Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Key Risk Indicators: Leading Signals, Not Lagging Counts

A key risk indicator is a measure chosen in advance, with a trigger set in advance. A change in it says something about a risk before anybody has to ask. A lagging count reports what already happened; a leading signal moves before the loss. At the invented Vindhya Commercial Bank Limited, 11 of 16 indicators are lagging counts, and 4 of the year's 13 incidents were preceded by an amber or a red.

One question settles the whole subject, and it is short enough to ask in a meeting without preparing for it. If this number moves today, has the thing I care about already happened? If the answer is yes, the number is a count, and its value is in explaining the past. If the answer is no, and the movement comes before the event, the number is a signal, and its value is entirely in the time between the movement and the loss. Almost every argument anybody has ever had about a dashboard is that question going unasked, and with the question in hand any indicator set in any institution can be sorted in about five minutes.

What is a key risk indicator, and what makes one key rather than merely interesting?

A key risk indicatorA measure chosen in advance, with a trigger set in advance, because a change in it says something about a risk somebody has named. is a measure that has to pass three tests before it earns a row on anything. The measure has to be chosen in advance. Otherwise the choice falls on whatever tells the most comfortable story after the event. The measure has to be measurable repeatedly, in the same way, from a source that will still exist next quarter. And the measure has to be connected to a risk somebody has actually named. Then a movement in it is a statement about something the institution has already agreed it cares about. Miss any one of the three and what remains is a number in a report rather than an indicator.

Take the household version first. The mechanism is identical and the stakes are legible. A household running on one salary decides to watch three things every month: how many days of expenses sit in the bank, whether the earner's employer has started delaying salary credits, and how many months are left on the rental agreement. All three were chosen before anything went wrong. All three can be measured the same way every month by looking at one statement, one bank credit date and one document. And all three attach to one risk somebody named out loud: the single income stops. Now add a fourth measure, the monthly electricity bill. The electricity bill is measurable, it is repeatable, it moves, and it has nothing to do with the risk that the income stops. The bill is interesting. The bill is not key.

The distinction between key and interesting does most of the work. Key means connected to a named risk, not important-sounding and not merely available. A bank can measure a very large number of things about itself, and the temptation of a dashboard is to fill it with whatever the systems already produce, because those numbers cost nothing to obtain and nobody has to justify them. The result is a dashboard full of movement, in which nothing that moves is telling anybody anything, and everybody who receives it learns to skim. A dashboardA single view of a chosen set of indicators with their current status, which is really a list of choices about what to watch. of everything measurable is a dashboard of nothing, and the way to tell is to take any row and ask which named risk it belongs to. If the answer takes more than one sentence, the row is decoration.

THREE GATES, AND A MEASURE HAS TO PASS ALL THREE Fail any one and what remains is a number on a page, not an indicator. A CANDIDATE GATE 1 chosen in advance GATE 2 measurable repeatedly GATE 3 attached to a named risk WHAT FAILS HERE A measure picked after the event, because it tells a good story now. WHAT FAILS HERE A measure whose source or definition changes, so months do not compare. WHAT FAILS HERE A measure that is real, repeatable and attached to no risk anybody named. THE HOUSEHOLD ELECTRICITY BILL, WORKED THROUGH THE GATES gate 1 passed: chosen up front gate 2 passed: same bill monthly gate 3 failed: no named risk INTERESTING, NOT KEY
A measure has to clear all three gates before it earns a row, and the third gate is the one that quietly rejects most candidates, because plenty of numbers are real and repeatable while belonging to no risk the institution has ever named out loud.

What separates a lagging count from a leading signal?

The whole of it is one question, and there is no second criterion hiding behind the first. The question applies to any indicator at all: if this number moves today, has the thing I care about already happened?

A lagging countAn indicator that counts something that has already happened, whose value is in explaining the past rather than in buying time. answers yes. Losses booked, breaches recorded, issues overdue, complaints received: every one of those moves because the event occurred. The number is a record. The count is often a good record, usually correct, and frequently the only thing anybody can agree on. But by the time it moves the loss is already in the accounts, so it cannot warn anybody. A leading signalAn indicator that moves before the loss, whose value is entirely in the time between the movement and the event. answers no. The signal moves because a condition is forming, and the loss, if it comes at all, comes later. Its whole value is the gap in between.

