Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

COF US Equity

Capital One Financial CorpFinancials · National Commercial Banks · CIK 927628 · FY ends Dec 31
$217.91
+5.43 (+2.56%)
USD · as of 2026-08-21 · marketstack

COF · 10-K · period ended 2024-12-31

← all COF documents
filed 2025-02-20 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1532 of 3,591683k characters rendered

cof-20241231

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

____________________________________

FORM 10-K

___________________________________

For the fiscal year ended December 31, 2024

OR

For the transition period from to

Commission File No. 001-13300

____________________________________

CAPITAL ONE FINANCIAL CORPORATION

(Exact name of registrant as specified in its charter)

____________________________________

1680 Capital One Drive,

(Address of principal executive offices) (Zip Code)

Registrant’s telephone number, including area code: (703) 720-1000

____________________________________

Securities registered pursuant to Section 12(b) of the Act:

Title of Each Class Trading Symbol(s) Name of Each Exchange on Which Registered

Common Stock (par value $.01 per share) COF New York Stock Exchange

1.650% Senior Notes Due 2029 COF29 New York Stock Exchange

Securities registered pursuant to section 12(g) of the Act: None

____________________________________

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No☒

Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer ☒ Accelerated filer ☐

Non-accelerated filer ☐ Smaller reporting company ☐

Emerging growth company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C.7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒

The aggregate market value of the voting and non-voting stock held by non-affiliates of the registrant as of the close of business on June 30, 2024 was approximately $52.3 billion. As of January 31, 2025, there were 381,327,698 shares of the registrant’s Common Stock outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

1.Portions of the Proxy Statement for the annual meeting of stockholders to be held on May 08, 2025, are incorporated by reference into Part III.

TABLE OF CONTENTS

Page

PART I 4

Item 1. Business 4

Overview 4

Operations and Business Segments 6

Competition 7

Supervision and Regulation 7

Human Capital Resources 18

Technology and Intellectual Property 18

Forward-Looking Statements 20

Item 1A. Risk Factors 22

Item 1B. Unresolved Staff Comments 46

Item 1C. Cybersecurity 46

Item 2. Properties 48

Item 3. Legal Proceedings 48

Item 4. Mine Safety Disclosures 48

Item 6. [Reserved] 52

Selected Financial Data 53

Executive Summary 56

Consolidated Results of Operations 57

Consolidated Balance Sheets Analysis 63

Off-Balance Sheet Arrangements 67

Business Segment Financial Performance 68

Critical Accounting Policies and Estimates 78

Accounting Changes and Developments 82

Capital Management 83

Risk Management 88

Credit Risk Profile 94

Liquidity Risk Profile 108

Market Risk Profile 113

Supplemental Tables 117

Glossary and Acronyms 119

Item 7A. Quantitative and Qualitative Disclosures about Market Risk 129

Item 8. Financial Statements and Supplementary Data 130

Consolidated Statements of Income 135

Consolidated Statements of Comprehensive Income 136

Consolidated Balance Sheets 137

1 Capital One Financial Corporation (COF)

Consolidated Statements of Changes in Stockholders’ Equity 138

Consolidated Statements of Cash Flows 139

Notes to Consolidated Financial Statements 141

Note 1—Summary of Significant Accounting Policies 141

Note 2—Business Combinations 156

Note 3—Investment Securities 157

Note 6—Variable Interest Entities and Securitizations 178

Note 7—Goodwill and Other Intangible Assets 182

Note 8—Premises, Equipment and Leases 185

Note 9—Deposits and Borrowings 187

Note 10—Derivative Instruments and Hedging Activities 189

Note 11—Stockholders’ Equity 198

Note 12—Regulatory and Capital Adequacy 201

Note 13—Earnings Per Common Share 203

Note 14—Stock-Based Compensation Plans 204

Note 15—Employee Benefit Plans 206

Note 17—Fair Value Measurement 211

Note 18—Business Segments and Revenue from Contracts with Customers 220

Note 19—Commitments, Contingencies, Guarantees and Others 225

Note 20—Capital One Financial Corporation (Parent Company Only) 229

Note 21—Related Party Transactions 231

Item 9A. Controls and Procedures 232

Item 9B. Other Information 232

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 232

Item 10. Directors, Executive Officers and Corporate Governance 233

Item 11. Executive Compensation 233

Item 14. Principal Accountant Fees and Services 233

Item 15. Exhibits and Financial Statement Schedules 234

EXHIBIT INDEX 235

2 Capital One Financial Corporation (COF)

INDEX OF MD&A AND SUPPLEMENTAL TABLES

MD&A Tables: Page

1 Average Balances, Net Interest Income and Net Interest Margin 58

2 Rate/Volume Analysis of Net Interest Income 59

3 Non-Interest Income 60

4 Non-Interest Expense 62

5 Loans Held for Investment 64

6 Funding Sources Composition 64

7 Business Segment Results 69

8 Credit Card Business Results 70

8.1 Domestic Card Business Results 72

9 Consumer Banking Business Results 73

10 Commercial Banking Business Results 75

11 Other Category Results 76

12 Capital Ratios Under Basel III 85

13 Regulatory Risk-Based Capital Components and Regulatory Capital Metrics 86

14 Preferred Stock Dividends Paid Per Share 87

15 Loan Maturity Schedule 95

16 Credit Card Portfolio by Geographic Region 96

17 Consumer Banking Portfolio by Geographic Region 97

18 Commercial Real Estate Portfolio by Region 98

19 Commercial Loans by Industry 99

20 Credit Score Distribution 100

22 Aging and Geography of 30+ Day Delinquent Loans 102

23 90+ Day Delinquent Loans Accruing Interest 103

24 Nonperforming Loans and Other Nonperforming Assets 104

28 Deposits Composition and Average Deposits Interest Rates 110

29 Amount of Uninsured Time Deposits by Contractual Maturity 111

30 Long-Term Debt Funding Activities 111

31 Senior Unsecured Long-Term Debt Credit Ratings 112

32 Interest Rate Sensitivity Analysis 115

Supplemental Tables:

A Net Charge-Offs 117

B Reconciliation of Non-GAAP Measures 117

3 Capital One Financial Corporation (COF)

Table of Contents

PART I

Item 1. Business

OVERVIEW

General

Capital One Financial Corporation, a Delaware corporation established in 1994 and headquartered in McLean, Virginia, is a diversified financial services holding company with banking and non-banking subsidiaries. Capital One Financial Corporation and its subsidiaries (the “Company” or “Capital One”) offer a broad array of financial products and services to consumers, small businesses and commercial clients through digital channels, branch locations, cafés and other distribution channels.

As of December 31, 2024, Capital One Financial Corporation’s principal operating subsidiary was Capital One, National Association (“CONA”). The Company is hereafter collectively referred to as “we,” “us” or “our.” CONA is referred to as the “Bank.”

References to “this Report” or our “2024 Form 10-K” or “2024 Annual Report” are to our Annual Report on Form 10-K for the fiscal year ended December 31, 2024. All references to 2024, 2023 and 2022, refer to our fiscal years ended, or the dates, as the context requires, December 31, 2024, December 31, 2023 and December 31, 2022, respectively. Certain business terms used in this document are defined in “Part II—Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations (“MD&A”)—Glossary and Acronyms” and should be read in conjunction with the Consolidated Financial Statements included in this Report.

We were the third largest issuer of Visa® (“Visa”) and MasterCard® (“MasterCard”) credit cards in the U.S. based on the outstanding balance of credit card loans as of December 31, 2024. In addition to credit cards, we also offer debit cards, bank lending, treasury management and depository services, auto loans and other consumer lending products in markets across the U.S. As one of the nation’s largest banks based on deposits as of December 31, 2024, we service banking customer accounts through digital channels and our network of branch locations, cafés, call centers and automated teller machines (“ATMs”).

We also offer products and services outside of the U.S. principally through Capital One (Europe) plc (“COEP”), an indirect subsidiary of CONA organized and located in the United Kingdom (“U.K.”), and through a branch of CONA in Canada. Both COEP and our Canadian branch of CONA have the authority to provide credit card loans.

Agreement to Acquire Discover

On February 19, 2024, the Company entered into an agreement and plan of merger (the “Merger Agreement”), by and among Capital One, Discover Financial Services, a Delaware corporation (“Discover”) and Vega Merger Sub, Inc., a Delaware corporation and a direct, wholly owned subsidiary of the Company (“Merger Sub”), pursuant to which (a) Merger Sub will merge with and into Discover, with Discover as the surviving entity in the merger (the “Merger”); (b) immediately following the Merger, Discover, as the surviving entity, will merge with and into Capital One, with Capital One as the surviving entity in the second-step merger (the “Second Step Merger”); and (c) immediately following the Second Step Merger, Discover Bank, a Delaware-chartered and wholly owned subsidiary of Discover, will merge with and into CONA, with CONA as the surviving entity in the merger (the “CONA Bank Merger,” and collectively with the Merger and the Second Step Merger, the “Transaction”). The Merger Agreement was unanimously approved by the Boards of Directors of each of Capital One and Discover.

At the effective time of the Merger, each share of common stock of Discover outstanding immediately prior to the effective time of the Merger, other than certain shares held by Discover or Capital One, will be converted into the right to receive 1.0192 shares of common stock of Capital One. Holders of Discover common stock will receive cash in lieu of fractional shares. At the effective time of the Second Step Merger, each share of Fixed-to-Floating Rate Non-Cumulative Perpetual Preferred Stock, Series C, of Discover, and each share of 6.125% Fixed-Rate Reset Non-Cumulative Perpetual Preferred Stock, Series D, of Discover, in each case outstanding immediately prior to the effective time of the Second Step Merger, will be converted into the right to receive a share of newly created series of preferred stock of Capital One having terms that are not materially less favorable than the applicable series of Discover preferred stock.

On February 18, 2025, Capital One and Discover each held a special meeting of their respective stockholders. During the respective meetings, Capital One stockholders approved by the requisite vote the issuance of Capital One common stock as

4 Capital One Financial Corporation (COF)

Table of Contents

merger consideration to the holders of Discover common stock, and Discover stockholders adopted by the requisite vote the Merger Agreement. The closing of the Transaction remains subject to the satisfaction of other customary closing conditions, including the receipt of required regulatory approvals.

Walmart Program Agreement Termination

On May 21, 2024, our credit card program agreement with Walmart terminated (“Walmart Program Termination”). Pursuant to terms of the termination, Capital One retained ownership and servicing of the existing credit card portfolio and is nearing completion of converting eligible customers into Capital One branded card products.

Other Business Developments

We regularly explore and evaluate opportunities to acquire financial products and services as well as financial assets, including credit card and other loan portfolios, and enter into strategic partnerships as part of our growth strategy. We also explore opportunities to acquire technology companies and related assets to improve our information technology infrastructure and to deliver on our digital strategy. We may issue equity or debt to fund our acquisitions. In addition, we regularly consider the potential disposition of certain of our assets, branches, partnership agreements or lines of business.

Additional Information

Our common stock trades on the New York Stock Exchange (“NYSE”) under the symbol “COF” and is included in the Standard & Poor’s (“S&P”) 100 Index. We maintain a website at www.capitalone.com. Documents available under “Governance & Leadership” in the Investor Relations section of our website include:

•our Certificate of Incorporation, Bylaws, Corporate Governance Guidelines, and Code of Conduct; and

•charters for the Audit, Compensation, Governance and Nominating, and Risk Committees of the Board of Directors.

These documents also are available in print to any stockholder who requests a copy. We intend to disclose any future amendments to, or waivers from, our Code of Conduct on the website following the date of any such amendment or waiver.

In addition, we make available free of charge through our website all of our U.S. Securities and Exchange Commission (“SEC”) filings, including our Annual Reports on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K and amendments to those reports filed or furnished pursuant to Section 13(a) or 15(d) of the Exchange Act, as soon as reasonably practicable after electronically filing or furnishing such material to the SEC at www.sec.gov. We also routinely post financial and other information, which could be deemed to be material to investors, on our investor relations website. Information regarding our corporate social responsibility and environmental sustainability initiatives is also available on our website. The content of any of our websites referred to in this Report is not incorporated by reference into this Report or any other filings with the SEC.

5 Capital One Financial Corporation (COF)

Table of Contents

OPERATIONS AND BUSINESS SEGMENTS

Our consolidated total net revenues are derived primarily from lending to consumer and commercial customers net of funding costs associated with our deposits, long-term debt and other borrowings. We also earn non-interest income which primarily consists of interchange income, net of reward expenses, and service charges and other customer-related fees. Our expenses primarily consist of the provision for credit losses, operating expenses, marketing expenses and income taxes.

Our principal operations are organized for management reporting purposes into three major business segments, which are defined primarily based on the products and services provided or the types of customers served: Credit Card, Consumer Banking and Commercial Banking. The operations of acquired businesses have been integrated into or managed as a part of our existing business segments. Certain activities that are not part of a business segment are included in the Other category, such as the management of our corporate investment portfolio and asset/liability positions performed by our centralized Corporate Treasury group and any residual tax expense or benefit beyond what is assessed to our business segments in order to arrive at the consolidated effective tax rate. The Other category also includes unallocated corporate expenses that do not directly support the operations of the business segments or for which the business segments are not considered financially accountable in evaluating their performance, such as certain restructuring charges and integration expenses related to the Transaction.

•Credit Card: Consists of our domestic consumer and small business card lending, and international card businesses in the U.K. and Canada.

•Consumer Banking: Consists of our deposit gathering and lending activities for consumers and small businesses, and national auto lending.

•Commercial Banking: Consists of our lending, deposit gathering, capital markets and treasury management services to commercial real estate and commercial and industrial customers. Our customers typically include companies with annual revenues between $20 million and $2 billion.

