VRM 6: Measuring Credit Risk
Losses have to land somewhere, and in a bank they land on equity capital first. A bank carrying equity capital of USD 5 billion that suffers losses of USD 1.5 billion is left with USD 3.5 billion. Should losses run far enough for equity to turn negative, the bank is insolvent. Equity is called going concern capital for that reason: while it remains positive the institution is still a going concern. Debt capital sits behind it and is called gone concern capital, since it starts protecting anybody only once the bank has already failed.
Debt capital ranks below deposits almost without exception, so in principle the debt holders absorb losses before depositors feel anything, and deposit insurance stands behind the depositors again. In the United States the Federal Deposit Insurance Corporation protects deposits up to USD 250,000 if a bank defaults.
Two different questions about the same number
Economic capital is the bank’s own estimate of how much capital its business requires. Regulatory capital is the amount supervisors insist it holds. Both are calculated separately for credit risk, market risk and operational risk. On the regulatory side the three components are added together. On the economic side a bank will often allow for the correlations between those categories, which pulls the total below a straight sum.
Global standards come from the Basel Committee on Banking Supervision in Switzerland, and each member country implements them through its own supervisor. The committee was formed in 1974 by the central banks of the G10 countries, at a point when banks were competing internationally while their transactions grew more complicated. A common credit risk regime followed in 1988, now called Basel I. Market risk capital was added in 1996, Basel II was proposed in 1999, and the two decades to 2019 brought its implementation along with Basel 2.5 and Basel III.
The Basel II credit risk rules still sit underneath the modern calculation. They offer a standardized approach, which leans on credit ratings and similar metrics, and an internal ratings-based approach, usually shortened to IRB. The IRB approach rests on work by Vasicek (1987) and Gordy (2003), and it is the one developed here.
Start with the comfortable case. Suppose a bank holds 100,000 loans, each with a 1% chance of going bad during the year, and the outcomes are independent. Defaults would cluster tightly around 1,000 every year, and the chance of the annual count passing 1,100 would be under 0.1%. A spreadsheet confirms it: BINOM.DIST(1100, 100000, 0.01, TRUE) returns 0.9992. Under independence the default rate on a large book is practically a constant, and credit risk capital would be an administrative matter.
Reality does not behave that way. Annual percentage default rates across all rated companies over 1981-2018 span 0.14%, recorded in 1981, up to 4.19%, recorded in 2009: a spread of roughly thirty to one. Their mean is 1.443% and their standard deviation is 0.984%, so the year-to-year variation is close to seven tenths of the average level itself. Good years and bad years are the pattern, not noise around a fixed rate.
The economy is the shared driver
Most of that variation traces back to economic conditions, which no bank and no bond holder can diversify away. Strong conditions in the run up to and during a year push down the default probability of every borrower at once; weak conditions push them all up together. The two extremes fit that reading, since conditions were favourable going into 1981 while 2009 sat at the end of a severe crisis.
Credit contagion adds a second channel
Trouble also travels along commercial links. Imagine Company A buying goods from Company B, which buys in turn from Company C. Bankruptcy at Company A damages Company B, and if enough of Company B trade ran through that relationship it may fail as well, dragging Company C down even though Company C never dealt with Company A. How much this matters outside finance is arguable. Inside the banking system it worries supervisors a great deal, because a failure at one bank can inflict large losses on the banks holding over-the-counter derivatives positions with it, and those losses propagate again. That is systemic risk, the risk of the whole financial system collapsing, and it is a separate idea from systematic risk, which is the market-wide risk created by the ups and downs of the economy.
Expected loss is the average credit loss over a year, built from three quantities. The probability of default, written PD, is the chance the borrower fails during the period. Exposure at default, written EAD, is the amount owed when that happens. Loss given default, written LGD, is the fraction of the exposure not recovered, so it equals one minus the recovery rate.
A bank treats expected loss as a cost of doing business rather than a risk, and recovers it in the interest rate it quotes. Take a portfolio with an expected default rate of 1.5% and a recovery rate of 40%. The expected loss rate is 0.9%, which is 0.6 multiplied by 1.5%. If the bank also needs a margin of 1.6% to cover the expense of managing and administering the loans, the two together demand 2.5%. Add an average funding cost of 1% and the rate charged has to be 3.5%.
