Feature Operational Risk
Early Warning Indicators vs KRIs: How Liquidity Teams Should Use Both
EWIs and KRIs are not the same thing — even when they measure the same metric. Here's how liquidity teams should design, separate, and connect them to CFP activation and board reporting.
Table of Contents
Silicon Valley Bank failed its own internal liquidity stress tests beginning in July 2022. The triggers existed. The metrics moved. The escalation was inadequate. By March 9, 2023, a bank run that effectively ended in 40 hours had begun.
The Federal Reserve’s post-mortem confirmed that SVB’s management responded to early stress tests by increasing funding capacity — but “the funding capacity actions were not rapidly undertaken or fully executed.” That’s a description of a well-known failure mode: early warning indicators that weren’t connected to fast, mandatory, pre-specified responses.
The SVB collapse prompted a lot of institutions to rewrite their contingency funding plans. Some also rewrote their KRI dashboards. Fewer connected the two — which is exactly the gap that matters.
TL;DR
- Early warning indicators (EWIs) are operational triggers — they tell treasury and risk teams to act now. KRIs are governance measures — they tell the board and risk committee what risk looks like over time.
- The same metric can serve both purposes, but only if the thresholds, cadences, and response protocols are designed intentionally for each role.
- When EWIs and KRIs aren’t connected to CFP activation, institutions end up with stress metrics that fire but don’t trigger the responses they were designed to prompt.
- The SVB failure wasn’t a failure of measurement — the metrics were there. It was a failure of connection between early warning signals and mandatory, time-bound escalation.
The Definitional Distinction That Actually Matters
The terminology in risk management is inconsistent. “Early warning indicator,” “key risk indicator,” “risk metric,” and “trigger” are used interchangeably in documents that mean different things by each term.
Here’s the working distinction that matters for liquidity programs:
An Early Warning Indicator (EWI) is a metric monitored at an operational level, on a short reporting cycle, calibrated to prompt an immediate action when it crosses a threshold. Treasury teams, ALCO, or risk staff monitor EWIs. When one fires, the response is operationally prescribed: escalate to management, activate a CFP tier, call a liquidity committee meeting.
A Key Risk Indicator (KRI) is a metric reported to a governance body — the board, the risk committee, ALCO at its monthly meeting — that conveys whether a risk category is within appetite. KRIs aggregate trend information. They provide context. When a KRI goes amber or red, it informs a governance-level discussion, not a same-day operational action.
The critical insight: the same metric can be both. Deposit runoff rate is a treasury EWI monitored daily. It’s also a board KRI reported monthly. What changes is the reporting cadence, the audience, the threshold calibration, and the required response.
The failure is treating them as interchangeable — using a monthly board KRI as the primary trigger for operational escalation, or tracking daily EWIs that never reach governance visibility.
Why Liquidity Is the Domain Where This Matters Most
Liquidity risk has a failure mode that’s qualitatively different from credit or operational risk. Credit losses accumulate over months or quarters. Operational events are usually bounded. Liquidity can collapse in hours.
The Financial Stability Board’s research on depositor behavior documented what practitioners have observed firsthand: mobile banking and social media have eliminated the friction that used to give institutions a window to respond. A depositor in 2025 doesn’t need to visit a branch to move money. A social media post with 10,000 shares can move a deposit base before compliance is in the office.
This speed requirement is why the EWI / KRI design distinction matters more in liquidity than almost any other risk domain. A KRI that informs the board in the next monthly report is structurally incapable of serving as a trigger for same-week operational action. Conflating them in a liquidity program isn’t just an aesthetics problem — it’s a safety problem.
The Comparison: How Five Metrics Function Differently
| Metric | As an EWI | As a KRI |
|---|---|---|
| Deposit runoff rate | Monitored daily; amber if >5% in 7 days; triggers ALCO notification | Reported monthly; amber if >8% trailing 30 days |
| Contingent funding line utilization | Checked weekly; yellow if >30%; red if >50% prompts CFP activation review | Reported quarterly; shows trend across 4 reporting periods |
| Wholesale funding renewal rate | Tracked at each funding event; red if <70% in a 30-day window | Reported monthly as % of prior month renewal rate |
| Uninsured deposit concentration | Weekly monitoring with daily trigger during elevated stress | Quarterly board KRI vs. policy limit (e.g., <50%) |
| Collateral availability ratio | Checked before any funding action; operational decision gate | Monthly ALCO metric showing available vs. pledged assets |
None of these metrics change by being categorized one way or the other. What changes is who receives them, when, and what the protocol requires when they move.
The CFP Activation Bridge
The mechanism that should connect EWIs to board KRIs is the CFP trigger framework. Every contingency funding plan should specify:
Normal tier: All EWIs green. KRIs reported on standard schedule. No exceptional action required.
Elevated monitoring tier (Yellow): One or more EWIs have crossed the yellow threshold. ALCO is notified. Liquidity committee convenes within 5 business days. KRI dashboard updated to amber. Board notified at next scheduled meeting unless escalation criteria require earlier notification.
Contingency tier (Amber/Orange): Multiple EWIs at yellow or one at red. CFP activated. Pre-specified funding sources queued. Daily liquidity monitoring. Board KRI moves to red. Ad hoc board notification within 24-48 hours depending on severity.