Customer usage and payment patterns, estimates of future expected credit losses, levels of marketing expense and operating efficiency all affect our profitability. In our Credit Card business, we generally experience fluctuations in purchase volume and the level of outstanding loan receivables from seasonal variances in consumer spending and payment patterns which, for example, have historically been the highest around the winter holiday season. Net charge-off rates for our credit card loan portfolio have historically exhibited seasonal patterns as well and generally tend to be the highest in the first quarter of the year.

For additional information on our business segments, including the financial performance of each business, see “Part II—Item 7. MD&A—Executive Summary,” “Part II—Item 7. MD&A—Business Segment Financial Performance” and “Part II—Item 8. Financial Statements and Supplementary Data—Note 18—Business Segments and Revenue from Contracts with Customers” of this Report.

6 Capital One Financial Corporation (COF)

Table of Contents

COMPETITION

Each of our business segments operates in a highly competitive environment, and we face competition in all aspects of our business from numerous bank and non-bank providers of financial services.

Our Credit Card business competes with international, national, regional and local issuers of Visa and MasterCard credit cards, as well as with American Express®, Discover Card®, private-label card brands, and, to a certain extent, issuers of debit cards. In general, customers are attracted to credit card issuers largely on the basis of price, credit limit, reward programs, customer experience and other product features.

Our Consumer Banking and Commercial Banking businesses compete with national, state and direct banks as well as with savings and loan associations and credit unions for loans and deposits. Our competitors also include automotive finance companies, commercial banking companies and other financial services providers that provide loans, deposits, and other similar services and products. In addition, we compete against non-bank institutions that are able to offer these products and services.

We also consider new and emerging companies in digital and mobile payments and other financial technology providers among our competitors. We compete with many forms of payment mechanisms, systems and products, offered by both bank and non-bank providers.

Our businesses generally compete on the basis of the quality and range of their products and services, transaction execution, innovation and price. Competition varies based on the types of clients, customers, industries and geographies served. Our ability to compete depends, in part, on our ability to attract and retain our associates and on our reputation as well as our ability to keep pace with innovation, in particular in the development of new technology platforms. There can be no assurance, however, that our ability to market products and services successfully or to obtain adequate returns on our products and services will not be impacted by the nature of the competition that now exists or may later develop, or by the broader economic environment. For a discussion of the risks related to our competitive environment, see “Item 1A. Risk Factors.”

SUPERVISION AND REGULATION

General

The regulatory framework applicable to banking organizations is intended primarily for the protection of depositors and the stability of the U.S. financial system, rather than for the protection of stockholders and creditors.

As a banking organization, we are subject to extensive regulation and supervision. In addition to banking laws and regulations, we are subject to various other laws and regulations, all of which directly or indirectly affect our operations, management and ability to make distributions to stockholders. We and our subsidiaries are also subject to supervision and examination by multiple regulators. In addition to laws and regulations, state and federal bank regulatory agencies may issue policy statements, interpretive letters and similar written guidance applicable to us and our subsidiaries. Any change in the statutes, regulations or regulatory policies applicable to us, including changes in their interpretation or implementation, could have a material effect on our business or organization.

Both the scope of the laws and regulations and the intensity of the supervision to which we are subject have increased, initially in response to the 2007-2008 financial crisis, and more recently in light of other factors such as technological, political and market changes, as well as the 2023 regional bank failures. Regulatory enforcement and fines have also increased across the banking and financial services sector.

The descriptions below summarize certain significant federal and state laws, as well as international laws, to which we are subject. The descriptions are qualified in their entirety by reference to the particular statutory or regulatory provisions summarized. They do not summarize all possible or proposed changes in current laws or regulations and are not intended to be a substitute for the related statutes or regulatory provisions.

Prudential Regulation of Banking

Capital One Financial Corporation is a bank holding company (“BHC”) and a financial holding company (“FHC”) under the Bank Holding Company Act of 1956, as amended (“BHC Act”), and is subject to the requirements of the BHC Act, including approval requirements for investments in or acquisitions of banking organizations, capital adequacy standards and limitations

7 Capital One Financial Corporation (COF)

Table of Contents

on non-banking activities. As a BHC and FHC, we are subject to supervision, examination and regulation by the Board of Governors of the Federal Reserve System (“Federal Reserve”). Permissible activities for a BHC include those activities that are so closely related to banking as to be a proper incident thereto. In addition, an FHC is permitted to engage in activities considered to be financial in nature (including, for example, securities underwriting and dealing and merchant banking activities), incidental to financial activities or, if the Federal Reserve determines that they pose no risk to the safety or soundness of depository institutions or the financial system in general, activities complementary to financial activities.

To become and remain eligible for FHC status, a BHC and its subsidiary depository institutions must meet certain criteria, including capital, management and Community Reinvestment Act (“CRA”) requirements. Failure to meet such criteria could result, depending on which requirements were not met, in restrictions on new financial activities or acquisitions or being required to discontinue existing activities that are not generally permissible for BHCs.

The Bank is a national association chartered under the National Bank Act, the deposits of which are insured by the Federal Deposit Insurance Corporation (“FDIC”) up to applicable limits. The Bank is subject to comprehensive regulation and periodic examination by the Office of the Comptroller of the Currency (“OCC”), the FDIC and the Consumer Financial Protection Bureau (“CFPB”).

We also are registered as a financial institution holding company under the laws of the Commonwealth of Virginia and, as such, we are subject to periodic examination by the Virginia Bureau of Financial Institutions. We also face regulation in the international jurisdictions in which we conduct business. See “Regulation by Authorities Outside the United States” below for additional details.

Capital and Stress Testing Regulation

The Company and the Bank are subject to capital adequacy guidelines adopted by the Federal Reserve and OCC, respectively. For a further discussion of the capital adequacy guidelines, see “Part II—Item 7. MD&A—Capital Management” and “Part II—Item 8. Financial Statements and Supplementary Data—Note 12—Regulatory and Capital Adequacy.”

Basel III and U.S. Capital Rules

The Company and the Bank are subject to the regulatory capital requirements established by the Federal Reserve and the OCC, respectively (“Basel III Capital Rules”). The Basel III Capital Rules implement certain capital requirements published by the Basel Committee on Banking Supervision (“Basel Committee”), along with certain provisions of the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 (“Dodd-Frank Act”) and other capital provisions.

As a BHC with total consolidated assets of at least $250 billion but less than $700 billion and not exceeding any of the applicable risk-based thresholds, the Company is a Category III institution under the Basel III Capital Rules.

The Bank, as a subsidiary of a Category III institution, is a Category III bank. Moreover, the Bank, as an insured depository institution, is subject to prompt corrective action (“PCA”) capital regulations, as described below.

Under the Basel III Capital Rules, we must maintain a minimum common equity Tier 1 (“CET1”) capital ratio of 4.5%, a Tier 1 capital ratio of 6.0% and a total capital ratio of 8.0%, in each case in relation to risk-weighted assets. In addition, we must maintain a minimum leverage ratio of 4.0% and a minimum supplementary leverage ratio of 3.0%. We are also subject to the capital conservation buffer requirement and countercyclical capital buffer requirement, each as described below. Our capital and leverage ratios are calculated based on the Basel III standardized approach framework.

We have elected to exclude certain elements of accumulated other comprehensive income (“AOCI”) from our regulatory capital as permitted for a Category III institution. See “Basel III Finalization Proposal” below for information on the recognition of AOCI in regulatory capital under the proposed changes to the Basel III Capital Rules.

Global systemically important banks (“G-SIBs”) that are based in the U.S. are subject to an additional CET1 capital requirement known as the “G-SIB Surcharge.” We are not a G-SIB based on the most recent available data and thus we are not subject to a G-SIB Surcharge.

8 Capital One Financial Corporation (COF)

Table of Contents

Stress Capital Buffer Rule

The Basel III Capital Rules require banking institutions to maintain a capital conservation buffer, composed of CET1 capital, above the regulatory minimum ratios. Under the Federal Reserve’s final rule to implement the stress capital buffer requirement (“Stress Capital Buffer Rule”), the Company’s “standardized approach capital conservation buffer” includes its stress capital buffer requirement (as described below), any G-SIB Surcharge (which is not applicable to us) and the countercyclical capital buffer requirement (which is currently set at 0%). Any determination to increase the countercyclical capital buffer generally would be effective twelve months after the announcement of such an increase, unless the Federal Reserve, OCC and the FDIC (collectively, “Federal Banking Agencies”) set an earlier effective date.

The Company’s stress capital buffer requirement is recalibrated every year based on the Company’s supervisory stress test results, as discussed below. In particular, the Company’s stress capital buffer requirement equals, subject to a floor of 2.5%, the sum of (i) the difference between the Company’s starting CET1 capital ratio and its lowest projected CET1 capital ratio under the severely adverse scenario of the Federal Reserve’s supervisory stress test plus (ii) the ratio of the Company’s projected four quarters of common stock dividends (for the fourth to seventh quarters of the planning horizon) to the projected risk-weighted assets for the quarter in which the Company’s projected CET1 capital ratio reaches its minimum under the supervisory stress test.

Based on the Company’s 2024 supervisory stress test results, the Company’s stress capital buffer requirement for the period beginning on October 1, 2024 through September 30, 2025 is 5.5%. Therefore, the Company’s minimum capital requirements plus the standardized approach capital conservation buffer for CET1 capital, Tier 1 capital and total capital ratios under the stress capital buffer framework are 10.0%, 11.5% and 13.5%, respectively, for the period from October 1, 2024 through September 30, 2025.

The Stress Capital Buffer Rule does not apply to the Bank. Pursuant to the OCC’s capital regulations, which are only applicable to the Bank, the capital conservation buffer for the Bank continues to be fixed at 2.5%. Therefore, the Bank’s minimum capital requirements plus its capital conservation buffer for CET1 capital, Tier 1 capital and total capital ratios are 7.0%, 8.5% and 10.5%, respectively. See “Part II—Item 7. MD&A—Capital Management” and “Part II—Item 8. Financial Statements and Supplementary Data—Note 12—Regulatory and Capital Adequacy” for additional information.

If the Company or the Bank fails to maintain its capital ratios above the minimum capital requirements plus the applicable capital conservation buffers, it will face increasingly strict automatic limitations on capital distributions and discretionary bonus payments to certain executive officers.

See also “Capital Planning and Stress Testing” below for more information about the stress capital buffer determination process.

CECL Transition Rule

The Federal Banking Agencies adopted a final rule (“CECL Transition Rule”) that provides banking institutions an optional five-year transition period to phase in the impact of the current expected credit losses (“CECL”) standard on their regulatory capital (“CECL Transition Election”). We adopted the CECL standard (for accounting purposes) as of January 1, 2020, and made the CECL Transition Election (for regulatory capital purposes) in the first quarter of 2020.

Pursuant to the CECL Transition Rule, a banking institution could elect to delay the estimated impact of adopting CECL on its regulatory capital through December 31, 2021 and then phase in the estimated cumulative impact from January 1, 2022 through December 31, 2024. For the “day 2” ongoing impact of CECL during the initial two years, the Federal Banking Agencies used a uniform “scaling factor” of 25% as an approximation of the increase in the allowance under the CECL standard compared to the prior incurred loss methodology. Accordingly, from January 1, 2020 through December 31, 2021, electing banking institutions were permitted to add back to their regulatory capital an amount equal to the sum of the after-tax “day 1” CECL adoption impact and 25% of the increase in the allowance since the adoption of the CECL standard. From January 1, 2022 through December 31, 2024, the after-tax “day 1” CECL adoption impact and the cumulative “day 2” ongoing impact were being phased in to regulatory capital at 25% per year. The following table summarizes the capital impact delay and phase in period on our regulatory capital from years 2020 to 2025.

9 Capital One Financial Corporation (COF)

Table of Contents

Capital Impact Delayed Phase In Period

Market Risk Rule

The “Market Risk Rule” supplements the Basel III Capital Rules by requiring institutions subject to the rule to adjust their risk-based capital ratios to reflect the market risk in their trading book. The Market Risk Rule generally applies to institutions with aggregate trading assets and liabilities equal to 10% or more of total assets or $1 billion or more. As of December 31, 2024, the Company and the Bank are subject to the Market Risk Rule. See “Part II一Item 7. MD&A一Market Risk Profile” for additional information.

Basel III Finalization Proposal

In July 2023, the Federal Banking Agencies released a notice of proposed rulemaking (“Basel III Finalization Proposal”) to revise the Basel III Capital Rules applicable to banking organizations with total assets of $100 billion or more and their subsidiary depository institutions, including the Company and the Bank.

The Basel III Finalization Proposal would introduce a new framework for calculating risk-weighted assets (“Expanded Risk-Based Approach”). An institution subject to the proposal would be required to calculate its risk-weighted assets under both the Expanded Risk-Based Approach and the existing Basel III standardized approach and, for each risk-based capital ratio, would be bound by the calculation that produces the lower ratio. All capital buffer requirements, including the stress capital buffer requirement, would apply regardless of whether the Expanded Risk-Based Approach or the existing Basel III standardized approach produces the lower ratio. The proposal would also replace the existing approach for calculating market risk with a new approach based on both internal models and standardized methodologies.

The Basel III Finalization Proposal would also make certain changes to the calculation of regulatory capital for Category III and IV institutions. Under the proposal, these institutions would be required to begin recognizing certain elements of AOCI in CET1 capital, including unrealized gains and losses on available for sale securities. The proposal would also generally reduce the threshold above which these institutions must deduct certain assets from their CET1 capital, including certain deferred tax assets, mortgage servicing assets and investments in unconsolidated financial institutions.

