Skip to main content

Basel Consolidated Guidelines

This page sets out the guidelines and sound practices issued by the Basel Committee on Banking Supervision (BCBS). The application page outlines the implementation expectations for guidelines and sound practices, and their scope of application.

The consolidated guidelines and sound practices comprise the 13 modules listed below. Each module is divided into chapters. Each chapter includes links to the original source publications from which the contents of the chapter are based, related standards, related guidelines or sound practices, and other publications that are relevant to a particular topic.

Please provide first name.
Looks good!
CRI30

Credit risk – internal ratings-based approach

This chapter contains specific guidance on issues related to the internal ratings-based approach.
  • Published: 01 Jan 2026

Guidelines

This chapter contains specific guidance on issues related to the internal ratings-based approach. Specifically, on: (i) the estimation of loss given default; (ii) the validation of low-default portfolios; (iii) the use test; and (iv) the use of vendor products.

The contents of this chapter are based on:

Related standards

Other related publications

Foreword

30.1

Banks which have received supervisory approval to use internal ratings-based (IRB) approaches for credit risk may rely on their own internal estimates of risk components to determine regulatory capital requirements for a given exposure. The Basel Framework sets out detailed requirements for IRB approval and implementation; this chapter provides additional guidance on certain aspects of the IRB approach set out in the following 4 sections.

  1. the estimation of loss given default with respect to CRE36.83;
  2. the use test;
  3. the use of vendor products; and
  4. the validation of low-default portfolios.

Key terms

30.2

The following terms are used throughout this chapter and have the meaning given below:

  1. Default rate: the number of defaults among a group of obligors divided by the number of obligors in the group. Note that unlike a probability of default (PD), the default rate is an ex post measure of realised default intensity and is defined with respect to a collection of obligors rather than with respect to a single obligor.
  2. IRB components: IRB components comprise the borrower and/or facility ratings, retail segmentation and estimates of PD, EAD (exposure at default) and LGD that the Basel Framework requires banks to use for the calculation of regulatory capital.
  3. Loss given default (LGD) or LGD estimate: for an exposure in a bank’s portfolio, the LGD parameter used for Pillar 1 calculations as defined in CRE36.83 to CRE36.88.
  4. Long-run default-weighted average loss rate given default: the default-weighted average economic loss rate of all relevant defaults, measured over the long-run.1 The average economic loss rate is default-weighted, if each loss rate in the event of a default has the same weight.
  5. Observed (or realised) loss rate: for an exposure that defaulted in the past and is included in a historical database, the realised loss rate is defined as the economic loss (see CRE36.76) divided by the exposure at default. Note that unlike LGD estimate, observed loss rate is an ex post realised measure of loss severity.
  6. Rating system: comprises all of the methods, processes, controls, and data collection and IT systems that support the assessment of credit risk, the assignment of internal risk ratings, and the quantification of default and loss estimates (see CRE36.9).
  7. Recovery rate: for a defaulted exposure, the present discounted value at the default date of recoveries received net of material direct and indirect costs associated with collecting on the exposure divided by the amount of the exposure at default.
  8. Use test: a bank’s internal employment of the IRB components that the Basel Framework requires for the calculation of regulatory capital as set out in CRE36.60.2
  9. Vendor products: comprise risk measurement models and data that have been developed by parties external to the bank to assist institutions in their risk measurement and management functions.
1

The concept of economic loss referred to here is defined in CRE36.76.

2

The Basel Framework contains cases in which a bank is required to first transform or adjust its risk estimates (eg by applying floors) before their use in the IRB approach. Use test compliance generally concerns the internal use of these estimates prior to their transformation or adjustment for regulatory capital purposes.

The estimation of loss given default

30.3

This section aims to further clarify the quantification of LGD parameters for the purpose of Pillar 1 capital calculations, including further guidance on identifying downturn conditions and incorporating these conditions into LGD estimates where appropriate.

Quantification of LGD parameters consistent with economic downturn conditions
30.4

Principle 1: The bank should have a rigorous and well documented process for assessing the effects, if any, of economic downturn conditions on recovery rates and for producing LGD estimates consistent with downturn conditions.

30.5

CRE36.83 of the Basel Framework requires that the LGD parameters used in Pillar 1 capital calculations must “reflect economic downturn conditions where necessary to capture the relevant risks.” The purpose of this requirement is to ensure that LGD parameters will embed forward-looking forecasts of recovery rates on exposures that default during conditions where credit losses are expected to be substantially higher than average. Under such conditions default rates are expected to be high so that if recovery rates are negatively related to default rates, LGD parameters should embed forecasts of future recovery rates that are lower than those expected during more neutral conditions. In those cases where future recovery rates are expected to be independent of future default rates there is no supervisory expectation that the forward-looking forecasts of recovery rates embedded in LGD parameters will differ from those expected during more neutral conditions.

