FULLTEXT DEL 2 AV 5
10-K – 2026-02-24 – ntrs-20251231.htm
Most U.S. states, the EU and other non-U.S. jurisdictions also have adopted their own statutes and/or regulations concerning data privacy and security and requiring notification of data breaches―for example, the General Data Protection Regulation (GDPR) in Europe and its equivalent in the UK (UK GDPR), the Personal Information Protection Law (PIPL) in China, and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, CCPA) in the United States. Similar laws are in effect or being implemented in other jurisdictions in which we operate across the globe. The GDPR is designed to harmonize data privacy and security laws across the European Economic Area (EEA) and to protect EEA citizens’ data privacy and security. The GDPR imposes stringent operational requirements on both data controllers and data processors and has extraterritorial effect as its scope includes all data controllers and processors outside the EEA whose processing activities relate to the offering of goods or services to, or monitoring the behavior of, EEA individuals. Organizations that violate certain provisions of the GDPR could be fined up to €20 million or 4% of their annual worldwide revenue for the preceding fiscal year, whichever is greater. The Digital Omnibus Regulation Proposal published in 2025 is expected to introduce technical amendments to a large corpus of digital legislation in Europe, including the EU GDPR. The UK GDPR, which operates in conjunction with other local data privacy requirements, as reformed in 2025 through the adoption of the UK Data Use and Access Act 2025, also provides for data protection requirements equivalent to the EU GDPR. In 2025, Northern Trust received regulatory approval in Europe to use Binding Corporate Rules as a legal mechanism supporting transfers of data from Northern Trust group entities in the EEA to other group entities outside the EEA. Northern Trust expects to launch the EU Binding Corporate Rules in 2026. The Corporation has adopted and disseminated privacy policies and communicates required information relating to financial privacy and data security in accordance with applicable law. In the United States, the CCPA broadly defines personal information and substantially increases the rights of California residents to understand how their personal information is collected, used, and otherwise processed by commercial businesses, such as affording them the right to access and request deletion of their information and to opt out of certain sharing and sales of personal information. The CCPA includes a private right of action (permitting lawsuits to be brought by private individuals instead of the state Attorney General or other government actor for certain breaches), and contemplates civil penalties of up to $2,500 for each violation and up to $7,500 for each intentional violation. In addition, several states have enacted, or are considering enacting, comprehensive data privacy laws similar to the CCPA. Similarly, Regulation S-P amendments introduced by the SEC create additional obligations for broker-dealers and registered investment advisers to protect customer information, including timely notification of incidents to impacted individuals. These laws apply, or will apply, in addition to laws that already exist in all 50 U.S. states that require businesses to provide notice under certain circumstances to consumers whose personal information has been disclosed as a result of a data breach. Moreover, the U.S. Congress has considered, and will likely in the future consider, various proposals for more comprehensive data privacy and security legislation, to which we may be subject if enacted. ARTIFICIAL INTELLIGENCE Northern Trust uses a variety of machine learning and artificial intelligence (AI) solutions to process transactional activity more efficiently and to mitigate risk. These uses currently include, among others, digitizing documents, detecting anomalous, fraudulent transactions and training services teams on operational processes. Regulation of AI is rapidly evolving in the U.S. and worldwide as legislators and regulators are increasingly focused on these powerful emerging technologies. The technologies underlying AI and its uses are subject to a variety of laws and regulations, including intellectual property, privacy, data protection, cybersecurity, consumer protection, competition, and equal opportunity laws, and are expected to be subject to increased regulation and new laws or new applications of existing laws and regulations. Additionally, several U.S. states, including Colorado and California, have passed or are continuing to propose laws and regulations that govern various facets and uses of AI, including consequential decisions, and, in Europe, the EU’s Artificial Intelligence Act (EU AI Act) entered into force on August 1, 2024. Northern Trust has certain processes and controls in place designed to mitigate the risks associated with the use of AI solutions, including monitoring the development and applicability of such evolving laws and regulations, and has taken, and will continue to take steps designed to comply with laws and regulations applicable to Northern Trust’s use of AI. CONSUMER LAWS AND REGULATIONS The Corporation’s banking subsidiaries are subject to certain federal and state laws and regulations designed to protect consumers in transactions with banks. Failure to comply with these laws and regulations could lead to substantial penalties, operating restrictions and reputational damage to the financial institution. Consumer laws and regulations are enforced by the Consumer Financial Protection Bureau (CFPB) and other federal and state regulators. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 9 NON-U.S. REGULATION Northern Trust is subject to the laws and regulatory authorities of the jurisdictions in which its non-U.S. branches and subsidiaries operate. For example, branches and subsidiaries conducting banking and asset servicing businesses in the UK are authorized to do so pursuant to the UK Financial Services and Markets Act 2000. They are authorized by the Prudential Regulation Authority (PRA) and/or the Financial Conduct Authority (FCA). The PRA and FCA exercise broad supervisory and disciplinary powers that include the power to revoke temporarily or permanently authorization to conduct a regulated business upon breach of the relevant regulations, impose capital requirements, suspend registered employees, and impose censures and fines on both regulated businesses and their regulated employees. Additionally, the Bank is licensed as a foreign authorized deposit-taking institution in Australia under the Banking Act (Australia) and as a wholesale bank in Singapore under the Banking Act (Singapore) and as a result is subject to the supervision of the Australian Prudential Regulation Authority and the Monetary Authority of Singapore, respectively. Northern Trust’s European branches and subsidiaries are subject to the laws and regulatory authorities of the EU and the member states in which they are domiciled. For example, Northern Trust Global Services SE, as an EU-domiciled credit institution in Luxembourg, is subject to the prudential supervision of the ECB and the CSSF. Moreover, Northern Trust’s non-EU branches and subsidiaries conducting financial services activities in the EU may fall within the scope of the laws of the EU and, given the increasing extraterritorial effect of EU legislation, non-EU branches and subsidiaries may still fall within the scope of EU law if they transact outside of the EU with EU clients. Since January 31, 2020, the UK has not been a member of the EU. EU legislation as it applied to the UK on December 31, 2020 is a part of UK domestic legislation, under the control of the UK’s parliament. Most UK law relevant to the Corporation and its subsidiaries is still closely aligned with the EU legislative framework in place in December 2020. However, in 2022, the UK government proposed legislation that makes significant reforms to the UK’s financial services regulations. In particular, the Financial Services and Markets Act 2023 includes measures that will, over time, revoke retained EU law relating to financial services. In addition, the UK government announced a package of post-Brexit reforms to drive growth and competitiveness in the financial services sector. The Financial Services and Markets Act 2023 along with these other reforms may directly and indirectly impact the Corporation. The following items provide a brief description of certain key regulatory requirements in the EU and the UK relevant to the Corporation and its subsidiaries, in addition to the BRRD and GDPR and UK GDPR discussed under “Resolution Planning” and “Data Privacy and Security,” respectively, above. EU and UK Prudential Regulatory Frameworks. The EU Capital Requirements Directive of June 26, 2013 (CRD) and the EU Capital Requirements Regulation of June 26, 2013 (CRR) set out the framework for prudential regulation of credit institutions in the EU, including, among other things, capital and liquidity requirements, leverage, and disclosure and reporting. CRR and CRD have been subject to extensive amendments relating to the leverage ratio, the net stable funding ratio, large exposures, and market and counterparty credit risk, enhancing the resiliency of EU banks to potential future economic shocks, the transition to climate neutrality and finalizing the implementation of the Basel III agreement. Since June 26, 2021, investment firms under the recast Markets in Financial Instruments Directive (MIFID) have been subject to a new prudential regime under the EU Investment Firm Directive and Investment Firm Regulation. In April 2021, the Financial Services Act came into force in the UK establishing among other things, (i) a framework for the new investment firm prudential framework to apply in the UK and (ii) the UK implementation of Basel III standards, including amendments to CRR as implemented into UK law following the withdrawal from the EU. UK and EU branches and subsidiaries of the Corporation may also be subject to local rules on outsourcing and operational resilience. In June 2024, the texts of CRR III and CRD VI, were formally published in the Official Journal of the EU. Through these legislative measures, the EU will implement the Basel III accord into EU law. These regulations affect the capital and liquidity requirements of European banking entities and restrict the provision of prescribed core banking services, including lending, the provision of guarantees and commitments, and the taking of deposits or other borrowing, by non-EU entities to EU entities, except where these services are provided through an authorized EU branch or where an exemption applies. The new regime is being phased in gradually until 2027. Markets Regulation. MIFID (which came into force in 2018), the linked Markets in Financial Instruments Regulation (MIFIR), and the European Market Infrastructure Regulation 648/2012 (EMIR) are the primary pieces of EU legislation which regulate, among other things, trading in derivative and securities markets, transaction reporting, investor protection, clearing and risk mitigation. MIFID, MIFIR and EMIR, with applicable amendments, now form part of UK law under the legislation implemented when the UK left the EU. Reforms incorporated into the UK version of MIFIR have been made by the UK Financial Services and Markets Act 2023. The reforms impact, among other things, the share trading obligation and derivatives trading obligation. 10 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Central Securities Depositories Regulation. On September 17, 2014, the EU Central Securities Depositories Regulation (CSDR) entered into force (subject to a number of transitional provisions). The CSDR aims principally to ensure that transactions between buyers and sellers of dematerialized securities are settled in a safe and timely manner by introducing common securities settlement standards across the EU. Key features of the CSDR include shorter settlement periods, settlement discipline measures (including mandatory cash penalties and “buy-ins” for settlement fails and settlement fails reporting) and an obligation regarding dematerialization for most securities. In the UK, the Financial Services and Markets Act 2023 grants to the Bank of England new rule-making powers in relation to central securities depositories (CSD). Securities Financing Transactions and Reuse of Collateral Regulation. On November 25, 2015, the EU adopted a regulation on securities financing transactions and reuse of collateral (SFTR) as part of its approach to addressing shadow banking. The regulation includes provisions for enhanced transparency and reporting of securities financing transactions. The SFTR entered into force on January 12, 2016. The reporting obligations under the SFTR were phased in over several periods through January 11, 2021. Benchmarks Regulation. On January 1, 2018, the EU Benchmarks Regulation (BMR) became applicable in all EU member states. The principal objectives of the BMR are to restore investor confidence in the accuracy, robustness and integrity of indices used as benchmarks in financial instruments and financial contracts or to measure the performance of investment funds, and the benchmark-setting process itself. The BMR aims to achieve these objectives by ensuring that benchmarks are not subject to conflicts of interest, are used appropriately, and reflect the actual market or economic reality they are intended to measure. The BMR has been incorporated into UK law following the withdrawal from the EU, with applicable amendments. Sustainable Finance Disclosure Regulations. On December 29, 2019, the EU Sustainable Finance Disclosure Regulations (SFDR) entered into force. SFDR aims to prevent “greenwashing” (conveying a misleading or false impression a product is more environmentally favorable than it actually is) by requiring disclosure of how sustainability risks and environmental, social and governance (ESG) factors are part of the investment and business processes of asset managers. Mandatory disclosures are required to be published at product and manager levels in a variety of ways, including on websites, in pre-contractual documents (e.g., prospectuses) and in annual reports. In November 2025, the European Commission published a proposal for a regulation amending the SFDR. If implemented, the Commission’s proposal will, among other things, introduce a new approach to categorizing financial products that will replace the existing Article 6, Article 8, and Article 9 product categories. In October 2021, the UK government announced that it will launch its own consultation with stakeholders on sustainable finance disclosures rules for certain UK market participants and certain investment products. On October 25, 2022, the FCA issued a consultation paper on new measures for a UK regime on sustainability disclosure requirements and investment labels. The new measures, including an anti-greenwashing rule, product labels and product naming and marketing rules, entered into force during the course of 2024. Taxonomy Regulation. On July 12, 2020, Regulation (EU) 2020/852 (Taxonomy Regulations) entered into force. The Taxonomy Regulations are part of the EU’s recent measures designed to encourage environmentally sustainable investment decision making and introduce a technical framework to ascertain how sustainable an economic activity is. The Taxonomy Regulations apply to financial market participants including MiFID firms, Undertakings for the Collective Investment in Transferable Securities (UCITS) management companies, and alternative investment fund managers, and will require them to make further entity, pre-contractual and periodic disclosures. The UK government previously consulted on implementing its own “green” taxonomy for guiding companies and investors on “green” investments, similar to the EU regime. However, in July 2025 the UK government announced that it decided not to proceed with a UK “green” taxonomy. Deposit Guarantee Scheme. Eligible deposits held with EU credit institutions and certain other financial entities are subject to the recast Deposit Guarantee Schemes Directive (DGSD) implemented in 2014. It required EU member states to introduce legislation establishing at least one deposit guarantee scheme (DGS). A DGS which is established and recognized in one member state is obliged to cover the depositors (up to certain prescribed amounts) at branches of the same institution in other EU member states. In the UK, the Financial Services Compensation Scheme is the national DGS for the protection and reimbursement of depositors of failed financial institutions. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 11 EU Money Laundering Directive. On July 9, 2018, the Fifth EU Money Laundering Directive (MLD5) entered into force. MLD5 was required to be transposed into local law by EU member states by January 10, 2020 and introduced the following key changes to the previous EU AML regime: (i) EU member states must ensure that registers of ultimate beneficial owners of companies and other legal entities are accessible to the general public; (ii) the previous AML regime was extended to additional service providers, such as electronic wallet providers, virtual currency exchange service providers, and art dealers, and further specifications regarding the scope of application of MLD5 with respect to tax advisors and estate agents were provided; (iii) the threshold for identifying holders of prepaid cards was lowered to €150; and (iv) EU member states were required to implement enhanced due diligence measures to monitor suspicious transactions involving high-risk countries more strictly. The UK government transposed MLD5 into UK law and, therefore, the UK anti-money laundering regime is currently broadly aligned with the EU. On December 7, 2022, the Council of the EU agreed its position on AML regulation through the Sixth EU Money Laundering Directive. The new rules will extend to, among other items, the entire crypto-asset sector, third-party intermediaries, persons trading in precious metals, precious stones and cultural goods. EU member states have until 2027 to transpose the Sixth EU Money Laundering Directive into national legislation. Shareholder Rights Directive. On May 17, 2017, the recast Shareholder Rights Directive (EU) 2017/828 was published (SRD II). Member states of the EU were required to bring into force the laws, regulations and administrative provisions necessary to comply with the Directive by June 10, 2019. SRD was designed to establish requirements in relation to the exercise of shareholder rights and, recognizing that shares are often held through complex chains of intermediaries, SRD II is designed to improve mechanisms for the identification of shareholders by companies, as well as improve the transmission of information along the chain of intermediaries to facilitate the exercise of shareholder rights. Non-EU intermediaries are required to comply with the requirements if they provide services with respect to shares of companies that have their registered office in the EU. SRD II has been incorporated into UK law and remains largely aligned with the EU. EU AI Act. The final text of the EU AI Act was published in the Official Journal of the European Union in July 2024 and entered into force in August 2024. Most of the EU AI Act’s substantive obligations will apply following a two-year implementation period, beginning in August 2026. The EU AI Act will have a significant impact on organizations that develop, deploy, or use AI systems both inside and outside the EU. Its application depends on the nature of the AI systems, the specific use case, and the role of the relevant actor (including whether the organization is acting as an AI provider or deployer). The EU AI Act adopts a risk-based regulatory framework. Certain AI systems used for specified purposes are prohibited outright. Other AI systems will be classified as high risk and subject to extensive pre- and post-market compliance obligations. The EU AI Act also contains dedicated provisions governing general-purpose AI models. AI systems posting lesser regulatory risk are generally subject only to limited transparency obligations, particularly where they interact with individuals. Administrative fines may be imposed for non-compliance and will vary based on the nature of the infringement and the size of the organization, including by reference to worldwide annual turnover. In addition to the above, the Bank’s and the Corporation’s subsidiary banks located outside the United States are subject to regulatory capital requirements in the jurisdictions in which they operate. As of December 31, 2025, each of our non-U.S. banking subsidiaries had capital ratios above their specified minimum requirements. Human Capital Management Our talent is our greatest asset and a core enabler of our strategy. Empowering our employees is central to our talent vision. Northern Trust employed approximately 23,800 full-time equivalent employees as of December 31, 2025. The regional breakout of our employee base is 42% Asia-Pacific, 41% North America, and 17% Europe, Middle East, and Africa. Our Board of Directors, including the Human Capital and Compensation Committee, oversees our human capital management strategies and practices. Northern Trust’s senior leadership provides regular human capital reporting and updates to the Board and its Committees to support this oversight. THE EMPLOYEE EXPERIENCE We elevate the employee experience from recruitment to retirement by investing in three core areas: professional development, rewarding performance, and strengthening workforce and operational resiliency. By fostering an environment where our employees thrive, we ensure that our workforce is fully engaged, motivated, celebrated, and equipped to drive our strategy. To support this effort, we continue to invest in our Human Capital Management System to help streamline manual processes, enable dynamic workforce analytics, and unlock new capabilities through a central manager workspace that helps managers make informed decisions and gain deeper insights into their teams. Our culture influences how we behave as an organization and unites us across businesses, geographies, and functions. Embedded in our culture are five behaviors to help us deliver on our strategic objectives: relentlessly client-centric, constantly managing risk, respectfully candid, intentionally inclusive, and always accountable. 