By Kevin Brenner | Thursday, September 24, 2026
Not Good is not an indictment of the companies it covers. It is a study of the mistakes made inside them by people prone to making them.
In June 2016, someone mailed an anonymous letter to the board of one of the largest banks in the world. The letter raised concerns about a senior hire. It was not threatening. It was not extortion. It was the kind of letter that compliance departments are built to receive, investigate, and resolve.
The CEO of Barclays read it and decided to find out who sent it.
That decision produced enforcement actions on two continents, a $15 million fine from New York’s banking regulator, and special reporting requirements never before imposed on a UK regulated firm over whistleblowing. And it was only the first chapter. The second chapter ended with the same CEO banned for life from holding a senior position in UK financial services. That chapter involved Jeffrey Epstein.
Same person. Same instinct. Different secret.
The Regulators
Barclays is a global bank headquartered in London. It is supervised by two UK regulators: the Financial Conduct Authority, which regulates the conduct of financial firms and the people who run them, and the Prudential Regulation Authority, part of the Bank of England, which focuses on institutional safety and soundness. Because Barclays operates a branch in New York, it also falls under the New York State Department of Financial Services, which has its own enforcement authority. All three regulators would eventually investigate the same letter.
The Letter
Jes Staley became CEO of Barclays on December 1, 2015. He came from JPMorgan, where he had run the investment bank and the private bank.
In early 2016, Staley recruited a friend and former JPMorgan colleague to run Barclays’ Financial Institutions Group in New York. In June, the board received an anonymous letter signed “John Q. Public,” claiming to be from a shareholder. The letter raised what the FCA later described as “various allegations, some of which concerned Mr. Staley.” The allegations were personal in nature and questioned the fitness of the new hire, along with Staley’s role in recruiting him.
Under Barclays’ own policies, the letter should have gone directly and only to the bank’s Investigations and Whistleblowing team. That did not happen. The letter was addressed to the Board Chairman, and senior management treated it as a governance matter about a hire rather than a whistleblower complaint. It was circulated among the bank’s most senior executives, including Staley.
On June 21, Group Compliance classified the letter as a whistleblowing matter and opened an investigation. Group Compliance is Barclays’ central compliance function, led by the Group Chief Compliance Officer and including a dedicated Investigations and Whistleblowing team responsible for receiving and investigating whistleblower complaints. Three days later, a second anonymous letter arrived, this one claiming to be from “concerned” Barclays employees in the same division. It raised nearly identical concerns.
Two letters. Both classified as whistleblowing matters. Compliance investigating. That should have been the end of Staley’s involvement.
The Warnings
What makes this case unusual is not only that Staley tried to identify the whistleblower. It is that he did so after he was told, clearly and repeatedly, not to.
Both Barclays’ Group Chief Compliance Officer and General Counsel firmly advised him against pursuing the source, emphasizing that the complaints had to be treated as protected whistleblowing matters. The compliance function made clear that it would investigate the allegations and that no further action should be taken until that review was complete.
The warnings continued. On July 5, Staley received the Monthly Whistleblowers’ Champion Report, which classified both letters as significant whistleblowing cases. Two days later, Barclays’ head of Investigations and Whistleblowing told Staley’s Chief of Staff “quite categorically” that the letters were being handled under the bank’s whistleblowing procedures. On July 8, Staley was informed that the recruitment allegations appeared unsubstantiated. According to the FCA’s Final Notice, he interpreted that update to mean the first letter was no longer protected by whistleblower safeguards. That interpretation was incorrect, and Staley never sought clarification from the compliance and legal officials who had repeatedly advised him otherwise.
Instead, he went looking for the author.
The Hunt
The DFS investigation found that, in June and July 2016, Staley personally directed Barclays’ head of Group Security to try to identify the author or authors of two whistleblower letters. Staley said his primary motivations were to protect a newly hired senior executive, a friend and former colleague, from what he believed were false and malicious allegations, and to preserve his ability as CEO to recruit senior talent to the bank. However, regulators concluded that he faced a significant conflict of interest because the letters also questioned his own role, and that of Barclays’ management, in the recruitment and employment of the executive with whom he had previously worked at another institution.