The Basel III Finalization Proposal includes a proposed effective date of July 1, 2025, subject to a three-year transition period ending July 1, 2028, over which risk-weighted assets calculated under the Expanded Risk-Based Approach and the recognition of AOCI in CET1 capital would be phased in. It is uncertain when or if a final rule will be adopted, and if so, whether and to what extent it will differ from the Basel III Finalization Proposal. As a result, the timing and content of any final rule, and the potential effects of any final rule on the Company and the Bank, remain uncertain.

FDICIA and Prompt Corrective Action

The Federal Deposit Insurance Corporation Improvement Act of 1991 (“FDICIA”) requires the Federal Banking Agencies to take PCA for banks that do not meet minimum capital requirements. FDICIA establishes five capital ratio levels: well capitalized; adequately capitalized; undercapitalized; significantly undercapitalized; and critically undercapitalized. The three undercapitalized categories are based upon the amount by which a bank falls below the ratios applicable to an adequately capitalized institution. The capital categories relate to FDICIA’s PCA provisions and such capital categories may not constitute an accurate representation of the Bank’s overall financial condition or prospects.

For an insured depository institution to be well capitalized, it must maintain a total risk-based capital ratio of 10% or more; a Tier 1 capital ratio of 8% or more; a CET1 capital ratio of 6.5% or more; and a leverage ratio of 5% or more. An adequately capitalized depository institution must maintain a total risk-based capital ratio of 8% or more; a Tier 1 capital ratio of 6% or more; a CET1 capital ratio of 4.5% or more; a leverage ratio of 4% or more; and, for Category III and certain other institutions, a supplementary leverage ratio of 3% or more. The PCA provisions also authorize the Federal Banking Agencies to reclassify a

10 Capital One Financial Corporation (COF)

Table of Contents

bank’s capital category or take other action against banks that are determined to be in an unsafe or unsound condition or to have engaged in unsafe or unsound banking practices.

Capital Planning and Stress Testing

Under the Federal Reserve’s capital plan rule, a covered company, such as the Company, must submit a capital plan to the Federal Reserve on an annual basis that contains a description of all planned capital actions, including dividends or stock repurchases, over a nine-quarter planning horizon beginning with the first quarter of the calendar year the capital plan is submitted.

Pursuant to the capital plan rule, the Company must file its capital plan with the Federal Reserve by April 5 of each year (unless the Federal Reserve designates a later date), using data as of the end of the prior calendar year. The Federal Reserve will release the results of the supervisory stress test and notify the Company of its preliminary stress capital buffer requirement by June 30 of that year, and final stress capital buffer requirement by August 31 of that year. The Company’s final stress capital buffer requirement will be effective from October 1 of the year in which the capital plan is submitted through September 30 of the following year. As a general matter, the Company may make capital distributions in excess of those included in its capital plan without the prior approval of the Federal Reserve so long as the Company is otherwise in compliance with the capital rule’s automatic limitations on capital distributions. However, as described below, in the event a capital plan resubmission is required, all capital distributions would be subject to the prior approval of the Federal Reserve.

The Federal Reserve’s capital plan rule further provides that if a covered company determines there has been or will be a material change in its risk profile, financial condition, or corporate structure since it last submitted its capital plan, it must update and resubmit its capital plan within 30 calendar days, subject to a potential 60-day extension. We determined that our proposed acquisition of Discover constitutes a material change and submitted an updated capital plan as required by the capital plan rule. In addition, the capital plan rule provides that upon the occurrence of an event requiring resubmission, a covered company may not make any capital distribution unless it has received approval of the Federal Reserve. Accordingly, all our capital distributions are now subject to the prior approval of the Federal Reserve pending the Federal Reserve’s consideration of our resubmitted capital plan. We have received prior approval of the Federal Reserve to make certain capital distributions.

We are also subject to supervisory and company-run stress testing requirements (also known as the Dodd-Frank Act stress tests (“DFAST”). DFAST is a forward-looking exercise conducted by the Federal Reserve and each covered company to help assess whether a company has sufficient capital to absorb losses and continue operations during adverse economic conditions. In particular, the Federal Reserve is required to conduct annual stress tests on certain covered companies, such as the Company, to ensure that the covered companies have sufficient capital to absorb losses and continue operations during adverse economic conditions, as well as to determine the Company’s stress capital buffer requirement as described above. As a Category III institution, we are also required to conduct company-run stress tests and publish the results of such tests on our website or other public forum on a biennial basis. Under the OCC’s stress test rule, a bank with at least $250 billion in assets, including the Bank, must conduct its own company-run stress tests. The Bank must also disclose the results of its stress test on a biennial basis.

Funding and Dividends from Subsidiaries

Dividends from the Company’s direct and indirect subsidiaries represent a major source of the funds we use to pay dividends on our capital stock, make payments on our corporate debt securities and meet our other obligations. There are various federal law limitations on the extent to which the Bank can finance or otherwise supply funds to the Company through dividends and loans. These limitations include minimum regulatory capital and capital buffer requirements, federal banking law requirements concerning the payment of dividends out of net profits or surplus, provisions of Sections 23A and 23B of the Federal Reserve Act and Regulation W governing transactions between an insured depository institution and its affiliates, as well as general federal regulatory oversight to prevent unsafe or unsound practices. In general, federal and applicable state banking laws prohibit insured depository institutions, such as the Bank, from making dividend distributions without first obtaining regulatory approval if such distributions are not paid out of available earnings or would cause the institution to fail to meet applicable capital adequacy standards.

Liquidity Regulation

11 Capital One Financial Corporation (COF)

Table of Contents

The Company and the Bank are subject to minimum liquidity standards as adopted by the Federal Reserve and OCC, respectively. For a further discussion of the minimum liquidity standards, see “Part II一Item 7. MD&A一Liquidity Risk Profile.”

The Basel Committee has published a liquidity framework that includes two standards for liquidity risk supervision. One standard, the liquidity coverage ratio (“LCR”), seeks to promote short-term resilience by requiring organizations to hold sufficient high-quality liquid assets (“HQLAs”) to survive a stress scenario lasting for 30 days. The other standard, the net stable funding ratio (“NSFR”), seeks to promote longer-term resilience by requiring sufficient stable funding over a one-year period based on the liquidity characteristics of the organization’s assets and activities.

The Company and the Bank are subject to the LCR standard as implemented by the Federal Reserve and OCC, respectively (“LCR Rule”). The LCR Rule requires each of the Company and the Bank to hold an amount of eligible HQLA that equals or exceeds 100% of its respective projected adjusted net cash outflows over a 30-day period, each as calculated in accordance with the LCR Rule. The LCR Rule requires each of the Company and the Bank to calculate its respective LCR daily. In addition, the Company is required to make quarterly public disclosures of its LCR and certain related quantitative liquidity metrics, along with a qualitative discussion of its LCR.

As a Category III institution with less than $75 billion in weighted average short-term wholesale funding, the Company’s and the Bank’s total net cash outflows are multiplied by an outflow adjustment percentage of 85%. Although the Bank may hold more HQLA than it needs to meet its LCR requirements, the LCR Rule restricts the amount of such excess HQLA held at the Bank (referred to as “Trapped Liquidity”) that can be included in the Company’s HQLA amount. Because we typically manage the Bank’s LCR to levels well above 100%, the result is additional Trapped Liquidity as the Bank’s net cash outflows are reduced by the outflow adjustment percentage of 85%.

The Company and the Bank are subject to the NSFR standard as implemented by the Federal Reserve and OCC, respectively (“NSFR Rule”). The NSFR Rule requires each of the Company and the Bank to maintain an amount of available stable funding, which is a weighted measure of a company’s funding sources over a one-year time horizon, calculated by applying standardized weightings to equity and liabilities based on their expected stability, that is no less than a specified percentage of its required stable funding, which is calculated by applying standardized weightings to assets, derivatives exposures and certain other items based on their liquidity characteristics. As a Category III institution, the Company and the Bank are each required to maintain available stable funding in an amount at least equal to 85% of its required stable funding. The Company is required to make public disclosures of its NSFR every second and fourth quarter, including certain quantitative metrics and a qualitative discussion of its NSFR drivers and results.

In addition to the LCR and NSFR requirements discussed above, the Company is required to meet liquidity risk management standards, conduct internal liquidity stress tests and maintain a 30-day buffer of highly liquid assets, in each case, consistent with Federal Reserve regulations.

Deposit Funding and Brokered Deposits

Under FDICIA, only well capitalized and adequately capitalized institutions may accept “brokered deposits,” as defined by FDIC regulations. Adequately capitalized institutions, however, must obtain a waiver from the FDIC before accepting brokered deposits, and such institutions may not pay rates that significantly exceed the rates paid on deposits of similar maturity obtained from the institution’s normal market area or, for deposits obtained from outside the institution’s normal market area, the national rate on deposits of comparable maturity. See “Part II一Item 7. MD&A一Liquidity Risk Profile” for additional information.

The FDIC is authorized to terminate a bank’s deposit insurance upon a finding by the FDIC that the bank’s financial condition is unsafe or unsound or that the institution has engaged in unsafe or unsound practices or has violated any applicable rule, regulation, order or condition enacted or imposed by the bank’s regulatory agency.

Resolution and Recovery Planning Requirements and Related Authorities

Resolution and Recovery Planning

The Company is required by Section 165(d) of the Dodd-Frank Act to submit to the Federal Reserve and FDIC every three years a resolution plan for orderly resolution in the event it faces material financial distress or failure, with submissions alternating between a full resolution plan and a targeted resolution plan. Following review of a plan, the Federal Reserve and

12 Capital One Financial Corporation (COF)

Table of Contents

FDIC may jointly determine that a resolution plan is not credible or would not facilitate an orderly resolution under the U.S. Bankruptcy Code. If the Company were to fail to adequately address deficiencies jointly identified by the Federal Reserve and FDIC in a timely manner, it may be subject to more stringent capital, leverage, or liquidity requirements, or restrictions on growth, activities, or operations. In July 2024, the Federal Reserve and FDIC extended the deadline for the next full resolution submission from March 31, 2025 to October 1, 2025.

The Bank, as an insured depository institution, is required by FDIC regulation to submit its own resolution plan to the FDIC. In June 2024, the FDIC issued a final rule amending the resolution plan submission requirements applicable to insured depository institutions with $50 billion or more in total assets, including the Bank. Under the final rule, the Bank is required to submit to the FDIC full resolution plans every three years and interim targeted information between full resolution plan submissions. In addition, under the final rule, the Bank’s resolution plan submissions are subject to more detailed content requirements and a new credibility standard for the FDIC’s evaluation of resolution plans, which is enforceable against the Bank.

In addition, the OCC has issued enforceable guidelines requiring banks with assets of $100 billion or more, including the Bank, to develop recovery plans detailing the actions they would take to remain a going concern when they experience considerable financial or non-financial risks but have not deteriorated to the point that resolution is imminent.

Long-Term Debt and Clean Holding Company Proposal

In September 2023, the Federal Banking Agencies proposed a rule that would require banking organizations with $100 billion or more in total assets, including the Company, to comply with certain long-term debt requirements and so called “clean holding company” requirements that are designed to improve the resolvability of covered organizations (“LTD Proposal”). If adopted as proposed, the LTD Proposal would require the Company and the Bank to each maintain a minimum outstanding eligible long-term debt amount of no less than the greatest of (i) 6% of total risk-weighted assets, (ii) 2.5% of total leverage exposure and (iii) 3.5% of average total consolidated assets. To qualify as eligible long-term debt, a debt instrument would be required to meet the requirements currently applicable under the rules that apply to U.S. G-SIBs, as well as certain additional requirements. Additionally, the clean holding company requirements included in the LTD Proposal would limit or prohibit the Company from entering into certain transactions that could impede its orderly resolution. It is uncertain when or if a final rule will be adopted, and if so, whether and to what extent it will differ from the LTD Proposal. As a result, the timing and content of any final rule, and the potential effects of any final rule on the Company and the Bank, remain uncertain.

Source of Strength

The Federal Reserve’s Regulation Y requires a BHC to serve as a source of financial and managerial strength to its subsidiary banks (this is known as the “source of strength doctrine”). In addition, the Dodd-Frank Act requires a BHC to serve as a source of financial strength to its subsidiary banks and further requires the Federal Banking Agencies to jointly adopt rules implementing this requirement. The Federal Banking Agencies have yet to propose rules as required by the Dodd-Frank Act, but they may do so in the future.

FDIC Orderly Liquidation Authority

The Dodd-Frank Act provides the FDIC with liquidation authority that may be used to liquidate non-bank financial companies and BHCs if the Treasury Secretary, in consultation with the President of the United States and based on the recommendation of the Federal Reserve and other appropriate Federal Banking Agencies, determines that doing so is necessary, among other criteria, to mitigate serious adverse effects on U.S. financial stability. Upon such a determination, the FDIC would be appointed receiver and must liquidate a company in a way that mitigates significant risks to financial stability and minimizes moral hazard. The costs of a liquidation of a company would be borne by shareholders and unsecured creditors and then, if necessary, by risk-based assessments on large financial companies. The FDIC has issued rules implementing certain provisions of its liquidation authority.

FDIC Deposit Insurance Assessments

The Bank, as an insured depository institution, is a member of the Deposit Insurance Fund (“DIF”) maintained by the FDIC. Through the DIF, the FDIC insures the deposits of insured depository institutions up to prescribed limits for each depositor. The FDIC sets a Designated Reserve Ratio (“DRR”) for the DIF. To maintain the DIF, member institutions may be assessed an insurance premium, and the FDIC may take action to increase insurance premiums if the DRR falls below its required level.

