KeyCorp 10-K 2024-12-31
Filed 2025-02-21. 24 sections, 931K characters. Original on sec.gov · Markdown · JSON
Cover and table of contents
UNITED STATES SECURITIES AND EXCHANGE COMMISSION
Washington, D.C. 20549
FORM 10-K
ANNUAL REPORT
PURSUANT TO SECTION 13 OR 15(d)
OF THE SECURITIES EXCHANGE ACT OF 1934
For the fiscal year ended
December 31, 2024
Commission file number: 1-11302
KeyCorp

Exact name of registrant as specified in its charter:
| Ohio | 34-6542451 | ||||
| State or other jurisdiction of incorporation or organization: | I.R.S. Employer Identification Number: |
| 127 Public Square, | Cleveland, | Ohio | 44114-1306 | ||||||||
| Address of principal executive offices: | Zip Code: |
(216) 689-3000
Registrant’s telephone number, including area code:
SECURITIES REGISTERED PURSUANT TO SECTION 12(b) OF THE ACT:
| Title of each class | Trading Symbol(s) | Name of each exchange on which registered | ||||||
| Common Shares, $1 par value | KEY | New York Stock Exchange | ||||||
| Depositary Shares (each representing a 1/40th interest in a share of Fixed-to-Floating Rate | KEY PrI | New York Stock Exchange | ||||||
| Perpetual Non-Cumulative Preferred Stock, Series E) | ||||||||
| Depositary Shares (each representing a 1/40th interest in a share of Fixed Rate Perpetual Non- | KEY PrJ | New York Stock Exchange | ||||||
| Cumulative Preferred Stock, Series F) | ||||||||
| Depositary Shares (each representing a 1/40th interest in a share of Fixed Rate Perpetual Non- | KEY PrK | New York Stock Exchange | ||||||
| Cumulative Preferred Stock, Series G) | ||||||||
| Depositary Shares (each representing a 1/40th interest in a share of Fixed Rate Reset Perpetual Non- | KEY PrL | New York Stock Exchange | ||||||
| Cumulative Preferred Stock, Series H) |
SECURITIES REGISTERED PURSUANT TO SECTION 12(g) OF THE ACT: NONE
Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☒ No ☐
Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐ No ☒
Indicate by check mark whether the registrant (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes ☒ No ☐
Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T (§ 232.405 of this Chapter) during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes ☒ No ☐
Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, a smaller reporting company, or an emerging growth company. See the definitions of “large accelerated filer,” “accelerated filer,” “smaller reporting company,” and “emerging growth company” in Rule 12b-2 of the Exchange Act.
| Large accelerated filer | ☒ | Accelerated filer | ☐ | Non-accelerated filer | ☐ | ||||||||||||
| Smaller reporting company | ☐ | Emerging growth company | ☐ |
If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐
Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☒
If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previous issued financial statements. ☐
Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to § 240.10D-1(b). ☐
Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒
The aggregate market value of voting and non-voting common stock held by nonaffiliates of the Registrant was $13,402,865,321 (based on the June 28, 2024, closing price of KeyCorp Common Shares of $14.21 as reported on the New York Stock Exchange). As of February 19, 2025, there were 1,105,119,318 Common Shares outstanding.
Certain specifically designated portions of KeyCorp’s definitive Proxy Statement for its 2025 Annual Meeting of Shareholders are incorporated by reference into Part III of this Form 10-K.
Forward-looking Statements
From time to time, we have made or will make forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These statements do not relate strictly to historical or current facts. Forward-looking statements usually can be identified by the use of words such as “goal,” “objective,” “plan,” “expect,” “assume,” “anticipate,” “intend,” “project,” “believe,” “estimate,” “will,” “would,” “should,” “could,” or other words of similar meaning. Forward-looking statements provide our current expectations or forecasts of future events, circumstances, results or aspirations. Our disclosures in this report contain forward-looking statements. We may also make forward-looking statements in other documents filed with or furnished to the SEC. In addition, we may make forward-looking statements orally to analysts, investors, representatives of the media and others.
Forward-looking statements, by their nature, are subject to assumptions, risks, and uncertainties, many of which are outside of our control. Our actual results may differ materially from those set forth in our forward-looking statements. There is no assurance that any list of risks and uncertainties or risk factors is complete. In addition, no assurance can be given that any plan, initiative, projection, goal, commitment, expectation, or prospect set forth in this report can or will be achieved. Factors that could cause our actual results to differ from those described in forward-looking statements include, but are not limited to:
-
the extensive regulation of the U.S. financial services industry;
-
complex and evolving laws and regulations regarding privacy and cybersecurity;
-
operational or risk management failures by us or critical third parties;
-
breaches of security or failures of our technology systems due to technological or other factors, cybersecurity threats, and increased risks resulting from remote work;
-
an ineffective risk management framework;
-
negative outcomes from claims, litigation, arbitration, investigations, or governmental proceedings;
-
failure or circumvention of our controls and procedures;
-
our exposure to a wide range of climate-related physical risks across different geographical areas;
-
evolving capital and liquidity standards under applicable regulatory rules;
-
disruption of the U.S. financial system, including the impact of inflation and a potential global economic downturn or recession;
-
unanticipated changes in our liquidity position, including but not limited to, changes in our access to or the cost of funding and our ability to secure alternative funding sources;
-
our ability to receive dividends from our subsidiaries, including KeyBank;
-
downgrades in our credit ratings or those of KeyBank;
-
a worsening of the U.S. economy due to financial, political or other shocks;
-
our ability to anticipate interest rate changes and manage interest rate risk;
-
deterioration of economic conditions in the geographic regions where we operate;
-
the soundness of other financial institutions, including instability in the financial industry;
-
our concentrated credit exposure in commercial and industrial loans;
-
deterioration of commercial real estate market fundamentals;
-
defaults by our loan clients or counterparties;
-
adverse changes in credit quality trends;
-
declining asset prices;
-
deterioration of asset quality and an increase in credit losses;
-
geopolitical destabilization;
-
labor shortages and supply chain constraints, as well as the impact of inflation;
-
our ability to develop and effectively use the quantitative models we rely upon in our business planning;
-
our ability to manage reputational risk, including risks related to corporate responsibility and sustainability efforts;
-
our ability to timely and effectively implement our strategic initiatives;
-
increased competitive pressure;
-
our ability to adapt our products and services to industry standards and consumer preferences;
-
our ability to attract and retain talented executives and employees;
-
unanticipated adverse effects of strategic partnerships or acquisitions and dispositions of assets or businesses;
-
the potential impact of Scotiabank’s significant equity interest in our business;
-
inaccurate assumptions or estimates underlying our consolidated financial statements;
-
changes in accounting policies, standards, and interpretations; and
-
impairment of goodwill.
