Credit risk measurement is built around a small set of parameters that have different uses, horizons and evidential standards under accounting and regulatory capital frameworks. IFRS 9 expected credit loss models emphasise unbiased, probability-weighted, forward-looking estimation of credit losses, while internal ratings-based capital models are designed for regulatory own funds requirements and use prudential parameter definitions. The same labels, PD, LGD and EAD, can therefore refer to related but not identical constructs. Sound governance requires a clear model inventory, reconciled definitions, disciplined overrides, independent validation and management information that separates portfolio movement from model artefact.
Core concepts in credit risk measurement
Credit risk is the risk of loss arising from an obligor failing to meet contractual obligations. For banks, insurers with credit portfolios, investment firms and other lenders, the central analytical task is to estimate default likelihood, loss severity and exposure at the point of default. These estimates are used in pricing, underwriting, provisioning, capital allocation, stress testing, limit setting and performance monitoring.
The common expected loss identity is:
`Expected loss = PD × LGD × EAD`
This identity is simple, but its implementation is not. Each component depends on definition, data history, product mechanics, collateral practice, legal enforceability, macroeconomic conditions and model use. A model that is fit for IFRS 9 provisioning may not be suitable without adjustment for IRB capital, and a downturn LGD model may overstate point-in-time accounting loss if used without calibration to the relevant measurement objective.
Credit risk models should therefore be governed as a family of connected models rather than isolated tools. The design should align with broader model risk management frameworks, documented risk ownership and accountability, and board-level reporting that highlights material movements, assumptions and limitations rather than only final impairment or capital numbers.
PD, LGD and EAD
Probability of default, or PD, estimates the likelihood that an obligor or facility defaults over a defined time horizon. IFRS 9 commonly requires 12-month PD for Stage 1 assets and lifetime PD for Stage 2 and Stage 3 assets. IRB models may use one-year PDs calibrated to long-run default experience, subject to regulatory requirements.
Loss given default, or LGD, estimates the proportion of exposure that is not recovered after default. It depends on collateral values, seniority, guarantees, cure assumptions, workout costs, time to recovery and discounting. Regulatory capital frameworks may require downturn LGD concepts, whereas IFRS 9 measurement should reflect expected recoveries under probability-weighted forward-looking scenarios.
Exposure at default, or EAD, estimates the amount outstanding if default occurs. For term loans, EAD may be close to the amortised outstanding balance, adjusted for scheduled repayments and prepayments. For revolving facilities, guarantees and undrawn commitments, EAD modelling requires credit conversion factors, utilisation behaviour and contractual constraints.
IFRS 9 and IRB: related parameters, different objectives
IFRS 9 and IRB both use credit risk parameters, but they are not interchangeable without analysis. The difference is not merely presentational; it affects calibration, validation, controls and interpretation.
IFRS 9 expected credit loss is an accounting estimate. It is intended to reflect expected cash shortfalls, probability-weighted outcomes, time value of money and reasonable and supportable forward-looking information. The framework distinguishes between assets that have not experienced significant increase in credit risk, assets with significant increase in credit risk, and credit-impaired assets. The staging assessment changes the horizon of the expected credit loss estimate.
IRB capital models, by contrast, determine regulatory capital requirements subject to supervisory approval and detailed parameter rules. The Basel framework and national supervisory expectations address rating system design, default definition, data standards, calibration, conservatism, use tests and validation. The IRB estimate is therefore a prudential measure, not an accounting fair estimate of expected loss.
Point-in-time and through-the-cycle effects
A key distinction is the degree of cyclicality. IFRS 9 models usually incorporate point-in-time risk sensitivity through macroeconomic scenarios, borrower financial condition and staging. IRB PD estimates are typically calibrated to long-run average default rates, although rating assignment may contain borrower-specific current information. The precise balance between point-in-time and through-the-cycle behaviour varies by portfolio and supervisory approach.
