Item 1. BUSINESS

76K characters. Original on sec.gov · Markdown

Item 1. BUSINESS

Northern Trust Corporation

Northern Trust Corporation (Corporation) is a leading provider of wealth management, asset servicing, asset management and banking solutions to corporations, institutions, families and individuals. The Corporation is a financial holding company conducting business through various U.S. and non-U.S. subsidiaries, including The Northern Trust Company (Bank).

The Bank is an Illinois banking corporation headquartered in Chicago and the Corporation’s principal subsidiary. Founded in 1889, the Bank conducts its business through its U.S. operations and its various U.S. and non-U.S. branches and subsidiaries. At December 31, 2023, the Bank had consolidated assets of $150.3 billion and common bank equity capital of $11.6 billion.

The Corporation was formed as a holding company for the Bank in 1971. The Corporation has a global presence with offices in 24 U.S. states and Washington, D.C., and across 22 locations in Canada, Europe, the Middle East and the Asia-Pacific region. At December 31, 2023, the Corporation had consolidated total assets of $150.8 billion and stockholders’ equity of $11.9 billion.

The Corporation expects that the Bank will continue in the foreseeable future to be the major source of the Corporation’s consolidated assets, revenues, and net income. Except where the context otherwise requires, references to “Northern Trust,” “we,” “us,” “our,” “its,” or similar terms mean Northern Trust Corporation and its subsidiaries on a consolidated basis.

Business Overview

Northern Trust focuses on managing and servicing client assets through its two client-focused reporting segments: Asset Servicing and Wealth Management. Asset management and related services are provided to Asset Servicing and Wealth Management clients primarily by the Asset Management business. The revenue and expenses of Asset Management and certain other support functions are allocated fully to Asset Servicing and Wealth Management. Northern Trust reports certain income and expense items not allocated to Asset Servicing and Wealth Management in a third reporting segment, Other.

ASSET SERVICING

Asset Servicing is a leading global provider of asset servicing and related services to corporate and public retirement funds, foundations, endowments, fund managers, insurance companies, sovereign wealth funds, and other institutional investors around the globe. Asset servicing and related services encompass a full range of capabilities including but not limited to: custody; fund administration; investment operations outsourcing; investment management; investment risk and analytical services; employee benefit services; securities lending; foreign exchange; treasury management; brokerage services; transition management services; banking; and cash management. Client relationships are managed through the Bank and the Bank’s and the Corporation’s other subsidiaries, including support from locations in North America, Europe, the Middle East, and the Asia-Pacific region. At December 31, 2023, total Asset Servicing assets under custody/administration (AUC/A), assets under custody, and assets under management (AUM) were $14.36 trillion, $10.88 trillion, and $1.03 trillion, respectively.

WEALTH MANAGEMENT

Wealth Management focuses on high-net-worth individuals and families, business owners, executives, professionals, retirees, and established privately-held businesses in its target markets. In supporting these targeted segments, Wealth Management provides trust, investment management, custody, and philanthropic services; financial consulting; guardianship and estate administration; family business consulting; family financial education; brokerage services; and private and business banking. Wealth Management also includes Global Family Office, which provides customized services, including but not limited to: investment consulting; global custody; fiduciary; and private banking; family office consulting, and technology solutions, to meet the complex financial and reporting needs of ultra-high-net-worth individuals and family offices across the globe.

Wealth Management is one of the largest providers of advisory services in the United States, with AUC/A, assets under custody, and AUM of $1.04 trillion, $1.03 trillion, and $402.5 billion, respectively, at December 31, 2023. Wealth Management services are delivered by multidisciplinary teams through a network of offices in 19 U.S. states and Washington, D.C., as well as offices in London, Guernsey, and Abu Dhabi.

2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION 1

ASSET MANAGEMENT

Asset Management, through the Corporation’s various subsidiaries, supports the Asset Servicing and Wealth Management reporting segments by providing a broad range of asset management and related services and other products to clients around the world. Investment solutions are delivered through separately managed accounts, bank common and collective funds, registered investment companies, exchange traded funds, non-U.S. collective investment funds, and unregistered private investment funds. Asset Management’s capabilities include active and passive equity; active and passive fixed income; cash management; multi-asset and alternative asset classes (such as private equity and hedge funds of funds); and multi-manager advisory services and products. Asset Management’s activities also include overlay services and other risk management services. Asset Management operates internationally through subsidiaries and distribution arrangements and its revenue and expense are fully allocated to Asset Servicing and Wealth Management. As discussed above, Northern Trust managed $1.43 trillion in assets as of December 31, 2023, including $1.03 trillion for Asset Servicing clients and $402.5 billion for Wealth Management clients.

Competition

Northern Trust faces intense competition in all aspects and areas of its business. Competition comes from both regulated and unregulated financial services organizations, whose products and services span the local, national, and global markets in which Northern Trust conducts operations. Our competitors include a broad range of financial institutions and service companies, including other custodial banks, investment counseling firms, deposit-taking institutions, asset management firms, benefits consultants, trust companies, investment banking firms, insurance companies, and various financial technology companies, including software providers and data services firms. As our businesses grow and markets evolve, we may encounter increasing and new forms of competition around the world.

Northern Trust’s business strategy is to provide quality financial services to targeted market segments in which it believes it has a competitive advantage and favorable growth prospects. As part of this strategy, Northern Trust seeks to differentiate itself from its competitors with premier, holistic solutions and exceptional experiences tailored to meet clients’ needs. In addition, Northern Trust emphasizes the development and growth of recurring and scalable sources of fee-based income and continual productivity improvements. Northern Trust also seeks to maintain its foundational strength with a strong, conservative balance sheet and a globally respected brand.

Economic Conditions And Government Policies

The earnings of Northern Trust are affected by numerous external influences. Chief among these are general economic conditions, both domestic and international, and actions that governments and their central banks take in managing their economies. These general conditions affect all of Northern Trust’s businesses, as well as the quality, value, and profitability of its loan and investment portfolios.

The Board of Governors of the Federal Reserve System (Federal Reserve Board) implements monetary policy through its open market operations in United States Government securities, its setting of the discount rate at which member banks may borrow from Federal Reserve Banks, and its changes in the reserve requirements for deposits. The policies adopted by the Federal Reserve Board directly affect interest rates and therefore what banks earn on their loans and investments and what they pay on their savings and time deposits and other purchased funds.

Supervision and Regulation

Northern Trust is subject to extensive regulation under state and federal laws in the United States and in each of the jurisdictions in which it does business. The descriptions below outline significant elements of selected laws and regulations applicable to Northern Trust and are qualified in their entirety by reference to the particular statutory or regulatory provisions summarized. These descriptions do not summarize all laws and regulations applicable to Northern Trust or all possible or proposed changes to such laws or regulations and are not intended to be a substitute for the related statutes or regulatory provisions.

Changes in laws or regulations applicable to Northern Trust may have a material effect on its businesses and results of operations. The scope of the laws and regulations, and the intensity of the supervision to which Northern Trust is subject have increased in recent years, initially in response to the financial crisis, and more recently in light of other factors, including the banking turmoil in early 2023, technological factors, market changes, and climate change concerns. Regulatory enforcement and fines have also increased across the banking and financial services sector. Northern Trust expects that its business will remain subject to extensive regulation and heightened supervision.