Any forward-looking statements made by us or on our behalf speak only as of the date they are made, and we do not undertake any obligation to update any forward-looking statement to reflect the impact of subsequent events or circumstances, except as required by applicable securities laws. Before making an investment decision, you should carefully consider all risks and uncertainties disclosed in our SEC filings, including this report on Form 10-K, our subsequent reports on Forms 10-Q and 8-K, and our registration statements filed with the SEC under the Securities Act of 1933, as amended, all of which are or will upon filing be accessible on the SEC’s website at www.sec.gov and on our website at www.key.com/ir.
Terminology
Throughout this discussion, references to “Key,” “we,” “our,” “us,” and similar terms refer to the consolidated entity consisting of KeyCorp and its subsidiaries. “KeyCorp” refers solely to the parent holding company, and “KeyBank” refers solely to KeyCorp’s subsidiary bank, KeyBank National Association. “KeyBank (consolidated)” refers to the consolidated entity consisting of KeyBank and its subsidiaries.
We want to explain some industry-specific terms at the outset so you can better understand the discussion that follows.
-
We use the phrase continuing operations in this document to mean all of our businesses other than our government-guaranteed and private education lending business, which are accounted for as discontinued operations.
-
We engage in capital markets activities primarily through business conducted by our Commercial Bank segment*.* These activities encompass a variety of products and services. Among other things, we trade securities as a dealer, enter into derivative contracts (both to accommodate clients’ financing needs and to mitigate certain risks), and conduct transactions in foreign currencies (to accommodate clients’ needs).
-
For regulatory purposes, capital is divided into two classes. Federal regulations currently prescribe that at least one-half of a bank or BHC’s total risk-based capital must qualify as Tier 1 capital. Both total and Tier 1 capital serve as bases for several measures of capital adequacy, which is an important indicator of financial stability and condition. Banking regulators evaluate a component of Tier 1 capital, known as Common Equity Tier 1, under the Regulatory Capital Rules. The “Capital” section of this report under the heading “Capital adequacy” provides more information on total capital, Tier 1 capital, and the Regulatory Capital Rules, including Common Equity Tier 1, and describes how these measures are calculated.
The acronyms and abbreviations identified below are used throughout this report, including in the Notes to Consolidated Financial Statements and in the Management’s Discussion and Analysis of Financial Condition and Results of Operations. You may find it helpful to refer back to this page as you read this report.
| ABO: Accumulated benefit obligation. ALCO: Asset/Liability Management Committee. ALLL: Allowance for loan and lease losses. A/LM: Asset/liability management. AML: Anti-money laundering. AOCI: Accumulated other comprehensive income (loss). APBO: Accumulated postretirement benefit obligation. ASC: Accounting Standards Codification. ASU: Accounting Standards Update. ATMs: Automated teller machines. BSA: Bank Secrecy Act. BHCA: Bank Holding Company Act of 1956, as amended. BHCs: Bank holding companies. Board: KeyCorp Board of Directors. CAPM: Capital Asset Pricing Model. CCAR: Comprehensive Capital Analysis and Review. CECL: Current Expected Credit Losses. CFPB: Consumer Financial Protection Bureau, also known as the Bureau of Consumer Financial Protection. CFTC: Commodities Futures Trading Commission. CMBS: Commercial mortgage-backed securities. CMO: Collateralized mortgage obligation. Common Shares: KeyCorp common shares, $1 par value. CVA: Credit valuation adjustment. DCF: Discounted cash flow. DIF: Deposit Insurance Fund of the FDIC. Dodd-Frank Act: Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010. EAD: Exposure at default. EBITDA: Earnings before interest, taxes, depreciation, and amortization. EPS: Earnings per share. ERISA: Employee Retirement Income Security Act of 1974. ERM: Enterprise risk management. EVE: Economic value of equity. FASB: Financial Accounting Standards Board. FDIA: Federal Deposit Insurance Act, as amended. FDIC: Federal Deposit Insurance Corporation. Federal Reserve: Board of Governors of the Federal Reserve System. FHLB: Federal Home Loan Bank of Cincinnati. FHLMC: Federal Home Loan Mortgage Corporation. FICO: Fair Isaac Corporation. FINRA: Financial Industry Regulatory Authority. First Niagara: First Niagara Financial Group, Inc. FNMA: Federal National Mortgage Association. FSOC: Financial Stability Oversight Council. FVA: Fair value of employee benefit plan assets. | GAAP: U.S. generally accepted accounting principles. GNMA: Government National Mortgage Association. HTC: Historic tax credit. IDI: Insured depository institution. IRS: Internal Revenue Service. ISDA: International Swaps and Derivatives Association. KBCM: KeyBanc Capital Markets, Inc. KCC: Key Capital Corporation. KCDC: Key Community Development Corporation. KCIC: Key Community Investment Capital LLC. LCR: Liquidity coverage ratio. LGD: Loss given default. LIHTC: Low-income housing tax credit. LTV: Loan-to-value. Moody’s: Moody’s Investor Services, Inc. MTRM: Market & Treasury Risk Management. MRC: Market Risk Committee. N/A: Not applicable. NAV: Net asset value. NFA: National Futures Association. N/M: Not meaningful. NMTC: New market tax credit. NPR: Notice of proposed rulemaking. NSF: Non-sufficient funds. NYSE: New York Stock Exchange. OCC: Office of the Comptroller of the Currency. OCI: Other comprehensive income (loss). OREO: Other real estate owned. PBO: Projected benefit obligation. PCCR: Purchased credit card relationship. PCD: Purchased credit deteriorated. PD: Probability of default. RMBS: Residential mortgage-backed securities. S&P: Standard and Poor’s Ratings Services, a Division of The McGraw-Hill Companies, Inc. SEC: U.S. Securities & Exchange Commission. Scotiabank: The Bank of Nova Scotia SIFIs: Systemically important financial institutions, including large, interconnected BHCs and nonbank financial companies designated by FSOC for supervision by the Federal Reserve. SOFR: Secured Overnight Financing Rate. TE: Taxable-equivalent. TROC: Treasury Risk Oversight Committee. U.S. Treasury: United States Department of the Treasury. VaR: Value at risk. VEBA: Voluntary Employee Beneficiary Association. VIE: Variable interest entity. |
KEYCORP
2024 FORM 10-K ANNUAL REPORT
TABLE OF CONTENTS
PART I
Item 1. BUSINESS
Overview
KeyCorp, organized in 1958 under the laws of the State of Ohio, is headquartered in Cleveland, Ohio. We are a BHC under the BHCA and one of the nation’s largest bank-based financial services companies, with consolidated total assets of approximately $187.2 billion at December 31, 2024. KeyCorp is the parent holding company for KeyBank National Association, its principal subsidiary, through which most of our banking services are provided. Through KeyBank and certain other subsidiaries, we provide a wide range of retail and commercial banking, commercial leasing, investment management, consumer finance, student loan refinancing, commercial mortgage servicing and special servicing, and investment banking products and services to individual, corporate, and institutional clients through two major business segments: Consumer Bank and Commercial Bank.