13 Capital One Financial Corporation (COF)

Table of Contents

The FDIC, as required under the Federal Deposit Insurance Act, established a plan in September 2020, to restore the DIF reserve ratio to meet or exceed 1.35 percent within eight years. On October 18, 2022, the FDIC finalized a rule that increases the initial base deposit insurance assessment rate schedules by 2 basis points (“bps”) for all insured depository institutions to improve the likelihood that the DIF reserve ratio reaches 1.35 percent by the statutory deadline of September 30, 2028. The rule took effect in January 2023 and this increase was reflected in the Bank’s first quarterly assessment in 2023.

In November 2023, the FDIC finalized a rule to implement a special assessment to recover the loss to the DIF arising from the protection of uninsured depositors in connection with the systemic risk determination announced in March 2023, following the closures of Silicon Valley Bank and Signature Bank. In December 2023, the FDIC provided notification that it would be collecting the special assessment at an annual rate of approximately 13.4 bps over eight quarterly collection periods, beginning with the first quarter of 2024 with the first payment due on June 28, 2024. In June 2024, the FDIC provided notification that the collection period will be extended an additional two quarters beyond the initial eight quarterly collection periods, at a lower annual rate. The special assessment base is equal to an insured depository institution’s estimated uninsured deposits reported on its Consolidated Reports of Condition and Income as of December 31, 2022 (“2022 Call Report”), adjusted to exclude the first $5 billion of uninsured deposits. For additional information, see “Part II—Item 8.Financial Statements and Supplementary Data—Note 19—Commitments, Contingencies, Guarantees and Others.”

Investment in the Company and the Bank

Certain acquisitions of our capital stock may be subject to regulatory approval or notice under federal or state law. Investors are responsible for ensuring that they do not, directly or indirectly, acquire shares of our capital stock in excess of the amount that can be acquired without regulatory approval, including under the BHC Act and the Change in Bank Control Act (“CIBC Act”).

Federal law and regulations prohibit any person or company from acquiring control of the Company or the Bank without, in most cases, prior written approval of the Federal Reserve or the OCC, as applicable. Control under the BHC Act exists if, among other things, a person or company acquires more than 25% of any class of our voting stock or otherwise has a controlling influence over us. A rebuttable presumption of control arises under the CIBC Act for a publicly traded BHC such as ourselves if a person or company acquires more than 10% of any class of our voting stock.

Additionally, the Bank is a “bank” within the meaning of Chapter 7 of Title 6.2 of the Code of Virginia governing the acquisition of interests in Virginia financial institutions (“Virginia Financial Institution Holding Company Act”). The Virginia Financial Institution Holding Company Act prohibits any person or entity from acquiring, or making any public offer to acquire, control of a Virginia financial institution or its holding company without making application to, and receiving prior approval from, the Virginia Bureau of Financial Institutions.

Transactions with Affiliates

There are various legal restrictions on the extent to which we and our non-bank subsidiaries may borrow or otherwise engage in certain types of transactions with the Bank. Under the Federal Reserve Act and Federal Reserve regulations, the Bank and its subsidiaries are subject to quantitative and qualitative limits on extensions of credit, purchases of assets and certain other transactions involving non-bank affiliates. In addition, transactions between the Bank and its non-bank affiliates are required to be on arm’s length terms and must be consistent with standards of safety and soundness.

Volcker Rule

We and each of our subsidiaries, including the Bank, are subject to the “Volcker Rule,” a provision of the Dodd-Frank Act that contains prohibitions on proprietary trading and certain investments in, and relationships with, covered funds (hedge funds, private equity funds and similar funds), subject to certain exemptions, in each case as the applicable terms are defined in the Volcker Rule and the implementing regulations.

Regulation of Business Activities

The business activities of the Company and the Bank, as well as certain of the Company’s non-bank subsidiaries, are subject to regulation and supervision under various other laws and regulations.

14 Capital One Financial Corporation (COF)

Table of Contents

Regulation of Consumer Lending Activities

The activities of the Bank as a consumer lender are subject to regulation under various federal laws, including, for example, the Truth in Lending Act (“TILA”), the Equal Credit Opportunity Act, the Fair Credit Reporting Act (“FCRA”), the CRA, the Servicemembers Civil Relief Act and the Military Lending Act, as well as under various state laws. TILA, as amended, and together with its implementing rule, Regulation Z, imposes a number of restrictions on credit card practices impacting rates and fees, requires that a consumer’s ability to pay be taken into account before issuing credit or increasing credit limits, and imposes revised disclosures required for open-end credit.

In March 2024, the CFPB issued a final rule amending Regulation Z that, if it goes into effect as currently issued, would significantly lower the safe harbor amount for past due fees that large credit card issuers, including the Bank, can charge on consumer credit card accounts. The final rule is currently stayed as a result of ongoing litigation. Moreover, in October 2024, the CFPB issued a final rule that will require certain financial institutions, including the Company, to, among other things, share certain data on certain consumer financial products and services upon request of the consumer. For more information on risks related to these rules, see the risk factors set forth under “Item 1A. Risk Factors.”

Depending on the underlying issue and applicable law, regulators may be authorized to impose penalties for violations of these statutes and, in certain cases, to order banks to compensate customers. Borrowers may also have a private right of action for certain violations. Federal bankruptcy and state debtor relief and collection laws may also affect the ability of a bank, including the Bank, to collect outstanding balances owed by borrowers.

Debit Card Interchange Fees and Transaction Processing

As an issuer of credit and debit cards, the Bank earns interchange fees, which are paid by merchants, when customers use its cards. The Bank is subject to the Federal Reserve’s Regulation II, which limits the amount of interchange fees that can be charged per debit card transaction for debit card issuers with over $10 billion in assets and places certain prohibitions on payment routing restrictions and network exclusivity. The Federal Reserve has proposed, but not yet finalized, amendments to Regulation II that would lower the cap on debit interchange fees and institute a process for automatically recalculating the debit interchange fee cap every two years based upon a biennial survey of large debit card issuers.

Privacy, Data Protection and Data Security

We are, or may become, subject to a variety of continuously evolving and developing laws and regulations in the United States at the federal, state and local level regarding privacy, data protection and data security, including those related to the collection, storage, handling, use, disclosure, transfer, security and other processing of personal information. For example, at the federal level, we are currently subject to the Gramm-Leach-Bliley Act (“GLBA”) and the FCRA, among other laws and regulations, and may become subject to additional privacy, data protection and data security requirements as a result of future laws, rules or regulations. This includes, for instance, the Cyber Incident Reporting for Critical Infrastructure Act (“CIRCIA”), which, once rulemaking is complete, will require, among other things, certain companies to report significant cyber incidents to the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (“CISA”) within 72 hours from the time the company reasonably believes the incident occurred (and within 24 hours of making a ransom payment as a result of a ransomware attack). Moreover, legislative updates have been proposed in the U.S. Congress for more comprehensive privacy, data protection and data security legislation, to which we may be subject if passed. At the state level, California has enacted the California Consumer Privacy Act (as amended by the California Privacy Rights Act, collectively, the “CCPA”) and continues to issue regulations thereunder, and various other states also have enacted or are in the process of enacting state-level privacy, data protection and/or data security laws and regulations, with which we may be required to comply. Additionally, the Federal Banking Agencies, as well as related self‐regulatory organizations, have issued guidance regarding cybersecurity that is intended to enhance cyber risk management among financial institutions.

For more information on privacy, data protection and data security laws and regulations at the international level, please see “Regulation by Authorities Outside the United States.”

For further discussion of privacy, data protection and data security, and related risks for our business, see “Item 1A. Risk Factors” under the headings “We face risks related to our operational, technological and organizational infrastructure,” “A cyber-attack or other security incident on us or third parties (including their supply chains) with which we conduct business, including an incident that results in the theft, loss, manipulation or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in

15 Capital One Financial Corporation (COF)

Table of Contents

revenue, reputational damage, legal exposure and business disruptions,” and “Our required compliance with applicable laws and regulations related to privacy, data protection and data security, in addition to compliance with our own privacy policies and contractual obligations to third parties, may increase our costs, reduce our revenue, increase our legal exposure and limit our ability to pursue business opportunities.”

For further discussion of our cybersecurity risk management, see “Item 1C. Cybersecurity.”

Anti-Money Laundering, Combating the Financing of Terrorism and Economic Sanctions

The Bank Secrecy Act (“BSA”), as amended by the USA PATRIOT Act of 2001 (“Patriot Act”), and its implementing regulations require financial institutions to, among other things, implement a risk-based compliance program reasonably designed to prevent money laundering and to combat the financing of terrorism, including through suspicious activity and currency transaction reporting, the implementation of policies, procedures, and internal controls, record-keeping and customer due diligence.

The Patriot Act provides enhanced information collection tools and enforcement mechanisms to the U.S. government and expanded certain requirements for financial institutions, including due diligence and record-keeping requirements for private banking and correspondent accounts; standards for verifying customer identification at account opening; rules to produce certain records upon request of a regulator or law enforcement agency; and rules to promote cooperation among financial institutions, regulators and law enforcement agencies in identifying parties that may be involved in terrorism, money laundering and other crimes.

The Anti-Money Laundering Act of 2020 (“AML Act”), enacted as part of the National Defense Authorization Act, requires the U.S. Treasury Department’s Financial Crimes Enforcement Network (“FinCEN”) to issue a number of rules that will update and expand the BSA’s regulatory requirements. For example, the AML Act requires FinCEN to issue National Anti-Money Laundering and Countering the Financing of Terrorism Priorities (the “National Priorities”), which the agency did in June 2021, and to conduct studies and issue regulations that may alter some of the due diligence, record-keeping and reporting requirements that the BSA and Patriot Act impose on banks. FinCEN has yet to issue a final rule that establishes the compliance obligations of financial institutions with respect to the National Priorities, and several other mandatory rule makings under the AML Act remain outstanding. The AML Act also promotes increased information-sharing and use of technology and increases penalties for violations of the BSA and includes whistleblower incentives, both of which could increase the prospect of regulatory enforcement.

We are also required to comply with sanctions laws and regulations administered and imposed by the United States government, including the U.S. Treasury Department's Office of Foreign Assets Control (“OFAC”) and the Department of State, as well as comparable sanctions programs imposed by foreign governments and multilateral bodies. Sanctions can be either comprehensive or selective and use the blocking of assets and trade restrictions to accomplish foreign policy and national security goals.

Derivatives Activities

Title VII of the Dodd-Frank Act establishes a regulatory framework for the governance of the over-the-counter (“OTC”) derivatives market, including swaps and security-based swaps and requires the registration of certain market participants as swap dealers or security-based swap dealers. The Bank is registered with the Commodity Futures Trading Commission (“CFTC”) as a swap dealer. Registration as a swap dealer subjects the Bank to additional regulatory requirements with respect to its swaps and other derivatives activities. As a result of the Bank’s swap dealer registration, it is subject to the rules of the OCC concerning capital and margin requirements for swap dealers, including the mandatory exchange of variation margin and initial margin with certain counterparties. Additionally, as a registered swap dealer, the Bank is subject to requirements under the CFTC’s regulatory regime, including rules regarding business conduct standards, recordkeeping obligations, regulatory reporting and procedures relating to swaps trading. The Bank’s swaps and other derivatives activities do not require it to register with the SEC as a security-based swap dealer.

Broker-Dealer Activities

Certain of our non-bank subsidiaries are subject to regulation and supervision by various federal and state authorities. Capital One Securities, Inc., KippsDeSanto & Company and TripleTree, LLC are registered broker-dealers regulated by the SEC and the Financial Industry Regulatory Authority (“FINRA”). These broker-dealer subsidiaries are subject to, among other things, net capital rules designed to measure the general financial condition and liquidity of a broker-dealer. Under these rules, broker-

16 Capital One Financial Corporation (COF)

Table of Contents

dealers are required to maintain the minimum net capital deemed necessary to meet their continuing commitments to customers and others, and to keep a substantial portion of their assets in relatively liquid form. These rules also limit the ability of a broker-dealer to transfer capital to its parent companies and other affiliates. Broker-dealers are also subject to regulations covering their business operations, including sales and trading practices, public and private offerings, publication of research reports, use and safekeeping of client funds and securities, capital structure, record-keeping and the conduct of directors, officers and employees.

Climate-related Developments

Climate change and the risks it may pose to financial institutions is an area of increased focus by the federal and state legislative bodies and regulators, including the Federal Banking Agencies. In the future, new regulations or guidance may be issued, or other regulatory or supervisory actions may be taken, in this area by the Federal Banking Agencies or other regulatory agencies, or new statutory requirements may be adopted. For example, the Federal Banking Agencies have issued principles for climate-related financial risk management, which are designed to support the identification and management of climate-related financial risks at regulated institutions with more than $100 billion in total consolidated assets. For more information, please see “Item 1A. Risk Factors” under the heading “Climate change manifesting as physical or transition risks could adversely affect our businesses, operations and customers and result in increased costs.”

Regulation by Authorities Outside the United States

The Bank is subject to laws and regulations in foreign jurisdictions where it operates, primarily in the U.K. and Canada. In the U.K., the Bank operates through COEP, an authorized payment institution regulated by the Financial Conduct Authority (“FCA”). COEP’s parent, Capital One Global Corporation, is wholly owned by the Bank and is subject to regulation by the Federal Reserve as an “agreement corporation” under the Federal Reserve’s Regulation K. COEP does not take deposits. In Canada, the Bank operates as an authorized foreign bank and is permitted to conduct its credit card business in Canada through its Canadian branch, Capital One Bank (Canada Branch) (“Capital One Canada”). Capital One Canada does not take deposits. The primary regulators of Capital One Canada are the Office of the Superintendent of Financial Institutions (“OSFI”) and the Financial Consumer Agency of Canada (“FCAC”).