FINANCIAL HOLDING COMPANY REGULATION

Under U.S. law, the Corporation is a bank holding company that has elected to be a financial holding company subject to the supervision, examination, and regulation of the Federal Reserve Board. A financial holding company is permitted to engage in a broader range of financial activities than a bank holding company. The Federal Reserve Board has authority to limit the activities that a financial holding company may conduct if any depository institution controlled by the financial

2 2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION

holding company is found to no longer be “well-capitalized” and “well-managed” or has not received at least a “satisfactory” rating in its most recent Community Reinvestment Act (CRA) examination. Failure to meet one or more of these requirements may result in restrictions on the Corporation’s ability to exercise powers granted to financial holding companies, to engage in new activities, to continue current activities, or to make acquisitions.

SUBSIDIARY REGULATION

The Bank is a member of the Federal Reserve System, with deposits insured by the Federal Deposit Insurance Corporation (FDIC), and is subject to regulation by both agencies. As an Illinois banking corporation, the Bank is also subject to Illinois state laws and regulations and to examination and supervision by the Division of Banking of the Illinois Department of Financial and Professional Regulation. The Bank is also registered as a transfer agent with the Federal Reserve Board and is registered as a swap dealer with the U.S. Commodity Futures Trading Commission (CFTC) under the Commodity Exchange Act. As a result, the Bank is subject to supervision, examination and enforcement by certain other regulatory bodies, including the CFTC and the National Futures Association (NFA). The Corporation’s nonbanking affiliates are subject to examination by the Federal Reserve Board and, in certain circumstances, other functional regulators, as discussed in greater detail below.

ENHANCED PRUDENTIAL STANDARDS

Under the Federal Reserve Board’s tailoring rules, the Corporation is subject to the enhanced prudential standards applicable to Category II banking organizations. As a Category II institution, the Corporation must submit annual capital plans to the Federal Reserve Board, conduct supervisory and internal periodic stress tests to evaluate capital adequacy in adverse economic conditions, maintain enhanced risk management procedures, comply with a liquidity risk management framework (discussed below in “Liquidity Standards”) and single counterparty credit limits, conduct liquidity stress tests, and hold a buffer of liquid assets estimated to meet funding needs during a financial stress event. The Corporation is not subject to all of the standards applicable to U.S. bank holding companies that are global systemically important bank holding companies (GSIBs), such as the total loss-absorbing capacity requirement, capital surcharge, enhanced supplementary leverage ratio, or additional single counterparty credit limits.

LONG-TERM DEBT AND CLEAN HOLDING COMPANY REQUIREMENTS

In the summer of 2023, the U.S. banking regulators proposed a rule that would require banking organizations with $100 billion or more in total assets to comply with long-term debt requirements and clean holding company requirements similar to those that currently apply only to GSIBs. This proposal would also impose a long-term debt requirement on certain categories of insured depository institutions that are not consolidated subsidiaries of U.S. GSIBs, including insured depository institutions with $100 billion or more in total assets, such as the Bank. If adopted, this proposal would require the Corporation and the Bank to each maintain a minimum outstanding eligible long-term debt amount of no less than the greatest of (i) 6% of risk-weighted assets (RWAs), (ii) 2.5% of total leverage exposure, and (iii) 3.5% of average total consolidated assets. The Bank would be required to issue the minimum amount of eligible long-term debt to the Corporation, and the Corporation would be required to issue the minimum amount of eligible long-term debt externally. In addition, if adopted as proposed, the clean holding company requirement would limit or prohibit the Corporation from entering into certain transactions that could impede its orderly resolution, including, for example, prohibiting the Corporation from entering into transactions that could spread losses to subsidiaries and third parties, as well as limiting the amount of the Corporation’s liabilities that are not eligible long-term debt. The public comment period on this proposed rule ran through January 16, 2024.

RESOLUTION PLANNING

As required by Section 165(d) of the Dodd-Frank Wall Street Reform and Consumer Protection Act (Dodd-Frank Act), the Corporation is required to submit periodically to the Federal Reserve Board and FDIC a resolution plan for its rapid and orderly resolution in the event of material financial distress or failure. In August 2023, the Federal Reserve Board and FDIC proposed updated guidance on resolution planning requirements applicable to the Corporation under Section 165(d). The Corporation’s next 2024 165(d) plan submission is due to the FDIC and Federal Reserve Board by March 31, 2025.

In addition, the Bank, as an insured depository institution, is required to submit to the FDIC periodic plans for resolution in the event of its failure, with the next plan being due for submission on December 1, 2024. In August 2023, the FDIC issued a proposed rule that would require covered insured depository institutions, such as the Bank, to submit a full resolution plan to the FDIC every two years and submit an interim supplement in each year that it is not required to submit a full resolution plan. The proposed rule would also increase the content requirements for plan submissions and introduce a new credibility standard for the FDIC’s evaluation of resolution plans, which would be enforceable against the covered insured depository institutions.

2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION 3

Separately, the European Union Bank Recovery and Resolution Directive (BRRD) sets out the framework for the recovery and resolution of European Union (EU) credit institutions and systemically-important investment firms, including certain of the Bank’s subsidiaries and branches. The BRRD establishes a set of harmonized rules for early intervention measures, recovery and resolution planning, bail-in powers and requirements for total loss absorbing capital for EU institutions, collectively known as minimum requirements for own funds and eligible liabilities (MREL). Northern Trust Global Services SE, a Luxembourg-incorporated indirect subsidiary of the Bank, is authorized and supervised by the European Central Bank (ECB) and subject to the prudential supervision of the ECB and the Luxembourg Commission de Surveillance du Secteur Financier (CSSF). As such, Northern Trust Global Services SE falls within the scope of the BRRD and its recovery and resolution planning is overseen by the CSSF and the Single Resolution Board (the resolution authority for ECB-supervised institutions).

The United Kingdom (UK) has established a special resolution regime and a resolvability assessment framework overseen by the Bank of England (as the UK resolution authority) with many similar features to the BRRD, which was substantially incorporated into UK law following the withdrawal of the UK from the EU. The special resolution regime applies to firms that are permitted to accept deposits under Part 4A of the Financial Services and Markets Act 2000. As such, the London branch of the Bank, as a UK branch of a third-country institution that accepts deposits, falls within the scope of the special resolution regime.

ORDERLY LIQUIDATION AUTHORITY.

Under the Dodd-Frank Act, certain financial companies, such as the Corporation and certain of its covered subsidiaries, can be subjected to an orderly liquidation authority if in default or danger of default and their resolution under the U.S. Bankruptcy Code would have serious adverse effects on financial stability in the United States, among other requirements set by statute. If the Corporation were subject to orderly liquidation authority, the FDIC would be appointed as its receiver, which would give the FDIC considerable powers to resolve the Corporation. Absent such actions, the Corporation, as a bank holding company, would remain subject to the U.S. Bankruptcy Code.

THE VOLCKER RULE.