Activated CFP (Red): CFP fully activated. Funding sources drawn. Regulatory notifications per applicable guidance. Board informed immediately.
The weakness in most CFP designs isn’t in the tier descriptions — it’s in the failure to specify which EWIs trigger which tier. Vague trigger language like “deteriorating liquidity conditions” requires management judgment at exactly the moment when judgment is most stressed. Pre-specified EWI thresholds remove that ambiguity.
See Contingency Funding Plan Triggers: How to Set Liquidity Thresholds You Can Defend to Regulators for the methodology on setting defensible CFP threshold values.
The SVB Design Problem — Lessons for EWI/KRI Programs
The Federal Reserve’s SVB review is specific about the failure mode. SVB was repeatedly failing its internal liquidity stress tests from July 2022. Management’s response — increasing funding capacity — was directionally correct but operationally inadequate. The capacity increases happened too slowly and weren’t fully executed by the time the March 2023 run began.
MIT Sloan’s analysis of SVB’s liquidity risk mismanagement frames the core issue as an extreme maturity mismatch — short-term, unstable, uninsured deposits funding long-term HTM investments — that was neither adequately hedged nor adequately monitored through EWIs calibrated to its speed of failure.
The implication for program design: an EWI that fires and generates a management memo is not the same as an EWI that fires and triggers a mandatory pre-specified response within 24 hours. The former is documentation. The latter is a control.
Three Common EWI/KRI Design Failures
1. EWIs that escalate to nobody. The metric is being tracked. It crosses the threshold. An email is sent. The recipient is busy. Nothing happens within the required window. This is a governance failure disguised as a risk management program.
2. Board KRIs that arrive too late to matter. If the board sees deposit runoff rate in a monthly KRI deck and it’s already at 12%, the operating team has had a problem for weeks. Board KRIs need to be informed by the EWI history — which means the EWI data and the board KRI data have to feed from the same source and tell a connected story.
3. Thresholds calibrated once and never revisited. Deposit runoff rate of 5% in 7 days might be an appropriate yellow threshold for a $200M community bank with stable core deposits. It’s inadequate for a fintech with a large concentration in uninsured tech-sector deposits. Threshold calibration should account for the institution’s specific deposit composition, funding mix, and the speed at which its depositor base can realistically move. The OCC Spring 2025 Risk Perspective flagged deposit competition and unrealized investment losses as ongoing monitoring priorities — both require institution-specific threshold calibration, not benchmark copying.
What a Connected EWI/KRI Program Looks Like
A program that successfully integrates both will have:
- An EWI register with each metric defined, owner assigned, threshold specified, monitoring cadence documented, and escalation protocol written
- A KRI dashboard that shows the same core metrics in trend form for governance audiences
- A CFP trigger mapping that explicitly lists which EWI thresholds activate which CFP tiers
- A reporting bridge — whether a paragraph in the ALCO package or a dedicated liquidity update — that translates EWI status into the context board members need for risk oversight
- Tested escalation paths — not assumed ones. Tabletop exercises should confirm that when an EWI fires, the right people are notified within the right window
For a structured set of pre-built liquidity KRIs with threshold guidance — including deposit runoff rate, wholesale renewal, contingent line utilization, and more — see our Liquidity KRIs for Fintech and Banking Teams guide.
For broader KRI design — including the leading versus lagging distinction that applies beyond liquidity — see Leading vs Lagging KRIs: Which Metrics Actually Warn You Early.
So What Does This Mean for Your Program?
If your liquidity program has EWIs and KRIs but they’re designed by different teams, reported to different audiences, and not connected to CFP activation, you have measurement without control. The metrics exist, but the response protocol doesn’t.
The fix isn’t adding more metrics. It’s connecting the ones you have — through documented thresholds, explicit CFP tier mapping, and tested escalation paths that specify who acts, what they do, and how fast.
The regulators who came through post-SVB weren’t primarily asking “what metrics do you track?” They were asking “what happened the last time a metric fired, and what did you do?”
That’s the question your EWI/KRI design should be built to answer.
If your liquidity KRI program needs pre-built metrics with thresholds calibrated for financial services — covering deposit concentration, runoff rates, wholesale funding, collateral, and more — the KRI Library (132 Key Risk Indicators) includes the financial risk domain with green/amber/red thresholds, data source mapping, and escalation triggers ready to deploy. Get the KRI Library →
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is the difference between an early warning indicator and a KRI?
Can the same metric be both an EWI and a KRI?
Why is it a problem if EWIs and KRIs are designed separately?
What should connect EWIs to CFP activation?
How often should liquidity EWIs be monitored vs KRIs?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Operational Risk
Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map
Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.
Jul 23, 2026
Operational Risk
FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.
On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.
Jul 21, 2026
Operational Risk
3,383 Incidents Later: What DORA's First ICT Data Reveals About Your Operational Risk Program
The ESAs published their first DORA ICT incident report in June 2026 — 3,383 major incidents, nearly one-third from third-party failures, only 10% cyber-related. Here's what the data means for your operational risk program.
Jul 16, 2026