Banking
Liquidity stress testing: severity and scenarios
Liquidity stress testing turns on two questions: which scenarios a bank models, and how severe it makes them. March 2023 showed that the standardised answers were calibrated for slower funding markets than the ones banks face today.
In March 2023, Silicon Valley Bank failed in a matter of days. Depositors coordinating on social media and moving money through a banking app pulled funds faster than any standard liquidity stress test had asked the bank to withstand. The thirty-day survival horizon at the centre of the global liquidity rules had been overtaken by a run that emptied the bank in a few days.
Liquidity stress testing is the discipline of asking what would happen to a bank’s cash position if funding dried up and outflows spiked, and whether the bank holds enough liquid assets to survive it. Two choices govern the whole exercise: which scenarios to model, and how severe to make them. Get the scenarios wrong and the test measures the wrong shock; get the severity wrong and it measures the right shock too gently.
For most of the past decade those two choices were treated as largely settled, anchored to a standardised regulatory scenario that every bank ran in much the same way. The 2023 turmoil reopened both. The Prudential Regulation Authority (PRA) is now consulting on a framework that pushes severity higher and adds a scenario the old rules never contemplated. Understanding liquidity stress testing today means understanding why the standardised answers weren’t enough.
What does the LCR actually stress-test?
Every bank’s liquidity stress testing starts from a scenario it didn’t design. The Liquidity Coverage Ratio (LCR) is the post-crisis standard developed by the Basel Committee on Banking Supervision and retained in UK law. It requires a bank to hold enough high-quality liquid assets to survive a severe thirty-day stress without leaning on emergency central bank funding. The ratio of those assets to net outflows over the thirty days must be at least 100%.
What makes the LCR a stress test rather than a static ratio is the scenario baked into the outflow side. The standard prescribes a combined shock, applying an idiosyncratic stress and a market-wide stress at the same time:
BCBS
Basel III international framework for liquidity risk measurement, standards and monitoring
View source ↗- The idiosyncratic shock: a partial loss of unsecured wholesale funding, a credit rating downgrade, increased collateral calls on derivatives, and partial drawdown of the committed facilities the bank has extended to others. The structure is the one the 2010 standard set out and the UK retained; the run-off factors themselves were recalibrated in 2013.1
- The market-wide shock: a partial loss of secured funding capacity, and elevated outflows from both retail and wholesale deposits.
The crucial feature is that the run-off rates are fixed by the rulebook, not chosen by the bank. A run-off rate is the percentage of each deposit or funding type assumed to leave. That standardisation is the LCR’s strength: it makes liquidity comparable across institutions and removes the temptation to assume away a bank’s own funding fragility.
That same standardisation is also the LCR’s weakness. A single set of run-off rates, written once and applied to every bank, can only ever represent the regulator’s view of a typical stress. It cannot capture what would empty a particular bank’s funding base, and it cannot update itself when the speed of a run changes. Silicon Valley Bank’s depositors proved the point, leaving far faster than the standard assumed.
Your scenarios, not the rulebook’s
The standardised scenario is the floor, not the whole exercise. The bank-specific work happens in the Internal Liquidity Adequacy Assessment Process (ILAAP), the firm-led assessment of all material liquidity and funding risks that the PRA reviews through its liquidity supervisory review, under supervisory statement SS24/15. This is where a bank designs its own scenarios and decides how hard to push them. We walk through the ILAAP itself, buffers and drawdown mechanics included, in our companion piece on ILAAP stress testing2.
The PRA expects more than one scenario, and the LCR standard supplies the combination underneath it: BCBS 188 specifies "a combined idiosyncratic and market-wide shock".1 In practice that means at least three: a name-specific stress (trouble that hits the bank alone, such as a ratings downgrade or an operational loss), a market-wide stress (a system-wide funding seizure that hits everyone), and a combination of the two. SS24/15 then expects the resulting cash-flow curve to be read both within the 30-day LCR horizon and across survival days along the firm’s own risk-appetite horizon, at daily granularity, because a shock that is survivable over a quarter can still be fatal in the first forty-eight hours.
The standardised scenario is the floor, not the test. The test is the one a bank builds for its own funding base.
