Every major risk pillar in banking has its own metric except one. Credit risk relies on probability of default (PD) and loss given default (LGD), market risk uses value at risk (VaR), and liquidity is measured through the liquidity coverage ratio (LCR).
According to Corlytics, non-financial risk (NFR), which drives the largest operational losses and almost every conduct fine, is still largely assessed using traffic-light colours.
That gap has real consequences. Risk and control self-assessment (RCSA) processes often end in a red, amber or green rating, which leaves business heads and risk owners struggling to decide whether to accept, mitigate or avoid a given risk.
The lack of practical modelling reflects the manual nature of RCSA itself, a process that typically costs a global bank between $10m and $50m a year. Regulators, particularly in EMEA, now expect firms to produce more quantifiable methods and outputs.
RegTech firm Corlytics believes it has an answer. The company has launched its Emerging Risk Quantification (ERQ) engine, which brings together four capabilities developed separately over the past decade.
These are structured, machine-readable regulatory obligations under continuous curation; codified policy content mapped granularly to those obligations; control data linked back to policies and obligations, making completeness objective and testable; and 12 years of enforcement data capturing global fines at event level, with 150 data points per event.
Each capability was built to solve its own problem. Combined, they feed a model in which obligations define the risk surface, controls define mitigation, enforcement defines severity and horizon scanning signals direction of travel.
Source link







