Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

NTRS US Equity

Northern Trust CorpFinancials · State Commercial Banks · CIK 73124 · FY ends Dec 31
$183.90
+1.39 (+0.76%)
USD · as of 2026-08-21 · marketstack

NTRS · 10-K · period ended 2025-12-31

← all NTRS documents
filed 2026-02-24 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1504 of 2,797630k characters rendered

ntrs-20251231

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

____________________________________________________________

FORM 10-K

____________________________________________________________

For the fiscal year ended December 31, 2025

OR

For the transition period fromto

Commission File No. 001-36609

____________________________________________________________

NORTHERN TRUST CORPORATION

(Exact name of registrant as specified in its charter)

____________________________________________________________

50 South La Salle Street

(Address of principal executive offices) (Zip Code)

Registrant’s telephone number, including area code: (312) 630-6000

____________________________________________________________

Securities registered pursuant to Section 12(b) of the Act:

Title of Each Class Trading Symbol Name of Each Exchange On Which Registered

Common Stock, $1.66 2/3 Par Value NTRS The NASDAQ Stock Market LLC

Securities registered pursuant to Section 12(g) of the Act: None

____________________________________________________________

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes☒ No ☐

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒

Indicate by check mark whether the registrant: (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§232.405 of this chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large accelerated filer ☒ Accelerated filer ☐ Emerging growth company ☐

Non-accelerated filer ☐ Smaller reporting company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. □

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). □

Indicate by check mark whether the registrant is a shell company (as defined in Exchange Act Rule 12b-2). Yes ☐ No ☒

The aggregate market value of the registrant’s common stock as of June 30, 2025 (the last business day of the registrant’s most recently completed second fiscal quarter), based upon the last sale price of the common stock at June 30, 2025 as reported by The NASDAQ Stock Market LLC, held by non-affiliates was approximately $24.1 billion. Determination of stock ownership by non-affiliates was made solely for the purpose of responding to this requirement and the registrant is not bound by this determination for any other purpose.

At January 31, 2026, 185,827,803 shares of common stock, $1.66 2/3 par value, were outstanding.

Portions of the registrant’s Proxy Statement for its 2026 Annual Meeting of Stockholders are incorporated by reference into Part III hereof.

NORTHERN TRUST CORPORATION

FORM 10-K

ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

Page

PART I

Item 1 Business 1

Item 1A Risk Factors 13

Item 1B Unresolved Staff Comments 33

Item 1C Cybersecurity 34

Item 2 Properties 35

Item 3 Legal Proceedings 35

Item 4 Mine Safety Disclosures 35

Supplemental Item Information About Our Executive Officers 36

PART II

Item 6 Reserved 39

Item 7A Quantitative and Qualitative Disclosures About Market Risk 88

Item 8 Financial Statements and Supplementary Data 89

Item 9A Controls and Procedures 165

Item 9B Other Information 167

Item 9C Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 167

PART III

Item 10 Directors, Executive Officers and Corporate Governance 167

Item 11 Executive Compensation 167

Item 14 Principal Accountant Fees and Services 167

PART IV

Item 15 Exhibits and Financial Statement Schedules 168

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION i

GLOSSARY OF TERMS

When the following terms and abbreviations appear in the text of this report, they have the meanings indicated below:

AFS Available for Sale

AIFMD Alternative Investment Fund Managers Directive

ALCO Asset and Liability Management Committee

AMA Basel Advanced Measurement Approach

AML Anti-Money Laundering

AOCI Accumulated Other Comprehensive Income

AS Asset Servicing

ASC Accounting Standards Codification

ASU Accounting Standards Update

AUC/A Assets Under Custody/Administration

AUM Assets Under Management

Bank The Northern Trust Company

Basel Committee International Basel Committee on Banking Supervision

Basel III Industry-standard guidelines published by the Basel Committee

BMR European Union Benchmarks Regulation

Brexit The withdrawal of the United Kingdom from the European Union

BRRD Bank Recovery and Resolution Directive (EU)

Risk Committee Risk Committee of the Board of Directors

CCAR Comprehensive Capital Analysis and Review

CCPA California Consumer Privacy Act, as amended

CFPB Consumer Financial Protection Bureau

CFTC U.S. Commodity Futures Trading Commission

Corporation Northern Trust Corporation

CRA Community Reinvestment Act

CRC Credit Risk Committee

CRD Capital Requirements Directive of June 26, 2013 (EU)

CRO Chief Risk Officer

CRR Capital Requirements Regulation of June 26, 2013 (EU)

CSD Central Securities Depositories

CSDR Central Securities Depositories Regulation (EU)

CSSF Commission de Surveillance du Secteur Financier (Luxembourg)

DFAST Dodd-Frank Act Stress Tests

DGS Deposit Guarantee Schemes

DGSD Deposit Guarantee Schemes Directive

DIF Federal Deposit Insurance Corporation’s Deposit Insurance Fund

Dodd-Frank Act Dodd-Frank Wall Street Reform and Consumer Protection Act

ECB European Central Bank

EEA European Economic Area

EMIR European Market Infrastructure Regulation 648/2012

EOP End of Period

ESG Environmental, Social and Governance

EU European Union

Exchange Act Securities Exchange Act of 1934, as amended

ii 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

GLOSSARY OF TERMS (continued)

FASB Financial Accounting Standards Board

FCA Financial Conduct Authority

FDIA Federal Deposit Insurance Act

FDIC Federal Deposit Insurance Corporation

Federal Reserve Board The Board of Governors of the Federal Reserve System

FICC Fixed Income Clearing Corporation

FinCEN Financial Crimes Enforcement Network

FINRA Financial Industry Regulatory Authority

FRC Fiduciary Risk Committee

FTE Fully Taxable Equivalent

FTP Funds Transfer Pricing

FX Foreign Exchange

GAAP Generally Accepted Accounting Principles

GDPR General Data Protection Regulation

GERC Global Enterprise Risk Committee

GFX Global Foreign Exchange

GSIB Global Systemically Important Banks

HTM Held to Maturity

HQLAs High-Quality Liquid Assets

Investment Advisers Act Investment Advisers Act of 1940, as amended

IR Interest Rate

IRD Interest Rate Derivative

ITRC Information Technology Risk Committee

LCR Liquidity Coverage Ratio

LGD Loss Given Default

LIBOR London Interbank Offered Rate

LIBOR Act Adjustable Interest Rate (LIBOR) Act

LTV Loan-to-Collateral Value

MD&A Management’s Discussion and Analysis

MIFID Market in Financial Instruments Directive

MIFIR Markets in Financial Instruments Regulation

MLD5 Fifth EU Money Laundering Directive

MLRC Market & Liquidity Risk Committee

MREL Minimum requirements for own funds and eligible liabilities (EU)

MROC Model Risk Oversight Committee

MSDC Macroeconomic Scenario Development Committee

MVE Market Value of Equity

NAICS North American Industry Classification System

NAV Net Asset Value

NFA National Futures Association

NII Net Interest Income

N/M Not Meaningful

NSFR Net Stable Funding Ratio requirement in the United States

OFAC U.S. Department of the Treasury’s Office of Foreign Assets Control

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION iii

GLOSSARY OF TERMS (continued)

ORC Operational Risk Committee

OREO Other Real Estate Owned

OTC Over-the-Counter

PD Probability of Default

PIPL Personal Information Protection Law (China)

PRA Prudential Regulation Authority

ROU Right-of-Use

RWA Risk-Weighted Assets

SEC U.S. Securities and Exchange Commission

Series D Preferred Stock Series D Non-Cumulative Perpetual Preferred Stock

Series E Preferred Stock Series E Non-Cumulative Perpetual Preferred Stock

SOFR Secured Overnight Finance Rate

SFDR Sustainable Finance Disclosure Regulations (EU)

SRD II Shareholder Rights Directive (EU)

SFTR Securities Financing Transactions and Reuse of Collateral

Taxonomy Regulations Regulation (EU) 2020/852

UCITS Undertakings for the Collective Investment in Transferable Securities

UK United Kingdom

UK GDPR General Data Protection Regulation in the UK

VaR Value-at-Risk

VIE Variable Interest Entity

WM Wealth Management

iv 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

PART I

ITEM 1 – BUSINESS

Northern Trust Corporation

Northern Trust Corporation (the “Corporation”) is a leading provider of wealth management, asset servicing, asset management and banking solutions to corporations, institutions, families and individuals. The Corporation is a financial holding company conducting business through various U.S. and non-U.S. subsidiaries, including The Northern Trust Company (Bank).

The Bank is an Illinois banking corporation headquartered in Chicago and the Corporation’s principal subsidiary. Founded in 1889, the Bank conducts its business through its U.S. operations and its various U.S. and non-U.S. branches and subsidiaries. At December 31, 2025, the Bank had consolidated assets of $176.4 billion and common bank equity capital of $11.4 billion.

The Corporation was formed as a holding company for the Bank in 1971. The Corporation has a global presence with offices in 24 U.S. states and Washington, D.C., and across 22 locations in Canada, Europe, the Middle East and the Asia-Pacific region. At December 31, 2025, the Corporation had consolidated total assets of $177.1 billion and stockholders’ equity of $13.0 billion.

The Corporation expects that the Bank will continue in the foreseeable future to be the major source of the Corporation’s consolidated assets, revenues, and net income. Except where the context otherwise requires, references to “Northern Trust,” “we,” “us,” “our,” “its,” or similar terms mean Northern Trust Corporation and its subsidiaries on a consolidated basis.

Business Overview

Northern Trust focuses on managing and servicing client assets through its two client-focused reporting segments: Asset Servicing and Wealth Management. Asset management and related services are provided to Asset Servicing and Wealth Management clients primarily by the Asset Management business. The revenue and expenses of Asset Management and certain other support functions are allocated fully to Asset Servicing and Wealth Management. Northern Trust reports certain income and expense items not allocated to Asset Servicing and Wealth Management in Other.

ASSET SERVICING

Asset Servicing (AS) is a leading global provider of asset servicing and related services to corporate and public retirement funds, foundations, endowments, fund managers, insurance companies, sovereign wealth funds, and other institutional investors around the globe. Asset servicing and related services encompass a full range of capabilities including but not limited to: custody; fund administration; investment operations outsourcing; investment management; investment risk and analytical services; employee benefit services; securities lending; foreign exchange; treasury management; brokerage services; transition management services; banking; and cash management. Client relationships are managed through the Bank and the Bank’s and the Corporation’s other subsidiaries, including support from locations in North America, Europe, the Middle East, and the Asia-Pacific region. At December 31, 2025, total Asset Servicing assets under custody/administration (AUC/A), assets under custody, and assets under management (AUM) were $17.4 trillion, $13.6 trillion, and $1.3 trillion, respectively.

WEALTH MANAGEMENT

Wealth Management (WM) focuses on high-net-worth individuals and families, business owners, executives, professionals, retirees, and established privately-held businesses in its target markets. In supporting these targeted segments, Wealth Management provides trust, investment management, custody, and philanthropic services; financial consulting; guardianship and estate administration; family business consulting; family financial education; brokerage services; and private and business banking. Wealth Management also includes Global Family Office, which provides customized services, including but not limited to: investment management; global custody; fiduciary; private banking; family office consulting; and technology solutions to meet the complex financial and reporting needs of family offices across the globe.

Wealth Management is one of the largest providers of advisory services in the United States, with AUC/A, assets under custody, and AUM of $1.3 trillion, $1.3 trillion, and $507.2 billion, respectively, at December 31, 2025. Wealth Management services are delivered by multidisciplinary teams through a network of offices in 19 U.S. states and Washington, D.C., as well as offices in London, Guernsey, Singapore, and Abu Dhabi.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 1

ASSET MANAGEMENT

Asset Management, through the Corporation’s various subsidiaries, supports the Asset Servicing and Wealth Management reporting segments by providing a broad range of asset management and related services and other products to clients around the world. Investment solutions are delivered through separately managed accounts, bank common and collective funds, registered investment companies, exchange traded funds, non-U.S. collective investment funds, and unregistered private investment funds. Asset Management’s capabilities include active and passive equity; active and passive fixed income; cash management; multi-asset and alternative asset classes (such as private equity and hedge funds of funds); and multi-manager advisory services and products. Asset Management’s activities also include overlay services and other risk management services. Asset Management operates internationally through subsidiaries and distribution arrangements and its revenue and expense are fully allocated to Asset Servicing and Wealth Management. As discussed above, Northern Trust managed $1.8 trillion in assets as of December 31, 2025, including $1.3 trillion for Asset Servicing clients and $507.2 billion for Wealth Management clients.

Competition

Northern Trust faces a number of competitors across its businesses. Competition comes from other financial services organizations, both regulated and unregulated, whose products and services may span the markets in which Northern Trust conducts operations. Our competitors include a broad range of financial institutions and service companies, including other custodial banks, investment counseling firms, deposit-taking institutions, asset management firms, benefits consultants, trust companies, investment banking firms, insurance companies, and various financial technology companies, including software providers and data services firms. As our businesses grow and markets evolve, we may encounter increasing and new forms of competition around the world.

Northern Trust’s growth strategy is to leverage our differentiators to serve targeted client segments with specialized solutions in select geographies. Northern Trust’s differentiators are our: trusted brand, deep expertise, tailored technology, proven relationships and network and strong balance sheet. Northern Trust emphasizes the development and growth of scalable, sustainable fee-based income. Northern Trust will continue to enable its strategy through significant investments in talent and culture, technology, data, AI and operational excellence.

Economic Conditions And Government Policies

The earnings of Northern Trust are affected by numerous external influences. Chief among these are general economic conditions, both domestic and international, and actions that governments and their central banks take in managing their economies. These general conditions affect all of Northern Trust’s businesses, as well as the quality, value, and profitability of its loan and investment portfolios.