Severity is where the judgement sits. The PRA is explicit that it must reflect the bank’s own funding structure, not a standardised template: an insured retail deposit base and a book of short-dated wholesale money don’t run at the same speed, and their stresses shouldn’t either. What comes out is concrete: a net cash position for each scenario at each horizon, and a verdict on whether the buffer holds. In practice that makes the ILAAP’s job the opposite of a compliance check. The ILAAP is not there to confirm the bank passes the LCR, but to find the stress the LCR does not describe.3
Why did Silicon Valley Bank outrun the LCR’s run-off rates?
For more than a decade the standardised assumptions held up well enough that few questioned their severity. March 2023 ended that. What failed at Silicon Valley Bank wasn’t capital adequacy but an assumption: that deposits leave at the pace the post-crisis run-off rates were calibrated to.
The frame was the issue. The LCR was written when moving a large deposit meant a phone call or a wire instruction, and a run took days to build. By 2023 a coordinated withdrawal could be organised on social media and executed from a phone. The PRA’s own reading of what followed is that "very significant liquidity outflows can happen in a few days".4 The standardised run-off rates, calibrated on pre-digital data, understated both how much could leave and how fast.
The Basel Committee reached the same conclusion. Its 2024 progress report to the G20, drawing on the banks that failed or came close (institutions with combined assets of roughly $1.1 trillion), found that the LCR’s standardised outflow rates weren’t calibrated for the speed at which digitally networked depositors can move.5
The Committee flagged three areas for further work: how to treat uninsured deposits, those above the protection limit, which are the quickest to leave; how much faster money moves when a customer can transfer it from a phone; and how central bank facility usage interacts with LCR compliance in a stress, a question of both mechanics and, in our reading, of the stigma firms attach to borrowing.5 The diagnosis went to severity and to design: the run-off rates were too slow, and the scenario set was missing one.
What does CP5/26 propose to make liquidity stress tests more severe?
The regulatory response is to recalibrate severity upward. In March 2026 the PRA published consultation paper CP5/26, the first comprehensive look at that layer since the post-crisis rules were retained after Brexit. It proposes to modernise the framework "with the focus on targeted changes to Pillar 2 through the Internal Liquidity Adequacy Assessment (ILAA) rules and supervisory expectations".4 Two of its proposals speak directly to scenario design and severity, and a third raises the bar in a different way.
CP5/26’s first proposal is a new sudden-outflow stress scenario, built specifically to capture the digital amplification the old calibration missed: social-media-driven deposit flight can produce outflow rates well beyond anything in the pre-digital record.
CP5/26’s second proposal revises the Pillar 2 combined benchmark stress, updating its horizon and cash-flow assumptions to the faster run dynamics observed in 2023.
CP5/26’s third proposal raises severity from the asset side, "requiring them to assess ‘monetisation risk’ rather than ‘marketable asset risk’" in internal stress testing.4 The test is whether a bank’s liquid assets can actually be sold or pledged as collateral under stress, not merely whether they sit on an eligible list. A buffer that cannot be monetised in time fails the test however large it is, which makes monetisation a severity question as much as a quality one.
In practice
CP5/26 is a consultation, not a rule. It was published in March 2026 and closes on 17 June 2026, with a policy statement to follow. A bank cannot yet calibrate to a final standard. What it can do is read the direction, which is unambiguous, and pressure-test its own run-off assumptions against a faster, digitally driven outflow now, rather than wait for the rule to land.
The direction of travel is consistent, and it runs through Pillar 2 rather than through the LCR. The severity is being raised in the firm-specific layer, where the ILAAP sits, while the LCR’s own run-off rates stay where they are. Our own view is that a bank still calibrating to pre-2023 run speeds will struggle to defend that in its next L-SREP, consultation or no consultation.
What is reverse stress testing, and how does it differ from a forward scenario?
Forward scenarios, however severe, share a blind spot: they begin from a shock the bank has already thought of. FG11/07 remains the most detailed operational guidance on running the exercise the other way round.6 Reverse stress testing removes the blind spot in a forward scenario by fixing the endpoint and working backward. Instead of asking how a chosen stress affects the bank, it asks what set of events would make the business model fail, and reasons back to the scenario that produces them.
