strategies may not be fully effective in mitigating our risk exposures in all market environments or against all types of risk.”
•Business Mix: We engage in a diverse mix of businesses with a broad range of potential credit exposure. Because we originate a relatively greater proportion of consumer loans in our loan portfolio compared to other large bank peers and originate both prime and subprime credit card accounts and auto loans, we may experience higher delinquencies and a greater number of accounts charging off, as well as greater fluctuations in those metrics, compared to other large bank peers, which could result in increased credit losses, operating costs and regulatory scrutiny. Additionally, a change in this business mix over time to include proportionally more consumer loans or subprime credit card accounts or auto loans could adversely affect the credit quality of our portfolio.
•Increasing Charge-off Recognition/Allowance for Credit Losses: We account for the allowance for credit losses according to accounting and regulatory guidelines and rules, including Financial Accounting Standards Board (“FASB”) standards and the Federal Financial Institutions Examination Council (“FFIEC”) Account Management Guidance. We measure our allowance for credit losses under the CECL standard, which is based on management’s best estimate of expected lifetime credit losses. The impact of measuring our allowance for credit losses on our results will depend on the characteristics of our financial instruments, economic conditions, and our economic and loss forecasts. The application of the CECL standard may require us to increase reserves faster and to a higher level in an economic downturn, resulting in greater adverse impact to our results and our capital ratios than we would have experienced in similar circumstances prior to the adoption of CECL. In addition, because credit cards represent a significant portion of our product mix, we could be disproportionately affected by use of the CECL standard, as compared to our large bank peers with a different product mix.
25 Capital One Financial Corporation (COF)
Table of Contents
•Insufficient Asset Values: The collateral we have on secured loans could be insufficient to compensate us for credit losses. When customers default on their secured loans, we attempt to recover collateral where permissible and appropriate. However, the value of the collateral may not be sufficient to compensate us for the amount of the unpaid loan, and we may be unsuccessful in recovering the remaining balance from our customers. Decreases in real estate and other asset values adversely affect the collateral value for our commercial lending activities, while the auto business is similarly exposed to collateral risks arising from the auction markets that determine used car prices. Borrowers may be less likely to continue making payments on loans if the value of the property used as collateral for the loan is less than what the borrower owes, even if the borrower is still financially able to make the payments. In that circumstance, the recovery of such property could be insufficient to compensate us for the value of these loans upon a default. In our auto business, business and economic conditions that negatively affect household incomes, housing prices and consumer behavior, as well as technological advances that make older cars obsolete faster, could decrease (i) the demand for new and used vehicles and (ii) the value of the collateral underlying our portfolio of auto loans, which could cause the number of consumers who become delinquent or default on their loans to increase.
•Geographic and Industry Concentration: Although our consumer lending is geographically diversified, approximately 40% of our commercial real estate loan portfolio is concentrated in the Northeast region. The regional economic conditions in the Northeast affect the demand for our commercial products and services as well as the ability of our customers to repay their commercial real estate loans and the value of the collateral securing these loans. An economic downturn or prolonged period of slow economic growth in, or a catastrophic event or natural disaster that disproportionately affects the Northeast region could have a material adverse effect on the performance of our commercial real estate loan portfolio and our results of operations. In addition, our Commercial Banking strategy includes an industry-specific focus. If any of the industries that we focus on experience changes, we may experience increased credit losses and our results of operations could be adversely impacted.
Capital and Liquidity Risk
We may not be able to maintain adequate capital or liquidity levels or may become subject to revised capital or liquidity requirements, which could have a negative impact on our financial results and our ability to return capital to our stockholders.
Financial institutions are subject to extensive and complex capital and liquidity requirements, which are subject to change. These requirements affect our ability to lend, grow deposit balances, make acquisitions and distribute capital. Failure to maintain adequate capital or liquidity levels, whether due to adverse developments in our business or the economy or to changes in the applicable requirements, could subject us to a variety of restrictions and/or remedial actions imposed by our regulators. These include limitations on the ability to pay dividends and/or repurchase shares and the issuance of a capital directive to increase capital. Such limitations or capital directive could have a material adverse effect on our business and results of operations.
We consider various factors in the management of capital, including the impact of both internal and supervisory stress scenarios on our capital levels as determined by our internal modeling and the Federal Reserve’s estimation of losses in supervisory stress scenarios that are used to annually set our stress capital buffer requirement. There can be significant differences between our modeling and the Federal Reserve’s projections for a given supervisory stress scenario and between the capital needs suggested by our internal stress scenarios and the supervisory scenarios. Therefore, although our estimated capital levels under stress disclosed as part of the stress testing processes may suggest that we have a particular capacity to return capital to stockholders and remain well capitalized under stress, the Federal Reserve’s modeling, our internal modeling of another scenario and/or other factors related to our capital management process may reflect a lower capacity to return capital to stockholders than that indicated by the projections released in the stress testing processes. This in turn, could lead to restrictions on our ability to pay dividends and engage in share repurchases. See “Part I—Item 1. Business—Supervision and Regulation” for additional information.
