I. SCOPE AND PURPOSE
The Risk Committees (together, “Committee,” unless usage or context dictates otherwise) are established by the Board of Directors of United Services Automobile Association ("USAA") and by the Board of Directors (together with the USAA Board of Directors, “Board”) of USAA Federal Savings Bank (the “Bank,” and together with USAA, the “Company”) and shall have, as its sole and exclusive function, oversight of, and responsibility for holding management accountable for, managing risk within the Company, including the establishment and adherence to the USAA Risk Management Framework and the Bank Risk Governance Framework, as well as the strategies, policies, and governance practices established by management to identify, assess, measure, and manage risk that will foster an appropriate risk management culture. In executing its responsibilities, the Committee will set clear and consistent direction regarding the Company's risk management strategy and risk appetite. Jointly with the Chief Executive Officer and the Bank President, respectively, and in accordance with the provisions below, the Committee has oversight responsibility for the USAA Chief Risk Officer and the Bank Chief Risk Officer (together with the USAA Chief Risk Officer, the “Chief Risk Officers”).
II. RESPONSIBILITIES
The duties and responsibilities of the Committee include the following:
A. Company Risk Management Frameworks and Governance Documents
- Review and approve material changes and oversee operation of the USAA Risk Management Framework considering (i) applicable regulatory or legal requirements and guidance, (ii) the evolution of industry risk management practices, (iii) USAA's structure, risk profile, complexity, activities, and size, (iv) establishment of a strong risk management culture, and (v) alignment to strategic, capital and liquidity plans.
- Review and approve material changes to and oversee operation of the Bank Risk Governance Framework considering (i) applicable regulatory or legal requirements and guidance, (ii) the evolution of industry risk management practices, (iii) the Bank’s structure, risk profile, complexity, activities, and size, (iv) establishment of a strong risk management culture, and (v) alignment to strategic, capital and liquidity plans.
- Review and approve, as necessary, significant risk management frameworks, policies, and governance practices.
B. Risk Appetite and Risk Profile
- Annually review and approve the Company's risk appetite statements, ensuring alignment to the Company's strategic, capital and liquidity plans.
- Annually review and approve the Company's risk appetite metrics, and corresponding risk appetite and triggers associated with those metrics, based on the size and volatility of risks and any material changes in the Company's business model, strategy, risk profile, or market conditions.
- Review and discuss the Company's risk profile, including but not limited to (i) significant financial and other risk exposures that could adversely affect the Company, members or its employees, (ii) risk trends and concentrations in the Company's portfolios and major risk concentrations, and (iii) the steps management has taken or plans to take to monitor, mitigate or control, and report such risk exposures, trends and concentrations.
- Review and challenge management's assumptions, decisions, and recommendations that could cause USAA's or the Bank’s risk profile to exceed its risk appetite or jeopardize the safety and soundness of USAA and/or the Bank.
C. Risk Program Oversight
- Oversee the USAA's association-wide and the Bank’s risk management functions, including (i) the strategies, processes and controls pertaining to material risk programs and initiatives; and (ii) the independent risk management functions including supporting their stature, authority, and independence. Review and assess the allocation of adequate funding for personnel and other resources for the independent risk management functions to execute their responsibilities.
- Annually review and assess the Company's Strategic and Operational Plans relative to Risk Appetite, Risk Profile, and capital and liquidity adequacy.
- Review and recommend to the Board for approval the Bank’s Resolution Plan, as required.
D. Capital Adequacy and Liquidity Risk
Oversee the Company's capital adequacy and liquidity risks. Jointly with the Finance and Audit Committee:
- Review and assess the sufficiency of the capital adequacy management program and appropriateness for the Company's overall size, complexity, and risk profile.
- Annually review and approve the USAA Consolidated and Bank Capital Plans and USAA Consolidated and Bank Contingency Funding Plans.
- Annually review and approve USAA-wide and Bank capital stress testing results for inclusion in the capital plans, and any remediation or recovery planning efforts which result from such stress testing.
- Annually review USAA-wide and Bank liquidity stress testing results for inclusion in the funding plans, and any remediation or recovery planning efforts which result from such stress testing.