The Volcker Rule generally prohibits banking entities, including the Bank and its affiliates, from engaging in proprietary trading, subject to certain exemptions and exclusions, such as for market-making, hedging, certain trading activities in U.S. and foreign sovereign debt, and trading activities related to liquidity management. The Volcker Rule also prohibits certain investments in, and relationships with, covered funds as defined in the Volcker Rule, such as hedge funds, private equity funds and similar funds, subject to a number of exemptions and exclusions. Northern Trust maintains an enterprise-wide compliance program to comply with the Volcker Rule.

HOLDING COMPANY AS A SOURCE OF STRENGTH

The Corporation, as a bank holding company, is required to serve as a source of financial and managerial strength to its depository institution subsidiary. Under this requirement, the Corporation could be required to commit resources to the Bank should the Bank experience financial distress.

PAYMENT OF DIVIDENDS

The Corporation may pay dividends, repurchase stock, and make other capital distributions only in accordance with the capital plan rules and capital adequacy standards of the Federal Reserve Board, including the stress capital buffer requirement, discussed further in “—Capital Adequacy Requirements” below. Dividends from the Bank are a significant source of funds for the Corporation, and the Corporation’s ability to pay dividends on its common stock therefore depends in part on the ability of the Bank to pay sufficient dividends to the Corporation.

Various other federal and state laws and regulations limit the amount of dividends that may be paid by the Bank to the Corporation without regulatory consent. The Bank may not pay any dividends if it is undercapitalized, or if the payment of the dividend would cause it to become undercapitalized. In general, the amount of dividends that may be paid in a calendar year is limited to its “recent earnings” (the current year’s net income combined with the retained net income of the two preceding years), or its “undivided profits” (generally, accumulated net profits that have not been paid out as dividends or transferred to surplus), whichever is less. The ability of the Bank to pay dividends to the Corporation may also be affected by the capital adequacy standards applicable to the Bank (discussed further below), which include minimum requirements and buffers.

CAPITAL PLANNING AND STRESS TESTING

The Corporation’s capital distributions are subject to the Federal Reserve Board’s capital plan rules, which require the Corporation to submit annual capital plans to the Federal Reserve Board for review.

The major components of that oversight are the Federal Reserve Board’s Comprehensive Capital Analysis and Review (CCAR) and Dodd-Frank Act Stress Tests (DFAST). These requirements involve both company-run and supervisory-run

4 2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION

testing of capital under various scenarios, including baseline and severely adverse scenarios provided by the appropriate banking regulator.

Under the DFAST regulations, the Corporation is required to undergo regulatory stress tests conducted by the Federal Reserve Board annually. The Bank also is required to conduct its own annual internal stress test (although it is permitted to combine certain reporting and disclosure of its stress test results with the results of the Corporation). Results from the Corporation’s and the Bank’s annual company-run stress tests are reported to the appropriate regulators and made publicly available. Northern Trust published the results of its most recent company-run stress tests on June 28, 2023.

CAPITAL ADEQUACY REQUIREMENTS

The Corporation, as a bank holding company, is subject to risk-based and leverage capital guidelines implemented by the Federal Reserve Board that are based on industry-standard guidelines published by the International Basel Committee on Banking Supervision (Basel Committee), known as Basel III. The Bank, as an FDIC-insured depository institution, is also required to meet risk-based and leverage capital guidelines established by regulators which are generally similar to those established by the Federal Reserve Board for bank holding companies.

Under the Basel III rules, the Corporation, with the Bank, is a “core” banking organization that is required to use the advanced approaches methodologies to calculate and disclose publicly its risk-based capital ratios. The Corporation also is subject to a capital floor that is based on the Basel III standardized approach to calculating risk-based capital ratios. The Corporation is therefore required to calculate its risk-based capital ratios under both the standardized and advanced approaches, and is subject to the more stringent of the two in the assessment of its capital adequacy.

In July 2023, the U.S. banking agencies issued a proposed rule to implement the Basel III endgame agreement for large banks (Basel III Endgame Proposal). The proposal would introduce a new measure of RWAs known as “Expanded Total RWAs” (the expanded risk-based approach), reflecting new RWA methodologies that generally align with changes to the global Basel Accord adopted by the Basel Committee. The proposal would eliminate the current Basel III rule’s advanced approaches methodologies and effectively replace it with the expanded risk-based approach, which more heavily relies on standardized methodologies. As compared with the standardized approach, the expanded risk-based approach includes more granular risk weights for credit risk and introduces a new market risk framework. In addition, unlike the standardized approach, the expanded risk-based approach includes operational risk and credit valuation adjustment RWA components.

The Basel III Endgame Proposal, if adopted as a final rule, would maintain the current Basel III rule’s dual-requirement structure, whereby the Corporation and the Bank would be required to calculate risk-based capital ratios under both the expanded risk-based approach and the standardized approach. In addition, the proposal would modify the standardized approach by requiring that the new market risk standards from the proposal also be applied in the standardized approach.

The Basel III Endgame Proposal would apply the stress capital buffer to risk-based capital requirements calculated under both the expanded risk-based approach and the standardized approach. The proposal includes a proposed effective date of July 1, 2025, with three-year transition arrangements until revised standards are fully phased in on July 1, 2028.

Based on our current understanding of the proposed rule, we estimate that, if the expanded risk-based approach had applied on a fully phased-in basis as of December 31, 2023, and in the absence of taking any actions to mitigate its impact, our expanded risk-based approach RWAs as of that date would have been approximately 5% to 15% higher than our actual standardized approach RWAs as of that date. The proposed rule would phase in the higher expanded risk-based approach RWAs on July 1 of each year during the transition, thereby increasing our regulatory capital requirements, with delayed incorporation of the potentially lower stress capital buffer calculations.

2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION 5

The Bank’s risk-based and leverage capital ratios at December 31, 2023, were well above the regulatory requirements established by U.S. banking regulators. The risk-based and leverage capital ratios for the Corporation and the Bank, together with the regulatory minimum ratios and the ratios required for classification as “well-capitalized,” are provided in the following chart.

TABLE 1: RISK-BASED AND LEVERAGE CAPITAL RATIOS AS OF DECEMBER 31, 2023

COMMON EQUITY TIER 1 CAPITALTIER 1 CAPITALTOTAL CAPITALTIER 1 LEVERAGESUPPLEMENTARY LEVERAGE
STANDARDIZED APPROACHADVANCED APPROACHSTANDARDIZED APPROACHADVANCED APPROACHSTANDARDIZED APPROACHADVANCED APPROACHSTANDARDIZED APPROACHADVANCED APPROACHADVANCED APPROACH
Northern Trust Corporation11.4%13.4%12.3%14.5%14.2%16.5%8.1%8.1%8.6%
The Northern Trust Company12.2%14.6%12.2%14.6%13.8%16.3%8.0%8.0%8.5%
Minimum required ratio4.5%4.5%6.0%6.0%8.0%8.0%4.0%4.0%3.0%
“Well-capitalized” minimum ratios, as applicable
Northern Trust CorporationN/AN/A6.0%6.0%10.0%10.0%N/AN/AN/A
The Northern Trust Company6.5%6.5%8.0%8.0%10.0%10.0%5.0%5.0%3.0%

Advanced approaches institutions, such as the Corporation and the Bank, are subject to a minimum supplementary leverage ratio of 3.0%. Advanced approaches institutions that are insured depository institutions, such as the Bank, also must maintain at least a 3.0% supplementary leverage ratio to be considered “well-capitalized.” The Corporation is also subject to a stress capital buffer, which integrates forward-looking stress test results with non-stress capital requirements, and the Bank is also subject to a capital conservation buffer, which respectively requires the Corporation and the Bank to hold a buffer of Common Equity Tier 1 capital above the minimum risk-based capital requirements in order to avoid constraints on dividends, equity repurchases and compensation. The minimum capital buffer requirement for advanced approaches banking organizations, such as the Corporation and the Bank, is 2.5%.