As of December 31, 2024, these services were provided across the country through KeyBank’s 944 full-service retail banking branches and a network of 1,182 ATMs in 15 states, as well as additional offices, online and mobile banking capabilities, including our national digital brand, Laurel Road, and a telephone banking call center. Additional information pertaining to our two business segments is included in the “Business Segment Results” section in Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations of this report, and in Note 25 (“Business Segment Reporting”) of the Notes to Consolidated Financial Statements presented in Item 8. Financial Statements and Supplementary Data, which are incorporated herein by reference.
In addition to the customary banking services of accepting deposits and making loans, our bank and its trust company subsidiary offer personal and institutional trust custody services, personal financial and planning services, access to mutual funds, treasury services, and international banking services. Through our bank, trust company, and registered investment adviser subsidiaries, we provide investment management services to clients that include large corporate and public retirement plans, foundations and endowments, high-net-worth individuals, and multi-employer trust funds established for providing pension or other benefits to employees.
We provide other financial services — both within and outside of our primary banking markets — through various nonbank subsidiaries. These services include community development financing, securities underwriting, investment banking and capital markets products, and brokerage. We also provide merchant services to businesses.
KeyCorp is a legal entity separate and distinct from its banks and other subsidiaries. Accordingly, the right of KeyCorp, its security holders, and its creditors to participate in any distribution of the assets or earnings of its banks and other subsidiaries is subject to the prior claims of the creditors of such banks and other subsidiaries, except to the extent that KeyCorp’s claims in its capacity as a creditor may be recognized.
We derive the majority of our revenues within the United States from customers domiciled in the United States. Revenue from foreign countries and external customers domiciled in foreign countries was immaterial to our consolidated financial statements.
Demographics
Our management structure and basis of presentation is divided into two business segments, Consumer Bank and Commercial Bank. Note 25 (“Business Segment Reporting”) describes the products and services offered by each of these business segments and provides more detailed financial information pertaining to the segments, including changes in basis of presentation.
The Consumer Bank serves individuals and small businesses throughout our 15-state branch footprint and through our Laurel Road digital brand by offering a variety of deposit and investment products, personal finance and financial wellness services, lending, student loan refinancing, mortgage and home equity, credit card, treasury services, and business advisory services. In addition, wealth management and investment services are offered to assist non-profit and high-net-worth clients with their banking, trust, portfolio management, charitable giving, and related needs.
The Commercial Bank consists of the Commercial and Institutional operating segments. The Commercial operating segment is a full-service, commercial banking platform that focuses primarily on serving the borrowing, cash
management, and capital markets needs of middle market clients within Key’s 15-state branch footprint. The Institutional operating segment operates nationally in providing lending, equipment financing, and banking products and services to large corporate and institutional clients. The industry coverage and product teams have established expertise in the following sectors: Consumer, Energy, Healthcare, Industrial, Public Sector, Real Estate, and Technology. It is also a significant, national, commercial real estate lender and third-party master and special servicer of commercial mortgage loans. The operating segment includes the KBCM platform which provides a broad suite of capital markets products and services including syndicated finance, debt and equity underwriting, fixed income and equity sales and trading, derivatives, foreign exchange, mergers & acquisition and other advisory, and public finance.
Additional Information
Our executive offices are located at 127 Public Square, Cleveland, Ohio 44114-1306, and our telephone number is (216) 689-3000. Our website is www.key.com, and the investor relations section of our website may be reached through www.key.com/ir. We make available free of charge, on or through the investor relations section of our website, annual reports on Form 10-K, quarterly reports on Form 10-Q, and current reports on Form 8-K, and amendments to those reports filed or furnished pursuant to Section 13(a) or 15(d) of the Securities Exchange Act of 1934, as amended (the “Exchange Act”), as well as proxy statements, as soon as reasonably practicable after we electronically file such material with, or furnish it to, the SEC. Also posted on our website, and available in print upon request from any shareholder to our Investor Relations Department, are the charters for the committees of our Board of Directors, which includes the Audit Committee, Compensation and Organization Committee, Executive Committee, Nominating and Corporate Governance Committee, Risk Committee, and Technology Committee; our Corporate Governance Guidelines; the Code of Business Conduct and Ethics for our directors, officers, and employees; our Standards for Determining Independence of Directors; our policy for Review of Transactions Between KeyCorp and Its Directors, Executive Officers and Other Related Persons; our Statement of Political Activity; and our Corporate Responsibility Report. Within the time period required by the SEC and the NYSE, we will post on our website any amendment to the Code of Ethics and any waiver applicable to any senior executive officer or director. We also make available a summary of filings made with the SEC of statements of beneficial ownership of our equity securities filed by our directors and officers under Section 16 of the Exchange Act. The “Regulatory Disclosures & Filings” section under the “Financials” tab of the investor relations section of our website includes public disclosures concerning our historic annual and mid-year stress-testing activities under the Dodd-Frank Act and our quarterly regulatory capital disclosures under the third pillar of Basel III.
Information contained on or accessible through, including any reports available on, our website or any other website referenced in this report is not part of this report. References to websites in this report are intended to be inactive textual references only.
Shareholders may obtain a copy of any of the above-referenced corporate governance documents b
Showing the first 8K of 85K characters. Open the full section
Item 1A. RISK FACTORS
Summary of Risk Factors
The following is a summary of some of the material risks and uncertainties that could have an adverse effect on our business.
- Credit Risk
◦We have concentrated credit exposure in commercial and industrial loans, commercial real estate loans, and commercial leases.
◦Should the fundamentals of the commercial real estate market deteriorate, our financial condition and results of operations could be adversely affected.
◦We are subject to the risk of defaults by our loan clients and counterparties.
◦Declining asset prices could adversely affect us.
◦Various factors may cause our allowance for loan and lease losses to increase or to be inadequate.
◦Geopolitical destabilization could adversely impact our loan portfolios.
- Market Risk
◦A worsening of the U.S. economy and volatile or recessionary conditions in the U.S. or abroad could negatively affect our business or our access to capital markets.
◦We are subject to interest rate risk, which could adversely affect net interest income.
◦Our profitability depends upon economic conditions in the geographic regions where we have significant operations and in certain market segments in which we conduct significant business.
◦The soundness of other financial institutions could adversely affect us.
- Liquidity Risk
◦We are subject to liquidity risk, which could negatively affect our funding levels.
◦Capital and liquidity requirements imposed by banking regulations require banks and BHCs to maintain more and higher quality capital and more and higher quality liquid assets.
◦Federal agencies’ actions to ensure stability of the U.S. economy and financial system may have costly or disruptive effects on us.
◦We rely on dividends by our subsidiaries for most of our funds.
◦Our credit ratings affect our liquidity position.
- Operational Risk
◦We are subject to a variety of operational risks.
◦We and third parties on which we rely (including their downstream service providers) may experience a cyberattack, technology failure, information system or security breach or interruption.
◦We rely on third parties to perform significant operational services for us, and their failure to perform to our standards or other issues of concern with them could harm us.
