Session Seven: Monitoring, Stress Testing and the ICAAP/ILAAP

Session Seven: Monitoring, Stress Testing and the ICAAP/ILAAP — Enterprise Risk Management in Practice

Enterprise Risk Management in Practice

A Practitioner's Course

Session Seven

Monitoring, Stress Testing and the ICAAP/ILAAP

How continuous monitoring differs from periodic review, what makes stress testing a genuine management tool, and what a strong internal capital assessment actually demonstrates

Session Seven: Monitoring, Stress Testing and the ICAAP/ILAAP

Risk management is not a one-time assessment. It is a continuous cycle of identifying, assessing, managing, monitoring, and reviewing risk as the business and its environment evolve. This session covers the mechanisms that keep that cycle running, and the specific regulatory processes that connect it to capital and liquidity.

Continuous monitoring

Banks use continuous monitoring to track key risk metrics as conditions change. Market risk teams monitor trading positions against limits during the trading day. Credit teams track portfolio performance and deteriorating exposures. Treasury and liquidity teams monitor funding positions and available buffers. Alerts matter, but only if the institution has clear thresholds, accountable owners, and a disciplined escalation path.

Transaction monitoring, central to financial crime compliance, is another form of continuous monitoring. It applies rules, scenarios, and models to transaction data to identify patterns that may indicate suspicious activity. Continuous monitoring of any kind depends on reliable data infrastructure. Institutions with fragmented legacy technology are structurally disadvantaged because they often cannot produce a consolidated risk view quickly enough for it to be useful when it matters.

Periodic review

Continuous monitoring does not replace structured review. Risk committees still need scheduled management information, usually monthly or quarterly, to assess the risk profile against appetite, test whether earlier actions have worked, and consider significant exposures and emerging concerns. Annual reviews of the risk appetite framework and the ERM approach help keep the framework aligned with business change. New products, new markets, acquisitions, and regulatory change may all require adjustment.

Stress testing as a management tool, not a submission

Stress testing gives management a forward-looking view of how an institution could perform under adverse conditions. Banks often conduct formal stress tests for regulatory purposes, but effective ERM uses stress testing more broadly. It should help management understand vulnerability, test assumptions, and decide what action is needed before stress arrives.

Internal stress tests should reflect the institution's own risk profile, not only standardised regulatory scenarios. A bank with concentrated commercial real estate exposure needs a severe property downturn scenario. A bank with material emerging market exposure needs scenarios that test currency, sovereign, and funding stress in those markets. Generic scenarios have their place, but they do not test the concentrations a specific institution carries.

The results should inform capital planning, limit setting, and strategic decisions. A stress test conducted only to satisfy a regulatory requirement is easy to recognise: the modelling team runs it, the output goes into a deck, the deck goes to a committee, and capital planning carries on unchanged. That is a submission, not a management tool. The diagnostic question is simple: when did the output of a stress test last change a capital, lending, or strategic decision? If the honest answer is never, stress testing is not doing its job.

The ICAAP and ILAAP

Banks subject to the supervisory review pillar of the Basel framework are expected to have a process for assessing overall capital adequacy in relation to their risk profile and a strategy for maintaining capital levels. In many jurisdictions, that process is expressed through an Internal Capital Adequacy Assessment Process, and the liquidity equivalent through an Internal Liquidity Adequacy Assessment Process.

Supervisors review a bank's capital and liquidity assessments through their supervisory review processes. Where the assessment shows that minimum requirements do not adequately reflect the bank's risk profile, supervisors may expect the bank to operate above the minimum or take other supervisory action.

The ICAAP in particular is one of the most comprehensive expressions of an institution's ERM framework, because producing a credible one requires everything covered so far in this course to work together. A well-developed ICAAP demonstrates that the board and management genuinely understand the bank's risk profile, that stress testing is rigorous rather than performative, and that capital planning is connected to strategy rather than running on a separate track. A weak ICAAP reads as a compliance exercise rather than a management tool. That is a serious supervisory concern. Experienced supervisors can usually tell when the document is not supported by the governance, data, challenge, and decision use it describes.

Risk reporting

Effective ERM depends on timely, accurate, relevant risk information reaching the people who need it. Risk reporting should give the board and senior management a clear view of the current risk profile, how it has changed, where it is close to or outside appetite, and what action is being taken.

Good risk reporting is not simply comprehensive. A report containing every available risk metric is not automatically useful. Effective reporting focuses on what matters, highlights emerging trends and concerns, and gives decision-makers enough context to act. A dashboard showing key indicators, trends, limits, and escalation triggers is more useful than a dense technical report that few people read in full.

The quality of risk data underpins all of this. Institutions that cannot aggregate risk data quickly and accurately across their portfolios and business lines are poorly placed to manage risk effectively, whatever their reporting templates look like. The Basel Committee's principles for effective risk data aggregation and risk reporting, often referred to as BCBS 239, were introduced after the global financial crisis to address exactly this problem: many banks could not aggregate exposures and identify concentrations fully, quickly, and accurately when the information mattered most.

Coming up in Session Eight

Session Eight covers risk culture and maturity, and how changing risk categories, including cyber, climate, operational resilience, and third-party concentration, are reshaping the landscape.

Further reading and resources

Enterprise Risk Management in Practice. The published Ārai Tika article this session draws on, including the diagnostic test of whether stress testing has changed a decision. Available at araitika.com.

Enterprise Risk Management in Banking. The published Ārai Tika guide with a fuller treatment of the ICAAP, ILAAP, and risk reporting. Available at araitika.com.