Feature Operational Risk
Stress Testing KRIs: How to Turn Scenario Results Into Board-Level Triggers
Most stress test results never make it into ongoing KRI programs. Here's how to convert scenario outputs — deposit runoff assumptions, capital floor breaches, credit loss projections — into calibrated KRI thresholds that fire automatically when conditions approach the scenario's breaking points.
Table of Contents
Your stress test ran. The results went to the ALCO. A presentation was made to the board. And then the outputs — the modeled deposit runoff, the credit loss projections, the capital sensitivity analysis — sat in a folder until next year’s test.
That’s not a stress testing failure. It’s a KRI design failure.
The purpose of stress testing is not to produce a report. It’s to understand where your breaking points are and to position your monitoring program so you see the approach to those breaking points before you’re already inside them. If the output of a stress scenario never feeds into how you calibrate your ongoing KRI thresholds, you’ve done the analytical work without building the early warning system it was supposed to produce.
TL;DR
- Stress test outputs tell you where the breaking points are. KRI thresholds should be set in the approach zone — before those breaking points, not at them.
- The link between stress scenarios and KRI thresholds needs to be documented: why is this threshold set at this value, and what scenario output supports it?
- Thresholds derived from last year’s stress test are wrong once your portfolio composition changes materially. Recalibration belongs in the annual review cycle.
- Board-level KRI triggers should reflect the stress scenario outputs the board approved — they’re not arbitrary management numbers.
- Examiners will ask how your KRI thresholds were calibrated. “That’s what we’ve always used” is not a defensible answer.
Why Stress Tests and KRI Programs Usually Don’t Talk to Each Other
The disconnect is organizational. Stress testing is typically run by treasury, finance, or a dedicated risk team — and the output goes to the ALCO and board as a point-in-time report. KRI monitoring runs on a different cadence, often owned by a different team, and the threshold values are typically set when the program is first built and rarely revisited.
The result: a stress test that models a 12% 30-day deposit runoff as the adverse scenario, while the KRI program uses an amber threshold of 10% that was set three years ago based on historical averages — not on the scenario modeling that showed 12% is where things break.
When real conditions move, the KRI fires too late to match the stress scenario’s intent. Or worse, the KRI never fires because the threshold wasn’t calibrated to the scenario at all.
The fix is structural. Stress test outputs need to feed into a formal KRI threshold review — not just the ALCO report, but the actual threshold values in your KRI monitoring program.
What “Calibrating Thresholds to Scenario Outputs” Actually Means
When a stress scenario models an adverse outcome, it implicitly defines a breaking point — the level of a specific metric at which adverse outcomes materialize. The KRI threshold should be set in the approach zone: at a level that gives management enough time to respond before hitting the breaking point.
The general framework:
Step 1 — Identify the breaking point from the scenario. At what metric level does the adverse outcome (liquidity exhaustion, capital floor breach, credit loss exceeding tolerance) occur?
Step 2 — Identify the realistic drift rate. At what rate is this metric likely to move? For deposit runoff, what’s the daily or weekly rate your scenario assumes? For credit deterioration, what’s the quarterly DPD migration rate?
Step 3 — Set the amber threshold at the level that gives you a pre-specified response window. If the breaking point is at 15% runoff and the drift rate is roughly 2% per week, an amber threshold at 8% gives approximately 3-4 weeks of warning. That’s enough time for treasury to begin pre-positioning. A threshold at 13% gives you a week — probably not enough.
Step 4 — Set the red threshold closer to the breaking point, triggering immediate management action. The red threshold is not the breaking point itself; it’s the level at which the response can no longer be gradual.
Step 5 — Document the calibration. The threshold values are defensible because they connect to scenario outputs and response timing. Write that down.
Connecting Liquidity Stress Outputs to KRIs
Liquidity stress testing is where the connection between scenario outputs and KRI calibration is most operationally mature — largely because the 2023 Interagency Addendum to the Interagency Policy Statement on Funding and Liquidity Risk Management pushed institutions to demonstrate not just scenario modeling but tested operational readiness.