- Oversee efforts to restore capital or liquidity above the risk appetite established through the USAA and/or Bank Capital Contingency Plan or USAA Consolidated and/or Bank Contingency Funding Plan.
E. Senior Management Reports
Review and discuss, as appropriate, the following reports from senior management:
- On a quarterly basis, review reporting on the following topics:
- Capital adequacy and liquidity including (i) current capital levels and risks with consideration of planned capital contributions and distributions, (ii) liquidity risk profile, and (iii) adequacy of liquidity for current and projected Company cash flow needs, and for consistency with established risk tolerances.
- Management’s assessments of and justifications for the estimated amounts reported each quarter for the Bank’s allowance for credit losses and provision for credit losses.
- On an annual basis, review reporting on the following topics:
- The Bank Secrecy Act / Anti-Money Laundering program.
- The Company’s financial institution insurance program, which includes coverage for the Company’s directors and officers, cyber insurance, and the Company financial institution bond program.
- Bank Audit Services’ annual independent assessment of management’s adherence to the Bank’s Risk Governance Framework and of the Bank’s Compliance Management System.
- On an as needed basis, review reporting on the following topics:
- Selected risk topics, including, but not limited to, material risks, concentrations and emerging risks.
- Risk and compliance related issues identified by regulatory authorities or in audit reports, management letters, and other reports and presentations. Discussions on material legal or regulatory matters may include the USAA Chief Legal Officer, the Bank General Counsel, or regulators, as appropriate, and at the Committee's discretion report such matters to the Board.
- Updates on regulatory matters including (i) the schedule and results of significant regulatory examinations and the nature and status of any corrective actions, and (ii) ongoing regulatory projects.
- Report(s) from either Chief Risk Officer concerning (i) the USAA CEO’s, the Bank President’s, or a front-line unit’s material non-adherence to either the USAA Risk Management Framework or the Bank’s Risk Governance Framework, and (ii) instances where independent risk management’s assessment of risk differs from the USAA CEO, the Bank President or a front-line unit.
- Assessments of the Company’s business continuation and resiliency program, including an evaluation of its effectiveness, identification of key risks and vulnerabilities, and an overview of mitigation strategies.
- Assessments of the Company’s complaint management program, training, and resources from complaints received across all member interaction points and through third-party affiliations, including trend analysis and identification of emerging issues, particularly related to compliance or regulatory concerns.
F. Executive Session
Meet with the Chief Risk Officers and such employees of the Company as deemed appropriate by the Committee in separate executive sessions as needed to discuss any matters that the Committee or either Chief Risk Officer believes should be discussed privately. Such matters may include, but not be limited to risk or compliance levels, risk and compliance control environment adequacy, compliance by executive management with frameworks, policies, or governance practices, and performance and incentives of executive management relative to risks and the Company’s risk appetites.
G. Oversight of Chief Risk Officers
The USAA and Bank Chief Risk Officers shall report jointly to the Committee and to the Chief Executive Officer and Bank President, respectively, who shall jointly oversee the Chief Risk Officers. In doing so, the Committee shall:
- Review and approve the appointment and removal of the Chief Risk Officers.
- Review the performance evaluation and approve the compensation and salary adjustment of the Chief Risk Officers and evaluate whether the compensation and other incentives paid to the Chief Risk Officers are consistent with providing an objective assessment of the risks taken by USAA and/or the Bank. As part of the performance evaluation, jointly with the Chief Executive Officer or the Bank President, respectively, establish and approve nonfinancial performance objectives for the Chief Risk Officers aligned with USAA's or the Bank’s risk strategy and tolerance, respectively.
- Review and provide input to succession planning for the Chief Risk Officers.
H. Committee Performance
- Annually review and assess the Committee's performance and provide the results to the Board.
- Annually review the Committee Charter and recommend any necessary changes for approval by the Board.
- Recommend to the Board, as necessary, investigations into any matters under the Committee's purview.
I. Other
- The Committee shall perform such other duties as may be delegated to it from time to time by the Board.
- The Committee shall coordinate its work with other committees as it deems appropriate.
- The Committee may delegate its authority to subcommittees, which shall report regularly to the Committee.
