Item 1. BUSINESS

67K characters. Original on sec.gov · Markdown

Item 1. BUSINESS

Northern Trust Corporation

Northern Trust Corporation (Corporation) is a leading provider of wealth management, asset servicing, asset management and banking solutions to corporations, institutions, families and individuals. The Corporation is a financial holding company conducting business through various U.S. and non-U.S. subsidiaries, including The Northern Trust Company (Bank).

The Bank is an Illinois banking corporation headquartered in Chicago and the Corporation’s principal subsidiary. Founded in 1889, the Bank conducts its business through its U.S. operations and its various U.S. and non-U.S. branches and subsidiaries. At December 31, 2021, the Bank had consolidated assets of $183.7 billion and common bank equity capital of $11.1 billion.

The Corporation was formed as a holding company for the Bank in 1971. The Corporation has a global presence with offices in 23 U.S. states and Washington, D.C., and across 23 locations in Canada, Europe, the Middle East and the Asia-Pacific region. At December 31, 2021, the Corporation had consolidated total assets of $183.9 billion and stockholders’ equity of $12.0 billion.

The Corporation expects that the Bank will continue in the foreseeable future to be the major source of the Corporation’s consolidated assets, revenues, and net income. Except where the context otherwise requires, references to “Northern Trust,” “we,” “us,” “our,” “its,” or similar terms mean Northern Trust Corporation and its subsidiaries on a consolidated basis.

Business Overview

Northern Trust focuses on managing and servicing client assets through its two client-focused reporting segments: Corporate & Institutional Services (C&IS) and Wealth Management. Asset management and related services are provided to C&IS and Wealth Management clients primarily by the Asset Management business. The revenue and expenses of Asset Management and certain other support functions are allocated fully to C&IS and Wealth Management. Northern Trust reports certain income and expense items not allocated to C&IS and Wealth Management in a third reporting segment, Other.

CORPORATE & INSTITUTIONAL SERVICES

C&IS is a leading global provider of asset servicing and related services to corporate and public retirement funds, foundations, endowments, fund managers, insurance companies, sovereign wealth funds, and other institutional investors around the globe. Asset servicing and related services encompass a full range of capabilities including but not limited to: custody; fund administration; investment operations outsourcing; investment management; investment risk and analytical services; employee benefit services; securities lending; foreign exchange; treasury management; brokerage services; transition management services; banking; and cash management. Client relationships are managed through the Bank and the Bank’s and the Corporation’s other subsidiaries, including support from locations in North America, Europe, the Middle East, and the Asia-Pacific region. At December 31, 2021, total C&IS assets under custody/administration, assets under custody, and assets under management were $15.18 trillion, $11.55 trillion, and $1.19 trillion, respectively.

WEALTH MANAGEMENT

Wealth Management focuses on high-net-worth individuals and families, business owners, executives, professionals, retirees, and established privately-held businesses in its target markets. In supporting these targeted segments, Wealth Management provides trust, investment management, custody, and philanthropic services; financial consulting; guardianship and estate administration; family business consulting; family financial education; brokerage services; and private and business banking. Wealth Management also includes Global Family Office, which provides customized services, including but not limited to: investment consulting; global custody; fiduciary; and private banking to meet the complex financial needs of ultra-high-net-worth individuals and family offices across the globe.

Wealth Management is one of the largest providers of advisory services in the United States, with assets under custody/administration, assets under custody, and assets under management of $1.07 trillion, $1.06 trillion, and $416.1 billion, respectively, at December 31, 2021. Wealth Management services are delivered by multidisciplinary teams through a network of offices in 19 U.S. states and Washington, D.C., as well as offices in London, Guernsey, and Abu Dhabi.

ASSET MANAGEMENT

Asset Management, through the Corporation’s various subsidiaries, supports the C&IS and Wealth Management reporting segments by providing a broad range of asset management and related services and other products to clients around the world. Investment solutions are delivered through separately managed accounts, bank common and collective

2021 Annual Report | Northern Trust Corporation 1

funds, registered investment companies, exchange traded funds, non-U.S. collective investment funds, and unregistered private investment funds. Asset Management’s capabilities include active and passive equity; active and passive fixed income; cash management; multi-asset and alternative asset classes (such as private equity and hedge funds of funds); and multi-manager advisory services and products. Asset Management’s activities also include overlay services and other risk management services. Asset Management operates internationally through subsidiaries and distribution arrangements and its revenue and expense are fully allocated to C&IS and Wealth Management. As discussed above, Northern Trust managed $1.61 trillion in assets as of December 31, 2021, including $1.19 trillion for C&IS clients and $416.1 billion for Wealth Management clients.

Competition

Northern Trust faces intense competition in all aspects and areas of its business. Competition comes from both regulated and unregulated financial services organizations, whose products and services span the local, national, and global markets in which Northern Trust conducts operations. Our competitors include a broad range of financial institutions and service companies, including other custodial banks, deposit-taking institutions, asset management firms, benefits consultants, trust companies, investment banking firms, insurance companies, investment counseling firms, and various financial technology companies, including software providers and data services firms. As our businesses grow and markets evolve, we may encounter increasing and new forms of competition around the world.

Northern Trust’s business strategy is to provide quality financial services to targeted market segments in which it believes it has a competitive advantage and favorable growth prospects. As part of this strategy, Northern Trust seeks to differentiate itself from its competitors with premier, holistic solutions and exceptional experiences tailored to meet clients’ needs. In addition, Northern Trust emphasizes the development and growth of recurring sources of fee-based income and continual productivity improvements. Northern Trust also seeks to maintain its foundational strength with a strong, conservative balance sheet and a globally respected brand.

Economic Conditions And Government Policies

The earnings of Northern Trust are affected by numerous external influences. Chief among these are general economic conditions, both domestic and international, and actions that governments and their central banks take in managing their economies. These general conditions affect all of Northern Trust’s businesses, as well as the quality, value, and profitability of its loan and investment portfolios.

The Board of Governors of the Federal Reserve System (Federal Reserve Board) implements monetary policy through its open market operations in United States Government securities, its setting of the discount rate at which member banks may borrow from Federal Reserve Banks, and its changes in the reserve requirements for deposits. The policies adopted by the Federal Reserve Board directly affect interest rates and therefore what banks earn on their loans and investments and what they pay on their savings and time deposits and other purchased funds.

