Regulation is changing credit risk measurement – and the processes behind it
Karl Tasch traces the regulatory developments from Basel II to the present day in the second edition of Kreditrisikomessung and examines what they mean for credit risk measurement and risk management in practice.
Credit risks have long been systematically analysed and managed. However, as regulation has become increasingly differentiated – particularly since Basel II – the requirements for credit risk measurement in practice have also evolved. Alongside models and methodologies, data, documentation, governance and the underlying processes are becoming increasingly important.
The second edition of Kreditrisikomessung: Statistische Grundlagen, Methoden und Modellierung, published by Springer Spektrum, provides an updated version of the reference work by Andreas Henking, Christian Bluhm, Ludwig Fahrmeir and Karl Tasch. In addition to the statistical foundations and methodologies of credit risk measurement, the new edition addresses developments that have significantly shaped the regulatory framework for banks.
Karl Tasch, CEO of FinAPU, contributed the chapter “Regulatorische Entwicklungen und ihre Auswirkungen auf die Kreditrisikomessung” to the new edition. It traces the evolution of regulatory requirements from Basel II through Basel III to the final Basel III reforms and examines what these changes mean for credit risk measurement in practice.
From risk sensitivity to limiting model risk
Basel II marked a significant step towards more risk-sensitive banking regulation. Internal rating systems and banks’ own estimates of key risk parameters such as probability of default (PD), loss given default (LGD) and exposure at default (EAD) could directly influence the calculation of regulatory capital requirements. The financial crisis of 2007/2008, however, also exposed the limitations of this approach. Differences between internal models, limited comparability and high model complexity came under increasing regulatory scrutiny. Basel III and the final reforms therefore limit the scope for internal models and strengthen standardised approaches.
One particularly visible example is the output floor: risk-weighted assets calculated using internal models may not fall below a specified proportion of the values calculated under standardised approaches. As a result, the standardised approach is becoming increasingly relevant even for institutions that have traditionally managed their credit risks primarily using internal models.
This development is also reflected in the Standardised Credit Risk Assessment (SCRA). For certain exposures to institutions without an external rating, CRR III requires classification into regulatory credit quality grades. Financial information must be collected and assessed, qualitative criteria considered, classifications documented in a traceable manner and decisions applied consistently across portfolios. A “standardised approach” therefore by no means makes credit risk assessment a purely mechanical process.
Credit risk measurement is becoming increasingly operational
Regulatory requirements can increasingly no longer be considered in isolation from their operational implementation. A model may be methodologically sophisticated and statistically robust. In day-to-day regulatory practice, it must also be possible to trace the data on which a decision was based, the criteria that were applied and how the result can be reproduced.
At the same time, such procedures must work not only for individual exposures but across large portfolios. Regulation therefore has a direct impact on data, processes, documentation and governance – and on how regulatory requirements are translated into robust, transparent and scalable processes.
Looking beyond Basel
The evolution does not end with the final Basel III reforms. The outlook in the regulatory chapter addresses further topics that are likely to shape risk management in the future. These include climate and ESG risks, the continuing digitalisation of supervision and digital operational resilience. At the same time, Artificial Intelligence and Big Data are becoming increasingly important for rating and decision-making processes.
This raises new regulatory questions: How transparent and explainable must automated decisions be? How are models validated and changes documented? What requirements apply to data quality, governance and reproducibility? And how can appropriate human oversight be maintained as automation increases?
Credit risk measurement is therefore increasingly situated at the intersection of methodology, regulation, data and technology.
About the publication
Andreas Henking, Christian Bluhm, Ludwig Fahrmeir, Karl Tasch (2026)
Kreditrisikomessung: Statistische Grundlagen, Methoden und Modellierung
2nd edition, Springer Spektrum
Contribution by Karl Tasch: “Regulatorische Entwicklungen und ihre Auswirkungen auf die Kreditrisikomessung”