Feature Operational Risk
Contingency Funding Plan KRIs: Metrics That Should Trigger CFP Activation
Most CFPs have a trigger section. Most trigger sections are too vague to actually fire. Here's how to build contingency funding plan KRIs that activate the right tier at the right time — with evidence artifacts regulators will accept.
Table of Contents
You have a contingency funding plan. It has an activation section. That section says something like: “The CFP will be activated when management determines that liquidity conditions have deteriorated to a level requiring emergency funding measures.”
That sentence is not a trigger. It’s a description of a judgment call — and a judgment call under stress is exactly what the CFP is supposed to replace with something faster and more reliable.
The July 2023 interagency addendum to the Interagency Policy Statement on Funding and Liquidity Risk Management — issued jointly by the OCC, Federal Reserve, FDIC, and NCUA — was direct about what it found in the CFPs it reviewed: plans that existed on paper but weren’t actionable in practice. The post-SVB supervisory review revealed institutions whose CFPs lacked pre-specified, threshold-bound triggers and who couldn’t demonstrate that contingent funding sources had been tested and verified.
TL;DR
- Most CFPs have activation language that describes a management judgment call, not a pre-specified trigger. That’s the design gap.
- CFP KRIs should specify: the exact metric, the threshold value at each tier, who receives notification within what timeframe, and what action is required — not just “management will review.”
- The OCC, FDIC, and Federal Reserve’s 2023 guidance update explicitly emphasizes testing, operational readiness verification, and actionable threshold design after the SVB and Signature Bank failures.
- Thresholds must be calibrated to your institution’s funding composition — not to industry averages or copied from peer institutions.
- Evidence artifacts matter: monitoring records, board minutes, testing documentation, and counterparty contact verification are what examiners look for when they pull the CFP.
Why Most CFP Triggers Fail Under Pressure
A well-designed CFP activation trigger answers five questions before stress arrives:
- What metric? Specifically named, with a data source and responsible owner.
- What threshold? Numerical values at each tier, not qualitative descriptions.
- Who acts? Named role or function, not “management.”
- Within what timeframe? Hours, not “promptly.”
- What is the required action? Specific operational step, not “review the situation.”
When those five elements aren’t present, the CFP activation section becomes a committee memo — not a funding control. The February 2023 Silicon Valley Bank failure is the most-cited example. SVB’s stress tests were showing adverse results by mid-2022. The Federal Reserve’s supervisory review documented that management response to those signals was “not rapidly undertaken or fully executed.” The trigger fired. The escalation was inadequate. The gap between signal and response was fatal.
What SVB’s experience illustrates — and what the 2023 interagency addendum responded to — is that CFP KRIs must be designed for automatic, mandatory escalation. Not for informed discretion.
The CFP Tier Structure and What Activates Each Stage
Most defensible CFPs use three to four activation stages. The KRIs that activate each stage should be documented explicitly in the CFP document itself — not in a separate risk dashboard that exists independently.
Stage 1 — Normal Operations All liquidity KRIs are green. Standard monitoring cadence (typically weekly ALCO review of liquidity position). No elevated actions required.
Stage 2 — Elevated Monitoring One or more KRIs breach amber thresholds. Enhanced monitoring frequency (daily), pre-positioning of contingent funding sources, ALCO notification, management liquidity review. No public communication required.
Stage 3 — Stressed Operations One or more KRIs breach red thresholds. Active funding response: drawing contingent lines, contacting counterparties, accelerating asset sales if applicable. Board and relevant regulators notified per your institution’s notification policy.
Stage 4 — Crisis / Activated CFP fully activated. Emergency funding in use. Regulatory notification triggered (FFIEC 36-hour notification may apply for institutions meeting the criteria). Daily executive reporting. Communications to key depositors and counterparties as appropriate.
The transition between stages should not require a management meeting to decide. Each threshold breach should have a pre-specified, mandatory response that begins without convening a committee first.
Core CFP KRIs: What to Monitor at Each Tier
The following KRIs reflect the most commonly cited liquidity stress signals from the 2023 interagency guidance, SVB post-mortems, and regulatory exam findings. Thresholds are illustrative — your institution must calibrate these to its specific funding composition.