30.6

To meet the standard set forth in CRE36.83 a bank’s quantification and validation system should comply with Principle 1. The process referred to in the principle should consist of the following integrated components:

  1. Identification of appropriate downturn conditions for each supervisory asset class within each jurisdiction.
  2. Identification of adverse dependencies, if any, between default rates and recovery rates.
  3. Incorporation of adverse dependencies, if identified, between default rates and recovery rates to produce LGD parameters for the bank’s exposures consistent with identified downturn conditions.
Downturn conditions
30.7

Appropriate downturn conditions might be characterised, for example, by the following:

  1. For a well-diversified wholesale portfolio, periods of negative GDP growth and elevated unemployment rates.
  2. Periods in which observed historical default rates have been elevated for a portfolio of exposures that is representative of the bank’s current portfolio.
  3. For exposure where common risk drivers (eg collateral values) influence the default rates and the recovery rates, periods where those drivers are expected to be distressed.
30.8

At a minimum, the bank’s quantification process should identify separate downturn conditions for each supervisory asset class, and with some exceptions, within each jurisdiction. Since, all else equal, greater granularity in defining downturn conditions will tend to result in more conservative LGD estimates, the bank may identify downturn conditions at a more granular level if such an approach is more risk sensitive. Appropriate downturn conditions are those in which the relevant drivers of default rates are consistent with conditions where credit losses for the supervisory asset class are expected to be substantially higher than average.

30.9

Where recovery rates of exposures are sensitive to local economic conditions, the bank should identify separate downturn conditions for each jurisdiction. However, in those cases where a bank can demonstrate that exposures in the same asset classes in different jurisdictions exhibit strong co-movement in recovery rates, the bank can group those jurisdictions together for the purpose of defining downturn conditions. Where recovery rates of exposures are not sensitive to local economic conditions (eg exposures to internationally diversified obligors), the bank may identify downturn conditions appropriate to the exposures, which may span national boundaries.

Adverse dependencies
30.10

Those adverse dependencies might be identified, for example, by some or all of the following:

  1. A comparison of average recovery rates with recovery rates observed during appropriate downturn periods identified according to CRI30.6a.
  2. A statistical analysis of the relationship between observed default rates and observed recovery rates over a complete economic cycle.
  3. For secured exposures where default is shown to be highly correlated with collateral values:
    1. a comparison of recovery rate forecasts derived from robust statistical models that use both “typical” assumptions about collateral value changes and appropriate “downturn” conditions identified according to CRI30.6a.
    2. a comparison of observed recovery rates for defaulted exposures given typical collateral values with those observed under conditions identified according to CRI30.6a where collateral values are depressed.
  4. Identification of the underlying factors (risk drivers) that determine recovery rates and analysis of the relationship between those factors and default rates, combined with an assessment of the net impact of those factors on recovery rates under “downturn” conditions.
LGD parameters
30.11

For example, for those exposures for which adverse dependencies between default rates and recovery rates have been identified through analysis consistent with CRI30.6b, the LGD estimates may be based on averages of observed loss rates during downturn periods identified according to CRI30.6a. or they may be derived from forecasts based on stressing appropriate risk drivers in a manner consistent with downturn conditions identified according to CRI30.6a. If no material adverse dependencies between default rates and recovery rates have been identified through analysis consistent with [6.b], the LGD estimates may be based on long-run default-weighted averages of observed loss rates, or they may be derived from forecasts that do not involve stressing appropriate risk drivers.

Discounting of recovery cash flows used in LGD estimation
30.12

Principle 2: For the estimation of LGDs, measures of recovery rates should reflect the costs3 of holding defaulted assets over the workout period, including an appropriate risk premium.

3

The concept of cost referred to here should be consistent with the concept of economic loss as described in CRE36.76 of the Basel Framework. This is not the accounting concept of cost.

30.13

Most approaches to quantifying LGDs either implicitly or explicitly involve the discounting of streams of recoveries received after a facility goes into default to compare the net present value of recovery streams as of a default date with a measure of exposure at default. Discount rates reflected in estimates of LGD should comply with Principle 2.

30.14

When recovery streams are uncertain and involve risk that cannot be diversified away, net present value calculations should reflect the time value of money and a risk premium appropriate to the undiversifiable risk. In establishing appropriate risk premiums for the estimation of LGDs consistent with economic downturn conditions, the bank should focus on the uncertainties in recovery cash flows associated with defaults that arise during the economic downturn conditions identified under Principle 1. When there is no uncertainty in recovery streams (eg recoveries derived from cash collateral), net present value calculations need only reflect the time value of money, and a risk-free discount rate is appropriate.

30.15

These measures of recovery rates can be computed in several ways, for example by:

  1. discounting the stream of recoveries and the stream of workout costs by a risk-adjusted discount rate which is the sum of the risk-free rate and a spread appropriate for the risk of the recovery and cost cash flows;
  2. converting the stream of recoveries and the stream of workout costs to certainty equivalent cash flows4 and discounting these by the risk-free rate; or
  3. a combination of adjustments to the discount rate and the stream of recoveries and the stream of workout costs that are consistent with this principle.5
4

A certainty-equivalent cash flow is defined as the cash payment required to make a risk averse investor indifferent between receiving the cash payment with certainty at the payment date and receiving an asset yielding an uncertain payout whose distribution at the payment date is equal to that of the uncertain cash flow.