Supervision and Regulation

Northern Trust is subject to extensive regulation under state and federal laws in the United States and in each of the jurisdictions in which it does business. The discussion below outlines significant elements of selected laws and regulations applicable to Northern Trust. Changes in laws or regulations applicable to Northern Trust may have a material effect on its businesses and results of operations.

FINANCIAL HOLDING COMPANY REGULATION

Under U.S. law, the Corporation is a bank holding company that has elected to be a financial holding company subject to the supervision, examination, and regulation of the Federal Reserve Board. A financial holding company is permitted to engage in a broader range of financial activities than a bank holding company. The Federal Reserve Board has authority to limit the activities that a financial holding company may conduct if any depository institution controlled by the financial holding company is found to no longer be “well-capitalized” and “well-managed” or has not received at least a “satisfactory” rating in its most recent Community Reinvestment Act (CRA) examination. Failure to meet one or more of these requirements may result in restrictions on the Corporation’s ability to exercise powers granted to financial holding companies, to engage in new activities, to continue current activities, or to make acquisitions.

SUBSIDIARY REGULATION

The Bank is a member of the Federal Reserve System, with deposits insured by the Federal Deposit Insurance Corporation (FDIC), and is subject to regulation by both agencies. As an Illinois banking corporation, the Bank is also subject to Illinois state laws and regulations and to examination and supervision by the Division of Banking of the Illinois Department of Financial and Professional Regulation. The Bank is also registered as a transfer agent with the Federal Reserve Board and is registered provisionally as a swap dealer with the U.S. Commodity Futures Trading Commission

2 2021 Annual Report | Northern Trust Corporation

(CFTC) under the Commodity Exchange Act. As a result, the Bank is subject to supervision, examination and enforcement by certain other regulatory bodies, including the CFTC and the National Futures Association (NFA).

The Corporation’s nonbanking affiliates are subject to examination by the Federal Reserve Board and, in certain circumstances, other functional regulators. The Corporation’s broker-dealer subsidiary is a member of the Financial Industry Regulatory Authority (FINRA), is registered with the U.S. Securities and Exchange Commission (SEC) as a broker-dealer, investment adviser, and municipal securities dealer, and is subject to the rules and regulations of these bodies. Certain nonbanking affiliates are registered with the CFTC as commodity trading advisors and commodity pool operators and subject to supervision and regulation by the CFTC and NFA. Other subsidiaries of the Corporation are registered with the SEC as investment advisers and are subject to regulation by the SEC. Subsidiaries may also be regulated by state regulators in various states.

THE DODD-FRANK ACT, AS AMENDED

The following items provide a brief description of certain provisions of the Dodd-Frank Wall Street Reform and Consumer Protection Act (Dodd-Frank Act), as implemented through final rules promulgated by the Federal Reserve Board and other agencies and amended by the Economic Growth, Regulatory Relief, and Consumer Protection Act (the Regulatory Relief Act), most relevant to the Corporation and its subsidiaries, including the Bank.

Enhanced Prudential Standards. The Dodd-Frank Act, as implemented by the Federal Reserve Board through various rulemakings and amended by the Regulatory Relief Act, generally imposes enhanced prudential requirements on U.S. bank holding companies with at least $100 billion in total consolidated assets, including the Corporation. The enhanced prudential standards include stringent risk-based capital, leverage, liquidity, risk management, and stress testing requirements and single counterparty credit limits for large bank holding companies, including the Corporation. The Federal Reserve Board also has the discretion to require these large U.S. bank holding companies to limit their short-term debt, to issue contingent capital instruments, and to provide enhanced public disclosures.

In October 2019, the Federal Reserve Board finalized a proposed rule implementing changes made by the Regulatory Relief Act. This rule introduced a new four-category framework to determine which enhanced prudential standards and other requirements are applicable to institutions with total consolidated assets of at least $100 billion, based on asset thresholds and other risk-based factors. Under the new rules, the Corporation is classified as a Category II institution.

The requirements under the new framework that apply to the Corporation are largely unchanged as a result of the Federal Reserve Board’s final tailoring rule for enhanced prudential standards. The Corporation must submit annual capital plans to the Federal Reserve Board, conduct supervisory and internal periodic stress tests to evaluate capital adequacy in adverse economic conditions, maintain enhanced risk management procedures, comply with a liquidity risk management framework (discussed below in “Liquidity Standards”) and aggregate credit exposure limits, conduct liquidity stress tests, and hold a buffer of liquid assets estimated to meet funding needs during a financial stress event. The Corporation is not subject to the total loss-absorbing capacity requirement, capital surcharge, enhanced supplementary leverage ratio, or aggregate credit exposure limit that apply to U.S. bank holding companies that are global systemically important bank holding companies.

Resolution Planning. As required by Section 165(d) of the Dodd-Frank Act, the Corporation is required to submit periodically to regulators a resolution plan for its rapid and orderly resolution in the event of material financial distress or failure. In addition, under an FDIC rule (the CIDI Resolution Plan Rule) the Bank must submit to the FDIC periodic plans for resolution in the event of its failure.

On March 29, 2019, the Federal Reserve Board and the FDIC provided joint written feedback to the Corporation regarding the resolution plan submitted by the Corporation in December 2017, pursuant to Section 165(d) of the Dodd-Frank Act (the 2017 165(d) Plan). The joint written feedback stated that the Federal Reserve Board and FDIC did not identify shortcomings or deficiencies in the 2017 165(d) Plan. On December 9, 2020, the Corporation received written guidance from the FDIC and Federal Reserve confirming that the 2021 resolution plan submission would be a targeted plan and include a targeted information request related to actions in response to events surrounding the COVID-19 pandemic. On December 17, 2021, the Corporation submitted its 2021 Section 165(d) resolution plan. In this submission, the Corporation addressed the requirements of a targeted resolution plan, as well as the targeted information request specified in the Federal Reserve Board and FDIC guidance letter.

In addition, on June 27, 2018, the Bank submitted its resolution plan (the 2018 CIDI Plan) to the FDIC under the CIDI Resolution Plan Rule. To date, no formal written feedback or guidance has been received regarding the 2018 CIDI Plan. On January 19, 2021, the FDIC announced that it will resume requiring resolution plan submissions for insured depository institutions with $100 billion or more in assets. The FDIC announcement indicated that no firm will be required to submit a resolution plan without at least 12 months advance notice provided to the firm. To date, the Bank has not received notice from the FDIC indicating its next resolution plan submission date.