The Board of Governors of the Federal Reserve System (Federal Reserve Board) implements monetary policy through its open market operations in United States Government securities, its setting of the discount rate at which member banks may borrow from Federal Reserve Banks, and its changes in the reserve requirements for deposits. The policies adopted by the Federal Reserve Board directly affect interest rates and therefore what banks earn on their loans and investments and what they pay on their savings and time deposits and other purchased funds.

Supervision and Regulation

Northern Trust is subject to extensive regulation and supervision under state and federal laws in the United States and in each of the jurisdictions in which it does business. The descriptions below outline significant elements of selected laws and regulations applicable to Northern Trust and are qualified in their entirety by reference to the particular statutory or regulatory provisions summarized. These descriptions do not summarize all laws and regulations applicable to Northern Trust or all possible or proposed changes to such laws or regulations and are not intended to be a substitute for the related statutes or regulatory provisions.

Changes in laws or regulations applicable to Northern Trust may have a material effect on its businesses and results of operations. The scope of the laws and regulations, and the intensity of the supervision to which Northern Trust is subject have increased in recent years, initially in response to the financial crisis, and more recently in light of other factors, including the banking turmoil in early 2023, technological factors, and market changes. Regulatory enforcement and fines have also increased across the banking and financial services sector. Northern Trust expects that its business will remain subject to extensive regulation and heightened supervision.

2 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

FINANCIAL HOLDING COMPANY REGULATION

Under U.S. law, the Corporation is a bank holding company that has elected to be a financial holding company subject to the supervision, examination, and regulation of the Federal Reserve Board. A financial holding company is permitted to engage in a broader range of financial activities than a bank holding company. The Federal Reserve Board has authority to limit the activities that a financial holding company may conduct if any depository institution controlled by the financial holding company is found to no longer be “well-capitalized” or “well-managed” or has not received at least a “satisfactory” rating in its most recent Community Reinvestment Act (CRA) examination. Failure to meet one or more of these requirements may result in restrictions on the Corporation’s ability to exercise powers granted to financial holding companies, to engage in new activities, to continue current activities, or to make acquisitions. The Bank Holding Company Act also requires a bank holding company to obtain prior approval from the Federal Reserve Board before it acquires substantially all the assets of any bank, or ownership or control of more than 5% of the voting shares of any bank.

SUBSIDIARY REGULATION

The Bank is a member of the Federal Reserve System, with deposits insured by the Federal Deposit Insurance Corporation (FDIC) up to the federal deposit insurance limits, and is subject to regulation by both agencies. As an Illinois banking corporation, the Bank is also subject to Illinois state laws and regulations and to examination and supervision by the Division of Banking of the Illinois Department of Financial and Professional Regulation. The Bank is also registered as a transfer agent with the Federal Reserve Board and is registered as a swap dealer with the U.S. Commodity Futures Trading Commission (CFTC) under the Commodity Exchange Act. As a result, the Bank is subject to supervision, examination and enforcement by certain other regulatory bodies, including the CFTC and the National Futures Association (NFA). The Corporation’s nonbanking affiliates are subject to regulation by the Federal Reserve Board and, in certain circumstances, other functional regulators, as discussed in greater detail below.

ENHANCED PRUDENTIAL STANDARDS

Under the Federal Reserve Board’s tailoring rules, the Corporation is subject to the enhanced prudential standards applicable to Category II banking organizations. As a Category II banking organization, the Corporation must submit annual capital plans to the Federal Reserve Board, conduct supervisory and internal periodic stress tests to evaluate capital adequacy in adverse economic conditions, maintain enhanced risk management procedures, and comply with a liquidity risk management framework (discussed below in “Liquidity Standards”) and single counterparty credit limits, and conduct liquidity stress tests. The Corporation is not subject to all of the standards applicable to U.S. bank holding companies that are global systemically important bank holding companies (GSIBs), such as the total loss-absorbing capacity requirement, capital surcharge, enhanced supplementary leverage ratio, or additional single counterparty credit limits.

LONG-TERM DEBT AND CLEAN HOLDING COMPANY REQUIREMENTS

In 2023, the U.S. banking regulators proposed a rule that would require banking organizations with $100 billion or more in total assets to comply with Long-Term Debt requirements and clean holding company requirements similar to those that currently apply only to GSIBs. This proposal would also impose a Long-Term Debt requirement on certain categories of insured depository institutions that are not consolidated subsidiaries of U.S. GSIBs, including insured depository institutions with $100 billion or more in total assets, such as the Bank. If adopted, this proposal would require the Corporation and the Bank to each maintain a minimum outstanding eligible Long-Term Debt amount of no less than the greatest of (i) 6% of risk-weighted assets (RWA), (ii) 2.5% of total leverage exposure, and (iii) 3.5% of average total consolidated assets. The Bank would be required to issue the minimum amount of eligible Long-Term Debt to the Corporation, and the Corporation would be required to issue the minimum amount of eligible Long-Term Debt externally. In addition, if adopted as proposed, the clean holding company requirement would limit or prohibit the Corporation from entering into certain transactions that could impede its orderly resolution, including, for example, prohibiting the Corporation from entering into transactions that could spread losses to subsidiaries and third parties, as well as limiting the amount of the Corporation’s liabilities that are not eligible Long-Term Debt. The timing and form of any final rule implementing the Long-Term Debt and clean holding company requirements is uncertain.

RESOLUTION PLANNING

As required by Section 165(d) of the Dodd-Frank Wall Street Reform and Consumer Protection Act (Dodd-Frank Act), the Corporation is required to submit periodically to the Federal Reserve Board and FDIC a resolution plan for its rapid and orderly resolution in the event of material financial distress or failure. In August 2024, the Federal Reserve Board and FDIC issued final joint guidance on resolution planning requirements applicable to the Corporation under Section 165(d). The Corporation’s most recent 165(d) plan was submitted timely to the FDIC and Federal Reserve Board by October 1, 2025. The Corporation’s next 165(d) plan submission is a targeted resolution plan due July 1, 2028, with future resolution plans due every three years after that, alternating between full and targeted resolution plans, pursuant to the rule.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 3

In addition, the Bank, as an insured depository institution, is required to submit to the FDIC periodic plans for resolution in the event of its failure. In June 2024, the FDIC adopted a final rule that would require covered insured depository institutions, such as the Bank, to submit a full resolution plan to the FDIC every three years and submit an interim supplement in each year that it is not required to submit a full resolution plan. The final rule increases the content requirements for plan submissions and introduces a new credibility standard for the FDIC’s evaluation of resolution plans, which would be enforceable against the covered insured depository institutions. In December 2025, the FDIC provided an update that it plans to propose changes to the final rule in 2026, including codifying the content requirement exemptions and frequently asked questions (FAQs) associated with the modified approach it set out in April 2025. The Bank submitted its most recent interim supplement timely by July 1, 2025. The Bank’s full resolution plan is due July 1, 2026.

Separately, the European Union Bank Recovery and Resolution Directive (BRRD) sets out the framework for the recovery and resolution of European Union (EU) credit institutions and systemically-important investment firms, including certain of the Bank’s subsidiaries and branches. The BRRD establishes a set of harmonized rules for early intervention measures, recovery and resolution planning, bail-in powers and requirements for total loss absorbing capital for EU institutions, collectively known as minimum requirements for own funds and eligible liabilities (MREL). Northern Trust Global Services SE, a Luxembourg-incorporated indirect subsidiary of the Bank, is authorized by the European Central Bank (ECB) and subject to the prudential supervision of the Luxembourg Commission de Surveillance du Secteur Financier (CSSF). As such, Northern Trust Global Services SE falls within the scope of the BRRD and its recovery and resolution planning is overseen by the CSSF and the CSSF Resolution Board.

The United Kingdom (UK) has established a special resolution regime and a resolvability assessment framework overseen by the Bank of England (as the UK resolution authority) with many similar features to the BRRD, which was substantially retained as part of UK law following the withdrawal of the UK from the EU. The special resolution regime applies to firms that are permitted to accept deposits under Part 4A of the Financial Services and Markets Act 2000. As such, the London branch of the Bank, as a UK branch of a third-country institution that accepts deposits, falls within the scope of the special resolution regime.

ORDERLY LIQUIDATION AUTHORITY

Under the Dodd-Frank Act, certain financial companies, such as the Corporation and certain of its covered subsidiaries, can be subjected to an orderly liquidation authority if in default or danger of default and their resolution under the U.S. Bankruptcy Code would have serious adverse effects on financial stability in the United States, among other requirements set by statute. If the Corporation were subject to orderly liquidation authority, the FDIC would be appointed as its receiver, which would give the FDIC considerable powers to resolve the Corporation. Absent such actions, the Corporation, as a bank holding company, would remain subject to the U.S. Bankruptcy Code.

THE VOLCKER RULE

The Volcker Rule generally prohibits banking entities, including the Bank and its affiliates, from engaging in proprietary trading, subject to certain exemptions and exclusions, such as for market-making, hedging, certain trading activities in U.S. and foreign sovereign debt, and trading activities related to liquidity management. The Volcker Rule also prohibits certain investments in, and relationships with, covered funds as defined in the Volcker Rule, such as hedge funds, private equity funds and similar funds, subject to a number of exemptions and exclusions. Northern Trust maintains an enterprise-wide compliance program to comply with the Volcker Rule.

HOLDING COMPANY AS A SOURCE OF STRENGTH

The Corporation, as a bank holding company, is required to serve as a source of financial and managerial strength to its depository institution subsidiary. Under this requirement, the Corporation could be required to commit resources to the Bank should the Bank experience financial distress.

PAYMENT OF DIVIDENDS

The Corporation may pay dividends, repurchase stock, and make other capital distributions only in accordance with the capital plan rules and capital adequacy standards of the Federal Reserve Board, including the stress capital buffer requirement, discussed further in “Capital Adequacy Requirements” below. Dividends from the Bank are a significant source of funds for the Corporation, and the Corporation’s ability to pay dividends on its common stock therefore depends in part on the ability of the Bank to pay sufficient dividends to the Corporation.

Various other federal and state laws and regulations limit the amount of dividends that may be paid by the Bank to the Corporation without regulatory consent. The Bank may not pay any dividends if it is undercapitalized, or if the payment of the dividend would cause it to become undercapitalized. In general, the amount of dividends that may be paid in a calendar year is limited to its “retained net income” (the current year’s net income combined with the retained net income of the two preceding years), or its “undivided profits” (generally, accumulated net profits that have not been paid out as dividends or transferred to surplus), whichever is less. The ability of the Bank to pay dividends to the Corporation may also be affected by the capital adequacy standards applicable to the Bank (discussed further below), which include minimum requirements and buffers.

4 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

CAPITAL PLANNING AND STRESS TESTING

The Corporation’s capital distributions are subject to the Federal Reserve Board’s capital plan rules, which require the Corporation to submit an annual capital plan to the Federal Reserve Board for review.

The major components of that oversight are the Federal Reserve Board’s Comprehensive Capital Analysis and Review (CCAR) and Dodd-Frank Act Stress Tests (DFAST). These requirements involve both company-run and supervisory-run testing of capital under various scenarios, including baseline and severely adverse scenarios provided by the appropriate banking regulator.

Under the DFAST regulations, the Corporation is required to undergo regulatory stress tests conducted by the Federal Reserve Board annually. In October 2025, the Federal Reserve proposed revisions to its supervisory stress testing framework through two related proposals designed to enhance the transparency and public accountability of its annual stress test (the Stress Testing Transparency Proposal). The first proposal solicits comments on the Federal Reserve’s stress test models, scenario design framework and an enhanced disclosure process under which the Federal Reserve would annually publish and invite public comment on stress test scenarios, models and material changes to those models. The second proposal solicits comments on the scenarios for the 2026 supervisory stress test.

The Bank also is required to conduct its own annual internal stress test (although it is permitted to combine certain reporting and disclosure of its stress test results with the results of the Corporation). Results from the Corporation’s and the Bank’s annual company-run stress tests are reported to the appropriate regulators and made publicly available. Northern Trust published the results of its most recent company-run stress tests on July 1, 2025.

CAPITAL ADEQUACY REQUIREMENTS

The Corporation, as a bank holding company, is subject to risk-based and leverage capital guidelines implemented by the Federal Reserve Board that are based on industry-standard guidelines published by the International Basel Committee on Banking Supervision (Basel Committee), known as Basel III. The Bank, as an FDIC-insured depository institution, is also required to meet risk-based and leverage capital guidelines established by regulators that are generally similar to those established by the Federal Reserve Board for bank holding companies.

Under the Basel III rules, the Corporation, with the Bank, is a “core” banking organization that is required to use the advanced approaches methodologies to calculate and disclose publicly its risk-based capital ratios. The Corporation also is subject to a capital floor that is based on the Basel III standardized approach to calculating risk-based capital ratios. The Corporation is therefore required to calculate its risk-based capital ratios under both the standardized and advanced approaches, and is subject to the more stringent of the two in the assessment of its capital adequacy.

In 2023, the U.S. banking agencies issued a proposed rule to implement the Basel III endgame agreement for large banks (Basel III Endgame Proposal). The Federal Reserve announced in September 2024 that it would publish a re-proposal of its regulations finalizing the Basel III standards. That re-proposal is expected in early 2026. The potential impacts on the Corporation and the Bank of a final rule remain uncertain until a final rule is published.

The Bank’s risk-based and leverage capital ratios at December 31, 2025, were well above the regulatory requirements established by U.S. banking regulators. The risk-based and leverage capital ratios for the Corporation and the Bank, together with the regulatory minimum ratios and the ratios required for classification as “well-capitalized,” are provided in the following chart.

