Staying prepared: developments in the world of stress testing

In our latest free report, we provide an update on approaches to stress testing in major financial jurisdictions around the globe and consider what the future might hold.

What are stress tests?

Banking regulators use stress tests to identify whether banks are prepared for potential financial and economic shocks. They help regulators to identify and address vulnerabilities in the banking system and ensure banks have the capital required to withstand a series of hypothetical risk events. The end goal is to ensure banks can continue operating smoothly, even in challenging environments.

Different jurisdictions take slightly different approaches to bank stress testing. Regulatory authorities design stress testing frameworks according to the characteristics of their individual financial systems, economic conditions and regulatory objectives.

EU stress tests

In the EU, the European Central Bank (ECB) conducts several different types of stress tests. EU law requires the ECB to carry out stress tests on supervised banks at least once per year, which the Bank then uses to inform its Supervisory Review and Evaluation Process (SREP). In the UK, the Bank of England (BoE) also performs thematic stress tests and forward-looking vulnerability analyses annually. This is in addition to biennial stress tests carried out as part of the comprehensive assessment process for banks deemed by the ECB as “significant,” and stress tests carried out for macroprudential purposes (focusing on financial stability and system-wide effects rather than individual banks.)

EU-wide European Banking Authority (EBA) stress tests and SREP stress tests

Every two years the EBA carries out an EU-wide stress test in cooperation with the ECB, the European Systemic Risk Board (ESRB) and the national supervisory authorities. The test covers the largest significant banks directly supervised by the ECB. The exercise is based upon the EBA’s methodology and templates, and incorporates scenarios provided by the ESRB. Both aggregate and individual results are published by the EBA.

In 2023, the EBA launched an updated methodology for its EU-wide stress test. The new framework incorporated an additional 26 banks compared with 2021, and further proportionality was introduced to the methodology. New templates were released in December 2022 and in January, an adverse scenario, which was “the most severe we have seen since the EBA began conducting EU-wide stress tests,” according to KPMG. It assumed a major breakdown in global markets and the supply chains, plus high inflation, weak growth and rising interest rates. The scenario suggested serious implications for consumer spending and investments, with “corresponding implications for credit, market, counterparty and operational risks,” said KMPG.

Cyber stress tests in the EU

Due to the increasing severity and impact of cyber incidents on the financial system, the EU will be introducing cyber stress tests in 2024 as part of its thematic tests, which are conducted in the years in which the normal biennial stress tests do not take place. “ECB Banking Supervision evaluates banks’ management of IT risk based on, among other things, two complementary sources of information: banks’ self-assessments and supervisors’ findings from on-site inspections,” said the ECB. “The information received from these sources consistently shows that banks need to improve their IT and cybersecurity risk controls.”

The ECB’s cyber stress testing exercise in 2024 will be conducted with two approaches, depending on the size of the institution: an in-depth assessment for a limited number of banks and a lighter assessment for other institutions. “The in-depth stress test will consist of a detailed questionnaire containing approximately 500 questions, with documentary evidence required for most answers. The lighter assessment will consist of a shortened questionnaire with less evidence required,” explains PwC

Each of the two approaches will involve clear communication across first, second and third lines of defence in the areas of business continuity management, IT service continuity management, information and cybersecurity, business risk and outsourcing management. “Any institution taking the test must be able to demonstrate an end-to-end response in preparation for a real-life scenario,” adds PwC.

Preparing for the EU 2024 cyber thematic stress tests

The simplified assessment began on 2nd January 2024, and banks will be given two months to complete the questionnaire and submit evidence by the 29th February deadline (according to KMPG). The in-depth assessment will then take place until 20th April and the test will conclude with a contribution to the SREP and lessons learned on 30 June.

Key components of the cyber stress tests will be: scenario-based testing; an assessment of vulnerabilities; incident response evaluation and information-sharing and communication. “In order to ensure quality of data during this process, it is essential that firms have an open approach to communication between the three lines of defence and various departments within the business – especially IT” says Mike Finlay, CEO of RiskBusiness. “This should be the case anyway, but the cyber stress test will really expose any weaknesses in this line of communication. Sharing risk intelligence and best practice with other firms is also key to ensuring your firm is covering as many bases as possible when it comes to managing cyber risk as it is such a fast-evolving risk landscape. The increasing use of more complex technologies, the growth of online banking and a heavier reliance on AI is providing firms with greater opportunities – but will also be widening their exposure to cyber risks. It will be interesting to see the results of the EU tests and how the regulators feel banks are currently performing in this area.”