This distinction affects management interpretation. A deterioration in IFRS 9 lifetime expected credit loss can result from macroeconomic overlays, migration into Stage 2, extension of remaining life, or borrower-level credit weakening. An increase in IRB capital requirements may reflect rating migration, exposure growth, parameter recalibration, or changes in supervisory floors and constraints. Governance should require reconciliations that explain these drivers separately.
Significant increase in credit risk
Under IFRS 9, significant increase in credit risk is a critical control point because it determines whether a financial asset remains on a 12-month expected loss basis or moves to lifetime expected loss. Institutions often use a combination of relative PD deterioration, absolute PD thresholds, days past due indicators, forbearance flags, watchlist status and qualitative credit risk indicators.
The staging framework should be tested for responsiveness and stability. Excessive stability may under-recognise deterioration, while excessive sensitivity may create volatile allowances without clear risk meaning. Overrides should be documented, approved and monitored, with outcomes reviewed by an independent function.
Framework
A robust credit risk framework links model purpose, data, methodology, validation and governance. The following structure is suitable for IFRS 9, IRB and internal risk management, although the evidential threshold and approval process will vary by use.
1. Define use and parameter scope
The first step is to document the intended use of each model. A PD model used for origination scorecards, IFRS 9 staging and IRB capital may share explanatory variables but will usually require separate calibration layers. The model inventory should distinguish obligor rating models, facility rating models, LGD models, EAD models, staging engines, macroeconomic scenario models and post-model adjustment processes.
Parameter definitions must be explicit. Default should be aligned, where relevant, with applicable regulatory definitions and internal default recognition policies. Cure rules, distressed restructuring, forbearance, days-past-due counting, connected obligors and technical defaults should be specified. Differences between accounting and capital definitions should be logged and justified.
2. Establish data lineage and representativeness
Credit risk data is often fragmented across origination, servicing, collections, collateral management, finance and regulatory reporting systems. Data lineage should trace key fields from source to model input and output. Controls should cover missing values, default date accuracy, collateral valuation dates, workout recoveries, write-off timing, limit changes and product restructuring.
Representativeness is central. Historical data may not reflect current underwriting standards, collateral policies, macroeconomic conditions or legal recovery practice. Where external data, pooled data or expert judgement is used, the institution should document relevance, limitations and compensating controls. This is particularly important for low-default portfolios such as sovereigns, banks, specialised lending and certain corporate segments.
3. Select modelling approach
PD models may use rating scorecards, logistic regression, survival analysis, transition matrices or other statistical methods. The choice should be driven by data volume, default count, portfolio heterogeneity, interpretability and validation feasibility. For regulated IRB purposes, model transparency, conservative calibration and evidence of discriminatory power are essential.
LGD models may segment by collateral type, product, seniority, loan-to-value, jurisdiction, recovery channel and time in default. EAD models commonly distinguish amortising products, revolving credit, trade finance, guarantees and cancellable commitments. For off-balance sheet products, the relationship between utilisation and credit deterioration is often a material risk driver.
4. Calibrate and apply conservatism
Calibration translates model scores or risk grades into quantitative parameter estimates. IFRS 9 calibration should align with unbiased expected credit loss, including forward-looking scenarios and discounting. IRB calibration requires attention to long-run averages, downturn conditions and supervisory margins of conservatism where data or methodology weaknesses exist.
Conservatism should be explicit rather than hidden inside opaque judgement. If data limitations require a margin, the rationale, magnitude and review trigger should be documented. This supports challenge by validation, audit and senior management.
5. Integrate governance and reporting
Credit risk models should be controlled through approval committees, change management, periodic performance monitoring and independent validation. The three lines should have distinct responsibilities, consistent with three lines in practice. The first line owns portfolio decisions and data quality; the risk function sets standards, reviews assumptions and challenges outputs; internal audit assesses framework effectiveness.
Board and committee reporting should include model performance, parameter movements, staging migration, concentration risk, overrides, post-model adjustments and validation findings. Reporting design should follow the principles in board risk reporting, particularly the need to show decision-relevant information, trend explanations and escalation points.
Worked numerical illustration
The following simplified example is illustrative and not a benchmark. It shows how different horizons and assumptions can affect expected loss.