The following table maps common liquidity stress scenario outputs to the KRIs they should calibrate.
| Scenario Output | What the Scenario Shows | Calibrated KRI | Threshold Setting Logic |
|---|---|---|---|
| 30-day net cash outflow | At X% deposit runoff, liquidity gap = $Y | Deposit runoff rate (7-day, 30-day) | Amber = ~half the adverse scenario runoff rate; Red = ~75% of adverse runoff |
| HQLA coverage at stress | At scenario outflows, HQLA coverage falls to Z% | HQLA coverage ratio | Amber threshold set above the scenario floor by a management response buffer |
| Contingent funding utilization | Adverse scenario requires drawing X% of contingent capacity | FHLB / contingent line utilization | Amber = 60-70% of what the scenario projects as fully stressed utilization |
| Brokered deposit reliance | Scenario shows loss of brokered access at PCA threshold | Brokered deposit concentration | Amber set at the level where PCA restrictions begin to approach |
| Wholesale funding rollover | Adverse scenario shows rollover failure at X% rate | Wholesale funding renewal rate | Amber = rollover rate approaching scenario assumptions |
The threshold values in this table aren’t universal — they’re illustrative calibration logic. Your institution’s actual thresholds should come from your own scenario outputs, not from industry benchmarks that don’t reflect your funding composition.
Credit Stress Outputs and Lending Portfolio KRIs
For lending institutions — community banks, fintechs, and credit programs — credit stress testing outputs are the right starting point for calibrating credit quality KRIs.
The standard credit stress test models how the portfolio’s credit metrics change under an adverse economic scenario: unemployment spikes, property values decline, or a sector-specific downturn affects a concentrated portfolio segment. The scenario produces projections of:
- Days past due (DPD) migration rates across 30, 60, 90+ DPD buckets
- Projected charge-off rates over a 12-24 month horizon
- Net credit loss as a percentage of average loans
- Allowance for credit losses (ACL) adequacy under the scenario
Each of these outputs can calibrate a corresponding KRI.
| Scenario Output | Calibrated KRI | Threshold Setting Logic |
|---|---|---|
| Projected 90+ DPD rate under adverse scenario | 90+ DPD as % of outstanding balance | Amber threshold set below the adverse scenario projection; Red = approaching adverse scenario level |
| Projected charge-off rate | Net charge-off rate (quarterly) | Amber = half of adverse scenario charge-off projection; Red = 75% of adverse scenario projection |
| ACL adequacy at scenario | ACL coverage ratio (ACL ÷ total loans, or ÷ non-performing loans) | Amber = approaching the level where ACL becomes stressed in scenario |
| Concentration loss under adverse scenario | Single-sector or single-borrower concentration | Amber = approaching the concentration level modeled in adverse scenario |
The ALCO often reviews these credit metrics quarterly. The KRI monitoring program should track them on the same cadence, with the threshold values connected to what the stress test showed — not arbitrary round numbers.
Capital Stress Outputs and Capital Adequacy KRIs
For chartered banks subject to capital adequacy requirements, capital stress testing connects most directly to KRIs around CET1 ratio, total capital ratio, and leverage ratio.
The Dodd-Frank stress testing framework for banks over $100 billion in assets — DFAST — produces projected capital ratios under baseline, adverse, and severely adverse scenarios. For smaller institutions, the OCC’s guidance for community banks encourages internal capital adequacy assessments that perform comparable, appropriately scaled scenario analyses.
The connection to KRIs is similar in structure to liquidity and credit:
| Capital Stress Output | Calibrated KRI | Board-Level Trigger Logic |
|---|---|---|
| CET1 ratio under adverse scenario | CET1 ratio (quarterly) | Amber threshold = scenario adverse floor + management buffer; Red = approaching regulatory minimum |
| Leverage ratio under stress | Leverage ratio (Tier 1 ÷ average total assets) | Amber set above the level where remediation options narrow materially |
| Risk-weighted assets growth | RWA growth rate | Amber = rate implying capital ratios approach stress scenario projections |
For community banks and credit unions not subject to formal DFAST, the same logic applies to internal capital stress analyses. The OCC and FDIC examiners at community institutions ask about capital adequacy under stress even when formal DFAST isn’t required — and the answer should connect to ongoing KRI monitoring, not just an annual document.
