What Basel III Is Really Testing in Banks Today

When Passing Every Test Is Not the Same as Being Prepared I sat across from a risk committee in Q3 2022 that had done everything right on paper. Liquidity coverage ratio was above threshold, net stable funding ratio was solid, and capital filings were submitted on time, every quarter, without drama. The room carried the particular confidence of people who had followed the rules and knew it. Six weeks later, a rate shock hit. The CFO called me, and he was not panicking, which, looking back, made it worse. Panic I could have worked with. What he had instead was genuine bewilderment. “We passed every stress test, Laksh. How is this happening?” I gave him an honest answer in that call, but the question itself stayed with me for much longer. Because he was right, they had passed every test, and they were still unprepared. The gap, between the test and the reality, is what I have been thinking about ever since. The Situation Here is what their balance sheet actually looked like, beneath the ratios. I saw that the product team had spent eighteen months pushing into longer-duration liabilities because the margins were attractive. Treasury had flagged concerns internally, twice. Both times the conversation ended when someone cited the capital ratios as evidence the position was sound. I decided that the stress tests had been produced by a small team, reviewed by risk, filed with the regulator, and essentially not touched again until the next cycle. I also decided that capital planning happened once a year, in a process the business units attended long enough to sign the assumptions and then left. No one had broken a rule. Every number was real. I followed the framework with genuine diligence. However, I did not think. The stress tests were treated as a compliance artefact, something I produce for the regulator, not something I use to make a better decision the following Monday. When the rate environment shifted faster than the annual cycle had modelled, there was no mechanism to catch it. The treasury desk and the product desk had been living in parallel universes, and Basel III had given them enough paperwork in common to feel like they were collaborating. I say with no pleasure that a bank can be a model Basel III institution and still be structurally unprepared for a real-world shock. I designed the framework to be rigorous, but I also implemented it in a way that is backward-looking. Filing last quarter’s ratios tells me where I was. It tells me almost nothing about where the next decision is taking me. Three Things That Conversation Confirmed **Resilience is an operating discipline, not a reported state.** I noticed that the institutions that held through the 2022 rate environment shared something: risk was not a department I consulted after the fact. It was a presence in the room when the product got priced, when the liability structure got approved, when the assumption about customer behaviour got embedded in a model. The ratio I filed was a consequence of the thinking that had already happened. Not the other way around. Most banks have inverted this. I use the ratio to justify decisions already made. When the ratio looks acceptable, the conversation stops. That is not risk management. That is risk rationalisation. **Stress testing works only if someone owns the result.** I found that the problem with how stress testing is practised in the majority of mid-sized institutions is not the methodology. The models are often genuinely sophisticated. The problem is what happens the morning after the document is filed. I ask myself, who reads it? Who changes something because of it? In that 2022 committee, the answer was effectively no one, not because they were negligent, but because the process had no forcing function attached to it. Stress testing had become a production exercise. A skilled team spent weeks building a credible scenario, and the output lived in a folder. I believe that stress testing earns its cost only when it is connected to a decision. When a scenario changes a pricing assumption, modifies a product approval, or triggers a board conversation about exposure, that is when it does the thing it was designed to do. Otherwise, it is expensive documentation. **Capital planning done annually is capital planning done wrong.** I think that the world that Basel III was designed for no longer moves at an annual cycle. Rate environments shift in quarters. Funding markets can reprice in weeks. The assumption embedded in most capital planning processes, that I review the balance sheet once a year in a structured exercise, is structurally mismatched with how risk actually arrives. It arrives continuously. It arrives in product decisions and pricing decisions and hiring decisions and the small assumptions that compound quietly until one external event makes them visible all at once. I have seen that the institutions that navigate volatility most effectively treat capital planning as a standing discipline with a live component, regular, shorter reviews that connect the balance sheet to the decisions being made now, not the decisions made last autumn. What This Means for Your Organisation If you are a CFO, a CRO, or a board member reading this, the question worth asking is not whether your ratios are in order. They probably are. The question is whether the people approving products, pricing liabilities, and building forecasts have ever been in the same room as the stress test output. Whether your capital planning process ends when the document is filed or when the business has changed something because of it. Whether your treasury desk and your product desk are genuinely in conversation before the decision, or only after the loss has been recognised. The answer to that question tells me more about your resilience than any number you will report this quarter. I gave the industry a language for resilience. What I cannot mandate is whether you use it to think or merely to report. The banks that