A “countercyclical buffer” of 0% to 2.5% of a banking organization’s total RWA for advanced approaches banking organizations, such as the Corporation, is also a component of the capital adequacy framework. In general, the amount of the countercyclical capital buffer is a weighted average of the countercyclical capital buffer established in the various jurisdictions in which the banking organization has credit exposures. The U.S. countercyclical buffer is currently set at 0%.

The results of the 2023 DFAST, published by the Federal Reserve Board on June 28, 2023, resulted in Northern Trust’s stress capital buffer and effective Common Equity Tier 1 capital ratio minimum requirement remaining constant at 2.5% and 7.0%, respectively, for the 2023 capital plan cycle, which began on October 1, 2023.

LIQUIDITY STANDARDS

Northern Trust is subject to the U.S. liquidity coverage ratio (LCR) requirement, which is designed to ensure that covered banking organizations, including the Corporation and the Bank, maintain an adequate level of unencumbered high-quality liquid assets equal to their expected net cash outflow for a 30-day time horizon under a prescribed regulatory liquidity stress scenario. As of December 31, 2023, the Corporation and the Bank were in compliance with applicable LCR requirements.

Northern Trust also is subject to the U.S. net stable funding ratio (NSFR) requirement, designed to promote more medium- and long-term funding of the assets and activities of banking entities over a one-year time horizon. As of December 31, 2023, the Corporation and the Bank were in compliance with applicable NSFR requirements. In addition, in 2023, Northern Trust began publicly disclosing certain qualitative and quantitative information about its NSFR consistent with the semi-annual disclosure requirements of the Federal Reserve Board’s final rule on U.S. NSFR disclosure.

As noted above, the enhanced prudential standards impose additional liquidity requirements for large bank holding companies. The Corporation, a Category II institution under the final tailoring rule, is subject to the liquidity risk management, monthly liquidity stress testing, liquidity buffer, and daily liquidity reporting requirements.

6 2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION

PROMPT CORRECTIVE ACTION

Federal banking regulators are required to take “prompt corrective action” with respect to a depository institution if that institution does not meet certain capital adequacy standards, and are also authorized to take appropriate action against a parent bank holding company of an under-capitalized banking subsidiary. In certain instances, the Corporation could be required to guarantee the performance of a capital restoration plan for the Bank if it were under-capitalized.

RESTRICTIONS ON TRANSACTIONS WITH AFFILIATES

The Bank is subject to restrictions governing transactions between it and affiliated entities, including the Corporation, its affiliates, and its subsidiaries. These transactions must be on terms and conditions that are, or in good faith would be, offered to nonaffiliated companies (i.e., on terms not less favorable to the Bank than market terms). Further, extensions of credit must be secured fully with qualifying collateral and are limited to 10% of the Bank’s capital and surplus for transactions with a single affiliate and to 20% of the Bank’s capital and surplus for transactions with all affiliates.

SWAPS AND OTHER DERIVATIVES.

Northern Trust is subject to comprehensive regulation of its derivatives businesses, including regulations that impose margin requirements, business conduct requirements, trade reporting, central clearing and mandatory trading on regulated exchanges or execution facilities for certain types of swaps and security-based swaps. CFTC and U.S. Securities and Exchange Commission (SEC) rules require registration of swap dealers and security-based swap dealers, respectively, and impose numerous obligations on such registrants, including adherence to business conduct standards for all in-scope instruments. The Bank is registered with the CFTC as a swap dealer and is subject to CFTC and NFA rules and supervision related to its swaps business. Swap dealers regulated by a prudential regulator, like the Bank, are subject to uncleared swap margin requirements and minimum capital requirements established by the prudential regulators. The Corporation has not registered and does not expect that it, or any of its affiliates, will be required to register as a security-based swap dealer with the SEC.

In addition, certain nonbanking affiliates, including Northern Trust Securities, Inc. and Northern Trust Investments, Inc., are registered with the CFTC as commodity trading advisors and/or commodity pool operators, or are operating under certain exemptions from such registration pursuant to CFTC rules and other guidance, and commodity pool operators have certain responsibilities with respect to each pool they operate or advise.

BROKER-DEALER AND INVESTMENT ADVISER REGULATION

Northern Trust Securities, Inc. is registered as a broker-dealer with the SEC and is a member of various self-regulatory organizations, including the Financial Industry Regulatory Authority, Inc. (FINRA). Broker-dealers are subject to laws and regulations relating to all aspects of their securities business operations, including, but not limited to, sales and trading practices, securities offerings, handling of customer funds, net capital levels, recordkeeping, privacy requirements, and the conduct of directors, officers, and employees. Broker-dealers are also regulated by securities administrators in those states where they do business. Northern Trust Securities, Inc. is also registered with the Municipal Securities Rulemaking Board (MSRB) as a municipal securities dealer and subject to regulation as such.

Northern Trust Securities, Inc. and other subsidiaries of the Corporation are registered with the SEC as investment advisers and are subject to regulation by the SEC. The Corporation’s registered investment advisers in the United States are subject to the Investment Advisers Act of 1940, as amended (the Investment Advisers Act), and SEC rules and regulations thereunder, including with respect to record-keeping, operational and marketing requirements, disclosure obligations, fiduciary and other obligations and prohibitions on fraudulent activities, and other applicable state and federal laws and regulations, including anti-fraud laws. The SEC is authorized to institute proceedings and impose sanctions for violations of the Investment Advisers Act, ranging from fines and censure to termination of an investment adviser’s registration. Noncompliance with the Investment Advisers Act or other federal and state securities laws and regulations could result in investigations, sanctions, disgorgement, termination of an investment adviser’s registration, fines and/or reputational harm.

ANTI-MONEY LAUNDERING, ANTI-TERRORISM LEGISLATION, AND OFFICE OF FOREIGN ASSETS CONTROL

Certain subsidiaries of the Corporation are subject to the Bank Secrecy Act of 1970, as amended by the USA PATRIOT Act of 2001 and implemented in the regulation of the federal banking regulators and the Financial Crimes Enforcement Network (FinCEN), which requires banks to comply with anti-money laundering (AML) and financial transparency requirements, such as conducting due diligence, verifying client and beneficial owner identification, and monitoring client transactions and detecting and reporting suspicious activities. AML laws outside the United States contain similar requirements.