TABLE 1: RISK-BASED AND LEVERAGE CAPITAL RATIOS AS OFDECEMBER 31, 2025

“Well-capitalized” minimum ratios, as applicable

Northern Trust Corporation N/A N/A 6.0 % 6.0 % 10.0 % 10.0 % N/A N/A N/A

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 5

Advanced approaches institutions, such as the Corporation and the Bank, are subject to a minimum supplementary leverage ratio of 3.0%. Advanced approaches institutions that are insured depository institutions, such as the Bank, also must maintain at least a 3.0% supplementary leverage ratio to be considered “well-capitalized.” The Corporation is also subject to a stress capital buffer, which integrates forward-looking stress test results with non-stress capital requirements, and the Bank is also subject to a capital conservation buffer, which respectively requires the Corporation and the Bank to hold a buffer of Common Equity Tier 1 capital above the minimum risk-based capital requirements in order to avoid constraints on dividends, equity repurchases and compensation. The minimum capital buffer requirement for advanced approaches banking organizations, such as the Corporation and the Bank, is 2.5%.

A “countercyclical buffer” of 0% to 2.5% of a banking organization’s total RWA for advanced approaches banking organizations, such as the Corporation, is also a component of the capital adequacy framework. In general, the amount of the countercyclical capital buffer is a weighted average of the countercyclical capital buffer established in the various jurisdictions in which the banking organization has credit exposures. The U.S. countercyclical buffer is currently set at 0%.

In April 2025, the Federal Reserve issued a proposed rule to reduce volatility in the stress capital buffer (SCB) requirement, primarily through the averaging of the decline in a firm’s Common Equity Tier 1 capital over a two-year horizon (current and prior year). The proposal would also extend the annual effective date of each firm’s stress capital buffer requirement by one quarter, from October 1 to January 1.

The results of the 2025 DFAST, published by the Federal Reserve Board on June 27, 2025, resulted in Northern Trust’s stress capital buffer and effective Common Equity Tier 1 capital ratio minimum requirement remaining constant at 2.5% and 7.0%, respectively, for the annual capital plan cycle, which began on October 1, 2025 and continues through September 30, 2026. On February 4, 2026, the Federal Reserve notified the Corporation that because the Stress Testing Transparency Proposal remains subject to public comment, absent further action from the Federal Reserve, the Corporation’s stress capital buffer requirement will remain at 2.5% until September 30, 2027.

LIQUIDITY STANDARDS

Northern Trust is subject to the U.S. liquidity coverage ratio (LCR) requirement, which is designed to ensure that covered banking organizations, including the Corporation and the Bank, maintain an adequate level of unencumbered high-quality liquid assets equal to their expected net cash outflow for a 30-day time horizon under a prescribed regulatory liquidity stress scenario. As of December 31, 2025, the Corporation and the Bank were in compliance with applicable LCR requirements.

Northern Trust also is subject to the U.S. net stable funding ratio (NSFR) requirement, designed to promote more medium- and long-term funding of the assets and activities of banking entities over a one-year time horizon. As of December 31, 2025, the Corporation and the Bank were in compliance with applicable NSFR requirements. In addition, Northern Trust publicly discloses certain qualitative and quantitative information about its NSFR consistent with the semi-annual disclosure requirements of the Federal Reserve Board’s final rule on U.S. NSFR disclosure.

As noted above, the enhanced prudential standards impose additional liquidity requirements for large bank holding companies. The Corporation, a Category II institution under the final tailoring rule, is subject to the liquidity risk management, monthly liquidity stress testing, liquidity buffer, and daily liquidity reporting requirements.

PROMPT CORRECTIVE ACTION

Federal banking regulators are required to take “prompt corrective action” with respect to a depository institution if that institution does not meet certain capital adequacy standards, and are also authorized to take appropriate action against a parent bank holding company of an under-capitalized banking subsidiary. In certain instances, the Corporation could be required to guarantee the performance of a capital restoration plan for the Bank if it were under-capitalized.

RESTRICTIONS ON TRANSACTIONS WITH AFFILIATES

The Bank is subject to restrictions governing covered transactions between it and its affiliated entities, including the Corporation, the Bank’s affiliates, and the Corporation’s subsidiaries. These transactions must be on terms and conditions that are, or in good faith would be, offered to nonaffiliated companies (i.e., on terms not less favorable to the Bank than market terms). Further, extensions of credit must be secured fully with qualifying collateral, while all covered transactions with affiliates are limited to 10% of the Bank’s capital and surplus for transactions with a single affiliate and to 20% of the Bank’s capital and surplus for transactions with all affiliates.

6 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

SWAPS AND OTHER DERIVATIVES

Northern Trust is subject to comprehensive regulation of its derivatives businesses, including regulations that impose margin requirements, business conduct requirements, trade reporting, central clearing and mandatory trading on regulated exchanges or execution facilities for certain types of swaps and security-based swaps. CFTC and U.S. Securities and Exchange Commission (SEC) rules require registration of swap dealers and security-based swap dealers, respectively, and impose numerous obligations on such registrants, including adherence to business conduct standards for all in-scope instruments. The Bank is registered with the CFTC as a swap dealer and is subject to CFTC and NFA rules and supervision related to its swaps business. Swap dealers regulated by a prudential regulator, like the Bank, are subject to uncleared swap margin requirements and minimum capital requirements established by the prudential regulators. The Corporation has not registered and does not expect that it, or any of its affiliates, will be required to register as a security-based swap dealer with the SEC.

In addition, certain nonbanking affiliates, including Northern Trust Investments, Inc., are registered with the CFTC as commodity trading advisors and/or commodity pool operators, or are operating under certain exemptions from such registration pursuant to CFTC rules and other guidance. Commodity pool operators have certain responsibilities with respect to each pool they operate or advise.

BROKER-DEALER AND INVESTMENT ADVISER REGULATION

Northern Trust Securities, Inc. is registered as a broker-dealer with the SEC and is a member of various self-regulatory organizations, including the Financial Industry Regulatory Authority, Inc. (FINRA). Broker-dealers are subject to laws and regulations relating to all aspects of their securities business operations, including, but not limited to, sales and trading practices, securities offerings, handling of customer funds, net capital levels, recordkeeping, privacy requirements, and the conduct of directors, officers, and employees. Broker-dealers are also regulated by securities administrators in those states where they do business. Northern Trust Securities, Inc. is also registered with the Municipal Securities Rulemaking Board (MSRB) as a municipal securities dealer and subject to regulation as such.

Northern Trust Securities, Inc. and other subsidiaries of the Corporation are registered with the SEC as investment advisers and are subject to regulation by the SEC. The Corporation’s registered investment advisers in the United States are subject to the Investment Advisers Act of 1940, as amended (the Investment Advisers Act), and SEC rules and regulations thereunder, including with respect to record-keeping, operational and marketing requirements, disclosure obligations, fiduciary and other obligations and prohibitions on fraudulent activities, and other applicable state and federal laws and regulations, including anti-fraud laws. The SEC is authorized to institute proceedings and impose sanctions for violations of the Investment Advisers Act, ranging from fines and censure to termination of an investment adviser’s registration. Noncompliance with the Investment Advisers Act or other federal and state securities laws and regulations could result in investigations, sanctions, disgorgement, termination of an investment adviser’s registration, fines and/or reputational harm.

ANTI-MONEY LAUNDERING, ANTI-TERRORISM LEGISLATION, AND OFFICE OF FOREIGN ASSETS CONTROL

Certain subsidiaries of the Corporation are subject to the Bank Secrecy Act of 1970, as amended by the USA PATRIOT Act of 2001 and Anti-Money Laundering Act of 2020 and implemented in the regulations of the federal banking regulators and the Financial Crimes Enforcement Network (FinCEN), which requires banks and other financial institutions to comply with anti-money laundering (AML) and financial transparency requirements, such as conducting due diligence, verifying client and beneficial owner identification, and monitoring client transactions and detecting and reporting suspicious activities. AML laws outside the United States contain similar requirements. The Anti-Money Laundering Act of 2020 includes the Corporate Transparency Act, which requires FinCEN to issue regulations requiring reporting of and access to beneficial ownership information of legal entities and amendments to related customer due diligence requirements for financial institutions.

The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) and U.S. Department of State administer and enforce U.S. economic sanctions laws and regulations, which prohibit the Corporation and its subsidiaries from engaging in certain transactions and dealings including business in or with certain jurisdictions and parties that are the target of U.S. economic sanctions, such as organizations and countries suspected of aiding, harboring or engaging in terrorist acts or undermining the sovereignty and territorial integrity of democratic countries. If the Corporation or the Bank finds a sanctioned name or jurisdiction on any transaction, asset or account, the Corporation or the Bank may be required to reject or block such account or transaction and notify the appropriate authorities.

Failure to comply with these requirements could result in fines, penalties, lawsuits, regulatory sanctions or difficulties in obtaining approvals, restrictions on their business activities or harm to reputation. Many other countries have imposed similar laws and regulations that apply to the Corporation’s non-U.S. offices. The Corporation has established policies and procedures to comply with these laws and the related regulations.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 7

DEPOSIT INSURANCE AND ASSESSMENTS

The Bank accepts deposits and eligible deposits have the benefit of FDIC insurance up to the standard maximum deposit insurance amount, which is currently $250,000 for each ownership right and capacity under which the eligible deposit accounts are maintained. Under the Federal Deposit Insurance Act (FDIA), insurance of deposits may be terminated by the FDIC upon a finding that the insured depository institution has engaged in unsafe and unsound practices, is in an unsafe or unsound condition, or has violated laws, regulations, or orders from a regulatory agency.

The FDIC’s Deposit Insurance Fund (DIF) is funded by assessments on FDIC-insured depository institutions. The FDIC assesses premiums based on an assessment rate and an assessment base. An insured depository institution’s assessment base considers average consolidated total assets, less the average tangible equity of the insured depository institution during the assessment period. The assessment base of custody banks is adjusted to exclude certain liquid assets from total average assets. To qualify as a custody bank, certain institutional eligibility criteria must be met. The Bank qualifies as a custody bank for this purpose. The FDIC utilizes a risk-based system to determine each institution’s assessment rate. The assessment rate schedule can change from time to time at the discretion of the FDIC, subject to certain limits.

The FDIC, as required under the FDIA, established a plan in September 2020 to restore the DIF reserve ratio to meet or exceed the statutory minimum of 1.35% within eight years. The FDIC determined that the reserve ratio exceeded the statutory minimum as of June 30, 2025. Consequently, the FDIC stopped operating under a Restoration Plan as of the third quarter of 2025. The FDIC maintained the long-term target reserve ratio for the DIF, referred to as the Designated Reserve Ratio, at 2.00% for 2025.

In 2023, the FDIC issued a final rule to implement a special assessment to recoup losses to the DIF associated with bank failures in the first half of 2023. The assessment base for the special assessment is equal to an insured depository institution’s estimated uninsured domestic office deposits reported as of December 31, 2022, adjusted to exclude the first $5 billion of uninsured domestic office deposits. The special assessment will be collected over eight quarterly assessment periods, beginning in 2024. In December 2025, the FDIC issued an interim final rule that would reduce the payment rate applied to the assessment base for the eighth and final collection quarter. Under the interim final rule, upon termination of the receiverships, the FDIC will either provide an offset to regular quarterly deposit insurance assessments for insured depository institutions subject to the special assessment if the amount collected exceeds losses or collect from insured depository institutions subject to the special assessment a one-time final shortfall special assessment if losses at the termination of the receiverships exceed the amount collected. In conjunction with the FDIC special assessment rules, Northern Trust has accrued a total of $83.4 million.

COMMUNITY REINVESTMENT ACT

The Bank is subject to the CRA. The CRA and the regulations issued thereunder are intended to encourage banks to help meet the credit needs of their service areas, including low- and moderate-income neighborhoods and persons, consistent with the safe and sound operations of the banks. For purposes of the CRA, the Bank operates under a “wholesale” designation granted by the Federal Reserve Board and fulfills its CRA obligations by making qualified investments for the purposes of community development. The Bank received an “outstanding” CRA rating from the Federal Reserve Board in its most recent CRA examination.

DATA PRIVACY AND SECURITY

Federal law establishes a minimum federal standard of financial privacy by, among other provisions, requiring financial institutions to adopt, disclose, and enforce privacy policies with respect to consumer information, setting limitations on disclosure to third parties of consumer information, setting standards for protecting client information and preventing unlawful access to such information, and requiring notice of data breaches in certain circumstances. For example, the Federal Trade Commission has the authority to regulate and enforce against unfair or deceptive acts or practices in or affecting commerce, including acts and practices with respect to data privacy and security, and the Gramm-Leach-Bliley Act regulates the confidentiality and security of customer information obtained by financial institutions and certain other types of financial services businesses.

8 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

Most U.S. states, the EU and other non-U.S. jurisdictions also have adopted their own statutes and/or regulations concerning data privacy and security and requiring notification of data breaches―for example, the General Data Protection Regulation (GDPR) in Europe and its equivalent in the UK (UK GDPR), the Personal Information Protection Law (PIPL) in China, and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, CCPA) in the United States. Similar laws are in effect or being implemented in other jurisdictions in which we operate across the globe. The GDPR is designed to harmonize data privacy and security laws across the European Economic Area (EEA) and to protect EEA citizens’ data privacy and security. The GDPR imposes stringent operational requirements on both data controllers and data processors and has extraterritorial effect as its scope includes all data controllers and processors outside the EEA whose processing activities relate to the offering of goods or services to, or monitoring the behavior of, EEA individuals. Organizations that violate certain provisions of the GDPR could be fined up to €20 million or 4% of their annual worldwide revenue for the preceding fiscal year, whichever is greater. The Digital Omnibus Regulation Proposal published in 2025 is expected to introduce technical amendments to a large corpus of digital legislation in Europe, including the EU GDPR. The UK GDPR, which operates in conjunction with other local data privacy requirements, as reformed in 2025 through the adoption of the UK Data Use and Access Act 2025, also provides for data protection requirements equivalent to the EU GDPR.