5

A bank may use an “effective interest rate” in accordance with IFRS9 as the discount rate, but in that case should adjust the stream of net recoveries in a way that is consistent with this principle.

Information for supervisory review
30.16

Given the substantial flexibility in identifying downturn conditions and incorporating the effects of identified downturn conditions in LGD estimates and the requirement of CRE36.83 that LGD estimates be no lower than the long-run default-weighted average loss rate given default for a facility type, it is important that banks and their supervisors be able to compare long-run default-weighted average loss rates given default with LGD estimates.

30.17

For each exposure to which an estimated LGD is assigned as part of the Pillar 1 capital calculations, banks also should be prepared to provide an estimate of long-run default-weighted average loss rate given default to supervisors if requested.

30.18

Supervisors may not wish to request this information if the bank can demonstrate that its estimates of loss rates given default under downturn conditions are consistent with the principles articulated above and that reporting separate estimates of long-run default-weighted average loss rates given default would not be practical. In no case may the LGD for an exposure used for Pillar 1 calculations be lower than the corresponding long-run default-weighted average loss rate given default for that exposure, but in some cases the two parameters may be the same.

Interim fallback solutions
30.19

Banks are expected to meet the principles described in this section to be eligible to use own-estimates of LGDs for regulatory purposes. However, in some circumstances, certain banks may temporarily not be able to comply with the principles above to the satisfaction of their supervisors for certain asset classes but may be able to estimate the long-run default-weighted average loss rates given default for that asset class and be otherwise compliant with the minimum requirements of the IRB approaches. If supervisory estimates of LGDs are available for the relevant asset class in that jurisdiction, these banks should use the supervisory estimated parameters for the entire asset class. For asset classes for which supervisory LGDs are not provided in that jurisdiction, supervisors may choose, at national discretion, to establish conservative and temporary measures for these banks. These measures should be conservative so that banks will have a strong incentive to work towards meeting the principles above. Any bank that is allowed to use these temporary measures will be required to produce a plan to become fully compliant with these principles, and have that plan approved by its supervisor.

Relationship with stress tests
30.20

There is no expectation that the stress tests referred to in CRE36.50 or CRE36.51 will necessarily produce an LGD that is either lower than or higher than the LGD estimated according to CRE36.83. To the extent that the identification of downturn periods under CRE36.83 coincides with the stress tests in CRE36.50 or CRE36.51, the calculation might turn out to be similar. More generally, some stress test calculations under CRE36.50 or CRE36.51 may function as one tool for assessing the robustness of the LGD estimation under CRE36.83.

The use test

30.21

This section sets out principles that are intended to support banks and supervisors in interpreting the key use test provisions set out in CRE36.60 of the Basel Framework.

Use of IRB Components
30.22

The IRB use test is based on the conception that supervisors can take additional comfort in the IRB components where such components “play an essential role” in how banks measure and manage risk in their businesses. If the IRB components are solely used for regulatory capital purposes, there could be incentives to minimise capital requirements rather than produce accurate measurement of the IRB components and the resultant capital requirement. Moreover, the employment of IRB components in internal decision making creates an automatic incentive to ensure sufficient quality and adequate robustness of the systems that produce such data.

30.23

The universal usage of the IRB components for all internal purposes, however, is not necessary. In some cases, differences between IRB components and other internal risk estimates can result from mismatches between prudential requirements in the Basel Framework and reasonable risk management practices, business considerations or other regulatory and legal considerations. Examples include different regulatory and accounting requirements for downturn LGD, PD and LGD floors, annualised PDs and provisioning. Other examples of where differences could occur include pricing practices and default definitions. In such cases, supervisors may take a flexible position with respect to the principles below, although the institution should still be able to elaborate on the reasonableness of the differences between the IRB and internal parameter estimates, and demonstrate the relationships between them.

30.24

In general, there are three main areas where the use of IRB components for internal risk management purposes should be observable:

  1. Strategy and planning processes: cover all activities related to a bank specifying its objectives; developing its policies and the plans to achieve these objectives; and allocating resources to implement these plans. IRB components may be used in assessment and allocation of economic capital; credit risk strategy; and decisions about acquisitions, new business lines/products, capacity and expansions.
  2. Credit exposure measurement and management: covers all activities related to management and control of the credit risk that a bank takes as a consequence of implementing its strategies. IRB components may be used in credit portfolio management; credit approval, review and monitoring; performance assessment/remuneration; pricing; individual/portfolio limit setting; provisioning; and retail segmentation.
  3. Reporting: refers to the information flow from credit exposure measurement and management to other functions of the organisation. Reporting is a necessary component of defining a bank’s strategic goals. IRB components may be used in credit portfolio reporting; credit portfolio analysis; and other credit risk information.

If IRB components are not used in some of these areas, the supervisor may require an explanation for such non-use or may raise concerns about the quality of the IRB components. In many instances, supervisors will need to exercise considerable judgement in assessing the use of IRB components.