Deposit Runoff Metrics
| KRI | Metric Definition | Green | Amber | Red | Owner | Tier Triggered |
|---|---|---|---|---|---|---|
| Uninsured deposit runoff (7-day) | Uninsured deposits departed ÷ opening uninsured balance, rolling 7 days | <2% | 2–5% | >5% | Treasury | Amber → Stage 2; Red → Stage 3 |
| Total deposit runoff (30-day) | Total deposit decline ÷ total deposits, rolling 30 days | <3% | 3–7% | >8% | Treasury / ALCO | Amber → Stage 2; Red → Stage 3 |
| Large depositor withdrawal activity | Balance declines >10% at top-25 depositor accounts | None | 2+ accounts in 30 days | 4+ accounts or any single account >5% of total deposits | Treasury | Amber → Enhanced monitoring; Red → ALCO convenes within 48 hours |
Deposit runoff is the fastest-moving CFP signal. The FDIC’s post-2023 guidance specifically noted that traditional runoff assumptions embedded in CFPs were based on historical averages that don’t reflect the behavioral characteristics of digitally-enabled depositors. Monitor runoff at the segment level — by depositor type, by product, by channel — not just in aggregate.
Contingent Funding Capacity Metrics
| KRI | Metric Definition | Green | Amber | Red | Owner | Response at Each Tier |
|---|---|---|---|---|---|---|
| FHLB advance utilization | Outstanding FHLB advances ÷ total pre-approved capacity | <30% | 30–55% | >60% | Treasury | Amber: Verify collateral pledging status; Red: CFO notified, ALCO convenes |
| Contingent credit line utilization | Used ÷ total committed contingent credit capacity (all sources) | <25% | 25–55% | >60% | Treasury / CFO | Amber: Contact counterparties to confirm availability; Red: Stage 3 activation |
| Unsecured wholesale funding rollover | % of unsecured wholesale funding maturing in next 30 days successfully renewed | >95% | 85–95% | <85% | Treasury | Amber: Management notification within 24 hours; Red: Immediate ALCO call |
The interagency guidance addendum specifically flagged that institutions often list FHLB advance capacity or Fed discount window as contingent sources without verifying that collateral has been pledged, that the operational access steps are understood by current staff, and that capacity estimates remain current. The KRI isn’t just about utilization — it’s about confirmed, tested availability.
Liquidity Coverage and Quality Metrics
| KRI | Metric Definition | Green | Amber | Red | Owner | Response |
|---|---|---|---|---|---|---|
| HQLA coverage ratio | HQLA balance ÷ estimated 30-day net cash outflow | >130% | 115–130% | <115% | Treasury / ALCO | Amber: Management review; Red: Stage 2-3 depending on trajectory |
| Collateral availability | Unencumbered eligible collateral ÷ total contingent borrowing needs | >150% | 120–150% | <120% | Treasury | Amber: Monthly validation; Red: Immediate inventory and pledging review |
| Brokered / wholesale funding dependency | Brokered + wholesale funding ÷ total funding | <20% | 20–35% | >35% | ALCO / Risk | Amber: Board notification at next meeting; Red: ALCO convenes within 48 hours |
For institutions that are not subject to the full LCR rule (generally applies to banks over $10 billion), internal equivalent metrics that capture the same ratio — available liquid assets versus projected stress outflows — are expected to be part of the CFP.
Early Stress Signals: Pre-Activation KRIs
Some institutions run a set of leading indicators specifically designed to fire before any formal CFP tier transitions occur. These aren’t activation triggers in themselves — they’re warnings that the monitoring frequency should increase.
| Signal KRI | What It Measures | Monitoring Response |
|---|---|---|
| Counterparty credit line confirmation gap | Days since contingent credit lines were last confirmed (by phone or written contact) with counterparties | If >60 days: treasury to initiate confirmation contact |
| Collateral pledging status gap | Days since collateral pledging has been verified operationally (not just on paper) | If >90 days: treasury to verify pledged collateral, confirm updated valuations |
| Stress test assumption age | Days since CFP run-off assumptions were reviewed against current deposit composition | If >180 days or significant composition change: trigger assumption review |
| Peer/market stress monitoring | Published reporting of peer institution stress events (runs, downgrades, liquidity events) | Qualitative trigger: if peer events involve depositor segments similar to yours, move monitoring to daily |
These pre-activation KRIs won’t appear on a board dashboard — they’re operational signals for treasury. But they should be documented in the CFP so there’s a clear record of the monitoring cadence and the triggers that escalate it.
Calibrating Thresholds to Your Funding Composition
The threshold values in any example table — including the ones above — are illustrative. Using them without calibration to your institution’s actual funding profile is the same mistake as copying a peer institution’s CFP language without adapting it to your funding mix.
Threshold calibration should begin with historical stress data:
What happened during the 2020 COVID shock? How quickly did deposits move? What was the maximum 7-day runoff rate you experienced? Where did you end up in terms of FHLB utilization? If you didn’t have a stress event, use peer data from public supervisory reports.
What do your stress tests show? If your own modeling produces a scenario where uninsured deposit runoff exceeds 4% in 7 days before management response time allows action — your amber threshold needs to be lower than 4%.
