Investment banks are in the business of taking calculated risks. Risk management infrastructure facilitates the safe pursuit of profits and the balancing of associated risks. By 2006, Lehman Brothers was thought to have a very respectable risk management system, and even its regulator, the Securities and Exchange Commission, viewed its risk framework as being fully compliant with regulatory requirements. In its public disclosures, Lehman characterized its risk controls as “meaningful constraints on its risk taking” and evidence of its continued financial stability. Beginning in late 2006, however, Lehman began dismantling its carefully crafted risk management framework as it pursued a new high-leverage growth strategy. During the next two years, it exceeded many risk limits, aggressively increased a number of risk metrics, disregarded its risk procedures, and excluded risk management personnel from key decisions. In October 2007, it replaced its well-regarded chief risk officer with a seasoned deal maker who lacked professional risk management experience. This case considers the value of a risk management system and how it functioned (and then did not) to constrain risk taking at Lehman. It also considers the role of its regulator.