In September 2022, FinCEN issued a final rule implementing one of three rulemakings planned in connection with the Corporate Transparency Act, which imposes new beneficial ownership information reporting requirements (Beneficial Ownership Reporting Rule). In order to comply with the Beneficial Ownership Reporting Rule, both domestic reporting companies and foreign reporting companies registered to do business in the United States generally will be required to

2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION 7

report information regarding themselves, their beneficial owners, and their company applicants. The Beneficial Ownership Reporting Rule became effective January 1, 2024 and may affect certain companies that the Corporation invests in, manages, or does business with. Additionally, on December 16, 2022, FinCEN published a Notice of Proposed Rulemaking for its second set of rulemakings in connection with the Corporate Transparency Act, which addresses how authorized recipients can access beneficial ownership information that will be reported to FinCEN and may affect certain activities conducted by the Bank. FinCEN issued the final rule on December 21, 2023, and it became effective on February 20, 2024.

The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) administers and enforces U.S. economic sanctions laws and regulations, which prohibit the Corporation and its subsidiaries from engaging in business in or with certain jurisdictions and parties that are the target of U.S. economic sanctions, such as organizations and countries suspected of aiding, harboring or engaging in terrorist acts or undermining the sovereignty and territorial integrity of democratic countries. If the Corporation or the Bank finds a sanctioned name or jurisdiction on any transaction, asset or account, the Corporation or the Bank must reject or block such account or transaction and notify the appropriate authorities.

Failure to comply with these requirements could result in fines, penalties, lawsuits, regulatory sanctions or difficulties in obtaining approvals, restrictions on their business activities or harm to reputation. Many other countries have imposed similar laws and regulations that apply to the Corporation’s non-U.S. offices. The Corporation has established policies and procedures to comply with these laws and the related regulations.

DEPOSIT INSURANCE AND ASSESSMENTS

The Bank accepts deposits and eligible deposits have the benefit of FDIC insurance up to the standard maximum deposit insurance amount, which is currently $250,000 for each ownership right and capacity under which the eligible deposit accounts are maintained. Under the Federal Deposit Insurance Act (FDIA), insurance of deposits may be terminated by the FDIC upon a finding that the insured depository institution has engaged in unsafe and unsound practices, is in an unsafe or unsound condition, or has violated laws, regulations, or orders from a regulatory agency.

The FDIC’s Deposit Insurance Fund (DIF) is funded by assessments on FDIC-insured depository institutions. The FDIC assesses premiums based on an assessment rate and an assessment base. An insured depository institution’s assessment base considers average consolidated total assets, less the average tangible equity of the insured depository institution during the assessment period. The assessment base of custody banks is adjusted to exclude certain liquid assets from total average assets. To qualify as a custody bank, certain institutional eligibility criteria must be met. The Bank qualifies as a custody bank for this purpose. The FDIC utilizes a risk-based system to determine each institution’s assessment rate. The assessment rate schedule can change from time to time at the discretion of the FDIC, subject to certain limits.

The FDIC, as required under the FDIA, established a plan in September 2020 to restore the DIF reserve ratio to meet or exceed the statutory minimum of 1.35% within eight years. Based on the FDIC’s recent projections, the FDIC determined that the DIF reserve ratio is at risk of not reaching the statutory minimum by the statutory deadline of September 30, 2028 without increasing the deposit insurance assessment rates. In 2022, the FDIC adopted a final rule, applicable to insured depository institutions, to increase initial base deposit insurance assessment rate schedules uniformly by 2 basis points, beginning on January 1, 2023. The FDIC also concurrently maintained the long-term target reserve ratio for the DIF, referred to as the Designated Reserve Ratio, at 2% for 2023. The increase in assessment rate schedules is intended to increase the likelihood that the reserve ratio of the DIF reaches the statutory minimum of 1.35% by the statutory deadline of September 30, 2028.

In November 2023, the FDIC issued a final rule to implement a special assessment to recoup losses to the DIF associated with bank failures in the first half of 2023. Under the final rule, the assessment base for the special assessment is equal to an insured depository institution’s estimated uninsured domestic office deposits reported as of December 31, 2022, adjusted to exclude the first $5 billion of uninsured domestic office deposits. The final rule provides that the FDIC will collect the special assessment at a quarterly rate of 3.36 basis points over eight quarterly assessment periods, subject to change depending on any adjustments to the loss estimate, mergers, failures, or amendments to reported estimates of uninsured deposits. In conjunction with the special assessment, $84.6 million was recognized as an accrued liability and related expense in the fourth quarter of 2023. The final rule becomes effective on April 1, 2024, and the first collection, including any adjustments as described above, will be reflected on the invoice for the first quarterly assessment period of 2024, with the first payment due on June 28, 2024. For more information on the FDIC’s special assessment, please see the “Consolidated Results of Operations—Noninterest Expense” included in Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations.”

COMMUNITY REINVESTMENT ACT

The Bank is subject to the CRA. The CRA and the regulations issued thereunder are intended to encourage banks to help meet the credit needs of their service areas, including low- and moderate-income neighborhoods and persons, consistent with the safe and sound operations of the banks. For purposes of the CRA, the Bank operates under a “wholesale” designation granted by the Federal Reserve Board and fulfills its CRA obligations by making qualified

8 2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION

investments for the purposes of community development. The Bank received an “outstanding” CRA rating from the Federal Reserve Board in its most recent CRA examination.

In October 2023, the U.S. banking agencies issued a final rule to amend their regulations implementing the CRA. The rule materially revises the current CRA framework, mostly for retail designated banks, including the assessment areas in which a bank is evaluated to include activities associated with online and mobile banking, the tests used to evaluate a bank in its assessment areas, new methods of calculating credit for lending, investment and service activities, and additional data collection and reporting requirements. The rule is expected to result in a significant increase in the thresholds for large banks to receive “outstanding” ratings in the future.

According to the new rule, banks currently designated as “wholesale” will be absorbed into the “limited purpose” designation. The rule outlines that a limited purpose bank is one that is not in the business of extending consumer or retail loans, except on an incidental and accommodation basis. Limited purpose banks are only subject to a qualitative and quantitative review of a bank’s community development lending and investments in each assessment area. While we will continue to be evaluated on our community development activities in our local markets, we will also be evaluated against a national benchmark based on assets.

The rule is expected to take effect on April 1, 2024, with most of its provisions becoming applicable on January 1, 2026. Reporting of the collected data will not be required until 2027.

DATA PRIVACY AND SECURITY

Federal law establishes a minimum federal standard of financial privacy by, among other provisions, requiring financial institutions to adopt, disclose, and enforce privacy policies with respect to consumer information, setting limitations on disclosure to third parties of consumer information, setting standards for protecting client information and preventing unlawful access to such information, and requiring notice of data breaches in certain circumstances. For example, the Federal Trade Commission has the authority to regulate and enforce against unfair or deceptive acts or practices in or affecting commerce, including acts and practices with respect to data privacy and security, and the Gramm-Leach-Bliley Act regulates the confidentiality and security of customer information obtained by financial institutions and certain other types of financial services businesses.