Separately, the European Union Bank Recovery and Resolution Directive (BRRD) sets out the framework for the recovery and resolution of European Union (EU) credit institutions and investment firms, including certain of the Bank’s

2021 Annual Report | Northern Trust Corporation 3

subsidiaries and branches, effective January 1, 2015. The BRRD established a set of harmonized rules for early intervention measures, recovery and resolution planning, bail-in powers and requirements for total loss absorbing capital for EU institutions, collectively known as minimum requirements for own funds and eligible liabilities (MREL). The BRRD was materially amended, including with respect to the MREL requirements, with the amended directive coming into force in December 2020. Northern Trust Global Services SE, a Luxembourg-incorporated indirect subsidiary of the Bank, is authorized and supervised by the European Central Bank (ECB) and subject to the prudential supervision of the ECB and the Luxembourg Commission de Surveillance du Secteur Financier (CSSF). As such, Northern Trust Global Services SE falls within the scope of the BRRD and its recovery and resolution planning is overseen by the CSSF and Single Resolution Board (the resolution authority for ECB-supervised institutions).

The United Kingdom (UK) has established a special resolution regime and a resolvability assessment framework overseen by the Bank of England (as the UK resolution authority) which has many similar features to the BRRD, which was substantially incorporated into UK law following the withdrawal of the UK from the EU. The special resolution regime applies to firms that are permitted to accept deposits under Part 4A of the Financial Services and Markets Act 2000. As such, the London branch of the Bank, as a UK branch of a third-country institution that accepts deposits, falls within the scope of the special resolution regime.

Orderly Liquidation Authority. Under the Dodd-Frank Act, certain financial companies, such as the Corporation and certain of its covered subsidiaries, can be subjected to an orderly liquidation authority if in default or danger of default and their resolution under the U.S. Bankruptcy Code would have serious adverse effects on financial stability in the United States, among other requirements set by statute. If the Corporation were subject to orderly liquidation authority, the FDIC would be appointed as its receiver, which would give the FDIC considerable powers to resolve the Corporation. Absent such actions, the Corporation, as a bank holding company, would remain subject to the U.S. Bankruptcy Code.

The Volcker Rule. The Volcker Rule bans proprietary trading subject to exceptions, such as for market-making, hedging, certain trading activities in U.S. and foreign sovereign debt, certain trading activities of non-U.S. banking entities trading outside the United States, and trading activities related to liquidity management. The Volcker Rule also imposes significant restrictions on sponsoring or investing in certain “covered funds,” such as hedge funds or private equity funds, again subject to exceptions. Northern Trust maintains an enterprise-wide compliance program to comply with the Volcker Rule.

Swaps and Other Derivatives. The Dodd-Frank Act imposed a regulatory structure on the over-the-counter derivatives market, including requirements for clearing, exchange trading, capital, margin, trade reporting, and recordkeeping. The Dodd-Frank Act also requires certain entities to register as a “major swap participant,” a “swap dealer,” a “major-security-based swap participant” or a “security-based swap dealer.” The Bank is required to register as a swap dealer and its swap dealer activities are subject to the CFTC’s rules and regulations, including rules regarding internal and external business conduct standards, reporting and recordkeeping, mandatory clearing for certain swaps, trade documentation and confirmation requirements, and cross-border swap activities. The Bank is also subject to Federal Reserve Board regulations regarding mandatory posting and collection of margin by certain swap counterparties. The Corporation has not registered and does not expect that it, or any of its affiliates, will be required to register as a security-based swap dealer with the SEC.

HOLDING COMPANY SUPPORT UNDER THE FEDERAL DEPOSIT INSURANCE ACT

The Dodd-Frank Act amended the Federal Deposit Insurance Act (FDIA) to obligate the Federal Reserve Board to require bank holding companies, such as the Corporation, to serve as a source of financial and managerial strength for any subsidiary depository institution. Under this requirement, the Corporation in the future could be required to provide financial assistance to the Bank should the Bank experience financial distress.

PAYMENT OF DIVIDENDS

The Corporation may pay dividends, repurchase stock, and make other capital distributions only in accordance with the capital plan rules and capital adequacy standards of the Federal Reserve Board, including the stress capital buffer requirement, discussed further in “—Capital Adequacy Requirements” below. Dividends from the Bank are a significant source of funds for the Corporation, and the Corporation’s ability to pay dividends on its common stock therefore depends on the ability of the Bank to pay sufficient dividends to the Corporation.

Various other federal and state laws and regulations limit the amount of dividends that may be paid by the Bank to the Corporation without regulatory consent. The Bank may not pay any dividends if it is undercapitalized, or if the payment of the dividend would cause it to become undercapitalized. In general, the amount of dividends that may be paid in a calendar year is limited to its “recent earnings” (the current year’s net income combined with the retained net income of the two preceding years), or its “undivided profits” (generally, accumulated net profits that have not been paid out as dividends or transferred to surplus), whichever is less. The ability of the Bank to pay dividends to the Corporation may also be affected by the capital adequacy standards applicable to the Bank (discussed further below), which include minimum requirements and buffers.

4 2021 Annual Report | Northern Trust Corporation

CAPITAL PLANNING AND STRESS TESTING

The Corporation’s capital distributions are subject to the Federal Reserve Board’s capital plan rules, which require the Corporation to submit annual capital plans to the Federal Reserve Board for review.

The major components of that oversight are the Federal Reserve Board’s Comprehensive Capital Analysis and Review (CCAR) and Dodd-Frank Act stress tests (DFAST). These requirements involve both company-run and supervisory-run testing of capital under various scenarios, including baseline and severely adverse scenarios provided by the appropriate banking regulator. Results from the Corporation’s and the Bank’s annual company-run stress tests are reported to the appropriate regulators and made publicly available.

Under the DFAST regulations, the Corporation is required to undergo regulatory stress tests conducted by the Federal Reserve Board annually. The Bank also is required to conduct its own annual internal stress test (although it is permitted to combine certain reporting and disclosure of its stress test results with the results of the Corporation). Results from the Corporation’s and the Bank’s annual company-run stress tests are reported to the appropriate regulators and made publicly available. Northern Trust published the results of its most recent company-run stress tests on June 24, 2021.