In 2025, Northern Trust received regulatory approval in Europe to use Binding Corporate Rules as a legal mechanism supporting transfers of data from Northern Trust group entities in the EEA to other group entities outside the EEA. Northern Trust expects to launch the EU Binding Corporate Rules in 2026. The Corporation has adopted and disseminated privacy policies and communicates required information relating to financial privacy and data security in accordance with applicable law.

In the United States, the CCPA broadly defines personal information and substantially increases the rights of California residents to understand how their personal information is collected, used, and otherwise processed by commercial businesses, such as affording them the right to access and request deletion of their information and to opt out of certain sharing and sales of personal information. The CCPA includes a private right of action (permitting lawsuits to be brought by private individuals instead of the state Attorney General or other government actor for certain breaches), and contemplates civil penalties of up to $2,500 for each violation and up to $7,500 for each intentional violation.

In addition, several states have enacted, or are considering enacting, comprehensive data privacy laws similar to the CCPA. Similarly, Regulation S-P amendments introduced by the SEC create additional obligations for broker-dealers and registered investment advisers to protect customer information, including timely notification of incidents to impacted individuals. These laws apply, or will apply, in addition to laws that already exist in all 50 U.S. states that require businesses to provide notice under certain circumstances to consumers whose personal information has been disclosed as a result of a data breach. Moreover, the U.S. Congress has considered, and will likely in the future consider, various proposals for more comprehensive data privacy and security legislation, to which we may be subject if enacted.

ARTIFICIAL INTELLIGENCE

Northern Trust uses a variety of machine learning and artificial intelligence (AI) solutions to process transactional activity more efficiently and to mitigate risk. These uses currently include, among others, digitizing documents, detecting anomalous, fraudulent transactions and training services teams on operational processes.

Regulation of AI is rapidly evolving in the U.S. and worldwide as legislators and regulators are increasingly focused on these powerful emerging technologies. The technologies underlying AI and its uses are subject to a variety of laws and regulations, including intellectual property, privacy, data protection, cybersecurity, consumer protection, competition, and equal opportunity laws, and are expected to be subject to increased regulation and new laws or new applications of existing laws and regulations. Additionally, several U.S. states, including Colorado and California, have passed or are continuing to propose laws and regulations that govern various facets and uses of AI, including consequential decisions, and, in Europe, the EU’s Artificial Intelligence Act (EU AI Act) entered into force on August 1, 2024.

Northern Trust has certain processes and controls in place designed to mitigate the risks associated with the use of AI solutions, including monitoring the development and applicability of such evolving laws and regulations, and has taken, and will continue to take steps designed to comply with laws and regulations applicable to Northern Trust’s use of AI.

CONSUMER LAWS AND REGULATIONS

The Corporation’s banking subsidiaries are subject to certain federal and state laws and regulations designed to protect consumers in transactions with banks. Failure to comply with these laws and regulations could lead to substantial penalties, operating restrictions and reputational damage to the financial institution. Consumer laws and regulations are enforced by the Consumer Financial Protection Bureau (CFPB) and other federal and state regulators.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 9

NON-U.S. REGULATION

Northern Trust is subject to the laws and regulatory authorities of the jurisdictions in which its non-U.S. branches and subsidiaries operate. For example, branches and subsidiaries conducting banking and asset servicing businesses in the UK are authorized to do so pursuant to the UK Financial Services and Markets Act 2000. They are authorized by the Prudential Regulation Authority (PRA) and/or the Financial Conduct Authority (FCA). The PRA and FCA exercise broad supervisory and disciplinary powers that include the power to revoke temporarily or permanently authorization to conduct a regulated business upon breach of the relevant regulations, impose capital requirements, suspend registered employees, and impose censures and fines on both regulated businesses and their regulated employees. Additionally, the Bank is licensed as a foreign authorized deposit-taking institution in Australia under the Banking Act (Australia) and as a wholesale bank in Singapore under the Banking Act (Singapore) and as a result is subject to the supervision of the Australian Prudential Regulation Authority and the Monetary Authority of Singapore, respectively.

Northern Trust’s European branches and subsidiaries are subject to the laws and regulatory authorities of the EU and the member states in which they are domiciled. For example, Northern Trust Global Services SE, as an EU-domiciled credit institution in Luxembourg, is subject to the prudential supervision of the ECB and the CSSF. Moreover, Northern Trust’s non-EU branches and subsidiaries conducting financial services activities in the EU may fall within the scope of the laws of the EU and, given the increasing extraterritorial effect of EU legislation, non-EU branches and subsidiaries may still fall within the scope of EU law if they transact outside of the EU with EU clients.

Since January 31, 2020, the UK has not been a member of the EU. EU legislation as it applied to the UK on December 31, 2020 is a part of UK domestic legislation, under the control of the UK’s parliament. Most UK law relevant to the Corporation and its subsidiaries is still closely aligned with the EU legislative framework in place in December 2020. However, in 2022, the UK government proposed legislation that makes significant reforms to the UK’s financial services regulations. In particular, the Financial Services and Markets Act 2023 includes measures that will, over time, revoke retained EU law relating to financial services. In addition, the UK government announced a package of post-Brexit reforms to drive growth and competitiveness in the financial services sector. The Financial Services and Markets Act 2023 along with these other reforms may directly and indirectly impact the Corporation.

The following items provide a brief description of certain key regulatory requirements in the EU and the UK relevant to the Corporation and its subsidiaries, in addition to the BRRD and GDPR and UK GDPR discussed under “Resolution Planning” and “Data Privacy and Security,” respectively, above.

EU and UK Prudential Regulatory Frameworks. The EU Capital Requirements Directive of June 26, 2013 (CRD) and the EU Capital Requirements Regulation of June 26, 2013 (CRR) set out the framework for prudential regulation of credit institutions in the EU, including, among other things, capital and liquidity requirements, leverage, and disclosure and reporting. CRR and CRD have been subject to extensive amendments relating to the leverage ratio, the net stable funding ratio, large exposures, and market and counterparty credit risk, enhancing the resiliency of EU banks to potential future economic shocks, the transition to climate neutrality and finalizing the implementation of the Basel III agreement. Since June 26, 2021, investment firms under the recast Markets in Financial Instruments Directive (MIFID) have been subject to a new prudential regime under the EU Investment Firm Directive and Investment Firm Regulation. In April 2021, the Financial Services Act came into force in the UK establishing among other things, (i) a framework for the new investment firm prudential framework to apply in the UK and (ii) the UK implementation of Basel III standards, including amendments to CRR as implemented into UK law following the withdrawal from the EU. UK and EU branches and subsidiaries of the Corporation may also be subject to local rules on outsourcing and operational resilience. In June 2024, the texts of CRR III and CRD VI, were formally published in the Official Journal of the EU. Through these legislative measures, the EU will implement the Basel III accord into EU law. These regulations affect the capital and liquidity requirements of European banking entities and restrict the provision of prescribed core banking services, including lending, the provision of guarantees and commitments, and the taking of deposits or other borrowing, by non-EU entities to EU entities, except where these services are provided through an authorized EU branch or where an exemption applies. The new regime is being phased in gradually until 2027.

Markets Regulation. MIFID (which came into force in 2018), the linked Markets in Financial Instruments Regulation (MIFIR), and the European Market Infrastructure Regulation 648/2012 (EMIR) are the primary pieces of EU legislation which regulate, among other things, trading in derivative and securities markets, transaction reporting, investor protection, clearing and risk mitigation. MIFID, MIFIR and EMIR, with applicable amendments, now form part of UK law under the legislation implemented when the UK left the EU. Reforms incorporated into the UK version of MIFIR have been made by the UK Financial Services and Markets Act 2023. The reforms impact, among other things, the share trading obligation and derivatives trading obligation.

10 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

Central Securities Depositories Regulation. On September 17, 2014, the EU Central Securities Depositories Regulation (CSDR) entered into force (subject to a number of transitional provisions). The CSDR aims principally to ensure that transactions between buyers and sellers of dematerialized securities are settled in a safe and timely manner by introducing common securities settlement standards across the EU. Key features of the CSDR include shorter settlement periods, settlement discipline measures (including mandatory cash penalties and “buy-ins” for settlement fails and settlement fails reporting) and an obligation regarding dematerialization for most securities. In the UK, the Financial Services and Markets Act 2023 grants to the Bank of England new rule-making powers in relation to central securities depositories (CSD).

Securities Financing Transactions and Reuse of Collateral Regulation. On November 25, 2015, the EU adopted a regulation on securities financing transactions and reuse of collateral (SFTR) as part of its approach to addressing shadow banking. The regulation includes provisions for enhanced transparency and reporting of securities financing transactions. The SFTR entered into force on January 12, 2016. The reporting obligations under the SFTR were phased in over several periods through January 11, 2021.

Benchmarks Regulation. On January 1, 2018, the EU Benchmarks Regulation (BMR) became applicable in all EU member states. The principal objectives of the BMR are to restore investor confidence in the accuracy, robustness and integrity of indices used as benchmarks in financial instruments and financial contracts or to measure the performance of investment funds, and the benchmark-setting process itself. The BMR aims to achieve these objectives by ensuring that benchmarks are not subject to conflicts of interest, are used appropriately, and reflect the actual market or economic reality they are intended to measure. The BMR has been incorporated into UK law following the withdrawal from the EU, with applicable amendments.

Sustainable Finance Disclosure Regulations. On December 29, 2019, the EU Sustainable Finance Disclosure Regulations (SFDR) entered into force. SFDR aims to prevent “greenwashing” (conveying a misleading or false impression a product is more environmentally favorable than it actually is) by requiring disclosure of how sustainability risks and environmental, social and governance (ESG) factors are part of the investment and business processes of asset managers. Mandatory disclosures are required to be published at product and manager levels in a variety of ways, including on websites, in pre-contractual documents (e.g., prospectuses) and in annual reports. In November 2025, the European Commission published a proposal for a regulation amending the SFDR. If implemented, the Commission’s proposal will, among other things, introduce a new approach to categorizing financial products that will replace the existing Article 6, Article 8, and Article 9 product categories. In October 2021, the UK government announced that it will launch its own consultation with stakeholders on sustainable finance disclosures rules for certain UK market participants and certain investment products. On October 25, 2022, the FCA issued a consultation paper on new measures for a UK regime on sustainability disclosure requirements and investment labels. The new measures, including an anti-greenwashing rule, product labels and product naming and marketing rules, entered into force during the course of 2024.

Taxonomy Regulation. On July 12, 2020, Regulation (EU) 2020/852 (Taxonomy Regulations) entered into force. The Taxonomy Regulations are part of the EU’s recent measures designed to encourage environmentally sustainable investment decision making and introduce a technical framework to ascertain how sustainable an economic activity is. The Taxonomy Regulations apply to financial market participants including MiFID firms, Undertakings for the Collective Investment in Transferable Securities (UCITS) management companies, and alternative investment fund managers, and will require them to make further entity, pre-contractual and periodic disclosures. The UK government previously consulted on implementing its own “green” taxonomy for guiding companies and investors on “green” investments, similar to the EU regime. However, in July 2025 the UK government announced that it decided not to proceed with a UK “green” taxonomy.

Deposit Guarantee Scheme. Eligible deposits held with EU credit institutions and certain other financial entities are subject to the recast Deposit Guarantee Schemes Directive (DGSD) implemented in 2014. It required EU member states to introduce legislation establishing at least one deposit guarantee scheme (DGS). A DGS which is established and recognized in one member state is obliged to cover the depositors (up to certain prescribed amounts) at branches of the same institution in other EU member states. In the UK, the Financial Services Compensation Scheme is the national DGS for the protection and reimbursement of depositors of failed financial institutions.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 11

EU Money Laundering Directive. On July 9, 2018, the Fifth EU Money Laundering Directive (MLD5) entered into force. MLD5 was required to be transposed into local law by EU member states by January 10, 2020 and introduced the following key changes to the previous EU AML regime: (i) EU member states must ensure that registers of ultimate beneficial owners of companies and other legal entities are accessible to the general public; (ii) the previous AML regime was extended to additional service providers, such as electronic wallet providers, virtual currency exchange service providers, and art dealers, and further specifications regarding the scope of application of MLD5 with respect to tax advisors and estate agents were provided; (iii) the threshold for identifying holders of prepaid cards was lowered to €150; and (iv) EU member states were required to implement enhanced due diligence measures to monitor suspicious transactions involving high-risk countries more strictly. The UK government transposed MLD5 into UK law and, therefore, the UK anti-money laundering regime is currently broadly aligned with the EU. On December 7, 2022, the Council of the EU agreed its position on AML regulation through the Sixth EU Money Laundering Directive. The new rules will extend to, among other items, the entire crypto-asset sector, third-party intermediaries, persons trading in precious metals, precious stones and cultural goods. EU member states have until 2027 to transpose the Sixth EU Money Laundering Directive into national legislation.

Shareholder Rights Directive. On May 17, 2017, the recast Shareholder Rights Directive (EU) 2017/828 was published (SRD II). Member states of the EU were required to bring into force the laws, regulations and administrative provisions necessary to comply with the Directive by June 10, 2019. SRD was designed to establish requirements in relation to the exercise of shareholder rights and, recognizing that shares are often held through complex chains of intermediaries, SRD II is designed to improve mechanisms for the identification of shareholders by companies, as well as improve the transmission of information along the chain of intermediaries to facilitate the exercise of shareholder rights. Non-EU intermediaries are required to comply with the requirements if they provide services with respect to shares of companies that have their registered office in the EU. SRD II has been incorporated into UK law and remains largely aligned with the EU.