III. DURATION
The Committee shall continue in existence until dissolved by the Board.
IV. COMMITTEE CHAIR
The Chair of the Committee and if the Committee so decides, the Vice Chair of the Committee shall be elected by the Board annually, or as necessary, with due consideration given to nominee(s) recommended by the Nominating and Governance Committee. The Committee Chair shall be an independent director and shall meet the independence requirements as set forth in the Corporate Governance Guidelines. In the event of the death, disability, or other incapacity that prevents the Committee Chair from properly performing his or her duties, the duties of the Committee Chair shall pass to the Committee Vice Chair or in the absence of a Vice Chair, a Committee member designated by the Committee, until a new Committee Chair is elected as provided for herein.
V. COMMITTEE MEMBERSHIP
The Committee shall consist of at least three members. A majority of the members shall satisfy the requirements of 12 CFR Part 30, Appendix D, Section III.D.1-3 and qualify as “independent” under Rule 303A.02 of the New York Stock Exchange (or any successor rule). The membership of the Committee shall be through appointment by the Board on consideration of nominee(s) recommended by the Nominating and Governance Committee. The Board shall have the authority to fill any vacancies and to remove any Committee member for any reason.
At least one member of the Committee shall have appropriate risk and compliance management expertise, as such qualification is interpreted by the Board in its business judgment considering regulatory guidance and industry best practices. Each Committee member will annually execute a "Certification Regarding Qualifications" (the "Certification") prepared by the Chief Legal Office.
Each Committee member shall maintain a working familiarity with relevant operational risk and compliance management principles and practices.
No less than annually, the Board shall assess Committee members' independence and determine if they meet applicable requirements.
VI. OUTSIDE CONSULTANTS
The Committee shall have the sole authority, without further approval by the Board to select, retain, evaluate the performance of and terminate such outside consultants or counsel as it determines appropriate to assist it in the performance of its functions, or to advise or inform the Committee. The Committee shall be able to approve, without further approval by the Board, any compensation payable by the Company to such consultant, including the fees, terms, and other conditions for the performance of such services.
The Committee may consult with internal or outside counsel, if, in the opinion of the Committee, any matter under consideration by the Committee has the potential for any conflict between the interests of USAA and those of the Bank in order to ensure that appropriate procedures are established for addressing any such potential conflict.
VII. MEETINGS
The Committee shall meet at such times and shall conduct such business as required to fulfill its responsibilities under this charter, with at least four regular meetings per year. Agendas and materials will be provided to Committee members in advance of any regular meetings. Special meetings may be held as called by the Committee Chair in consultation with the Chairman. A majority of the members of the Committee shall constitute a quorum and the affirmative vote of a majority of the members of the Committee participating in any meeting of the Committee is necessary for the approval of any Committee business. The Committee may also act by unanimous written consent. Meetings by telephonic or video conference call are authorized, and actions taken during such meetings shall have the same force and effect as actions taken in an in-person meeting.
The Committee may hold separate sessions as the USAA Committee or the Bank Committee if necessary to address issues relevant to one entity but not the other, or to consider transactions between the two entities or other matters where USAA and the Bank may have different interests.
Meetings between the Committee and external regulators will be coordinated by management. The Committee will extend a standing offer to meet with regulators. Any member of the Committee has the right to contact either Chief Risk Officer directly. The Chief Risk Officers have the right to contact the Committee Chair or any member of the Committee, if warranted.
Meetings are to be attended only by members of the Committee, the appointed recorder, designated management, and guests approved by the Committee Chair.
VIII. MINUTES AND REPORTS
The Corporate Secretary, in collaboration with the Committee Chair, shall designate a person to record the proceedings of the Committee's meetings. The records of the Committee meetings shall be confidential and retained in accordance with USAA's records retention schedule.
The Committee Chair may authorize the creation and distribution of reports or position papers as appropriate. The Committee shall make regular reports to the Board regarding its deliberations and actions and to make recommendations to the Board.
IX. EFFECTIVE DATE
This Charter was approved by the Board on August 20, 2026, to be effective August 31, 2026, and shall govern the operation of the Committee hereafter.