The foreign legal and regulatory requirements to which the Company’s non-U.S. operation are subject include, among others, those related to consumer protection, business practices and limits on interchange fees. For more information on foreign regulatory activity concerning interchange fees, please see “Item 1A. Risk Factors” under the heading “Our business, financial condition and results of operations may be adversely affected by legislation, regulation and merchants’ efforts to reduce the interchange fees charged by credit and debit card networks to facilitate card transactions.”

We also are, or may become, subject to continuously evolving and developing laws and regulations in other jurisdictions regarding privacy, data protection and data security. For example, in Canada we are subject to the Personal Information Protection and Electronic Documents Act (“PIPEDA”) as well as the provincial privacy laws, and may become subject to additional privacy, data protection and data security laws and regulations in Canada, including those which may differ from PIPEDA and the provincial privacy laws, if passed. We also are subject to the U.K. General Data Protection Regulation (“U.K. GDPR”). In addition, subject to limited exceptions, the European Union (“EU”) General Data Protection Regulation (“EU GDPR”) applies EU data protection laws to certain companies processing personal data of individuals in the European Economic Area, regardless of the company’s location. These laws and regulations, and similar laws and regulations in other jurisdictions, impose strict requirements regarding the collection, storage, handling, use, disclosure, transfer, security and other processing of personal information, which may have adverse consequences, including significant compliance costs and severe monetary penalties for non-compliance. Significant uncertainty exists as privacy, data protection, and data security laws and regulations may be interpreted and applied differently from country to country and may create inconsistent or conflicting requirements. For more information on privacy, data protection and data security requirements, please see “Privacy, Data Protection and Data Security.”

17 Capital One Financial Corporation (COF)

Table of Contents

HUMAN CAPITAL RESOURCES

Our human capital practices are designed to develop a collaborative work environment while rewarding employees based on the merit of their work. We prioritize employee recruitment, development, recognition and retention. As of December 31, 2024, Capital One had approximately 52,600 employees worldwide, whom we refer to as “associates.” The following disclosures provide information on our human capital resources, including certain human capital objectives and measures that we focus on in managing our business.

Governance of Human Capital

Our Board of Directors oversees our human capital management, including strategies, policies and practices, and diversity, inclusion and belonging (“DIB”), and is assisted by our Board’s Compensation Committee and Governance and Nominating Committee. Our Executive Committee, a committee of senior management which includes our Chief Human Resources Officer, advises, assists and makes recommendations to our Chief Executive Officer and Board of Directors on human capital matters such as human resource practices and programs, including general employee benefits and compensation programs.

Hiring, Developing, and Retaining

We employ a comprehensive people strategy that includes significant investments in recruiting and associate development in order to attract and retain top talent from all backgrounds. We recruit through a variety of channels, including professional partnerships, job fairs, online platforms, on-campus recruiting and diversity-related recruiting events and initiatives, among others. Investment in associate training and professional development is important to maintaining our talent competitiveness. Our internal enterprise learning and development team blends multiple approaches to learning to support associate development across lines of business, levels, and roles, including online and live classroom training. In addition to formal programming provided by learning professionals, including regulatory compliance, role-specific topics and others, our peer-to-peer learning strategy allows associates to be both learners and teachers, further enhancing a culture of learning. We also focus on cultivating talent with leadership development courses, cohort-based programs, network building and coaching.

On a quarterly basis, we review our ability to attract and retain talent. Each line of business and staff group reviews hiring, tenure and attrition metrics as part of this assessment, and they implement mitigation plans when needed.

At Capital One, we also value the diversity of our talent, and our employee programs are intended to support a culture of belonging. Our DIB strategy is developed and executed in close collaboration with leaders and teams across the organization. These efforts are overseen by the Chief Diversity & Inclusion Officer, and members of the Executive Committee sponsor Capital One’s Business Resource Groups, associate-led organizations that are open to everyone and enrich our culture of belonging and deepen our understanding of diversity across our associates.

Our corporate website contains additional information regarding employee programs and workforce composition, such as that reported to the U.S. Equal Employment Opportunity Commission on the mandatory EEO-1 report.

Compensation and Wellness

We appreciate the importance of a competitive total compensation package to attract and retain great talent. Our benefits, including competitive parental leave, on-site health centers, company contributions to associates’ 401(k) plans, educational assistance and other health, wellness, and financial benefits are designed to support our associates’ wellbeing inside and outside of the workplace. Furthermore, pay equity is an important element of our pay philosophy. We evaluate base pay and incentive pay for all of our associates globally, at least annually. We review groups of associates in similar roles, adjusting for factors that appropriately explain differences in pay such as job location and experience.

Communication and Connection

We communicate with our associates regularly to better understand their perspectives. To assess and improve associate retention and engagement, the Company surveys associates on a periodic basis with the assistance of third-party consultants and takes actions to address various areas of associate concern. We encourage full participation and use the results to effect change and promote transparency.

TECHNOLOGY AND INTELLECTUAL PROPERTY

18 Capital One Financial Corporation (COF)

Table of Contents

Technology/Systems

We leverage information and technology to achieve our business objectives and to develop and deliver products and services that satisfy our customers’ needs. A key part of our strategic focus is the development and use of efficient, flexible computer and operational systems, such as cloud technology, to support complex marketing and account management strategies, the servicing of our customers, and the development of new and diversified products. We believe that the continued development and integration of these systems is an important part of our efforts to reduce costs, improve quality and security and provide faster, more flexible technology services. Consequently, we frequently consider our capabilities and develop or acquire systems, processes and competencies to meet our unique business requirements.

As part of our frequent consideration of our technologies, we may either develop such capabilities internally or rely on third-party service providers who have the ability to deliver technology that is of higher quality, lower cost, or both. We continue to rely on third-party service providers to help us deliver systems and operational infrastructure. These relationships include, but are not limited to: Amazon Web Services, Inc. (“AWS”) for our cloud infrastructure, Total System Services LLC (“TSYS”) for consumer and commercial credit card processing services for our North American and U.K. portfolios and Fidelity Information Services (“FIS”) for certain of our banking systems.

We are committed to implementing safeguards designed to protect our customers’ information, as well as our own information and technology. For additional information on our risks associated with cybersecurity and our use of technology systems and our management of these risks, please see “Item 1A. Risk Factors” under the headings “A cyber-attack or other security incident on us or third parties (including their supply chains) with which we conduct business, including an incident that results in the theft, loss, manipulation or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions” and“We face risks related to our operational, technological and organizational infrastructure” and “Item 1C. Cybersecurity.”

Intellectual Property and Other Proprietary Information

As part of our overall and ongoing strategy to protect and enhance our intellectual property rights, we rely on a variety of protections, including copyrights, trademarks, trade secrets, patents and certain restrictions on disclosure, solicitation and competition. We also undertake other measures to control access to, or distribution of, our other proprietary and confidential information. Any patents we may obtain may increase our competitive advantage, protect our investments in commercializing our technology, preserve our freedom to operate, and allow us to enter into licensing (e.g., cross-licenses) or other arrangements with third parties. For a discussion of risks associated with intellectual property, see “Item 1A. Risk Factors” under the heading “If we are not able to protect our intellectual property rights, or we violate third-party intellectual property rights, our revenue and profitability could be negatively affected.”

19 Capital One Financial Corporation (COF)

Table of Contents

FORWARD-LOOKING STATEMENTS

From time to time, we have made and will make forward-looking statements, including those that discuss, among other things: strategies, goals, outlook or other non-historical matters; projections, revenues, income, returns, expenses, assets, liabilities, capital and liquidity measures, capital allocation plans, accruals for claims in litigation and for other claims against us; earnings per share, efficiency ratio, operating efficiency ratio or other financial measures for us; future financial and operating results; our plans, objectives, expectations and intentions; and the assumptions that underlie these matters.

To the extent that any such information is forward-looking, it is intended to fit within the safe harbor for forward-looking information provided by the Private Securities Litigation Reform Act of 1995.

Forward-looking statements often use words such as “will,” “anticipate,” “target,” “expect,” “think,” “estimate,” “intend,” “plan,” “goal,” “believe,” “forecast,” “outlook” or other words of similar meaning. Any forward-looking statements made by us or on our behalf speak only as of the date they are made or as of the date indicated, and we do not undertake any obligation to update forward-looking statements as a result of new information, future events or otherwise. For additional information on factors that could materially influence forward-looking statements included in this Report, see the risk factors set forth under “Item 1A. Risk Factors.” You should carefully consider the factors discussed below, and in our Risk Factors or other disclosures, in evaluating these forward-looking statements.

Numerous factors could cause our actual results to differ materially from those described in such forward-looking statements, including, among other things:

•risks relating to the pending Transaction, including the risk that the cost savings and any revenue synergies and other anticipated benefits from the Transaction may not be fully realized or may take longer than anticipated to be realized; disruption to our business and to Discover’s business as a result of the announcement and pendency of the Transaction; the risk that the integration of Discover’s business and operations into ours, including into our compliance management program, will be materially delayed or will be more costly or difficult than expected, or that we are otherwise unable to successfully integrate Discover’s business into ours, including as a result of unexpected factors or events; the possibility that the requisite regulatory approvals are not received or other conditions to the closing are not satisfied on a timely basis or at all, or are obtained subject to conditions that are not anticipated (and the risk that requisite regulatory approvals may result in the imposition of conditions that could adversely affect us or the expected benefits of the Transaction following the closing of the Transaction); reputational risk and the reaction of customers, suppliers, employees or other business partners of ours or of Discover to the Transaction; the failure of the closing conditions in the Merger Agreement to be satisfied, or any unexpected delay in completing the Transaction or the occurrence of any event, change or other circumstances that could give rise to the termination of the Merger Agreement; the dilution caused by our issuance of additional shares of our common stock in connection with the Transaction; the possibility that the Transaction may be more expensive to complete than anticipated, including as a result of unexpected factors or events; risks related to management and oversight of our expanded business and operations following the Transaction due to the increased size and complexity of our business; the possibility of increased scrutiny by, and/or additional regulatory requirements of, governmental authorities as a result of the Transaction or the size, scope and complexity of our business operations following the Transaction; the outcome of any legal or regulatory proceedings that may be currently pending or later instituted against us (before or after the Transaction) or against Discover; the risk that expectations regarding the timing, completion and accounting and tax treatments of the Transaction are not met; the risk that any announcements relating to the Transaction could have adverse effects on the market price of our common stock; certain restrictions during the pendency of the Transaction; the diversion of management’s attention from ongoing business operations and opportunities; the risk that revenues following the Transaction may be lower than expected and/or the risk that certain expenses, such as the provision for credit losses, of Discover or the surviving entity may be greater than expected; our and Discover’s success in executing their respective business plans and strategies and managing the risks involved in the foregoing; effects of the announcement, pendency or completion of the Transaction on our or Discover’s ability to retain customers and retain and hire key personnel and maintain relationships with our and Discover’s suppliers and other business partners, and on our and Discover’s operating results and businesses generally; and other factors that may affect our future results or the future results of Discover;

20 Capital One Financial Corporation (COF)

Table of Contents

•changes and instability in the macroeconomic environment, resulting from factors that include, but are not limited to monetary and fiscal policy actions, geopolitical conflicts or instability, such as the war between Ukraine and Russia and the conflict in the Middle East, labor shortages, government shutdowns, inflation and deflation, potential recessions, technology-driven disruption of certain industries, lower demand for credit, changes in deposit practices and payment patterns;

•increases in credit losses and delinquencies and the impact of incorrectly estimated expected losses, which could result in inadequate reserves;

•compliance with new and existing domestic and foreign laws, regulations and regulatory expectations, which may change over time including as a result of the political and policy goals of elected officials;

•limitations on our ability to receive dividends from our subsidiaries;

•our ability to maintain adequate capital or liquidity levels or to comply with revised capital or liquidity requirements, which could have a negative impact on our financial results and our ability to return capital to our stockholders;

•the use, reliability, and accuracy of the models, artificial intelligence, and data on which we rely;

•our ability to manage fraudulent activity risks;

•increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions that can result from a cyber-attack or other security incident on us or third parties (including their supply chains) with which we conduct business, including an incident that results in the theft, loss, manipulation or misuse of information, or the disabling of systems and access to information critical to business operations;

•developments, changes or actions relating to any litigation, governmental investigation or regulatory enforcement action or matter involving us;

•the amount and rate of deposit growth and changes in deposit costs;

•our ability to execute on our strategic initiatives and operational plans;

•our response to competitive pressures;

•legislation, regulation and merchants’ efforts to reduce the interchange fees charged by credit and debit card networks to facilitate card transactions, and by legislation and regulation impacting such fees;

•our success in integrating acquired businesses and loan portfolios, and our ability to realize anticipated benefits from announced transactions and strategic partnerships;

•our ability to develop, operate, and adapt our operational, technology and organizational infrastructure suitable for the nature of our business;

•the success of our marketing efforts in attracting and retaining customers;

•our risk management strategies;

•changes in the reputation of, or expectations regarding, us or the financial services industry with respect to practices, products, services or financial condition;

•fluctuations in interest rates;

•our ability to maintain adequate sources of funding and liquidity to operate our business;

•our ability to attract, develop, retain and motivate key senior leaders and skilled employees;

•climate change manifesting as physical or transition risks;

•our assumptions or estimates in our financial statements;

21 Capital One Financial Corporation (COF)

Table of Contents

•the soundness of other financial institutions and other third parties, actual or perceived;

•our ability to invest successfully in and introduce digital and other technological developments across all our businesses;

•a downgrade in our credit ratings;

•our ability to manage risks from catastrophic events;

•compliance with applicable laws and regulations related to privacy, data protection and data security, in addition to compliance with our own privacy policies and contractual obligations to third parties;

•our ability to protect our intellectual property rights; and

•other risk factors identified from time to time in our public disclosures, including in the reports that we file with the SEC.