CAPITAL ADEQUACY REQUIREMENTS

The Corporation, as a bank holding company, is subject to risk-based and leverage capital guidelines implemented by the Federal Reserve Board that are based on industry-standard guidelines published by the International Basel Committee on Banking Supervision (Basel Committee), known as Basel III. The Bank, as an FDIC-insured depository institution, is also required to meet risk-based and leverage capital guidelines established by regulators which are generally similar to those established by the Federal Reserve Board for bank holding companies.

Under the final Basel III rules, the Corporation, with the Bank, is a “core” banking organization that is required to use the advanced approaches methodologies to calculate and disclose publicly its risk-based capital ratios. The Corporation also is subject to a capital floor that is based on the Basel III standardized approach to calculating risk-based capital ratios. The Corporation is therefore required to calculate its risk-based capital ratios under both the standardized and advanced approaches, and is subject to the more stringent of the two in the assessment of its capital adequacy.

The Bank’s risk-based and leverage capital ratios at December 31, 2021, were well above the regulatory requirements established by U.S. banking regulators. The risk-based and leverage capital ratios for the Corporation and the Bank, together with the regulatory minimum ratios and the ratios required for classification as “well-capitalized,” are provided in the following chart.

TABLE 1: RISK-BASED AND LEVERAGE CAPITAL RATIOS AS OF DECEMBER 31, 2021

COMMON EQUITY TIER 1 CAPITALTIER 1 CAPITALTOTAL CAPITALTIER 1 LEVERAGESUPPLEMENTARY LEVERAGE(1)
STANDARDIZED APPROACHADVANCED APPROACHSTANDARDIZED APPROACHADVANCED APPROACHSTANDARDIZED APPROACHADVANCED APPROACHSTANDARDIZED APPROACHADVANCED APPROACHADVANCED APPROACH
Northern Trust Corporation11.9%13.2%12.9%14.3%14.1%15.3%6.9%6.9%8.2%
The Northern Trust Company12.0%13.5%12.0%13.5%13.0%14.4%6.4%6.4%7.6%
Minimum required ratio4.5%4.5%6.0%6.0%8.0%8.0%4.0%4.0%3.0%
“Well-capitalized” minimum ratios, as applicable
Northern Trust CorporationN/AN/A6.0%6.0%10.0%10.0%N/AN/AN/A
The Northern Trust Company6.5%6.5%8.0%8.0%10.0%10.0%5.0%5.0%3.0%

(1) In November 2019, the Federal Reserve Board and other U.S. federal banking agencies adopted a final rule that established a deduction for central bank deposits from the total leverage exposures of custodial banking organizations, including the Corporation and the Bank, equal to the lesser of (i) the total amount of funds the custodial banking organization and its consolidated subsidiaries have on deposit at qualifying central banks and (ii) the total amount of client funds on deposit at the custodial banking organization that are linked to fiduciary or custodial and safekeeping accounts. The rule became effective on April 1, 2020. The supplementary leverage ratios at December 31, 2021 for the Corporation and the Bank reflect the impact of this final rule.

Advanced approaches institutions, such as the Corporation and the Bank, are subject to a minimum supplementary leverage ratio of 3.0%. Advanced approaches institutions that are insured depository institutions, such as the Bank, also must maintain at least a 3.0% supplementary leverage ratio to be considered “well-capitalized.” The Corporation is also subject to a stress capital buffer, which integrates forward-looking stress test results with non-stress capital requirements, and the Bank is also subject to a capital conservation buffer, which respectively requires the Corporation and the Bank to hold a buffer of Common Equity Tier 1 capital above the minimum risk-based capital requirements in order to avoid constraints on dividends, equity repurchases and compensation. The minimum capital buffer requirement for advanced approaches banking organizations, such as the Corporation and the Bank, is 2.5%.

2021 Annual Report | Northern Trust Corporation 5

A “countercyclical buffer” of 0% to 2.5% of a banking organization’s total risk-weighted assets for advanced approaches banking organizations, such as the Corporation, is also a component of the capital adequacy framework. In general, the amount of the countercyclical capital buffer is a weighted average of the countercyclical capital buffer established in the various jurisdictions in which the banking organization has credit exposures. The U.S. countercyclical buffer is currently set at 0%.

As a result of the stress test results published by the Federal Reserve Board on June 24, 2021, the Corporation’s stress capital buffer requirement for the 2021 capital plan cycle was set at 2.5%. The 2021 stress capital buffer became effective October 1, 2021, and results in an effective Common Equity Tier 1 capital ratio minimum requirement of 7.0% inclusive of this buffer.

LIQUIDITY STANDARDS

Northern Trust is subject to the U.S. liquidity coverage ratio (LCR) requirement, which is designed to ensure that covered banking organizations including the Corporation and the Bank maintain an adequate level of unencumbered high-quality liquid assets equal to their expected net cash outflow for a 30-day time horizon under a prescribed regulatory liquidity stress scenario. As of December 31, 2021, the Corporation and the Bank were in compliance with applicable LCR requirements.

Northern Trust also is subject to the U.S. net stable funding ratio (NSFR) requirement, designed to promote more medium- and long-term funding of the assets and activities of banking entities over a one-year time horizon. As of December 31, 2021, the Corporation and the Bank were in compliance with applicable NSFR requirements.

The enhanced prudential standards imposed by the Dodd-Frank Act, as amended by the Regulatory Relief Act, specify certain required liquidity risk management practices for large bank holding companies and banks. The Federal Reserve Board’s October 2019 final tailoring rule targets certain aspects of these requirements based on banking organizations’ business model and risk profile, as delineated into four risk-based categories. The Corporation, a Category II institution under the final tailoring rule, is subject to the liquidity risk management, monthly liquidity stress testing, liquidity buffer, and daily liquidity reporting requirements.

PROMPT CORRECTIVE ACTION

Federal banking regulators are required to take “prompt corrective action” with respect to a depository institution if that institution does not meet certain capital adequacy standards, and are also authorized to take appropriate action against a parent bank holding company of an under-capitalized banking subsidiary. In certain instances, the Corporation could be required to guarantee the performance of a capital restoration plan for the Bank if it were under-capitalized.

RESTRICTIONS ON TRANSACTIONS WITH AFFILIATES

The Bank is subject to restrictions governing transactions between it and affiliated entities, including the Corporation, its affiliates, and its subsidiaries. These transactions must be on terms and conditions that are, or in good faith would be, offered to nonaffiliated companies (i.e., on terms not less favorable to the Bank than market terms). Further, extensions of credit must be secured fully with qualifying collateral and are limited to 10% of the Bank’s capital and surplus for transactions with a single affiliate and to 20% of the Bank’s capital and surplus for transactions with all affiliates.