The difference is not the subject matter, it is the timing. Timing is worth stating flatly, and the commonest mistake is to sort indicators by topic. People assume that anything about fraud is a leading signal because fraud sounds urgent, and anything about complaints is lagging because complaints sound administrative. Neither holds. A count of fraud losses booked is a lagging count, and the proportion of exceptions approved by the very person who raised them is a leading signal, and both are about the same risk. In this invented bank the second of those is one of only five indicators that moves before anything is lost, and it is not a fraud number at all: it is an approvals number.

The everyday test runs the same way. A street food stall outside a single office building can count its takings each evening. The customers either came or they did not, so the takings are a lagging count. Or the stall can count how many parked scooters are outside the office at nine in the morning. The scooter count moves in the week the office starts letting people work from home, weeks before the takings fall. Same risk, being that one building supplies every customer. One number records it after the fact; the other one sees it forming. A count cannot be made leading by watching it more often, and a signal cannot be made lagging by ignoring it.

IF THIS NUMBER MOVES TODAY, HAS THE THING ALREADY HAPPENED? YES NO A LAGGING COUNT It counts something that already happened. Its value is in explaining the past. IN THIS INVENTED BANK K9, operational loss events recorded this month. K6, backtesting exceptions in the last 250 days. Both are correct. Neither buys a single day. A LEADING SIGNAL It moves while the condition is forming. Its value is the time before the event. IN THIS INVENTED BANK K15, exceptions approved by whoever raised them. K12, attrition in the dealing room. Neither is a loss figure. That is the point. THE SAME TWELVE MONTHS, WATCHED TWO WAYS COUNT moves here, on the day the loss is booked SIGNAL moves here, while the condition is forming THIS GAP IS THE WHOLE VALUE OF A SIGNAL
Two indicators can attach to exactly the same risk and still be different objects, because the count only moves on the day the loss lands while the signal moves while the condition is still forming, and the distance between those two moments is the only thing anybody buys by watching.
Try it out

What is the single question that settles whether an indicator is lagging or leading?

Risk Management Program Bootcamp — Fin Maverick

Why does a bank end up with mostly lagging counts?

Not through laziness, and not because anybody prefers them. Counts accumulate because of what happens in the room where a dashboard is agreed, and the mechanism is almost entirely social. Nobody argues with a count, and everybody argues with a signal.

Put a count of losses booked on the table and there is nothing to dispute. The number is a fact somebody can look up in the loss register, the definition writes itself, and the source is already producing it every month for another purpose. The count costs nothing to add and it survives every challenge. The only challenge available is that the register is wrong, and that is a different conversation. Now put a leading signal on the table. The share of manual journal entries at close, say. Immediately somebody asks the fair question: why does that predict anything? And the honest answer is that it is a claim, held by the person proposing it, that manual entries are where errors and manipulations hide, and that the share rising means the automated route is being bypassed more often. The claim can be doubted, and doubting it costs the doubter nothing.

So the two kinds of row face completely different odds of surviving the meeting. A count needs no defence and gets none. A signal needs a defence and finds one person to give it. Over three or four annual cycles of adding a row here and dropping a row there, the composition drifts, and nobody ever made a decision to make the dashboard backward looking. The ease of agreement is exactly what makes a count useless as a warning, and it is also exactly why the count is on the dashboard.

The same drift appears in a school report. Marks in last term's examinations are a count: undisputed, easy to produce, and entirely about what already happened. Whether the child has stopped asking questions in class is a signal, and it would tell a parent months earlier. Nobody writes that one down. A teacher who writes it down can be asked to justify it, and a teacher who writes down a mark cannot.

TWO ROWS ARRIVE AT THE SAME MEETING PROPOSED: A COUNT OF LOSSES BOOKED It is a fact anybody in the room can look up. The definition writes itself. The source already produces it monthly. NO CHALLENGE. IT STAYS. PROPOSED: MANUAL JOURNAL ENTRY SHARE It is a claim that one thing predicts another. Somebody asks why it predicts anything. Doubting it costs the doubter nothing. CHALLENGED. IT NEEDS A DEFENDER. WHAT SEVERAL ANNUAL CYCLES OF THAT DO TO A DASHBOARD an even set COUNTS SIGNALS this bank 11 LAGGING COUNTS 5 SIGNALS 8 to 8 68.8 to 31.3 Nobody ever decided to make the dashboard backward looking. It drifted, one undisputed row at a time.
Counts survive the meeting because there is nothing in them to dispute, signals need somebody willing to defend a claim, and a dashboard that nobody redesigned ends up two thirds backward looking purely through the accumulated arithmetic of what is easy to agree.