The requirement sits in Chapter 15 of the Internal Capital Adequacy Assessment Part of the PRA Rulebook, with SS31/15 setting the expectations on top of it, and it is where severity gets its honest benchmark:7 the scenario that fails the bank defines how severe severe needs to be. We go deeper on the method in our companion piece on reverse stress testing8.
The definition of failure is the part practitioners most often get wrong. The PRA defines it as the point at which the market loses confidence and the bank can no longer carry on its business, and it is explicit that this point "may be reached well before the firm’s financial resources are exhausted". For liquidity, this is the entire game. A bank doesn’t fail when its buffer hits zero; it fails when counterparties stop rolling funding and depositors leave, which happens while the buffer still looks healthy on paper.
Reverse stress testing is uncomfortable by design. That discomfort is its value.
Scenario selection here is governed by plausibility, not probability. Guidance from the then Financial Services Authority, inherited by the Financial Conduct Authority, instructs firms to start from a wide range of events that could threaten the business model and narrow to the most severe plausible candidates, rather than filling in the corners of a prescribed grid. For a liquidity reverse stress test, that means identifying the funding concentration, rating trigger, or reputational event that would empty the bank fastest, and asking honestly how far away it is. For Silicon Valley Bank the answer was a concentrated, uninsured deposit base and two days, over which 85% of its deposits went, on the Basel Committee’s figures.5
What should a liquidity risk team actually do about severity?
For a treasury or liquidity risk team, the lesson of Silicon Valley Bank’s failure is that severity isn’t a setting inherited from the rulebook. The LCR scenario is a shared floor, useful for comparability. It should never become the ceiling on what a bank imagines going wrong. The work that matters is the calibration the bank owns: the run-off rates applied to its own deposits, the horizons over which it tests survival, and the plausible scenario that would actually break it.
The practical action isn’t another model. It is a defensible severity case. A bank should be able to show, for each material funding source, why its assumed run-off rate fits that source’s behaviour in a fast, digital stress, why its survival horizons are the right ones for its balance sheet, and how its reverse stress test informs the scenarios it runs forward. When the PRA’s revised framework lands, the banks that adjust quickest will be those that had already stopped treating the standardised scenario as the answer.
The reason to get this right goes beyond the supervisor. When a bank fails a liquidity run, depositors lose access to their money, confidence drains from every bank that looks similar, and the cost of restoring it lands on the public. Silicon Valley Bank made that sequence real in the space of a weekend. Stress testing, done honestly, is how a bank finds that failure on paper first, while it is still cheap to fix.
Frequently asked questions
What is liquidity stress testing?
Liquidity stress testing asks what would happen to a bank's cash position if funding dried up and outflows spiked, and whether the bank holds enough liquid assets to survive it. Two choices govern the whole exercise: which scenarios to model, and how severe to make them. Get the scenarios wrong and the test measures the wrong shock. Get the severity wrong and it measures the right shock too gently.
What scenario is built into the Liquidity Coverage Ratio?
The LCR is a stress test rather than a static ratio, because a scenario is baked into its outflow side. The standard prescribes a combined shock, applying an idiosyncratic and a market-wide stress at once. The idiosyncratic side assumes a partial loss of unsecured wholesale funding, a credit rating downgrade, increased collateral calls on derivatives, and partial drawdown of the committed facilities the bank has extended to others. The market-wide side assumes a partial loss of secured funding capacity and elevated outflows from both retail and wholesale deposits.
Why is the LCR a floor rather than the whole test?
The run-off rates in the LCR, meaning the percentage of each deposit or funding type assumed to leave, are fixed by the rulebook rather than chosen by the bank. That standardisation is the strength: it makes liquidity comparable across institutions and removes the temptation to assume away a bank's own funding fragility. It is also the limit. One set of run-off rates written once for every bank can only represent the regulator's view of a typical stress. It cannot capture what would empty a particular bank's funding base, and it does not update itself when the speed of a run changes.
Where does a bank design its own liquidity stress scenarios?
Bank-specific scenario work happens in the Internal Liquidity Adequacy Assessment Process, the firm-led assessment of all material liquidity and funding risks that the PRA reviews under supervisory statement SS24/15. SS24/15 expects scenarios selected to reveal the firm’s own funding vulnerabilities, including a macroeconomic stress, which in practice means at least three: a name-specific stress hitting the bank alone, such as a ratings downgrade or an operational loss, a market-wide funding seizure, and a combination of the two. The cash-flow curve is read both within the 30-day LCR horizon and across survival days along the firm’s own risk-appetite horizon, at daily granularity, because a shock survivable over a quarter can still be fatal in the first forty-eight hours.