ANTI-MONEY LAUNDERING, ANTI-TERRORISM LEGISLATION, AND OFFICE OF FOREIGN ASSETS CONTROL

The Corporation and certain of its subsidiaries are subject to the Bank Secrecy Act of 1970, as amended by the USA PATRIOT Act of 2001 and implemented in the regulation of the federal banking regulators and Financial Crimes Enforcement Network, which contain anti-money laundering (AML) and financial transparency requirements for conducting due diligence, verifying client and beneficial owner identification, and monitoring client transactions and detecting and reporting suspicious activities. AML laws outside the United States contain similar requirements.

Various legal requirements prohibit Northern Trust entities from engaging in business in or with certain jurisdictions and parties, such as organizations and countries suspected of aiding, harboring or engaging in terrorist acts or undermining the sovereignty and territorial integrity of democratic countries. The U.S. Department of the Treasury’s Office of Foreign Assets Control publishes lists of these prohibited parties. If the Corporation or the Bank finds a sanctioned name or jurisdiction on any transaction or account, the Corporation or the Bank must reject or block such account or transaction and notify the appropriate authorities.

Failure to comply with these requirements could result in fines, penalties, lawsuits, regulatory sanctions or difficulties in obtaining approvals, restrictions on their business activities or harm to reputation. Many other countries have imposed similar laws and regulations that apply to the Corporation’s non-U.S. offices. The Corporation has established policies and procedures to comply with these laws and the related regulations.

DEPOSIT INSURANCE AND ASSESSMENTS

The Bank accepts deposits, and eligible deposits have the benefit of FDIC insurance up to the applicable limit, which is currently $250,000 for each depositor account. Under the FDIA, insurance of deposits may be terminated by the FDIC

6 2021 Annual Report | Northern Trust Corporation

upon a finding that the insured depository institution has engaged in unsafe and unsound practices, is in an unsafe or unsound condition, or has violated laws, regulations, or orders from a regulatory agency. Certain liquid assets are excluded from the deposit insurance assessment base of custody banks that satisfy certain institutional eligibility criteria. This has the effect of reducing the amount of deposit insurance fund insurance premiums payable by custody banks. The Bank qualifies as a custody bank for this purpose.

COMMUNITY REINVESTMENT ACT

The Bank is subject to the Community Reinvestment Act (CRA). The CRA and the regulations issued thereunder are intended to encourage banks to help meet the credit needs of their service areas, including low and moderate income neighborhoods, consistent with the safe and sound operations of the banks. The Bank fulfills its CRA obligations by making qualified investments for the purposes of community development. The Bank received an “outstanding” CRA rating from the Federal Reserve Board in its most recent CRA examination.

PRIVACY AND SECURITY

Federal law establishes a minimum federal standard of financial privacy by, among other provisions, requiring financial institutions to adopt, disclose, and enforce privacy policies with respect to consumer information, setting limitations on disclosure to third parties of consumer information, setting standards for protecting client information and preventing unlawful access to such information, and requiring notice of data breaches in certain circumstances.

Most states, the EU and other non-U.S. jurisdictions also have adopted their own statutes and/or regulations concerning data privacy and security and requiring notification of data breaches. For example, a European data protection framework—the General Data Protection Regulation (GDPR)—was adopted on April 8, 2016, and became effective in all European Economic Area (EEA) member states on May 25, 2018. GDPR also has been implemented into UK law as part of the arrangements following the UK’s withdrawal from the EU and operates in conjunction with other local data privacy requirements. GDPR is designed to harmonize data privacy laws across the EEA, to protect EEA citizens’ data privacy and to reshape the way organizations across the region approach data privacy. GDPR has extraterritorial effect as its scope includes all data controllers and processors outside the EEA whose processing activities relate to the offering of goods or services to, or monitoring the behavior of, EEA individuals. Organizations that violate certain provisions of GDPR could be fined up to €20 million or 4% of their annual worldwide revenue for the preceding fiscal year, whichever is greater.

In the United States, the California Consumer Privacy Act (CCPA) was adopted by the State of California and became effective January 1, 2020, and then enforceable on July 1, 2020. The CCPA substantially increased the rights of California residents to understand how their personal data is collected and used by commercial businesses. The CCPA includes a private right of action (permitting lawsuits to be brought by private individuals instead of the state Attorney General or other government actor for breaches), and contemplates civil penalties of up to $2,500 for each violation and up to $7,500 for each intentional violation. On November 3, 2020, the California Privacy Rights Act of 2020 (CPRA), which amends and supersedes portions of the CCPA, was approved by a majority of California voters. Among other changes, the CPRA establishes the California Privacy Protection Agency to administer, implement, and enforce the CCPA and CPRA. The CPRA is expected to be fully operative beginning in 2023, and will apply to personal information collected on or after January 1, 2022. However, the CCPA, including its implementing regulations, remains in effect until the CPRA is operative.

The Corporation has adopted and disseminated privacy policies and communicates required information relating to financial privacy and data security in accordance with applicable law.

CONSUMER LAWS AND REGULATIONS

The Corporation’s banking subsidiaries are subject to certain federal and state laws and regulations designed to protect consumers in transactions with banks. Failure to comply with these laws and regulations could lead to substantial penalties, operating restrictions and reputational damage to the financial institution. Consumer laws and regulations are enforced by the Consumer Financial Protection Bureau (CFPB) and other federal and state regulators.

NON-U.S. REGULATION

Northern Trust is subject to the laws and regulatory authorities of the jurisdictions in which its non-U.S. branches and subsidiaries operate. For example, branches and subsidiaries conducting banking and asset servicing businesses in the UK are authorized to do so pursuant to the UK Financial Services and Markets Act 2000. They are authorized by the Prudential Regulation Authority (PRA) and/or the Financial Conduct Authority (FCA). The PRA and FCA exercise broad supervisory and disciplinary powers that include the power to revoke temporarily or permanently authorization to conduct a regulated business upon breach of the relevant regulations, impose capital requirements, suspend registered employees, and impose censures and fines on both regulated businesses and their regulated employees.