30.25

Principle 3: Banks are responsible for demonstrating their compliance with the use test.

30.26

According to CRE36.122, banks have the responsibility for validating their rating system and associated IRB parameter estimates. The use test is no exception to this principle: banks are responsible for complying with the use test requirement and for demonstrating compliance by providing relevant documentation and evidence of use of IRB components.

30.27

Banks should demonstrate to their supervisors the processes where IRB components play an essential role and provide the relevant supporting evidence for compliance with the use test. In line with CRE36.61, banks should illustrate how these internal uses confirm management’s belief in the validity of the IRB components and contribute towards meeting the use test objectives. Banks should clarify whether the IRB components are used directly in risk management processes, or whether they are used in a derived form or in a partial way. Banks should also demonstrate how risk management processes support the accuracy, robustness and timeliness of the IRB components.

30.28

Banks and supervisors may rely on existing internal documentation for the purpose of demonstrating use test compliance. To a large extent, the obligations implied by this principle will be met through normal documentation of the banks’ overall validation and governance frameworks and internal operating processes.

30.29

Principle 4: Internal use of IRB components should be sufficiently material to result in continuous pressure on the quality of the IRB components.

30.30

To make the use of the IRB approach credible, IRB components should be entrenched in the bank’s internal risk management processes. While IRB components should play an essential role in risk management and decision making, this does not necessarily mean an exclusive or primary role in all relevant processes. In addition, as elaborated upon in Principle 5, there may be differences between the internal risk measures used for risk management and the IRB components.

30.31

One of the aims of the use test is to promote adequate and appropriate incentives internal to banks so that the banks have a strong belief and interest in the accuracy of their IRB components and the quality of the processes that generate those components. The following are examples of situations where a lack of quality in the IRB components or their underlying processes may give rise to supervisory concern:

  1. the IRB components are calculated solely for regulatory purposes with little or no internal incentives for ensuring the quality of those components;
  2. a deterioration in the accuracy, robustness, and timeliness of the IRB components is unlikely to be picked up by the bank’s internal processes;
  3. the IRB components are based on insufficient or lower quality data relative to what is used to estimate internal parameters;
  4. the bank lacks a process for continuous improvement of the IRB components; and
  5. the bank has used the Basel Framework’s flexibility for designing a rating system in a way that produces artificially low capital requirements inconsistent with their internal approach to measuring credit risk.
30.32

In a bank that meets the use test, supervisors would expect to see evidence of the occurrence of internal challenges to the accuracy, robustness, and timeliness of IRB components resulting from any direct or indirect employment of IRB components along the lines mentioned in the introductory section, ie strategy and planning processes, credit exposure management, and reporting.

30.33

As a quality check of IRB components and underlying processes, the use test is a necessary supplement to the overall validation process. It represents a very important supervisory tool and a fundamental component of the case that banks should put to their supervisors to demonstrate that they initially meet the IRB minimum requirements and will continue to do so, on an ongoing basis.

30.34

The use test plays a key role in ensuring and encouraging the accuracy, robustness, and timeliness of a bank’s IRB components, confirms the bank’s trust in those components and allows supervisors to place more reliance on their robustness and thus on the adequacy of regulatory capital. The evaluation of the use test in banks’ risk management processes and the focus on continuous quality assurance for risk estimates may also encourage improved risk management, which is an overarching objective of the Basel Framework.

30.35

Principle 5: Demonstrating consistency and explaining differences between IRB components and internal measures can establish sufficient comfort that principles 3 and 4 are met.

30.36

Measures used for internal processes may reasonably differ from IRB components in some instances. Such differences may arise from legitimate mismatches between the prudential requirements of the IRB framework and a bank’s own risk management practices. Where such differences exist, banks should demonstrate good reasons for use of parameters that do not match IRB components. The supervisory objectives of the use test could be met if banks demonstrate that the degree of consistency between the IRB components and the internal estimates is sufficiently high as to contribute to continuous quality pressure on the IRB components. In this context, consistency might be demonstrated by establishing clear linkages between the internal inputs and the IRB components, showing that any differences reflect legitimate risk management needs.

30.37

A combination of multiple features could provide comfort to supervisors that sufficient linkage exists. Such features could include use of the same underlying data for computations, reliance on the same IT systems, application of similar quality checks and similar validation techniques, or use of common methodologies or similar models.

30.38

Principle 6: The importance of an internal process to the bank’s decision making influences the extent to which that process contributes to an assessment of use test compliance. Banks should take a holistic approach when assessing overall compliance of their institution with the use test requirements.

30.39

Any processes in which significant use is made of IRB components or where incentives to ensure the quality of IRB components are sufficiently strong can contribute to a bank’s overall self-assessment of use test compliance. Certain uses in certain processes could potentially provide higher comfort than others. Generally, the more important, pervasive and granular the use of the IRB components in a bank’s decision-making processes, the greater is the likelihood of meaningful internal challenge and the stronger are the incentives to ensure the accuracy and robustness of IRB components, giving greater confidence that management is committed to the validity of the IRB components. Supervisors should adopt a similar approach when assessing factors supporting a bank’s compliance with the use test.