When Risk Frameworks Become Obsolete: An MRA Story

The Friday I Signed Off on a Risk Framework I Knew Was Broken There’s a particular kind of exhaustion that sets in on a Friday afternoon in Q3 when an OCC examination cycle looms. It’s not the clean tiredness of hard work finished. It’s the grubby, low-grade fatigue of a problem you’ve been managing rather than solving for the better part of a year. Everything on your desk is a version of the same question: how long can we hold this position? In Q3 2021, I found out exactly how long. The answer was four months. We had an open MRA – a Matter Requiring Attention – that had been sitting on the books for eleven months. For anyone outside the OCC’s regulatory world: an MRA isn’t a fine, it isn’t a public censure, but it’s a formal signal that the examiner has found something structurally wrong with your risk management practices and expects you to fix it. It’s the regulator telling you, in careful institutional language, that they’re watching. What we submitted that Friday addressed every word of the finding. It didn’t address the condition that had produced it. I knew this when I signed. — The Decision I Made in That Room The framework we built was technically responsive. That’s the exact right phrase. It answered the question as written rather than the question being asked. We’d brought in outside counsel, run it through the risk committee, and produced something that looked, on paper, like a serious institutional response. It had the right headings. It cited the right regulations. It mapped to the MRA’s specific language with the kind of precision that signals effort. What it didn’t do was account for the direction our risk environment was moving. The original finding had been written against conditions from early 2020. By the time we submitted the remediation framework in 2021, those conditions had shifted materially: vendor concentration had increased, a key operational process had been restructured, and two of the control owners named in the original framework had left the organisation. The framework we submitted was already ageing before the ink dried. I knew this. The head of my risk team knew this. We submitted it anyway, because the examination window was closing and an open MRA going into the next cycle felt like a worse outcome. That’s the calculation that leads you to the wrong decision in a very calm and rational way. The examiner accepted the framework. For approximately four months. Then the follow-up review arrived, and what had been an MRA became an MRA with a deadline. In OCC language, that’s the last door before formal enforcement action. We had to rebuild the entire framework under significant pressure, on a compressed timeline, with an examiner who now had a documented record of our previous submission sitting in the file. We hadn’t bought ourselves time. We’d borrowed it at an interest rate nobody quoted us at closing. — What Regulatory Time-Buying Actually Costs The first thing to understand is that OCC examiners have institutional memory that outlasts personnel changes on both sides of the table. Examination files follow an institution. When you resolve an MRA with a framework that’s already structurally compromised, that’s noted – not always in the formal finding, but in the examiner’s working papers, in the tone of the next examination, in the questions that surface two cycles later about the same underlying risk area. Regulators track patterns, not just incidents. A technically compliant response followed by a material lapse reads, to an experienced examiner, as a pattern. The second thing is that the goodwill cost is real and hard to recover. Regulated institutions often underestimate how much of the OCC examination relationship runs on examiner judgement – judgement about whether management genuinely understands its risk environment, whether leadership takes findings seriously, whether the organisation has a credible culture of risk management or a credible performance of one. That judgement is formed over multiple examination cycles. When you trade a substantive response for a timely one, you’re spending a currency you don’t get back by submitting the next framework on schedule. The third insight, and the one that cost me the most to learn: the MRA itself isn’t the problem. It’s a signal about the condition underneath. This sounds obvious until you’re the person sitting across the table from a Friday afternoon examination deadline with an open finding, at which point it stops being obvious and starts being inconvenient. Most MRA remediation work I’ve reviewed – and I’ve reviewed a substantial amount, at enough institutions to recognise the pattern – is designed around closing the finding rather than resolving the condition. Those aren’t the same activity. The finding is a description of a symptom at a point in time. The condition is a structural feature of how risk is identified, escalated, and owned inside the organisation. You can resolve the former without touching the latter. Banks do it regularly. The examiners know. This same dynamic appears in how organisations manage third-party risk. A vendor who fails a due diligence review is a finding. The governance gap that allowed the vendor relationship to become operationally critical before due diligence was completed is the condition. I’ve written separately about how third-party risk frameworks often suffer from exactly this confusion – treating relationship incidents as the unit of analysis when the control environment is the actual problem. — What This Means for Your Organisation If you’re managing an open MRA right now, the practical implication is this: build the remediation framework for where your risk environment will be in eighteen months, not where it was when the finding was written. That means the control owners named in the framework need to be current. The risk scenarios need to reflect your actual operational configuration, not the one that existed at examination time. The governance structure underpinning the framework needs to have real teeth – real escalation paths, real accountability, real testing cycles – because an OCC examiner