Credit Risk
Pronunciation: KREH-duht RISK
Definition
Credit risk is the possibility of financial loss because a borrower, issuer, customer, or counterparty fails to meet payment obligations. Decision-makers use Credit Risk to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified. A score for Credit Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions.
Overview
Credit risk arises whenever value is delivered before full and final payment. It applies to loans, bonds, receivables, derivatives, settlement exposures, undercollateralized lending, and balances owed by customers, issuers, or financial counterparties.
Assessment considers probability of default, exposure at default, loss after recoveries, collateral quality, seniority, concentration, maturity, and economic conditions. Credit quality can deteriorate quickly when market stress also reduces collateral value and liquidity.
Controls include underwriting, limits, collateral, guarantees, covenants, pricing, diversification, monitoring, provisions, and recovery planning. Historical repayment and ratings are useful but cannot replace current cash-flow analysis, legal enforceability, and stress testing. Expected-loss estimates should be refreshed as exposure, collateral, and counterparty conditions change materially over time.
Credit risk is the possibility of financial loss because a borrower, issuer, customer, or counterparty fails to meet payment obligations. Credit risk depends on default probability, exposure, and recoverability, requiring underwriting, limits, monitoring, diversification, and enforceable protections.
For Credit Risk, the assessment should evaluate the use of a borrower, issuer, customer, or counterparty fails to meet payment obligations. The assessment record should separate observed evidence supporting the use of a borrower, issuer, customer, or counterparty fails to meet payment obligations from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in the use of a borrower, issuer, customer, or counterparty fails to meet payment obligations have changed enough to require a new rating, treatment, or approval.
Decision-makers should use findings about the use of a borrower, issuer, customer, or counterparty fails to meet payment obligations to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.
Key Takeaway
Credit risk depends on default probability, exposure, and recoverability, requiring underwriting, limits, monitoring, diversification, and enforceable protections.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)