Item 1A. Risk Factors

The following discussion sets forth what management currently believes could be the material risks and uncertainties that could impact our businesses, results of operations and financial condition. The events and consequences discussed in these risk factors could, in circumstances we may not be able to accurately predict, recognize, or control, have a material adverse effect on our business, growth, reputation, prospects, financial condition, operating results, cash flows, liquidity, and stock price. These risk factors do not identify all risks that we face; our operations could also be affected by factors, events, or uncertainties that are not presently known to us or that we currently do not consider to present significant risks to our operations. In addition, the global economic and political climate may amplify many of these risks.

Summary of Risk Factors

The following is a summary of the Risk Factors disclosure in this Item 1A. This summary does not address all of the risks that we face. Additional discussion of the risks summarized in this risk factor summary, and other risks that we face, can be found below and should be carefully considered, together with other information in this Form 10-K and our other filings with the SEC, before making an investment decision regarding our securities.

•The consummation of the Transaction is contingent upon the satisfaction of a number of conditions, including regulatory approvals, that may be outside either party’s control and that either party may be unable to satisfy or obtain or which may delay the consummation of the Transaction or result in the imposition of conditions that could reduce the anticipated benefits from the Transaction or cause the parties to abandon the Transaction.

•We expect to incur substantial expenses related to the Transaction and to the integration of Discover, and the expenses may be greater than anticipated due to unexpected events.

•We may fail to realize all of the anticipated benefits of the Transaction, or those benefits may take longer to realize than expected due to factors that may be outside our control or Discover’s control. We may also encounter significant difficulties in integrating Discover.

•Our future results may suffer if we do not effectively manage our expanded operations following the Transaction.

•While the Transaction is pending, we will be subject to business uncertainties and contractual restrictions that could adversely affect our business and operations.

•Changes and instability in the macroeconomic environment could disrupt capital markets, reduce consumer and business activity, and weaken the labor market, all of which could impact borrowers’ ability to service their debt obligations and adversely impact our financial results.

•Fluctuations in interest rates could adversely affect our business, results of operations and financial condition.

•We may not be able to maintain adequate sources of funding and liquidity to operate our business.

22 Capital One Financial Corporation (COF)

Table of Contents

•We may experience increases in delinquencies and credit losses, or we may incorrectly estimate expected losses, which could result in inadequate reserves.

•We may not be able to maintain adequate capital or liquidity levels or may become subject to revised capital or liquidity requirements, which could have a negative impact on our financial results and our ability to return capital to our stockholders.

•Limitations on our ability to receive dividends from our subsidiaries could affect our liquidity and ability to pay dividends and repurchase our common stock.

•A downgrade in our credit ratings could significantly impact our liquidity, funding costs and access to the capital markets.

•We face risks related to our operational, technological and organizational infrastructure.

•A cyber-attack or other security incident on us or third parties (including their supply chains) with which we conduct business, including an incident that results in the theft, loss, manipulation or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions.

•We face risks resulting from the extensive use of models and data, as well as from our evolving use of AI.

•Fraudulent activity associated with our products could cause our fraud losses to increase, the use of our products to decrease and our brands to suffer reputational damage, all of which could have a material adverse effect on our business.

•Compliance with new and existing domestic and foreign laws, regulations and regulatory expectations is costly and complex, and any significant changes may adversely affect our business.

•Our required compliance with applicable laws and regulations related to privacy, data protection and data security, in addition to compliance with our own privacy policies and contractual obligations to third parties, may increase our costs, reduce our revenue, increase our legal exposure and limit our ability to pursue business opportunities.

•Our businesses are subject to the risk of increased litigation, government investigations and regulatory enforcement.

•We face intense competition in all of our markets, which could have a material adverse effect on our business and results of operations.

•Our business, financial condition and results of operations may be adversely affected by legislation, regulation and merchants’ efforts to reduce the interchange fees charged by credit and debit card networks to facilitate card transactions.

•If we are not able to invest successfully in and introduce digital and other technological developments across all our businesses, our financial performance may suffer.

•We may fail to realize the anticipated benefits of our mergers, acquisitions and strategic partnerships.

•Reputational risk and social factors may impact our results and damage our brand.

•If we are not able to protect our intellectual property rights, or we violate third-party intellectual property rights, our revenue and profitability could be negatively affected.

•Our risk management strategies may not be fully effective in mitigating our risk exposures in all market environments or against all types of risk.

•Our business could be negatively affected if we are unable to attract, develop, retain and motivate key senior leaders and skilled employees.

•We face risks from catastrophic events.

•Climate change manifesting as physical or transition risks could adversely affect our businesses, operations and customers and result in increased costs.

23 Capital One Financial Corporation (COF)

Table of Contents

•We face risks from the use of or changes to assumptions or estimates in our financial statements.

•The soundness of other financial institutions and other third parties, actual or perceived, could adversely affect us.

Risks Relating to the Acquisition of Discover

We have identified certain additional risk factors in connection with the Merger Agreement and the proposed Transaction. For additional information concerning these risks, uncertainties and assumptions, please refer to the section entitled “Risk Factors” included in our joint proxy statement/prospectus included in the registration statement declared effective by the SEC on January 6, 2025.

The consummation of the Transaction is contingent upon the satisfaction of a number of conditions, including regulatory approvals, that may be outside either party’s control and that either party may be unable to satisfy or obtain or which may delay the consummation of the Transaction or result in the imposition of conditions that could reduce the anticipated benefits from the Transaction or cause the parties to abandon the Transaction.

Consummation of the Transaction is contingent upon the satisfaction of a number of conditions, some of which are beyond either party's control, including, the receipt of the requisite regulatory approvals and the absence of any order, injunction, decree or other legal restraint preventing the completion of the Transaction.

Each party’s obligation to complete the Transaction is also subject to certain additional customary conditions, including:

•subject to certain exceptions, the accuracy of the representations and warranties of the other party;

•performance in all material respects by the other party of its obligations under the Merger Agreement; and

•receipt by such party of an opinion from its counsel to the effect that the Merger and the Second Step Merger, taken together, will qualify as a reorganization within the meaning of Section 368(a) of the Internal Revenue Code of 1986, as amended.

These conditions to the closing of the Transaction may not be fulfilled in a timely manner, or at all, and, accordingly, the Transaction may not be completed. In addition, the parties can mutually decide to terminate the Merger Agreement at any time, or either party may elect to terminate the Merger Agreement in certain other circumstances.

As a condition to granting required regulatory approvals, governmental entities may impose conditions, limitations, obligations or costs or place restrictions on our conduct after the closing of the Transaction. Such conditions or changes and the process of obtaining regulatory approvals could, among other things, have the effect of delaying completion of the Transaction or of imposing additional costs or limitations on us following the Transaction, any of which may have an adverse effect on us.

Either party may also be subject to lawsuits challenging the Transaction, and adverse rulings in these lawsuits may delay or prevent the Transaction from being completed or require either party to incur significant costs to defend or settle these lawsuits. Any delay in completing the Transaction could cause us not to realize, or to be delayed in realizing, some or all of the benefits that we expect to achieve if the Transaction is successfully completed within its expected time frame.

We expect to incur substantial expenses related to the Transaction and to the integration of Discover, and the expenses may be greater than anticipated due to unexpected events.

We have incurred and expect to incur a number of significant non-recurring costs associated with the Transaction and the integration of Discover. These costs include legal, financial advisory, accounting, consulting and other advisory fees, severance/employee benefit‐related costs, public company filing fees and other regulatory fees, financial printing and other printing costs and other related costs. In addition, we will incur integration costs following the completion of the Transaction as we integrate Discover’s business with ours, including facilities and systems consolidation costs and employment-related costs. There are a large number of processes, policies, procedures, operations, technologies and systems that may need to be integrated, including purchasing, accounting and finance, payroll, compliance, treasury management, branch operations, vendor management, risk management, lines of business, pricing and benefits.

While we have assumed that a certain level of costs will be incurred, there are many factors beyond our control that could affect the total amount or the timing of these expenses. Moreover, many of the expenses that we will incur are, by their nature, difficult to estimate accurately. These expenses could, particularly in the near term, exceed the savings that we expect to

24 Capital One Financial Corporation (COF)

Table of Contents

achieve from the elimination of duplicative expenses and the realization of economies of scale. These expenses may result in us recording increased expenses as a result of the Transaction or the integration of Discover, and the amount and timing of such charges are uncertain at the present and could exceed initial estimates.

We may fail to realize all of the anticipated benefits of the Transaction, or those benefits may take longer to realize than expected due to factors that may be outside our control or Discover’s control. We may also encounter significant difficulties in integrating Discover.

We may fail to realize the anticipated benefits of the proposed Transaction, including, among other things, anticipated revenue and cost synergies, due to factors that may be outside either party’s control. These factors include, but are not limited to, changes in laws or regulations or the implementation or interpretation of laws or regulation due to changes in government or general economic, political, legislative or regulatory conditions. For example, debit card transactions on three-party networks—comprising the cardholder, merchant and network provider—could become subject to the Federal Reserve’s Regulation II limitation on interchange fees or its prohibition on network exclusivity, and other changes in laws or regulation could impose additional limitations on the fees issuers or networks can charge on debit or credit card transactions or require merchants to be provided an alternative network for transaction routing, any of which may have an adverse effect on our business. Other factors that may impact our ability to achieve the anticipated benefits of the proposed Transaction include the outcome of any legal or regulatory proceedings that may be currently pending or later instituted against us (before or after completion of the Transaction) or against Discover, including those related to Discover’s card product misclassification issue. As a result of the Transaction, we will be the legal successor to Discover and as a result we will assume the risks relating to actions that may be currently pending or later instituted against Discover, as well as any ongoing expense in defending and resolving these actions, and may be subject to reputational and other risks associated with Discover’s actions.

Both parties have operated and, until the completion of the Transaction, will continue to operate, independently. The success of the Transaction, including anticipated benefits and cost savings, will depend, in part, on our ability to successfully integrate Discover’s operations in a manner that results in various benefits and that does not materially disrupt existing customer relationships or materially decrease revenues due to loss of customers, as well as our ability to successfully integrate Discover into our Framework, compliance systems and corporate culture, which we believe will require extensive investment, including to enhance the risk management function at Discover consistent with our risk management standards and those of regulators, as well as to address remediation obligations under existing and possible future regulatory orders. The costs of these investments may be greater than anticipated and the benefits thereof may take longer than expected to realize. The process of integrating operations could result in a loss of key personnel or cause an interruption of, or loss of momentum in, the activities of one or more of our businesses following the completion of the Transaction. Inconsistencies in standards, controls, procedures and policies between us and Discover could adversely affect us following the completion of the Transaction. The diversion of management’s attention and any delays or difficulties encountered in connection with the Transaction and the integration of Discover’s operations could have an adverse effect on our business, financial condition, operating results and prospects.

An inability to realize the full extent of the anticipated benefits of Transaction, as well as any delays encountered in the integration process, could have an adverse effect on our revenues, levels of expenses and operating results following the completion of the Transaction.

Our future results may suffer if we do not effectively manage our expanded operations following the Transaction.

Following the Transaction, the size and scope of our business will increase significantly beyond our current size and scope. Our future success depends, in part, upon the ability to manage our expanded businesses, which will pose substantial challenges for management, including challenges related to the management and monitoring of new operations and associated increased costs and complexity. There can be no assurances we will be successful or that we will realize the expected operating efficiencies, cost savings and other benefits currently anticipated from the Transaction.

In addition, following the Transaction, we may be subject to increased scrutiny by, and/or additional regulatory requirements of, governmental authorities as a result of the Transaction or the size, scope and complexity of our business operations, which may have an adverse effect on our business, operations or stock price.

While the Transaction is pending, we will be subject to business uncertainties and contractual restrictions that could adversely affect our business and operations.

25 Capital One Financial Corporation (COF)

Table of Contents

Uncertainty about the effect of the Transaction on employees, customers, suppliers and other persons with whom we or Discover have a business relationship may have an adverse effect on our business, operations and stock price. Existing customers, suppliers and other business partners of ours and of Discover could decide to no longer do business with us or with Discover before the completion of the Transaction or with us after the Transaction is completed, reducing its anticipated benefits. Both parties are also subject to certain restrictions on the conduct of our respective businesses while the Transaction is pending. As a result, certain projects may be delayed or abandoned and business decisions could be deferred. Employee retention may be challenging for Discover before completion of the Transaction, as certain employees of Discover may experience uncertainty about their future roles with us following the Transaction, and these retention challenges will require us to incur additional expenses in order to retain key employees of Discover. If key employees of Discover depart because of issues relating to the uncertainty and difficulty of integration or a desire not to remain with Discover or with us following the Transaction, the benefits of the Transaction could be materially diminished.

General Economic and Market Risks

Changes and instability in the macroeconomic environment could disrupt capital markets, reduce consumer and business activity, and weaken the labor market, all of which could impact borrowers’ ability to service their debt obligations and adversely impact our financial results.

Changes or instability in the macroeconomic environment may impact payment patterns, consumer spending, and credit losses. Because we offer a broad array of financial products and services to consumers, small businesses and commercial clients, our financial results are impacted by the level of consumer and business activity and the demand for our products and services. A prolonged period of economic weakness, volatility, slow growth, or a significant deterioration in economic conditions, in the countries in which we operate, could have a material adverse effect on our financial condition and results of operations as customers or commercial clients default on their loans, maintain lower deposit levels or, in the case of credit card accounts, carry lower balances and reduce credit card purchase activity.