Most U.S. states, the EU and other non-U.S. jurisdictions also have adopted their own statutes and/or regulations concerning data privacy and security and requiring notification of data breaches―for example, the General Data Protection Regulation (GDPR) in Europe and its equivalent in the UK (UK GDPR), the Personal Information Protection Law (PIPL) in China, and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, CCPA) in the United States. Similar laws are in effect or being considered in other jurisdictions in which we operate across the globe. The GDPR is designed to harmonize data privacy and security laws across the European Economic Area (EEA), to protect EEA citizens’ data privacy and security. The GDPR imposes stringent operational requirements on both data controllers and data processors and has extraterritorial effect as its scope includes all data controllers and processors outside the EEA whose processing activities relate to the offering of goods or services to, or monitoring the behavior of, EEA individuals. Organizations that violate certain provisions of the GDPR could be fined up to €20 million or 4% of their annual worldwide revenue for the preceding fiscal year, whichever is greater. The GDPR also has been implemented into UK law as part of the arrangements following the UK’s withdrawal from the EU and operates in conjunction with other local data privacy requirements, although the GDPR and UK GDPR may diverge over time. The UK is also in the process of reforming its data privacy rules through a new Data Protection and Digital Information Bill.

In the United States, the CCPA broadly defines personal information and substantially increases the rights of California residents to understand how their personal information is collected, used, and otherwise processed by commercial businesses, such as affording them the right to access and request deletion of their information and to opt out of certain sharing and sales of personal information. The CCPA includes a private right of action (permitting lawsuits to be brought by private individuals instead of the state Attorney General or other government actor for certain breaches), and contemplates civil penalties of up to $2,500 for each violation and up to $7,500 for each intentional violation.

In addition, several states have enacted comprehensive data privacy laws similar to the CCPA. These will apply in addition to laws that already exist in all 50 U.S. states that require businesses to provide notice under certain circumstances to consumers whose personal information has been disclosed as a result of a data breach. Moreover, the U.S. Congress has recently considered, and is currently considering, various proposals for more comprehensive data privacy and security legislation, to which we may be subject if enacted.

The Corporation maintains a regulatory change framework to monitor and respond to regulatory change, including for data privacy, and has adopted and disseminated privacy policies and communicates required information relating to financial privacy and data security in accordance with applicable law.

CONSUMER LAWS AND REGULATIONS

The Corporation’s banking subsidiaries are subject to certain federal and state laws and regulations designed to protect consumers in transactions with banks. Failure to comply with these laws and regulations could lead to substantial penalties,

2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION 9

operating restrictions and reputational damage to the financial institution. Consumer laws and regulations are enforced by the Consumer Financial Protection Bureau (CFPB) and other federal and state regulators.

NON-U.S. REGULATION

Northern Trust is subject to the laws and regulatory authorities of the jurisdictions in which its non-U.S. branches and subsidiaries operate. For example, branches and subsidiaries conducting banking and asset servicing businesses in the UK are authorized to do so pursuant to the UK Financial Services and Markets Act 2000. They are authorized by the Prudential Regulation Authority (PRA) and/or the Financial Conduct Authority (FCA). The PRA and FCA exercise broad supervisory and disciplinary powers that include the power to revoke temporarily or permanently authorization to conduct a regulated business upon breach of the relevant regulations, impose capital requirements, suspend registered employees, and impose censures and fines on both regulated businesses and their regulated employees. Additionally, the Bank is licensed as a foreign authorized deposit-taking institution in Australia under the Banking Act (Australia) and as a wholesale bank in Singapore under the Banking Act (Singapore) and as a result is subject to the supervision of the Australian Prudential Regulation Authority and the Monetary Authority of Singapore, respectively.

Northern Trust’s European branches and subsidiaries are subject to the laws and regulatory authorities of the EU and the member states in which they are domiciled. For example, Northern Trust Global Services SE, as an EU-domiciled credit institution in Luxembourg, is subject to the prudential supervision of the ECB and the CSSF. Moreover, Northern Trust’s non-EU branches and subsidiaries conducting financial services activities in the EU may fall within the scope of the laws of the EU and, given the increasing extraterritorial effect of EU legislation, non-EU branches and subsidiaries may still fall within the scope of EU law if they transact outside of the EU with EU clients.

Since January 31, 2020, the UK has not been a member of the EU. EU legislation as it applied to the UK on December 31, 2020 is a part of UK domestic legislation, under the control of the UK’s parliament. Most UK law relevant to the Corporation and its subsidiaries is still closely aligned with the EU legislative framework in place in December 2020. However, in 2022, the UK government proposed legislation that makes significant reforms to the UK’s financial services regulations. In particular, the Financial Services and Markets Act 2023 includes measures revoking retained EU law relating to financial services. In addition, the UK government announced a package of post-Brexit reforms to drive growth and competitiveness in the financial services sector. The Financial Services and Markets Act 2023 along with these other reforms may directly and indirectly impact the Corporation.

The following items provide a brief description of certain key regulatory requirements in the EU and the UK relevant to the Corporation and its subsidiaries, in addition to the BRRD and GDPR discussed under “Resolution Planning” and “Data Privacy and Security,” respectively, above.

EU and UK Prudential Regulatory Frameworks. The EU Capital Requirements Directive of June 26, 2013 (CRD) and the EU Capital Requirements Regulation of June 26, 2013 (CRR) set out the framework for prudential regulation of credit institutions in the EU, including, among other things, capital and liquidity requirements, leverage, and disclosure and reporting. CRR and CRD have been subject to extensive amendments relating to the leverage ratio, the net stable funding ratio, large exposures, and market and counterparty credit risk, enhancing the resiliency of EU banks to potential future economic shocks, the transition to climate neutrality and finalizing the implementation of the Basel III agreement. Since June 26, 2021, investment firms under the Markets in Financial Instruments Directive (MIFID) have been subject to a new prudential regime under the EU Investment Firm Directive and Investment Firm Regulation. In April 2021, the Financial Services Act came into force in the UK establishing among other things, (i) a framework for the new investment firm prudential framework to apply in the UK and (ii) the UK implementation of Basel III standards, including amendments to CRR as implemented into UK law following the withdrawal from the EU. UK and EU branches and subsidiaries of the Corporation may also be subject to local rules on outsourcing and operational resilience.

Markets Regulation. MIFID (which came into force in 2018), the linked Markets in Financial Instruments Regulation (MIFIR), and the European Market Infrastructure Regulation 648/2012 (EMIR) are the primary pieces of EU legislation which regulate, among other things, trading in derivative and securities markets, transaction reporting, investor protection, clearing and risk mitigation. MIFID, MIFIR and EMIR, with applicable amendments, now form part of UK law under the legislation implemented when the UK left the EU. Reforms to the onshored version of MIFIR have been made by the UK Financial Services and Markets Act 2023. The reforms impact, among other things, the share trading obligation and derivatives trading obligation.

Central Securities Depositories Regulation. On September 17, 2014, the EU Central Securities Depositories Regulation (CSDR) entered into force (subject to a number of transitional provisions). The CSDR aims principally to ensure that transactions between buyers and sellers of dematerialized securities are settled in a safe and timely manner by introducing common securities settlement standards across the EU. Key features of the CSDR include shorter settlement periods, settlement discipline measures (including mandatory cash penalties and “buy-ins” for settlement fails and settlement fails reporting) and an obligation regarding dematerialization for most securities. In the UK, the Financial

10 2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION

Services and Markets Act 2023 grants to the Bank of England new rule-making powers in relation to central securities depositories (CSD).