One caution before the list. The even split drawn on the left of that figure is an illustration of a starting point, not a target and not this bank's history: there is no correct proportion of leading to lagging for an institution to hold. The invented bank's own composition can be counted exactly, and the table below gives it.

Try it out

Of the sixteen indicators this invented bank runs, how many are genuinely leading, meaning they move before the loss rather than after it?

Derivatives Foundation Bootcamp — Fin Maverick

What does a real dashboard of sixteen indicators actually contain?

Vindhya Commercial Bank Limited runs sixteen key risk indicators, and every number attached to them is that bank's own. Its own record counts them and does not number them, so the numbering K1 to K16 below is added here to give every row an identifier that can be cited without anybody writing a bare number. Month 12 is this bank's reporting date. At month 12 the sixteen stand at 9 green, 5 amberA status meaning attention is required and no limit has been breached, whose usefulness depends entirely on where the level was set. and 2 red, and 9 plus 5 plus 2 is 16.

Two of those figures are locked by the bank's own record and the rest is assignment. The record fixes the sixteen, fixes 9 green, 5 amber and 2 red, and fixes which two are red, and it fixes nothing else. So the colours shown against K3 to K11 below are an allocation against the bank's locked totals and its own trigger levels, rather than the bank's own record. Every one of the sixteen rows, and every number in them, belongs to the invented bank.

RowWhat it measuresReading at month 12Status
The eleven lagging counts, K1 to K11
K1Sector concentration against limit L313.0 per cent of gross advances against a 12.0 per cent limitRED
K2Top twenty depositor share against limit L1214.5 per cent of deposits against a 12.0 per cent limitRED
K3Net operational loss, rolling twelve months, against limit L11Rs 43.8 crore of Rs 60.0 croreAMBER
K4Open issues past their agreed remediation date31 of 92AMBER
K5Open issues aged beyond 365 days, being ageing bucket AG59 issuesAMBER
K6Backtesting exceptions in the last 250 days7 exceptions, being X1 to X7AMBER
K7Single name exposure utilisation on limit L194.5 per centAMBER
K8Customer complaints closed in the monthwithin the bank's own triggerGREEN
K9Operational loss events recorded in the monthwithin the bank's own triggerGREEN
K10Near misses recordedwithin the bank's own triggerGREEN
K11Trading book value at risk utilisation on limit L586.7 per centGREEN
The five leading signals, K12 to K16
K12Attrition in the dealing roomwithin the bank's own triggerGREEN
K13Age profile of open privileged access rightswithin the bank's own triggerGREEN
K14Share of manual journal entries at closewithin the bank's own triggerGREEN
K15Exceptions approved by the same person who raised themwithin the bank's own triggerGREEN
K16Certificate of deposit roll ratewithin the bank's own triggerGREEN
1611 lagging counts and 5 leading signals68.8 per cent lagging, 31.3 per cent leading9 G, 5 A, 2 R

Read the rows on their own and nothing jumps out. Two things are red, five need attention, nine are fine, and a committee looking at that would conclude, quite reasonably, that most of the bank is in order and two concentrations need work. The finding is not in any row. The finding is in the arrangement.

What changes when the dashboard is sorted by type instead of by colour?

Sorting by colour gives a summary of health. Sorting by type gives a summary of foresight, and they are not the same summary at all. Here is what the second sort shows, and it is exact. Both reds, K1 and K2, are lagging counts: a sector concentration that has already crossed limit L3 and a depositor concentration that has already crossed limit L12. All five leading signals, K12 to K16, are green. Every amber, K3 to K7, is also a lagging count.

Say that back in plain words. Everything on this dashboard that is shouting is a record of something that has already gone wrong, and everything capable of moving first is silent. The type sort delivers a genuinely different message from the colour sort. Green on a leading signal is not bad news. Green on a signal is real good news and should be read as such. A committee told that two things are red and five things need attention has been told about the past in detail and about the next quarter not at all, and nothing on the dashboard distinguishes those two kinds of telling.