Assume a bank holds a term loan with a current outstanding balance of 10,000,000. The facility is fully drawn. The effective interest rate is assumed to be 5 percent. For simplicity, assume EAD remains 10,000,000 over the next year and then amortises to an average lifetime EAD of 8,500,000 in later years. The base case one-year PD is 1.2 percent, LGD is 35 percent, and the asset is in Stage 1.
Stage 1 expected credit loss can be approximated as:
`12-month ECL = 1.2% × 35% × 10,000,000 = 42,000`
Now assume the borrower experiences a significant increase in credit risk due to weakened debt service metrics and adverse sector conditions. The exposure moves to Stage 2. The institution estimates marginal PDs of 2.0 percent, 2.5 percent and 3.0 percent over the next three years. EADs are 10,000,000, 9,000,000 and 8,000,000 respectively. LGD rises to 40 percent under the probability-weighted scenario set. Ignoring discounting for simplicity, lifetime expected credit loss is:
`Year 1: 2.0% × 40% × 10,000,000 = 80,000`
`Year 2: 2.5% × 40% × 9,000,000 = 90,000`
`Year 3: 3.0% × 40% × 8,000,000 = 96,000`
`Total simplified lifetime ECL = 266,000`
The increase from 42,000 to 266,000 is not solely a deterioration in one-year default risk. It reflects the move from a 12-month to a lifetime horizon, higher marginal PDs, higher LGD and the remaining exposure profile. A management report should decompose these effects. Without decomposition, senior management may misinterpret the allowance movement as a single credit quality signal.
If the same exposure is also in an IRB portfolio, the regulatory capital calculation would not necessarily use the Stage 2 lifetime PDs. It may use a one-year PD linked to a rating grade and calibrated to long-run average default experience, together with downturn LGD and applicable regulatory formulae. The accounting and regulatory results should therefore be reconciled, not forced to match.
Validation and monitoring priorities
Independent validation should test conceptual soundness, data quality, implementation, performance and ongoing use. The validation plan should be proportionate to materiality and model risk, but high materiality models require more than annual back-testing.
Discrimination, calibration and stability
PD validation usually includes discriminatory power, calibration accuracy and rating migration analysis. Common tests include observed-versus-expected default comparisons by grade, vintage and segment. For low-default portfolios, validation may require qualitative evidence, benchmarking and sensitivity analysis because statistical tests have limited power.
LGD validation should assess realised recoveries, workout timing, collateral valuation, discounting and segmentation. EAD validation should review utilisation patterns prior to default, credit conversion factors, limit management and product-specific behaviour. Monitoring should identify whether changes are driven by borrower behaviour, policy changes, collection strategy or data capture.
Implementation testing
Implementation errors can be material even when methodology is sound. Validation and controls should test data transformations, staging rules, scenario weights, discounting, model versioning, override processing and downstream journal or regulatory reporting interfaces. Parallel runs are useful when models are redeveloped or recalibrated.
Challenge of expert judgement
Expert judgement is common in credit risk models, especially for overlays, low-default portfolios, macroeconomic scenario translation and data limitations. It should be governed through clear criteria, approval authority, quantitative impact assessment and review dates. The approach should be consistent with a wider policy for governance of expert judgement.
Model risk, controls and accountability
Credit risk parameter models affect financial statements, regulatory capital and risk appetite metrics. This creates a need for strong accountability. Institutions should identify model owners, data owners, methodology approvers and business users. The control framework should address development standards, validation independence, approval gates, change control, access rights, end-user computing tools and incident management.
Post-model adjustments deserve particular attention. They may be necessary when models do not fully capture current conditions, such as changes in underwriting quality, collateral market liquidity or borrower support measures. However, persistent overlays can signal model weakness. Governance should require root-cause analysis, remediation plans and expiry conditions.
Risk appetite should connect parameter movements to credit decisions. For example, rising Stage 2 balances, higher lifetime PDs, adverse LGD trends or increased undrawn utilisation in vulnerable segments should inform underwriting, pricing, collections and concentration limits. This aligns with the principles discussed in risk appetite that actually guides decisions and credit risk governance for IFRS 9, concentration and stress.
