Skip to content
BIZENIUS

What is stress testing in banking? A practical guide

BIZENIUS Advisory Team · Last updated: 26 August 2026

Written and reviewed by the BIZENIUS advisory practice — senior practitioners from risk, treasury, finance and supervision.

Not a forecast and not a compliance exercise — a conditional estimate of what severe conditions would do to capital, liquidity and earnings, built to change a decision. The four questions a test answers, top-down versus bottom-up, and who owns each part.

In short

  • Stress testing is a conditional estimate of how an institution’s capital, liquidity and earnings would change under specified severe but plausible conditions, in order to inform a decision taken now — not a prediction of what will happen.
  • A well-built test answers four questions in order: how much would be lost, where capital and liquidity ratios would end up, which exposures drive the result, and what management would actually do about it. The fourth converts an analytical exercise into a control.
  • Severity is a governance decision about how much adversity the institution wishes to be able to absorb, not an estimate to be got right.
  • Solvency and liquidity tests obey different clocks and must not be collapsed into one exercise: an institution can be comfortably solvent and still fail.
  • What separates a credible programme from a compliant one is not modelling sophistication but governance — and governance properties are what a reviewer tests first.
On this page
  1. What stress testing actually is
  2. The four questions a test answers
  3. Not a forecast
  4. Top-down, bottom-up and three related exercises
  5. Solvency and liquidity run on different clocks
  6. The chain from narrative to ratios
  7. Who owns which part
  8. Where the results have to land
  9. Where it goes wrong
  10. What good looks like

What stress testing actually is#

Stress testing in banking is the practice of estimating how an institution’s capital, liquidity and earnings would change under specified severe but plausible conditions, in order to inform a decision taken now. The emphasis belongs on both halves of that sentence.

It is an estimate under conditions someone has chosen, not a prediction of what will happen; and its purpose is a decision — about how much capital to hold, which exposures to limit, what funding to arrange in advance — rather than a document.

A stress test that produces a number nobody acts on has performed the arithmetic and skipped the point.

The four questions a test answers#

A well-built test answers four questions in order.

  1. How much would the institution lose, expressed through the profit and loss account rather than as an abstract loss figure.
  2. Where would capital and liquidity ratios end up, measured against regulatory minimums, internal appetite and any buffers the board has committed to.
  3. Which exposures, portfolios or funding lines drive the result, because a headline depletion number is not actionable until it is attributed.
  4. What would management actually do about it, which is where most exercises quietly stop.

The fourth question is the one that converts an analytical exercise into a control.

Not a forecast#

The most persistent misunderstanding is that a stress test is a forecast. It is not, and the difference matters practically rather than semantically. A forecast attaches a likelihood to an outcome; a stress test asserts nothing about likelihood at all. It says: if these conditions held, this is roughly where the institution would stand.

Severity is therefore a choice — a governance decision about how much adversity the institution wishes to be able to absorb — not an estimate to be got right. Boards that treat severity as a forecasting question end up debating whether a scenario is likely, which is the wrong debate; the useful debate is whether the institution is willing to be unable to withstand it.

Tests are built either top-down or bottom-up, and mature programmes run both. A top-down test applies scenario parameters to portfolio aggregates using relationships estimated at a high level: it is fast, it is reproducible, and it is the only practical way to answer a board question within a meeting.

A bottom-up test pushes the scenario into individual exposures, obligor by obligor or facility by facility, and aggregates upward: it captures concentration and structure that averages hide, and it takes far longer.

The characteristic failure of top-down work is that it misses the exposure whose behaviour is nothing like the portfolio average. The characteristic failure of bottom-up work is that it arrives after the decision window has closed. Running the two against each other — and investigating where they disagree — is more informative than either alone.

It also helps to keep three related exercises distinct, because they answer different questions and are often conflated in the same report.

  • Sensitivity analysis moves one risk factor and observes the effect — useful for calibration and for understanding the machinery, but silent about how factors move together.
  • Scenario analysis moves a coherent set of factors according to a narrative, which is what most people mean by stress testing.
  • Reverse stress testing inverts the direction entirely: it starts from failure and searches for the conditions that would produce it.

The three are complements, and a programme that offers only the first is not stress testing so much as documenting model behaviour.

Solvency and liquidity run on different clocks#

Solvency and liquidity stress tests are frequently run by the same team from the same scenario, and they should be — but they obey different clocks and must not be collapsed into one exercise.

A solvency test typically runs over several years, tracks losses through provisions and earnings into capital resources, and moves risk-weighted assets as portfolio quality migrates.

A liquidity test runs over days and weeks, tracks cash rather than accounting profit, and turns on behavioural assumptions that no accounting standard governs: how fast deposits leave, which committed lines are drawn, which assets remain saleable and at what haircut.

An institution can be comfortably solvent and still fail, which is why the liquidity leg is not an appendix to the capital leg.

The chain from narrative to ratios#

Mechanically, every test follows the same chain, and the quality of a programme is usually decided by how honestly the middle links are handled.