We also consider various factors in the management of liquidity, including maintaining sufficient liquid assets to meet the requirements of several internal and regulatory stress tests. There can be significant differences in estimated liquidity needs between internal and regulatory stress testing, and liquidity resources required to meet regulatory requirements, such as applicable LCR and NSFR requirements, may exceed what would otherwise be required to satisfy internal liquidity metrics and stress testing. Regulatory liquidity stress testing and regulatory liquidity requirements may, therefore, require us to take actions to increase our liquid assets or alter our activities or funding sources, which could negatively affect our financial results or our
26 Capital One Financial Corporation (COF)
Table of Contents
ability to return capital to our stockholders. See “Part I—Item 1. Business—Supervision and Regulation” for additional information.
In addition, changes to applicable capital and liquidity requirements could result in increased expenses or unexpected or new limitations on our ability to pay dividends and engage in share repurchases.
Limitations on our ability to receive dividends from our subsidiaries could affect our liquidity and ability to pay dividends and repurchase common stock.
We are a separate and distinct legal entity from our subsidiaries, including the Bank and our broker-dealer subsidiaries. Dividends to us from these direct and indirect subsidiaries have represented a major source of funds for us to pay dividends on our common and preferred stock, repurchase common stock, make payments on corporate debt securities and meet other obligations. These capital distributions may be limited by law, regulation or supervisory policy. There are various federal law limitations on the extent to which the Bank can finance or otherwise supply funds to us through dividends and loans. These limitations include minimum regulatory capital requirements, federal banking law requirements concerning the payment of dividends out of net profits or surplus, and Sections 23A and 23B of the Federal Reserve Act and Regulation W governing transactions between an insured depository institution and its affiliates, as well as general federal regulatory oversight to prevent unsafe or unsound practices. Our broker-dealer subsidiaries are also subject to laws and regulations, including net capital requirements, that may limit their ability to pay dividends or make other distributions to us. If our subsidiaries’ earnings are not sufficient to make dividend payments to us while maintaining adequate capital levels, our liquidity may be affected and we may not be able to make dividend payments to our common or preferred stockholders, repurchase our common stock, make payments on outstanding corporate debt securities or meet other obligations, each and any of which could have a material adverse impact on our results of operations, our financial position or the perception of our financial health. The frequency and size of any future dividends to our stockholders and stock repurchases will depend upon regulatory limitations imposed by the Federal Banking Agencies and the SEC and our results of operations, financial condition, capital levels, cash requirements, future prospects, regulatory review and other factors as further described in “Part I—Item 1. Business—Supervision and Regulation.”
Operational Risk
We face risks related to our operational, technological and organizational infrastructure.
Our ability to retain and attract customers depends on our ability to develop, operate, and adapt our technology and organizational infrastructure in a rapidly changing environment. In addition, we must accurately process, record and monitor an increasingly large number of complex transactions. Digital technology, cloud-based services, data and software development are deeply embedded into our business model and how we work.
Similar to other large corporations in our industry, we are exposed to operational risk that can manifest itself in many ways, such as errors in execution, inadequate processes, inaccurate models, faulty or disabled technological infrastructure, malicious disruption and fraud by employees or persons outside of our company, whether through attacks on Capital One directly or on our customers. In addition, the increasing use of near real-time money movement solutions, among other risks, increases the complexity of preventing, detecting and recovering fraudulent transactions. In addition, we are heavily dependent on the security, capability, integrity and continuous availability of the technology systems that we use to manage our internal financial and other systems, monitor risk and compliance with regulatory requirements, provide services to our customers, develop and offer new products and communicate with stakeholders. We also face risk of adverse customer impacts and business disruption arising from the execution of strategic initiatives and operational plans we may pursue across our operations.
If we do not maintain the necessary operational, technological and organizational infrastructure to operate our business, including to maintain the resiliency and security of that infrastructure, our business and reputation could be materially adversely affected. We also are subject to disruptions to our systems arising from events that are wholly or partially beyond our control, which may include computer viruses, electrical or telecommunications outages, bugs, design flaws in foundational components or platforms, availability and quality of vulnerability patches from key vendors, cyber-attacks and other security incidents, natural disasters, other damage to property or physical assets, or events arising from local or larger scale politics, including terrorist acts. Any failure to maintain our infrastructure or prevent disruption of our systems and applications could diminish our ability to operate our businesses, service customer accounts and protect customers’ information, or result in potential liability to customers, reputational damage, regulatory intervention and customers’ loss of confidence in our businesses, any of which could result in a material adverse effect.