Limitations
No credit risk model can eliminate uncertainty. Default is a rare event in many portfolios, recoveries are path-dependent, and macroeconomic relationships can change. Historical loss data may not capture future legal, behavioural, policy or collateral market conditions. Model estimates may also be affected by survivorship bias, merged obligors, incomplete recovery data and inconsistent default identification.
IFRS 9 models are sensitive to macroeconomic scenarios, scenario weights, staging rules and remaining life assumptions. A small change in significant increase in credit risk thresholds can materially alter the allowance for portfolios with long maturities. Conversely, IRB models may be constrained by regulatory floors, downturn assumptions and long-run calibration requirements, which can make them less responsive to short-term changes than management expects.
Validation also has limits. Back-testing is backward-looking, and statistical confidence may be weak where defaults are limited. Benchmarking is useful but may be distorted by different default definitions, underwriting policies and collateral practices. Sensitivity analysis and stress testing can reveal vulnerabilities, but they do not prove that a model will perform well under future conditions.
These limitations should be visible in model documentation, committee papers and board reporting. Where limitations are material, compensating controls may include conservative calibration, additional monitoring, expert review, exposure limits or restrictions on model use.
Frequently asked questions
How should IFRS 9 PD differ from IRB PD?
IFRS 9 PD should support expected credit loss measurement and normally reflects point-in-time and forward-looking information over either 12 months or the remaining lifetime. IRB PD is used for regulatory capital and is generally a one-year parameter calibrated to long-run default experience, subject to regulatory requirements. Institutions may use common data and rating systems, but they should document calibration differences and reconcile outputs.
Can one LGD model be used for both accounting and capital?
A common modelling infrastructure may be possible, but the target measure often differs. IFRS 9 LGD should estimate expected cash shortfalls under probability-weighted forward-looking conditions. IRB LGD may require downturn calibration and prudential conservatism. If one model is used with separate calibration layers, governance should demonstrate that each layer is fit for its purpose.
What evidence is needed for EAD validation?
Evidence should include observed utilisation before default, comparison of predicted and realised EAD, segmentation performance, treatment of undrawn commitments, limit changes, prepayment and amortisation assumptions, and product-specific behaviour. For low-default portfolios, validation may need benchmarking, sensitivity analysis and expert review in addition to realised default analysis.
How should management handle persistent IFRS 9 overlays?
Persistent overlays should trigger root-cause analysis. Management should determine whether the overlay reflects a temporary data gap, a macroeconomic feature not captured by the model, a portfolio shift or a structural model weakness. The overlay should have an owner, rationale, quantified impact, approval record and review date. If the issue is structural, model redevelopment or recalibration may be required.
This article is for general technical information and does not constitute accounting, regulatory, legal or investment advice.
Frequently asked questions
What should risk leaders know about core concepts in credit risk measurement?
Credit risk is the risk of loss arising from an obligor failing to meet contractual obligations. For banks, insurers with credit portfolios, investment firms and other lenders, the central analytical task is to estimate default likelihood, loss severity and exposure at the point of default. These estimates are used in pricing, underwriting, provisioning, capital allocation, stress testing, limit setting and performance monitoring.
What should risk leaders know about iFRS 9 and IRB: related parameters, different objectives?
IFRS 9 and IRB both use credit risk parameters, but they are not interchangeable without analysis. The difference is not merely presentational; it affects calibration, validation, controls and interpretation.
What should risk leaders know about framework?
A robust credit risk framework links model purpose, data, methodology, validation and governance. The following structure is suitable for IFRS 9, IRB and internal risk management, although the evidential threshold and approval process will vary by use.
What should risk leaders know about worked numerical illustration?
The following simplified example is illustrative and not a benchmark. It shows how different horizons and assumptions can affect expected loss.
What should risk leaders know about validation and monitoring priorities?
Independent validation should test conceptual soundness, data quality, implementation, performance and ongoing use. The validation plan should be proportionate to materiality and model risk, but high materiality models require more than annual back-testing.