EU AI Act. The final text of the EU AI Act was published in the Official Journal of the European Union in July 2024 and entered into force in August 2024. Most of the EU AI Act’s substantive obligations will apply following a two-year implementation period, beginning in August 2026. The EU AI Act will have a significant impact on organizations that develop, deploy, or use AI systems both inside and outside the EU. Its application depends on the nature of the AI systems, the specific use case, and the role of the relevant actor (including whether the organization is acting as an AI provider or deployer). The EU AI Act adopts a risk-based regulatory framework. Certain AI systems used for specified purposes are prohibited outright. Other AI systems will be classified as high risk and subject to extensive pre- and post-market compliance obligations. The EU AI Act also contains dedicated provisions governing general-purpose AI models. AI systems posting lesser regulatory risk are generally subject only to limited transparency obligations, particularly where they interact with individuals. Administrative fines may be imposed for non-compliance and will vary based on the nature of the infringement and the size of the organization, including by reference to worldwide annual turnover.

In addition to the above, the Bank’s and the Corporation’s subsidiary banks located outside the United States are subject to regulatory capital requirements in the jurisdictions in which they operate. As of December 31, 2025, each of our non-U.S. banking subsidiaries had capital ratios above their specified minimum requirements.

Human Capital Management

Our talent is our greatest asset and a core enabler of our strategy. Empowering our employees is central to our talent vision. Northern Trust employed approximately 23,800 full-time equivalent employees as of December 31, 2025. The regional breakout of our employee base is 42% Asia-Pacific, 41% North America, and 17% Europe, Middle East, and Africa.

Our Board of Directors, including the Human Capital and Compensation Committee, oversees our human capital management strategies and practices. Northern Trust’s senior leadership provides regular human capital reporting and updates to the Board and its Committees to support this oversight.

THE EMPLOYEE EXPERIENCE

We elevate the employee experience from recruitment to retirement by investing in three core areas: professional development, rewarding performance, and strengthening workforce and operational resiliency. By fostering an environment where our employees thrive, we ensure that our workforce is fully engaged, motivated, celebrated, and equipped to drive our strategy.

To support this effort, we continue to invest in our Human Capital Management System to help streamline manual processes, enable dynamic workforce analytics, and unlock new capabilities through a central manager workspace that helps managers make informed decisions and gain deeper insights into their teams.

Our culture influences how we behave as an organization and unites us across businesses, geographies, and functions. Embedded in our culture are five behaviors to help us deliver on our strategic objectives: relentlessly client-centric, constantly managing risk, respectfully candid, intentionally inclusive, and always accountable.

12 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

PROFESSIONAL DEVELOPMENT

From internships to executive development, our goal is to help our employees excel in their current roles and acquire new skills for future growth. Through Northern Trust University, we deliver comprehensive professional and functional training programs designed to equip our employees at every stage of their careers. Our performance management practices promote high performance across the company and are aligned to our strategy from goal setting to evaluation.

Our managers play a pivotal role in advancing Northern Trust’s strategic goals through their teams. Northern Trust is intentionally investing in manager development through a comprehensive program that addresses both enterprise and individual priorities aligned to four areas of focus: Tools and Resources, Development, Engagement, and Talent Processes. We believe managers need not only the skills to lead effectively but also the right ecosystem to succeed.

REWARDING PERFORMANCE

Recognizing and rewarding the contributions of our employees is critical to their continued success. We offer a variety of awards and recognition programs tailored to different opportunities and achievements. Our Celebrate Great platform provides real-time, peer-to-peer recognition, reinforcing everyday moments of appreciation. Our in-person celebrations, such as the Quarter Century Club, which honors our long-tenured employees, and the Chairman’s Awards, which recognize outstanding individual and team achievements further reinforce a culture of performance and appreciation.

We ensure our employees are compensated fairly by aligning their total compensation with market competitive pay for their roles, experience, and performance. Our total compensation includes base salaries, performance-linked incentive compensation, and comprehensive benefits designed to meet the needs of our employees and their families.

WORKFORCE & OPERATIONAL RESILIENCY

Our operating model is designed to reinforce the strength of our control framework, foster enterprise change management, provide robust governance and oversight, accelerate scalable growth, and leverage and develop our talent. To align with our strategy and position the Corporation for future success, new leaders are appointed from our internal talent pool as well as recruited externally to bring in new skills and expertise.

Planning for leadership resiliency is a core component of our talent strategy. We identify and develop leaders with the necessary skills to execute business strategies and have documented succession plans for leadership resiliency roles.

Our well-being programs support employees and help maintain an inclusive and resilient environment. Through these programs, we enhance employee engagement, reduce workforce risks, and build an adaptive, high-performing culture.

In 2025, over 87% of our employees participated in our annual employee engagement survey which is a crucial tool for understanding and meeting the needs of our employees and driving engagement and retention. The survey results are reviewed by the Board and discussed in leadership meetings, reflecting our dedication to continuous improvement.

Embedded in our engagement survey is an inclusion index which is a gauge to understand our employees’ sense of belonging and their ability to contribute to the success of the firm. We are committed to fostering an inclusive workplace that aligns with the Corporation’s mission, values, goals, business practices, and all applicable laws.

Available Information

Through the Corporation’s website at www.northerntrust.com, the Corporation makes available free of charge its Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and all other reports and all amendments to those reports filed or furnished pursuant to Section 13(a) or 15(d) of the Securities Exchange Act of 1934, as amended (Exchange Act), as soon as reasonably practicable after it files such material with, or furnishes such material to, the SEC. The contents of the Corporation’s website, the website of the SEC at www.SEC.gov or any other website referenced herein are not a part of this Annual Report on Form 10-K.

ITEM 1A - RISK FACTORS

In the normal course of our business activities, we are exposed to a variety of risks. The following discussion sets forth the material risk factors that we have identified. Although we discuss these risk factors primarily in the context of their potential effects on our business, financial condition or results of operations, these risks could have other possible adverse consequences, including those described below. Additional risks beyond those discussed below, elsewhere in this Annual Report on Form 10-K or in other of our reports filed with, or furnished to, the SEC also could affect us adversely. Further, we cannot assure you that the risk factors herein or elsewhere in our other reports address all potential risks that we may face.

For a discussion of the risks and uncertainties that may affect our future results, see “Forward-Looking Statements” included in Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations.”

Summary

Our business, financial condition or results of operations may be materially and adversely affected by various risk types and considerations, including market risks, operational risks, credit risks, liquidity risks, regulatory and legal risks, strategic risks, and other risks, including as a result of the following:

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 13

Market Risks

•We are dependent on fee-based business for a majority of our revenues, which may be affected adversely by market volatility, a downturn in economic conditions, underperformance and/or negative trends in investment preferences.

•Changes in interest rates can affect our earnings negatively.

•Changes in the monetary, trade and other policies of various regulatory authorities, central banks, governments and international agencies may reduce our earnings and affect our growth prospects negatively.

•Macroeconomic conditions and uncertainty in the global economy, including the financial stability of various regions or countries across the globe, including the risk of defaults on sovereign debt and related stresses on financial markets, could have a significant adverse effect on our earnings.

•Declines in the value of securities held in our investment portfolio can affect us negatively.

•Changes in a number of particular market conditions, including in foreign currency rates, cross-border investing activity and the demand for borrowing or lending securities, could affect our earnings negatively.

Operational Risks

•We are subject to many types of operational risks that could affect our earnings negatively.

•We are highly dependent on information technology systems, and networks, many of which are operated by third parties, and any failures of, or disruptions to, our or such third parties’ technological systems or networks could materially and adversely affect our business.

•Breaches of our security measures, including, but not limited to, those resulting from cyber-attacks, or other information security incidents may result in losses.

•Errors, breakdowns in controls or other mistakes in the provision of services to clients or in carrying out transactions for our own account can subject us to liability, result in losses or have a negative effect on our earnings in other ways.

•Our dependence on technology, and the need to update frequently our technology infrastructure, exposes us to risks that also can result in losses.

•A failure or circumvention of our controls and procedures could have a material adverse effect on our business, financial condition and results of operations.

•Failure of any of our third-party vendors (or their vendors) to perform can result in losses.

•We are subject to certain risks inherent in operating globally which may affect our business adversely.

•Failure to control our costs and expenses adequately could affect our earnings negatively.

•Pandemics, natural disasters, global climate change, acts of terrorism, geopolitical tensions, and global conflicts may have a negative impact on our business and operations.

Credit Risks

•Failure to evaluate accurately the prospects for repayment when we extend credit or maintain an adequate allowance for credit losses can result in losses or the need to make additional provisions for credit losses, both of which reduce our earnings.

•Market volatility and/or weak economic conditions can result in losses or the need for additional provisions for credit losses, both of which reduce our earnings.

•The failure or perceived weakness of any of our significant counterparties could expose us to loss.

Liquidity Risks

•If we do not manage our liquidity effectively, our business could suffer.

•If the Bank is unable to supply the Corporation with funds over time, the Corporation could be unable to meet its various obligations.

•We may need to raise additional capital in the future, which may not be available to us or may only be available on unfavorable terms.

•Any downgrades in our credit ratings, or an actual or perceived reduction in our financial strength, could affect our borrowing costs, capital costs and liquidity adversely.

14 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

Regulatory and Legal Risks

•Failure to comply with regulations and/or supervisory expectations can result in penalties and regulatory constraints that restrict our ability to grow or even conduct our business, or that reduce earnings.

•We are subject to extensive and evolving government regulation and supervision that impacts our operations. Changes by the U.S. and other governments to laws, regulations and policies applicable to the financial services industry may heighten the challenges we face and make regulatory compliance more difficult and costly.

•We are subject to complex and evolving laws, regulations, rules, standards and contractual obligations regarding data privacy and security, which could increase the cost of doing business, compliance risks and potential liability.

•We may be impacted adversely by claims or litigation, including claims or litigation relating to our fiduciary responsibilities.

•We may be impacted adversely by supervisory and/or regulatory enforcement matters.

•We may fail to set aside adequate reserves for, or otherwise underestimate our liability relating to, pending and threatened claims, with a negative effect on our earnings.

•The ultimate impact on us of regulatory divergence between the United Kingdom and the European Union remains uncertain.

•If we fail to comply with legal standards, we could incur liability to our clients or lose clients, which could affect our earnings negatively.

Strategic Risks

•If we are not able to attract, retain and motivate personnel, our business could be negatively affected.

•If we do not develop and execute strategic plans successfully, our growth may be impacted negatively.

•We are subject to intense competition in all aspects of our businesses, which could have a negative effect on our ability to maintain satisfactory prices and grow our earnings.

•Damage to our reputation could have a direct and negative effect on our ability to compete, grow and generate revenue.

•We need to invest in innovation constantly, and the inability or failure to do so may affect our businesses and earnings negatively.

•Failure to understand or appreciate fully the risks associated with development or delivery of new product and service offerings may affect our businesses and earnings negatively.

•Our success with large, complex clients requires an understanding of the market and legal, regulatory and accounting standards in various jurisdictions.

•We may take actions to maintain client satisfaction that result in losses or reduced earnings.

•Our operations, businesses and clients could be materially adversely affected by the effects of climate change or concerns related thereto.

Other Risks

•The systems and models we employ to analyze, monitor and mitigate risks, as well as for other business purposes, are inherently limited, may not be effective in all cases and, in any case, cannot eliminate all risks that we face.

•Changes in tax laws and interpretations and challenges to our tax positions may affect our earnings negatively.

•Changes in accounting standards may be difficult to predict and could have a material impact on our consolidated financial statements.

•Our ability to return capital to stockholders is subject to the discretion of our Board of Directors and may be limited by U.S. banking laws and regulations, applicable provisions of Delaware law, or our failure to pay full and timely dividends on our preferred stock and the terms of our outstanding debt.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 15

Market Risks

We are dependent on fee-based business for a majority of our revenues, which may be affected adversely by market volatility, a downturn in economic conditions, underperformance and/or negative trends in investment preferences.

Our principal operational focus is on fee-based business, which is distinct from commercial banking institutions that earn most of their revenues from loans and other traditional interest-generating products and services. Fees for many of our products and services are based on the market value of assets under management, custody or administration; the volume of transactions processed; securities lending volume and spreads; fees for other services rendered; and in certain businesses, fees calculated as a percentage of our clients’ earnings, all of which may be impacted negatively by market volatility, a downturn in economic conditions, underperformance and/or negative trends in investment preferences. For example, downturns in equity markets and decreases in the value of debt-related investments resulting from market disruption, illiquidity or other factors historically have reduced the valuations of the assets we manage or service for others, which generally impacted our earnings negatively. Further, although we do not hold, invest in, or custody cryptocurrency assets, the markets in which they trade are highly volatile and volatility in these markets may impact the markets for other assets that we hold, invest in, or custody, which could also impact our fees or financial condition. Market volatility and/or weak economic conditions also could affect wealth creation, investment preferences, trading activities, and savings patterns, which in turn could impact demand for certain products and services that we provide.

Our earnings also could be affected by poor investment returns or changes in our clients’ investment preferences driven by factors beyond market volatility or weak economic conditions. Poor absolute or relative investment performance in funds or client accounts that we manage or in investment products that we design or provide could result in declines in the market values of portfolios that we manage and/or administer and could affect our ability to retain existing assets and to attract new clients or additional assets from existing clients. For example, from time to time in the past, outflows from certain of our products driven by relative investment performance or other factors adversely impacted our overall fees derived from assets that we manage. Broader changes in our clients’ investment preferences that lead to less investment in mutual funds or other collective funds, such as the shift in investment preference to lower fee products, could also impact our earnings negatively.

Changes in interest rates could affect our earnings negatively.