◦Our framework for managing risks and mitigating losses may not be effective.
◦We are, and may in the future be, subject to claims, litigation, arbitration, investigations, and governmental proceedings, which could result in significant financial liability and/or reputational harm.
◦Our controls and procedures may fail or be circumvented, and our methods of reducing risk exposure may not be effective.
◦Our operations and financial performance could be adversely affected by severe weather and natural disasters exacerbated by climate change.
◦Societal and governmental responses to climate change could adversely affect our business and performance, including indirectly through impacts on our customers.
◦The increased use of remote work infrastructure has expanded potential attack vectors and resulted in increased operational risks.
- Compliance Risk
◦We are subject to extensive government regulation, supervision, and tax legislation.
◦We are subject to complex and evolving laws and regulations regarding privacy and cybersecurity, which could limit our ability to pursue business initiatives, increase the cost of doing business and subject us to compliance risks and potential liability.
- Strategic Risk
◦We may not realize the expected benefits of our strategic initiatives.
◦We operate in a highly competitive industry.
◦Maintaining or increasing our market share depends upon our ability to adapt our products and services to evolving industry standards and consumer preferences, while maintaining competitive products and services.
◦We may not be able to attract and retain skilled people.
◦Acquisitions or strategic partnerships may disrupt our business and dilute shareholder value.
◦Scotiabank holds a significant equity interest in our business and may exercise influence over us, including through its ability to designate up to two directors to our Board of Directors.
- Reputation Risk
◦Damage to our reputation could significantly impact our business and major stakeholders.
◦Key is subject to corporate responsibility and sustainability efforts risks that could adversely affect our reputation and our business and results of operations.
- Model Risk
◦We rely on quantitative models to manage certain accounting, risk management, capital planning, and treasury functions.
- Estimates and Assumptions Risk
◦The preparation of our consolidated financial statements requires us to make subjective determinations and use estimates that may vary from actual results and materially impact our financial condition and results of operations.
◦Changes in accounting policies, standards, and interpretations could materially affect how we report our financial condition and results of operations.
◦Impairment of goodwill could require charges to earnings, which could result in a negative impact on our results of operations.
As a financial services organization, we are subject to a number of risks inherent in our transactions and present in the business decisions we make. Described below are the material risks and uncertainties that if realized could have a material and adverse effect on our business, financial condition, results of operations or cash flows, and our access to liquidity. Although the risks are organized by headings and each risk is discussed separately, many are interrelated. The risks and uncertainties described below are not the only risks we face. Disclosures of risks should not be interpreted to imply that the risks have not already materialized.
Our ERM program incorporates risk management throughout our organization to identify, understand, and manage the risks presented by our business activities. Our ERM program identifies Key’s major risk categories as: compliance risk, operational risk, liquidity risk, market risk, credit risk, model risk, reputation risk, strategic risk, and estimates and assumptions risk. These risk factors, and other risks we may face, are discussed in more detail in other sections of this report.
I. Credit Risk
We have concentrated credit exposure in commercial and industrial loans, commercial real estate loans, and commercial leases.
As of December 31, 2024, approximately 69% of our loan portfolio consisted of commercial and industrial loans, commercial real estate loans, including commercial mortgage and construction loans, and commercial leases. These types of loans are typically larger than single family residential real estate loans and other types of consumer loans and have a different risk profile. The deterioration of a larger loan or a group of loans in this category could cause an increase in criticized, classified, and nonperforming loans, which could result in lower earnings from these loans, additional provision for loan and lease losses, and ultimately an increase in loan losses.
Should the fundamentals of the commercial real estate market deteriorate, our financial condition and results of operations could be adversely affected.
Recent Federal Reserve monetary policy, including shrinkage of its balance sheet and incremental increases in target interest rates early in 2023 followed by a sustained period of relatively higher target interest rates throughout the latter part of 2023 and 2024, continue to impact the commercial and residential real estate markets. Capitalization rates have risen, and property value appreciation has slowed and continues to decline. In many markets within Key’s footprint, property values continue to decrease. Industrial and retail properties continue to remain stable, but multifamily, office, hospitality, and single family detached properties show signs of deterioration. Development and c
Showing the first 8K of 94K characters. Open the full section
Item 1B. UNRESOLVED STAFF COMMENTS
None.
Item 1C. CYBERSECURITY
Cybersecurity Risk Management
As a financial services institution, Key faces heightened risk of cybersecurity incidents. Risks and exposures related
to cybersecurity incidents are expected to remain high for the foreseeable future due to the rapidly evolving nature
and sophistication of cybersecurity threats and geopolitical events, as well as due to the expanding use of Internet and mobile banking and other technology-based products and services utilized by us and our clients, including products and services that utilize the cloud and artificial intelligence (AI), among other emerging technologies. To date, Key has not experienced material disruption to our operations, or material harm to our client base, from cyberattacks. However, we have incurred, and may again incur, expenses related to the investigation of cybersecurity incidents involving third-party providers or related to the protection of our clients from identity theft as a result of such incidents. We have also incurred, and may continue to incur, expenses to enhance our systems or processes to protect against cyber or other security incidents. For more information, see “Risk Factors—We and third parties on which we rely (including their downstream service providers) may experience a cyberattack, technology failure, information system or security breach or interruption” in Item 1A. Risk Factors of this report.
Key maintains an Information Security Program (the “IS Program”) to support the management of information security risk, including cybersecurity risk, across the organization. The IS Program is designed to protect Key’s
clients, employees, third parties, and assets from threats by managing the confidentiality, availability, and integrity of
Key’s information assets. Our Chief Information Security Officer (“CISO”), who is also the Enterprise Security
Executive, oversees the IS Program and its related policy and has overall responsibility for managing the appropriate identification and ownership of cybersecurity risks. Key’s Corporate Information Security Team, under the oversight of the CISO, is responsible for maintaining the IS Program, assessing program-level risks and threats to our information assets, and overseeing the proper level of investment in security resources.
The IS Program is designed to provide safeguards for Key’s assets through a series of administrative, technical,
and physical controls. Key employs a variety of security practices and controls to protect information and assets,
including, but not limited to, access controls, vulnerability scans, network monitoring, internal and external
penetration testing, monitoring of vendor vulnerability notices and patch releases, scanning of systems and emails
for malware and other vulnerabilities, firewalls and intrusion detection and prevention systems, and dedicated
security personnel.
As described in more detail in “Risk Management — Overview” in Item 7 of this report and in “Cybersecurity
Governance” below, Key employs the “Three Lines of Defense” in its risk governance framework. Assessing,
identifying, and managing cybersecurity risk across the organization in support of the IS Program is a cross-functional effort that requires collaboration and direction from all lines of defense – the lines of business and support functions (First Line of Defense), Risk Management (Second Line of Defense), and the Risk Review Group (RRG), Key’s internal audit function (Third Line of Defense):
-
First Line of Defense – Lines of Business and Support Functions. Primary responsibility for day-to-day management of cybersecurity risk lies with the senior management of each of Key’s lines of business (LOB) and support functions. The LOB and support functions own and manage the individual processes and procedures that are used throughout the IS Program, implement and manage business-specific security controls, and enforce behavioral controls throughout the management structure.