Northern Trust’s European branches and subsidiaries are subject to the laws and regulatory authorities of the EU and the member states in which they are domiciled. For example, Northern Trust Global Services SE as an EU-domiciled credit

2021 Annual Report | Northern Trust Corporation 7

institution in Luxembourg, is subject to the prudential supervision of the ECB and the CSSF. Moreover, Northern Trust’s non-EU branches and subsidiaries conducting financial services activities in the EU may fall within the scope of the laws of the EU and, given the increasing extraterritorial effect of EU legislation, non-EU branches and subsidiaries may still fall within the scope of EU law if they transact outside of the EU with EU clients.

Since January 31, 2020, the UK has not been a member of the EU. EU legislation as it applied to the UK on December 31, 2020 is a part of UK domestic legislation, under the control of the UK’s parliament and assemblies. Most UK law relevant to the Corporation and its subsidiaries is still closely aligned with the EU legislative framework in place in December 2020.

The following items provide a brief description of certain key regulatory requirements in the EU and the UK relevant to the Corporation and its subsidiaries, in addition to the BRRD and GDPR discussed under “The Dodd-Frank Act, as Amended—Resolution Planning” and “Privacy and Security,” respectively, above.

EU and UK Prudential Regulatory Frameworks. The EU Capital Requirements Directive of June 26, 2013 (CRD) and the EU Capital Requirements Regulation of June 26, 2013 (CRR) set out the framework for prudential regulation of credit institutions in the EU, including, among other things, capital and liquidity requirements, leverage, and disclosure and reporting. CRR and CRD have been subject to extensive amendments by a new directive (CRD V) and the revised CRR (CRR II). CRD V and CRR II entered into force on June 27, 2019. CRD V has largely applied since December 29, 2020, and CRD II has largely applied since June 28, 2021. The key changes introduced by CRD V and CRR II include changes to the leverage ratio, the net stable funding ratio, large exposures, and market and counterparty credit risk. Since June 26, 2021, investment firms under the Markets in Financial Instruments Directive (MIFID) have been subject to a new prudential regime under the EU Investment Firm Directive and Investment Firm Regulation. In April 2021, the Financial Services Act came into force in the UK establishing among other things, (i) a framework for the new investment firm prudential framework to apply in the UK and (ii) the UK implementation of Basel III standards, including amendments to CRR implemented into the UK following the withdrawal from the EU. UK and EU branches and subsidiaries of the Corporation may also be subject to local rules on outsourcing and operational resilience.

Markets Regulation. MIFID (which came into force in 2018), the linked Markets in Financial Instruments Regulation (MIFIR), and the European Market Infrastructure Regulation 648/2012 (EMIR) are the primary pieces of EU legislation which regulate, among other things, trading in derivative and securities markets, transaction reporting, investor protection, clearing and risk mitigation. MIFID, MIFIR and EMIR, with applicable amendments, now form part of UK law under the legislation implemented when the UK left the EU.

Central Securities Depositories Regulation. On September 17, 2014, the EU Central Securities Depositories Regulation (CSDR) entered into force (subject to a number of transitional provisions). The CSDR aims principally to ensure that transactions between buyers and sellers of dematerialized securities are settled in a safe and timely manner by introducing common securities settlement standards across the EU. Key features of the CSDR include shorter settlement periods, settlement discipline measures (including mandatory cash penalties and ‘buy-ins’ for settlement fails and settlement fails reporting) and an obligation regarding dematerialization for most securities. In November 2021, EU legislators announced a delay to the implementation of the CSDR mandatory buy-in rules under the settlement discipline regime.

Securities Financing Transactions and Reuse of Collateral Regulation. On November 25, 2015, the EU adopted a regulation on securities financing transactions and reuse of collateral (SFTR) as part of its approach to addressing shadow banking. The regulation includes provisions for enhanced transparency and reporting of securities financing transactions. The SFTR entered into force on January 12, 2016. The reporting obligations under the SFTR have been phased in since April 11, 2020, with the final phase commencing on January 11, 2021.

UK Criminal Finances Act. On September 30, 2017, the UK Criminal Finances Act (CFA) entered into force. The CFA has extra-territorial effect, introducing certain new corporate criminal offenses in circumstances where a corporate entity or partnership (a relevant body) fails to prevent an “associated person” (broadly meaning an employee, agent or person who performs services for or on behalf of the relevant body) from criminally facilitating the evasion of tax, whether the tax evaded is owed (i) in the UK or (ii) in a foreign country if the relevant body has a nexus, or any conduct constituting part of the foreign tax evasion facilitation offense takes place, in the UK. These corporate offenses are strict liability offenses, such that in circumstances where an associated person of a relevant body criminally facilitates the evasion of tax and such relevant body has failed to prevent the associated person from committing such criminal facilitation of tax evasion, the relevant body will itself be guilty of a criminal offense carrying unlimited fines, unless it can show that it put in place reasonable prevention procedures (or by showing that it was not reasonable in all the circumstances to expect the relevant body to have any prevention procedures in place).

Benchmarks Regulation. On January 1, 2018, the EU Benchmarks Regulation (BMR) became applicable in all EU member states. The principal objectives of the BMR are to restore investor confidence in the accuracy, robustness and integrity of indices used as benchmarks in financial instruments and financial contracts or to measure the performance of

8 2021 Annual Report | Northern Trust Corporation

investment funds, and the benchmark-setting process itself. The BMR aims to achieve these objectives by ensuring that benchmarks are not subject to conflicts of interest, are used appropriately, and reflect the actual market or economic reality they are intended to measure. BMR has been incorporated into UK law following the withdrawal from the EU, with applicable amendments. In 2017, the FCA and the Bank of England’s Financial Policy Committee raised questions about the future sustainability of the London Interbank Offered Rate (LIBOR) benchmarks and began planning the transition to alternative reference rates beginning December 31, 2021. The UK and EU legislators have each taken legislative steps to manage the transition from LIBOR. In the UK, the FCA has exercised powers under the BMR to effect the publication of a synthetic LIBOR rate for one-month, three-month and six-month sterling and yen LIBOR beyond 2021. In December 2021, the Critical Benchmarks (References and Administrators’ Liability) Act 2021 was passed in the UK. That legislation includes “safe harbor” provisions to mitigate certain litigation risks associated with contractual continuity following the transition to synthetic LIBOR.