The letters carried U.S. postmarks, prompting Barclays’ security team to seek assistance in tracing their origin. According to the DFS Consent Order, a U.S. Postal Service official was told only that the letter was “a threat to the bank” and involved “potential criminal activity.” In reality, the letters were whistleblower complaints concerning the hiring of the senior executive and did not involve a threat to the institution or criminal activity.
Staley also shared the first letter with two friends and former colleagues, neither of whom worked at Barclays. At the same time, Barclays’ compliance function provided clear guidance regarding the bank’s whistleblowing protections and the restrictions on efforts to identify whistleblowers. Regulators found that despite receiving and understanding that guidance, Staley proceeded with actions that sought to circumvent those protections rather than abide by them.
The Bill
In January 2017, a separate whistleblower complaint revealed Staley’s efforts to the compliance function, which had been completely unaware of the hunt. The Board launched an internal investigation. In April 2017, Barclays publicly disclosed the matter. Staley apologized. On May 11, 2018, the FCA and PRA jointly fined Staley £642,430, the first enforcement case ever brought under the UK’s Senior Managers Regime. The regulators found a breach of the requirement to act with due skill, care, and diligence, not a lack of integrity: in the regulators’ view, Staley mistakenly believed the first letter was no longer protected. FCA Executive Director Mark Steward said: “Mr Staley breached the standard of care required and expected of a Chief Executive in a way that risked undermining confidence in Barclays’ whistleblowing procedures. … It is critical that individuals are able to speak up anonymously and without fear of retaliation if they want to raise concerns.” Barclays was placed under special reporting requirements, the first ever imposed on a UK regulated firm in relation to whistleblowing, and clawed back £500,000 from Staley’s compensation. The board stood by him. Two regulators had concluded the CEO tried to unmask a whistleblower. The board clawed back part of a bonus and called the matter closed.
Seven months later, DFS fined Barclays $15 million, citing shortcomings in governance, controls, and corporate culture relating to the whistleblowing function.
The Second Chapter
Jeffrey Epstein was arrested in July 2019, and the FCA needed to satisfy itself that a sitting CEO of a major UK bank did not have a compromising relationship with a convicted sex offender. Under the Senior Managers Regime, approved persons are required to act with integrity and be open and cooperative with their regulators. In August 2019, the FCA asked Barclays to explain Staley’s relationship with Epstein. Staley approved a letter to the FCA stating he did not have a close relationship with Epstein and that contact had ceased well before he joined Barclays. Both statements were false. The FCA uncovered hundreds of emails showing contact as late as the days before Staley’s appointment was announced. In emails between them, Staley described Epstein as one of his “deepest” and “most cherished” friends. Staley stepped down on November 1, 2021. Barclays did not fire him.
On June 26, 2025, the Upper Tribunal upheld a lifetime ban, finding that Staley “had a clear motive for downplaying the relationship” and “has shown no remorse for his conduct.” The fine was reduced to £1.1 million only because Barclays had separately withheld deferred shares. The FCA issued its Final Notice on July 23, 2025, prohibiting Staley from performing any senior management or significant influence function in relation to any regulated activity.
The total bill for Staley personally: a £642,430 fine and public censure, a £500,000 clawback, a £1.1 million fine, and a lifetime ban from UK financial services. For Barclays: a $15 million fine from DFS, years of enhanced supervisory reporting, and an outside review of its entire whistleblowing program. The underlying letter raised concerns about a hire. The CEO’s response produced years of regulatory proceedings and a career-ending ban that had nothing to do with the letter at all.
My Read on Barclays
The whistleblower letter was a test, and Staley failed it. The substance of the complaint appears to have been unsubstantiated. Had Staley done nothing, the compliance team would have investigated, closed the matter, and the letter likely would have faded into obscurity.