What’s the composition of your deposit base today? If your deposit composition has shifted significantly since your last calibration — new fintech partnerships, a product launch that brought in institutional depositors, geographic expansion — your runoff assumptions are wrong for your current book.
See Contingency Funding Plan Triggers: How to Set Liquidity Thresholds You Can Defend to Regulators for a detailed walkthrough of the calibration methodology, including how to use your own stress test results to set defensible amber/red thresholds.
Evidence Artifacts Regulators Look For
A CFP with well-designed KRIs needs corresponding evidence that the monitoring actually happened and that the thresholds weren’t just aspirational. Examiners reviewing the CFP will typically request:
Monitoring records: Historical KRI tracking showing the metrics were actually measured on the specified cadence. A weekly ALCO liquidity report that includes each CFP KRI with current status, compared to prior period, is the standard format.
Threshold breach documentation: If any metric ever reached amber or red — even briefly — the examiner will ask for evidence of the management response: who was notified, within what timeframe, what actions were taken, and how the metric moved afterward.
Contingent source testing evidence: Documentation showing that contingent funding sources were contacted, balances and availability were confirmed, operational access procedures were tested, and collateral pledging status was verified. This isn’t just paper; it’s records of actual outreach.
ALCO and board minutes: Evidence that the CFP — including trigger thresholds — was reviewed and approved by the appropriate governance bodies, and that any material changes to the funding composition were brought to board or committee attention with CFP implications noted.
Annual CFP review documentation: A formal annual review that evaluates whether existing thresholds remain appropriate given current funding composition, stress test results, and any market developments.
Connecting CFP KRIs to the Board Reporting Layer
CFP KRIs operate at two levels: operational (treasury/ALCO, typically daily or weekly) and governance (board risk committee, typically quarterly with escalation on any stage transition).
The board reporting layer doesn’t need every CFP KRI — it needs the summary: current CFP stage, current status of the tier-trigger KRIs (green/amber/red), and any events over the reporting period that caused a stage transition or threshold breach. That’s four to six data points, not a liquidity dashboard.
What the board needs to know: are we currently in normal operations, and if not, why not and what’s being done?
What the board does not need: detailed collateral pledging spreadsheets, individual counterparty confirmation records, or intraday deposit monitoring data. Those belong in ALCO and treasury management reporting.
For guidance on how to separate operational EWI monitoring from board KRI design — using the same underlying metrics but with different cadences, audiences, and responses — see Early Warning Indicators vs KRIs: How Liquidity Teams Should Use Both.
For a specific look at how deposit concentration KRIs connect to CFP run-off assumptions and activation triggers, see Deposit Concentration KRIs: Measuring Customer, Sector, and Platform Dependency.
So What Does This Mean for Your Program?
The regulators who reviewed SVB and Signature Bank post-failure found the same failure mode: metrics existed, stress signals appeared, and escalation was inadequate. The 2023 interagency guidance update was a direct response — and examiners are now specifically testing CFP activation design, threshold calibration, and evidence of operational readiness in a way they weren’t before 2023.
If your CFP’s activation section uses language like “when management determines that stress is sufficiently severe,” that section needs to be rebuilt around specific, threshold-bound KRIs with pre-specified, mandatory responses. Not because regulators are asking — but because the design that prevents management discretion from being the only variable standing between a stress signal and a response is what makes the CFP functional.
The calibration takes time. Start with your three highest-risk deposit runoff metrics, set amber thresholds that match your actual stress test outputs, assign named owners, and specify the response within 24 hours for each amber breach. That’s the minimum viable CFP KRI design.
If your program needs pre-built liquidity and financial risk KRIs — including deposit runoff rate, HQLA coverage, contingent funding line utilization, and brokered deposit concentration — with green/amber/red thresholds, data source fields, owners, and escalation triggers ready to deploy, the KRI Library (132 Key Risk Indicators) covers the financial risk domain with metrics calibrated for financial services institutions. Get the KRI Library →
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is a contingency funding plan KRI?
How many activation tiers should a CFP have?
What threshold values should CFP KRIs use?
What evidence do regulators expect to see for CFP KRI monitoring?
Who should own CFP KRI monitoring?
How often should CFP KRIs be reviewed and thresholds recalibrated?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Operational Risk
Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map
Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.
Jul 23, 2026
Operational Risk
FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.
On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.
Jul 21, 2026
Operational Risk
3,383 Incidents Later: What DORA's First ICT Data Reveals About Your Operational Risk Program
The ESAs published their first DORA ICT incident report in June 2026 — 3,383 major incidents, nearly one-third from third-party failures, only 10% cyber-related. Here's what the data means for your operational risk program.
Jul 16, 2026