Some of the factors that could disrupt capital markets, reduce consumer and business activity, and weaken the labor market include the following:

•Monetary policy actions, such as changes to interest rates, taken by the Federal Reserve and other central banks, such as the central banks in the United Kingdom and Canada, and a growing fiscal deficit and increase in the U.S. debt to gross domestic product ratio;

•Fiscal policy actions, such as changes to applicable tax codes;

•Geopolitical conflicts or instabilities, such as the war between Ukraine and Russia and the conflict in the Middle East, and increased geopolitical tensions between the U.S. and China;

•Trade wars, tariffs, labor shortages and disruptions of global supply chains;

•The effects of stalemates in the U.S. government, including government shutdowns whether recurring, prolonged or otherwise, developments related to the U.S. federal debt ceiling, default by the U.S. government on its debt obligations, or related credit-rating downgrades;

•Inflation and deflation, including the effects of related governmental responses;

•Concerns over a potential recession, which may lead to adjustments in spending patterns;

•Technology-driven disruption of certain industries, such as those due to advances in AI, robotics and cryptocurrency;

•Lower demand for credit and shifts in consumer behavior, including shifts away from using credit cards, changes in deposit practices, and changes in payment patterns; and

•Changes in usage of commercial real estate, which may have a sustained negative impact on utilization rates and values.

Decreases in overall business activity and changes in customer behavior may lead to increases in our charge-off rate caused by bankruptcies and may reduce our ability to recover debt that we have previously charged-off. Such changes may also decrease the reliability of our internal processes and models, including those we use to estimate our allowance for credit losses,

26 Capital One Financial Corporation (COF)

Table of Contents

particularly if unexpected variations in key inputs and assumptions cause actual losses to diverge from the projections of our models and our estimates become increasingly subject to management’s judgment. See “We face risks resulting from the extensive use of models and data, as well as our evolving use of AI.”

Fluctuations in interest rates could adversely affect our business, results of operations and financial condition.

Like other financial institutions, our business is sensitive to interest rate movements. Changes in interest rates could adversely affect the results of our operations and financial condition. For example, higher interest rates may increase our borrowing costs and may require us to increase the interest we pay on funds deposited with us and may reduce the market value of our securities holdings. If interest rates increase or if higher interest rates persist for an extended period of time, our expenses may increase further. On the other hand, lower interest rates could also adversely affect our business, results of operations and financial condition. If the rate of economic growth decreased sharply, causing the Federal Reserve to lower interest rates, our net income could be adversely affected. While higher interest rates generally enhance our ability to grow our net interest income, there are potential risks associated with operating in a higher interest rate environment. For example, some customers have been and may continue to be less willing or able overall to borrow at higher interest rates. Higher interest rates also have hindered and may continue to hinder the ability of some borrowers to support required loan payments.

Additionally, interest rate fluctuations and competitor responses to those changes may have a material adverse effect on our financial condition and results of operations, as customers or commercial clients default on their loans, maintain lower deposit levels or, in the case of credit card accounts, reduce demand for credit or (for existing customers) the level of borrowing or purchase activity. For example, increases in interest rates increase debt service requirements for some of our borrowers, which may adversely affect those borrowers’ ability to pay as contractually obligated. This could result in additional or fluctuating delinquencies or charge-offs and negatively impact our results of operations. These changes could reduce the overall yield on our interest-earning asset portfolio.

We assess our interest rate risk by estimating the effect on our net interest income and earnings, economic value and capital under various interest rate scenarios of different direction and magnitude. We take risk mitigation actions based on those assessments. For example, the Company employs various hedging strategies to mitigate the interest rate, foreign exchange, and market risks inherent in many of our assets and liabilities. The Company’s hedging strategies rely considerably on assumptions and projections regarding our assets and liabilities as well as general market factors. If any of these assumptions or projections prove to be incorrect or our hedges do not adequately mitigate the impact of changes in interest rates, foreign exchange rates, and other market factors, the Company may experience volatility in our earnings that could adversely affect our profitability and financial condition. We face the risk that changes in interest rates could materially reduce our net interest income and our earnings, especially if actual conditions turn out to be materially different than those we assumed.

Changes in valuations in the debt and equity markets could have a negative impact on the assets we hold in our investment portfolio. Such market changes could also have a negative impact on the valuation of assets for which we provide servicing. See “Part II—Item 7. MD&A—Market Risk Profile” and “We face intense competition in all of our markets, which could have a material adverse effect on our business and results of operation” for additional information.

We may not be able to maintain adequate sources of funding and liquidity to operate our business.

We may not be able to maintain adequate sources of funding and liquidity to fund our operations, grow our business, pay our outstanding liabilities and meet regulatory expectations. Our ability to borrow from other financial institutions or to engage in funding transactions on favorable terms or at all could be adversely affected by factors outside of our control, including disruptions, uncertainty or volatility in the capital markets. Additionally, increased charge-offs, rising interest rates, increased refinancing activity and other events may cause our securitization transactions to amortize earlier than scheduled or reduce the value of the securities that we hold for liquidity purposes, which could accelerate our need for additional funding from other sources. We could also experience impairments of other financial assets and other negative impacts on our financial position, including possible constraints on liquidity and capital, as well as higher costs of capital.

In addition, our access to funding sources in amounts adequate to finance our activities on terms that are acceptable to us could be impaired by factors that affect us specifically or the financial services industry or economy generally. Factors that could detrimentally impact our access to liquidity sources include increases in funding costs, downturns in the geographic markets in which our loans and operations are concentrated, difficulties in credit markets or unforeseen outflows of cash or collateral, including as a result of unusual effects in the market.

27 Capital One Financial Corporation (COF)

Table of Contents

Our ability to fund our business and our liquidity position also depend on our ability to attract or maintain deposits. Many other financial institutions have increased their reliance on deposit funding and, as such, we expect continued competition in the deposit markets. We cannot predict how this competition will affect our costs. If we are required to offer higher interest rates to attract or maintain deposits, our funding costs will be adversely impacted. Although we have historically been able to meet the liquidity needs of customers as necessary, the ability to do so is not assured, especially if a large number of our depositors seek to withdraw their accounts or if our customers seek significant draws on their credit lines, regardless of the reason. A failure to maintain adequate liquidity could materially and adversely affect our business, results of operations and financial condition.

Credit Risk

We may experience increases in delinquencies and credit losses, or we may incorrectly estimate expected losses, which could result in inadequate reserves.

Like other lenders, we face the risk that our customers will not repay their loans. A customer’s ability and willingness to repay us can be adversely affected by decreases in the income of the borrower or increases in their payment obligations to other lenders, whether as a result of a job loss, higher debt levels or rising cost of servicing debt, inflation outpacing wage growth, or by restricted availability of credit generally. We may fail to quickly identify and reduce our exposure to customers that are likely to default on their payment obligations, whether by closing credit lines or restricting authorizations. Our ability to manage credit risk also is affected by legal or regulatory changes (such as restrictions on collections, bankruptcy laws, minimum payment regulations and re-age guidance), competitors’ actions and consumer behavior, and depends on the effectiveness of our collections staff, techniques and models.

Rising credit losses or leading indicators of rising credit losses (such as higher delinquencies, higher rates of nonperforming loans, higher bankruptcy rates, lower collateral values, elevated unemployment rates or changing market terms) may require us to increase our allowance for credit losses, which would decrease our profitability if we are unable to raise revenue or reduce costs to compensate for higher credit losses, whether actual or expected. In particular, we face the following risks in this area:

•Missed Payments: Our customers may fail to make required payments on time and may default or become delinquent. Loan charge-offs (including from bankruptcies) are generally preceded by missed payments or other indications of worsening financial conditions for our customers. Historically, customers are more likely to miss payments during an economic downturn, recession, periods of high unemployment, or prolonged periods of slow economic growth. Customers might also be more likely to miss payments if the payment burdens on their existing debt grow due to higher interest rates, or if inflation outpaces wage growth. Additionally, the CFPB has, among other things, issued a final rule amending Regulation Z that, if it goes into effect as currently issued, would significantly lower the safe harbor amount for past due fees that a large credit card issuer, such as the Bank, can charge on consumer credit card accounts, which could result in changes in consumer repayment patterns.

•Incorrect Estimates of Expected Credit Losses: The credit quality of our loan portfolios can have a significant impact on our earnings. We allow for and reserve against credit risks based on our assessment of expected credit losses in our loan portfolios. This process, which is critical to our financial condition and results of operations, requires complex judgments, including forecasts of economic conditions. We may underestimate our expected credit losses and fail to hold an allowance for credit losses sufficient to account for these credit losses. Incorrect assumptions could lead to material underestimations of expected credit losses and an inadequate allowance for credit losses. See “We face risks resulting from the extensive use of models and data, as well as our evolving use of AI.”

•Inaccurate Underwriting: Our ability to accurately assess the creditworthiness of our customers may diminish, which could result in an increase in our credit losses and a deterioration of our returns. See “Our risk management strategies may not be fully effective in mitigating our risk exposures in all market environments or against all types of risk.”

•Business Mix: We engage in a diverse mix of businesses with a broad range of potential credit exposure. Because we originate a relatively greater proportion of consumer loans in our loan portfolio compared to other large bank peers and originate both prime and subprime credit card accounts and auto loans, we may experience higher delinquencies and a greater number of accounts charging off, as well as greater fluctuations in those metrics, compared to other large bank peers, which could result in increased credit losses, operating costs and regulatory scrutiny. Additionally, a change in this business mix over time to include proportionally more consumer loans or subprime credit card accounts or auto loans could adversely affect the credit quality of our loan portfolios.

28 Capital One Financial Corporation (COF)

Table of Contents

•Increasing Charge-off Recognition/Allowance for Credit Losses: We account for the allowance for credit losses according to accounting and regulatory guidelines and rules, including Financial Accounting Standards Board (“FASB”) standards and the Federal Financial Institutions Examination Council (“FFIEC”) Account Management Guidance. We measure our allowance for credit losses under the CECL standard, which is based on management’s best estimate of expected lifetime credit losses. The impact of measuring our allowance for credit losses on our results will depend on the characteristics of our financial instruments, economic conditions, and our economic and loss forecasts. The application of the CECL standard may require us to increase reserves faster and to a higher level in an economic downturn, resulting in greater adverse impact to our results and our capital ratios than we would have experienced in similar circumstances prior to the adoption of CECL. Due to our business mix and the impact of credit losses on our income statement as compared to many of our large bank peers, we could be disproportionately affected by use of the CECL standard.

•Insufficient Asset Values: The collateral we have on secured loans could be insufficient to compensate us for credit losses. When customers default on their secured loans, we attempt to recover collateral where permissible and appropriate. However, the value of the collateral may not be sufficient to compensate us for the amount of the unpaid loan, and we may be unsuccessful in recovering the remaining balance from our customers. Decreases in real estate and other asset values adversely affect the collateral value for our commercial lending activities, while the auto business is similarly exposed to collateral risks arising from the auction markets that determine used car prices. Borrowers may be less likely to continue making payments on loans if the value of the property used as collateral for the loan is less than what the borrower owes, even if the borrower is still financially able to make the payments. In that circumstance, the recovery of such property could be insufficient to compensate us for the value of these loans upon a default. For example, high vacancy rates in commercial properties may affect the value of commercial real estate, including by causing the value of properties securing commercial real estate loans to be less than the amounts owed on such loans. In our auto business, business and economic conditions that negatively affect household incomes and savings, housing prices and consumer behavior, as well as technological advances that make older cars obsolete faster, could decrease (i) the demand for new and/or used vehicles and (ii) the value of the collateral underlying our portfolio of auto loans, which could cause the number of consumers who become delinquent or default on their loans to increase.

•Geographic and Industry Concentration: Although our consumer lending is geographically diversified, approximately 38.1% of our commercial real estate loan portfolio is concentrated in the Northeast region. The regional economic conditions in the Northeast affect the demand for our commercial products and services as well as the ability of our customers to repay their commercial real estate loans and the value of the collateral securing these loans. An economic downturn or prolonged period of slow economic growth in, or a catastrophic event or natural disaster that disproportionately affects the Northeast region could have a material adverse effect on the performance of our commercial real estate loan portfolio and our results of operations. In addition, our Commercial Banking strategy includes an industry-specific focus. If any of the industries that we focus on experience changes, we may experience increased credit losses and our results of operations could be adversely impacted.

Capital and Liquidity Risk

We may not be able to maintain adequate capital or liquidity levels or may become subject to revised capital or liquidity requirements, which could have a negative impact on our financial results and our ability to return capital to our stockholders.

Financial institutions are subject to extensive and complex capital and liquidity requirements, which are subject to change. These requirements affect our ability to lend, grow deposit balances, make acquisitions and distribute capital. Failure to maintain adequate capital or liquidity levels, whether due to adverse developments in our business or the economy or to changes in the applicable requirements, could subject us to a variety of restrictions and/or remedial actions imposed by our regulators. These include limitations on the ability to pay dividends or repurchase shares and the issuance of a capital directive to increase capital. Such limitations or capital directive could have a material adverse effect on our business and results of operations. For example, changes to applicable capital, liquidity, or other regulations, such as the changes proposed in the Basel III Finalization Proposal and the LTD Proposal, could result in increased regulatory capital requirements, operating expenses or cost of funding, which could negatively affect our financial results or our ability to distribute capital.

We consider various factors in the management of capital, including the impact of both internal and supervisory stress scenarios on our capital levels as determined by our internal modeling and the Federal Reserve’s estimation of losses in supervisory stress

29 Capital One Financial Corporation (COF)

Table of Contents

scenarios that are used to annually set our stress capital buffer requirement. There can be significant differences between our modeling and the Federal Reserve’s projections for a given supervisory stress scenario and between the capital needs suggested by our internal stress scenarios and the supervisory stress scenarios. Therefore, although our estimated capital levels under stress disclosed as part of the stress testing processes may suggest that we have a particular capacity to return capital to stockholders and remain well capitalized under stress, the Federal Reserve’s modeling, our internal modeling of another scenario or other factors related to our capital management process may reflect a lower capacity to return capital to stockholders than that indicated by the projections released in the stress testing processes. This, in turn, could lead to restrictions on our ability to pay dividends and engage in repurchases of our common stock. See “Item 1. Business—Supervision and Regulation” for additional information.