Securities Financing Transactions and Reuse of Collateral Regulation. On November 25, 2015, the EU adopted a regulation on securities financing transactions and reuse of collateral (SFTR) as part of its approach to addressing shadow banking. The regulation includes provisions for enhanced transparency and reporting of securities financing transactions. The SFTR entered into force on January 12, 2016. The reporting obligations under the SFTR were phased in over several periods through January 11, 2021.

Benchmarks Regulation. On January 1, 2018, the EU Benchmarks Regulation (BMR) became applicable in all EU member states. The principal objectives of the BMR are to restore investor confidence in the accuracy, robustness and integrity of indices used as benchmarks in financial instruments and financial contracts or to measure the performance of investment funds, and the benchmark-setting process itself. The BMR aims to achieve these objectives by ensuring that benchmarks are not subject to conflicts of interest, are used appropriately, and reflect the actual market or economic reality they are intended to measure. The BMR has been incorporated into UK law following the withdrawal from the EU, with applicable amendments. In the UK, the FCA has exercised powers under the BMR to effect the publication of a synthetic LIBOR rate for one-month, three-month and six-month sterling and U.S. Dollar LIBOR (USD LIBOR) beyond their respective dates of cessation.

Sustainable Finance Disclosure Regulations. On December 29, 2019, the EU Sustainable Finance Disclosure Regulations (SFDR) entered into force. SFDR aims to prevent “greenwashing” (conveying a misleading or false impression a product is more environmentally favorable than it actually is) by requiring disclosure of how sustainability risks and environmental, social and governance (ESG) factors are part of the investment and business processes of asset managers. Mandatory disclosures are required to be published at product and manager levels in a variety of ways, including on websites, in pre-contractual documents (e.g., prospectuses) and in annual reports. In October 2021, the UK government announced that it will launch its own consultation with stakeholders on sustainable finance disclosures rules for certain UK market participants and certain investment products. On October 25, 2022, the FCA issued a consultation paper on new measures for a UK regime on sustainability disclosure requirements and investment labels. The new measures will enter into force during the course of 2024.

Taxonomy Regulation. On July 12, 2020, Regulation (EU) 2020/852 (Taxonomy Regulations) entered into force. The Taxonomy Regulations are part of the EU’s recent measures designed to encourage environmentally sustainable investment decision making and introduce a technical framework to ascertain how sustainable an economic activity is. The Taxonomy Regulations apply to financial market participants including MiFID firms, Undertakings for the Collective Investment in Transferable Securities (UCITS) management companies, and alternative investment fund managers, and will require them to make further entity, pre-contractual and periodic disclosures. The UK government is in the process of implementing its own “green” taxonomy for guiding companies and investors on “green” investments, similar to the EU regime.

Deposit Guarantee Scheme. Eligible deposits held with EU credit institutions and certain other financial entities are subject to the recast Deposit Guarantee Schemes Directive (DGSD) implemented in 2014. It required EU member states to introduce legislation establishing at least one deposit guarantee scheme (DGS). A DGS which is established and recognized in one member state is obliged to cover the depositors (up to certain prescribed amounts) at branches of the same institution in other EU member states. In the UK, the Financial Services Compensation Scheme is the national DGS for the protection and reimbursement of depositors of failed financial institutions.

Fifth EU Money Laundering Directive. On July 9, 2018, the Fifth EU Money Laundering Directive (MLD5) entered into force. MLD5 was required to be transposed into local law by EU member states by January 10, 2020 and introduced the following key changes to the previous EU AML regime: (i) EU member states must ensure that registers of ultimate beneficial owners of companies and other legal entities are accessible to the general public; (ii) the previous AML regime was extended to additional service providers, such as electronic wallet providers, virtual currency exchange service providers, and art dealers, and further specifications regarding the scope of application of MLD5 with respect to tax advisors and estate agents were provided; (iii) the threshold for identifying holders of prepaid cards was lowered to €150; and (iv) EU member states were required to implement enhanced due diligence measures to monitor suspicious transactions involving high-risk countries more strictly. The UK government transposed MLD5 into UK law and, therefore, the UK anti-money laundering regime is currently broadly aligned with the EU. On December 7, 2022, the Council of the EU agreed its position on AML regulation through the Sixth EU Money Laundering Directive. The new rules will extend to, among other items, the entire crypto-asset sector, third-party intermediaries, persons trading in precious metals, precious stones and cultural goods.

Shareholder Rights Directive. On May 17, 2017, the recast Shareholder Rights Directive (EU) 2017/828 was published (SRD II). Member states of the EU were required to bring into force the laws, regulations and administrative provisions necessary to comply with the Directive by June 10, 2019. SRD was designed to establish requirements in relation to the exercise of shareholder rights and, recognizing that shares are often held through complex chains of intermediaries, SRD II is designed to improve mechanisms for the identification of shareholders by companies, as well as

2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION 11

improve the transmission of information along the chain of intermediaries to facilitate the exercise of shareholder rights. Non-EU intermediaries are required to comply with the requirements if they provide services with respect to shares of companies that have their registered office in the EU. SRD II has been incorporated into UK law and remains largely aligned with the EU.

Depositary Books & Records. Following the European Securities and Markets Authority’s opinion on asset segregation and application of depositary delegation rules to CSDs published on July 20, 2017, changes were introduced by two EU regulations modifying the existing Alternative Investment Fund Managers Directive (AIFMD) and UCITS Level 2 Regulations. The changes aim to better define asset segregation requirements and to add additional safeguards, primarily focusing on information flow between the depositary and any third party to whom safe-keeping functions have been delegated. The key changes (i) impact the frequency of reconciliations between the depositary’s internal accounts and records and those of any third party in the custody chain, (ii) require the depositary to maintain an independent record separate from the record maintained by the third party, and (iii) increase due diligence obligations where custody of assets is delegated to third parties outside of the EU. AIFMD and the UCITS directive were incorporated into UK law and remain largely aligned with the EU. The changes impact Northern Trust’s subsidiaries providing depositary services to European-domiciled fund clients.

In addition to the above, the Bank’s and the Corporation’s subsidiary banks located outside the United States are subject to regulatory capital requirements in the jurisdictions in which they operate. As of December 31, 2023, each of our non-U.S. banking subsidiaries had capital ratios above their specified minimum requirements.

Human Capital Management

The success of our company relies heavily on the strength of the people we employ. Attracting, engaging, developing and retaining Northern Trust talent is critical. We invest in our employees holistically to continually build a diverse pipeline of future leaders and enable internal professional advancement. The overview below outlines Northern Trust’s human capital objectives—talent management, total rewards, and diversity, equity and inclusion.

EMPLOYEES

Northern Trust employed approximately 23,100 full-time equivalent employees as of December 31, 2023. The regional breakout of our employee base is 42% Asia-Pacific, 41% North America, and 17% Europe, Middle East, and Africa.