SIXTEEN ROWS, ARRANGED TWICE, WITH NOTHING CHANGED BUT THE ORDER SORTED BY COLOUR SORTED BY TYPE RED, 2 K1 K2 AMBER, 5 K3 K4 K5 K6 K7 GREEN, 9 K8 K9 K10 K11 K12 K13 K14 K15 K16 What the committee reads: two problems, five things to watch, and nine that are fine. Most of it is fine. LAGGING COUNTS, 11 K1 K2 K3 K4 K5 K6 K7 K8 K9 K10 K11 LEADING SIGNALS, 5 K12 K13 K14 K15 K16 WHAT THE SECOND SORT SHOWS Both reds are counts of things already done. Every amber is a count as well. All five signals are green and silent. SAME SIXTEEN ROWS. SAME SIXTEEN COLOURS. TWO DIFFERENT MEETINGS. The colour sort answers: how healthy is the bank? The type sort answers: how much notice is it buying? Only the second question has an answer that changes what anybody does next. Colours on K3 to K11 are this sequence's assignment against the invented bank's locked totals of 9 green, 5 amber and 2 red.
Nothing moves between the two columns except the ordering, and yet the left column reports that most of the institution is healthy while the right column reports that everything raising its voice is describing the past, which is the same sixteen readings answering two different questions.
Try it out

Both red indicators are lagging counts and all five leading signals are green. What has the board actually been told?

Breaking Into Quants Bootcamp — Fin Maverick

Can the most important thing on a dashboard be something that is not on it?

Yes, and this invented bank supplies the example. Three of its twelve limits are in live breach at month 12. Limit L3, sector concentration, is breach B1 and it appears as indicator K1. Limit L12, depositor concentration, is breach B4 and it appears as indicator K2. Limit L10, the wholesale funding share, is breach B3, standing at 22.6 per cent of total liabilities against a 20.0 per cent limit, and it appears nowhere among the sixteen indicators at all.

Nobody removed it, and the absence is the part worth sitting with. There was no meeting in which somebody argued for taking the wholesale funding share off the dashboard and won. The wholesale funding share was simply never chosen, at some point years ago, by people picking sixteen things out of a very long list of measurable things who had to stop somewhere. And because it was never chosen, it produces no colour, no trigger and no line of discussion, every single month, including the months in which it crossed its limit.

The absence does something to the reading. A committee looking at the dashboard sees two reds, both concentrations, and forms a picture: this bank has a concentration problem on the asset side and on the deposit side. The picture is not wrong. The picture is incomplete, and the incompleteness is invisible from inside the dashboard. The third concentration, on the funding side, is the one that is missing. Absence produces nothing to notice, so an indicator that is absent cannot be spotted by reading the dashboard, however carefully. The only route to it is to read the dashboard against something outside it: the breach log, the limit set, the register of risks. Reading the dashboard against the breach log takes ten minutes a quarter, and it is the single highest yield move anybody can make with a dashboard.

The household version is unpleasantly familiar. A household tracks its bank balance, its card outstanding and its loan instalment every month, all three chosen years ago, all three carefully watched. The household does not track how many months of the earner's notice period remain. Nobody ever put that on the list. Every month, the three tracked numbers are read and discussed. The untracked one goes to zero without producing a single conversation.

THREE LIVE BREACHES ON ONE SIDE, TWO INDICATORS ON THE OTHER THE BREACH LOG AT MONTH 12 B1, limit L3, sector concentration 13.0 per cent against a 12.0 per cent limit B4, limit L12, depositor concentration 14.5 per cent against a 12.0 per cent limit B3, limit L10, wholesale funding share 22.6 per cent against a 20.0 per cent limit THE SIXTEEN INDICATORS K1, RED, sector concentration produces a colour, a trigger and a discussion K2, RED, depositor concentration produces a colour, a trigger and a discussion NO ROW EXISTS HERE nothing to colour, nothing to raise A DASHBOARD IS A LIST OF CHOICES, AND THE CHOICES ARE INVISIBLE FROM INSIDE IT Nobody removed the wholesale funding share. It was never chosen, so it has produced no colour in any month, including the months it crossed its limit. Reading the dashboard against the breach log is the only way to find it.
Two of this bank's three live limit breaches arrive on the dashboard as red rows and argue for themselves every month, while the third has no row to arrive in, so the strongest thing anybody can say about this dashboard is a sentence about something that is not printed on it.
Try it out

The wholesale funding share is in breach at 22.6 per cent against a 20.0 per cent limit and is not one of the sixteen indicators. How would anybody notice?