30.40

If, on the other hand, ratings, retail segmentation and estimates used in internal processes differ from respective IRB components without convincing explanation as to the reasons for the lack of consistency, bank management’s commitment to the importance of the IRB components and thus compliance with the use test may be in doubt. However, shortfalls in use test compliance in individual processes do not in and of themselves imply a negative overall evaluation of an institution’s compliance with the use test.

30.41

A group with subsidiaries in more than one country may conduct much of its risk management and business management activities on a group basis using processes, procedures and IRB and internal components defined at the group level. In such cases both home and host supervisors may need to be flexible in determining whether the purposes of the use test are met on a holistic basis, generally with reference to such group policies, procedures and components.6

6

For a more thorough treatment of cross-border implementation of the Basel Framework, see SCA30.

The use of vendor products

30.42

The section provides guidance regarding how banks might satisfy IRB validation requirements when vendor products, which frequently introduce information transparency issues, are used within banks’ IRB processes. It focuses on vendor developed models and datasets used within the context of banks’ IRB processes to assign exposures to rating grades, or segments, or to estimate IRB risk parameters.

30.43

The Basel Framework does not make any exceptions from minimum requirements when vendor products are used within banks’ IRB processes (CRE36.37). The proprietary nature of certain aspects of vendor products does not necessarily disqualify their use in the bank’s IRB quantification and validation processes; however, when full and complete details concerning aspects of a vendor product are lacking, it will be necessary for banks to rely more heavily on other validation techniques or methods designed to compensate for the lack of access to full information. As examples:

  1. If, due to the proprietary claims of a vendor, a bank is unable to document the statistical weights of model parameters used within a vendor model, it may compensate for this lack of developmental information by employing other validation techniques. Such techniques might include comparing vendor model results against alternative internal model results or external reference data sources (benchmarking), or outcomes analysis, whereby the risk parameter estimates produced by vendor models are compared with actual bank portfolio outcomes; and
  2. If the applicability of the vendor model to the internal portfolio relies on the characteristics of certain exposures included in a vendor’s proprietary database, the bank could establish a protocol with the vendor to gain access to a sample of the exposures in this database in order to test if the exposures in the vendor’s developmental database meet certain requirements (eg timeframes of exposures, types of exposures, geographic distribution, etc).
30.44

The principles set out in this section balance the need for banks to be transparent in developing their IRB risk estimates and the need for vendors to protect the intellectual property that accompanies their proprietary models. For supervisors it is appropriate to scale supervisory expectations by the relative importance of vendor models or data within the bank’s IRB processes.7

7

For instance, if results produced by a vendor model rely heavily on external data inputs, and that model in turn plays a material role in estimating a bank’s IRB parameters, then Principles 7 to 10 outlined below should be applied to the fullest extent possible to both the vendor model and the external data inputs used by the model as they relate specifically to a bank’s IRB risk quantification and validation processes. If, in another instance, external data are used only to provide broad benchmarks for certain IRB risk parameters, a bank’s validation efforts might be limited to processes that ensure the integrity of the data and their applicability to the bank’s exposures.

30.45

Principle 7: Banks should be able to document and explain the role of vendor products and the extent to which they are used within their IRB processes.

30.46

Vendor products can play several roles within a bank’s IRB processes. It is the responsibility of the bank to demonstrate and document how its risk estimates are derived and validated. When vendor products play a material role in either deriving or validating these risk estimates, it is important that banks clearly articulate what role these products play in the estimation process and the extent to which these products are used in arriving at IRB parameter estimates. At a minimum, banks need to describe the particular portfolios to which the vendor products are applied as well as how these products are applied. To improve both supervisory and internal understanding of the bank’s IRB processes, banks should be prepared to explain the underlying rationale for choosing third-party products over internally developed models and data (eg lack of default data or internal resources). Banks should be able to explain what alternative solutions it has considered, and, if possible, how results using the vendor products compare to those of alternative products or solutions.

30.47

Principle 8: Banks should be able to demonstrate a thorough understanding of vendor products used in their IRB processes.

30.48

In general, when banks use vendor products in their IRB processes, they should be able to demonstrate a thorough understanding of those products. Additionally, if banks integrate vendor models within their IRB risk quantification processes, banks need to demonstrate how those models effectively contribute to IRB risk quantification. This in-house knowledge of vendor products might be demonstrated by the following:

  1. In-depth knowledge of the methodological underpinnings and basic construction of vendor models, including an understanding of the models’ capabilities, limitations, and appropriateness for use in developing IRB risk estimates for the bank’s own portfolio of credit exposures;
  2. Demonstration of a full understanding of the effect and significance of the proprietary elements in the vendor models;
  3. Documentation of the rationale behind any judgment-based overrides or any other adjustments made to vendor datasets or vendor model outputs; and
  4. Retention of in-house expertise on the vendor products for as long as these products are used within the bank’s IRB processes.
30.49

Principle 9: Vendor products should be appropriate to the bank’s exposures and risk rating methodologies and suitable for use within the IRB framework.