27 Capital One Financial Corporation (COF)
Table of Contents
We also rely on the business infrastructure and systems of third parties with which we do business and to whom we outsource the operation, maintenance and development of our information technology and communications systems. We have substantially migrated all aspects of our core information technology systems and customer-facing applications to third-party cloud infrastructure platforms, principally AWS. If we fail to architect, administer or oversee these environments in a well-managed, secure and effective manner, or if such platforms become unavailable, are disrupted, fail to scale, do not operate as designed, or do not meet their service level agreements for any reason, we may experience unplanned service disruption or unforeseen costs which could result in material harm to our business and operations. We must successfully develop and maintain information, financial reporting, disclosure, privacy, data protection, data security and other controls adapted to our reliance on outside platforms and providers. In addition, AWS, or other service providers could experience system or telecommunication breakdowns or failures, outages, degradation in service, downtime, failure to scale, software bugs, cyber-attacks and other security incidents, adverse changes to financial condition, bankruptcy, or other adverse conditions, (including conditions which interfere with our access to and use of AWS), which could have a material adverse effect on our business and reputation. Thus, the substantial amount of our infrastructure that we outsource to AWS or to other third parties may increase our risk exposure.
Any disruptions, failures or inaccuracies of our operational processes, technology systems and models, including those associated with improvements or modifications to such technology systems and models, could cause us to be unable to market and manage our products and services, manage our risk, meet our regulatory obligations or report our financial results in a timely and accurate manner, all of which could have a negative impact on our results of operations. In addition, our ongoing investments in infrastructure, which are necessary to maintain a competitive business, integrate acquisitions and establish scalable operations, may increase our expenses. As our business develops, changes or expands, additional expenses can arise as a result of a reevaluation of business strategies, management of outsourced services, asset purchases or other acquisitions, structural reorganization, compliance with new laws or regulations, the integration of newly acquired businesses, or the prevention or occurrence of cyber-attacks and other security incidents. If we are unable to successfully manage our expenses, our financial results will be negatively affected. Changes to our business, including those resulting from our strategic objectives, also requires robust governance to ensure that our objectives are executed as intended without adversely impacting our customers, associates, operations or financial performance. Ineffective change management oversight and governance over the execution of our strategic objectives could expose us to operational, strategic and reputational risk and could negatively impact customers or our financial performance.
A cyber-attack or other security incident, including one that results in the theft, loss, manipulation or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions.
Our ability to provide our products and services, many of which are internet-based, and communicate with our customers, depends upon the management and safeguarding of information systems and infrastructure, networks, software, data, technology, methodologies and business secrets, including those of our service providers. Our products and services involve the collection, authentication, management, usage, storage, transmission and eventual destruction of sensitive and confidential information, including personal information, regarding our customers and their accounts, our employees, our partners and other third parties with which we do business. We also have arrangements in place with third parties through which we share and receive information about their customers who are or may become our customers. The financial services industry, including Capital One, is particularly at risk because of the use of and reliance on digital banking products and other digital services, including mobile banking products, such as mobile payments, and other internet- and cloud-based products and applications, and the development of additional remote connectivity solutions, which increase cybersecurity risks and exposure. Consumer acceptance and use of such digital banking products and services has substantially increased since the onset of the COVID pandemic.
Technologies, systems, networks, and other devices of Capital One, as well as those of our employees, service providers, partners and other third parties with whom we interact, have been and may continue to be the subject of cyber-attacks and other security incidents, including computer viruses, hacking, malware, ransomware, supply chain attacks, vulnerabilities, credential stuffing, or phishing or other forms of social engineering. Such cyber-attacks and other security incidents are designed to lead to various harmful outcomes, such as unauthorized transactions in Capital One accounts, unauthorized or unintended access to or release, gathering, monitoring, disclosure, loss, destruction, corruption, disablement, encryption, misuse, modification or other processing of confidential or sensitive information (including personal information), intellectual property, software, methodologies or business secrets, disruption, sabotage or degradation of service, systems or networks, or other damage. These threats may derive from, among other things, error, fraud or malice on the part of our employees, insiders, or third parties or may result from accidental technological failure or design flaws. Any of these parties may also attempt to fraudulently induce
28 Capital One Financial Corporation (COF)
Table of Contents
employees, service providers, customers, partners or other third-party users of our systems or networks to disclose confidential or sensitive information (including personal information) in order to gain access to our systems, networks or data or that of our customers, partners, or third parties with whom we interact, or to unlawfully obtain monetary benefit through misdirected or otherwise improper payment. For instance, any party that obtains our confidential or sensitive information (including personal information) through a cyber-attack or other security incident may use this information for ransom, to be paid by us or a third party, as part of a fraudulent activity that is part of a broader criminal activity, or for other illicit purposes.