Where does an amber trigger come from, and how wide should the band be?

An indicator without a triggerThe level at which an indicator changes colour, set by the institution itself and in advance rather than in the meeting. is a number that moves. The trigger is what turns movement into a status, and it is worth being blunt about where it comes from. Nobody outside the institution sets it. It is not derived, it is not published anywhere, and no supervisor hands it over. The trigger is a decision the institution makes about itself, in advance, and writes down. Every trigger level below belongs to the invented Vindhya Commercial Bank Limited, and none of them is a requirement of any kind.

Take indicator K3, the net operational loss over a rolling twelve months. The bank's own limit L11 caps that at Rs 60.0 crore. The position at month 12 is Rs 43.8 crore, the year's thirteen incidents I1 to I13 netted down, and it stands at 73.0 per cent of the limit. Somewhere between zero and Rs 60.0 crore, somebody has to put an amber line. Where?

The two ends answer that faster than any principle. Put the amber at Rs 60.0 crore, being 100 per cent of the limit, and the indicator changes colour at exactly the moment the limit is gone. The colour change is not a warning but a breach report, and the breach log already carries the same fact. Put the amber at Rs 43.8 crore, being 73.0 per cent, and the indicator turns amber on the day it is switched on. Rs 43.8 crore is where the bank already is. The indicator has told nobody anything, and it will keep telling them nothing until the position moves. Both ends destroy the indicator, and they destroy it in opposite directions.

So the useful range for the amber on K3 runs from Rs 43.8 crore to Rs 60.0 crore. The range is Rs 16.2 crore wide, being 27.0 per cent of the limit. The distance between the amber and the limit is the bandThe distance between a warning level and the limit it warns about, which is the whole of the warning an indicator gives., and it is not a detail of the design, it is the design. Set the band at zero and there is no warning. Set it so wide that the amber sits below today's position and there is no warning either, only a permanent colour. The width of the band is the whole of the warning, measured in whatever the indicator is measured in.

The everyday version is the fuel gauge. A car whose warning light comes on when the tank is empty has a light and no warning. A car whose light is on permanently because it was wired to come on at three quarters full has a light and no warning either, and after a week the driver stops seeing it. The useful setting leaves enough distance to reach a fuel station. How much distance that is depends on where the car is driven, and that is a decision about the driver rather than about the car.

WHERE AN AMBER TRIGGER CAN USEFULLY SIT ON INDICATOR K3 Net operational loss, rolling twelve months, Rs crore. Every figure is the invented bank's own. AMBER HERE FIRES ON DAY ONE THE USEFUL WINDOW Rs 0 Rs 20.0 cr Rs 40.0 cr Rs 60.0 cr TODAY: Rs 43.8 CRORE, BEING 73.0 PER CENT OF L11 LIMIT L11: Rs 60.0 CRORE Rs 16.2 CRORE WIDE 27.0 PER CENT OF THE LIMIT SET IT AT TODAY, Rs 43.8 CRORE It turns amber the day it is switched on. SET IT AT THE LIMIT, Rs 60.0 CRORE It reports a breach instead of warning of one.
The only positions worth putting an amber line on lie between where the institution already stands and the limit it is trying not to cross, and on this indicator that whole stretch is worth Rs 16.2 crore, which is far narrower than the full scale makes it look.
Try it out

Somebody proposes setting the amber on K3 at 100 per cent of limit L11, on the grounds that it will never fire unnecessarily. What have they built?

Try it out

Net operational loss stands at Rs 43.8 crore against limit L11 of Rs 60.0 crore. Before the control below is moved: what happens if the amber trigger on K3 is set at 73 per cent of the limit?