30.50

Banks using the IRB approach should be able to demonstrate clear linkages between vendor model inputs, datasets, and estimates and the bank’s own portfolio characteristics and risk rating methodologies. This requirement does not imply that vendor model inputs and data need to mirror those of the bank’s portfolio in detail. Nevertheless, there should be a reasonable degree of consistency between model inputs and the risk drivers of the bank’s internal portfolio as well as a reasonable comparability between the data that were used for building the model and the bank’s internal portfolio characteristics to produce meaningful risk rating assignments or risk parameter estimates. As examples:

  1. In the case of the use of a vendor rating model, the bank should be able to demonstrate how well the historical reference data used to develop this model map into the bank’s existing portfolio in terms of significant risk characteristics; and
  2. In the case of vendor models used to assign exposures to risk grades or segments, if there is material information (eg expert judgment) not incorporated into the vendor model, the output of the vendor model should be supplemented to incorporate such information.
30.51

Banks should also ensure that vendor products are consistent with the requirements for use in an IRB context. The output of the vendor products may be consistent with the Basel standards and requirements but, in themselves, may not achieve full compliance. That is, the vendor product outcomes may require adjustment or supplementation in the form of additional information (eg qualitative information not included in the vendor model) or a mathematical adjustment or transformation (eg conversion to logarithms). The bank should recognize the need for such supplementation and incorporate the combined results in its IRB processes to achieve full compliance. As examples:

  1. In retail, it is common to use external scores as an element of the segmentation process. This external score might be based on data history that covers a short span of time and definition of default not aligned with CRE36.68 to CRE36.75. To be compliant with the Basel Framework, the PD estimates will have to be based on a longer timeframe and the definition of default applicable for IRB purposes; and
  2. When corporate vendor products use definitions of default that are not aligned with the Basel Framework to estimate PDs, the bank must ensure that the final estimates are compliant with CRE36.68 to CRE36.75. A bank may achieve this requirement by transforming (eg scaling up or down) the PDs of the vendor product to account for material differences between the vendor’s definition of default and that under CRE36.68 to CRE36.75.
30.52

Principle 10: Banks should have clearly articulated strategies for regularly reviewing the performance of vendor model results and the integrity of external data used in their IRB risk quantification processes.

30.53

A fundamental difference between internally and externally developed models is the degree to which banks are able to provide transparent descriptions of a model’s development. When the developmental evidence is less than fully transparent in the case of vendor models, the bank will have to rely more heavily on alternative validation approaches. Accordingly, banks should implement clear strategies designed to periodically (at least once a year) assess the performance of any vendor models used in the bank’s IRB processes to ensure the models continue to function as intended. Since vendor model parameters and weights may have been calibrated using external data, it is critical for banks to test the performance of vendor models against the bank’s own portfolio of exposures. Where there is a scarcity of internal performance data (eg low-default portfolios) with which to perform backtesting or outcomes analysis, bank’s performance reviews will have to rely more heavily on alternative performance measurement techniques. In addition, banks should develop and implement strategies designed to verify the accuracy and consistency of any external data used within the bank’s IRB risk quantification processes. This can be done, among other ways, by comparing the results obtained using the external data to the results obtained using a bank’s own portfolio data in the same risk rating, segmentation, or parameter estimation models or methods.

What should banks expect from vendors?
30.54

First and foremost, banks should ask vendors to follow good model validation practices. However, it is expected that the scope of these validation activities will focus on the vendor model itself and not on IRB processes. Vendors should be willing to demonstrate these practices to their clients and should always be willing to furnish documentation and reports relating to the validation of their models and the mapping (applicability) of developmental data used in those models to a client bank’s portfolio. When new versions or releases of their products are released, banks should obtain documentation that describes the recalibration or conversion from the old product to the new product as well as information on the validation of the new versions. Banks should obtain from vendors descriptions of key model parameters and the sensitivity of model results to changes in these parameters and their statistical weights. Perhaps most critically, banks should be able to test the performance of the vendor model against the bank’s own portfolio when those models are used in the IRB processes.

30.55

In the case of sensitive, proprietary data and model information that is not disclosed, vendors should nonetheless provide descriptions of the general nature, model characteristics, and sources of development data. Proprietary elements often include technical model characteristics, such as the equation specifications and statistical weights; in some cases, details of the datasets used in the formulation of the model are also not disclosed. While the evaluation of such developmental information is a key component of banks’ validation processes, banks, in most cases, could compensate for the non-disclosure of proprietary information by applying the principles outlined in this section. Banks should be able to demonstrate to their supervisors that they have taken sufficient measures to ensure that proprietary elements of vendor models do not inhibit them from meeting these principles. The extent of the measures required will depend on the relative importance of a vendor product within a bank’s IRB processes and may be material when a bank relies heavily on vendor products with non-disclosed elements.

The validation of low-default portfolios

30.56

This section sets out guidance regarding the appropriate treatment within the foundation and advanced IRB approaches of portfolios where banks may have limited loss data.