12 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION PROFESSIONAL DEVELOPMENT From internships to executive development, our goal is to help our employees excel in their current roles and acquire new skills for future growth. Through Northern Trust University, we deliver comprehensive professional and functional training programs designed to equip our employees at every stage of their careers. Our performance management practices promote high performance across the company and are aligned to our strategy from goal setting to evaluation. Our managers play a pivotal role in advancing Northern Trust’s strategic goals through their teams. Northern Trust is intentionally investing in manager development through a comprehensive program that addresses both enterprise and individual priorities aligned to four areas of focus: Tools and Resources, Development, Engagement, and Talent Processes. We believe managers need not only the skills to lead effectively but also the right ecosystem to succeed. REWARDING PERFORMANCE Recognizing and rewarding the contributions of our employees is critical to their continued success. We offer a variety of awards and recognition programs tailored to different opportunities and achievements. Our Celebrate Great platform provides real-time, peer-to-peer recognition, reinforcing everyday moments of appreciation. Our in-person celebrations, such as the Quarter Century Club, which honors our long-tenured employees, and the Chairman’s Awards, which recognize outstanding individual and team achievements further reinforce a culture of performance and appreciation. We ensure our employees are compensated fairly by aligning their total compensation with market competitive pay for their roles, experience, and performance. Our total compensation includes base salaries, performance-linked incentive compensation, and comprehensive benefits designed to meet the needs of our employees and their families. WORKFORCE & OPERATIONAL RESILIENCY Our operating model is designed to reinforce the strength of our control framework, foster enterprise change management, provide robust governance and oversight, accelerate scalable growth, and leverage and develop our talent. To align with our strategy and position the Corporation for future success, new leaders are appointed from our internal talent pool as well as recruited externally to bring in new skills and expertise. Planning for leadership resiliency is a core component of our talent strategy. We identify and develop leaders with the necessary skills to execute business strategies and have documented succession plans for leadership resiliency roles. Our well-being programs support employees and help maintain an inclusive and resilient environment. Through these programs, we enhance employee engagement, reduce workforce risks, and build an adaptive, high-performing culture. In 2025, over 87% of our employees participated in our annual employee engagement survey which is a crucial tool for understanding and meeting the needs of our employees and driving engagement and retention. The survey results are reviewed by the Board and discussed in leadership meetings, reflecting our dedication to continuous improvement. Embedded in our engagement survey is an inclusion index which is a gauge to understand our employees’ sense of belonging and their ability to contribute to the success of the firm. We are committed to fostering an inclusive workplace that aligns with the Corporation’s mission, values, goals, business practices, and all applicable laws. Available Information Through the Corporation’s website at www.northerntrust.com, the Corporation makes available free of charge its Annual Report on Form 10-K, Quarterly Reports on Form 10-Q, Current Reports on Form 8-K, and all other reports and all amendments to those reports filed or furnished pursuant to Section 13(a) or 15(d) of the Securities Exchange Act of 1934, as amended (Exchange Act), as soon as reasonably practicable after it files such material with, or furnishes such material to, the SEC. The contents of the Corporation’s website, the website of the SEC at www.SEC.gov or any other website referenced herein are not a part of this Annual Report on Form 10-K. ITEM 1A - RISK FACTORS In the normal course of our business activities, we are exposed to a variety of risks. The following discussion sets forth the material risk factors that we have identified. Although we discuss these risk factors primarily in the context of their potential effects on our business, financial condition or results of operations, these risks could have other possible adverse consequences, including those described below. Additional risks beyond those discussed below, elsewhere in this Annual Report on Form 10-K or in other of our reports filed with, or furnished to, the SEC also could affect us adversely. Further, we cannot assure you that the risk factors herein or elsewhere in our other reports address all potential risks that we may face. For a discussion of the risks and uncertainties that may affect our future results, see “Forward-Looking Statements” included in Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations.” Summary Our business, financial condition or results of operations may be materially and adversely affected by various risk types and considerations, including market risks, operational risks, credit risks, liquidity risks, regulatory and legal risks, strategic risks, and other risks, including as a result of the following: 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 13 Market Risks • We are dependent on fee-based business for a majority of our revenues, which may be affected adversely by market volatility, a downturn in economic conditions, underperformance and/or negative trends in investment preferences. • Changes in interest rates can affect our earnings negatively. • Changes in the monetary, trade and other policies of various regulatory authorities, central banks, governments and international agencies may reduce our earnings and affect our growth prospects negatively. • Macroeconomic conditions and uncertainty in the global economy, including the financial stability of various regions or countries across the globe, including the risk of defaults on sovereign debt and related stresses on financial markets, could have a significant adverse effect on our earnings. • Declines in the value of securities held in our investment portfolio can affect us negatively. • Changes in a number of particular market conditions, including in foreign currency rates, cross-border investing activity and the demand for borrowing or lending securities, could affect our earnings negatively. Operational Risks • We are subject to many types of operational risks that could affect our earnings negatively. • We are highly dependent on information technology systems, and networks, many of which are operated by third parties, and any failures of, or disruptions to, our or such third parties’ technological systems or networks could materially and adversely affect our business. • Breaches of our security measures, including, but not limited to, those resulting from cyber-attacks, or other information security incidents may result in losses. • Errors, breakdowns in controls or other mistakes in the provision of services to clients or in carrying out transactions for our own account can subject us to liability, result in losses or have a negative effect on our earnings in other ways. • Our dependence on technology, and the need to update frequently our technology infrastructure, exposes us to risks that also can result in losses. • A failure or circumvention of our controls and procedures could have a material adverse effect on our business, financial condition and results of operations. • Failure of any of our third-party vendors (or their vendors) to perform can result in losses. • We are subject to certain risks inherent in operating globally which may affect our business adversely. • Failure to control our costs and expenses adequately could affect our earnings negatively. • Pandemics, natural disasters, global climate change, acts of terrorism, geopolitical tensions, and global conflicts may have a negative impact on our business and operations. Credit Risks • Failure to evaluate accurately the prospects for repayment when we extend credit or maintain an adequate allowance for credit losses can result in losses or the need to make additional provisions for credit losses, both of which reduce our earnings. • Market volatility and/or weak economic conditions can result in losses or the need for additional provisions for credit losses, both of which reduce our earnings. • The failure or perceived weakness of any of our significant counterparties could expose us to loss. Liquidity Risks • If we do not manage our liquidity effectively, our business could suffer. • If the Bank is unable to supply the Corporation with funds over time, the Corporation could be unable to meet its various obligations. • We may need to raise additional capital in the future, which may not be available to us or may only be available on unfavorable terms. • Any downgrades in our credit ratings, or an actual or perceived reduction in our financial strength, could affect our borrowing costs, capital costs and liquidity adversely. 14 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Regulatory and Legal Risks • Failure to comply with regulations and/or supervisory expectations can result in penalties and regulatory constraints that restrict our ability to grow or even conduct our business, or that reduce earnings. • We are subject to extensive and evolving government regulation and supervision that impacts our operations. Changes by the U.S. and other governments to laws, regulations and policies applicable to the financial services industry may heighten the challenges we face and make regulatory compliance more difficult and costly. • We are subject to complex and evolving laws, regulations, rules, standards and contractual obligations regarding data privacy and security, which could increase the cost of doing business, compliance risks and potential liability. • We may be impacted adversely by claims or litigation, including claims or litigation relating to our fiduciary responsibilities. • We may be impacted adversely by supervisory and/or regulatory enforcement matters. • We may fail to set aside adequate reserves for, or otherwise underestimate our liability relating to, pending and threatened claims, with a negative effect on our earnings. • The ultimate impact on us of regulatory divergence between the United Kingdom and the European Union remains uncertain. • If we fail to comply with legal standards, we could incur liability to our clients or lose clients, which could affect our earnings negatively. Strategic Risks • If we are not able to attract, retain and motivate personnel, our business could be negatively affected. • If we do not develop and execute strategic plans successfully, our growth may be impacted negatively. • We are subject to intense competition in all aspects of our businesses, which could have a negative effect on our ability to maintain satisfactory prices and grow our earnings. • Damage to our reputation could have a direct and negative effect on our ability to compete, grow and generate revenue. • We need to invest in innovation constantly, and the inability or failure to do so may affect our businesses and earnings negatively. • Failure to understand or appreciate fully the risks associated with development or delivery of new product and service offerings may affect our businesses and earnings negatively. • Our success with large, complex clients requires an understanding of the market and legal, regulatory and accounting standards in various jurisdictions. • We may take actions to maintain client satisfaction that result in losses or reduced earnings. • Our operations, businesses and clients could be materially adversely affected by the effects of climate change or concerns related thereto. Other Risks • The systems and models we employ to analyze, monitor and mitigate risks, as well as for other business purposes, are inherently limited, may not be effective in all cases and, in any case, cannot eliminate all risks that we face. • Changes in tax laws and interpretations and challenges to our tax positions may affect our earnings negatively. • Changes in accounting standards may be difficult to predict and could have a material impact on our consolidated financial statements. • Our ability to return capital to stockholders is subject to the discretion of our Board of Directors and may be limited by U.S. banking laws and regulations, applicable provisions of Delaware law, or our failure to pay full and timely dividends on our preferred stock and the terms of our outstanding debt. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 15 Market Risks We are dependent on fee-based business for a majority of our revenues, which may be affected adversely by market volatility, a downturn in economic conditions, underperformance and/or negative trends in investment preferences. Our principal operational focus is on fee-based business, which is distinct from commercial banking institutions that earn most of their revenues from loans and other traditional interest-generating products and services. Fees for many of our products and services are based on the market value of assets under management, custody or administration; the volume of transactions processed; securities lending volume and spreads; fees for other services rendered; and in certain businesses, fees calculated as a percentage of our clients’ earnings, all of which may be impacted negatively by market volatility, a downturn in economic conditions, underperformance and/or negative trends in investment preferences. For example, downturns in equity markets and decreases in the value of debt-related investments resulting from market disruption, illiquidity or other factors historically have reduced the valuations of the assets we manage or service for others, which generally impacted our earnings negatively. Further, although we do not hold, invest in, or custody cryptocurrency assets, the markets in which they trade are highly volatile and volatility in these markets may impact the markets for other assets that we hold, invest in, or custody, which could also impact our fees or financial condition. Market volatility and/or weak economic conditions also could affect wealth creation, investment preferences, trading activities, and savings patterns, which in turn could impact demand for certain products and services that we provide. Our earnings also could be affected by poor investment returns or changes in our clients’ investment preferences driven by factors beyond market volatility or weak economic conditions. Poor absolute or relative investment performance in funds or client accounts that we manage or in investment products that we design or provide could result in declines in the market values of portfolios that we manage and/or administer and could affect our ability to retain existing assets and to attract new clients or additional assets from existing clients. For example, from time to time in the past, outflows from certain of our products driven by relative investment performance or other factors adversely impacted our overall fees derived from assets that we manage. Broader changes in our clients’ investment preferences that lead to less investment in mutual funds or other collective funds, such as the shift in investment preference to lower fee products, could also impact our earnings negatively. Changes in interest rates could affect our earnings negatively. The direction and level of interest rates are important factors in our earnings. Interest rate changes could affect the interest earned on assets differently than interest paid on liabilities. In response to rising inflation, the Federal Reserve Board increased interest rates from historically low levels during 2022 and 2023. While a rising interest rate environment generally has had a positive effect on our net interest margin, in some circumstances, a rise in interest rates has affected us negatively, and could again in the future affect us negatively. For example, the rapid increases in interest rates during 2022 and 2023 adversely impacted the value of certain of our investment securities, and consequently, our capital, liquidity, and earnings. Additionally, higher interest rates historically have caused, and could in the future cause: market volatility and downturns in equity markets, resulting in a decrease in the valuations of the assets we manage or service for others, which generally impact our earnings negatively; our clients to transfer funds into investments with higher rates of return, resulting in decreased deposit levels and higher fund or account redemptions; our borrowers to experience difficulties in making higher interest payments, resulting in increased credit costs, provisions for loan and lease losses and charge-offs; reduced bond and fixed income fund liquidity, resulting in lower performance, yields and fees; or higher funding costs. Conversely, low-interest-rate environments generally result in a compressed net interest margin and also have a negative impact on our fees earned on certain of our products. For example, in the past we waived certain fees associated with money market funds due to the low level of short-term interest rates. Low net interest margins and fee waivers each negatively impact our earnings. Although we have policies and procedures in place to assess and mitigate potential impacts of interest rate risks, if our assumptions about any number of variables are incorrect, these policies and procedures to mitigate risk may be ineffective, which could impact earnings negatively. Please see “Market Risk” in the “Risk Management” section included in Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” for a more detailed discussion of interest rate and market risks we face. 16 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Changes in the monetary, trade and other policies of various regulatory authorities, central banks, governments and international agencies may reduce our earnings and affect our growth prospects negatively. The monetary, trade and other policies of U.S. and international governments, agencies and regulatory bodies have a significant impact on economic conditions and overall financial market performance. For example, the Federal Reserve Board regulates the supply of money and credit in the U.S. through quantitative tightening and/or easing, and its policies determine in large part the level of interest rates and our cost of funds for lending and investing, and play a role in contributing to or moderating levels of inflation, all of which meaningfully impact our earnings. Further, the Federal Reserve Board’s policies can affect our borrowers by increasing interest rates or making sources of funding less available, which may increase the risk that borrowers fail to repay their loans from us. Changes in monetary, trade and other governmental policies are beyond our control and can be difficult to predict, and we cannot determine the ultimate effect that any such changes would have upon our business, financial condition or results of operations. Macroeconomic conditions and uncertainty in the global economy, including the financial stability of various regions or countries across the globe, including the risk of defaults on sovereign debt and related stresses on financial markets, could have a significant adverse effect on our earnings. Risks and concerns about the financial stability of various regions or countries across the globe could have a detrimental impact on economic and market conditions in these or other markets across the world. Foreign market volatility and economic disruptions have affected, and may in the future affect, consumer confidence levels and spending, international trade policy, personal bankruptcy rates, levels of incurrence of and default on consumer debt, and home prices. Additionally, financial markets may be adversely affected by the liquidity or capital deficiencies (actual or perceived) of financial institutions and related industry and government actions, the outbreak of hostilities or political and governmental instability, terrorism, political or civil unrest, stricter immigration policies, public health epidemics or pandemics, sovereign debt downgrades or debt crises, or other geopolitical events. For example, developments related to the U.S. federal debt ceiling, including the possibility of a government shutdown, default by the U.S. government on its debt obligations, or related credit-rating downgrades, could have adverse effects on the broader economy, disrupt access to capital markets, and contribute to, or worsen, an economic recession. The cumulative effect of uncertain business conditions or economic challenges faced in various foreign markets, including fiscal or monetary concerns, economic downturns and the possibility of a recession in some jurisdictions, other economic factors (including changes in tariffs, foreign currency exchange rates, interest rates and changes to tax laws or the application or enforcement practices of such laws), or volatility or lack of confidence in the financial markets may adversely affect certain portions of our business, financial condition, and results of operations. Declines in the value of securities held in our investment portfolio could affect us negatively. Our investment securities portfolio represents a greater proportion, and our loan portfolio represents a smaller proportion, of our total consolidated assets in comparison to many other financial institutions. The value of securities available for sale and held to maturity within our investment portfolio, which is generally determined based upon market values available from third-party sources, have fluctuated, and may continue in the future to fluctuate, as a result of market volatility and economic or financial market conditions, including interest rates. Declines in the value of securities held in our investment portfolio negatively impact our levels of capital, liquidity, and, to the extent we realize losses, earnings. Although we have policies and procedures in place to assess and mitigate potential impacts of market risks, including hedging-related strategies, those policies and procedures are inherently limited because they cannot anticipate the existence or future development of currently unanticipated or unknown risks. Accordingly, market risks have, from time to time, negatively affected the value of securities held in our investment portfolio and in the future we could suffer additional adverse effects as a result of our failure to anticipate and manage these risks properly. Changes in a number of particular market conditions, including in foreign currency exchange rates, cross-border investing activity and the demand for borrowing or lending securities, could affect our earnings negatively. We provide foreign exchange services to our clients, primarily in connection with our Asset Servicing business. Foreign currency volatility influences our foreign exchange trading income as does the level of client activity. Foreign currency volatility and changes in client activity may result in reduced foreign exchange trading income. Fluctuations in exchange rates could raise the potential for losses resulting from foreign currency trading positions where aggregate obligations to purchase and sell a currency other than the U.S. dollar do not offset each other or offset each other in different time periods. We also are exposed to non-trading foreign currency risk as a result of our holdings of non-U.S. dollar denominated assets and liabilities, investments in non-U.S. subsidiaries, and future non-U.S. dollar denominated revenue and expense. We have policies and procedures in place to assess and mitigate potential impacts of foreign exchange risks, including hedging-related strategies. Any failure or circumvention of our procedures to mitigate risk could impact earnings negatively. Please see “Market Risk” in the “Risk Management” section included in Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” for a more detailed discussion of market risks we face. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 17 In addition, in past periods, reductions in the volatility of currency-trading markets, the level of cross-border investing activity, and the demand for borrowing securities or willingness to lend such securities have affected our earnings from activities such as foreign exchange trading and securities lending negatively. If these conditions occur again in the future, our earnings from these activities could be affected negatively. In certain of our businesses, such as securities lending, our fee is calculated as a percentage of our clients’ earnings, such that market and other factors that reduce our clients’ earnings from investments or trading activities also reduce our revenues. Operational Risks We are subject to many types of operational risks that could affect our earnings negatively. We regularly assess and monitor operational risk in our businesses. Despite our efforts to assess and monitor operational risk, our risk management program may not be effective in all cases. Factors that could impact our operations and expose us to risks varying in size, scale and scope, include: • failures of technological systems or networks or breaches of security measures, including, but not limited to, those resulting from computer viruses, cyber-attacks or other information security incidents; • human errors or omissions, including failures to comply with applicable laws or corporate policies and procedures; • theft, fraud or misappropriation of assets, whether arising from the intentional actions of internal personnel or external third parties; • defects or interruptions in computer or communications systems; • breakdowns in processes and internal controls; over-reliance on manual processes and controls, which are less scalable than automated processes and controls; • failures of the systems and facilities that support our operations; • failure of any third-party vendor to properly execute the processes on which Northern Trust relies; • unsuccessful or difficult implementation of computer systems upgrades; • defects in product design or delivery; • difficulty in accurately pricing assets, which can be aggravated by market volatility and illiquidity and lack of reliable pricing from third-party vendors; • negative developments in relationships with key counterparties, third-party vendors, employees or associates in our day-to-day operations; and • external events that are wholly or partially beyond our control, such as pandemics, geopolitical events, political or social unrest, natural disasters or acts of terrorism. While we have in place many controls and business continuity plans designed to address many of these factors, these plans may not operate successfully to mitigate these risks effectively. We also may fail to identify or fully understand the implications and risks associated with changes in the financial markets or our businesses—particularly as our geographic footprint, product pipeline and client needs and expectations evolve—and consequently fail to enhance our controls and business continuity plans to address those changes in an adequate or timely fashion. If our controls and business continuity plans do not address the factors noted above and operate to mitigate the associated risks successfully, such factors may have a negative impact on our business (including operational resilience), financial condition or results of operations. In addition, an important aspect of managing our operational risk is creating a risk culture in which all employees fully understand the inherent risk in our business and the importance of managing risk as it relates to their job functions. We continue to enhance our risk management program to support our risk culture, ensuring that it is sustainable and appropriate for our role as a major financial institution. Nonetheless, if we fail to provide the appropriate environment that sensitizes all of our employees to managing risk, our business could be impacted adversely. Please see “Other Risks” in this “Risk Factors” section for further description of risks associated with the systems and models we employ to analyze, monitor and mitigate risks. We are highly dependent on information technology systems and networks, many of which are operated by third parties, and any failures of, or disruptions to, our or such third parties’ technological systems or networks could materially and adversely affect our business. Our business is dependent on our and third parties’ information technology systems and networks. Any failure, interruption or breach in the security of any such systems or networks could severely disrupt our operations and could subject us to liability claims, harm our reputation, interrupt our operations, or otherwise adversely affect our business, financial condition or results of operations. Additionally, our computer, communications, data processing, networks, backup, business continuity or other operating, information or technology systems, including those that we outsource to providers, may fail to operate properly or become disabled, overloaded or damaged as a result of a number of factors, including events that are wholly or partially beyond our control, which could have a negative effect on our ability to conduct our business activities. 18 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION The third parties with which we do business also are susceptible to the foregoing risks (including regarding the third parties with which they are similarly interconnected or on which they otherwise rely), and our or their business operations and activities may therefore be affected adversely, perhaps materially, by failures, disruptions, terminations, software bugs or errors, natural disasters or malfeasance by, or attacks or constraints on, one or more financial, technology, infrastructure or government institutions or intermediaries with whom we or they are interconnected or conduct business. Our business interruption insurance may be inadequate to compensate us for all losses that may occur as a result of any system, network or operational failure or disruption. Breaches of our security measures, including, but not limited to, those resulting from cyber-attacks or other information security incidents, may result in losses. Our systems involve the storage, transmission and other processing of clients’ and our personal, proprietary, confidential and sensitive information, and security breaches, including cyber-attacks or other information security incidents, have previously exposed us and could in the future expose us to theft, loss, destruction, gathering, monitoring, dissemination, misappropriation, misuse, alteration, or unauthorized disclosure of or unauthorized access to this information. Despite our implementation of a variety of security measures, our computer systems, networks, and data, including clients’ or our personal, proprietary, confidential and sensitive information, could be subject to cyber-attacks or other information security incidents, such as, among other things, from physical and electronic break-ins or unauthorized tampering, theft, malware and computer virus attacks, ransomware attacks, social engineering attacks (including phishing and vishing attacks), credential stuffing, account takeovers, insider threats or denial-of-service attacks. Our security measures also may be breached due to the actions of outside parties, employee error, failure of our controls with respect to access to our systems, malfeasance or otherwise. Any failure, interruption or breach in the security of our systems could severely disrupt our operations and could subject us to liability claims, harm our reputation, interrupt our operations, or otherwise adversely affect our business, financial condition or results of operations. Data privacy and security risks for large financial institutions like us are significant in part because of the evolving proliferation of new technologies, the use of internet-based solutions, mobile devices, and cloud technologies to conduct financial transactions and the increased sophistication and rapidly evolving techniques of hackers, terrorists, organized crime and other external parties, including foreign state actors and state-sponsored actors, any of which may see their effectiveness enhanced by the use of AI. Data privacy and security risks also may derive from fraud or malice on the part of our employees or third parties, or may result from human error, software bugs or errors, server malfunctions, software or hardware failure or other technological failure. If we fail to continue to upgrade our technology infrastructure to ensure effective data privacy and security relative to the type, size and complexity of our operations, we could become more vulnerable to cyber-attacks and other information security incidents and, consequently, subject to significant regulatory penalties and reputational damage. Also, the trend in the past several years toward a hybrid work environment that includes a combination of in-office and remote work creates a broader attack surface for, and increases potential vulnerabilities from, cyber threats. While we generally conduct security assessments on third-party vendors, we cannot be certain that their information security protocols are sufficient to withstand a cyber-attack or other information security incident. Some of our vendors may store or have access to our data and may not have effective controls, processes, or practices to protect our information from loss, unauthorized disclosure, unauthorized use or misappropriation, cyber-attacks or other information security incidents. In addition, our clients often use personal devices, such as computers, smart phones and tablets, which are particularly vulnerable to loss and theft, as well as third parties with whom they share information used for authentication, to access our systems and networks and manage their accounts, which may heighten the risk of system failures, interruptions or security breaches. Moreover, the increased use of mobile and cloud technologies could heighten these and other operational risks. Reliance on mobile or cloud technology or any failure by mobile technology and cloud service providers to adequately safeguard their systems and networks and prevent cyber-attacks or other information security incidents could disrupt our operations or the operations of our or their service providers and result in misappropriation, corruption or loss of personal, confidential, proprietary, or other sensitive information or the inability to conduct ordinary business operations. In addition, there is a risk that encryption and other protective measures may be circumvented, particularly to the extent that new computing technologies increase the speed and computing power available. A vulnerability in our service providers’ software or systems, a failure of our service providers’ safeguards, policies or procedures, or a cyber-attack or other information security incident affecting any of these third parties could harm our business. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 19 In recent years, several financial services firms suffered successful cyber-attacks launched both domestically and from abroad, resulting in the disruption of services to clients, loss or misappropriation of sensitive or private information, and reputational harm. We and our clients have been, and expect to continue to be, subject to a wide variety of cyber-attacks and other similar threats, including computer viruses, ransomware and other malicious code, distributed denial-of-service attacks, and phishing and vishing attacks, and it is possible that we could suffer material losses resulting from a breach. Because the techniques used to obtain unauthorized access, disable or degrade service or sabotage systems and networks change frequently and often are not recognized until launched against a target, we may be unable to anticipate these techniques, to implement adequate preventative measures, or to address them until they are discovered. In addition, successful cyber-attacks may persist for an extended period of time before being detected. Because any investigation of an information security incident would be inherently unpredictable, the extent of a particular information security incident and the path of investigating the incident may not be immediately clear. It may take a significant amount of time before such an investigation can be completed and full and reliable information about the incident is known. While such an investigation is ongoing, we may not necessarily know the extent of the harm or how best to remediate it, certain errors or actions could be repeated or compounded before they are discovered and remediated, and communication to the public, regulators, clients and other stakeholders may be inaccurate, any or all of which could further increase the costs and consequences of an information security incident. We could be the subject of legal claims or proceedings related to information security incidents, including regulatory investigations and other legal actions, carrying the potential for damages, fines, sanctions or other penalties, injunctive relief requiring costly compliance measures and reputational damage. Further, the market perception of the effectiveness of our information security measures could be harmed, our reputation could suffer and we could lose clients in conjunction with security incidents, each of which could have a negative effect on our business, financial condition and results of operations. A breach of our security also may affect adversely our ability to effect transactions, service our clients, manage our exposure to risk or expand our business. An event that results in the loss of information also may require us to reconstruct lost data or reimburse clients for data and credit monitoring services, which could be costly and have a negative impact on our business and reputation. Although we maintain insurance coverage in the event of information theft, damage, or destruction from cyber-attacks or other information security incidents, there can be no assurance that liabilities or losses we may incur will be covered under such policies, that the amount of insurance will be adequate to cover such losses, that insurance will continue to be available to us on economically reasonable terms, or at all, or that our insurer will not deny coverage as to any future claim. Further, even if not directed at us, attacks on financial or other institutions important to the overall functioning of the financial system or on our counterparties could affect, directly or indirectly, aspects of our business. Errors, breakdowns in controls or other mistakes in the provision of services to clients or in carrying out transactions for our own account can subject us to liability, result in losses or have a negative effect on our earnings in other ways. In our asset servicing, investment management, fiduciary administration and other business activities, we effect or process transactions for clients and for ourselves that involve very large amounts of money. Failure to manage or mitigate operational risks properly can have adverse consequences, and increased volatility in the financial markets may increase the magnitude of resulting losses. Further, remote working and other modified business practices initiated in recent years, combined with the increasing sophistication and frequency of potential cyber-attacks and other information security incidents, have heightened our operational and execution risk. Given the high volume of transactions we process, errors that affect earnings may be repeated or compounded before they are discovered and corrected. 20 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Our dependence on technology, and the need to update frequently our technology infrastructure, exposes us to risks that also can result in losses. Our businesses depend on information technology infrastructure, both internal and external, to record and process, among other things, a large volume of increasingly complex transactions and other data, in many currencies, on a daily basis, across numerous and diverse markets and jurisdictions. Due to our dependence on technology and the important role it plays in our business operations, combined with the increasing sophistication and frequency of potential cyber-attacks and other information security incidents, we must constantly improve and update our information technology infrastructure. Upgrading, replacing, and modernizing these systems can require significant resources and often involves implementation, integration and security risks that could cause financial, reputational, and operational harm. In recent years, there has been an acceleration in the transition from traditional to digital financial services and heightened customer expectations in this area, and this transition may require us to invest greater resources in technological advancements. Failure to ensure adequate review and consideration of critical business and regulatory issues prior to and during the introduction and deployment of key technological systems or networks or failure to align operational capabilities adequately with evolving client commitments and expectations may have a negative impact on our results of operations. The failure to respond properly to, and invest in, changes and advancements in technology and/or to compete for and retain employees with the necessary technical skills and expertise could limit our ability to attract and retain clients, prevent us from offering products and services comparable to those offered by our competitors, inhibit our ability to meet regulatory requirements or otherwise have a material adverse effect on our operations. A failure or circumvention of our controls and procedures could have a material adverse effect on our business, financial condition and results of operations. We regularly review and update our internal controls, disclosure controls and procedures, and corporate governance policies and procedures. Any system of controls, however well designed and operated, is based in part on certain assumptions and can provide only reasonable, not absolute, assurances that the objectives of the system will be met. Any failure or circumvention of our controls and procedures or failure to comply with regulations related to controls and procedures could have a material adverse effect on our business, financial condition and results of operations. If we identify material weaknesses in our internal control over financial reporting or are otherwise required to restate our financial statements, we could be required to implement expensive and time-consuming remedial measures and could lose investor confidence in the accuracy and completeness of our financial reports. In addition, there are risks that individuals, either employees or contractors, consciously circumvent established control mechanisms by, for example, exceeding trading or investment management limitations, or committing fraud. Failure of any of our third-party vendors (or their vendors) to perform can result in losses. Third-party vendors provide key components of our business operations such as data processing, recording and monitoring transactions, online banking interfaces and services, and network access. Our use of third-party vendors exposes us to the risk that such vendors (or their vendors) may not comply with their servicing and other contractual obligations, including with respect to indemnification and information security, and to the risk that we may not satisfy applicable regulatory responsibilities regarding the management and oversight of third parties and outsourcing providers. While we have established risk management processes and continuity plans, any disruptions in service from a key vendor for any reason or poor performance of services have in the past and could in the future have a negative effect on our ability to deliver products and services to our clients and conduct our business. Replacing these third-party vendors or performing the tasks they perform for ourselves has in the past and could in the future create significant delay and expense. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 21 We are subject to certain risks inherent in operating globally which may affect our business adversely. In conducting our U.S. and non-U.S. business, we are subject to risks of loss and adverse economic impacts from various unfavorable political, economic, legal, public health, or other developments, including social or political instability, changes in governmental policies or policies of central banks, expropriation, nationalization, confiscation of assets, price controls, capital controls, exchange controls, unfavorable tax rate changes, tax court rulings and changes in laws and regulations. Less mature and often less regulated business and investment environments heighten these risks in various emerging markets. Our non-U.S. operations accounted for 30% of our revenue in 2025. Our non-U.S. businesses are subject to extensive regulation by various non-U.S. regulators, including governments, securities exchanges, central banks and other regulatory bodies in the jurisdictions in which those businesses operate. In many countries, the laws and regulations applicable to the financial services industry are uncertain and evolving and may be applied with extra scrutiny to foreign companies. Moreover, the regulatory and supervisory standards and expectations in one jurisdiction may not conform with standards or expectations in other jurisdictions. Even within a particular jurisdiction, the standards and expectations of multiple supervisory agencies exercising authority over our affairs may not be harmonized fully. Accordingly, it may be difficult for us to determine the exact requirements of local laws in every market or manage our relationships with multiple regulators in various jurisdictions. Our inability to remain in compliance with local laws in a particular market and manage our relationships with regulators could have an adverse effect not only on our businesses in that market but also on our reputation generally. The failure to mitigate properly such risks or the failure of our operating infrastructure to support such international activities could result in operational failures and regulatory fines or sanctions, which could affect our business and results of operations adversely. We actively strive to optimize our geographic footprint. This optimization may occur by establishing operations in lower-cost locations or by outsourcing to third-party vendors in various jurisdictions. These efforts expose us to the risk that we may not maintain service quality, control or effective management within these operations. In addition, we are exposed to the relevant macroeconomic, political, public health, and similar risks generally involved in doing business in those jurisdictions. The increased elements of risk that arise from conducting certain operating processes in some jurisdictions could lead to an increase in reputational risk. During periods of transition, greater operational risk and client concern exist with respect to maintaining a high level of service delivery. In addition, we are subject in our global operations to rules and regulations relating to corrupt and illegal payments, money laundering, and laws that prohibit us from doing business with certain individuals, groups and countries, such as the U.S. Foreign Corrupt Practices Act, the USA PATRIOT Act, the UK Bribery Act, and economic sanctions and embargo programs administered by the U.S. Office of Foreign Assets Control and similar agencies worldwide. While we have invested and continue to invest significant resources in training and in compliance monitoring, the geographic diversity of our operations, employees, clients and customers, as well as the vendors and other third parties with whom we deal, presents the risk that we may be found in violation of such rules, regulations, laws or programs and any such violation could subject us to significant penalties or affect our reputation adversely. Failure to control our costs and expenses adequately could affect our earnings negatively. Our success in controlling the costs and expenses of our business operations also impacts operating results. Through various parts of our business strategy, we aim to produce efficiencies in operations that help reduce and control costs and expenses, including the costs of losses associated with operating risks attributable to servicing and managing financial assets. Increased expenses have affected—and a failure to control our costs and expenses in the future, whether as a result of inflation or otherwise, could affect—our earnings negatively. 22 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Pandemics, natural disasters, global climate change, acts of terrorism, geopolitical tensions, and global conflicts may have a negative impact on our business and operations. Pandemics, natural disasters, global climate change, acts of terrorism, geopolitical tensions, global conflicts or other similar events, as well as government actions or other restrictions in connection with such events, have had in the past, or may in the future have, a negative impact on our business and operations. While we have in place business continuity plans, such events may still damage our facilities, disrupt or delay the normal operations of our business (including communications and technology), result in harm to or cause travel limitations on our employees, impose significant compliance costs with new financial and economic sanctions regimes, and have a similar impact on our clients, suppliers, third-party vendors and counterparties. For example, in some jurisdictions such as the Russian Federation, local market restrictions, laws, sanctions programs or government intervention inhibit our clients’ and our ability to access or transfer cash or securities held for clients through subcustodians and clearing agencies. When such client deposit liabilities are on our consolidated balance sheet, we maintain a corresponding amount of cash on deposit with the subcustodian or clearing agency, which increases our credit exposure to that entity and can accumulate over time based upon distributions on, or other activities related to, our clients’ assets. If the subcustodian or clearing agency were to become insolvent in circumstances not involving expropriation of assets or other sovereign risk events and/or factors or events beyond our reasonable control that excuse performance under force majeure or other contractual provisions, the risk of loss on such cash on deposit may potentially be incurred by us. As of December 31, 2025, we held cash that accumulates in relation to Russian securities with our subcustodian and/or clearing agencies for the benefit of certain clients in our Asset Servicing business which are subject to restrictions that inhibit our ability to access or transfer such deposits, and which amount is expected to increase significantly over time as long as the sanctions and other relevant restrictions remain in effect. The foregoing or similar events also could impact us negatively to the extent that they result in reduced capital markets activity, lower asset price levels, or disruptions in general economic activity in the U.S. or abroad, or in financial market settlement functions. In addition, these or similar events may impact economic growth negatively, which could have an adverse effect on our business and operations, and may have other adverse effects on us in ways that we are unable to predict. Please see “Strategic Risks” in this “Risk Factors” section for further description of risks associated with climate change. Credit Risks Failure to evaluate accurately the prospects for repayment when we extend credit or maintain an adequate allowance for credit losses can result in losses or the need to make additional provisions for credit losses, both of which reduce our earnings. We evaluate extensions of credit before we make them and provide for credit risks based on our assessment of the credit losses inherent in our loan and securities portfolio, including undrawn credit commitments. This process requires us to make difficult and complex judgments, including forecasts of economic conditions through the life of these credit exposures. Challenges associated with our credit risk assessments include identifying the proper factors to be used in assessments and accurately estimating the impacts of those factors. Allowances that prove to be inadequate may require us to realize increased provisions for credit losses or write down the value of certain assets on our balance sheet, which result in losses and/or increased provisions for credit losses and in turn would affect earnings negatively. Market volatility and/or weak economic conditions can result in losses or the need for additional provisions for credit losses, both of which reduce our earnings. Credit risk levels and our earnings can be affected by market volatility and/or weakness in the economy in general and in the particular locales in which we extend credit, a deterioration in credit quality, or a reduced demand for credit. Adverse changes in the financial performance or condition of our borrowers resulting from market volatility, elevated interest rates, and/or weakened economic conditions could impact the borrowers’ abilities to repay outstanding loans, which could in turn impact our financial condition and results of operations negatively. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 23 The failure or perceived weakness of any of our significant counterparties could expose us to loss. The financial markets are characterized by extensive interconnections among financial institutions, including banks, broker-dealers, collective investment funds and insurance companies. As a result of these interconnections, we and many of our clients have counterparty exposure to other financial institutions. This counterparty exposure presents risks to us and to our clients because the failure or perceived weakness of any of our counterparties has the potential to expose us to risk of loss. Instability in the financial markets, or in certain countries where these counterparties are domiciled, has resulted historically in some financial institutions becoming less creditworthy. During such periods of instability, we are exposed to increased counterparty risks, both as principal and in our capacity as agent for our clients. Changes in market perception of the financial strength of particular financial institutions can occur rapidly, are often based upon a variety of factors and can be difficult to predict. In addition, the criteria for and manner of governmental support of financial institutions and other economically important sectors remain uncertain. Further, the consolidation of financial services firms and the failures of other financial institutions has in the past increased, and may in the future increase, the concentration of our counterparty risk. These risks are heightened by the fact that our operating model relies on the use of unaffiliated sub-custodians to a greater degree than certain of our competitors that have banking operations in more jurisdictions than we do. We are not able to mitigate all of our and our clients’ counterparty credit risk. If a significant individual counterparty defaults on an obligation to us, we could incur financial losses that have a material and adverse effect on our business, financial condition and results of operations. Liquidity Risks If we do not manage our liquidity effectively, our business could suffer. Liquidity is essential for the operation of our business. Market conditions, unforeseen outflows of funds or other events could have a negative effect on our level or cost of funding, affecting our ongoing ability to accommodate liability maturities and deposit withdrawals, meet contractual obligations, and fund new business transactions at a reasonable cost and in a timely manner. If our access to stable and low-cost sources of funding, such as customer deposits, is reduced, we may need to use alternative funding, which could be more expensive or of limited availability. Further evolution in the regulatory requirements relating to liquidity and risk management also may impact us negatively. Additional regulations may impose more stringent liquidity requirements for large financial institutions, including the Corporation and the Bank. Given the overlap and complex interactions of these regulations with other regulatory changes, the full impact of the adopted and proposed regulations remains uncertain until their full implementation. In addition, a significant portion of our business involves providing certain services to large, complex clients, which, by their nature, require substantial liquidity. Our failure to manage successfully the liquidity and balance sheet issues attendant to this portion of our business may have a negative impact on our ability to meet client needs and grow. We also manage investment products that, while not obligations of ours, may be exposed to liquidity risks. These products, such as money market and other short-term investments provide clients a right to the return of cash or assets on limited notice. If clients demand a return of their cash or assets, particularly on limited notice, and these investment products do not have the liquidity to support those demands, we could be forced to sell investment securities held by these investment products at unfavorable prices potentially damaging our reputation with the investment community. For more information on regulations and other regulatory changes relating to liquidity, see “Supervision and Regulation—Liquidity Standards” in Item 1, “Business.” Any substantial, unexpected or prolonged changes in the level or cost of liquidity could affect our business adversely. If the Bank is unable to supply the Corporation with funds over time, the Corporation could be unable to meet its various obligations. The Corporation is a legal entity separate and distinct from the Bank and the Corporation’s other subsidiaries. The Corporation relies in large part on dividends paid to it by the Bank to meet its obligations and to pay dividends to stockholders of the Corporation. There are various legal limitations on the extent to which the Bank and the Corporation’s other subsidiaries can supply funds to the Corporation by dividend or otherwise. Dividend payments by the Bank to the Corporation in the future will require continued generation of earnings by the Bank and could require regulatory approval under certain circumstances. For more information on dividend restrictions, see “Supervision and Regulation—Payment of Dividends” in Item 1, “Business.” 24 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION We may need to raise additional capital in the future, which may not be available to us or may only be available on unfavorable terms. We may need to raise additional capital to provide sufficient resources to meet our business needs and commitments, to accommodate the transaction and cash management needs of our clients, to maintain our credit ratings in response to regulatory changes, including capital rules, or for other purposes. However, our ability to access the capital markets, if needed, will depend on a number of factors, including the state of the financial markets. Heightened interest rates, disruptions in financial markets, negative perceptions of our business or our financial strength, or other factors may impact our ability to raise additional capital, if needed, on terms favorable to us. For example, in the event of future turmoil in the banking industry or other idiosyncratic events, there is no guarantee that the U.S. government will invoke the systemic risk exception, create additional liquidity programs, or take any other action to stabilize the banking industry or provide liquidity. Any diminished ability to access short-term funding or capital markets to raise additional capital, if needed, could subject us to liability, restrict our ability to grow, require us to take actions that would affect our earnings negatively or otherwise affect our business and our ability to implement our business plan, capital plan and strategic goals adversely. Any downgrades in our credit ratings, or an actual or perceived reduction in our financial strength, could affect our borrowing costs, capital costs and liquidity adversely. Rating agencies publish credit ratings and outlooks on our creditworthiness and that of our obligations or securities, including Long-Term Debt, short-term borrowings, preferred stock and other securities. Our credit ratings are subject to ongoing review by the rating agencies and thus may change from time to time based on the agencies’ evaluation of a number of factors, including our financial strength, performance, prospects and operations as well as factors not under our control, such as rating-agency-specific criteria or frameworks for our industry or certain security types, which are subject to revision from time to time, and conditions affecting the financial services industry generally. Downgrades in our credit ratings may affect our borrowing costs, our capital costs and our ability to raise capital and, in turn, our liquidity adversely. A failure to maintain an acceptable credit rating also may preclude us from being competitive in certain products. Additionally, our counterparties, as well as our clients, rely on our financial strength and stability and evaluate the risks of doing business with us. If we experience diminished financial strength or stability, actual or perceived, a decline in our stock price or a reduced credit rating, our counterparties may be less willing to enter into transactions, secured or unsecured, with us, our clients may reduce or place limits on the level of services we provide them or seek other service providers, or our prospective clients may select other service providers, all of which may have other adverse effects on our business. The risk that we may be perceived as less creditworthy relative to other market participants is higher in a market environment in which the consolidation, and in some instances failure, of financial institutions, including major global financial institutions, could result in a smaller number of larger counterparties and competitors. If our counterparties perceive us to be a less viable counterparty, our ability to enter into financial transactions on terms acceptable to us or our clients, on our or our clients’ behalf, will be compromised materially. If our clients reduce their deposits with us or select other service providers for all or a portion of the services we provide to them, our revenues will decrease accordingly. Regulatory and Legal Risks Failure to comply with regulations and/or supervisory expectations could result in penalties and regulatory constraints that restrict our ability to grow or even conduct our business, or that reduce earnings. Virtually every aspect of our business in the United States and around the world is regulated by domestic and foreign governmental agencies that have broad supervisory powers and the ability to impose sanctions. These regulations cover a variety of matters, including prohibited activities, required capital levels, resolution planning, human trafficking and modern slavery, and data privacy and security. Some of these requirements are directed specifically at protecting depositors of the Bank, the U.S. DIF and the banking system as a whole. Regulatory violations or the failure to meet formal or informal commitments made to regulators could generate penalties, require corrective actions that increase costs of conducting business, result in limitations on our ability to conduct business, restrict our ability to expand or impact our reputation adversely. Failure to obtain necessary approvals from regulatory agencies, whether formal or based upon supervisory expectations, on a timely basis could affect proposed business opportunities and results of operations adversely. Similarly, changes in laws or failure to comply with new requirements or with future changes in laws or regulations could impact our results of operations and financial condition negatively. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 25 We are subject to extensive and evolving government regulation and supervision that impacts our operations. Changes by the U.S. and other governments to laws, regulations and policies applicable to the financial services industry could heighten the challenges we face and make regulatory compliance more difficult and costly. We operate in a highly regulated environment, and are subject to a comprehensive statutory and regulatory regime affecting all aspects of our business and operations, including oversight by governmental agencies both inside and outside the United States. Various regulatory bodies have demonstrated heightened scrutiny of financial institutions through many regulatory initiatives. These initiatives have increased compliance costs and regulatory risks and may lead to financial and reputational damage in the event of a compliance violation, even if the failure to comply was inadvertent or reflected a difference in interpretation. Although we have programs in place, including policies, training and various forms of monitoring, designed to ensure compliance with legislative and regulatory requirements, we cannot provide assurance that these programs and policies are or will be adequate to identify and manage internal and external compliance risks. For example, our business may be adversely impacted by actual or alleged misconduct by an employee or other negative outcomes caused by human error. In addition, changes to statutes, regulations or regulatory and supervisory policies or their interpretation or implementation and the continued heightening of regulatory and supervisory requirements could affect us in substantial and unpredictable ways. For example, governments and regulators could take actions that increase intervention in the normal operation of our businesses and the businesses of our competitors in the financial services industry, and these likely would involve additional legislative and regulatory requirements imposed on banks and other financial services companies. Any such actions could increase compliance costs and regulatory risks, lead to financial and reputational damage in the event of a violation, affect our ability to compete successfully or limit how we conduct our business, and also could impact the nature and level of competition in the industry in unpredictable ways. The full scope and impact of possible legislative or regulatory changes and the extent of regulatory activity is uncertain and difficult to predict. Congress and the presidential administration have introduced and may continue to introduce changes in the laws or policies applicable to us and the agencies that regulate us, including their interpretations of rules and guidelines. These changes may subject financial institutions like us to change in regulation, supervision and enforcement that are difficult to predict and uncertain for a period of time and may create the possibility of significant impacts on business activity in the United States and globally, including impacts relating to the trade policies (including tariffs) of the United States or other countries. Some of the regulations finalized in the prior administration that are applicable to financial institutions were modified, rescinded or withdrawn or are subject to reevaluation, creating further uncertainty. Moreover, political and policy goals of elected and appointed officials may change over time, which could impact the rulemaking, supervision, examination, and enforcement priorities of the federal banking agencies. It is possible the expected changed in law, regulation and policy do not occur or are reversed subsequently, or the regulatory measures that are ultimately enacted deliver significant competitive advantages to financial services that are structured differently or serve different markets than us. Further, the regulatory framework for AI and similar technologies, and automated decision making, is changing rapidly. It is possible that new laws and regulations will be adopted in the U.S. and in non-U.S. jurisdictions, or that existing laws and regulations may be interpreted, in ways that would affect the operation of our products and services and the way in which we use AI and similar technologies. For more information on regulations regarding AI, see “Supervision and Regulation” in Item 1, “Business.” The evolving regulatory and supervisory environment and uncertainty about the timing and scope of future laws, regulations and policies may contribute to decisions we may make to suspend, reduce or withdraw from existing businesses, activities or initiatives, which may result in potential lost revenue or significant restructuring or related costs or exposures. We also face the risk of becoming subject to new or more stringent requirements in connection with the introduction of new regulations or modification of existing regulations, which could require us to hold more capital or liquidity or have other adverse effects on our businesses or profitability. For more information on these proposals, see “Supervision and Regulation” in Item 1, “Business.” In addition, regulatory responses in connection with severe market downturns or unforeseen stress events could alter or disrupt our planned future strategies and actions. Adverse developments affecting the overall strength and soundness of other financial institutions, the financial services industry as a whole and the general economic climate and the U.S. Treasury market could have a negative impact on perceptions about the strength and soundness of our business even if we are not subject to the same adverse developments. For example, during 2023, the FDIC took control and was appointed receiver of Silicon Valley Bank, Signature Bank, and First Republic Bank. The failure of other banks and financial institutions and the measures taken by governments and regulators in response to these events could adversely impact our business, financial condition and results of operations. 26 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION We are subject to complex and evolving laws, regulations, rules, standards and contractual obligations regarding data privacy and security, which could increase the cost of doing business, compliance risks and potential liability. We are subject to complex and evolving laws, regulations, rules, standards and contractual obligations governing data privacy and security, which may differ and potentially conflict, in various jurisdictions, and any failure to comply with these laws, regulations, rules, standards and contractual obligations could expose us to liability and/or reputational damage. Regulators globally are introducing the potential for greater monetary fines on institutions that suffer from breaches leading to the loss, misappropriation or unauthorized access, use or disclosure of personal, confidential, proprietary or sensitive information. Most U.S. states, the EU and other non-U.S. jurisdictions also have adopted their own statutes and/or regulations concerning data privacy and security and notification of data breaches. These and other changes in laws or regulations associated with the enhanced protection of personal and other types of information could greatly increase compliance costs, the size of potential fines related to the protection of such information and reporting obligations in the case of cyber-attacks or other information security incidents. Compliance with these laws, regulations, rules and standards may require us to change and continuously update our policies, procedures and technology controls for information security, which could, among other things, make us more vulnerable to operational failures and to monetary penalties for breach of such laws, regulations, rules and standards. Legal developments in the EEA and the UK also have created complexity and uncertainty regarding processing and transfers of personal data from the EEA and the UK to the U.S. and other so-called third countries outside the EEA and the UK that have not been determined by the relevant data protection authorities to provide an adequate level of protection for privacy rights. Importantly, significant monetary fines have been imposed since the introduction of such stringent privacy laws in the EU and the UK and regulatory expectations of governance and accountability with respect to the protection of personal, proprietary, confidential and sensitive information continue to expand and evolve. For more information on regulations regarding data privacy and security, see “Supervision and Regulation” in Item 1, “Business.” Further, while we strive to publish and prominently display privacy notices and policies that are accurate, comprehensive, and compliant with applicable laws, regulations, rules and industry standards, we cannot ensure that our privacy policies and other statements regarding our practices will be considered sufficient to protect us from claims, proceedings, liability or adverse publicity relating to data privacy and security, considering the fast-evolving regulatory landscape. Although we endeavor to comply with our privacy policies, we may at times fail to do so or be alleged to have failed to do so. The publication of our privacy policies and other documentation that provide promises and assurances about data privacy and security can subject us to potential government or legal action if they are found to be deceptive, unfair, or misrepresentative of our actual practices. Any concerns about our data privacy and security practices, even if unfounded, could damage our reputation and adversely affect our business. Any failure or perceived failure by us to comply with our privacy policies, or applicable data privacy and security laws, regulations, rules, standards or contractual obligations, or any compromise of security that results in unauthorized access to, or unauthorized loss, destruction, use, modification, acquisition, disclosure, release or transfer of personal information, may result in requirements to modify or cease certain operations or practices, the expenditure of substantial costs, time and other resources, proceedings or actions against us, legal liability, governmental investigations, enforcement actions, claims, fines, judgments, awards, penalties, sanctions and costly litigation (including class actions). Any of the foregoing could harm our reputation, distract our management and technical personnel, increase our costs of doing business, adversely affect the demand for our products and services, and ultimately result in the imposition of liability, any of which could have a material adverse effect on our business, financial condition and results of operations. We may be impacted adversely by claims or litigation, including claims or litigation relating to our fiduciary responsibilities. Our businesses involve the risk that clients or others may sue us, claiming that we or third parties for whom they say we are responsible have failed to perform under a contract or otherwise failed to carry out a duty perceived to be owed to them. Our trust, custody and investment management businesses are particularly subject to this risk. This risk is heightened when we act as a fiduciary for our clients and may be further heightened during periods when credit, equity or other financial markets are deteriorating in value or are particularly volatile, or when clients or investors are experiencing losses. In addition, regulators, tax authorities and courts have increasingly sought to hold financial institutions liable for the misconduct of their clients where such regulators and courts have determined that the financial institution should have detected that the client was engaged in wrongdoing, even though the financial institution had no direct knowledge of the wrongdoing. Claims made or actions brought against us, whether founded or unfounded, may result in lawsuits, injunctions, settlements, damages, fines or penalties, which could have a material adverse effect on our financial condition or results of operations or require changes to our business. Even if we defend ourselves successfully, litigation often is costly and time-consuming and requires significant attention from our management, and public reports regarding claims made against us may cause damage to our reputation among existing and prospective clients or negatively impact the confidence of counterparties, rating agencies and stockholders, consequently affecting our earnings negatively. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 27 We may be impacted adversely by supervisory and/or regulatory enforcement matters. In the ordinary course of our business, we are subject to various governmental enforcement inquiries, supervisory examinations, investigations and subpoenas. These may be directed generally to participants in the businesses in which we are involved or may be directed specifically at us. In conjunction with both supervisory and enforcement matters, we may face limits on our ability to conduct or expand our business, be required to implement corrective actions that increase the costs of conducting business, or become subject to civil or criminal penalties or other remedial sanctions, any of which could result in reputational damage or otherwise have an adverse impact on us. The complexity of the federal and state regulatory, supervisory and enforcement regimes in the U.S., coupled with the global scope of our operations and the increased aggressiveness of the tax and regulatory environment worldwide, also means that a single event may give risk to a large number of overlapping investigations and regulatory proceedings, either by multiple agencies in the U.S. or by multiple regulators and other governmental entities or tax authorities in different jurisdictions. Responding to inquiries, investigations, and proceedings, regardless of the outcome of the matter, is time consuming and expensive and can divert the attention of our senior management from our business. The outcome of such proceedings may be difficult to predict or estimate until late in the proceedings, which may last a number of years. The number of regulatory and governmental investigations and proceedings, as well as the amount of penalties and fines sought, has remained elevated for many firms in the financial services industry. The Corporation and other financial institutions have become subject to increased scrutiny, more intense supervision and regulation, and a higher risk of enforcement action, which we expect to continue. For example, the failures in 2023 of Silicon Valley Bank, Signature Bank, and First Republic Bank and the regulatory investigations into these failures resulted in increased regulatory scrutiny and heightened supervisory expectations of these banks, which could require us to expend significant time and effort to implement enhanced compliance procedures or to incur other expenses. Any such heightened enforcement activity or new regulations could have a material adverse effect on our business, financial condition and results of operations. We may fail to set aside adequate reserves for, or otherwise underestimate our liability relating to, pending and threatened claims, with a negative effect on our earnings. We estimate our potential liability for pending and threatened claims and record reserves when appropriate pursuant to generally accepted accounting principles (GAAP). The process is inherently subject to risk, including the risks that a judge or jury could decide a case contrary to our evaluation of the law or the facts or that a court could change or modify existing law on a particular issue important to the case. Our earnings will be adversely affected if our reserves are not adequate. The ultimate impact on us of regulatory divergence between the United Kingdom and the European Union remains uncertain. While regulatory standards remain largely aligned following the UK’s withdrawal from the EU, commonly referred to as “Brexit,” it is possible that future divergence may occur between the UK and EU; therefore, the final impact remains uncertain. Since the UK’s withdrawal from the EU on December 31, 2020, the UK government has embarked on a program of significant regulatory reform. In particular, the Financial Services and Markets Act 2023 contains provisions that will eventually repeal all EU rules and regulations relating to financial services that were incorporated into UK law following Brexit. The UK government and the UK financial services regulatory authorities has been consulting on a number of measures that will replace the current EU-based rules and regulations with measures that reflect the particular needs of the UK market and policy objectives of the UK’s regulatory authorities. Consequently, over time it is likely that the rules and regulations relating to financial services will diverge, which may result in additional compliance costs for our UK and EU businesses. If we fail to comply with legal standards, we could incur liability to our clients or lose clients, which could affect our earnings negatively. Managing or servicing assets with reasonable prudence in accordance with the terms of governing documents and applicable laws is an important part of our business. Failure to comply with the terms of governing documents and applicable laws, manage adequately the risks or manage appropriately the differing interests often involved in the exercise of fiduciary responsibilities may subject us to liability or cause client dissatisfaction, which could impact negatively our earnings and growth. 28 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Strategic Risks If we are not able to attract, retain and motivate personnel, our business could be negatively affected. Our success depends, in large part, on our ability to attract new employees, retain and motivate our existing employees, and continue to compensate our employees competitively. Competition for the best employees in most activities in which we engage can be intense, and there can be no assurance that we will be successful in our efforts to recruit and retain necessary personnel. Factors that affect our ability to attract and retain talented employees include our compensation and benefits programs, our profitability and our reputation for rewarding and promoting qualified employees. Our ability to attract and retain key executives and other employees may be hindered as a result of existing and potential regulations applicable to incentive compensation and other aspects of our compensation programs. These laws and regulations may not apply in the same manner to all financial institutions and other companies, which therefore may subject us to more restrictions than other institutions and companies with which we compete for talent and may also hinder our ability to compete for talent with other industries. In addition, our current or future approach to in-office and remote work arrangements may not meet the needs or expectations of our current or prospective employees, may not be perceived as favorable as compared to the arrangements offered by competitors and may not be conducive to a collaborative working environment, which could adversely affect our ability to attract, retain and motivate employees. The unexpected loss of services of necessary personnel, both in businesses and corporate functions, could have a material adverse impact on our business because of their skills; knowledge of our markets, operations and clients; years of industry experience; and, in some cases, the difficulty of promptly finding qualified replacement personnel. Similarly, the loss of necessary employees, either individually or as a group, could affect our clients’ perception of our abilities adversely. A competitive labor market may also have the effect of heightening many of these risks. If we do not develop and execute strategic plans successfully, our growth may be impacted negatively. Our growth depends upon successful, consistent development and execution of our business strategies. A failure to develop and execute these strategies may impact growth negatively. A failure to grow organically or to integrate successfully an acquisition could have an adverse effect on our business. The challenges arising from the integration of an acquired business may include preserving valuable relationships with employees, clients, suppliers and other business partners, delivering enhanced products and services, as well as combining accounting, data processing and internal control systems. To the extent we enter into transactions to acquire complementary businesses and/or technologies, we may not achieve the expected benefits of such transactions, which could result in increased costs, lowered revenues, ineffective deployment of capital, regulatory concerns, exit costs or diminished competitive position or reputation. These risks may be increased if the acquired company operates internationally or in a geographic location where we do not already have significant business operations. Execution of our business strategies also may require certain regulatory approvals or consents, which may include approvals of the Federal Reserve Board and other domestic and non-U.S. regulatory authorities. These regulatory authorities have the ability to impose conditions on the activities or transactions contemplated by our business strategies which may impact negatively our ability to realize fully the expected benefits of certain opportunities. Further, acquisitions we announce may not be completed, or completed in the time frame anticipated, if we do not receive the required regulatory approvals, if regulatory approvals are significantly delayed or if other closing conditions are not satisfied. We are subject to intense competition in all aspects of our businesses, which could have a negative effect on our ability to maintain satisfactory prices and grow our earnings. We provide a broad range of financial products and services in highly competitive markets. We compete against large, well-capitalized, and geographically diverse companies that are capable of offering a wide array of financial products and services at competitive prices. In certain businesses, such as foreign exchange trading, electronic networks present a competitive challenge. Additionally, technological advances (such as the use of generative AI) and the growth of internet-based commerce have made it possible for other types of institutions to offer a variety of products and services competitive with certain areas of our business. Many of these nontraditional service providers have fewer regulatory constraints and some have lower cost structures. The same may be said for competitors based in non-U.S. jurisdictions, where legal and regulatory environments may be more favorable than those applicable to the Corporation and the Bank as U.S.-domiciled financial institutions. These competitive pressures may have a negative effect on our earnings and ability to grow. Pricing pressures, as a result of the willingness of competitors to offer comparable or improved products or services at a lower price, also may result in a reduction in the price we can charge for our products and services, which could have, and in some cases has had, a negative effect on our ability to maintain or increase our profitability. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 29 Damage to our reputation could have a direct and negative effect on our ability to compete, grow and generate revenue. Our ability to compete effectively, to attract and retain clients and employees, and to grow our business is dependent on maintaining our reputation. Damage to our reputation can therefore cause significant harm to our business and prospects, and can arise from various sources, including, among others, the failure or perceived failure to meet or appropriately address client expectations or fiduciary or other obligations; operational failures; legal and regulatory requirements; potential conflicts of interest; data privacy and security; social and sustainability concerns related to our business activities; or any other of the risks discussed in this Item 1A. Additionally, the actual or alleged actions of our affiliates, vendors or other third parties with which we do business, the actual or alleged actions or statements of our employees or adverse publicity could negatively impact our reputation and significantly harm our business prospects. Damage to our reputation for delivery of a high level of service could undermine the confidence of clients and prospects in our ability to serve them and accordingly affect our earnings negatively. Damage to our reputation also could affect the confidence of rating agencies, regulators, stockholders and other parties in a wide range of transactions that are important to our business and the performance of our common stock. Failure to maintain our reputation ultimately could have an adverse effect on our ability to manage our balance sheet or grow our business. Actions by the financial services industry generally or by other members of or individuals in the financial services industry also could impact our reputation negatively or lead to a general loss of confidence in, or impact market perception of, financial institutions that could negatively affect us. Our reputation may be significantly damaged by adverse publicity or negative information regarding the Corporation and the Bank, whether true or not, that may be published or broadcast by the media or posted on social media, non-mainstream news services or other parts of the internet. The proliferation of social media channels utilized by us and third parties, as well as the personal use of social media by our employees and others, may increase the risk of negative publicity, including through the rapid dissemination of inaccurate, misleading or false information, which could harm our reputation or have other negative consequences. Furthermore, ESG-related issues have been the subject of increased focus by regulators and stakeholders, including outside the U.S., and particularly in Europe. Any inability to meet applicable requirements or expectations, including those from conflicting U.S. and non-U.S. global expectations, may adversely impact our reputation. Additionally, various stakeholders have divergent views on ESG-related matters, including in the countries in which we operate and invest, as well as states and localities where we serve public sector clients. In the case of proxy voting, there is the inherent risk of misalignment between the proxy votes we cast on behalf of clients and all of our clients’ values and preferences. This divergence increases the risk that any action or lack thereof by us on such matters will be perceived negatively by some stakeholders and could adversely impact our reputation and business. We need to invest in innovation constantly, and the inability or failure to do so may affect our businesses and earnings negatively. Our success in the competitive environment in which we operate requires consistent investment of capital and human resources in innovation, particularly in light of the current “FinTech” environment, in which the financial services industry is undergoing rapid technological changes and financial institutions are investing significantly in evaluating new technologies, such as AI, machine learning, blockchain and other distributed ledger technologies, and developing potentially industry-changing new products, services and industry standards. Widespread adoption and rapid evolution of emerging technologies, including with respect to digital assets, such as stablecoins, as well as developments in the regulatory landscape relating to emerging technologies, such as the enactment and implementation of the Guiding and Establishing National Innovation for U.S. Stablecoins Act of 2025 (GENIUS ACT) and potential enactment of the Digital Asst Market Clarity Act of 2025 (CLARITY Act) or similar market structure legislation, may affect our clients’ needs and expectations for products and services. Our investment is directed at generating new products and services, and adapting existing products and services to the evolving standards and demands of the marketplace. Among other things, investing in innovation helps us maintain a mix of products and services that keeps pace with our competitors and achieve acceptable margins. Our investment also focuses on enhancing the delivery of our products and services in order to compete successfully for new clients or gain additional business from existing clients. Further, our competitors or other third parties may incorporate AI into their products more quickly or more successfully than us, which could impair our ability to compete effectively. Effectively identifying gaps or weaknesses in our product offerings is important to our success. Failure to keep pace with our competition in any of these areas could affect our business opportunities, growth and earnings adversely. There are substantial risks and uncertainties associated with innovation efforts, including an increased risk that new and emerging technologies may expose us to increased data privacy and security and other information technology threats. We must invest significant time and resources in developing and marketing new products and services, and expected timetables for the introduction and development of new products or services may not be achieved and price and profitability targets may not be met. Further, our revenues and costs may fluctuate because new products and services generally require start-up costs while corresponding revenues take time to develop or may not develop at all. 30 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Failure to understand or appreciate fully the risks associated with development or delivery of new product and service offerings may affect our businesses and earnings negatively. The success of our innovation efforts depends, in part, on the successful implementation of new product and service initiatives. Not only must we keep pace with competitors in the development of these new offerings, but we must accurately price them (as well as existing products) on a risk-adjusted basis and deliver them to clients effectively. Our identification of risks arising from new products and services, both in their design and implementation, and effective responses to those identified risks, including pricing, is key to the success of our efforts at innovation and investment in new product and service offerings. Our success with large, complex clients requires an understanding of the market and legal, regulatory and accounting standards in various jurisdictions. A significant portion of our business involves providing certain services to large, complex clients which requires an understanding of the market and legal, regulatory and accounting standards in various jurisdictions. Any failure to understand, address or comply with those standards appropriately could affect our growth prospects or affect our reputation negatively. We identify and manage risk through our business strategies and plans and our risk management practices and controls. If we fail to identify and manage significant risks successfully, we could incur financial loss, suffer damage to our reputation that could restrict our ability to grow or conduct business profitably, or become subject to regulatory penalties or constraints that could limit some of our activities or make them significantly more expensive. In addition, our businesses and the markets in which we operate are continuously evolving. We may fail to understand fully the implications of changes in legal or regulatory requirements, our businesses or the financial markets or fail to enhance our risk framework to address those changes in a timely fashion. If our risk framework is ineffective, either because it fails to keep pace with changes in the financial markets, legal and regulatory requirements, our businesses, our counterparties, clients or service providers or for other reasons, we could incur losses, suffer reputational damage or find ourselves out of compliance with applicable regulatory or contractual mandates or expectations. These risks are magnified as client requirements become more complex and as our increasingly global business requires end-to-end management of operational and other processes across multiple time zones and many inter-related products and services. We may take actions to maintain client satisfaction that could result in losses or reduced earnings. We may take action or incur expenses in order to maintain client satisfaction or preserve the usefulness of investments or investment vehicles we manage in light of changes in security ratings, liquidity or valuation issues or other developments, even though we are not required to do so by law or the terms of governing instruments. The risk that we will decide to take actions to maintain client satisfaction that result in losses or reduced earnings is greater in periods when credit or equity markets are deteriorating in value or are particularly volatile and liquidity in markets is disrupted. Our operations, businesses and clients could be materially adversely affected by the effects of climate change or concerns related thereto. Risks related to climate change could adversely impact our business, financial condition, and results of operations. The physical risks of climate change include harm to people and property. These arise from acute climate-related events, such as floods, hurricanes, heatwaves, droughts and wildfires. They also arise from chronic, longer-term shifts in climate patterns, such as rising average global temperatures, rising sea levels, and an increase in the frequency and severity of extreme weather events and natural disasters. Such developments could disrupt our operations and resilience capabilities, those of our clients, or third parties on which we rely. Further, physical risks from climate change could negatively impact our clients’ ability to pay outstanding loans, reduce the value of collateral, or result in insurance shortfalls. Climate change could also result in transition risk arising from changes in policy, regulations, technology, business practices or market preferences toward a lower-carbon economy. While these changes could create opportunities, they could also adversely impact us and our clients. These impacts could result in increased operational or compliance costs, higher energy expenses, additional taxes, and the devaluation of assets. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 31 Our reputation and business prospects may also be damaged if we do not, or are perceived not to, effectively prepare for the potential business and operational opportunities and risks associated with climate change. This includes the development and marketing of effective and competitive new products, objectively understanding how climate changes might impact the financial performance of direct and indirect client investments, and other services designed to address our clients’ climate related needs. We also face regulatory and liability risk associated with not meeting regulatory expectations on climate risks, greenwashing claims, a failure to execute on our public climate-related commitments, or through association with individuals, entities, industries or products connected to climate change issues. At the same time, financial institutions have also been subject to external scrutiny from stakeholders, including some regulatory agencies, government officials, and clients in relation to areas our business decisions, public commitments and affiliations associated with climate change. Due to the divergent views of stakeholders, there is an increased risk that any action, or lack thereof, by us concerning our response to climate change will be perceived negatively by some stakeholders. If we do not identify, quantify, and mitigate such risks successfully, we may experience financial losses, litigation, reputational harm, and losses of investor and stakeholder confidence. Methodologies and data used to conduct more robust climate-related risk analyses are being developed. Modeling capabilities across the industry to analyze climate-related risks and interconnections are improving but remain imperfect, for example, third-party exposures, emissions and other data are limited in availability and variable in quality. However, legislative and regulatory uncertainties along with inconsistencies and conflicts of policy across jurisdictions could result in higher costs and regulatory, compliance, credit, and reputational risks. Other Risks The systems and models we employ to analyze, monitor and mitigate risks, as well as for other business purposes, are inherently limited, may not be effective in all cases and, in any case, cannot eliminate all risks that we face. We use various systems and models, including AI-powered solutions, in analyzing and monitoring several risk categories, as well as for other business purposes. While we assess and improve these systems and models on an ongoing basis, there can be no assurance that they, along with other related controls, will effectively mitigate risk under all circumstances, or that they will adequately mitigate any risk or loss to us. As with any systems and models, there are inherent limitations because they involve techniques and judgments that cannot anticipate every economic and financial outcome in the markets in which we operate, nor can they anticipate the specifics and timing of such outcomes. Further, these systems and models may fail to quantify accurately the magnitude of the risks we face or they may not be effective against all types of risk, including risks that are unidentified or unanticipated. Our measurement methodologies rely on many assumptions and historical analyses and correlations. These assumptions may be incorrect, and the historical correlations on which we rely may not continue to be relevant. Models based on historical data sets might not be accurate predictors of future outcomes and their ability to appropriately predict future outcomes may degrade over time due to limited historical patterns, extreme or unanticipated market movements or customer behavior and liquidity, especially during severe market downturns or stress events (e.g., geopolitical events or pandemics). Consequently, the measurements that we make may not adequately capture or express the true risk profiles of our businesses or provide accurate data for other business purposes, each of which ultimately could have a negative impact on our business, financial condition and results of operations. Errors in the underlying model or model assumptions, or inadequate model assumptions, could result in unanticipated and adverse consequences, including material loss or noncompliance with regulatory requirements or expectations. In addition, the use of generative AI, a relatively new and emerging technology in the early stages of commercial use, exposes us to additional risks, such as damage to our reputation, competitive position, and business, legal and regulatory risks and additional costs. For example, generative AI has been known to produce false or “hallucinatory” inferences or output, and certain generative AI uses machine learning and predictive analytics, which can create inaccurate, incomplete, or misleading content, unintended biases, and other discriminatory or unexpected results, errors or inadequacies, any of which may not be easily detectable. Additionally, to the extent that we do not have sufficient rights to use the data or other material or content used in or produced by the AI tools used in our business, or if we experience cybersecurity incidents in connection with our use of AI, it could adversely affect our reputation and expose us to legal liability or regulatory risk, including with respect to third-party intellectual property, privacy, data protection and cybersecurity, publicity, contractual or other rights. Despite internal policies in place with respect to the usage of AI, if any of our employees or service providers were to use any third-party AI-powered software in connection with our business or the services they provide to us, it may lead to the inadvertent disclosure or incorporation of our confidential information into publicly available training set, which may impact our ability to realize the benefit of, or adequately maintain, protect and enforce our intellectual property or confidential information, harming our competitive position and business. We may not be able to sufficiently mitigate or detect any of the foregoing limitations or risks given our and other market participant’s lack of experience with using AI, the pace of technological change, and rapid adoption of AI by our business partners and competitors. As the utilization of AI becomes more prevalent, we anticipate that it will continue to present new or unanticipated ethical, reputational, technical, operational, legal, competitive, and regulatory issues, among others. As a result, the challenges presented with our use of AI could adversely affect our business, financial condition, and results of operations. 32 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Changes in tax laws and interpretations and challenges to our tax positions could affect our earnings negatively. Both U.S. and non-U.S. governments and tax authorities, including states and municipalities, from time to time issue new, or modify existing, tax laws and regulations. These authorities may also issue new, or modify existing, interpretations of those laws and regulations. These new laws, regulations or interpretations, and our actions taken in response to, or reliance upon, such changes in the tax laws may impact our tax position in a manner that affects our earnings negatively. We are sometimes subject to challenges from U.S. and non-U.S. tax authorities, including states and municipalities, regarding the amount of taxes due. These challenges may result in adjustments to the timing or amount of taxable income, deductions, tax credits, or the allocation of income among tax jurisdictions, all of which could require a greater provision for taxes or otherwise affect earnings negatively. Changes in accounting standards may be difficult to predict and could have a material impact on our consolidated financial statements. New accounting standards, changes to existing accounting standards, or changes in the interpretation of existing accounting standards by the Financial Accounting Standards Board, the SEC or bank regulatory agencies, or otherwise reflected in GAAP, potentially could have a material impact on our financial condition and results of operations. These changes are difficult to predict and in some cases we could be required to apply a new or revised standard retroactively, resulting in the revised treatment of certain transactions or activities, or even the restatement of consolidated financial statements for prior periods. Our ability to return capital to stockholders is subject to the discretion of our Board of Directors and may be limited by U.S. banking laws and regulations, applicable provisions of Delaware law, or our failure to pay full and timely dividends on our preferred stock and the terms of our outstanding debt. Holders of our common stock are entitled to receive only such dividends and other distributions of capital as our Board of Directors may declare out of funds legally available for such payments under Delaware law. Although we have declared cash dividends on shares of our common stock historically, we are not required to do so. In addition to the approval of our Board of Directors, our ability to take certain actions, including our ability to pay dividends, repurchase stock, and make other capital distributions, is dependent upon, among other things, their payment being made in accordance with the capital plan rules and capital adequacy standards of the Federal Reserve Board. A significant source of funds for the Corporation is dividends from the Bank. As a result, our ability to pay dividends on the Corporation’s common stock will depend in large part on the ability of the Bank to pay dividends to the Corporation. There are various legal limitations on the extent to which the Bank and the Corporation’s other subsidiaries can supply funds to the Corporation by dividend or otherwise. Dividend payments by the Bank to the Corporation in the future will require continued generation of earnings by the Bank and could require regulatory approval under certain circumstances. If the Bank is unable to pay dividends to the Corporation in the future, our ability to pay dividends on the Corporation’s common stock would be affected adversely. Our ability to declare or pay dividends on, or purchase, redeem or otherwise acquire, shares of our common stock or any of our shares that rank junior to our preferred stock as to the payment of dividends and/or the distribution of any assets on any liquidation, dissolution or winding-up of the Corporation also generally will be prohibited in the event that we do not declare and pay in full dividends on our Series D Non-Cumulative Perpetual Preferred Stock (Series D Preferred Stock) and Series E Non-Cumulative Perpetual Preferred Stock (Series E Preferred Stock). Further, in the future if we default on certain of our outstanding debt we will be prohibited from making dividend payments on our common stock until such payments have been brought current. Any reduction or elimination of our common stock dividend, or even our failure to maintain the common stock dividend level in a manner comparable to our competitors, likely would have a negative effect on the market price of our common stock. For more information on dividend restrictions, see “Supervision and Regulation—Payment of Dividends” and “Supervision and Regulation—Capital Planning and Stress Testing” in Item 1, “Business.” Additionally, on July 22, 2025, we announced that our Board authorized a new share repurchase program to repurchase up to $2.5 billion of the Corporation’s outstanding common stock with a capacity of $1.9 billion of repurchase authority remaining under the plan as of December 31, 2025. The Corporation retains the ability to repurchase when circumstances warrant and applicable regulation permits. The Inflation Reduction Act of 2022, imposes a 1% excise tax on the fair market value of stock repurchases after December 31, 2022. There have been proposals to significantly increase this excise tax rate. Any such material increases may impact our future strategies relating to the return of capital to our shareholders, including the size of, or execution against, current or future repurchase programs related to shares of our common stock. ITEM 1B – UNRESOLVED STAFF COMMENTS None. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 33 ITEM 1C – CYBERSECURITY Risk management and strategy Northern Trust understands the importance of managing cyber risk to ensure the safety and security of our data, network and systems. Our cybersecurity program is regularly assessed by Audit Services through various assurance activities, with the results reported to the Audit Committee of the Board of Directors (Audit Committee), and by Technology and Cyber Risk Management, with the results reported to the Risk Committee of the Board of Directors (Risk Committee). Northern Trust also operates a global security operations center for threat identification and response. The center aggregates security threat information from systems and platforms across the business and alerts the organization in accordance with its documented Cybersecurity Incident Response Plan. In addition to the cybersecurity controls managed and monitored within the organization, Northern Trust uses external third-party security teams on a regular basis to assess the effectiveness of our cybersecurity program and controls. These teams perform program maturity assessments, penetration tests, security assessments, and reviews of Northern Trust’s vulnerability to cyber-attacks. Annually, certain elements of the cybersecurity program are subject to an audit by an independent consultant, as well as an assessment by a separate, independent third party, the results of which, including opportunities identified for improvement and related remediation plans, are reviewed with the Board. Our cybersecurity program is also examined regularly by the Corporation’s prudential and conduct regulators within the scope of their jurisdiction. The Cybersecurity Incident Response Plan was developed to respond to cybersecurity incidents. A cybersecurity incident starts with malicious intent and can include, but is not limited to, disruptions of service, denials-of-service, compromises of information systems, data exfiltration or data corruption. The plan provides a streamlined approach that includes enterprise-level response plans. The plans can be invoked rapidly to address matters that raise enterprise concern and to communicate impact, actions, and status to senior management, including the Chief Information Security Officer (CISO), and appropriate stakeholders, including escalation to appropriate Board-level governance committees, and is reviewed, tested, and updated regularly. Northern Trust’s disclosure procedures and controls also address cybersecurity incidents and include elements to ensure an analysis of potential disclosure obligations arising from any such incidents. Northern Trust maintains compliance programs to address the applicability of restrictions on securities trading while in possession of material, nonpublic information, including instances in which such information may relate to cybersecurity incidents. Northern Trust also maintains a comprehensive Information and Cyber Security Training and Awareness practice providing baseline and targeted education and awareness for employees and contractors. This program includes at least one required annual online training class for all employees and contractors, supplemental refresher training throughout the year, targeted training based on roles and risk levels, multiple simulated phishing and vishing attacks with associated training, the distribution of regular cybersecurity awareness materials, and the designation of individuals as Information Security and Privacy champions within the businesses. Governance The Risk Committee, which reports regularly to the Board, oversees management’s actions to identify, assess, mitigate and remediate material issues related to technology and cyber risk as part of our enterprise risk management program and processes. The Technology and Operations Committee, chaired by the former chief information officer and chief transformation officer of a Fortune 50 company, assists the Board in discharging its oversight duties with respect to the technology and operations of the Corporation and receives regular reporting from management on the Corporation’s practices, management, and functioning of risks related to technology and cybersecurity, including the identification, assessment, measurement, treatment and control, monitoring, and reporting of such risks. The Risk Committee, Technology and Operations Committee, and the Board are regularly briefed on the organization’s cybersecurity posture by senior management, including the Chief Executive Officer, Chief Information Officer (CIO), Chief Risk Officer, Chief Technology Risk Officer (CTRO), and the CISO. Senior technology leaders, including the CIO, CISO, and CTRO, each have more than 20 years of experience in their respective areas of expertise - including leading technology teams in the case of the CIO, leading cyber-security teams including in the areas of risk management and information security in the case of the CISO, and oversight of cybersecurity and risk management, in the case of the CTRO. The CISO reports to the CIO and is responsible for identifying, managing, and, if necessary, remediating cyber risk to ensure the protection of our data, network, and systems. The primary management-level committees responsible for assessing and managing cyber risk are the Information Technology Oversight Committee, chaired by the CIO, and the Information Technology Risk Committee, chaired by the Chief Technology Risk Officer. 34 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Effective management of risks related to the confidentiality, integrity, and availability of information is crucial in an environment of increasing cybersecurity threats and requires a structured approach to establish and communicate expectations and required practices. Northern Trust’s technology and cyber risk management program provides the overall structure for identifying, assessing and managing the respective risks in a sustainable manner supported by an organizational structure that reflects support from executive management and includes risk committees comprised of members from across the business. The program is supported by the Cyber and Technology Risk Management Policy approved by the Risk Committee. The Cyber and Technology Risk Management Policy is informed by the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) and Cyber Risk Institute (CRI) Profile and provide a comprehensive overview of technology and cyber risk management governance activities pertaining to the confidentiality of information, integrity of systems, data and processes, and the availability of business functions that may be adversely impacted. These governance processes, internal controls, and risk management practices, which are part of our enterprise risk management program and processes, are designed to keep risk at levels appropriate to Northern Trust’s overall cyber risk appetite and the inherent risk in the markets in which Northern Trust operates. Northern Trust employees are responsible for promoting cybersecurity best practices as well as adhering to applicable policies and standards to safeguard data and business systems. In cases where Northern Trust relies on third-party vendors to perform services, controls are routinely reviewed for alignment with industry standards and their ability to protect information in accordance with Northern Trust’s Third-Party Risk Management Program. To date, Northern Trust has not identified any cybersecurity threats or incidents that have materially affected or are reasonably likely to materially affect our business strategy, results of operations, or financial condition. However, despite our efforts, we cannot eliminate all risks from cybersecurity threats or incidents, or provide assurances that we have not experienced an undetected cybersecurity threat or incident. For more information about these risks, see “Breaches of our security measures, including, but not limited to, those resulting from cyber-attacks or other information security incidents, may result in losses,” in Item 1A, “Risk Factors.” ITEM 2 – PROPERTIES The executive offices of the Corporation and the Bank are located at 50 South La Salle Street in Chicago. This Bank-owned building is occupied by various divisions of Northern Trust’s businesses. Adjacent to this building is one office building in which the Bank leases space principally for the asset management business. Financial services are provided by the Bank and other subsidiaries of the Corporation through a network of offices in 24 U.S. states and Washington, D.C., and across 22 locations in Canada, Europe, the Middle East and the Asia-Pacific region. The majority of those offices are leased. The Bank’s other primary U.S. operations are located in five facilities: a leased facility at 333 South Wabash Avenue in Chicago; a leased facility in Tempe, Arizona; and one leased and two Bank-owned supplementary operations/data center buildings located in the western suburbs of Chicago. A majority of the Bank’s London-based staff is located at a leased facility at Canary Wharf in London. Additional support and operations activity originates from two facilities in India, one facility in Ireland, and one facility in the Philippines, all of which are leased. The Bank and the Corporation’s other subsidiaries operate from various other facilities in North America, Europe, the Asia-Pacific region, and the Middle East, most of which are leased. The Corporation believes that its owned and leased facilities are suitable and adequate for its business needs. The Corporation continues to evaluate its owned and leased facilities and may determine from time to time that certain of its facilities are no longer necessary for its operations. There is no assurance that the Corporation will be able to dispose of any excess facilities or that it will not incur costs in connection with such dispositions, which could be material to its operating results in a given period. For additional information relating to properties and lease commitments, refer to Note 8, “Buildings and Equipment” and Note 9, “Lease Commitments,” included under Item 8, “Financial Statements and Supplementary Data,” and which information is incorporated herein by reference. ITEM 3 – LEGAL PROCEEDINGS The information presented under the caption “Legal Proceedings” in Note 24, “Commitments and Contingent Liabilities,” included under Item 8, “Financial Statements and Supplementary Data,” is incorporated herein by reference. ITEM 4 – MINE SAFETY DISCLOSURES Not applicable. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 35 SUPPLEMENTAL ITEM – INFORMATION ABOUT OUR EXECUTIVE OFFICERS The following sets forth certain information with regard to each executive officer of the Corporation. Michael G. O’Grady - Mr. O’Grady, age 60, joined Northern Trust in 2011 and has served as Chairman of the Board since 2019, as Chief Executive Officer since 2018 and as President since 2017. Prior to that, Mr. O’Grady served as Executive Vice President and President of Corporate & Institutional Services from 2014 to 2016 and as Chief Financial Officer from 2011 to 2014. Before joining Northern Trust, Mr. O’Grady served as a Managing Director in Bank of America Merrill Lynch’s Investment Banking Group. Clive A. Bellows - Mr. Bellows, age 62, joined Northern Trust in 2011 and has served as Executive Vice President and President of Europe, Middle East and Africa since June 2024 and Co-President of Asset Servicing since January 2026. Prior to that, Mr. Bellows served as Head of Global Fund Services for Europe, Middle East and Africa from 2016 to June 2024. Before joining Northern Trust in 2011, Mr. Bellows served as Managing Director and Head of Relationship Management for Asset Managers and Hedge Funds at JPMorgan Chase & Co. from 2006 to 2011 and as Executive Director and Global Head of Client Service, Global Markets at Deutsche Bank AG from 2004 to 2006. Mr. Bellows also served as Head of Relationship Management for the Global Fund Services and Investment Manager Liaison Group at Northern Trust from 1997 to 2003. Peter B. Cherecwich - Mr. Cherecwich, age 61, joined Northern Trust in 2007 and has served as Executive Vice President and Chief Operating Officer since October 2024. Prior to that, Mr. Cherecwich served as President of Asset Servicing since 2017, as President of Global Fund Services from 2010 to 2017 and as Chief Operating Officer of Corporate & Institutional Services from 2008 to 2014. From 2007 to 2008, he served as Head of Institutional Strategy & Product Development. Before joining Northern Trust, Mr. Cherecwich served in several executive and operational roles at State Street Corporation. David W. Fox, Jr. - Mr. Fox, age 66, joined Northern Trust in 2012 and has served as Executive Vice President and Chief Financial Officer since October 2024. Prior to that, Mr. Fox served as Executive Vice President and President of the Global Family & Private Investment Offices Group from July 2015 through September 2024 and as Executive Vice President and Head of the Americas, Corporate & Institutional Services from May 2012 to June 2015. Before joining Northern Trust, Mr. Fox served in various leadership roles with J.P. Morgan. Guy Gibson - Mr. Gibson, age 51, joined Northern Trust in 2016 and has served as Executive Vice President and Head of Institutional Banking and Global Markets since 2022 and Co-President of Asset Servicing since January 2026. Before joining Northern Trust in 2016, Mr. Gibson co-founded Aviate Global LLP in 2007, which Northern Trust acquired in 2016. Aengus Hallinan - Mr. Hallinan, age 53, joined Northern Trust in 2025 and has served as Executive Vice President and Chief Risk Officer since May 2025. Prior to joining Northern Trust, Mr. Hallinan spent over five years at Bank of New York Mellon Corporation, where he served as Managing Director from 2020 to May 2025; as Chief Risk Officer, Securities Services & Digital, AI Hub & Growth Venture from 2023 to May 2025; as Chief Operational Risk Officer & Chief Risk Officer for Securities Services & Digital from 2021 to 2024; as Chief Technology Risk Officer from 2020 to 2021; and as Head of Enterprise-Wide Risk Management from 2020 to 2021. Michael Hunstad, Ph.D. - Mr. Hunstad, age 48, joined Northern Trust in 2012 and has served as President of Asset Management since September 2025. Prior to that, Mr. Hunstad served as Global Co-Chief Investment Officer from June 2025 to September 2025, and as Deputy Chief Investment Officer from July 2023 to June 2025. Before joining Northern Trust, Mr. Hunstad was head of research at Breakwater Capital and head of quantitative asset allocation at Allstate Investments. John P. Landers - Mr. Landers, age 53, joined Northern Trust in 2003 and has served as Executive Vice President since December 2024 and as Controller since December 2023. Mr. Landers previously served as Chief Productivity Officer from January 2023 to December 2023 and as Chief Financial Officer of Asset Servicing from September 2015 to January 2023. Susan C. Levy - Ms. Levy, age 68, joined Northern Trust in 2014 and has served as Executive Vice President and General Counsel since that time. Ms. Levy also previously served as Corporate Secretary from 2018 to 2021. Before joining Northern Trust, Ms. Levy served as Managing Partner of the law firm Jenner & Block from 2008 to 2014, where she was a partner since 1990. 36 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION Thomas A. South - Mr. South, age 56, joined Northern Trust in 1999 and has served as Executive Vice President and Chief Information Officer since 2018. Prior to that, Mr. South served as Chief Business Architect from 2014 to 2018 and as Chief Operating Officer of Operations & Technology from 2013 to 2014. Alexandria Taylor - Ms. Taylor, age 43, joined Northern Trust in 2022 and has served as Executive Vice President and Chief Administrative Officer since October 2024. Prior to that, she served as Chief Human Resources Officer. Before joining Northern Trust, Ms. Taylor spent nearly two decades at Bank of America based in New York City where she was the head of Human Resources for corporate, institutional and wealth management businesses. She also oversaw the team responsible for Global Human Resources regulatory relations. Prior to that, Ms. Taylor held positions of increasing responsibility and complexity at Bank of America. Jason J. Tyler - Mr. Tyler, age 54, joined Northern Trust in 2011 and has served as Executive Vice President and President of Wealth Management since October 2024. Prior to that, Mr. Tyler served as Chief Financial Officer since 2020, as Chief Financial Officer of Wealth Management from 2018 to 2019, as Global Head of Asset Management’s Institutional Group from 2014 to 2018, and as Global Head of Strategy from 2011 to 2014. Before joining Northern Trust, Mr. Tyler served in certain executive and operational roles at Ariel Investments and Bank One/American National Bank. All officers are appointed annually by the Board of Directors. Officers continue to hold office until their successors are duly elected or until their death, resignation or removal by the Board. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 37 PART II ITEM 5 – MARKET FOR REGISTRANT’S COMMON EQUITY, RELATED STOCKHOLDER MATTERS AND ISSUER PURCHASES OF EQUITY SECURITIES Our common stock is listed on The NASDAQ Stock Market LLC under the symbol “NTRS.” There were 1,356 stockholders of record as of January 31, 2026. The following table shows certain information relating to the Corporation’s purchases of common stock through our share repurchase program for the three months ended December 31, 2025. TABLE 2: REPURCHASES OF COMMON STOCK IN THE FOURTH QUARTER OF 2025 (Dollars in millions except per share amounts; shares in thousands) TOTAL NUMBER OF SHARES PURCHASED AVERAGE PRICE PAID PER SHARE TOTAL NUMBER OF SHARES PURCHASED AS PART OF A PUBLICLY ANNOUNCED PLAN MAXIMUM APPROXIMATE DOLLAR VALUE OF SHARES THAT MAY YET BE PURCHASED UNDER THE PUBLICLY ANNOUNCED PLAN PERIOD: October 1 - 31, 2025 1,080 $ 128.44 1,080 $ 2,159 November 1 - 30, 2025 1,216 128.01 1,216 2,004 December 1 - 31, 2025 541 136.40 541 1,930 Total (Fourth Quarter) 2,837 $ 129.78 2,837 $ 1,930 On July 22, 2025 the Corporation’s Board of Directors approved a new common stock repurchase authorization (the “New Stock Repurchase Authorization”) authorizing, but not obligating, the repurchase of up to $2.5 billion (the “Maximum Program Amount”) of the Corporation’s outstanding shares of common stock from time to time. The New Stock Repurchase Authorization replaces the previously announced authorization approved on October 19, 2021. All funds expected in connection with repurchases after the New Stock Repurchase Authorization shall count against the Maximum Program Amount. The New Stock Repurchase Authorization has no expiration date. Thus the Corporation retains the ability to repurchase when circumstances warrant and applicable regulation permits. The Corporation expects to acquire shares of common stock under the New Stock Repurchase Authorization through open market transactions, block trades, privately negotiated transactions, and/or pursuant to any trading plan that may be adopted by the Corporation’s management in accordance with federal securities laws from time to time, including pursuant to Rule 10b5-1 of the Exchange Act. The timing and actual number of shares of common stock repurchased will depend on a variety of factors including price, corporate and regulatory requirements, market conditions, and other corporate liquidity requirements and priorities. The New Stock Repurchase Authorization does not obligate the Corporation to acquire a specific dollar amount or number of shares and may be modified, suspended or discontinued at any time. For more information, please refer to Note 13, “Stockholders’ Equity,” provided in Item 8, “Financial Statements and Supplementary Data.” 38 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION COMPARISON OF FIVE-YEAR CUMULATIVE TOTAL RETURN The following graph compares the cumulative total stockholder return on the Corporation’s common stock to the cumulative total return of the S&P 500 Index and the KBW Bank Index for the five fiscal years ended December 31, 2025. The cumulative total stockholder return assumes the investment of $100 in the Corporation’s common stock and in each index on December 31, 2020 and assumes reinvestment of dividends. The KBW Bank Index is a modified-capitalization-weighted index made up of 24 of the largest banking companies in the United States. The Corporation is included in the S&P 500 Index and the KBW Bank Index. Total Return Assumes $100 Invested on December 31, 2020 with Reinvestment of Dividends DECEMBER 31, 2020 2021 2022 2023 2024 2025 Northern Trust $ 100 $ 132 $ 100 $ 99 $ 125 $ 176 S&P 500 Index 100 129 105 133 166 196 KBW Bank Index 100 138 109 108 148 196 ITEM 6 – [RESERVED] 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 39 MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS ITEM 7 – MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS The following is management’s discussion and analysis of the financial condition and results of operations (MD&A) of Northern Trust Corporation (Corporation) for the year ended December 31, 2025. The following should be read in conjunction with the consolidated financial statements and related footnotes included in this report. Investors also should read the section titled “Forward-Looking Statements.” BUSINESS OVERVIEW The Corporation is a leading provider of wealth management, asset servicing, asset management and banking solutions to corporations, institutions, families and individuals. The Corporation focuses on managing and servicing client assets through its two client-focused reporting segments: Asset Servicing and Wealth Management. Asset management and related services are provided to Asset Servicing and Wealth Management clients primarily by the Asset Management business. The Corporation conducts business through various U.S. and non-U.S. subsidiaries, including The Northern Trust Company (the Bank). The Corporation was formed as a holding company for the Bank in 1971. The Corporation has a global presence with offices in 24 U.S. states and Washington, D.C., and across 22 locations in Canada, Europe, the Middle East and the Asia-Pacific region. Except where the context requires otherwise, the terms “Northern Trust,” “we,” “us,” “our,” “its,” or similar terms refers to the Corporation and its subsidiaries on a consolidated basis. FINANCIAL OVERVIEW TABLE 3: FINANCIAL HIGHLIGHTS FOR THE YEAR ENDED DECEMBER 31, CHANGE (1) ($ In Millions) 2025 2024 2023 2025 / 2024 2024 / 2023 Noninterest Income (2) $ 5,675.4 $ 6,113.3 $ 4,791.5 (7) % 28 % Net Interest Income 2,411.0 2,177.1 1,982.0 11 10 Total Revenue $ 8,086.4 $ 8,290.4 $ 6,773.5 (2) % 22 % Provision for Credit Losses (7.5) (3.0) 24.5 N/M N/M Noninterest Expense (3) 5,754.4 5,633.9 5,284.2 2 7 Income before Income Taxes $ 2,339.5 $ 2,659.5 $ 1,464.8 (12) % 82 % Provision for Income Taxes 602.6 628.4 357.5 (4) 76 Net Income $ 1,736.9 $ 2,031.1 $ 1,107.3 (14) % 83 % Preferred Stock Dividends 41.8 41.8 41.8 — — Net Income Applicable to Common Stock $ 1,695.1 $ 1,989.3 $ 1,065.5 (15) % 87 % PER COMMON SHARE Net Income – Basic $ 8.78 $ 9.80 $ 5.09 (10) % 93 % – Diluted 8.74 9.77 5.08 (11) 92 Cash Dividends Declared Per Common Share 3.10 3.00 3.00 3 — Carrying Value – End of Period (EOP) 64.79 60.74 53.69 7 13 Market Price – EOP 136.59 102.50 84.38 33 21 SELECTED RATIOS AND METRICS Return on Average Common Equity 14.4 % 17.4 % 10.0 % Dividend Payout Ratio 35.5 30.7 59.1 Average Stockholders’ Equity to Average Assets 8.3 8.4 8.1 (1) Percentage calculations are based on actual balances rather than the rounded amounts presented in the table above. (2) 2025 Noninterest Income includes a $19.2 million expense related to mark-to-market activity associated with existing Visa Class B swap agreements. 