-
Second Line of Defense – Risk Management. Risk Management oversees risk and monitors the First Line of Defense controls. Operational Risk Management performs review and challenge of controls, monitors the operational risk profile, and ensures Key operates within its operational risk appetite. Compliance Risk Management provides an independent, enterprise-wide function that focuses on compliance with laws, rules, regulations, and guidance applicable to Key. Privacy Compliance, which sits within Compliance Risk Management, provides advisory support, governance, and oversight of privacy-related statutes, regulations, and risks related to Key’s customers, employees, and other individuals from who Key collects personally identifiable information.
-
Third Line of Defense – Risk Review Group (RRG). The RRG reviews and evaluates the scope and breadth of security activities throughout Key and the effectiveness of the IS Program. RRG conducts independent internal
audits on Key’s LOBs, operations, information systems, and technologies. These internal audits provide an independent perspective on Key’s processes and risks. Technology risks are evaluated in areas including cybersecurity and information security, data control, acquisition and development, delivery and support, business continuity, and information technology governance. RRG shares the results of its audits with the LOB management, Key’s Operational and Compliance Risk Management Groups, the Board’s Audit Committee, and banking regulators.
As part of its cybersecurity risk management strategy, Key regularly reviews its security and privacy controls in the context of industry standard practices, frameworks, evolving laws, and changing client expectations. Key engages external providers periodically to perform a maturity assessment of the IS Program against industry cybersecurity frameworks. Key also engages external advisors periodically to perform security posture assessments of our environment to proactively identify weakness within our security policy and/or configurations. Summary level results from these assessments are shared to internal stakeholders through Key’s Risk Governance committee structure. Key is also subject to cybersecurity and privacy regulatory exams, as required by law for financial institutions.
Key has implemented cybersecurity, privacy, and fraud education and awareness programs across the
enterprise to educate teammates on how to identify and report cybersecurity and privacy concerns. Employees and
contractors with access to assets or data owned or maintained by Key receive mandatory enterprise-wide
cybersecurity, privacy, and fraud training on an annual basis. In addition, our management team from time to time participates in cybersecurity tabletop exercises that simulate cybersecurity incidents. These exercises are intended to test our response to potential incidents and assess the procedures outlined in our incident response playbooks.
With respect to third party service providers, Key maintains a third party management program that is designed to
identify, review, monitor, escalate, and, if necessary, remediate third party information security risks. Key’s third
party onboarding process includes risk-based due diligence and security-relevant contract language. Risk-based
due diligence can also include an assessment of the strength of certain control areas, including, but not limited to,
information security management, physical security, network security, platform security, application security, cloud
security, encryption management, business resiliency, and privacy. Once a business relationship is established with a service provider, Key performs risk-based periodic reviews of the third party service provider's security programs. In addition to an established governance approval process for new engagements, Key has established a Third Party Management Committee to oversee compliance with Key’s Third Party Management Policy and Program.
Cybersecurity Governance
As described in more detail in “Risk Management — Overview” in Item 7 of this report, the Board serves in an
oversight capacity to ensure that Key’s risks, including risk from cybersecurity threats, are managed in a manner that is effective and balanced and adds value for our shareholders. The Board’s Risk Committee exercises primary oversight over enterprise-wide risk at Key, including operational risk, which includes cybersecurity risk, and provides oversight of management’s activities related to cybersecurity risk. The Board’s Audit Committee monitors and exercises oversight over cybersecurity risk as part of its joint oversight of operational risk with the Risk Committee. The Board’s Technology Committee provides additional oversight of management’s activities related to Key’s technology strategic investment plan, cybersecurity investments, and major technology vendor relationships and is expected to escalate to the Risk Committee on certain risk management issues.
Key’s CISO oversees the IS Program and its related policies and is responsible for determining whether relevant security risk information is properly integrated into strategic and business decisions, overseeing the appropriate identification and ownership of security risks, monitoring critical risks, and maintaining the appropriate oversight and governance of information security through associated programs and/or standards. Our CISO has served in various roles in information technology and information security at Key for over 30 years, including serving as Enterprise Security Executive. The CISO holds a B.S.B.A in Management Information Systems.
The CISO is responsible for reporting on information security matters, including cybersecurity risk, to the Board. The CISO provides updates to the Audit Committee on cybersecurity matters at each regularly scheduled Committee meeting (six times in 2024). The CISO’s update to the Committee generally address the cybersecurity threat landscape, information security trends, strategic initiatives related to information security, and cybersecurity program reviews. The CISO also updates the Risk Committee on cybersecurity matters and on Key’s compliance with the Gramm-Leach-Bliley Act on an annual basis and presents the Information Security Policy for approval. The CISO, along with Key’s Deputy CISO, also report annually to the Technology Committee to obtain approval on Key’s Cyber Strategy and Investment Plan. The CISO provides updates to the Board as needs arise and from time to time.
Key’s Deputy CISO leads the Corporate Information Security function, including the Cyber Defense Center, Identity
& Access Management Operations, Information Security Governance and Data Protection, and Security Architecture, Engineering and Platform Operations. The Deputy CISO has over 17 years of cybersecurity and technology risk management experience across financial services and retail, previously served as the Head of Information Security Governance within KeyCorp’s Corporate Information Security group, as well as the Head of Cybersecurity and Technology Risk Oversight within KeyCorp’s Risk Management group. He holds a bachelor’s degree in Finance and Management Information Systems and an MBA.
The CISO reports to Key’s Chief Information Officer who oversees all of Key’s shared services for technology,
operations, data, servicing, cyber and physical security, and corporate real estate solutions. Our Chief Information Officer, who has served in the role since 2012, has extensive experience overseeing technology and operations delivery for critical enterprise functions and has held various leadership roles during her over 30-year career in the financial services industry.
At the management level, our Enterprise Risk Management (ERM) Committee, chaired by the Chief Executive
Officer and comprising other senior level executives, including the Chief Information Officer, reports to the Board’s
Risk Committee and is responsible for managing risk, including cybersecurity risk. The ERM Committee serves as a
senior level forum for review and discussion of material operational risk issues, including cybersecurity risk, and
receives regular updates from the CISO regarding cybersecurity risk. The ERM Committee directly oversees the
Operational Risk Committee, which provides governance, direction, oversight, and high-level management of
operational risk, including cybersecurity risk, and includes senior management representation from the LOB and
support areas. The CISO is a voting member of the Operational Risk Committee.
The Operational Risk Committee also includes subcommittees which, among other things, address security issues
and concerns, pursue security-related program enhancements, address fraud trends, provide input on fraud
strategy, weigh the impacts of fraud risk on customers, business clients, and the LOB, and cascades awareness of
fraud risks across Key.