The direction and level of interest rates are important factors in our earnings. Interest rate changes could affect the interest earned on assets differently than interest paid on liabilities. In response to rising inflation, the Federal Reserve Board increased interest rates from historically low levels during 2022 and 2023. While a rising interest rate environment generally has had a positive effect on our net interest margin, in some circumstances, a rise in interest rates has affected us negatively, and could again in the future affect us negatively. For example, the rapid increases in interest rates during 2022 and 2023 adversely impacted the value of certain of our investment securities, and consequently, our capital, liquidity, and earnings. Additionally, higher interest rates historically have caused, and could in the future cause: market volatility and downturns in equity markets, resulting in a decrease in the valuations of the assets we manage or service for others, which generally impact our earnings negatively; our clients to transfer funds into investments with higher rates of return, resulting in decreased deposit levels and higher fund or account redemptions; our borrowers to experience difficulties in making higher interest payments, resulting in increased credit costs, provisions for loan and lease losses and charge-offs; reduced bond and fixed income fund liquidity, resulting in lower performance, yields and fees; or higher funding costs.

Conversely, low-interest-rate environments generally result in a compressed net interest margin and also have a negative impact on our fees earned on certain of our products. For example, in the past we waived certain fees associated with money market funds due to the low level of short-term interest rates. Low net interest margins and fee waivers each negatively impact our earnings.

Although we have policies and procedures in place to assess and mitigate potential impacts of interest rate risks, if our assumptions about any number of variables are incorrect, these policies and procedures to mitigate risk may be ineffective, which could impact earnings negatively.

Please see “Market Risk” in the “Risk Management” section included in Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” for a more detailed discussion of interest rate and market risks we face.

16 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

Changes in the monetary, trade and other policies of various regulatory authorities, central banks, governments and international agencies may reduce our earnings and affect our growth prospects negatively.

The monetary, trade and other policies of U.S. and international governments, agencies and regulatory bodies have a significant impact on economic conditions and overall financial market performance. For example, the Federal Reserve Board regulates the supply of money and credit in the U.S. through quantitative tightening and/or easing, and its policies determine in large part the level of interest rates and our cost of funds for lending and investing, and play a role in contributing to or moderating levels of inflation, all of which meaningfully impact our earnings. Further, the Federal Reserve Board’s policies can affect our borrowers by increasing interest rates or making sources of funding less available, which may increase the risk that borrowers fail to repay their loans from us. Changes in monetary, trade and other governmental policies are beyond our control and can be difficult to predict, and we cannot determine the ultimate effect that any such changes would have upon our business, financial condition or results of operations.

Macroeconomic conditions and uncertainty in the global economy, including the financial stability of various regions or countries across the globe, including the risk of defaults on sovereign debt and related stresses on financial markets, could have a significant adverse effect on our earnings.

Risks and concerns about the financial stability of various regions or countries across the globe could have a detrimental impact on economic and market conditions in these or other markets across the world. Foreign market volatility and economic disruptions have affected, and may in the future affect, consumer confidence levels and spending, international trade policy, personal bankruptcy rates, levels of incurrence of and default on consumer debt, and home prices. Additionally, financial markets may be adversely affected by the liquidity or capital deficiencies (actual or perceived) of financial institutions and related industry and government actions, the outbreak of hostilities or political and governmental instability, terrorism, political or civil unrest, stricter immigration policies, public health epidemics or pandemics, sovereign debt downgrades or debt crises, or other geopolitical events. For example, developments related to the U.S. federal debt ceiling, including the possibility of a government shutdown, default by the U.S. government on its debt obligations, or related credit-rating downgrades, could have adverse effects on the broader economy, disrupt access to capital markets, and contribute to, or worsen, an economic recession. The cumulative effect of uncertain business conditions or economic challenges faced in various foreign markets, including fiscal or monetary concerns, economic downturns and the possibility of a recession in some jurisdictions, other economic factors (including changes in tariffs, foreign currency exchange rates, interest rates and changes to tax laws or the application or enforcement practices of such laws), or volatility or lack of confidence in the financial markets may adversely affect certain portions of our business, financial condition, and results of operations.

Declines in the value of securities held in our investment portfolio could affect us negatively.

Our investment securities portfolio represents a greater proportion, and our loan portfolio represents a smaller proportion, of our total consolidated assets in comparison to many other financial institutions. The value of securities available for sale and held to maturity within our investment portfolio, which is generally determined based upon market values available from third-party sources, have fluctuated, and may continue in the future to fluctuate, as a result of market volatility and economic or financial market conditions, including interest rates. Declines in the value of securities held in our investment portfolio negatively impact our levels of capital, liquidity, and, to the extent we realize losses, earnings. Although we have policies and procedures in place to assess and mitigate potential impacts of market risks, including hedging-related strategies, those policies and procedures are inherently limited because they cannot anticipate the existence or future development of currently unanticipated or unknown risks. Accordingly, market risks have, from time to time, negatively affected the value of securities held in our investment portfolio and in the future we could suffer additional adverse effects as a result of our failure to anticipate and manage these risks properly.

Changes in a number of particular market conditions, including in foreign currency exchange rates, cross-border investing activity and the demand for borrowing or lending securities, could affect our earnings negatively.

We provide foreign exchange services to our clients, primarily in connection with our Asset Servicing business. Foreign currency volatility influences our foreign exchange trading income as does the level of client activity. Foreign currency volatility and changes in client activity may result in reduced foreign exchange trading income. Fluctuations in exchange rates could raise the potential for losses resulting from foreign currency trading positions where aggregate obligations to purchase and sell a currency other than the U.S. dollar do not offset each other or offset each other in different time periods. We also are exposed to non-trading foreign currency risk as a result of our holdings of non-U.S. dollar denominated assets and liabilities, investments in non-U.S. subsidiaries, and future non-U.S. dollar denominated revenue and expense.

We have policies and procedures in place to assess and mitigate potential impacts of foreign exchange risks, including hedging-related strategies. Any failure or circumvention of our procedures to mitigate risk could impact earnings negatively. Please see “Market Risk” in the “Risk Management” section included in Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” for a more detailed discussion of market risks we face.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 17

In addition, in past periods, reductions in the volatility of currency-trading markets, the level of cross-border investing activity, and the demand for borrowing securities or willingness to lend such securities have affected our earnings from activities such as foreign exchange trading and securities lending negatively. If these conditions occur again in the future, our earnings from these activities could be affected negatively. In certain of our businesses, such as securities lending, our fee is calculated as a percentage of our clients’ earnings, such that market and other factors that reduce our clients’ earnings from investments or trading activities also reduce our revenues.

Operational Risks

We are subject to many types of operational risks that could affect our earnings negatively.

We regularly assess and monitor operational risk in our businesses. Despite our efforts to assess and monitor operational risk, our risk management program may not be effective in all cases. Factors that could impact our operations and expose us to risks varying in size, scale and scope, include:

•failures of technological systems or networks or breaches of security measures, including, but not limited to, those resulting from computer viruses, cyber-attacks or other information security incidents;

•human errors or omissions, including failures to comply with applicable laws or corporate policies and procedures;

•theft, fraud or misappropriation of assets, whether arising from the intentional actions of internal personnel or external third parties;

•defects or interruptions in computer or communications systems;

•breakdowns in processesand internal controls; over-reliance on manual processesand controls, which are less scalable than automated processesand controls;

•failures of the systems and facilities that support our operations;

•failure of any third-party vendor to properly execute the processes on which Northern Trust relies;

•unsuccessful or difficult implementation of computer systems upgrades;

•defects in product design or delivery;

•difficulty in accurately pricing assets, which can be aggravated by market volatility and illiquidity and lack of reliable pricing from third-party vendors;

•negative developments in relationships with key counterparties, third-party vendors, employees or associates in our day-to-day operations; and

•external events that are wholly or partially beyond our control, such as pandemics, geopolitical events, political or social unrest, natural disasters or acts of terrorism.

While we have in place many controls and business continuity plans designed to address many of these factors, these plans may not operate successfully to mitigate these risks effectively. We also may fail to identify or fully understand the implications and risks associated with changes in the financial markets or our businesses—particularly as our geographic footprint, product pipeline and client needs and expectations evolve—and consequently fail to enhance our controls and business continuity plans to address those changes in an adequate or timely fashion. If our controls and business continuity plans do not address the factors noted above and operate to mitigate the associated risks successfully, such factors may have a negative impact on our business (including operational resilience), financial condition or results of operations. In addition, an important aspect of managing our operational risk is creating a risk culture in which all employees fully understand the inherent risk in our business and the importance of managing risk as it relates to their job functions. We continue to enhance our risk management program to support our risk culture, ensuring that it is sustainable and appropriate for our role as a major financial institution. Nonetheless, if we fail to provide the appropriate environment that sensitizes all of our employees to managing risk, our business could be impacted adversely. Please see “Other Risks” in this “Risk Factors” section for further description of risks associated with the systems and models we employ to analyze, monitor and mitigate risks.

We are highly dependent on information technology systems and networks, many of which are operated by third parties, and any failures of, or disruptions to, our or such third parties’ technological systems or networks could materially and adversely affect our business.

Our business is dependent on our and third parties’ information technology systems and networks. Any failure, interruption or breach in the security of any such systems or networks could severely disrupt our operations and could subject us to liability claims, harm our reputation, interrupt our operations, or otherwise adversely affect our business, financial condition or results of operations.

Additionally, our computer, communications, data processing, networks, backup, business continuity or other operating, information or technology systems, including those that we outsource to providers, may fail to operate properly or become disabled, overloaded or damaged as a result of a number of factors, including events that are wholly or partially beyond our control, which could have a negative effect on our ability to conduct our business activities.

18 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

The third parties with which we do business also are susceptible to the foregoing risks (including regarding the third parties with which they are similarly interconnected or on which they otherwise rely), and our or their business operations and activities may therefore be affected adversely, perhaps materially, by failures, disruptions, terminations, software bugs or errors, natural disasters or malfeasance by, or attacks or constraints on, one or more financial, technology, infrastructure or government institutions or intermediaries with whom we or they are interconnected or conduct business.

Our business interruption insurance may be inadequate to compensate us for all losses that may occur as a result of any system, network or operational failure or disruption.

Breaches of our security measures, including, but not limited to, those resulting from cyber-attacksor other information security incidents, may result in losses.

Our systems involve the storage, transmission and other processing of clients’ and our personal, proprietary, confidential and sensitive information, and security breaches, including cyber-attacks or other information security incidents, have previously exposed us and could in the future expose us to theft, loss, destruction, gathering, monitoring, dissemination, misappropriation, misuse, alteration, or unauthorized disclosure of or unauthorized access to this information. Despite our implementation of a variety of security measures, our computer systems, networks, and data, including clients’ or our personal, proprietary, confidential and sensitive information, could be subject to cyber-attacks or other information security incidents, such as, among other things, from physical and electronic break-ins or unauthorized tampering, theft, malware and computer virus attacks, ransomware attacks, social engineering attacks (including phishing and vishing attacks), credential stuffing, account takeovers, insider threats or denial-of-service attacks. Our security measures also may be breached due to the actions of outside parties, employee error, failure of our controls with respect to access to our systems, malfeasance or otherwise. Any failure, interruption or breach in the security of our systems could severely disrupt our operations and could subject us to liability claims, harm our reputation, interrupt our operations, or otherwise adversely affect our business, financial condition or results of operations.

Data privacy and security risks for large financial institutions like us are significant in part because of the evolving proliferation of new technologies, the use of internet-based solutions, mobile devices, and cloud technologies to conduct financial transactions and the increased sophistication and rapidly evolving techniques of hackers, terrorists, organized crime and other external parties, including foreign state actors and state-sponsored actors, any of which may see their effectiveness enhanced by the use of AI. Data privacy and security risks also may derive from fraud or malice on the part of our employees or third parties, or may result from human error, software bugs or errors, server malfunctions, software or hardware failure or other technological failure. If we fail to continue to upgrade our technology infrastructure to ensure effective data privacy and security relative to the type, size and complexity of our operations, we could become more vulnerable to cyber-attacks and other information security incidents and, consequently, subject to significant regulatory penalties and reputational damage. Also, the trend in the past several years toward a hybrid work environment that includes a combination of in-office and remote work creates a broader attack surface for, and increases potential vulnerabilities from, cyber threats.

While we generally conduct security assessments on third-party vendors, we cannot be certain that their information security protocols are sufficient to withstand a cyber-attack or other information security incident. Some of our vendors may store or have access to our data and may not have effective controls, processes, or practices to protect our information from loss, unauthorized disclosure, unauthorized use or misappropriation, cyber-attacks or other information security incidents. In addition, our clients often use personal devices, such as computers, smart phones and tablets, which are particularly vulnerable to loss and theft, as well as third parties with whom they share information used for authentication, to access our systems and networks and manage their accounts, which may heighten the risk of system failures, interruptions or security breaches.