2024 Noninterest Income includes an $878.4 million net gain related to Northern Trust's participation in a Visa Exchange Offer, a $189.3 million loss on AFS debt securities sold in conjunction with a repositioning of the portfolio, a $68.1 million gain related to the sale of an equity investment, a $12.8 million expense of mark-to-market activity associated with existing Visa Class B swap agreements, a $7.6 million charge for investment impairments, and a $6.5 million loss recognized as a result of a securities repositioning related to the supplemental pension plan. 2023 Noninterest Income includes a $169.5 million loss on AFS debt securities sold in conjunction with a repositioning of the portfolio. (3) 2025 Noninterest Expense includes a $58.8 million severance-related charge and a $15.9 million release of the Federal Deposit Insurance Corporation (FDIC) special assessment reserve, including a $9.5 million released during the fourth quarter. 2024 Noninterest Expense includes an $85.2 million severance-related charge, a $70.0 million charitable contribution, a $16.4 million charge for software accelerations and dispositions, a $14.7 million expense related to the FDIC special assessment, and a $10.6 million expense related to a legal settlement. 2023 Noninterest Expense includes an $84.6 million expense related to the FDIC special assessment, a $38.7 million severance-related charge, a $25.6 million charge related to the write-off of an investment in a client capability, and a $12.8 million occupancy charge. N/M - Not meaningful 40 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS CONSOLIDATED RESULTS OF OPERATIONS The following information summarizes our consolidated results of operations for 2025 compared to 2024. For a discussion related to the consolidated results of operations for 2024 compared to 2023, refer to Part II, Item 7, “Management’s Discussion and Analysis of Financial Condition and Results of Operations,” in our Annual Report on Form 10-K for the year ended December 31, 2024 (2024 Form 10-K), which was filed with the United States Securities and Exchange Commission on February 24, 2025. Revenue Northern Trust generates the majority of its revenue from Noninterest Income that primarily consists of Trust, Investment and Other Servicing Fees. Net Interest Income comprises the remainder of revenue and consists of Interest Income generated by earning assets, net of Interest Expense on deposits and borrowed funds. TABLE 4: REVENUE FOR THE YEAR ENDED DECEMBER 31, CHANGE ($ In Millions) 2025 2024 2023 2025 / 2024 2024 / 2023 Noninterest Income Trust, Investment and Other Servicing Fees $ 5,017.8 $ 4,727.8 $ 4,361.8 6 % 8 % Foreign Exchange Trading Income 240.8 231.2 203.9 4 13 Treasury Management Fees 38.7 35.7 31.6 8 13 Security Commissions and Trading Income 170.4 150.5 135.0 13 11 Other Operating Income 207.7 1,157.4 228.7 (82) N/M Investment Security Gains (Losses), net — (189.3) (169.5) N/M 12 Total Noninterest Income $ 5,675.4 $ 6,113.3 $ 4,791.5 (7) % 28 % Net Interest Income (1) 2,411.0 2,177.1 1,982.0 11 10 Total Revenue $ 8,086.4 $ 8,290.4 $ 6,773.5 (2) % 22 % (1) Net Interest Income stated on a GAAP basis. Net Interest Income on an FTE basis includes FTE adjustments of $28.5 million, $31.8 million, and $57.5 million for 2025, 2024, and 2023, respectively. A reconciliation of total consolidated revenue, Net Interest Income and net interest margin on a GAAP basis to revenue, Net Interest Income and net interest margin on an FTE basis, respectively, (each of which is a non-GAAP financial measure) is provided in “Supplemental Information—Reconciliation to Fully Taxable Equivalent” within this “Management’s Discussion and Analysis of Financial Condition and Results of Operations” section. Revenue in 2025 decreased $204.0 million from 2024, reflecting: • Trust, Investment and Other Servicing Fees increased $290.0 million in 2025 compared to 2024, primarily due to favorable markets, net new business, and favorable currency movements. • Noninterest Income, excluding Trust, Investment and Other Servicing Fees, decreased $727.9 million in 2025 compared to 2024 primarily due to lower Other Operating Income driven by a $896.7 million gain related to Northern Trust’s participation in a Visa Exchange Offer in the prior year, partially offset by lower losses recognized on investment securities and higher Security Commissions and Trading Income. • Net Interest Income on a fully taxable equivalent (FTE) basis in 2025 of $2.4 billion increased $230.6 million, or 10%, from $2.2 billion in 2024, primarily due to higher deposits and lower funding costs, partially offset by lower yields on interest-earning assets. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 41 MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS Trust, Investment and Other Servicing Fees Trust, Investment and Other Servicing Fees are based primarily on the market value of assets held in custody, managed or serviced; the volume of transactions; number of accounts; securities lending volume and spreads; and fees for other services rendered. Certain market value calculations on which fees are based are performed on a monthly or quarterly basis in arrears. The components of Trust, Investment and Other Servicing Fees are provided in the following table. TABLE 5: TRUST, INVESTMENT AND OTHER SERVICING FEES FOR THE YEAR ENDED DECEMBER 31, CHANGE ($ In Millions) 2025 2024 2023 2025 / 2024 2024 / 2023 Asset Servicing Trust, Investment and Other Servicing Fees Custody and Fund Administration $ 1,901.6 $ 1,792.6 $ 1,689.5 6 % 6 % Investment Management 635.2 595.2 528.1 7 13 Securities Lending 82.4 72.3 83.0 14 (13) Other 181.0 172.7 161.3 5 7 Total Asset Servicing Trust, Investment and Other Servicing Fees $ 2,800.2 $ 2,632.8 $ 2,461.9 6 % 7 % Wealth Management Trust, Investment and Other Servicing Fees Central $ 786.0 $ 740.9 $ 673.8 6 % 10 % East 575.5 539.7 491.5 7 10 West 439.0 418.9 378.0 5 11 Global Family Office 417.1 395.5 356.6 5 11 Total Wealth Management Trust, Investment and Other Servicing Fees $ 2,217.6 $ 2,095.0 $ 1,899.9 6 % 10 % Total Consolidated Trust, Investment and Other Servicing Fees $ 5,017.8 $ 4,727.8 $ 4,361.8 6 % 8 % Asset Servicing Asset Servicing Trust, Investment and Other Servicing Fees are primarily attributable to services related to custody, fund administration, investment management, and securities lending. Custody and Fund Administration fees are driven primarily by values of client AUC/A, transaction volumes and the number of accounts. The asset values used to calculate these fees vary depending on the individual fee arrangements negotiated with each client. Custody fees related to asset values are client specific and are priced based on month-end market values, quarter-end market values, or the average of month-end market values for the quarter. The fund administration fees that are asset-value-related are priced using month-end, quarter-end, or average daily balances. Investment Management fees are based generally on market values of client AUM throughout the period. Typically, the asset values used to calculate fee revenue are based on a one-month or one-quarter lag. Securities Lending revenue is affected by market values; the demand for securities to be lent, which drives volumes; and the interest rate spread earned on the investment of cash deposited by investment firms as collateral for securities they have borrowed. The Other fee category in Asset Servicing includes products such as investment risk and analytical services, benefit payments, and other services. Revenue from these products is based generally on the volume of services provided or a fixed fee. Custody and Fund Administration fees increased in 2025 from 2024 primarily due to favorable markets, net new business, and favorable currency movements. Investment Management fees increased in 2025 from 2024 primarily due to favorable markets and net new business. Securities Lending increased in 2025 from 2024 primarily due to higher volumes. Other fees increased from the prior-year, primarily due to net new business. The following tables provide a breakdown of the Asset Servicing assets under custody and assets under management. TABLE 6: ASSET SERVICING ASSETS UNDER CUSTODY DECEMBER 31, CHANGE ($ In Billions) 2025 2024 2023 2025 / 2024 2024 / 2023 North America $ 8,066.1 $ 7,286.9 $ 6,373.4 11 % 14 % Europe, Middle East, and Africa 4,330.0 3,855.0 3,493.9 12 10 Asia Pacific 1,000.9 895.9 847.3 12 6 Securities Lending 207.8 176.2 167.4 18 5 Total Assets Under Custody $ 13,604.8 $ 12,214.0 $ 10,882.0 11 % 12 % 42 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS TABLE 7: ASSET SERVICING ASSETS UNDER MANAGEMENT DECEMBER 31, CHANGE ($ In Billions) 2025 2024 2023 2025 / 2024 2024 / 2023 North America $ 844.6 $ 788.8 $ 681.3 7 % 16 % Europe, Middle East, and Africa 195.0 154.1 141.8 27 9 Asia Pacific 48.6 40.6 41.5 20 (2) Securities Lending (1) 207.8 176.2 167.4 18 5 Total Assets Under Management $ 1,296.0 $ 1,159.7 $ 1,032.0 12 % 12 % (1) Cash and other assets deposited by investment firms as collateral for securities borrowed from custody clients are managed by Northern Trust and are included in assets under custody and assets under management Wealth Management Wealth Management fee income is calculated primarily based on market values of client AUC/A and AUM and is impacted by both one-month and one-quarter lagged asset values. Fee income in the regions increased in 2025 from 2024 primarily due to favorable markets. Global Family Office fee income increased in 2025 from 2024 primarily due to favorable markets and asset inflows. The following tables provide a summary of Wealth Management assets under custody and assets under management. TABLE 8: WEALTH MANAGEMENT ASSETS UNDER CUSTODY DECEMBER 31, CHANGE ($ In Billions) 2025 2024 2023 2025 / 2024 2024 / 2023 Global Family Office $ 908.2 $ 802.4 $ 728.0 13 % 10 % Central 171.5 150.2 120.7 14 24 East 125.6 111.0 119.8 13 (7) West 79.0 71.6 66.0 10 9 Total Assets Under Custody $ 1,284.3 $ 1,135.2 $ 1,034.5 13 % 10 % TABLE 9: WEALTH MANAGEMENT ASSETS UNDER MANAGEMENT DECEMBER 31, CHANGE ($ In Billions) 2025 2024 2023 2025 / 2024 2024 / 2023 Global Family Office $ 194.4 $ 170.2 $ 144.3 14 % 18 % Central 149.1 132.7 102.8 12 29 East 98.1 87.6 100.0 12 (12) West 65.6 60.2 55.4 9 9 Total Assets Under Management $ 507.2 $ 450.7 $ 402.5 13 % 12 % The Wealth Management regions shown are comprised of the following: Central includes Illinois, Michigan, Minnesota, Missouri, Ohio and Wisconsin; East includes Connecticut, Delaware, Florida, Georgia, Massachusetts, New York, Pennsylvania, and Washington, D.C.; West includes Arizona, California, Colorado, Nevada, Texas, and Washington. Global Family Office provides customized services, including but not limited to investment consulting, global custody, fiduciary, private banking, family office consulting, and technology solutions, to meet the complex financial and reporting needs of family offices across the globe. Asset Management Asset Management, through the Corporation’s various subsidiaries, supports the Asset Servicing and Wealth Management reporting segments by providing a broad range of asset management and related services and other products to clients around the world. Investment solutions are delivered through separately managed accounts, bank common and collective funds, registered investment companies, exchange traded funds, non-U.S. collective investment funds, and unregistered private investment funds. Asset Management’s capabilities include active and passive equity; active and passive fixed income; cash management; multi-asset and alternative asset classes (such as private equity and hedge funds of funds); and multi-manager advisory services and products. Asset Management’s activities also include overlay services and other risk management services. Asset Management operates internationally through subsidiaries and distribution arrangements and its revenue and expense are allocated fully to Asset Servicing and Wealth Management. 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 43 MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS Market Indices The following tables present selected market indices and the percentage changes year-over-year to provide context regarding equity and fixed income market impacts on the Corporation’s results. TABLE 10: EQUITY MARKET INDICES DAILY AVERAGES YEAR-END 2025 2024 CHANGE 2025 2024 CHANGE S&P 500 6,216 5,426 15 % 6,846 5,882 16 % MSCI EAFE (U.S. dollars) 2,609 2,326 12 2,893 2,262 28 MSCI EAFE (local currency) 1,625 1,496 9 1,774 1,510 18 TABLE 11: FIXED INCOME MARKET INDICES AS OF DECEMBER 31, 2025 2024 CHANGE Barclays Capital U.S. Aggregate Bond Index 2,349 2,189 7 % Barclays Capital Global Aggregate Bond Index 501 463 8 Client Assets Northern Trust, in the normal course of business, holds assets under custody/administration and management in a fiduciary or agency capacity for its clients. In accordance with GAAP, these assets are not assets of Northern Trust and are not included in its consolidated balance sheets. AUC/A and AUM are a driver of our Trust, Investment and Other Servicing Fees. For the purposes of disclosing AUC/A, to the extent that both custody and administration services are provided, the value of the assets is included only once in this amount. At December 31, 2025, total AUC/A and AUC increased from the prior year primarily driven by favorable markets. AUM at the end of 2025 increased from 2024, primarily reflecting favorable markets and net asset inflows. The following table presents AUC/A by reporting segment. TABLE 12: ASSETS UNDER CUSTODY/ADMINISTRATION BY REPORTING SEGMENT DECEMBER 31, CHANGE ($ In Billions) 2025 2024 2023 2025 /2024 2024 /2023 Asset Servicing $ 17,418.4 $ 15,640.1 $ 14,362.6 11 % 9 % Wealth Management 1,297.7 1,147.9 1,042.3 13 10 Total Assets Under Custody/Administration $ 18,716.1 $ 16,788.0 $ 15,404.9 11 % 9 % The following table presents assets under custody, a component of AUC/A, by reporting segment. TABLE 13: ASSETS UNDER CUSTODY BY REPORTING SEGMENT DECEMBER 31, CHANGE ($ In Billions) 2025 2024 2023 2025 /2024 2024 / 2023 Asset Servicing $ 13,604.8 $ 12,214.0 $ 10,882.0 11 % 12 % Wealth Management 1,284.3 1,135.2 1,034.5 13 10 Total Assets Under Custody $ 14,889.1 $ 13,349.2 $ 11,916.5 12 % 12 % The following table presents the investment allocation of Northern Trust’s custodied assets by reporting segment. TABLE 14: ALLOCATION OF ASSETS UNDER CUSTODY DECEMBER 31, 2025 2024 2023 AS WM TOTAL AS WM TOTAL AS WM TOTAL Equities 48 % 60 % 50 % 49 % 62 % 50 % 46 % 60 % 47 % Fixed Income Securities 31 13 30 31 13 29 33 13 31 Cash and Other Assets 19 27 19 19 25 20 19 27 21 Securities Lending Collateral 2 — 1 1 — 1 2 — 1 44 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS The following table presents Northern Trust’s assets under custody by investment type. TABLE 15: ASSETS UNDER CUSTODY BY INVESTMENT TYPE DECEMBER 31, CHANGE ($ In Billions) 2025 2024 2023 2025 / 2024 2024 / 2023 Equities $ 7,359.0 $ 6,639.0 $ 5,652.5 11 % 17 % Fixed Income Securities 4,435.8 3,884.9 3,737.1 14 4 Cash and Other Assets 2,886.0 2,648.8 2,359.5 9 12 Securities Lending Collateral 208.3 176.5 167.4 18 5 Total Assets Under Custody $ 14,889.1 $ 13,349.2 $ 11,916.5 12 % 12 % The following table presents Northern Trust’s AUM by reporting segment. TABLE 16: ASSETS UNDER MANAGEMENT BY REPORTING SEGMENT DECEMBER 31, CHANGE ($ In Billions) 2025 2024 2023 2025 / 2024 2024 / 2023 Asset Servicing $ 1,296.0 $ 1,159.7 $ 1,032.0 12 % 12 % Wealth Management 507.2 450.7 402.5 13 12 Total Assets Under Management $ 1,803.2 $ 1,610.4 $ 1,434.5 12 % 12 % The following table presents the investment allocation of Northern Trust’s AUM by reporting segment. TABLE 17: ASSETS UNDER MANAGEMENT BY INVESTMENT TYPE DECEMBER 31, 2025 2024 2023 AS WM TOTAL AS WM TOTAL AS WM TOTAL Equities 55 % 60 % 56 % 56 % 57 % 56 % 55 % 55 % 55 % Fixed Income Securities 11 19 13 11 20 14 11 22 14 Cash and Other Assets 18 21 19 18 23 19 18 23 19 Securities Lending Collateral 16 — 12 15 — 11 16 — 12 The following table presents consolidated AUM as of December 31, 2025, 2024 and 2023 by investment type. TABLE 18: CONSOLIDATED ASSETS UNDER MANAGEMENT BY INVESTMENT TYPE DECEMBER 31, CHANGE ($ In Billions) 2025 2024 2023 2025 / 2024 2024 / 2023 Equities $ 1,015.6 $ 903.1 $ 785.5 12 % 15 % Fixed Income Securities 235.2 217.5 203.4 8 7 Cash and Other Assets 344.1 313.3 278.2 10 13 Securities Lending Collateral 208.3 176.5 167.4 18 5 Total Assets Under Management $ 1,803.2 $ 1,610.4 $ 1,434.5 12 % 12 % The following table presents activity in consolidated AUM by product during the years ended December 31, 2025, 2024 and 2023. TABLE 19: ACTIVITY IN CONSOLIDATED ASSETS UNDER MANAGEMENT BY PRODUCT (In Billions) 2025 2024 2023 Balance as of January 1 $ 1,610.4 $ 1,434.5 $ 1,249.5 Net Inflows (Outflows) by Product Equities (57.9) (13.7) (18.1) Fixed Income 2.4 9.3 0.7 Cash and Other Assets 40.7 54.9 42.2 Securities Lending Collateral 31.9 9.0 19.1 Net Inflows (Outflows) $ 17.1 $ 59.5 $ 43.9 Total Market Performance, Currency & Other 175.7 116.4 141.1 Balance as of December 31 $ 1,803.2 $ 1,610.4 $ 1,434.5 2025 ANNUAL REPORT | NORTHERN TRUST CORPORATION 45 MANAGEMENT’S DISCUSSION AND ANALYSIS OF FINANCIAL CONDITION AND RESULTS OF OPERATIONS Other Noninterest Income The components of Other Noninterest Income and a discussion of significant changes during 2025 are provided below. TABLE 20: OTHER NONINTEREST INCOME FOR THE YEAR ENDED DECEMBER 31, CHANGE ($ In Millions) 2025 2024 2023 2025 / 2024 2024 / 2023 Foreign Exchange Trading Income $ 240.8 $ 231.2 $ 203.9 4 % 13 % Treasury Management Fees 38.7 35.7 31.6 8 13 Security Commissions and Trading Income 170.4 150.5 135.0 13 11 Other Operating Income 207.7 1,157.4 228.7 (82) N/M Investment Security Gains (Losses), net — (189.3) (169.5) N/M 12 Total Other Noninterest Income $ 657.6 $ 1,385.5 $ 429.7 (53) % N/M Security Commissions and Trading Income Security Commissions and Trading Income, generated primarily from securities brokerage services provided by Northern Trust Securities, Inc., increased in 2025 from 2024, primarily driven by higher revenue from growth in outsourced trading activity. Other Operating Income Other Operating Income in 2025 decreased from 2024 primarily driven by a $896.7 million gain related to Northern Trust’s participation in a Visa Exchange Offer and a $68.1 million gain on the sale of an equity investment, partially offset by higher expense associated with mark-to-market activity on existing Visa Class B swap agreements, all recorded in the prior year. Please refer to Note 18, “Other Operating Income” and Note 24, “Commitments and Contingent Liabilities” included under Item 8, “Financial Statements and Supplementary Data,” for additional details related to Other Operating Income and Visa, respectively. Investment Security Gains (Losses), Net Investment Security Gains (Losses), net reflects a $189.3 million loss on the sale of AFS debt securities in the prior year arising from a repositioning of the portfolio.