Key also has a Privacy Team led by a Chief Privacy Officer (CPO) who has over ten years of experience in legal,
compliance, and risk roles at financial institutions, focusing primarily on data protection and privacy. Our CPO holds
an undergraduate degree in finance, a master’s degree in business administration, and a juris doctorate. He is
licensed to practice law in the state of Ohio and has obtained the CIPP/US certification through the International
Association of Privacy Professionals. The CPO and Privacy team have the authority to escalate privacy risks to the
Board. The Privacy and Information Security teams work together to implement controls around how personally
identifiable information is managed and protected and to comply with applicable laws and regulations.
Cybersecurity Incidents
When a cybersecurity incident is identified, we follow established processes in our enterprise privacy and cyber
incident response plans, which are a supplement to our corporate incident response plan. These plans provide a
framework to enable the appropriate personnel to recover operations in the event of a cyberattack and manage
incidents impacting banking information, including our clients’ and employees’ information.
Our Core Incident Response Rapid Emergency Assessment and Coordination Team (Core IR REACT) is
responsible for responding to incidents, including cyberattacks, performing a preliminary assessment, and engaging
additional support team members as necessary. The Core IR REACT team is a multidisciplinary team that is
empowered to escalate issues, as appropriate, to our Crisis Management Team (CMT), which includes the CEO
and senior executives from Key’s LOB and major support areas. The CMT provides overall strategic
direction for incident responses and recovery. Incidents are also reported internally to key stakeholders through Key’s risk governance committee structure.
As discussed above in “Cybersecurity Risk Management,” the RRG shares the results of its independent internal
audits of security activities at Key and the effectiveness of the IS Program with the line of business management,
Key’s Operational and Compliance Risk Management Groups, the Board’s Audit Committee, and banking
regulators. Any identified gaps are risk rated, issued a due date for remediation, and tracked through completion of
remediation. Remediation is then verified by the RRG.
Item 2. PROPERTIES
The headquarters of KeyCorp and KeyBank are located at 127 Public Square, Cleveland, Ohio 44114-1306 in the Key Center. At December 31, 2024, Key leased approximately 375,414 square feet of the complex, encompassing the first floor branch, the 2nd, 3rd and 5th through 9th office floors, the 12th floor, and the 54th through 56th floors of the 57-story Key Center. In addition, Key owned two buildings in Brooklyn, Ohio, with office space that it operated from and totaling 584,930 square feet at December 31, 2024. Our office space is used by all of our segments. As of the same date, KeyBank owned 410 branches and leased 534 branches. The lease terms for applicable branches are not individually material, with terms ranging from month-to-month to 99 years from inception.
Item 3. LEGAL PROCEEDINGS
The information presented in the Legal Proceedings section of Note 22 (“Commitments, Contingent Liabilities, and Guarantees”) of the Notes to Consolidated Financial Statements is incorporated herein by reference.
On at least a quarterly basis, we assess our liabilities and contingencies in connection with outstanding legal proceedings utilizing the latest information available. Where it is probable that we will incur a loss and the amount of the loss can be reasonably estimated, we record a liability in our consolidated financial statements. These legal reserves may be increased or decreased to reflect any relevant developments on a quarterly basis. Where a loss is not probable or the amount of the loss is not estimable, we have not accrued legal reserves, consistent with applicable accounting guidance. Based on information currently available to us, advice of counsel, and available insurance coverage, we believe that our established reserves are adequate and any liabilities that may arise from outstanding legal proceedings will not have a material adverse effect on our consolidated financial condition. We note, however, that in light of the inherent uncertainty in legal proceedings there can be no assurance that the ultimate resolution will not exceed established reserves. As a result, the outcome of a particular matter or a combination of matters may be material to our results of operations for a particular period, depending upon the size of the loss or our income for that particular period.
Item 4. MINE SAFETY DISCLOSURES
Not applicable.
PART II
Item 5. MARKET FOR THE REGISTRANT’S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES
The following disclosures included in Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations are incorporated herein by reference:
| Page(s) | |||||
| Discussion of dividends in the section captioned “Capital — Dividends” | 73 | ||||
| Discussion of our common shares, shareholder information, and repurchase activities in the section captioned “Capital — Common Shares outstanding” | 73 |
The following graph compares the price performance of our Common Shares (based on an initial investment of $100 on December 31, 2019, and assuming reinvestment of dividends) with that of the S&P 500 Index and a group of other banks that constitute our peer group. The peer group consists of the banks that make up the S&P 500 Regional Bank Index and the banks that make up the Standard & Poor’s 500 Diversified Bank Index. We are included in the S&P 500 Index and the peer group. Share price performance is not necessarily indicative of future price performance.

From time to time, KeyCorp or its principal subsidiary, KeyBank, may seek to retire, repurchase, or exchange outstanding debt of KeyCorp or KeyBank, and capital securities or preferred stock of KeyCorp, through cash purchase, privately negotiated transactions, or otherwise. Such transactions, if any, depend on prevailing market conditions, our liquidity and capital requirements, contractual restrictions, and other factors. The amounts involved may be material.
We did not complete any open market share repurchases in 2024, and have no Board-approved repurchase authorizations outstanding.
During 2024, Key repurchased $28 million of shares related to equity compensation programs.
On August 30, 2024, KeyCorp issued 47,829,359 Common Shares for approximately $821 million in gross proceeds to Scotiabank pursuant to the first closing under the Investment Agreement. On December 27, 2024, Scotiabank completed the second and final purchase of 115,042,316 Common Shares under the Investment Agreement with an investment of approximately $2.0 billion in gross proceeds. These acquisitions were exempt from registration under the Securities Act of 1933, as amended (“Securities Act”), by virtue of the exemption provided by Section 4(a)(s) of the Securities Act.
The following table summarizes our repurchases of our Common Shares for the three months ended December 31, 2024. See Note 24 (“Shareholders' Equity”) for more information regarding share repurchases.
| Calendar month | Total number of shares repurchased**(a)** | Average price paid per share | Total number of shares purchased as part of publicly announced plans or programs | Dollar value of shares that may yet be purchased as part of publicly announced plans or programs (b) | |||||||||||||
| October 1 - 31 | 236 | $ | 17.21 | — | $ | — | |||||||||||
| November 1 - 30 | 103,712 | 19.49 | — | — | |||||||||||||
| December 1 -30 | 262 | 18.84 | — | — | |||||||||||||
| Total | 104,210 | $ | 19.48 | — | |||||||||||||
(a)Includes Common Shares deemed surrendered by employees in connection with our stock compensation and benefit plans to satisfy tax obligations. We did not complete any open market share repurchases in the fourth quarter of 2024.