ICAAP – Internal Capital Adequacy Assessment Process (EU and UK)

Both EU and UK firms are required to complete an Internal Capital Adequacy Assessment Process. In the UK, firms are required to assess on an ongoing basis the “amounts, types and distribution of capital that it considers adequate to cover the level and nature of the risks to which it is or might be exposed,” says the Bank of England. “This assessment should cover the major sources of risks to the firm’s ability to meet its liabilities as they fall due, and should incorporate stress testing and scenario analysis.”

Firms are warned against taking a copy-and-paste approach to this internal assessment process. “If a firm is merely attempting to replicate the PRA’s own methodologies, it will not be carrying out its own assessment in accordance with the ICAA [Internal Capital Adequacy Assessment] rules,” says the guidelines document.

The ICAAP must be fully documented and maintained on an annual basis, or however frequently changes that are made to the business, strategy, “nature or scale of its activities or operational environment” suggest it should be updated.

Who is responsible for the ICAAP?

Both the EU and UK’s ICAAP guidelines place the onus on the management body to ensure the ICAAP is completed, but the process itself is carried out largely by the following departments:

  • Risk Management: The Risk Management team assesses and quantifies the various risks faced by the bank, including credit risk, market risk, liquidity risk and operational risk.
  • Finance Department: Members of the finance team provide financial data and ensure accurate financial reporting for the ICAAP. They are also involved in assessing the impact of various stress scenarios on the bank’s balance sheets.
  • Treasury Department: Professionals in the treasury team must manage the firm’s liquidity risk for the ICAAP submission and ensure the bank has sufficient liquidity to meet its obligations under the stress scenarios.
  • Capital Management Team: Members of this department evaluate whether the bank holds enough capital to cover risks identified in the ICAAP.
  • Internal Audit: Internal audit may be involved in the ICAAP process by providing an independent review and assessment before it is submitted.
  • Compliance Team: The compliance department will ensure the ICAAP process meets all regulatory requirements.
  • Modelling and Analytics Team: Members of this department are essential in completing the simulation and stress testing aspects of the ICAAP process.
  • Senior Management and the Board of Directors: Senior executives and the board must oversee the entire ICAAP process ensuring that risk management strategies align with the bank’s overall objectives. They are responsible for approving the ICAAP documentation and its recommendations. 

The PRA says it expects an ICAAP to be “the responsibility of a firm’s management body, that it is approved by the management body, and that it is used as an integral part of the firm’s management process and decision making.” Similarly, the ECB says “the management body has overall responsibility for the implementation of the ICAAP, and it is expected to approve an ICAAP governance framework with a clear and transparent assignment of responsibilities, adhering to the segregation of functions.”

Criticism of the ICAAP

Though ICAAP submissions must be independently verified (according to both EU and UK guidelines), there has been some criticism of how much trust is placed upon banks to assess their own capital adequacy. A report commissioned by the ECB in September 2022 looked into how the ECB’s SREP could be improved upon. One criticism was that ICAAPs could potentially be subject to biases. “Banks’ self-evaluations are often subject to biases that may become even more significant when ICAAPs play a prominent role in the determination of P2R (Pillar 2 requirements),” said the report. “ICAAPs should be used as ancillary information, rather than the basis for the analysis.” The report also recommends the ECB makes changes to the way it sets capital requirements, saying it should focus “on specific risks requiring additional capital coverage, while significantly limiting the use of ICAAPs.”

Bank of England updates

The Bank of England (BoE) announced in October 2023 it would be conducting a desk-based stress test in 2024, rather than its usual Annual Cyclical Scenario (ACS) due to banks balance sheets being in good health, according to the Q3 Financial Policy Summary. It will only be publishing aggregate results of stress testing in 2024, not the more detailed bank-by-bank results as it has previously, and has said it will “take stock and update” its stress testing methodology. The BoE will also be looking into whether additional firms need to be included in the test.

