Essay

Defining Bad Before the Campaign Runs: The Governance Problem That Financial Services Keeps Discovering Too Late

10 June 2026 · Digital Risk · No.02

Campaign risk is one of the least examined governance problems in financial services, and the reason is structural rather than accidental.

Risk attention follows established categories. Credit risk has a discipline, a vocabulary, and a committee. So do operational risk and technology risk. Campaign risk sits in the space between compliance, marketing, and product, which in practice often means that it sits in no single governance lane clearly. A campaign is a commercial act with a marketing surface and a product underneath, and each of those functions assumes that the risk question belongs to one of the others. By the time anyone reviews a campaign specifically for risk, it has usually been designed, approved commercially, and scheduled. The review can adjust the wording. It can rarely change the thing.

The more useful question is not whether a given campaign is compliant. It is whether the institution has defined, before the campaign runs, what bad actually means.

Bad is not one thing

The instinct in most institutions is to treat a campaign as good until something forces a different conclusion. That instinct collapses several distinct kinds of harm into a single vague category, and the collapse is where the governance gap lives.

Bad for a campaign is at least three separate things, and they do not move together. The first is bad for the customer: an offer that creates a commitment that the customer cannot meet, or promotes a product that they do not actually understand. The second is bad for the institution: a campaign that creates regulatory exposure, or a conduct question that cannot be answered cleanly once it has been asked. The third is bad for the relationship between the institution and its regulator: a campaign that tests the boundary of a supervisory expectation in a way that sets a precedent that the institution will later regret.

These three failures are genuinely different. A campaign can be excellent for the customer and still create a precedent problem with the regulator. It can be perfectly compliant and still push a product onto people who should not take it. Treating them as one undifferentiated notion of bad means the institution never quite defines any of them, and undefined harm cannot be designed against.

The category that gets left out

Most campaign governance frameworks, where they exist at all, are built around the first two kinds of bad. Customer harm has a conduct vocabulary. Institutional exposure has a compliance and legal vocabulary. Both can be reviewed, even if the review comes late.

The third kind is the one that tends to be implicit rather than defined. The relationship between an institution and its regulator is not governed only by written rules. It is governed by a history of expectations, signals, and precedents that accumulate over time. A campaign can comply with every written requirement and still spend down that relationship, by testing a boundary that the regulator had assumed would be respected, or by establishing a practice that becomes harder to walk back the moment a competitor copies it. This kind of harm rarely appears in a campaign review, because it is not a rule violation. It is a judgment about how a permitted action will be read by a supervisor who is paying attention.

Leaving this category implicit is how institutions end up surprised by a regulatory reaction to a campaign that broke no rule. The campaign was compliant. It was also unwise in a way the framework had no slot for, because the framework only checked the kinds of bad it had names for.

The common failure across all three

Whatever combination of harms a framework covers, the recurring failure is the same, and it is not a failure of analysis. It is a failure of timing.

In most cases the institution is capable of identifying that a campaign is bad. It simply does so retrospectively. The harm is discovered when a complaint arrives, when a regulator asks a question, or when the campaign has already gone out at scale and the consequence is no longer hypothetical. The institution had the capacity to see the problem. It deployed that capacity after the campaign ran rather than before it was designed, because the governance touchpoint was placed at the end of the process rather than the beginning.

This is the part that makes campaign risk feel intractable. It is not that institutions lack the judgment to tell good campaigns from bad ones. It is that the judgment is applied at the moment when it can only diagnose, not prevent. By the time risk has meaningful visibility, the design decisions that determined whether the campaign was good or bad have already been made by people who were not asking the risk question.

Campaign governance as design, not review

Campaign risk governance done well is a design discipline, not a review process, and the difference is not cosmetic.

A review process accepts a finished campaign and asks whether it passes. A design discipline puts the definition of bad at the front, before the campaign is built, so that the people designing it know in advance what they are designing against. If an institution has decided, ahead of time, what customer harm, institutional exposure, and regulatory precedent each look like for a given product, the campaign can be shaped to avoid them while shaping is still possible. The same judgment that would otherwise arrive too late arrives early enough to matter.

This requires moving the risk question upstream, into the part of the process where a campaign is still an idea rather than a plan. It requires the institution to treat the definition of bad as something produced before the work, not discovered after the fact. And it requires accepting that the most valuable campaign risk work leaves no visible trace, because its success is a harm that never happened, and therefore never gets counted.

None of this makes campaign risk a solved problem. It relocates the problem to the place where it can actually be solved: the design stage, where the question of what bad means can still change what gets built. The institutions that ask that question early are not slower to market. They are simply choosing to know the answer before the campaign runs rather than after.

The question worth sitting with: at what point in campaign development does risk gain meaningful input into the design, and not just the approval, and how few institutions could answer it honestly.

I write about governance, risk, and the decisions institutions find hardest to make. If this is relevant to a problem you are working through, reach me at aan@asifahmednoor.com.

← Back to writing