Item 6. [RESERVED]
Item 7. MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS
Introduction
This section reviews the financial condition and results of operations of KeyCorp and its subsidiaries for 2024 and 2023. Some tables may include additional periods to comply with disclosure requirements or to illustrate trends in greater depth. When you read this discussion, you should also refer to the consolidated financial statements and related notes in this report. The page locations of specific sections and notes that we refer to are presented in the Table of Contents. To review our financial condition and results of operations for 2022 and a comparison between the 2022 and 2023 results, see Item 7. Management’s Discussion and Analysis of Financial Condition and Results of Operations of our 2023 Form 10-K filed with the SEC on February 22, 2024, which discussion is incorporated herein by reference.
Corporate strategy
We remain committed to enhancing long-term shareholder value by continuing to execute our relationship-based business model, growing our franchise, and being disciplined with respect to capital management. We intend to pursue this commitment by growing profitably; acquiring and expanding targeted client relationships; effectively managing risk and rewards; maintaining financial strength; and engaging, retaining, and inspiring our high-performing and talented workforce and fostering a culture that is fair and inclusive for all. These strategic priorities for enhancing long-term shareholder value are described in more detail below.
-
Grow profitably — We intend to continue to focus on generating positive operating leverage by growing revenue and creating a more efficient operating environment. We expect our relationship business model to keep generating organic growth as it helps us expand engagement with existing clients and attract new customers. We plan to leverage our continuous improvement culture to maintain an efficient cost structure that is aligned, sustainable, and consistent with the current operating environment and that supports our relationship business model.
-
Acquire and expand targeted client relationships — We seek to be client-centric in our actions and have taken purposeful steps to enhance our ability to acquire and expand targeted relationships. We seek to provide solutions to serve our clients' needs. We focus on markets and clients where we can be the most relevant. In aligning our businesses and investments against these targeted client segments, we are able to make a meaningful positive impact for our clients.
-
Effectively manage risk and rewards —** Our risk management activities are focused on ensuring we properly identify, measure, and manage risks across the entire company to maintain safety and soundness and maximize profitability.
-
Maintain financial strength —** With the foundation of a strong balance sheet, we intend to remain focused on sustaining strong reserves, liquidity, and capital. We plan to work closely with our Board and regulators to manage capital to support our clients’ needs an
Showing the first 8K of 229K characters. Open the full section
Item 7A. QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK
The information included under the caption “Risk Management — Market risk management” in the MD&A beginning on page 78 is incorporated herein by reference.
Item 8. FINANCIAL STATEMENTS AND SUPPLEMENTARY DATA
Management’s Annual Report on Internal Control over Financial Reporting
We are responsible for the preparation, content and integrity of the financial statements and other statistical data and analyses compiled for this annual report. The financial statements and related notes have been prepared in conformity with U.S. generally accepted accounting principles and include amounts which of necessity are based on management’s best estimates and judgments and give due consideration to materiality. We believe the financial statements and notes present fairly our financial position, results of operations and cash flows in all material respects.
We are responsible for establishing and maintaining a system of internal control that is designed to protect our assets and the integrity of our financial reporting as defined in the Securities Exchange Act of 1934, as amended. This corporate-wide system of controls includes policies and procedures that (1) pertain to the maintenance of records that, in reasonable detail, accurately and fairly reflect the transactions and dispositions of the assets of KeyCorp; (2) provide reasonable assurance that transactions are recorded as necessary to permit preparation of the consolidated financial statements in conformity with U.S. generally accepted accounting principles, and that receipts and expenditures of KeyCorp are made only in accordance with authorizations of management and directors of KeyCorp; and (3) provide reasonable assurance regarding prevention or timely detection of unauthorized acquisition, use or disposition of KeyCorp’s assets that could have a material effect on the consolidated financial statements. All employees are required to comply with our code of ethics. We conduct an annual certification process to ensure that our employees meet this obligation. Although any system of internal control can be compromised by human error or intentional circumvention of required procedures, we believe our system provides reasonable assurance that financial transactions are recorded and reported properly, providing an adequate basis for reliable financial statements.
During 2024, the Audit Committee of the Board of Directors met regularly with Management, internal audit, and the independent registered public accounting firm, Ernst & Young LLP, to review the scope of their audits and to discuss the evaluation of internal accounting controls and financial reporting matters. The independent registered public accounting firm and the internal auditors have free access to, and meet confidentially with, the audit c
Showing the first 8K of 444K characters. Open the full section
Item 9. CHANGES IN AND DISAGREEMENTS WITH ACCOUNTANTS ON ACCOUNTING AND FINANCIAL DISCLOSURE
None.
Item 9A. CONTROLS AND PROCEDURES
Evaluation of Disclosure Controls and Procedures
As of the end of the period covered by this report, KeyCorp carried out an evaluation, under the supervision and with the participation of KeyCorp’s management, including our Chief Executive Officer and Chief Financial Officer, of the effectiveness of the design and operation of KeyCorp’s disclosure controls and procedures (as defined in Rule 13a-15(e) under the Securities Exchange Act of 1934 (the “Exchange Act”)), to ensure that information required to be disclosed by KeyCorp in reports that it files or submits under the Exchange Act, is recorded, processed, summarized and reported within the time periods specified in the SEC’s rules and forms, and that such information is accumulated and communicated to KeyCorp’s management, including its Chief Executive Officer and Chief Financial Officer, as appropriate, to allow for timely decisions regarding required disclosure. Based upon that evaluation, KeyCorp’s Chief Executive Officer and Chief Financial Officer concluded that the design and operation of these disclosure controls and procedures were effective, in all material respects, as of the end of the period covered by this report. No changes were made to KeyCorp’s internal control over financial reporting (as defined in Rule 13a-15(f) under the Exchange Act) during the quarter ended December 31, 2024, that materially affected, or are reasonably likely to materially affect, KeyCorp’s internal control over financial reporting.
Reports Regarding Internal Controls
Management’s Annual Report on Internal Control over Financial Reporting, the Report of Independent Registered Public Accounting Firm on Internal Control over Financial Reporting, and the Report of Independent Registered Public Accounting Firm are included in Item 8 on pages 100, 101, and 102, respectively.
Item 9B. OTHER INFORMATION
Insider trading arrangements
No director or officer (as defined in Rule 16a-1(f) of the Exchange Act) of KeyCorp adopted, modified,
or terminated any Rule 10b5-1 trading arrangement or any non-Rule 10b5-1 trading arrangement (as such terms
are defined in Item 408 of Regulation S-K of the Exchange Act) during the quarter ended December 31, 2024,
except as may be noted below. We do not permit the use of Rule 10b5-1 trading arrangements by our directors or
executive officers.
Certain of our directors or officers have made elections to participate in, and are participating in, our KeyCorp
Second Amended and Restated Discounted Stock Purchase Plan, our Long-Term Incentive Deferral Plan, our
Directors’ Deferred Share Sub-Plan, and the Dividend Reinvestment Plan and dividend reinvestment features under
various compensation plans and arrangements, and previously made elections to participate in KeyCorp common
stock funds that are now frozen but were previously available as an investment option under our Deferred Savings
Plan and KeyCorp 401(k) plan. By participating in these plans or stock funds, the directors or officers have made,
and/or may from time to time make, elections involving transactions in KeyCorp common shares which may be
designed to satisfy the affirmative defense conditions of Rule 10b5-1 under the Exchange Act or may constitute
non-Rule 10b5-1 trading arrangements (as such term is defined in Item 408(c) of Regulation S-K of the Exchange
Act).