  1. A narrative describes what is happening in the world.
  2. Parameters express that narrative as paths for observable variables — output, rates, currency, property and commodity prices, unemployment.
  3. Translation converts those paths into risk-factor behaviour: default rates, loss severities, prepayment, deposit attrition, spread widening.
  4. Impact applies that behaviour to the actual portfolio.
  5. Financial statements absorb the impact through provisions, revenue, costs and tax.
  6. Ratios fall out at the end.

The last two links are arithmetic; the middle links are judgement, and they are where a reviewer will spend their time.

Who owns which part#

Ownership is where programmes succeed or quietly rot, because stress testing sits across functions that report to different people.

  • Risk normally designs the scenarios and owns the methodology.
  • Finance and treasury supply the balance-sheet projection, the funding plan and the accounting mechanics.
  • The business lines challenge the assumptions about their own portfolios and are the only people who can say whether an assumed management action is executable.
  • Independent validation tests the models and the judgement, and must have standing to say the answer is not supportable.
  • The board approves severity before the exercise runs and receives the results with the decisions attached.

When any one of those roles is vacant, the usual symptom is a technically competent exercise that nobody outside the risk function believes.

Where the results have to land#

Integration is the difference between a stress-testing programme and a stress-testing report. The results have somewhere to land:

  • into the capital plan, as the buffer the institution holds above its minimum
  • into the funding plan and the contingency funding arrangements
  • into concentration and sector limits, which is where a bottom-up attribution earns its cost
  • into pricing, where the cost of holding capital against a stressed exposure belongs
  • into the recovery plan, whose options ought to be sized against the scenarios the tests actually produce
An institution that can point to a limit that moved, a buffer that was raised or a facility that was arranged because of a stress result has a programme. One that cannot has an annual report.

Where it goes wrong#

The failure modes are recognisable and largely independent of sophistication.

  • Scenarios borrowed from elsewhere, describing shocks that have little to do with this balance sheet’s concentrations.
  • Severity selected, consciously or not, so that the result passes — visible when every scenario for several years lands just above the minimum.
  • A static balance sheet held constant for years while the narrative describes a collapsing economy.
  • Management actions that assume asset sales into the same market the scenario has just closed, or capital raised at a moment the scenario says capital is unavailable.
  • Results delivered after the capital plan has been signed.
  • And the most common of all: an exercise owned by three people, never challenged by anybody with the standing to reject it, and read by a board that has never sent one back.

What good looks like#

What separates a credible programme from a compliant one is not modelling sophistication. It is that:

  • somebody senior chose the severity deliberately and can explain the choice
  • the scenarios describe risks this institution recognises as its own
  • the assumptions were argued with people who would bear the consequences
  • the management actions are ones the institution could actually take, in the order and timeframe claimed
  • the results reached a forum with the authority to change something, in time to change it

Those are governance properties, not quantitative ones, and they are what a reviewer tests first.

Frequently asked

What is stress testing in banking?

Stress testing in banking is the practice of estimating how an institution’s capital, liquidity and earnings would change under specified severe but plausible conditions, in order to inform decisions taken now. It is a conditional estimate rather than a forecast: it attaches no likelihood to the scenario and instead asks where the institution would stand if those conditions held. A complete test answers four questions — how much would be lost, where capital and liquidity ratios would end up against minimums and internal appetite, which exposures drive the result, and what management would actually do about it. The fourth question is what turns the exercise into a control rather than a report.

What is the difference between top-down and bottom-up stress testing?

A top-down stress test applies scenario parameters to portfolio aggregates using relationships estimated at a high level. It is fast and reproducible, which makes it the only practical way to answer a board question inside a meeting, but it can miss an exposure whose behaviour is nothing like the portfolio average. A bottom-up stress test pushes the scenario into individual exposures — obligor by obligor or facility by facility — and aggregates upward, capturing concentration and structure that averages hide, at the cost of far longer turnaround. Mature programmes run both and treat disagreements between them as findings worth investigating rather than reconciliation noise.

How often should a bank run stress tests?

There is no single correct frequency, because different tests serve different decisions. The full solvency exercise is normally annual, aligned to the capital planning cycle so that results arrive before the plan is signed rather than after. Liquidity stress tests are run far more often — monthly is common, and daily or weekly for the core survival horizon — because liquidity conditions change on a timescale capital does not. Sensitivity analyses and ad hoc scenarios should be available on demand, which is really a statement about infrastructure: an institution that needs a quarter to answer a board what-if does not have a scenario capability, whatever its calendar says. Any material change in strategy, portfolio mix or market conditions is itself a trigger to rerun.

What makes a stress test credible to a supervisor?

Credibility rests on governance rather than on modelling sophistication. A reviewer will look for severity that a named senior forum chose deliberately and can justify; scenarios built from this institution’s own concentrations rather than a template pack; assumptions that were challenged by the business lines who would bear the consequences; management actions that are executable in the order and timeframe claimed, and not dependent on markets the scenario has just closed; independent validation with the standing to withhold sign-off; and evidence that results reached a decision-making forum in time to change something. The single most persuasive piece of evidence is a specific decision — a limit, a buffer, a facility — that changed because of a stress result.

More where this came from

Browse the full resources hub, or subscribe in the footer for occasional substantial pieces.

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.