Moreover, the increased use of mobile and cloud technologies could heighten these and other operational risks. Reliance on mobile or cloud technology or any failure by mobile technology and cloud service providers to adequately safeguard their systems and networks and prevent cyber-attacks or other information security incidents could disrupt our operations or the operations of our or their service providers and result in misappropriation, corruption or loss of personal, confidential, proprietary, or other sensitive information or the inability to conduct ordinary business operations. In addition, there is a risk that encryption and other protective measures may be circumvented, particularly to the extent that new computing technologies increase the speed and computing power available. A vulnerability in our service providers’ software or systems, a failure of our service providers’ safeguards, policies or procedures, or a cyber-attack or other information security incident affecting any of these third parties could harm our business.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 19

In recent years, several financial services firms suffered successful cyber-attacks launched both domestically and from abroad, resulting in the disruption of services to clients, loss or misappropriation of sensitive or private information, and reputational harm. We and our clients have been, and expect to continue to be, subject to a wide variety of cyber-attacks and other similar threats, including computer viruses, ransomware and other malicious code, distributed denial-of-service attacks, and phishing and vishing attacks, and it is possible that we could suffer material losses resulting from a breach. Because the techniques used to obtain unauthorized access, disable or degrade service or sabotage systems and networks change frequently and often are not recognized until launched against a target, we may be unable to anticipate these techniques, to implement adequate preventative measures, or to address them until they are discovered. In addition, successful cyber-attacks may persist for an extended period of time before being detected. Because any investigation of an information security incident would be inherently unpredictable, the extent of a particular information security incident and the path of investigating the incident may not be immediately clear. It may take a significant amount of time before such an investigation can be completed and full and reliable information about the incident is known. While such an investigation is ongoing, we may not necessarily know the extent of the harm or how best to remediate it, certain errors or actions could be repeated or compounded before they are discovered and remediated, and communication to the public, regulators, clients and other stakeholders may be inaccurate, any or all of which could further increase the costs and consequences of an information security incident.

We could be the subject of legal claims or proceedings related to information security incidents, including regulatory investigations and other legal actions, carrying the potential for damages, fines, sanctions or other penalties, injunctive relief requiring costly compliance measures and reputational damage. Further, the market perception of the effectiveness of our information security measures could be harmed, our reputation could suffer and we could lose clients in conjunction with security incidents, each of which could have a negative effect on our business, financial condition and results of operations. A breach of our security also may affect adversely our ability to effect transactions, service our clients, manage our exposure to risk or expand our business. An event that results in the loss of information also may require us to reconstruct lost data or reimburse clients for data and credit monitoring services, which could be costly and have a negative impact on our business and reputation. Although we maintain insurance coverage in the event of information theft, damage, or destruction from cyber-attacks or other information security incidents, there can be no assurance that liabilities or losses we may incur will be covered under such policies, that the amount of insurance will be adequate to cover such losses, that insurance will continue to be available to us on economically reasonable terms, or at all, or that our insurer will not deny coverage as to any future claim.

Further, even if not directed at us, attacks on financial or other institutions important to the overall functioning of the financial system or on our counterparties could affect, directly or indirectly, aspects of our business.

Errors, breakdowns in controls or other mistakes in the provision of services to clients or in carrying out transactions for our own account can subject us to liability, result in losses or have a negative effect on our earnings in other ways.

In our asset servicing, investment management, fiduciary administration and other business activities, we effect or process transactions for clients and for ourselves that involve very large amounts of money. Failure to manage or mitigate operational risks properly can have adverse consequences, and increased volatility in the financial markets may increase the magnitude of resulting losses. Further, remote working and other modified business practices initiated in recent years, combined with the increasing sophistication and frequency of potential cyber-attacks and other information security incidents, have heightened our operational and execution risk. Given the high volume of transactions we process, errors that affect earnings may be repeated or compounded before they are discovered and corrected.

20 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

Our dependence on technology, and the need to update frequently our technology infrastructure, exposes us to risks that also can result in losses.

Our businesses depend on information technology infrastructure, both internal and external, to record and process, among other things, a large volume of increasingly complex transactions and other data, in many currencies, on a daily basis, across numerous and diverse markets and jurisdictions. Due to our dependence on technology and the important role it plays in our business operations, combined with the increasing sophistication and frequency of potential cyber-attacks and other information security incidents, we must constantly improve and update our information technology infrastructure. Upgrading, replacing, and modernizing these systems can require significant resources and often involves implementation, integration and security risks that could cause financial, reputational, and operational harm. In recent years, there has been an acceleration in the transition from traditional to digital financial services and heightened customer expectations in this area, and this transition may require us to invest greater resources in technological advancements. Failure to ensure adequate review and consideration of critical business and regulatory issues prior to and during the introduction and deployment of key technological systems or networks or failure to align operational capabilities adequately with evolving client commitments and expectations may have a negative impact on our results of operations. The failure to respond properly to, and invest in, changes and advancements in technology and/or to compete for and retain employees with the necessary technical skills and expertise could limit our ability to attract and retain clients, prevent us from offering products and services comparable to those offered by our competitors, inhibit our ability to meet regulatory requirements or otherwise have a material adverse effect on our operations.

A failure or circumvention of our controls and procedures could have a material adverse effect on our business, financial condition and results of operations.

We regularly review and update our internal controls, disclosure controls and procedures, and corporate governance policies and procedures. Any system of controls, however well designed and operated, is based in part on certain assumptions and can provide only reasonable, not absolute, assurances that the objectives of the system will be met. Any failure or circumvention of our controls and procedures or failure to comply with regulations related to controls and procedures could have a material adverse effect on our business, financial condition and results of operations. If we identify material weaknesses in our internal control over financial reporting or are otherwise required to restate our financial statements, we could be required to implement expensive and time-consuming remedial measures and could lose investor confidence in the accuracy and completeness of our financial reports. In addition, there are risks that individuals, either employees or contractors, consciously circumvent established control mechanisms by, for example, exceeding trading or investment management limitations, or committing fraud.

Failure of any of our third-party vendors (or their vendors)to perform can result in losses.

Third-party vendors provide key components of our business operations such as data processing, recording and monitoring transactions, online banking interfaces and services, and network access. Our use of third-party vendors exposes us to the risk that such vendors (or their vendors) may not comply with their servicing and other contractual obligations, including with respect to indemnification and information security, and to the risk that we may not satisfy applicable regulatory responsibilities regarding the management and oversight of third parties and outsourcing providers. While we have established risk management processes and continuity plans, any disruptions in service from a key vendor for any reason or poor performance of services have in the past and could in the future have a negative effect on our ability to deliver products and services to our clients and conduct our business. Replacing these third-party vendors or performing the tasks they perform for ourselves has in the past and could in the future create significant delay and expense.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 21

We are subject to certain risks inherent in operating globally which may affect our business adversely.

In conducting our U.S. and non-U.S. business, we are subject to risks of loss and adverse economic impacts from various unfavorable political, economic, legal, public health, or other developments, including social or political instability, changes in governmental policies or policies of central banks, expropriation, nationalization, confiscation of assets, price controls, capital controls, exchange controls, unfavorable tax rate changes, tax court rulings and changes in laws and regulations. Less mature and often less regulated business and investment environments heighten these risks in various emerging markets. Our non-U.S. operations accounted for 30% of our revenue in 2025. Our non-U.S. businesses are subject to extensive regulation by various non-U.S. regulators, including governments, securities exchanges, central banks and other regulatory bodies in the jurisdictions in which those businesses operate. In many countries, the laws and regulations applicable to the financial services industry are uncertain and evolving and may be applied with extra scrutiny to foreign companies. Moreover, the regulatory and supervisory standards and expectations in one jurisdiction may not conform with standards or expectations in other jurisdictions. Even within a particular jurisdiction, the standards and expectations of multiple supervisory agencies exercising authority over our affairs may not be harmonized fully. Accordingly, it may be difficult for us to determine the exact requirements of local laws in every market or manage our relationships with multiple regulators in various jurisdictions. Our inability to remain in compliance with local laws in a particular market and manage our relationships with regulators could have an adverse effect not only on our businesses in that market but also on our reputation generally. The failure to mitigate properly such risks or the failure of our operating infrastructure to support such international activities could result in operational failures and regulatory fines or sanctions, which could affect our business and results of operations adversely.

We actively strive to optimize our geographic footprint. This optimization may occur by establishing operations in lower-cost locations or by outsourcing to third-party vendors in various jurisdictions. These efforts expose us to the risk that we may not maintain service quality, control or effective management within these operations. In addition, we are exposed to the relevant macroeconomic, political, public health, and similar risks generally involved in doing business in those jurisdictions. The increased elements of risk that arise from conducting certain operating processes in some jurisdictions could lead to an increase in reputational risk. During periods of transition, greater operational risk and client concern exist with respect to maintaining a high level of service delivery.

In addition, we are subject in our global operations to rules and regulations relating to corrupt and illegal payments, money laundering, and laws that prohibit us from doing business with certain individuals, groups and countries, such as the U.S. Foreign Corrupt Practices Act, the USA PATRIOT Act, the UK Bribery Act, and economic sanctions and embargo programs administered by the U.S. Office of Foreign Assets Control and similar agencies worldwide. While we have invested and continue to invest significant resources in training and in compliance monitoring, the geographic diversity of our operations, employees, clients and customers, as well as the vendors and other third parties with whom we deal, presents the risk that we may be found in violation of such rules, regulations, laws or programs and any such violation could subject us to significant penalties or affect our reputation adversely.

Failure to control our costs and expenses adequately could affect our earnings negatively.

Our success in controlling the costs and expenses of our business operations also impacts operating results. Through various parts of our business strategy, we aim to produce efficiencies in operations that help reduce and control costs and expenses, including the costs of losses associated with operating risks attributable to servicing and managing financial assets. Increased expenses have affected—and a failure to control our costs and expenses in the future, whether as a result of inflation or otherwise, could affect—our earnings negatively.

22 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

Pandemics, natural disasters, global climate change, acts of terrorism, geopolitical tensions, and global conflicts may have a negative impact on our business and operations.

Pandemics, natural disasters, global climate change, acts of terrorism, geopolitical tensions, global conflicts or other similar events, as well as government actions or other restrictions in connection with such events, have had in the past, or may in the future have, a negative impact on our business and operations. While we have in place business continuity plans, such events may still damage our facilities, disrupt or delay the normal operations of our business (including communications and technology), result in harm to or cause travel limitations on our employees, impose significant compliance costs with new financial and economic sanctions regimes, and have a similar impact on our clients, suppliers, third-party vendors and counterparties. For example, in some jurisdictions such as the Russian Federation, local market restrictions, laws, sanctions programs or government intervention inhibit our clients’ and our ability to access or transfer cash or securities held for clients through subcustodians and clearing agencies. When such client deposit liabilities are on our consolidated balance sheet, we maintain a corresponding amount of cash on deposit with the subcustodian or clearing agency, which increases our credit exposure to that entity and can accumulate over time based upon distributions on, or other activities related to, our clients’ assets. If the subcustodian or clearing agency were to become insolvent in circumstances not involving expropriation of assets or other sovereign risk events and/or factors or events beyond our reasonable control that excuse performance under force majeure or other contractual provisions, the risk of loss on such cash on deposit may potentially be incurred by us. As of December 31, 2025, we held cash that accumulates in relation to Russian securities with our subcustodian and/or clearing agencies for the benefit of certain clients in our Asset Servicing business which are subject to restrictions that inhibit our ability to access or transfer such deposits, and which amount is expected to increase significantly over time as long as the sanctions and other relevant restrictions remain in effect.

The foregoing or similar events also could impact us negatively to the extent that they result in reduced capital markets activity, lower asset price levels, or disruptions in general economic activity in the U.S. or abroad, or in financial market settlement functions. In addition, these or similar events may impact economic growth negatively, which could have an adverse effect on our business and operations, and may have other adverse effects on us in ways that we are unable to predict. Please see “Strategic Risks” in this “Risk Factors” section for further description of risks associated with climate change.

Credit Risks

Failure to evaluate accurately the prospects for repayment when we extend credit or maintain an adequate allowance for credit losses can result in losses or the need to make additional provisions for credit losses, both of which reduce our earnings.

We evaluate extensions of credit before we make them and provide for credit risks based on our assessment of the credit losses inherent in our loan and securities portfolio, including undrawn credit commitments. This process requires us to make difficult and complex judgments, including forecasts of economic conditions through the life of these credit exposures. Challenges associated with our credit risk assessments include identifying the proper factors to be used in assessments and accurately estimating the impacts of those factors. Allowances that prove to be inadequate may require us to realize increased provisions for credit losses or write down the value of certain assets on our balance sheet, which result in losses and/or increased provisions for credit losses and in turn would affect earnings negatively.

Market volatility and/or weak economic conditions can result in losses or the need for additional provisions for credit losses, both of which reduce our earnings.

Credit risk levels and our earnings can be affected by market volatility and/or weakness in the economy in general and in the particular locales in which we extend credit, a deterioration in credit quality, or a reduced demand for credit. Adverse changes in the financial performance or condition of our borrowers resulting from market volatility, elevated interest rates, and/or weakened economic conditions could impact the borrowers’ abilities to repay outstanding loans, which could in turn impact our financial condition and results of operations negatively.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 23

The failure or perceived weakness of any of our significant counterparties could expose us to loss.

The financial markets are characterized by extensive interconnections among financial institutions, including banks, broker-dealers, collective investment funds and insurance companies. As a result of these interconnections, we and many of our clients have counterparty exposure to other financial institutions. This counterparty exposure presents risks to us and to our clients because the failure or perceived weakness of any of our counterparties has the potential to expose us to risk of loss. Instability in the financial markets, or in certain countries where these counterparties are domiciled, has resulted historically in some financial institutions becoming less creditworthy. During such periods of instability, we are exposed to increased counterparty risks, both as principal and in our capacity as agent for our clients. Changes in market perception of the financial strength of particular financial institutions can occur rapidly, are often based upon a variety of factors and can be difficult to predict. In addition, the criteria for and manner of governmental support of financial institutions and other economically important sectors remain uncertain. Further, the consolidation of financial services firms and the failures of other financial institutions has in the past increased, and may in the future increase, the concentration of our counterparty risk. These risks are heightened by the fact that our operating model relies on the use of unaffiliated sub-custodians to a greater degree than certain of our competitors that have banking operations in more jurisdictions than we do. We are not able to mitigate all of our and our clients’ counterparty credit risk. If a significant individual counterparty defaults on an obligation to us, we could incur financial losses that have a material and adverse effect on our business, financial condition and results of operations.