How severe should a liquidity stress scenario be?
Severity is where the judgement sits, and the PRA is explicit that it must reflect the bank's own funding structure rather than a standardised template. An insured retail deposit base and a book of short-dated wholesale money do not run at the same speed, so their stresses should not either. What the exercise produces is concrete: a net cash position for each scenario at each horizon, and a verdict on whether the buffer holds.
What did the Basel Committee conclude after the 2023 bank failures?
The Basel Committee's 2024 progress report to the G20, drawing on the banks that failed or came close, found that the LCR's standardised outflow rates were not calibrated for the speed at which digitally networked depositors can move. It flagged three areas for further work: how to treat uninsured deposits, meaning those above the protection limit, which are the quickest to leave; how much faster money moves when a customer can transfer it from a phone; and the interaction between LCR compliance and use of central bank facilities during a stress.
What does CP5/26 propose on scenario design and severity?
CP5/26, published by the PRA in March 2026, is the first comprehensive modernisation of the UK Pillar 2 liquidity framework since the post-crisis rules were retained. Three proposals bear on stress testing. It adds a sudden-outflow scenario built for the digital amplification the old calibration missed. It revises the Pillar 2 combined benchmark stress, updating its horizon and cash-flow assumptions to the faster run dynamics observed in 2023. And it replaces the loose notion of a marketable asset with an explicit test of monetisation risk. The consultation closed on 17 June 2026, so a bank cannot yet calibrate to a final standard.
What is monetisation risk, and why is it a severity question?
Monetisation risk is whether a bank's liquid assets can actually be sold or pledged as collateral under stress, rather than whether they sit on an eligible list. It belongs to severity as much as to asset quality, because a buffer that cannot be converted in time fails the test however large it is. Raising severity from the asset side is a different lever from raising assumed outflow rates, and CP5/26 pulls both.
How does reverse stress testing set a benchmark for severity?
Forward scenarios share a blind spot: they begin from a shock the bank has already thought of. Reverse stress testing fixes the endpoint at business-model failure and reasons back to the events that would produce it, so the scenario that fails the bank defines how severe severe needs to be. The expectation is set out in supervisory statement SS31/15, with the underlying obligation in the PRA Rulebook. Selection is governed by plausibility rather than probability: start from a wide range of events that could threaten the business model and narrow to the most severe plausible candidates.
Why does a bank fail before its buffer reaches zero?
Because failure is a confidence event. The PRA defines it as the point at which the market loses confidence and the bank can no longer carry on its business, and states that this point may be reached well before the firm's financial resources are exhausted. A bank does not fail when the buffer hits zero. It fails when counterparties stop rolling funding and depositors leave, which happens while the buffer still looks healthy on paper.
What made Silicon Valley Bank's funding base vulnerable?
Silicon Valley Bank held a concentrated deposit base that was largely uninsured, meaning above the protection limit, and uninsured depositors are the quickest to leave. It failed within days in March 2023, with depositors coordinating through social media and moving money through a banking app faster than any standard liquidity stress test had asked the bank to withstand. For a liquidity reverse stress test, the equivalent question is which funding concentration, rating trigger or reputational event would empty the bank fastest, and how far away it actually sits.
Sources
- 1 BCBS. Basel III international framework for liquidity risk measurement, standards and monitoring View source ↗
- 2 Gini. ILAAP stress testing: PRA expectations View source ↗
- 3 PRA. SS24/15: The PRA's approach to supervising liquidity and funding risks View source ↗
- 4 PRA. CP5/26: Modernising the liquidity policy framework View source ↗
- 5 BCBS. The 2023 banking turmoil and liquidity risk, a progress report View source ↗
- 6 FSA. FG11/07: Reverse stress-testing surgeries, frequently asked questions View source ↗
- 7 PRA. SS31/15: The ICAAP and the SREP, Chapter 4 View source ↗
- 8 Gini. Reverse stress testing explained View source ↗