Instead, Staley’s instinct was to treat the identity of the critic as more important than the content of the criticism. That instinct cost him a fine in 2018. The same instinct, applied to a different secret, cost him his career in 2025.
The failure was not entirely his alone. The DFS investigation found that senior Barclays executives involved in counseling Staley repeatedly failed to properly document the advice they gave him or maintain adequate internal records of those discussions. Regulators also concluded that several members of senior management failed to apply the bank’s whistleblowing policies and procedures in a manner that protected both Staley and Barclays. The episode exposed gaps not only in individual judgment but also in the institution’s controls.
Yet those shortcomings do not change the central fact: Staley was warned. He was told the letters were protected whistleblowing matters. He was advised by compliance and legal leadership not to seek the author’s identity. He understood the process and chose to work around it.
In 2016, Staley was told something uncomfortable existed, and his response was to control the information rather than let the process work. In 2019, when the FCA asked about something uncomfortable, his response was to approve a letter that said what he wanted the answer to be rather than what the answer was. The FCA gave him the benefit of the doubt the first time, finding carelessness rather than dishonesty. He did not receive the same benefit the second time. The Upper Tribunal found a “lack of integrity,” “no remorse,” and a “calculated risk” that the truth would never surface.
That is the throughline of this story. The underlying problem is often survivable. The decision to manage the narrative rather than allow the facts and processes to run their course is what creates the enforcement case.
How to Avoid Becoming the Next Cautionary Tale
-
Whistleblowing investigations belong to Compliance, not to the subject of the complaint. The moment a leader named in or connected to a complaint begins directing the response, the investigation is compromised. Build a standing protocol: any complaint that touches the executive team or the board gets handled by people who do not report to the person named. Document the wall and enforce it.
-
“Who sent this?” is the wrong first question. The right first question is: “Is this true?” If the criticism is unfounded, the investigation will show that. If the critic’s identity matters, compliance and legal can decide whether and how to pursue it through proper channels. The CEO’s curiosity is not a proper channel.
-
Do not let the security function become an instrument of retaliation. Any security request that targets the identity of a person who raised an internal concern should require sign-off from compliance and legal, documented in writing, before any action is taken.
One More Thing
The detail that stays with me is not the fine, the ban, or the Epstein chapter. It is the timeline.
June 21: Compliance classifies the letter as a whistleblowing matter. June 29: The General Counsel and Chief Compliance Officer both tell Staley not to pursue the author. July 5: Staley receives the Whistleblowers’ Champion Report identifying the cases as significant. July 7: The head of Investigations and Whistleblowing tells his Chief of Staff “quite categorically” the letters are whistleblowing matters.
Staley went looking anyway.
He was not confused about the rules. He was advised by the people who knew the rules best. He received the reports that confirmed the rules applied. He decided, as experienced people under pressure sometimes do, that the rules could be managed.
That is the point of Not Good. The cover-up is rarely the work of someone who does not understand the rules. It is often the work of the person who understands them well enough to find the workaround.
And the people inside the organization are always watching. The fear of retaliation is not ultimately a question of policy language. It is a question of example. Employees learn what a company’s whistleblowing culture really is by observing what its leaders do when criticism arrives at their door.
Spot the red flag now. Or read about it in the next issue.
Click Here to Schedule a 30 minute Consultation with Kevin Brenner
Not Good is a LinkedIn newsletter about corporate misconduct, enforcement actions, and the very expensive lessons hidden inside other companies’ worst decisions. Subscribe, share, and send me the bad acts you can’t believe happened.
The information provided on this website is for general informational purposes only and should not be considered legal advice. No attorney-client relationship is created by accessing or using this website. Please consult with a qualified attorney before making any legal decisions. Global Link Law is not liable for any reliance on the information provided. Prior results do not guarantee a similar outcome.