30.57

Portfolios for which bank’s internal data systems include relatively few loss events (ie low default portfolios (LDP)), present challenges for risk quantification and validation. A straightforward calculation based on historic losses for a given wholesale rating or retail segment would not be sufficiently reliable to form the basis of a PD estimate, let alone an estimate of LGD or EAD. In addition, backtesting realised outcomes against estimates may not provide strong evidence to support the accuracy of the rating system.

30.58

Several types of portfolios may have low numbers of defaults, eg low risk portfolios, small portfolios, or portfolios with a short history due to entry in a new market. Other portfolios may not have incurred recent losses, but historical experience or other analysis might suggest that there is a greater likelihood of losses than is captured in recent data.

30.59

A relative lack of historic data does not automatically preclude portfolios from use of the IRB approaches. Relatively sparse data might require increased reliance on alternative data sources and data-enhancing tools for quantification and alternative techniques for validation. The choice of specific tools and techniques will depend on the particular circumstances of the individual bank and the specific portfolio. Nevertheless, banks are strongly encouraged to consider the tools and techniques listed below and to utilise those that are most appropriate to their particular circumstances to improve their risk assessments.

Guidance for banks and supervisors in designing and validating rating systems for LDPs
30.60

Parameter estimates should be forward-looking and predictive.

While parameter estimates must be grounded in historical experience and empirical evidence, and not based purely on subjective or judgmental considerations, they are intended to be predictive for all portfolios. Relative scarcity of historical loss data in some circumstances may not be a serious impediment to developing PD, LGD and EAD estimates. Where, for example, there is a lack of recent loss data but historical experience or other analysis suggests that this is unlikely to be representative of probable long-term outcomes, it should be possible to base risk estimates not solely on recent loss data, but also on additional information about the drivers of losses.

30.61

The qualitative requirements for the IRB approaches apply to all portfolios.

There is a range of IRB qualifying criteria in the Basel Framework, of which data and statistical elements are only one part. Regardless of whether or not a bank has relatively scarce internal loss data in a particular portfolio, supervisors should expect the bank to satisfy all of the qualitative criteria set forth in CRE36.

30.62

A relative lack of loss data can at times be compensated for by other methods for assessing risk parameters.

For some portfolios (eg sovereign and bank), there may be limited loss data. According to the quality of loss data that might be available internally and/or externally, there may be tools that banks can utilise to enhance data richness (see CRI30.65 to CRI30.71).

30.63

Where scarce internal loss data makes it difficult to test risk estimates against actual experience, a variety of validation tools are available.

In some cases, even where tools such as those described below have been used to enhance data richness, banks and supervisors may find that backtesting risk rating system predictions against realised defaults cannot be done in a manner that strongly demonstrates predictiveness. In such cases, a bank may find that employing a variety of validation tools, including review of developmental evidence, process verification and benchmarking, can satisfy both itself and its supervisor that its rating estimates are reasonable see CRI30.65 to CRI30.71.

The role of supervisors with regard to bank treatment of LDPs
30.64

Supervisors will review bank estimates and evaluate whether the bank has taken reasonable steps to address the scarcity of internal loss data consistent with the minimum requirements set forth in the Basel Framework (CRE36) and the guidance in this section. For example, supervisors will have to be satisfied with any additional conservatism in loss estimates used by the bank as per CRE36.67 and CRE36.78. Where a bank does not, in the judgement of the supervisor, take adequate steps to address its lack of historic loss data, there is a range of options open to supervisors that will depend on the circumstances of the bank, the jurisdiction and the specific portfolio.

Data-enhancing tools for quantification and validation
30.65

While a relative lack of loss data may make it more difficult to use quantitative methods to assess risk parameters, there are nevertheless some tools that could potentially be used to enhance data richness or to determine the degree of uncertainty to be addressed through conservatism. This sub-section outlines several possible data-enhancing and validation tools that can be used in the quantification and validation of all portfolios, but that might be especially relevant for the treatment of LDPs. These tools are more applicable to estimation of PDs rather than LGDs or EADs. The suitability and most appropriate combination of individual tools and techniques will depend on the nature of the bank and the characteristics of the specific portfolio.

30.66

Pooling of data with other banks or market participants, the use of other external data sources, and the use of market measures of risk can be effective methods to complement internal loss data. While a bank would need to satisfy itself and its supervisor that these sources of data are relevant to its own situation, in principle, data pooling, external data and market measures can be effective means to augment internal data in appropriate circumstances. This can be especially relevant for small portfolios or for portfolios where a bank is a recent market entrant.

30.67

Internal portfolio segments with similar risk characteristics might be combined. For example, a bank might have a broad portfolio with adequate default history that, if narrowly segmented, could result in the creation of a number of LDPs. While such segmentation might be appropriate from the standpoint of internal use (eg pricing), for purposes of assigning risk parameters for regulatory capital purposes it might be more appropriate to combine subportfolios.

30.68

In some circumstances, different rating categories might be combined and PDs analysed for the combined category. A bank using a rating system that maps to rating agency categories might find it useful, for example, to combine AAA, AA and A-rated credits, provided this is done in a manner that is consistent with CRE36.19 to CRE36.20. This could enhance default data without necessarily sacrificing the predictiveness or risk-sensitivity of the bank’s rating system.