For example, on July 29, 2019, we announced that on March 22 and 23, 2019 an outside individual gained unauthorized access to our systems (the “Cybersecurity Incident”). This individual obtained certain types of personal information relating to people who had applied for our credit card products and to our credit card customers. While the Cybersecurity Incident has been remediated, it has resulted in fines, litigation, settlements, government investigations and other regulatory enforcement inquiries, as well as consent orders with the Federal Reserve and the OCC. On August 31, 2022, the OCC terminated its consent order. Cyber and information security risks for large financial institutions like us continue to increase due to the proliferation of new technologies, the industry-wide shift to reliance upon the internet to conduct financial transactions, and the increased sophistication and activities of malicious actors, organized crime, perpetrators of fraud, hackers, terrorists, activists, extremist parties, formal and informal instrumentalities of foreign governments, state-sponsored actors and other external parties. In addition, our customers access our products and services using personal devices that are necessarily external to our security control systems. There has also been a significant proliferation of consumer information available on the internet resulting from breaches of third-party entities, including personal information, log-in credentials and authentication data. While we were not directly involved in these third-party breach events, the stolen information can create a threat for our customers if their Capital One log-in credentials are the same as or similar to the credentials that have been compromised on other internet sites. This threat could include the risk of unauthorized account access, data loss and fraud. The use of artificial intelligence, “bots” or other automation software can increase the velocity and efficacy of these types of attacks. As our employees are currently operating under our hybrid work model, our remote interaction with service providers, partners and other third parties on systems, networks and environments over which we have less control increases our cybersecurity risk exposure. We will likely face an increasing number of attempted cyber-attacks as we expand our mobile and other internet-based products and services, as well as our usage of mobile and cloud technologies and as we provide more of these services to a greater number of retail banking customers.
The methods and techniques employed by malicious actors change frequently, are increasingly sophisticated and often are not fully recognized or understood until after they have occurred, and some techniques could occur and persist for an extended period of time before being detected and remediated. For example, although we immediately fixed the configuration vulnerability that was exploited in the Cybersecurity Incident once we discovered the unauthorized access, a period of time elapsed between the occurrence of the unauthorized access and the time when we discovered it. In other circumstances, we and our service providers and other third parties with which we interact may be unable to anticipate or identify certain attack methods or techniques in order to implement effective preventative or detective measures or mitigate or remediate the damages caused in a timely manner. We may also be unable to hire, develop and retain talent that keeps pace with the rapidly changing cyber threat landscape, and which are capable of preventing, detecting, mitigating or remediating these risks. Although we seek to maintain a robust suite of authentication and layered information security controls, any one or combination of these controls could fail to prevent, detect, mitigate or remediate these risks in a timely manner.
A disruption or breach, including as a result of a cyber-attack such as the Cybersecurity Incident, or media reports of perceived security vulnerabilities at Capital One or at our service providers, could result in significant legal and financial exposure, regulatory intervention, litigation, remediation costs, card reissuance, supervisory liability, damage to our reputation or loss of confidence in the security of our systems, products and services that could adversely affect our business. There can be no assurance that unauthorized access or cyber incidents similar to the Cybersecurity Incident will not occur or that we will not suffer material losses in the future. If future attacks are successful or if customers are unable to access their accounts online for other reasons, it could adversely impact our ability to service customer accounts or loans, complete financial transactions for our customers or otherwise operate any of our businesses or services. In addition, a breach or attack affecting one of our service providers or other third parties with which we interact could harm our business even if we do not control the service that is attacked.
Further, our ability to monitor our service providers’ cybersecurity practices is limited. Although the agreements that we have in place with our service providers generally include requirements relating to cybersecurity and data privacy, we cannot guarantee that such agreements will prevent a cyber incident impacting our systems or information or enable us to obtain adequate or any reimbursement from our service providers in the event we should suffer any such incidents. However, due to
29 Capital One Financial Corporation (COF)
Table of Contents
applicable laws and regulations or contractual obligations, we may be held responsible for cyber incidents attributed to our service providers as they relate to the information we share with them.
In addition, the increasing prevalence and the evolution of cyber-attacks and other efforts to breach or disrupt our systems or networks or those of our customers, service providers, partners or other third parties with which we interact has led, and will likely continue to lead, to increased costs to us with respect to preventing, detecting, mitigating and remediating these risks, as well as any related attempted fraud. In order to address ongoing and future risks, we must expend significant resources to support protective security measures, investigate and remediate any vulnerabilities of our information systems and infrastructure and invest in new technology designed to mitigate security risks. Further, high profile cyber incidents at Capital One or other large financial institutions could lead to a general loss of customer confidence in financial institutions that could negatively affect us, including harming the market perception of the effectiveness of our security measures or the global financial system in general, which could result in reduced use of our financial products. We have insurance against some cyber risks and attacks; nonetheless, our insurance coverage may not be sufficient to offset the impact of a material loss event (including if our insurer denies coverage as to any particular claim in the future), and such insurance may increase in cost or cease to be available on commercially reasonable terms, or at all, in the future.