The BoE only returned to its usual ACS stress testing framework in 2022 after two years of Covid-19 pandemic crisis-related stress testing and a postponement following Russia’s invasion of Ukraine in February 2022. “In 2020, in place of a cyclical stress test, the Bank performed a ‘reverse stress-test’ exercise focused on risks presented by the Covid pandemic,” said the BoE when it published the 2022/23 stress test results. “In 2021, the Bank undertook a ‘solvency stress test’ (SST), to test the resilience of the UK banking system against a much more severe evolution of the pandemic and consequent economic shock.”

System-wide exploratory scenario exercise (SWES)

The BoE also announced in June 2023 that it would be launching its first system-wide exploratory scenario (SWES) exercise. “The exercise aims to improve understanding of the behaviours of banks and non-bank financial institutions (NBFIs) in stressed financial market conditions,” said the BoE. “It will explore how those behaviours might interact to amplify shocks in UK financial markets that are core to UK financial stability.” The tests are in-part a reaction to shocks experienced in the market in September 2022 when Liz Truss’s government announced its fiscal plans, and also the so-called “dash for cash” at the height of the pandemic in 2020. Participating firms will include a selection of 50 large banks, insurers, central counterparties and a variety of funds including pension funds, hedge funds, and funds managed by asset managers, all selected by the UK’s FCA (Financial Conduct Authority) and the TPR (The Pensions Regulator). “This reflects the wide range of institutions engaged in UK financial markets. Participants will be actively engaged in both the design and execution of the exercise,” said the Bank. “We expect to run a second round of the scenario phase through 2024 and intend to publish our final report on SWES findings by end-2024.”

US stress tests

Stress tests in the United States, particularly those conducted by the Federal Reserve, differ in several aspects from stress tests in other jurisdictions. Here are some of the key differences:

Comprehensive Capital Analysis and Review (CCAR): The primary stress testing programme in the US is known as CCAR. It assesses large US bank holding companies to ensure they have sufficient capital to withstand economic stress. CCAR evaluates not only the adequacy of capital but also the banks’ capital distribution plans, including dividends and share buybacks.

  • Stringent requirements: US stress tests are known for their stringency. They include severe and hypothetical economic scenarios, such as a deep recession, adverse market conditions, and high unemployment, to assess a bank’s resilience under extreme circumstances.
  • Frequency: Stress tests in the US, especially CCAR, are conducted annually. This regularity ensures ongoing monitoring and adjustment of capital planning strategies.
  • Public disclosure: Results of stress tests in the US are made public. This transparency helps build confidence in the financial system by demonstrating the strength and resilience of major banks.
  • Role of the Federal Reserve: The Federal Reserve takes a central role in designing and conducting stress tests. It sets the scenarios, methodologies, and criteria for assessment.
  • Focus on large banks: US stress tests primarily target large, systemically important banks. The scope of the tests is often broader compared to stress tests in some other jurisdictions.
  • Integration with regulatory capital rules: Stress testing results are integrated with regulatory capital rules, influencing the capital requirements that banks must meet.
  • Risk sensitivity: US stress tests often incorporate a risk-sensitive approach, considering the specific risk profiles of individual banks and tailoring scenarios accordingly.

How banks are stress tested in the US became the subject of criticism recently during the US banking crisis of March 2023. The crisis saw the collapse of two major US banks: SVB and Signature Bank. Under the Obama administration, banks with assets of more than US$50bn were subject to annual stress testing and stricter capital and regulatory requirements. After Donald Trump’s presidency and subsequent unravelling of the Dodd-Frank Act, the threshold was increased so that only banks with assets of US$250bn or more were subject to these measures. SVB would therefore have been under much greater regulatory scrutiny had the Trump administration’s changes not been implemented.

South Africa

The South African Reserve Banks’s (SARB) common scenario stress test (CSST) takes place every two years and incorporates firms designated as systemically important (SIFIs) by the SARB. “The tests estimate potential losses and capital shortfalls in the banking sector resulting from severe and plausible scenarios over a three-year horizon. A risk assessment matrix is used to identify the stress-testing scenarios,” says the Bank.