TALENT MANAGEMENT

We pride ourselves in attracting strong talent and have identified the development of our talent as a strategic priority. Our focus on well-being, diversity, and a culture of trust, care and collaboration contribute to our employer brand.

Sourcing and Recruitment. We target our talent identification, sourcing methods, and recruitment strategies to specific locations using various channels such as job boards, colleges, professional networks, associations and online social networks. We base hiring decisions on a variety of factors including relevant experience and accomplishments, educational background, professional licensing, and strong evidence of integrity and ethical behavior.

Onboarding. Northern Trust is committed to helping all new hires succeed from day one. New employees begin their onboarding journey with a comprehensive learning roadmap that orients them to our history, brand, businesses, and culture. Orientation programs also augment the onboarding experience by providing global, regional, and/or local information along with networking activities to help connect new hires to each other and other colleagues.

Learning and Development. An integrated partnership between our enterprise-wide and functional learning and development teams ensures we deliver holistic training solutions. Through our online learning portal, Northern Trust University, all employees can access a portfolio of professional and functional training offerings most helpful to their role. We provide targeted development opportunities for employees transitioning into management and throughout their management and leadership career. Our training content is dynamic as we regularly evaluate its quality and utilization and we refresh and organize courses and resources to enable employees to develop skills most critical to servicing our clients and developing their careers. A continuing area of focus is helping expand digital, analytical and financial acumen and skills across the enterprise. Many of our programs are interactive, include peer networking, and offer direct access to expert facilitators. Training is offered through online libraries of self-study content and in both virtual and classroom instructor-led formats.

Talent Planning and Organizational Effectiveness. Northern Trust is committed to identifying and developing talent with the breadth, depth, and diversity of technical and leadership skills to execute business strategies today and in the future. Managers conduct talent assessments for employees annually and business and regional leadership teams hold regular talent review discussions focused on specific topics, such as workforce needs, retention risks, diversity, top talent, readiness for promotion, readiness-to-move, and succession plans. Senior level talent reviews are also conducted each year by our senior management and Board of Directors, led by our Chairman and Chief Executive Officer and Chief Human Resources Officer.

12 2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION

Performance Management. Northern Trust’s annual performance management process includes goal setting, mid-year check-ins, multi-rater feedback, and year-end reviews. Strategic corporate priorities are set by our Chairman and Chief Executive Officer and are applied to each business, department, team and individual. Managers are encouraged to provide regular feedback and real-time coaching to drive performance outcomes and facilitate development.

Engagement and Recognition. Building an inclusive, connected and engaged employee culture is essential to retaining our talent. We collect employee perspectives and ideas through an annual Engagement Survey. Results are evaluated to identify strengths, progress, and opportunities to strengthen employee engagement, and are shared with employees and the Board of Directors. We also offer an online employee recognition platform that strengthens the unity that binds us as a company and connects employees in new and meaningful ways.

TOTAL REWARDS

Our compensation and benefit programs are designed to be market-competitive and enable us to attract and retain talent to deliver on Northern Trust’s strategy.

Compensation Programs. Our compensation programs are intended to motivate our employees to deliver the highest-quality service to our clients and achieve the greatest collective business results while appropriately managing risk. They are designed, implemented, and communicated to promote behaviors that are consistent with Northern Trust’s desired culture, character and enduring values of service, expertise, and integrity. We also regularly review our compensation processes and programs and take appropriate measures to ensure we can attract and retain talent in relevant markets.

Northern Trust’s base salary programs provide a competitive level of fixed pay reflecting each employee’s position, experience, qualifications and tenure. Additionally, all employees are eligible for incentive compensation to reward performance that delivers strong team or individual results. Incentive compensation is linked to both financial and non-financial performance criteria, including risk considerations, as determined by our Board of Directors and senior management. Select senior leaders and individual contributors may receive a percentage of their incentive in Northern Trust stock to encourage retention of key talent and to align rewards with company performance.

Employee Benefits. While the exact composition of the employee benefit package varies by country, our benefit programs are designed to be locally competitive, to meet the needs of our employees and their families, and to reflect the cultural values of the organization. Typical benefit programs include retirement, health care, paid time off, income protection such as disability and life insurance, leaves of absence, and access to our Employee Assistance Program. Our expanded employee well-being programs and resources focus on how to manage stress, build resiliency, and be attuned to mental health issues; accessing flexible or voluntary benefits; and enhancements to various parental leave offerings.

DIVERSITY, EQUITY, AND INCLUSION (DE&I)

Northern Trust is committed to an inclusive culture and strives to create a work environment in which all individuals are welcomed, respected, supported, valued, and can fully contribute to the success of the business.

Leading From the Top. Our vision for creating an inclusive environment is embedded at all levels of the organization. Our Board of Directors, through its Human Capital and Compensation Committee, and our Chairman and Chief Executive Officer actively engage in oversight of our DE&I strategies and initiatives. All DE&I functions are led by our Head of Corporate Sustainability, Inclusion and Social Impact, who is an Executive Vice President, and reports directly to our Chairman and Chief Executive Officer. Reflecting the importance of an inclusive workplace, in 2023, we established the role of Global Chief DE&I Officer, responsible for developing the enterprise’s inclusion strategies. Three Regional DE&I Leads are responsible for the design and execution of topic relevant programs across North America, Europe, the Middle East, and the Asia-Pacific region. Our Global DE&I Executive Council is responsible for providing strategic oversight and driving accountability on the inclusion priorities.

The following table presents the gender and ethnic diversity of our Board of Directors and executive officers.

TABLE 2: BOARD OF DIRECTORS AND EXECUTIVE OFFICERS REPRESENTATION

DECEMBER 31, 2023
FEMALEMALEWHITEBLACKHISPANICASIAN
Board of Directors25%75%59%25%8%8%
Executive Officers33%67%84%8%8%—%

Bolstering Inclusion. We are committed to providing equal opportunities for all employees regardless of race, gender, gender identity, sexual orientation, age, disability, religion, ethnicity, veteran status, or any other characteristic. We strive to ensure that our policies, processes, and structures promote inclusivity and offer equitable opportunities for our employees to grow and thrive within the workplace. We invest in ongoing education to increase awareness and understanding of diversity and inclusion concepts and behaviors.

2023 ANNUAL REPORT | NORTHERN TRUST CORPORATION 13

Leveraging our employee Engagement Survey and insights and benchmarks from industry experts, we launched our Inclusion Index to better understand the factors that drive inclusion and our employees’ sense of belonging across the organization. The Index helps us identify gaps and opportunities to build upon our strengths around inclusion. Our leaders are committed to implementing solutions to foster an inclusive and diverse workplace that aligns with the Corporation’s mission, values, goals, and business practices.

Available Information

Through the Corporation’s website at www.northerntrust.com, the Corporation makes available free of charge its Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and all other reports and all amendments to those reports filed or furnished pursuant to Section 13(a) or 15(d) of the Securities Exchange Act of 1934, as amended (Exchange Act), as soon as reasonably practicable after it files such material with, or furnishes such material to, the SEC. The contents of the Corporation’s website, the website of the SEC or any other website referenced herein are not a part of this Annual Report on Form 10-K.

Previous: Cover and table of contents · Next: Item 1A. RISK FACTORS