We also consider various factors in the management of liquidity, including maintaining sufficient liquid assets to meet the requirements of several internal and regulatory stress tests. Regulatory liquidity stress testing, regulatory liquidity requirements, and internal stress tests may, therefore, require us to take actions to increase our liquid assets or alter our activities or funding sources, which could negatively affect our financial results or our ability to return capital to our stockholders. See “Item 1. Business—Supervision and Regulation” for additional information.

Limitations on our ability to receive dividends from our subsidiaries could affect our liquidity and ability to pay dividends and repurchase our common stock.

We are a separate and distinct legal entity from our subsidiaries, including, without limitation, the Bank and our broker-dealer subsidiaries. Dividends to us from these direct and indirect subsidiaries have represented a major source of funds for us to pay dividends on our common and preferred stock, repurchase our common stock, make payments on corporate debt securities and meet other obligations. These capital distributions may be limited by law, regulation or supervisory policy. There are various federal law limitations on the extent to which the Bank can finance or otherwise supply funds to us through dividends and loans. These limitations include minimum regulatory capital and capital buffer requirements, federal banking law requirements concerning the payment of dividends out of net profits or surplus, and Sections 23A and 23B of the Federal Reserve Act and Regulation W governing transactions between an insured depository institution and its affiliates, as well as general federal regulatory oversight to prevent unsafe or unsound practices. Our broker-dealer subsidiaries are also subject to laws and regulations, including net capital requirements, that may limit their ability to pay dividends or make other distributions to us. If our subsidiaries’ earnings are not sufficient to make dividend payments to us while maintaining adequate capital levels, our liquidity may be affected and we may not be able to make dividend payments to our common or preferred stockholders, repurchase our common stock, make payments on outstanding corporate debt securities or meet other obligations, each and any of which could have a material adverse impact on our results of operations, our financial position or the perception of our financial health. The frequency and size of any future dividends to our stockholders and our stock repurchases will depend upon regulatory limitations imposed by our regulators and our results of operations, financial condition, capital levels, cash requirements, future prospects, regulatory review and other factors as further described in “Item 1. Business—Supervision and Regulation.”

A downgrade in our credit ratings could significantly impact our liquidity, funding costs and access to the capital markets.

Our credit ratings are based on a number of factors, including financial strength, as well as factors not within our control, including conditions affecting the financial services industry generally, the macroeconomic environment and changes made by rating agencies to their methodologies or ratings criteria. Our ratings could be downgraded at any time and without any notice by any of the rating agencies, which could, among other things, adversely affect our ability to borrow funds, increase our funding cost, increase our cost of capital, limit the number of investors or counterparties willing to do business with or lend to us, adversely limit our ability to access the capital markets and result in additional collateral requirements under certain of our existing agreements, all of which could have a negative impact on our results of operations.

Operational Risk

We face risks related to our operational, technological and organizational infrastructure.

Our ability to retain and attract customers depends on our ability to develop, operate, and adapt our technology and organizational infrastructure in a rapidly changing environment. In addition, we must accurately process, record and monitor an increasingly large number of complex transactions. Digital technology, cloud-based services, data and software development are deeply embedded into our business model and how we work.

30 Capital One Financial Corporation (COF)

Table of Contents

Similar to other large corporations in our industry, we are exposed to operational risk that can manifest itself in many ways, such as errors in execution, inadequate processes, inaccurate models, faulty or disabled technological infrastructure, malicious disruption and fraud by employees or persons outside of our company, whether through attacks on Capital One directly, or on our third-party service providers or customers. In addition, the increasing use of near real-time money movement solutions, among other risks, increases the complexity of preventing, detecting and recovering fraudulent transactions. We are also heavily dependent on the security, capability, integrity and continuous availability of the technology systems and networks that we use to manage our internal financial and other systems, monitor risk and compliance with regulatory requirements, provide services to our customers, develop and offer new products and communicate with stakeholders. Despite our implementation of various internal and external procedures and security measures, our employees, service providers, partners and other third parties with whom we interact may expose us to certain risks as a result of human error. For example, errors in processing wire transfers may result in the inadvertent release of funds in incorrect amounts or to incorrect recipients, and we may be unable to recover such funds.

We also face the risk of adverse customer impacts and business disruption arising from the execution of strategic initiatives and operational plans we may pursue across our operations. For example, when we launch a new product, service or platform for the delivery or distribution of products or services, acquire or invest in a business or make changes to an existing product, service or delivery platform, there is the risk of execution issues related to changes to operations or processes. These issues could be driven by insufficient mitigation of operational risks associated with the change implementation, inadequate training, failure to account for new or changed requirements, or failure to identify or address impacted downstream processes. Furthermore, ineffective change management oversight and governance over the execution of our key projects and initiatives could expose us to operational, strategic and reputational risk and could negatively impact customers or our financial performance. In addition, we may experience increased costs and/or disruptions due to our hybrid work model, which could also affect our ability to operate effectively and maintain our corporate culture.

If we do not maintain the necessary operational, technological and organizational infrastructure to operate our business, including to maintain the resiliency and security of that infrastructure, our business and reputation could be materially adversely affected. We also are subject to disruptions to our systems or networks arising from events that are wholly or partially beyond our control, which may include computer viruses; computer, telecommunications, network, utility, electronic or physical infrastructure outages; bugs, errors, insider threats, design flaws in systems, networks or platforms; availability and quality of vulnerability patches from key vendors, cyber-attacks and other security incidents, natural disasters, other damage to property or physical assets, or events arising from local or larger scale politics, including civil unrest, terrorist acts and military conflict. Any failure to maintain our infrastructure or prevent disruption of our systems, networks and applications could diminish our ability to operate our businesses, service customer accounts and protect customers’ information, or result in potential liability to customers, reputational damage, regulatory intervention and customers’ loss of confidence in our businesses, any of which could result in a material adverse effect.

We also rely on the business infrastructure and systems of third-party service providers (and their supply chains) with which we do business and/or to whom we outsource the operation, maintenance and development of our information technology and communications systems. We have substantially migrated primarily all aspects of our core information technology systems and customer-facing applications to third-party cloud infrastructure platforms, principally AWS. If we fail to architect, administer or oversee these environments in a well-managed, secure and effective manner, or if such platforms become unavailable, are disrupted, fail to scale, do not operate as designed, or do not meet their service level agreements for any reason, we may experience unplanned service disruption or unforeseen costs which could result in material harm to our business and operations. We must successfully develop and maintain information, financial reporting, disclosure, privacy, data protection, data security and other controls adapted to our reliance on outside platforms and providers. Weakness in our third-party service providers’ processes or controls could impact our ability to deliver products or services to our customers and expose us to compliance and operational risks. In addition, AWS, or other service providers (including, without limitation, those who also rely on AWS) have experienced, and may continue to experience system or telecommunication breakdowns or failures, outages, degradation in service, downtime, failure to scale, software bugs, design flaws, cyber-attacks and other security incidents, insider threats, adverse changes to financial condition, bankruptcy, or other adverse conditions, (including conditions which interfere with our access to and use of AWS) that are outside of our control, any of which could have a material adverse effect on our business and reputation. For example, in January 2025, we experienced a multi-day system outage due to a technical issue experienced by FIS, a third-party service provider, which temporarily impacted certain services for some of our customers. Although we were able to reconnect our systems following restoration of the vendor’s capabilities, there can be no assurance that we will not experience additional system outages in the future as a result of technical issues experienced by our third-party vendors. Any such service outage, particularly where the vendor is the single source from which we obtain such services, could significantly

31 Capital One Financial Corporation (COF)

Table of Contents

disrupt our business or negatively impact the relationship we have with customers that rely on such services.. We also face a risk that our third-party service providers might be unable or unwilling to continue to provide services to meet our current or future needs in an efficient, cost-effective, or favorable manner or may terminate or seek to terminate their contractual relationship with us. Any transition to alternative third-party service providers or internal solutions may be difficult to implement, may cause us to incur significant time and expense and may disrupt or degrade our ability to deliver our products and services. Thus, the substantial amount of our infrastructure that we outsource to AWS or to other third-party service providers may increase our risk exposure.

Any disruptions, failures or inaccuracies of our operational processes, technology systems, networks and models, including those associated with improvements or modifications to such technology systems, networks and models, or failure to identify or effectively respond to operational risks in a timely manner and continue to deliver our services through an operational disruption, could cause us to be unable to market and manage our products and services, manage our risk, meet our regulatory obligations or report our financial results in a timely and accurate manner, all of which could have a negative impact on our results of operations. In addition, our ongoing investments in infrastructure, which are necessary to maintain a competitive business, integrate acquisitions and establish scalable operations, may increase our expenses. As our business develops, changes or expands, additional expenses can arise as a result of a reevaluation of business strategies or risks, management of outsourced services, asset purchases or other acquisitions, structural reorganization, compliance with new laws or regulations, the integration of newly acquired businesses, or the prevention or occurrence of cyber-attacks and other security incidents. If we are unable to successfully manage our expenses, our financial results will be negatively affected. Changes to our business, including those resulting from our strategic imperatives, also require robust governance to ensure that our objectives are executed as intended without adversely impacting our customers, associates, operations or financial performance.

A cyber-attack or other security incident on us or third parties (including their supply chains) with which we conduct business, including an incident that results in the theft, loss, manipulation or misuse of information (including personal information), or the disabling of systems and access to information critical to business operations, may result in increased costs, reductions in revenue, reputational damage, legal exposure and business disruptions.

Our ability to provide our products and services and communicate with our customers, depends upon the management and safeguarding of information systems and infrastructure, networks, software, data, technology, methodologies and business secrets, including those of our service providers. Our products and services involve the collection, authentication, management, usage, storage, transmission and destruction of sensitive and confidential information, including personal information, regarding our customers and their accounts, our employees, our partners and other third parties with which we do business. We also have arrangements in place with third-party business partners through which we share and receive information about their customers who are or may become our customers. The financial services industry, including Capital One, is particularly at risk because of the increased use of and reliance on digital banking products and other digital services, including mobile banking products, such as mobile payments, and other internet- and cloud-based products and applications, and the development of additional remote connectivity solutions, which increase cybersecurity risks and exposure. In addition, global events and geopolitical instability (including, without limitation, the conflict in the Middle East, the war between Ukraine and Russia and the related sanctions imposed by the U.S. and other countries, and increased geopolitical tensions between the U.S. and China) may lead to increased nation state targeting of financial institutions in the U.S. and abroad.

Technologies, systems, networks and other devices of Capital One, as well as those of our employees, service providers, partners and other third parties with whom we interact, have been and may continue to be the subject of cyber-attacks and other security incidents, including computer viruses, hacking, malware, ransomware, denial of service attacks, supply chain attacks, exploitation of vulnerabilities, credential stuffing, account takeovers, insider threats, business email compromise scams or the use of phishing, vishing (through voice messages), smishing (through SMS text), “deep fakes”, or other forms of social engineering. Such cyber-attacks and other security incidents are designed to lead to various harmful outcomes, such as unauthorized transactions in Capital One accounts, unauthorized or unintended access to or release, gathering, monitoring, disclosure, loss, destruction, corruption, disablement, encryption, misuse, modification or other processing of confidential or sensitive information (including personal information), intellectual property, software, methodologies or business secrets, disruption, sabotage or degradation of service, systems or networks, an attempt to extort Capital One, its third-party service providers or its business partners or other damage. Cyber-attacks and other security incidents that occur in the supply chain of third parties with which we interact could also negatively impact Capital One.

These threats may derive from, among other things, error, fraud or malice on the part of our employees, insiders, or third parties or may result from accidental technological failure or design flaws. Any of these parties may attempt to fraudulently induce employees, service providers, customers, partners or other third-party users of our systems or networks to disclose confidential

32 Capital One Financial Corporation (COF)

Table of Contents

or sensitive information (including personal information) in order to gain access to our systems, networks or data or that of our customers, partners, or third parties with whom we interact, or to unlawfully obtain monetary benefit through misdirected or otherwise improper payment. For instance, any party that obtains our confidential or sensitive information (including personal information) through a cyber-attack or other security incident may use this information for ransom, to be paid by us or a third party, as part of a fraudulent activity that is part of a broader criminal activity, or for other illicit purposes. Additionally, the failure of our employees, third-party service providers or business partners, or their respective supply chains, to exercise sound judgment and vigilance when targeted with social engineering or other cyber-attacks may increase our vulnerability.

For example, on July 29, 2019, we announced that on March 22 and 23, 2019 an outside individual gained unauthorized access to our systems (the “2019 Cybersecurity Incident”). This individual obtained certain types of personal information relating to people who had applied for our credit card products and to our credit card customers. While the 2019 Cybersecurity Incident has been remediated, it resulted in fines, litigation, consent orders, settlements, government investigations and other regulatory enforcement inquiries. Cyber and information security risks for large financial institutions like us continue to increase due to the proliferation of new technologies, the industry-wide shift to reliance upon the internet to conduct financial transactions, the increased sophistication and activities of malicious actors, organized crime, perpetrators of fraud, hackers, terrorists, activists, extremist parties, formal and informal instrumentalities of foreign governments, state-sponsored or nation-state actors and other external parties and the growing use of AI by threat actors.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2024-12-31, filed 2025-02-20 · accession 0000927628-25-000092

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 23 headings are on that chain and 17 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.