Liquidity Risks

If we do not manage our liquidity effectively, our business could suffer.

Liquidity is essential for the operation of our business. Market conditions, unforeseen outflows of funds or other events could have a negative effect on our level or cost of funding, affecting our ongoing ability to accommodate liability maturities and deposit withdrawals, meet contractual obligations, and fund new business transactions at a reasonable cost and in a timely manner. If our access to stable and low-cost sources of funding, such as customer deposits, is reduced, we may need to use alternative funding, which could be more expensive or of limited availability. Further evolution in the regulatory requirements relating to liquidity and risk management also may impact us negatively. Additional regulations may impose more stringent liquidity requirements for large financial institutions, including the Corporation and the Bank. Given the overlap and complex interactions of these regulations with other regulatory changes, the full impact of the adopted and proposed regulations remains uncertain until their full implementation.

In addition, a significant portion of our business involves providing certain services to large, complex clients, which, by their nature, require substantial liquidity. Our failure to manage successfully the liquidity and balance sheet issues attendant to this portion of our business may have a negative impact on our ability to meet client needs and grow.

We also manage investment products that, while not obligations of ours, may be exposed to liquidity risks. These products, such as money market and other short-term investments provide clients a right to the return of cash or assets on limited notice. If clients demand a return of their cash or assets, particularly on limited notice, and these investment products do not have the liquidity to support those demands, we could be forced to sell investment securities held by these investment products at unfavorable prices potentially damaging our reputation with the investment community.

For more information on regulations and other regulatory changes relating to liquidity, see “Supervision and Regulation—Liquidity Standards” in Item 1, “Business.” Any substantial, unexpected or prolonged changes in the level or cost of liquidity could affect our business adversely.

If the Bank is unable to supply the Corporation with funds over time, the Corporation could be unable to meet its various obligations.

The Corporation is a legal entity separate and distinct from the Bank and the Corporation’s other subsidiaries. The Corporation relies in large part on dividends paid to it by the Bank to meet its obligations and to pay dividends to stockholders of the Corporation. There are various legal limitations on the extent to which the Bank and the Corporation’s other subsidiaries can supply funds to the Corporation by dividend or otherwise. Dividend payments by the Bank to the Corporation in the future will require continued generation of earnings by the Bank and could require regulatory approval under certain circumstances. For more information on dividend restrictions, see “Supervision and Regulation—Payment of Dividends” in Item 1, “Business.”

24 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

We may need to raise additional capital in the future, which may not be available to us or may only be available on unfavorable terms.

We may need to raise additional capital to provide sufficient resources to meet our business needs and commitments, to accommodate the transaction and cash management needs of our clients, to maintain our credit ratings in response to regulatory changes, including capital rules, or for other purposes. However, our ability to access the capital markets, if needed, will depend on a number of factors, including the state of the financial markets. Heightened interest rates, disruptions in financial markets, negative perceptions of our business or our financial strength, or other factors may impact our ability to raise additional capital, if needed, on terms favorable to us. For example, in the event of future turmoil in the banking industry or other idiosyncratic events, there is no guarantee that the U.S. government will invoke the systemic risk exception, create additional liquidity programs, or take any other action to stabilize the banking industry or provide liquidity. Any diminished ability to access short-term funding or capital markets to raise additional capital, if needed, could subject us to liability, restrict our ability to grow, require us to take actions that would affect our earnings negatively or otherwise affect our business and our ability to implement our business plan, capital plan and strategic goals adversely.

Any downgrades in our credit ratings, or an actual or perceived reduction in our financial strength, could affect our borrowing costs, capital costs and liquidity adversely.

Rating agencies publish credit ratings and outlooks on our creditworthiness and that of our obligations or securities, including Long-Term Debt, short-term borrowings, preferred stock and other securities. Our credit ratings are subject to ongoing review by the rating agencies and thus may change from time to time based on the agencies’ evaluation of a number of factors, including our financial strength, performance, prospects and operations as well as factors not under our control, such as rating-agency-specific criteria or frameworks for our industry or certain security types, which are subject to revision from time to time, and conditions affecting the financial services industry generally.

Downgrades in our credit ratings may affect our borrowing costs, our capital costs and our ability to raise capital and, in turn, our liquidity adversely. A failure to maintain an acceptable credit rating also may preclude us from being competitive in certain products. Additionally, our counterparties, as well as our clients, rely on our financial strength and stability and evaluate the risks of doing business with us. If we experience diminished financial strength or stability, actual or perceived, a decline in our stock price or a reduced credit rating, our counterparties may be less willing to enter into transactions, secured or unsecured, with us, our clients may reduce or place limits on the level of services we provide them or seek other service providers, or our prospective clients may select other service providers, all of which may have other adverse effects on our business.

The risk that we may be perceived as less creditworthy relative to other market participants is higher in a market environment in which the consolidation, and in some instances failure, of financial institutions, including major global financial institutions, could result in a smaller number of larger counterparties and competitors. If our counterparties perceive us to be a less viable counterparty, our ability to enter into financial transactions on terms acceptable to us or our clients, on our or our clients’ behalf, will be compromised materially. If our clients reduce their deposits with us or select other service providers for all or a portion of the services we provide to them, our revenues will decrease accordingly.

Regulatory and Legal Risks

Failure to comply with regulations and/or supervisory expectations could result in penalties and regulatory constraints that restrict our ability to grow or even conduct our business, or that reduce earnings.

Virtually every aspect of our business in the United States and around the world is regulated by domestic and foreign governmental agencies that have broad supervisory powers and the ability to impose sanctions. These regulations cover a variety of matters, including prohibited activities, required capital levels, resolution planning, human trafficking and modern slavery, and data privacy and security. Some of these requirements are directed specifically at protecting depositors of the Bank, the U.S. DIF and the banking system as a whole. Regulatory violations or the failure to meet formal or informal commitments made to regulators could generate penalties, require corrective actions that increase costs of conducting business, result in limitations on our ability to conduct business, restrict our ability to expand or impact our reputation adversely. Failure to obtain necessary approvals from regulatory agencies, whether formal or based upon supervisory expectations, on a timely basis could affect proposed business opportunities and results of operations adversely. Similarly, changes in laws or failure to comply with new requirements or with future changes in laws or regulations could impact our results of operations and financial condition negatively.

2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 25

We are subject to extensive and evolving government regulation and supervision that impacts our operations. Changes by the U.S. and other governments to laws, regulations and policies applicable to the financial services industry could heighten the challenges we face and make regulatory compliance more difficult and costly.

We operate in a highly regulated environment, and are subject to a comprehensive statutory and regulatory regime affecting all aspects of our business and operations, including oversight by governmental agencies both inside and outside the United States. Various regulatory bodies have demonstrated heightened scrutiny of financial institutions through many regulatory initiatives. These initiatives have increased compliance costs and regulatory risks and may lead to financial and reputational damage in the event of a compliance violation, even if the failure to comply was inadvertent or reflected a difference in interpretation. Although we have programs in place, including policies, training and various forms of monitoring, designed to ensure compliance with legislative and regulatory requirements, we cannot provide assurance that these programs and policies are or will be adequate to identify and manage internal and external compliance risks. For example, our business may be adversely impacted by actual or alleged misconduct by an employee or other negative outcomes caused by human error. In addition, changes to statutes, regulations or regulatory and supervisory policies or their interpretation or implementation and the continued heightening of regulatory and supervisory requirements could affect us in substantial and unpredictable ways. For example, governments and regulators could take actions that increase intervention in the normal operation of our businesses and the businesses of our competitors in the financial services industry, and these likely would involve additional legislative and regulatory requirements imposed on banks and other financial services companies. Any such actions could increase compliance costs and regulatory risks, lead to financial and reputational damage in the event of a violation, affect our ability to compete successfully or limit how we conduct our business, and also could impact the nature and level of competition in the industry in unpredictable ways. The full scope and impact of possible legislative or regulatory changes and the extent of regulatory activity is uncertain and difficult to predict. Congress and the presidential administration have introduced and may continue to introduce changes in the laws or policies applicable to us and the agencies that regulate us, including their interpretations of rules and guidelines. These changes may subject financial institutions like us to change in regulation, supervision and enforcement that are difficult to predict and uncertain for a period of time and may create the possibility of significant impacts on business activity in the United States and globally, including impacts relating to the trade policies (including tariffs) of the United States or other countries. Some of the regulations finalized in the prior administration that are applicable to financial institutions were modified, rescinded or withdrawn or are subject to reevaluation, creating further uncertainty.

Moreover, political and policy goals of elected and appointed officials may change over time, which could impact the rulemaking, supervision, examination, and enforcement priorities of the federal banking agencies. It is possible the expected changed in law, regulation and policy do not occur or are reversed subsequently, or the regulatory measures that are ultimately enacted deliver significant competitive advantages to financial services that are structured differently or serve different markets than us.

Further, the regulatory framework for AI and similar technologies, and automated decision making, is changing rapidly. It is possible that new laws and regulations will be adopted in the U.S. and in non-U.S. jurisdictions, or that existing laws and regulations may be interpreted, in ways that would affect the operation of our products and services and the way in which we use AI and similar technologies. For more information on regulations regarding AI, see “Supervision and Regulation” in Item 1, “Business.”

The evolving regulatory and supervisory environment and uncertainty about the timing and scope of future laws, regulations and policies may contribute to decisions we may make to suspend, reduce or withdraw from existing businesses, activities or initiatives, which may result in potential lost revenue or significant restructuring or related costs or exposures. We also face the risk of becoming subject to new or more stringent requirements in connection with the introduction of new regulations or modification of existing regulations, which could require us to hold more capital or liquidity or have other adverse effects on our businesses or profitability. For more information on these proposals, see “Supervision and Regulation” in Item 1, “Business.”

In addition, regulatory responses in connection with severe market downturns or unforeseen stress events could alter or disrupt our planned future strategies and actions. Adverse developments affecting the overall strength and soundness of other financial institutions, the financial services industry as a whole and the general economic climate and the U.S. Treasury market could have a negative impact on perceptions about the strength and soundness of our business even if we are not subject to the same adverse developments. For example, during 2023, the FDIC took control and was appointed receiver of Silicon Valley Bank, Signature Bank, and First Republic Bank. The failure of other banks and financial institutions and the measures taken by governments and regulators in response to these events could adversely impact our business, financial condition and results of operations.

26 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION

We are subject to complex and evolving laws, regulations, rules, standards and contractual obligations regarding data privacy and security, which could increase the cost of doing business, compliance risks and potential liability.

We are subject to complex and evolving laws, regulations, rules, standards and contractual obligations governing data privacy and security, which may differ and potentially conflict, in various jurisdictions, and any failure to comply with these laws, regulations, rules, standards and contractual obligations could expose us to liability and/or reputational damage. Regulators globally are introducing the potential for greater monetary fines on institutions that suffer from breaches leading to the loss, misappropriation or unauthorized access, use or disclosure of personal, confidential, proprietary or sensitive information. Most U.S. states, the EU and other non-U.S. jurisdictions also have adopted their own statutes and/or regulations concerning data privacy and security and notification of data breaches. These and other changes in laws or regulations associated with the enhanced protection of personal and other types of information could greatly increase compliance costs, the size of potential fines related to the protection of such information and reporting obligations in the case of cyber-attacks or other information security incidents. Compliance with these laws, regulations, rules and standards may require us to change and continuously update our policies, procedures and technology controls for information security, which could, among other things, make us more vulnerable to operational failures and to monetary penalties for breach of such laws, regulations, rules and standards.

Legal developments in the EEA and the UK also have created complexity and uncertainty regarding processing and transfers of personal data from the EEA and the UK to the U.S. and other so-called third countries outside the EEA and the UK that have not been determined by the relevant data protection authorities to provide an adequate level of protection for privacy rights. Importantly, significant monetary fines have been imposed since the introduction of such stringent privacy laws in the EU and the UK and regulatory expectations of governance and accountability with respect to the protection of personal, proprietary, confidential and sensitive information continue to expand and evolve. For more information on regulations regarding data privacy and security, see “Supervision and Regulation” in Item 1, “Business.”

Further, while we strive to publish and prominently display privacy notices and policies that are accurate, comprehensive, and compliant with applicable laws, regulations, rules and industry standards, we cannot ensure that our privacy policies and other statements regarding our practices will be considered sufficient to protect us from claims, proceedings, liability or adverse publicity relating to data privacy and security, considering the fast-evolving regulatory landscape. Although we endeavor to comply with our privacy policies, we may at times fail to do so or be alleged to have failed to do so. The publication of our privacy policies and other documentation that provide promises and assurances about data privacy and security can subject us to potential government or legal action if they are found to be deceptive, unfair, or misrepresentative of our actual practices. Any concerns about our data privacy and security practices, even if unfounded, could damage our reputation and adversely affect our business.

Any failure or perceived failure by us to comply with our privacy policies, or applicable data privacy and security laws, regulations, rules, standards or contractual obligations, or any compromise of security that results in unauthorized access to, or unauthorized loss, destruction, use, modification, acquisition, disclosure, release or transfer of personal information, may result in requirements to modify or cease certain operations or practices, the expenditure of substantial costs, time and other resources, proceedings or actions against us, legal liability, governmental investigations, enforcement actions, claims, fines, judgments, awards, penalties, sanctions and costly litigation (including class actions). Any of the foregoing could harm our reputation, distract our management and technical personnel, increase our costs of doing business, adversely affect the demand for our products and services, and ultimately result in the imposition of liability, any of which could have a material adverse effect on our business, financial condition and results of operations.

We may be impacted adversely by claims or litigation, including claims or litigation relating to our fiduciary responsibilities.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2025-12-31, filed 2026-02-24 · accession 0000073124-26-000016

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 23 headings are on that chain and 19 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.