Unexpected loss is what pricing cannot handle
Actual losses never come in at the expected figure. In some years they fall short of 0.9% and in others they overshoot it, and the amount by which a year exceeds the average is the unexpected loss. Interest income cannot absorb that, because the pricing was set for the average. Capital absorbs it instead, which is why unexpected loss is what a capital calculation is aimed at.
A bank makes a single loan of USD 1 million. The probability of default over one year is 0.5% and the recovery rate is estimated at 40%.
The distribution of credit losses over a year is nothing like a normal curve. Losses cannot be negative, since a loan that performs simply pays as agreed, so the left side is packed against zero. On the right there is no natural stopping point, because a bad enough economy can put a large slice of the book into default at once. The result is a curve with most of its weight low down, a long thin right tail, and a mean above the most likely outcome.
Fitting a curve to the record
A lognormal distribution gives a workable fit to the historical default rates, meaning the natural logarithm of the annual rate is treated as normal. Converting the observed percentages to decimals and taking logarithms puts the distributional mean at -4.458, with 0.699 as the spread on that log scale. Percentiles then follow from the inverse cumulative normal. At the 99.9 percentile the log-scale value is -4.458 + (3.09 × 0.699) = -2.298, and the default rate itself is around 10.05%, since that is exp(-2.298). Running the same arithmetic at the 99.98 percentile gives around 13.76%.
Set those against a mean default rate of 1.443% and the shape of the problem is visible. A one-in-a-thousand year is about seven times an average year, and a one-in-five-thousand year is closer to ten times. The standard deviation of 0.984% gives no hint of that, and a capital number built from the mean plus a few standard deviations would fall badly short.
Credit value at risk is the loss on the portfolio that will not be exceeded over a one-year horizon at a stated confidence level, the X percentile marked in Figure 1. Since the interest charged already covers the mean, the capital requirement is credit value at risk less expected loss, and that difference is the unexpected loss the bank must absorb.
Choosing X
For regulatory capital under the internal ratings-based approach the Basel Committee fixes X at 99.9%, wanting credit risk capital to be enough in all but one year in a thousand. Banks setting economic capital go further, because their target is a credit rating rather than a supervisory minimum. An AA-rated corporation defaults with a probability of about 0.02% over one year, so a bank seeking acceptance as AA must show a 99.98% probability of surviving, and setting X at 99.98% delivers capital theoretically sufficient in 4,999 years out of 5,000.
A bank holds a loan portfolio whose risk matches the average rated company, so the fitted lognormal from the previous section applies: default rates of 10.05% at the 99.9 percentile, 13.76% at the 99.98 percentile, and a mean of 1.443%. Recovery rates fall when default rates are high, so a recovery rate of 25% is assumed at these extremes and at the mean.
Two cautions travel with a calculation of this kind. The recovery rate assumed in an extreme year should arguably be lower than the one used for an average year, since defaults and recoveries move against each other. And the exercise assumes the bank lends to a cross-section resembling all rated companies, which very few banks do.
The first of the three models works upward from the individual loans. Write L for the amount borrowed, p for the probability of default over the year and R for the recovery rate, all treated as fixed. If the borrower defaults the lender loses L(1 – R), and otherwise loses nothing. Only two outcomes exist, so the loss on one loan follows a binomial distribution with a single trial.
For the standard deviation, the squared loss equals the square of L(1 – R) with probability p and zero otherwise. Subtracting the square of the mean from that expected square leaves a variance of (p – p2) multiplied by the squared loss amount.
Individual standard deviations combine into a portfolio figure through the correlations between the losses. Writing the correlation between losses on loans i and j as rho, with rho equal to one when i equals j, the portfolio standard deviation is the square root of the double sum below. Dividing by the total amount lent expresses the answer as a standard deviation of the percentage loss, written alpha.
Three loans of USD 1 million each carry the same terms as the loan in Example 1: a default probability of 0.5% and a recovery rate of 40%. The correlation between the losses on any pair of them is 0.2.
Simplify the portfolio so every loan is the same size L, carries the same default probability p and the same recovery rate R, and every pair of losses has the same correlation rho. The double sum then collapses. There are n diagonal terms and n(n – 1) off-diagonal terms, each of the latter scaled by rho, and the percentage loss standard deviation reduces to a single expression.