Operational Stress Outputs: The KRI Category Most Programs Skip
Credit and liquidity stress outputs get the most attention. Operational stress testing — modeling the impact of system outages, key personnel loss, third-party failures, or cyber events — gets less systematic treatment, and its outputs rarely feed into KRI programs.
That’s a gap worth closing, because operational resilience KRIs are increasingly in scope for regulatory exams. The FFIEC’s Business Continuity Management booklet and state regulators in the UK and EU have formally moved toward operational resilience frameworks that require institutions to define impact tolerances and monitor against them — which is, effectively, the same structure as stress testing KRI calibration.
| Operational Scenario Output | Calibrated KRI | Threshold Logic |
|---|---|---|
| System recovery time in adverse scenario | Mean time to recover (MTTR) for critical systems | Amber = approaching RTO; Red = RTO exceeded |
| Third-party outage duration in scenario | Critical vendor downtime (rolling 12 months) | Amber = approaching impact tolerance for that vendor category |
| Incident frequency in adverse conditions | Security incident rate (per month/quarter) | Amber = rate implying trajectory toward scenario assumptions |
| Key personnel unavailability | Coverage rate for critical roles | Amber = fewer than N backup-qualified personnel per critical function |
The operational KRI thresholds derived from stress scenarios are typically calibrated to impact tolerances — the maximum duration or frequency of disruption that can be tolerated before material harm occurs. Those tolerances are what operational stress scenarios test.
The Board Reporting Layer: What Belongs There
KRI thresholds derived from stress scenarios operate at two levels: management (ALCO, credit committee, operational risk teams) and governance (board, risk committee).
The board should see the KRI thresholds that correspond to the stress scenarios they approved — not because they need all the underlying calibration detail, but because the board’s approval of the stress scenarios implies approval of the monitoring program that makes those scenarios actionable.
What belongs in board-level KRI reporting from stress scenario calibration:
- Current status of the two to four highest-consequence stress scenario KRIs (liquidity, capital, credit quality by portfolio type)
- Comparison to threshold — are we in the green zone, approaching amber, or in the red zone that corresponds to the scenario’s danger zone?
- Trend direction — are conditions moving toward the stress scenario’s assumptions, and at what rate?
- Threshold review status — when were thresholds last recalibrated against scenario outputs, and is recalibration scheduled?
What doesn’t belong in board-level reporting: the technical detail of scenario assumptions, daily monitoring data, or the full ALCO liquidity package. That’s management reporting. The board needs signal, not noise.
See KRI Appetite Statements: How to Tie Metrics to Board-Approved Risk Appetite for how to connect KRI thresholds to the risk appetite language the board actually approved — which, for stress scenario KRIs, should reference the scenario’s adverse assumptions explicitly.
Common Calibration Failures: What Goes Wrong
Thresholds set from industry averages, not your own scenarios. A benchmark that says community bank deposit runoff KRIs typically use a 5% amber threshold means nothing if your stress test showed your specific funding mix breaks at 8%. Calibrate to your scenario.
Scenarios that aren’t stressed enough. If the adverse scenario is just a mild downturn, the KRI thresholds calibrated against it will miss a real stress event. The Federal Reserve’s 2026 DFAST severely adverse scenario models unemployment peaking at 10%, commercial real estate prices falling 39%, and equities dropping 54% — these are the parameters that reveal structural vulnerabilities. Calibrating KRI thresholds against a mild internal scenario instead produces false comfort.
Threshold calibration that isn’t refreshed when the portfolio changes. The stress test that justified your deposit runoff KRI threshold was run when your deposit base looked different. If you’ve added a BaaS program, or shifted from retail to institutional depositors, the runoff assumptions are wrong for your current book.