Our required compliance with applicable laws and regulations related to privacy, data protection and data security may increase our costs, reduce our revenue, increase our legal exposure and limit our ability to pursue business opportunities.
We are subject to a variety of continuously evolving and developing laws and regulations in the United States at the federal, state and local level regarding privacy, data protection and data security, including those related to the collection, storage, handling, use, disclosure, transfer, security and other processing of personal information. For example, at the federal level, we are subject to the GLBA, among other laws and regulations. Moreover, the U.S. Congress is currently considering various proposals for more comprehensive privacy, data protection and data security legislation, to which we may be subject if passed. In addition, in November 2021, the Federal Reserve, OCC, and FDIC issued a final rule that, among other things, requires all banking organizations in the United States to notify their primary federal regulators of certain material computer-security incidents as soon as possible and no later than 36 hours after determining that the incident has occurred. The enactment of CIRCIA, once rulemaking is complete, will require, among other things, certain companies to report significant cyber incidents to the CISA within 72 hours from the time the company reasonably believes the incident occurred, and a proposed rule by the SEC, if enacted, would mandate public disclosure of material cybersecurity incidents within four business days of determining that such an incident has occurred. At the state level, California has enacted the California Privacy Rights Act (“CPRA”), and various other states also have enacted or are in the process of enacting state-level privacy, data protection and/or data security laws and regulations, with which we may be required to comply.
We also are, or may become, subject to continuously evolving and developing laws and regulations in other jurisdictions regarding privacy, data protection and data security. For example, in Canada we are subject to the Personal Information Protection and Electronic Documents Act (“PIPEDA”). In addition, subject to limited exceptions, the EU General Data Projection Regulation (“EU GDPR”) applies EU data protection law to all companies processing personal data of EU residents, regardless of the company’s location. We also are subject to the UK General Data Protection Regulation (“U.K. GDPR”), which is how the EU GDPR has been implemented into U.K. law. These laws and regulations, and similar laws and regulations in other jurisdictions, impose strict requirements regarding the collection, storage, handling, use, disclosure, transfer, security and other processing of personal information, which may have adverse consequences, including significant compliance costs and severe monetary penalties for non-compliance. Significant uncertainty exists as privacy, data protection, and data security laws may be interpreted and applied differently from country to country and may create inconsistent or conflicting requirements.
Further, we make public statements about our use, collection, disclosure and other processing of personal information through our privacy policies, information provided on our website and press statements. Although we endeavor to comply with our public statements and documentation, we may at times fail to do so or be alleged to have failed to do so. The publication of our privacy policies and other statements that provide promises and assurances about privacy, data protection and data security can subject us to potential government or legal action if they are found to be deceptive, unfair or misrepresentative of our actual practices.
Our efforts to comply with GLBA, CPRA, PIPEDA, EU GDPR, U.K. GDPR and other privacy, data protection and data security laws and regulations, as well as our posted privacy policies, and related contractual obligations to third parties, entail substantial expenses, may divert resources from other initiatives and projects, and could limit the services we are able to offer. Furthermore, enforcement actions and investigations by regulatory authorities related to data security incidents and privacy, data protection and data security violations continue to increase. The enactment of more restrictive laws or regulations, or future
30 Capital One Financial Corporation (COF)
Table of Contents
enforcement actions or investigations, could impact us through increased costs or restrictions on our business, and any noncompliance or perceived noncompliance could result in monetary or other penalties, harm to our reputation and significant legal liability.
We face risks resulting from the extensive use of models and data.
We rely on quantitative models and our ability to manage and aggregate data in an accurate and timely manner to assess and manage our various risk exposures, create estimates and forecasts, and manage compliance with regulatory capital requirements. Models may be used in processes such as determining the pricing of various products, grading loans and extending credit, measuring interest rate and other market risks, predicting deposit levels or loan losses, assessing capital adequacy, calculating managerial and regulatory capital levels, estimating the value of financial instruments and balance sheet items, and other operational functions. Our risk reporting and management, including business decisions based on information incorporating models, depend on the effectiveness of our models and our policies, programs, processes and practices governing how data or models, as applicable, are acquired, validated, stored, protected, processed and analyzed. Any issues with the quality or effectiveness of our data aggregation and validation procedures, as well as the quality and integrity of data inputs, formulas or algorithms, could result in inaccurate forecasts, ineffective risk management practices or inaccurate risk reporting. In addition, models based on historical data sets might not be accurate predictors of future outcomes and their ability to appropriately predict future outcomes may degrade over time. While we continuously update our policies, programs, processes and practices, many of our data management, modeling, aggregation and implementation processes are manual and may be subject to human error, data limitations, process delays or system failure. Failure to manage data effectively and to aggregate data in an accurate and timely manner may limit our ability to manage current and emerging risk, to produce accurate financial, regulatory and operational reporting as well as to manage changing business needs. If our Framework is ineffective, we could suffer unexpected losses which could materially adversely affect our results of operation or financial condition. Also, any information we provide to the public or to our regulators based on poorly designed or implemented models could be inaccurate or misleading. Some of the decisions that our regulators make, including those related to capital distribution to our stockholders, could be affected adversely due to the perception that the quality of the models used to generate the relevant information is insufficient.