Two regimes hide inside that formula. With rho at zero it becomes sigma divided by L times the square root of n, which falls away to nothing as the book grows: a granular portfolio of independent loans carries almost no loss uncertainty. With rho above zero the numerator also grows roughly as the square root of n, the two square roots cancel, and alpha settles onto a floor of sigma times the square root of rho, divided by L. Adding the ten-thousandth loan to a correlated book buys almost nothing.
| Number of loans | alpha if rho = 0 | alpha if rho = 0.15 | Ratio of the two |
|---|---|---|---|
| 10 | 3.099% | 4.751% | 1.5 |
| 100 | 0.980% | 3.902% | 4.0 |
| 1,000 | 0.310% | 3.806% | 12.3 |
| 10,000 | 0.098% | 3.797% | 38.7 |
Source: computed from the formula above. Each loan has a standard deviation of USD 0.196 million, and the correlated column approaches its floor of 3.796%.
A concentrated portfolio fails on the other axis. Where a handful of large loans make up the book, n is small and the borrower-specific component never washes out, so one failure moves the total. Both problems raise capital, and the models that follow assume a granular book, leaving supervisors to add a separate charge for concentration.
A high percentile of portfolio loss needs the joint distribution of the individual outcomes, not just their separate distributions. That is straightforward when everything involved is normal, since a bivariate normal with a chosen correlation does the job. Default is binary, so nothing here is normal, and there is no obvious way to write a sensible joint distribution for two such variables directly.
The Gaussian copula sidesteps the problem by changing the variables rather than the method. Suppose the distributions of two quantities V1 and V2 are known. Each is mapped onto a standard normal variable, U1 and U2, percentile by percentile. The one-percentile point of V1 becomes the one-percentile point of the standard normal, which is -2.326. The five-percentile point of V1 becomes -1.645. The same treatment is applied to V2, and the correspondence continues across the whole range.
With both variables transformed, U1 and U2 are assumed bivariate normal with a particular correlation, and that assumption fixes their joint distribution. Because each mapping runs one to one, the joint distribution of the original pair follows unambiguously as well. The correlation specified is between the transformed variables, not the raw quantities, and in credit risk capital work the Basel Committee sets the number to use.
Other copulas exist and differ mainly in tail correlation, the chance of both variables hitting extreme values at the same moment. The Gaussian copula carries relatively little of it, so relatively large correlation estimates are needed to fit market data. Before the crisis of 2007-2009 it was widely used to model default correlation across mortgages, and the criticism afterwards was precisely that it understated tail correlation.
The Vasicek model is what bank supervisors use to set capital for loan portfolios, and its appeal is that the high percentile of the loss distribution comes out analytically rather than from a simulation. Assume every company in a large portfolio shares the same probability of default, PD. Each borrower’s binary default outcome is mapped onto a standard normal variable U as just described, with the far left tail standing for default. Borrower i defaults when U falls to or below the inverse cumulative normal of PD. At a PD of 1% that threshold is -2.326, so values below -2.326 mean default and values above it mean no default.
To make the portfolio tractable, all the coefficients are set equal, so U equals aF plus the square root of one minus a squared multiplied by Z, and the correlation between any pair of transformed variables is a squared. Write that correlation as rho.
Now fix the economy at a particular value of F. Conditional on that value, each U is normal, centred at aF, with the square root of one minus a squared for its spread, and the borrowers default independently. In a large portfolio the realised default rate then equals the conditional probability that U sits below the threshold.
A high F means a healthy economy, every U is pulled upward, and few borrowers cross the threshold. A low F pulls them all down together and defaults multiply. The bad year the capital calculation is aimed at is a very low value of F, and for a 99.9% standard that value is the inverse cumulative normal of 0.001.
Substituting the worst value of the economic factor into the conditional default rate produces the percentile the supervisors want. Since the standard normal is symmetric, the inverse cumulative normal at 0.001 is the negative of the value at 0.999, and rewriting it that way removes the minus signs.