Scenarios that don’t feed back into KRI programs. The stress test report went to the ALCO in January. The KRI library hasn’t been touched since the risk program was built. Nobody connected the outputs.
Red thresholds set at the breaking point rather than in the approach zone. A KRI that fires when you’re already at the breaking point doesn’t give you response time. It gives you notification that something has already gone wrong.
The Documentation Regulators Look For
When an examiner asks how your KRI thresholds were calibrated, the evidence trail should connect:
Stress test documentation: The scenarios, the assumptions, the results, and board/committee approval.
KRI library version history: The date thresholds were set or revised, and the specific scenario output that justified the threshold value.
Recalibration records: Annual threshold review documentation, showing what changed and why.
Board and ALCO minutes: Evidence that the stress scenario outputs — and their translation into KRI thresholds — were reviewed and approved at the appropriate governance level.
The gap most often found in examination: a well-documented stress test that doesn’t appear anywhere in the KRI program. The scenarios and the thresholds live in separate documents, owned by separate teams, with no documented link between them.
See Leading vs. Lagging KRIs: Which Metrics Actually Warn You Early? for how to ensure your stress-scenario-derived KRIs are designed as leading indicators — warning signals that appear before the scenario’s adverse outcomes materialize, not confirmations that they already have.
So What Does This Mean for Your Program?
If you ran a stress test in the last 12 months and the outputs haven’t been reviewed against your current KRI thresholds, start there. Pull the scenario results and compare each stress metric to its corresponding KRI threshold. Ask two questions: Is the threshold set in the approach zone, not at the breaking point? And does the threshold reflect this year’s portfolio, not last year’s?
If you don’t have a formal KRI program that maps to your stress scenarios, build the connection incrementally. Start with the two or three metrics your stress test showed were most sensitive — the metrics where the adverse scenario’s breaking point was closest to current conditions. Set thresholds for those first, document the calibration logic, and establish a review cadence. That’s the minimum viable stress-scenario KRI program.
The connection between stress testing and KRI monitoring is where point-in-time analysis becomes continuous risk detection. Building that connection is what turns a stress test report into an early warning system.
If your program needs pre-built KRIs that cover liquidity, credit, capital, and operational risk domains — each with green/amber/red thresholds, data sources, escalation triggers, and calibration guidance — the KRI Library (132 Key Risk Indicators) is built for exactly this. Get the KRI Library →
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is a stress testing KRI?
Do community banks under $10 billion in assets need to do stress testing?
How often should stress test outputs feed into KRI threshold recalibration?
What's the difference between a stress test output and a KRI threshold?
What evidence do examiners want to see connecting stress tests to KRI thresholds?
Can I use stress test outputs to calibrate KRIs even if my stress tests are informal?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
KRI Library (132 Key Risk Indicators)
132 KRIs with thresholds, data sources, and escalation triggers pre-built for financial services.
◆ Keep reading
Related posts.
Operational Risk
Risk Assessment Template in Excel: Build the Evidence Trail, Not Just the Heat Map
Build a risk assessment template in Excel that preserves evidence, challenge, approvals, and score history—not just a polished heat map.
Jul 23, 2026
Operational Risk
FedNow's Network Intelligence API Launched in April 2026. Your Fraud Risk Program Probably Hasn't Caught Up.
On April 28, 2026, the Federal Reserve made pre-payment network-level fraud intelligence available to every FedNow participant. The data — receiver account behavioral trends derived from system-wide FedNow activity — is available before a transaction is approved. Most institutions haven't updated their fraud policies, controls, or KRIs to account for what this changes.
Jul 21, 2026
Operational Risk
3,383 Incidents Later: What DORA's First ICT Data Reveals About Your Operational Risk Program
The ESAs published their first DORA ICT incident report in June 2026 — 3,383 major incidents, nearly one-third from third-party failures, only 10% cyber-related. Here's what the data means for your operational risk program.
Jul 16, 2026