30.69

The upper bound of the PD estimate can be used as an input to the formula for risk-weighted assets for those portfolios where the PD estimate itself is deemed to be too unreliable to warrant direct inclusion in capital adequacy calculations.

30.70

Banks may derive PD estimates from data with a horizon that is different from one year. Where defaults are spread out over several years, a bank may calculate a multi-year cumulative PD and then annualise the resulting figure. Where intra-year rating migrations contain additional information, these migrations could be analysed as separate rating movements to infer PDs, which may be especially useful for the higher-quality rating grades.

30.71

If low default rates in a particular portfolio are the result of credit support, the lowest non-default rating could be used as a proxy for default (eg banks, investment firms, thrifts, pension funds, insurance firms) to develop ratings that differentiate risk. When such an approach is taken, calibration of such ratings to a PD consistent with the Basel definition of default would still be necessary.

Benchmarking tools for validation
30.72

In addition, where a scarcity of internal historical data makes it difficult to meaningfully backtest risk rating predictions against realised defaults, it may be possible to make greater use of various benchmarking tools for validation. Among the tools that could potentially be used are the following:

  1. Internal ratings and migration matrices could be compared with the ratings and migrations of third parties such as rating agencies or data pools, or with the ratings and migrations resulting from other internal models.
  2. Internal ratings could be benchmarked against internal or external expert judgements, for example where a portfolio has not experienced recent losses but where historical experience suggests the risk of loss is greater than zero.
  3. Internal ratings could be compared with market-based proxies for credit quality, such as equity prices, bond spreads, or premiums for credit derivatives.
  4. An analysis of the rating characteristics of similarly rated exposures could be undertaken.
  5. The average rating output for the portfolio as a whole could be compared with actual experience for the portfolio rather than focusing on backtesting estimates for more narrowly defined segments of the portfolio. Similarly, rating grades can be combined to make backtesting more meaningful.
30.73

This list is not intended to be exhaustive but rather is intended to provide examples of some benchmarking tools that may be useful in the case of scarce internal loss data. It is important that banks utilise as many tools and techniques, including those other than benchmarking, as they deem necessary to build confidence and demonstrate the predictive ability of their risk rating systems.

Application of the guidelines and sound practices

  1. The Basel Framework is the full set of standards of the BCBS. The membership of the BCBS has agreed to fully implement these standards and apply them to the internationally active banks in their jurisdiction.1 For other banks, BCBS members may adopt a proportional approach to implementing specific rules and principles under the given standard.
  2. Guidelines elaborate the standards in areas where they are considered desirable for the prudential regulation and supervision of banks, in particular internationally active banks. They generally supplement BCBS standards by providing additional guidance for the purpose of their implementation.
  3. Sound practices generally describe actual observed practices, with the goal of promoting common understanding and improving supervisory or banking practices. BCBS members are encouraged to compare these practices with those applied by themselves and their supervised institutions to identify potential areas for improvement.
  4. The BCBS also publishes various other documents, including implementation reports and newsletters. These documents do not constitute standards, guidelines or sound practices.
  5. The Committee's standards (ie those set out in the Basel Framework) are subject to monitoring and assessment of their adoption by jurisdictions through the Regulatory Consistency Assessment Programme (RCAP). The Basel Core Principles are used in assessing the effectiveness of countries' regulatory and supervisory regimes, generally under the Financial Sector Assessment Program (FSAP). Guidelines, sound practices and other publications are not subject to RCAPs or FSAPs.
  6. The Committee periodically reviews its guidelines and sound practices as standards, supervisory practices and the financial system evolve. The consolidated guidelines and sound practices are intended to be a living document, which will be updated when the Committee publishes new materials.
  7. Unless otherwise indicated, the guidelines have been developed with a view towards application to: (i) large, internationally active banks; and (ii) supervisory and other relevant financial authorities in Basel Committee member jurisdictions. However, smaller banks and authorities in all jurisdictions may benefit from considering the guidelines and applying them on a proportionate basis, depending on the size, complexity and risk profile of the bank or banking sector for which the authority is responsible.

1 The Core Principles for effective banking supervision (Basel Core Principles) are also a standard and form part of the Basel Framework but are applicable to all jurisdictions and all banks.

This module describes expectations to combat money laundering and terrorist financing.

This module describes expectations and practices relating to capital adequacy.

This module describes expectations for corporate governance.

This module describes expectations for credit risk and counterparty credit risk management.

This module describes expectations for external audit and sets out references related to public disclosure.

This module describes expectations for banks’ internal audit and compliance functions.

This module describes expectations for liquidity risk management.

This module sets out references related to market risk and interest rate risk.

This module describes expectations for the management of operational risk and operational resilience.

This module describes expectations for the management of problem assets and expected credit losses.

This module describes the application of proportionality in prudential regulation and supervision.

This module describes expectations for risk management.

This module describes the nature and application of prudential supervision.

You might also be interested in