Play with it

Move the amber trigger on K3 and watch it stop warning at both ends

One control: a, the amber trigger on indicator K3, net operational loss over a rolling twelve months, expressed as a percentage of limit L11 of Rs 60.0 crore. Today's position is Rs 43.8 crore, being 73.0 per cent. Two consequences move together: the trigger in Rs crore, and the headroom between it and today's position. The headroom is negative wherever the indicator is already amber. A third readout says which month of the year the trigger would first have fired, running the amber against the twelve month build of net loss from incidents I1 to I13. The solved points are these. At a of 50 the trigger is Rs 30.0 crore and the indicator is already amber by Rs 13.8 crore. At 60 it is Rs 36.0 crore, already amber by Rs 7.8 crore. At 70 it is Rs 42.0 crore, and the Rs 42.0 crore there is an amber trigger level on K3 rather than the gross loss of incident I2, a different Rs 42.0 crore in this bank; the indicator is already amber by Rs 1.8 crore. At 73 it is Rs 43.8 crore and the trigger is exactly today's position, so it turns amber on the day it is switched on and tells nobody anything they did not already know. At 80 it is Rs 48.0 crore with Rs 4.2 crore of headroom. At 90 it is Rs 54.0 crore with Rs 10.2 crore. At 100 it is Rs 60.0 crore, the limit itself, so the indicator reports a breach rather than warning of one, and the headroom is the full Rs 16.2 crore. Set below 73 per cent and the indicator is permanently coloured; set at 100 per cent and it is a breach report; the entire useful window is the Rs 16.2 crore in between.

50 PER CENT OF THE LIMIT73 PER CENT100 PER CENT, THE LIMIT
THE YEAR THE INDICATOR WOULD HAVE WATCHED: NET OPERATIONAL LOSS BUILDING TO Rs 43.8 CRORE Rs crore, cumulative across the twelve months of incidents I1 to I13. Every figure is the invented bank's own. 60 45 30 15 0 Rs CRORE LIMIT L11, Rs 60.0 CRORE FIRST FIRES: MONTH 12 AMBER TRIGGER Rs 43.8 CRORE 123456789101112 MONTH OF THE YEAR the step at month 8 is incidents I8 and I13 together THE SAME TRIGGER ON THE SCALE, AND ITS DISTANCE FROM WHERE THE BANK STANDS A TRIGGER HERE IS ALREADY AMBER THE USEFUL WINDOW Rs 0Rs 20.0 crRs 40.0 crRs 60.0 cr TODAY Rs 43.8 CRORE THE TRIGGER IS EXACTLY WHERE THE BANK STANDS No trigger level anywhere in this case is a requirement. Where an amber sits is always the institution's own choice.
Amber trigger
Rs 43.8 cr
Headroom to today
Rs 0.0 cr
First fires in
Month 12

An amber set at 73 per cent of the limit fires at Rs 43.8 crore, which is exactly where the bank stands today, so it turns amber the moment it is switched on, and against the twelve month build of net operational loss it would first have turned amber in month 12, which is the reporting date itself.

Educational illustration. Invented figures throughout. Limit L11 of Rs 60.0 crore, the month 12 position of Rs 43.8 crore, the resulting 73.0 per cent utilisation and the thirteen incident losses that build to it are Vindhya Commercial Bank Limited's own invented figures, and none of them is a requirement of any kind. Every position of the control other than those fixed points is the reader's own setting and is not a figure from the case. This bank's record fixes that K3 is amber and fixes nothing about where its amber line sits. The month readout runs the chosen trigger against the cumulative net loss of the twelve months, being the same Rs 43.8 crore reached in the same order, and it assumes the rolling twelve month window starts at month 1. In this case month 1 is where the record starts. Above 73 per cent the readout says the trigger never fired inside these twelve months, a true statement about this year and not a claim about any other year.

How many of the year's incidents did the dashboard actually warn about?

Four out of thirteen. Test a dashboard against the year, not against itself.

Every argument about dashboards up to this point can be settled by one measurement, and this invented bank has it. Thirteen operational risk incidents happened in the twelve months, numbered I1 to I13. Four of them were preceded by an amber or a red indicator, being 30.8 per cent. Nine arrived with nothing showing at all, being 69.2 per cent. Call that the foresight rateThe share of incidents that were preceded by a warning, which is the only honest test of an indicator set., and note that it is the only test of a dashboard that does not consult the dashboard.

The bank's record fixes the count of four and does not identify which four. The count settles the shape of the failure. A committee that reads sixteen colours every month, for twelve months, was given notice of fewer than one incident in three. The other nine were reported to it after the money had gone.

And the reason is the composition, not the effort. Eleven of the sixteen are counts. A count of losses moves when the loss is booked, and a count of breaches moves when the limit is crossed, so a count cannot precede an incident. So eleven of the sixteen rows were structurally incapable of warning about anything, however diligently anybody read them. A dashboard that is two thirds lagging counts is a history of the quarter and not a warning about the next one, and this one measured exactly that.

