CySEC Advanced · Chapter 9 · Topic 13 of 13

What goes in a risk register, and how do the three stress-testing methods differ?

What a risk register records, why stress testing is part of the ICAAP, how sensitivity analysis, scenario analysis and reverse stress testing work, and what a sound stress test looks like.

By the ExamPass CY editorial teamLast reviewed 6 min read

Short answer

A risk register lists and classifies every risk a CIF is exposed to, or may be exposed to later, with its severity and the harm it could cause if it crystallised. Stress testing must be built into the ICAAP and the firm's wider risk management. Sensitivity analysis moves one risk factor and holds the rest; scenario analysis moves several at once; reverse stress testing starts from business failure and works back to its causes. Stress tests must be tailored and forward-looking, reviewed at least annually and when factors change, and run again after management acts.

Risk register and stress testing at a glance

Risk registerAll current and potential risks, categorised, with severity and potential adverse impact, measured in figures or in words
ResultA risk profile that groups risks by severity
Stress testingPart of the ICAAP and the risk framework; assesses all material risks comprehensively, in an integrated way and looking ahead; no single correct method
Sensitivity analysisOne factor changes, others unchanged; easy to size, but factors rarely move alone
Scenario analysisSeveral factors change together, using hypothetical or historical scenarios; captures links between factors, but those links may not hold in a crisis
Reverse stress testingStarts from an unviable business model and identifies what could cause it; management decides on triggers or actions
DesignFits the portfolio, the risks taken, the external environment and the firm's risk profile and operating model
ReviewDesign reviewed at least annually, and when relevant factors change or are expected to change; the tests themselves run more often
After the testActions assigned to named people and departments, implemented, and the test run again

Source: CySEC Circular C026 (2012).

What is a risk register?

The exam material follows CySEC's 2012 ICAAP guidelines, Circular C026, which CySEC still publishes. Most CIFs have been under the IFR since 26 June 2021. Since 5 November 2021, Class 2 CIFs have assessed their internal capital and liquid assets together under section 18 of Law 165(I)/2021, and Class 3 CIFs only if CySEC asks. This does not replace the ICAAP but widens it: the joint EBA and ESMA guidelines call the whole process the ICARAP, made up of an ICAAP for capital and an ILAAP for liquidity, and CySEC's January 2022 practical guide to the IFR and IFD calls it the ICAAP and ILAAP.

A risk register is where a CIF records and classifies every risk it is exposed to now or could be exposed to in future. For each risk it shows how severe the harm would be. C026 measures that harm as if the risk crystallised; the exam material puts it as the damage the risk could have done had it gone unidentified. The impact may be expressed in figures or in words, for example as a financial loss, a loss of capital, damage to reputation or even harm to people. The outcome is a risk profile that sorts risks into levels of severity. The register feeds the ICAAP by showing which Pillar 1, partly covered and Pillar 2 risks are material; see What are the Pillar 2 risks a CIF must assess in its ICAAP?.

Terms used in this note

Risk register
A record of all current and potential risks, categorised by type and severity.
Sensitivity analysis
A stress test that changes one risk factor while holding all others constant.
Scenario analysis
A stress test that changes several risk factors together to model a hypothetical or historical event.
Reverse stress testing
A stress test that starts from business failure and works back to the events that could cause it.

Why stress test, and how do the three methods differ?

Stress testing covers quantitative and qualitative techniques that show how vulnerable a firm is to rare but plausible events with severe consequences. Its importance grew after the global financial crisis, and it must be built into each CIF's ICAAP and risk management framework. In the ICAAP its purpose is to assess all material risks comprehensively, in an integrated way and looking ahead, taking in market, economic, institutional and political factors that could substantially affect the firm's prudent and solvent operation. CySEC accepts that no single methodology is correct: the right approach depends on the firm's size, activities, risk appetite and quality of risk management, but it must be sophisticated enough for the firm and meet the rules.

Sensitivity analysis is the simplest method. It shows how the firm's position changes when one relevant risk factor moves and all others stay the same. Its strength is that the size of losses from that factor is easy to measure; its weakness is that in reality factors do not move in isolation. Scenario analysis changes several risk factors at the same time and measures their combined effect, using hypothetical and historical scenarios; the exam material adds expected ones. It captures the links between factors, which gives an integrated view of risk, but those links may break down in a crisis. C026 adds that they can be unstable even in normal conditions. Reverse stress testing is mainly a tool for finding weaknesses in the business model. It starts from the outcome, a business that is no longer viable, and identifies the circumstances that could produce it. Senior management then decides whether to take mitigating action now, or to set triggers for action if such a scenario starts to develop.

What makes a sound stress test, and what happens afterwards?

Stress tests must be designed around the firm's portfolio and the risks it takes, and in line with its external environment. They must suit its specific circumstances, risk profile and operating model. They must be forward-looking, taking in both the current position and planned strategic developments, and they must show how adverse scenarios would affect future profitability and capital adequacy. They are reviewed at least annually, and whenever the underlying factors change or are expected to change, and revised as needed. C026 also expects the tests themselves to be run more often than once a year. In the ICAAP, the risk management function applies them.

A stress test is not finished when the report is written. Management defines actions, assigns them to responsible people and departments, and implements them. The same stress test is then run again to see how the actions have changed the impact. For the wider organisational rules on risk management, see What organisation, risk management and internal audit must an investment firm have?.

How to think about it

Ask what moves. One factor alone is sensitivity analysis, several together is scenario analysis, and starting from failure and working backwards is reverse stress testing. Each method has its trade-off: sensitivity is easy to size but unrealistic, scenarios are realistic but depend on relationships that may break, and reverse testing reveals weak points rather than measuring a loss. Then close the loop: act on the results and run the test again.

Common mistakes

  1. Assuming sensitivity analysis is the most realistic method. It is the simplest; in reality risk factors move together.

  2. Trusting past relationships between factors in a crisis. Scenario analysis depends on links between factors that may not hold under stress.

  3. Using reverse stress testing to size a single shock. It starts from failure and looks for the causes, to expose weaknesses in the business model.

  4. Running a stress test once. Tests are reviewed at least annually and when factors change, and run again after management acts.

Practise this topic

Test what you just read

The Chapter 9 pack has 198 exam-style questions, 17 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 48 free Chapter 9 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error