This converts an average default probability into a default rate that should, in theory, be exceeded only once in a thousand years. When rho equals zero the expression collapses back to PD itself, which is what a large portfolio of independent borrowers gives, since the law of large numbers holds the realised rate at its mean.
| PD | rho = 0.0 | rho = 0.2 | rho = 0.4 | rho = 0.6 | rho = 0.8 | Multiple of PD at rho = 0.2 |
|---|---|---|---|---|---|---|
| 0.1% | 0.1% | 2.8% | 7.1% | 13.5% | 23.3% | 28.0 |
| 0.5% | 0.5% | 9.1% | 21.1% | 38.7% | 66.3% | 18.2 |
| 1% | 1.0% | 14.6% | 31.6% | 54.2% | 83.6% | 14.6 |
| 1.5% | 1.5% | 18.9% | 39.0% | 63.8% | 90.8% | 12.6 |
| 2% | 2.0% | 22.6% | 44.9% | 70.5% | 94.4% | 11.3 |
Source: worst case default rates as tabulated in the chapter, arranged with PD down the rows. The final column is a ratio calculated here for comparison.
Both drivers push the same way. Raising PD raises the worst case rate, and raising rho raises it far more sharply, since a higher correlation means a bad economy takes a larger share of the book down at once. The final column shows the second pattern from another angle: the worst case is a much bigger multiple of PD for high quality borrowers, so a book of very safe loans still needs capital out of all proportion to its average loss.
Reading one cell out of the table
Take the entry for an average default probability of 1.5% and a correlation parameter of 0.4. The inverse cumulative normal of 0.015 is -2.1701, the square root of 0.4 is 0.6325, and the inverse cumulative normal of 0.999 is 3.0902, so the second term in the numerator is close to 1.9545. Adding that to -2.1701 leaves roughly -0.2156 on top, while the denominator is the square root of 0.6, or 0.7746. Carrying full precision through the division gives -0.2784, and the cumulative normal of -0.2784 is 39.0%. A book expected to lose 1.5% of its borrowers in an average year can lose 39.0% of them in a one-in-a-thousand year.
Take a portfolio in which every loan shares a default probability, a correlation, a loss given default and a principal amount. The Basel II capital requirement for a bank on the internal ratings-based approach is then written directly in terms of the worst case default rate.
The logic underneath is the credit value at risk calculation from earlier. WCDR multiplied by LGD is the loss rate at the 99.9 percentile, and multiplying by EAD turns it into a loss amount, which is credit value at risk. PD multiplied by LGD multiplied by EAD is expected loss. Subtracting the second from the first leaves the unexpected loss at a 99.9% confidence level, and that is the capital.
Real portfolios are not homogeneous, and Gordy showed the one factor model extends sensibly to a mixed book. Each loan is treated on its own terms and the results added, so a bank can compute capital loan by loan without ever building a portfolio correlation matrix.
Some loan types attract a maturity adjustment factor on top, recognising that a loan running beyond one year can lose credit quality without anybody defaulting. The correlation rho is not estimated by the bank at all: Basel II specifies what to assume in each situation. Banks on the IRB approach supply their own PD estimates, while EAD and LGD come either from the Basel II rules or from the bank’s own models, depending on what the supervisor has approved. One caution on vocabulary: the Vasicek correlation is between the normal distributions the binary default outcomes were mapped onto, and it is a larger number than the correlation between those binary outcomes.
A loan book of USD 100 million carries a PD of 0.75% and a correlation parameter of 0.2. On default, the recovery rate is 30%.
CreditMetrics is the third model, and the one banks reach for when setting economic capital rather than meeting a regulatory minimum. Every borrower carries a credit rating, external or internal, and a one-year transition table describes how ratings move. The portfolio is valued at the start of the year. A Monte Carlo simulation then runs the year many times over, drawing each borrower’s closing rating, revaluing the portfolio at those ratings, and recording the opening value minus the closing value as that trial’s credit loss. Collecting the results builds the whole loss distribution, and economic capital is a high percentile of it less expected loss.
Turning a transition table into sampling rules
Suppose a bank works with four categories: A, B, C and default. The transition probabilities for a borrower currently rated B are given below, alongside the ranges of a standard normal draw that reproduce them.
| Outcome | Probability | Cumulative | Range of the standard normal sample |
|---|---|---|---|
| Upgraded to A | 0.05 | 0.05 | Less than -1.645 |
| Stays at B | 0.80 | 0.85 | Between -1.645 and 1.036 |
| Downgraded to C | 0.13 | 0.98 | Between 1.036 and 2.054 |
| Defaults | 0.02 | 1.00 | Greater than 2.054 |
Source: transition probabilities and sample ranges as set out in the chapter. The cumulative column is added here to show where the cut-offs come from.