Legal and Regulatory Risk
Compliance with new and existing laws, regulations and regulatory expectations is costly and complex.
A wide array of laws and regulations, including banking and consumer lending laws and regulations, apply to every aspect of our business. We and our subsidiaries are also subject to supervision and examination by multiple regulators, and the manner in which our regulators interpret applicable laws and regulations may affect how we comply with them. Failure to comply with these laws and regulations, even if the failure was inadvertent or reflects a difference in interpretation, could subject us to restrictions on our business activities, fines, criminal sanctions and other penalties, and/or damage to our reputation with regulators, our customers or the public. Hiring, training and retaining qualified compliance and legal personnel, and establishing and maintaining risk management and compliance-related systems, infrastructure and processes, is difficult and may lead to increased expenses. These efforts and the associated costs could limit our ability to invest in other business opportunities.
Applicable rules and regulations may affect us disproportionately compared to our competitors or in an unforeseen manner. For example, we have a large number of customer accounts in our credit card and auto lending businesses and we have made the strategic choice to originate and service subprime credit card and auto loans, which typically have higher delinquencies and charge-offs than prime customer accounts. As a result, we have significant involvement with credit bureau reporting and the collection and recovery of delinquent and charged-off debt, primarily through customer communications, the filing of litigation against customers in default, the periodic sale of charged-off debt and vehicle repossession. These and other consumer lending activities are subject to enhanced legal and regulatory scrutiny from regulators, courts and legislators. Any future changes to or legal liabilities resulting from our business practices in these areas, including our debt collection practices and the fees we charge, whether mandated by regulators, courts, legislators or otherwise, could have a material adverse impact on our financial condition.
The legislative and regulatory environment is beyond our control, may change rapidly and unpredictably, and may negatively influence our revenue, costs, earnings, growth, liquidity and capital levels. For example, there may be future rulemaking in emerging regulatory areas such as climate-related risks and new technologies. In addition, some rules and regulations may be subject to litigation or other challenges that delay or modify their implementation and impact on us. Adoption of new technologies, such as distributed ledger technologies, tokenization, cloud computing, artificial intelligence and machine learning technologies, can present unforeseen challenges in applying and relying on existing compliance systems.
31 Capital One Financial Corporation (COF)
Table of Contents
Certain laws and regulations, and any interpretations and applications with respect thereto, are generally intended to protect consumers, borrowers, depositors, the DIF, the U.S. banking and financial system, and financial markets as a whole, but not stockholders. Our success depends on our ability to maintain compliance with both existing and new laws and regulations. For a description of the material laws and regulations, including those related to the consumer lending business, to which we are subject, see “Part I—Item 1. Business—Supervision and Regulation.”
Our businesses are subject to the risk of increased litigation, government investigations and regulatory enforcement.
Our businesses are subject to increased litigation, government investigations and other regulatory enforcement risks as a result of a number of factors and from various sources, including the highly regulated nature of the financial services industry, the focus of state and federal prosecutors on banks and the financial services industry and the structure of the credit card industry.
Given the inherent uncertainties involved in litigation, government investigations and regulatory enforcement decisions, and the very large or indeterminate damages sought in some matters asserted against us, there can be significant uncertainty as to the ultimate liability we may incur from these kinds of matters. The finding, or even the assertion, of substantial legal liability against us could have a material adverse effect on our business and financial condition and could cause significant reputational harm to us, which could seriously harm our business. For example, the Cybersecurity Incident has resulted in litigation, settlements, government investigations and other regulatory enforcement inquiries.
In addition, financial institutions, such as ourselves, face significant regulatory scrutiny, which can lead to public enforcement actions or nonpublic supervisory actions. We and our subsidiaries are subject to comprehensive regulation and periodic examination by, among other regulatory bodies, the Federal Banking Agencies, SEC, CFTC and CFPB. We have been subject to enforcement actions by many of these and other regulators and may continue to be involved in such actions, including governmental inquiries, investigations and enforcement proceedings, including by the OCC, Department of Justice, Financial Crimes Enforcement Network (“FinCEN”) and state Attorneys General.
Over the last several years, federal and state regulators have focused on compliance with AML and sanctions laws, privacy, data protection and data security, use of service providers, fair lending and other consumer protection issues. In August 2020, we entered into consent orders with the Federal Reserve and the OCC resulting from regulatory reviews of the Cybersecurity Incident and relating to ongoing enhancements of our cybersecurity and operational risk management processes, and we paid a civil monetary penalty as part of the OCC agreement. On August 31, 2022, the OCC terminated its consent order. In January 2021, we also paid a civil monetary penalty assessed by FinCEN against the Bank in connection with AML violations alleged to have occurred between 2008 and 2014. Regulatory scrutiny is expected to continue in these areas, including as a result of implementation of the AML Act of 2020.