Item 9C. DISCLOSURE REGARDING FOREIGN JURISDICTIONS THAT PREVENT INSPECTIONS
Not applicable.
PART III
Item 10. DIRECTORS, EXECUTIVE OFFICERS AND CORPORATE GOVERNANCE
The names of our executive officers, and biographical information for each, are set forth in Item 1. Business of this report.
The other information required by this item will be set forth in the following sections of KeyCorp’s Definitive Proxy Statement for the 2025 Annual Meeting of Shareholders to be held on May 15, 2025 (the “2025 Proxy Statement”), and these sections are incorporated herein by reference:
-
“Proposal One: Election of Directors”
-
“Corporate Governance Documents — Code of Business Conduct and Ethics”
-
“The Board of Directors and Its Committees — Board and Committee Responsibilities — Audit Committee”
-
“Insider Trading Policies and Procedures”
-
“Additional Information — Other Proposals and Director Nominations for the 2026 Annual Meeting of Shareholders”
KeyCorp expects to file the 2025 Proxy Statement with the SEC on or about March 28, 2025.
Any amendment to, or waiver from a provision of, the Code of Business Conduct and Ethics that applies to KeyCorp’s Chief Executive Officer, Chief Financial Officer, and Chief Accounting Officer, or any other executive officer or director, will be promptly disclosed on KeyCorp’s website (www.key.com/ir) as required by laws, rules and regulations of the SEC.
Item 11. EXECUTIVE COMPENSATION
The information required by this item will be set forth in the following sections of the 2025 Proxy Statement and these sections are incorporated herein by reference:
-
“Compensation Discussion and Analysis”
-
“Compensation of Executive Officers and Directors”
-
“Compensation and Organization Committee Report”
-
“The Board of Directors and Its Committees — Oversight of Compensation Related Risks”
Item 12. SECURITY OWNERSHIP OF CERTAIN BENEFICIAL OWNERS AND MANAGEMENT AND RELATED STOCKHOLDER MATTERS
The information required by this item will be set forth in the section captioned “Ownership of KeyCorp Equity Securities” contained in the 2025 Proxy Statement, and is incorporated herein by reference.
Item 13. CERTAIN RELATIONSHIPS AND RELATED TRANSACTIONS, AND DIRECTOR INDEPENDENCE
The information required by this item will be set forth in the following sections of the 2025 Proxy Statement and these sections are incorporated herein by reference:
-
“The Board of Directors and Its Committees — Director Independence”
-
“The Board of Directors and Its Committees — Related Party Transactions”
Item 14. PRINCIPAL ACCOUNTANT FEES AND SERVICES
The information required by this item will be set forth in the sections captioned “Audit Matters — Ernst & Young’s Fees” and “Audit Matters — Pre-Approval Policies and Procedures” contained in the 2025 Proxy Statement, and is incorporated herein by reference.
PART IV
Item 15. EXHIBITS AND FINANCIAL STATEMENT SCHEDULES
(a) (1) Financial Statements
The following financial statements of KeyCorp and its subsidiaries, and the auditor’s report thereon are filed as part of this report under Item 8. Financial Statements and Supplementary Data:
(a) (2) Financial Statement Schedules
All financial statement schedules for KeyCorp and its subsidiaries have been included in this Form 10-K in the consolidated financial statements or the related footnotes, or they are either inapplicable or not required.
(a) (3) Exhibits*
*Incorporated by reference. Copies of these Exhibits have been filed with
the SEC. Exhibits that are not incorporated by reference are filed with this report. Shareholders may obtain a copy of any exhibit, upon payment of reproduction costs, by writing KeyCorp Investor Relations, 127 Public Square, Mail Code OH-01-27-0737, Cleveland, OH 44114-1306.
Schedules have been omitted pursuant to Item 601(a)(5) of Regulation S-K. KeyCorp hereby undertakes to furnish supplemental copies of any of the omitted schedules upon request by the SEC.
† Certain sensitive personally identifiable information in this exhibit was omitted by means of redacting a portion of the text and replacing it with [***]
KeyCorp hereby agrees to furnish the SEC upon request, copies of instruments, including indentures, which define the rights of long-term debt security holders. The documents listed as Exhibits 10.1 through 10.44 constitute management contracts or compensatory plans or arrangements. In addition, certain confidential portions of the forms of award agreements listed within Exhibits 10.1 through Exhibit 10.44 may be omitted by means of marking
such portions with the brackets (“[***]”) because the identified confidential portions (i) are not material and (ii) would be competitively harmful if publicly disclosed.
Item 16. FORM 10-K SUMMARY
Not applicable.
SIGNATURES
Pursuant to the requirements of Section 13 or 15(d) of the Securities Exchange Act of 1934, the Registrant has duly caused this report to be signed on its behalf by the undersigned, thereunto duly authorized, on the date indicated.
| KEYCORP | ||
| /s/ Clark H. Khayat | ||
| Clark H. Khayat | ||
| Chief Financial Officer (Principal Financial Officer) | ||
| February 21, 2025 | ||
| /s/ Stacy L. Gilbert | ||
| Stacy L. Gilbert | ||
| Chief Accounting Officer (Principal Accounting Officer) | ||
| February 21, 2025 |
Pursuant to the requirements of the Securities Exchange Act of 1934, this report has been signed below by the following persons on behalf of the Registrant and in the capacities and on the date indicated.
| Signature | Title | |||||||
| /s/ Christopher M. Gorman | Chairman, Chief Executive Officer and President (Principal Executive Officer), and Director | |||||||
| Christopher M. Gorman | ||||||||
| /s/ Clark H. Khayat | Chief Financial Officer (Principal Financial Officer) | |||||||
| Clark H. Khayat | ||||||||
| /s/ Stacy L. Gilbert | Chief Accounting Officer (Principal Accounting Officer) | |||||||
| Stacy L. Gilbert | ||||||||
| *Jacqueline Allard | Director | |||||||
| *Alexander M. Cutler | Director | |||||||
| *H. James Dallas | Director | |||||||
| *Elizabeth R. Gile | Director | |||||||
| *Ruth Ann M. Gillis | Director | |||||||
| *Robin N. Hayes | Director | |||||||
| *Carlton L. Highsmith | Director | |||||||
| *Richard J. Hipple | Director | |||||||
| *Somesh Khanna | Director | |||||||
| *Devina A. Rankin | Director | |||||||
| *Barbara R. Snyder | Director | |||||||
| *Richard J. Tobin | Director | |||||||
| *Todd J. Vasos | Director | |||||||
| *David K. Wilson | Director |
| /s/ James L. Waters | ||
| * By James L. Waters, attorney-in-fact | ||
| February 21, 2025 |