The cut-offs are the inverse cumulative normal of the cumulative probabilities: -1.645 at 0.05, 1.036 at 0.85 and 2.054 at 0.98. Note that the ordering here runs the opposite way to the Vasicek convention, where the left tail meant default; only the widths of the four ranges matter, and they reproduce the four probabilities exactly.
Sampling comes from a normal distribution rather than a uniform one so that correlation can be built in. A factor model links the normal variables across borrowers, which makes the simulation an implementation of the Gaussian copula: each borrower’s rating transition distribution is transformed to a normal, and the correlations are imposed on the transformed variables. Those correlations are often taken from returns on traded equities, an approach Merton’s model supports, since there a company defaults once the market value of its assets drops below the book value of its debt.
What separates CreditMetrics from the other two models is that downgrades cost money. A borrower falling from B to C in a trial is discounted at a higher rate at the year end, the loan is worth less, and the bank books a credit loss with no default anywhere in sight.
Knowing the risk of a portfolio is not the same as knowing which positions created it. Risk allocation answers the second question, and a result of Leonhard Euler splits many risk measures into per-position contributions that add back to the total. It applies to homogeneous functions, meaning functions with the property that multiplying every input by a constant multiplies the output by that same constant.
Scale every position in a portfolio by a constant and a risk measure normally scales by the same constant, so most of the measures used in practice qualify. Define the contribution of position i as the change in the risk measure caused by a small change in that position, divided by the proportional size of the change. Euler showed that in the limit these contributions sum to the risk measure itself.
Loan 1 has a loss standard deviation of 1.1, while Loan 2 and Loan 3 each have 0.9. Loan 1 is uncorrelated with the other two. Between the losses on Loan 2 and Loan 3 the correlation is 0.7.
The allocation says something the standalone numbers do not. Loan 1 has the largest standard deviation of the three and the smallest contribution to the total, because it is uncorrelated with the rest of the book and so adds less to portfolio risk than the two loans that move together.
Loans are not the only source of credit risk. A company buying an option is exposed to the writer failing to pay when the option comes good, and a company in an interest rate swap takes a credit loss if the counterparty defaults while the swap is worth something positive. The additive capital formula covers derivatives too, but two features make it awkward to apply.
The first is exposure at default. On a loan, EAD is broadly the amount advanced or expected to be advanced. On a derivative the exposure changes every day as the contract moves in and out of the money, so there is no principal to point at. The Basel Committee’s standard rules handle this by setting EAD at the current exposure, plus an add-on. Current exposure is the most that could be lost if the counterparty defaulted today, and the add-on allows for the exposure worsening before a default actually arrives.
The second is netting. Derivatives with a single counterparty are usually covered by a netting agreement, which means that on default the whole set is treated as one contract. Capital cannot be computed trade by trade under those conditions, so the calculation has to run counterparty by counterparty.
Estimates that resist estimation
PD comes in two flavours and a bank has to produce both. A through-the-cycle PD averages across an economic cycle, and supervisors require it for regulatory capital, reasoning that point-in-time numbers would make capital swing with the cycle and amplify it. Accounting standards including IFRS 9 pull the other way, requiring expected losses to be deducted from the carrying amount of a loan, which needs a point-in-time estimate. Regulators and auditors want different numbers on the same book.
Recovery rates are negatively correlated with default rates, so a downturn hurts twice over: more borrowers fail and less is recovered from each one. Exposure at default has its own difficulties, and on an overdraft or a line of credit the prudent assumption is the full limit, since a customer heading for trouble is likely to have drawn it all down. A term loan is easier, being the expected principal during the year, while a book of derivatives needs a full modelling exercise. Wrong-way risk sits behind all of it, the tendency for a counterparty to be more likely to fail exactly when the position is valuable to the bank.
Correlations are the hardest input of all. The Gaussian copula is convenient, but nothing guarantees it describes loan losses in a one-in-a-thousand-year scenario, still less at the more extreme levels economic capital targets. Credit risk is also only one of the exposures a bank runs alongside market risk, operational risk, liquidity risk and strategic risk. Different teams own them, they are not independent, and they interact in ways that shape both capital totals.