We expect that regulators and governmental enforcement bodies will continue taking public enforcement actions against financial institutions in addition to addressing supervisory concerns through nonpublic supervisory actions or findings, which could involve restrictions on our activities, or our ability to make acquisitions or otherwise expand our business, among other limitations that could adversely affect our business. In addition, a violation of law or regulation by another financial institution is likely to give rise to an investigation by regulators and other governmental agencies of the same or similar practices by us. Furthermore, a single event may give rise to numerous and overlapping investigations and proceedings. These and other initiatives from governmental authorities and officials may subject us to further judgments, settlements, fines or penalties, or cause us to restructure our operations and activities or to cease offering certain products or services, all of which could harm our reputation or lead to higher operational costs. Litigation, government investigations and other regulatory actions could generally subject us to significant fines, increased expenses, restrictions on our activities and damage to our reputation and our brand, and could adversely affect our business, financial condition and results of operations. For additional information regarding legal and regulatory proceedings to which we are subject, see “Part II—Item 8.Financial Statements and Supplementary Data—Note 18—Commitments, Contingencies, Guarantees and Others.”
Other Business Risks
We face intense competition in all of our markets.
We operate in a highly competitive environment across all of our lines of business, whether in making loans, attracting deposits or in the global payments industry, and we expect competitive conditions to continue to intensify with respect to most of our products particularly in our credit card and consumer banking business. We compete on the basis of the rates we pay on deposits and the rates and other terms we charge on the loans we originate or purchase, as well as the quality and range of our
32 Capital One Financial Corporation (COF)
Table of Contents
customer service, products, innovation and experience. This increasingly competitive environment is primarily a result of changes in technology, product delivery systems and regulation, as well as the emergence of new or significantly larger financial services providers, all of which may affect our customers’ expectations and demands. In addition to offering competitive products and services, we invest in and conduct marketing campaigns to attract and inform customers. If our marketing campaigns are unsuccessful, it may adversely impact our ability to attract new customers and grow market share.
Some of our competitors, including new and emerging competitors in the digital and mobile payments space and other financial technology providers, are not subject to the same regulatory requirements or scrutiny to which we are subject, which also could place us at a competitive disadvantage, in particular in the development of new technology platforms or the ability to rapidly innovate. We compete with many forms of payments offered by both bank and non-bank providers, including a variety of new and evolving alternative payment mechanisms, systems and products, such as aggregators and web-based and wireless payment platforms or technologies, digital or cryptocurrencies, prepaid systems and payment services targeting users of social networks, communications platforms and online gaming. If we are unable to continue to keep pace with innovation, do not effectively market our products and services or are prohibited from or unwilling to enter emerging areas of competition, our business and results of operations could be adversely affected.
Some of our competitors are substantially larger than we are, which may give those competitors advantages, including a more diversified product and customer base, the ability to reach more customers and potential customers, operational efficiencies, broad-based local distribution capabilities, lower-cost funding and larger existing branch networks. Many of our competitors are also focusing on cross-selling their products and developing new products or technologies, which could affect our ability to maintain or grow existing customer relationships or require us to offer lower interest rates or fees on our lending products or higher interest rates on deposits. Competition for loans could result in origination of fewer loans, earning less on our loans or an increase in loans that perform below expectations.
We operate as an online direct bank in the United States. While direct banking provides a significant opportunity to attract new customers that value greater and more flexible access to banking services at reduced costs, we face strong and increasing competition in the direct banking market. Aggressive pricing throughout the industry may adversely affect the retention of existing balances and the cost-efficient acquisition of new deposit funds and may affect our growth and profitability. Customers could also close their online accounts or reduce balances or deposits in favor of products and services offered by competitors for other reasons. These shifts, which could be rapid, could result from general dissatisfaction with our products or services, including concerns over pricing, online security or our reputation. The potential consequences of this competitive environment are exacerbated by the flexibility of direct banking and the financial and technological sophistication of our online customer base.
In our credit card business, competition for rewards customers may result in higher rewards expenses, or we may fail to attract new customers or retain existing rewards customers due to increasing competition for these consumers. As of December 31, 2022, we have a number of large partnerships in our credit card loan portfolio. The market for key business partners, especially in the credit card business, is very competitive, and we may not be able to grow or maintain these partner relationships or assure that these relationships will be profitable or valued by our customers. Additionally, partners themselves may face changes in their business, including market factors and ownership changes, that could impact the partnership. We face the risk that we could lose partner relationships, even after we have invested significant resources into acquiring and developing the relationships. The loss of key business partners could have a negative impact on our results of operations, including lower returns, excess operating expense and excess funding capacity.