The stress tests are conducted on a bottom-up and top-down bases. SIFIs are given the scenarios to carry out bottom-up stress tests using their own internal models, while the SARB also conducts a top-down stress test to validate and benchmark the results from each bank. “For each scenario, new capital and liquidity ratios are calculated and compared to their minimum prudential regulatory requirements,” says the SARB. The Bank does not publish individual results, but sector-wide results are published in its Financial Stability Review.

Climate risk

An increasing number of jurisdictions have begun including climate risk stress testing as part of thematic tests and regular stress testing frameworks, including South Africa. SARB included a climate change risk add-on in its 2021 Common Scenario Stress Test for the first time ever. This focussed mainly on physical risks emanating from climate change as the result of a drought scenario. “Banks were requested to quantitatively simulate the solvency impact of the scenario, with the impact incorporated into the already stressed solvency positions from the CSST adverse scenario. This was complemented by qualitative assessments of the impact of transition risks and the materiality of environmental risks to different economic sectors,” said the SARB.

According to investment research firm MSCI, at least 31 central banks and financial regulators around the world had completed, were conducting, or were planning bottom-up or top-down climate scenario analysis exercises, as of September 2022. Most of these banks use the Network for Greening the Financial System (NGFS) as their source for baseline reference scenarios, which in theory, should allow for consistency so that firms can compare results across borders. However, this often isn’t the case due to differences in how the tests are applied by participants. “One major difference is how supervisors view the balance sheets of financial services companies,” explains Sita Subramanian from MSCI. “Balance-sheet assumptions remain important, providing investors with insight into the possible strategic investments and divestments a financial institution may make to adjust its exposure to climate-related risks. The Bank of England (BoE), Bank of Canada (BoC) and Hong Kong Monetary Authority (HKMA) assumed a static balance sheet, under which the size, composition and risk profile does not vary over the stress testing time horizon. But several other jurisdictions have used a hybrid approach, assuming a dynamic balance sheet for certain, long-term horizons.”

Another difference identified by Subramanian is the type of climate risk supervisors have assessed in their climate stress tests. “The BoC has focused on testing for transition risks, while the European Central Bank (ECB), BoE, Autorité de Contrôle Prudentiel et de Resolution (ACPR), HKMA and Australian Prudential Regulation Authority (APRA) focused on both transition and physical risks. These differences may hamper investors’ ability to compare the full suite of climate-related risks faced by all institutions.”

Australia: a cross-industry approach

It’s worth noting that although banking stress tests provide a rigorous examination of the banking sector’s resilience to a risk scenario, the financial system is made up of more parts than just banking alone. In its 2023/24 corporate plan, the Australian Prudential Regulation Authority (APRA) said it would be looking into developing a cross-industry stress testing framework which would “explore how shocks to the financial system might be mitigated or propagated by the interactions between the banking, insurance, and superannuation industries.” The framework, which the regulator described as being “over the plan horizon,” will seek to assess system-wide vulnerabilities and consider how APRA could address them.

Potential future developments in stress testing

How banks are stress tested is regularly evaluated to include the most relevant and impactful scenarios. Below are some potential future trends we may see emerge in stress testing methodologies: 

  • Integration of climate risk: There has been a growing emphasis on incorporating climate-related risks into stress testing frameworks. Regulators and financial institutions are exploring ways to assess the impact of climate change on banks’ balance sheets and overall financial stability. As climate-related events increase in frequency and intensity, this will be an important area for banks to stress test.
  • Enhanced scenario analysis: Continuous advancements in AI and data analytics are likely to lead to more sophisticated scenario analysis. This could involve better modelling of tail risks, considering a wider range of economic scenarios, and improving the granularity of stress test models.
  • Incorporating cyber risk: With the increasing frequency and sophistication of cyber threats, there is a heightened focus on integrating cyber risk into stress testing. This includes assessing the potential financial impact of cyber incidents on a bank’s operations and resilience.
  • Regulatory changes: Financial regulators may introduce new guidelines or requirements for stress testing to address evolving risks in the financial industry. Staying abreast of regulatory updates is crucial for banks to ensure compliance and effective risk management.
  • Dynamic stress testing: Traditional stress testing has often been conducted on a periodic basis. There is a move towards more dynamic and continuous stress testing, allowing banks to assess risks in real-time and respond promptly to changing economic conditions.

You can download a PDF version of this article here.

Facebook
Twitter
LinkedIn