Sustainable Finance Disclosure Regulations. On December 29, 2019, the EU Sustainable Finance Disclosure Regulations (SFDR) entered into force. SFDR aims to prevent “greenwashing” (conveying a misleading or false impression a product is more environmentally favorable than it actually is) by requiring disclosure of how sustainability risks and environmental, social and governance (ESG) factors are part of the investment and business processes of asset managers. Mandatory disclosures are required to be published at product and manager levels in a variety of ways, including on websites, in pre-contractual documents (e.g. prospectuses) and in annual reports. Certain significant provisions apply since March 10, 2021. In October 2021, the UK government announced that it will launch its own consultation with stakeholders on sustainable finance disclosures rules for certain UK market participants and certain investment products.

Taxonomy Regulation. On July 12, 2020, Regulation (EU) 2020/852 (Taxonomy Regulations) entered into force. The Taxonomy Regulations are part of the EU’s recent measures designed to encourage environmentally sustainable investment decision making and introduce a technical framework to ascertain how sustainable an economic activity is. The Taxonomy Regulations apply to financial market participants including MiFID firms, Undertakings for the Collective Investment in Transferable Securities (UCITS) management companies, and alternative investment fund managers, and will require them to make further entity, pre-contractual and periodic disclosures. In October 2021, the UK government announced that it will launch its own consultation with stakeholders on sustainable finance disclosures rules for certain UK market participants.

Deposit Guarantee Scheme. Eligible deposits held with EU credit institutions and certain other financial entities are subject to the recast Deposit Guarantee Schemes Directive (DGSD) implemented in 2014. It required EU member states to introduce legislation establishing at least one deposit guarantee scheme (DGS). A DGS which is established and recognized in one member state is obliged to cover the depositors (up to certain prescribed amounts) at branches of the same institution in other EU member states. In the UK, the Financial Services Compensation Scheme is the national DGS for the protection and reimbursement of depositors of failed financial institutions.

Fifth EU Money Laundering Directive. On July 9, 2018, the Fifth EU Money Laundering Directive (MLD5) entered into force. MLD5 was required to be transposed into local law by EU member states by January 10, 2020 and introduced the following key changes to the previous EU AML regime: (i) EU member states must ensure that registers of ultimate beneficial owners of companies and other legal entities are accessible to the general public; (ii) the previous AML regime was extended to additional service providers, such as electronic wallet providers, virtual currency exchange service providers, and art dealers, and further specifications regarding the scope of application of MLD5 with respect to tax advisors and estate agents were provided; (iii) the threshold for identifying holders of prepaid cards was lowered to €150; and (iv) EU member states were required to implement enhanced due diligence measures to monitor suspicious transactions involving high-risk countries more strictly. In May 2018, the UK’s Sanctions and Anti-Money Laundering Act came into force. The UK government transposed MLD5 into UK law and, therefore, the UK anti-money laundering regime is currently broadly aligned with the EU.

Shareholder Rights Directive. On May 17, 2017, the recast Shareholder Rights Directive (EU) 2017/828 was published (SRD II). Member states of the EU were required to bring into force the laws, regulations and administrative provisions necessary to comply with the Directive by June 10, 2019. SRD was designed to establish requirements in relation to the exercise of shareholder rights and, recognizing that shares are often held through complex chains of intermediaries, SRD II is designed to improve mechanisms for the identification of shareholders by companies, as well as improve the transmission of information along the chain of intermediaries to facilitate the exercise of shareholder rights. Non-EU intermediaries are required to comply with the requirements if they provide services with respect to shares of companies that have their registered office in the EU. The Commission Implementing Regulation (EU) 2018/1212 of September 3, 2018 set out minimum requirements for implementing SRD II, which have applied since September 3, 2020. SRD II has been incorporated into UK law and remains largely aligned with the EU.

Depositary Books & Records. Following the European Securities and Markets Authority’s opinion on asset segregation and application of depositary delegation rules to central securities depositories published on July 20, 2017, and entered into force on April 1, 2020, changes were introduced by two EU regulations modifying the existing Alternative

2021 Annual Report | Northern Trust Corporation 9

Investment Fund Managers Directive (AIFMD) and UCITS Level 2 Regulations: Commission Delegated Regulation (EU) No 2018/1618 relating to the safe-keeping duties of depositaries of alternative investment funds and Commission Delegated Regulation (EU) No 2018/1619 relating to the safe-keeping duties of depositaries of UCITS. The changes aim to better define asset segregation requirements and to add additional safeguards, primarily focusing on information flow between the depositary and any third party to whom safe-keeping functions have been delegated. The key changes (i) impact the frequency of reconciliations between the depositary’s internal accounts and records and those of any third party in the custody chain, (ii) require the depositary to maintain an independent record separate from the record maintained by the third party, and (iii) increase due diligence obligations where custody of assets is delegated to third parties outside of the EU. AIFMD and the UCITS directive were incorporated into UK law and remain largely aligned with the EU. The changes impact Northern Trust’s subsidiaries providing depositary services to European-domiciled fund clients.

In addition to the above, the Bank’s and the Corporation’s subsidiary banks located outside the United States are subject to regulatory capital requirements in the jurisdictions in which they operate. As of December 31, 2021, each of our non-U.S. banking subsidiaries had capital ratios above their specified minimum requirements.

Human Capital Management

At Northern Trust, our employees are our most important assets. Because the success of our company relies on the strength of the people we employ, our search for and retention of talent is critical. We invest in our employees holistically to continually develop a diverse pipeline of future leaders and to help employees advance their individual careers. The overview below outlines Northern Trust’s human capital objectives—talent management, total rewards, and diversity, equity and inclusion.

EMPLOYEES

Northern Trust employed approximately 21,100 full-time equivalent staff members as of December 31, 2021. The regional breakout of our workforce is 43% North America, 39% Asia-Pacific region, and 18% Europe, Middle East, and Africa.

TALENT ACQUISITION, DEVELOPMENT, AND MANAGEMENT

We pride ourselves in attracting strong talent and have identified the development of diverse talent as a strategic priority. Our focus on career development, work/life balance, diversity, and our unique culture of care and collaboration also contribute to our employer brand.

Sourcing and Recruitment. We target our talent identification, sourcing methods, and recruitment strategies to specific locations using various channels such as job boards, colleges, professional networks, associations and online social networks. We base hiring decisions on a variety of factors including relevant experience and accomplishments, educational background, professional licensing, and strong evidence of integrity and ethical behavior.