We depend on our partners to effectively promote our co-brand and private label products and integrate the use of our credit cards into their retail operations. The failure by our partners to effectively promote and support our products as well as changes they may make in their business models could adversely affect card usage and our ability to achieve the growth and profitability objectives of our partnerships. In addition, if our partners do not adhere to the terms of our program agreements and standards, or otherwise diminish the value of our brand, we may suffer reputational damage and customers may be less likely to use our products.
Some of our competitors have developed, or may develop, substantially greater financial and other resources than we have, may offer richer value propositions or a wider range of programs and services than we offer, or may use more effective advertising, marketing or cross-selling strategies to acquire and retain more customers, capture a greater share of spending and borrowings, attain and develop more attractive co-brand card programs and maintain greater merchant acceptance than we have. We may not be able to compete effectively against these threats or respond or adapt to changes in consumer spending habits as effectively as our competitors.
33 Capital One Financial Corporation (COF)
Table of Contents
In such a competitive environment, we may lose entire accounts or may lose account balances to competing firms, or we may find it more costly to maintain our existing customer base. Customer attrition from any or all of our lending products, together with any lowering of interest rates or fees that we might implement to retain customers, could reduce our revenues and therefore our earnings. Similarly, unexpected customer attrition from our deposit products, in addition to an increase in rates or services that we may offer to retain deposits, may increase our expenses and therefore reduce our earnings.
Our business, financial condition and results of operations may be adversely affected by merchants’ increasing focus on the fees charged by credit and debit card networks and by legislation and regulation impacting such fees.
Interchange fees are generally one of the largest components of the costs that merchants pay in connection with the acceptance of credit and debit cards and are a meaningful source of revenue for our credit and debit card businesses. Interchange fees are the subject of significant and intense global legal, legislative and regulatory focus, and the resulting decisions, legislation and regulation may have a material adverse impact on our overall business, financial condition and results of operations.
Legislative and regulatory bodies in a number of countries are seeking to reduce interchange fees through legislation, competition-related regulatory proceedings, voluntary agreements, central bank regulation and/or litigation. For credit transactions, interchange reimbursement rates in the United States are set by credit card networks such as MasterCard and Visa. For debit transactions, Federal Reserve rules place limits on the interchange fees we may charge. For more information on these rules, please see “Part I—Item 1. Business—Supervision and Regulation.” In some jurisdictions, such as Canada and certain countries in Europe, including the U.K., interchange fees and related practices are subject to regulatory activity, including in some cases, imposing caps on permissible interchange fees. Our international card businesses have been impacted by these restrictions. For example, in the U.K., interchange fees are capped for both credit and debit card transactions. In addition, in Canada, Visa and Mastercard payment networks have entered into voluntary agreements with the Department of Finance Canada to maintain an agreed upon average interchange rate. Lowering interchange fees remains an area of domestic and international governmental focus. Legislators and regulators around the world are aware of each other’s approaches to the regulation of the payments industry. Consequently, a development in one country, state or region may influence regulatory approaches in another, such as our primary market, the United States.
In addition to this regulatory activity, merchants are also seeking avenues to reduce interchange fees. In the past, merchants and their trade groups have filed numerous lawsuits against Visa, MasterCard, American Express and their card-issuing banks, claiming that their practices toward merchants, including interchange and similar fees, violate federal antitrust laws. In 2005, a number of entities filed antitrust lawsuits against MasterCard and Visa and several member banks, including our subsidiaries and us, alleging among other things, that the defendants conspired to fix the level of interchange fees. In December 2013, the U.S. District Court for the Eastern District of New York granted final approval of the proposed class settlement. The settlement provided, among other things, that merchants would be entitled to join together to negotiate lower interchange fees. The settlement was appealed to the Second Circuit Court of Appeals, which rejected the settlement in June 2016; a revised settlement was reached in the second half of 2018, and the trial court issued its final approval of the settlement in December 2019. See “Part II—Item 8.Financial Statements and Supplementary Data—Note 18—Commitments, Contingencies, Guarantees and Others” for further details.
Some major retailers have sufficient bargaining power to independently negotiate lower interchange fees with MasterCard and Visa, which could, in turn, result in lower interchange fees for us when our cardholders undertake purchase transactions with these retailers. Merchants also continue to lobby Congress aggressively for restrictions on interchange fees and their efforts may be successful. Retailers may in the future bring legal proceedings against us or other credit card and debit card issuers and networks.
Beyond pursuing litigation, legislation and regulation, merchants may also promote forms of payment with lower fees, such as ACH-based payments, or seek to impose surcharges at the point of sale for use of credit or debit cards. New payment systems, particularly mobile-based payment technologies, could also gain widespread adoption and lead to issuer transaction fees or the displacement of credit card accounts as a payment method.