Onboarding. Northern Trust is committed to helping all new hires succeed from day one. New employees begin their onboarding journey with a comprehensive learning roadmap that orients them to our history, brand, businesses, and culture. Orientation programs also augment the onboarding experience by providing global, regional, and/or local information along with networking activities to help connect new hires to each other and other colleagues.

Learning and Development. An integrated partnership between our enterprise-wide and functional learning and development teams ensure we deliver holistic training solutions. Through our online learning portal, Northern Trust University, all employees can access a portfolio of professional and functional training solutions most helpful to their role. Our training content is dynamic as we regularly evaluate and offer courses and resources that will allow our employees to develop skills most critical to servicing our clients and developing their careers. An emerging area of focus is helping expand digital, analytical and financial acumen and skills across the enterprise. Many of our programs are interactive, include peer networking, and offer direct access to expert facilitators. Training is offered in both virtual and classroom instructor-led formats.

Talent Cultivation and Review. Northern Trust is committed to identifying and developing a deep pipeline of diverse, future talent at all levels across the globe to meet our evolving business needs. Annually, managers conduct talent assessments, and business and regional leadership teams hold talent reviews focused on specific topics, such as workforce needs, diversity, top talent, development opportunities, readiness for promotion, internal movement, and succession plans. Robust talent discussions are held annually with our executive management team and Board of Directors.

Performance Management. Northern Trust’s annual performance management process includes goal setting, mid-year check-ins, multi-rater feedback, and year-end reviews. Priorities are set by our Chief Executive Officer and applied to each business, department, team and individual. Managers are encouraged to provide regular feedback and real-time coaching to enhance performance outcomes and continually develop our talent.

Engagement and Recognition. Building an inclusive, connected and engaged employee culture is essential to retaining our talent. We invite all employees to provide management with anonymous responses about their everyday experiences at work through an annual Employee Engagement Survey and periodically through pulse surveys and other

10 2021 Annual Report | Northern Trust Corporation

interactive feedback channels. Results are thoroughly evaluated to identify strengths, progress, and opportunities to further strengthen employee engagement, and are transparently shared with both employees and the Board of Directors. We also foster an “attitude of gratitude” through our online recognition platform that allows employees to recognize one another for everyday contributions.

TOTAL REWARDS

Our compensation and benefit programs are designed to be market competitive and positioned around the median of the local market, enabling us to attract and retain talent needed to deliver on Northern Trust’s strategy.

Compensation Programs. Our compensation programs are intended to motivate our employees to deliver the highest-quality service to our clients and achieve the greatest collective business results. They are designed, implemented and communicated to promote behaviors that are consistent with Northern Trust’s desired culture, character and enduring values of service, expertise, and integrity. We also regularly review our compensation processes and programs and take appropriate measures to ensure we can attract and retain talent in relevant markets.

Northern Trust’s base salary programs provide a competitive level of fixed pay reflecting each employee’s position, experience, qualifications and tenure. Additionally, all employees are eligible for incentive compensation to reward performance that delivers superior team or individual results. Incentive compensation is linked to both financial and non-financial performance criteria, including risk considerations, as determined by our Board of Directors and senior management. Select senior leaders and individual contributors may receive a percentage of their incentive in Northern Trust stock to encourage retention of key talent and to align rewards with company performance.

Employee Benefits. While the exact composition of the employee benefit package varies by country, our benefit programs are designed to be locally competitive, to meet the needs of our employees and their families, and to reflect the cultural values of the organization. Typical benefit programs include retirement, health care, paid time off, income protection such as disability and life insurance, leaves of absence, and access to our Employee Assistance Program. We have expanded our focus on employee well-being by providing additional programs and resources to improve wellness. These programs focus on how to manage stress, build resiliency, and be attuned to mental health issues; access to flexible or voluntary benefits; and enhancements to various parental leave offerings.

DIVERSITY, EQUITY, AND INCLUSION (DE&I)

Northern Trust embraces the values of diversity, equity and inclusion and strives to create a work environment in which all individuals are welcomed, respected, supported, and valued so that they can fully participate in, and contribute to, our success and the success of our stakeholders.

Embedding DE&I. Our DE&I strategy is designed to develop a diverse, equitable, and inclusive workforce that represents all perspectives, attributes, experiences and backgrounds. Our Board, through its Corporate Governance Committee, engages in active oversight of our DE&I strategies, programs, and principles. Our Head of Corporate Sustainability, Inclusion and Impact serves as an Executive Vice President, and reports directly to our Chairman and Chief Executive Officer. The following table presents detail with respect to the gender and ethnic diversity of our Board of Directors and executive officers.

TABLE 2: BOARD OF DIRECTORS AND EXECUTIVE OFFICERS REPRESENTATION

DECEMBER 31, 2021
FEMALEMALEWHITEBLACKHISPANICASIAN
Board of Directors25%75%59%25%8%8%
Executive Officers36%64%82%18%—%—%

As of December 31, 2021, our global workforce was 46% female and 54% male, and 37% of our U.S. workforce self-identified as ethnically diverse.

Progress and Accountability. We utilize a global DE&I dashboard to track the organization’s progress and integrate these metrics as part of our overall corporate strategy and goals. To drive accountability for increasing diverse representation across the organization, we measure representation in relation to our hiring, retention and promotion practices. Each business unit evaluates this data, and acts as needed, to improve overall diversity within their organization. Our executive leaders report their progress through the DE&I Executive Council co-chaired by our Chief Executive Officer and our Head of Corporate Sustainability, Inclusion and Impact. Our Global Executive DE&I Council is responsible for providing strategic oversight and defining and driving accountability on the global DE&I priorities.

For information on our response to the COVID-19 pandemic, including with respect to human capital measures to preserve the health and safety of our workforce, see Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations—COVID-19 Pandemic and Recent Events.”

2021 Annual Report | Northern Trust Corporation 11

Available Information

Through the Corporation’s website at www.northerntrust.com, the Corporation makes available free of charge its Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and all other reports and all amendments to those reports filed or furnished pursuant to Section 13(a) or 15(d) of the Securities Exchange Act of 1934, as amended (Exchange Act), as soon as reasonably practicable after it files such material with, or furnishes such material to, the SEC. The contents of the Corporation’s website, the website of the SEC or any other website referenced herein are not a part of this Annual Report on Form 10-K.

Previous: Cover and table of contents · Next: Item 1A. RISK FACTORS