THIRTEEN INCIDENTS, AND WHAT THE DASHBOARD WAS SHOWING BEFOREHAND One square for each incident of the year at this invented bank. The order here carries no meaning. 4 PRECEDED BY AN AMBER OR A RED 9 ARRIVED WITH NOTHING SHOWING THE SAME RESULT AS A SHARE OF THE YEAR 30.8 PER CENT 69.2 PER CENT warned not warned WHAT THE RECORD FIXES, AND WHAT IT DOES NOT It fixes that four of the thirteen were preceded by a colour. It does not say which four, so no incident is named here.
Testing an indicator set against the year rather than against its own colours is the only measurement that cannot flatter it, and on this bank's twelve months it returned notice of fewer than one incident in three, which is a fact about the composition rather than about anybody's diligence.
Debt Capital Markets Bootcamp — Fin Maverick

Are the two thirds on the dashboard and the two thirds in the year the same fact?

No, and the closeness is a trap rather than a clue. Two figures in this guide sit 0.4 percentage points apart. Eleven of sixteen indicators being lagging is 68.8 per cent, and nine of thirteen incidents arriving unheralded is 69.2 per cent, and they are different objects with no arithmetic connecting them at all.

The first counts rows on a dashboard. Its denominator is sixteen, it is a fact about how somebody designed a dashboard, and it would be exactly the same figure in a year with no incidents in it. The second counts events in twelve months. Its denominator is thirteen, it is a fact about what happened, and it would move if a single incident had landed differently. Change one and the other does not budge. There is no formula that takes 68.8 per cent and produces 69.2 per cent, and if the bank had run 17 indicators with 12 lagging, the first figure would be 70.6 per cent while the second stayed exactly where it is.

Why labour a coincidence? Because a sentence that puts them side by side without naming both objects invents a relationship that is not there, and it is a very tempting sentence to write. Something like: the dashboard is two thirds backward looking, and that is why two thirds of incidents came as a surprise. The sentence reads beautifully. The sentence is also causal-sounding, memorable and false. The second figure would be roughly what it is even if the composition were different, and the first would be what it is even in a year when nothing happened. A near coincidence is more dangerous than a distant one. Nobody merges a distant one.

TWO FIGURES 0.4 POINTS APART, MEASURED ON TWO DIFFERENT POPULATIONS 68.8 PER CENT 11 of 16 rows on the dashboard LAGGING COUNTS 69.2 PER CENT 9 of 13 incidents in the year ARRIVED UNHERALDED NO ARITHMETIC JOINS THESE TWO THE FIRST IS A DESIGN FACT Denominator 16. It would read the same in a year with no incidents in it at all. THE SECOND IS AN EVENT FACT Denominator 13. It would move if one incident had landed differently.
Two percentages that almost match are describing a dashboard and a year respectively, and because a reader who sees them together will reach for a causal sentence joining them, the safest thing anybody can do is print both denominators next to both numerators every time.
Try it out

Eleven of sixteen indicators are lagging, being 68.8 per cent, and nine of thirteen incidents arrived unheralded, being 69.2 per cent. Are those the same fact?

Ratio Analysis That Says Something — free micro-course from Fin Maverick

What is the cheapest leading signal available, and why did this bank waste it?

A near miss. A near miss carries almost the same information as a loss, it costs nothing to collect because somebody has already noticed it, and it arrives before the money goes. A near miss is the cheapest leading signal any institution has, and this invented bank collected two of them and used neither.

Near miss N3, in month 6: a data quality check caught the collateral valuation feed stale for 2 working days. The check worked exactly as designed. The staleness was found, and nobody raised it as an issue. In month 10 the same feed went stale for 11 working days and 340 loans were wrongly marked, and that is incident I10, at a net loss of Rs 1.4 crore. Near miss N4, in month 7: a checker refused a trade finance document set carrying the same forgery pattern that runs through incident I13. The refusal was correct. The refusal was recorded as routine and never linked to anything. One month later, in month 8, I13 was discovered, at a net loss of Rs 15.4 crore, the largest of the year.

The obvious reading of those two stories is the wrong one. Both controls worked. Both people did their jobs correctly. The data quality check found the stale feed. The checker refused the forged documents. Nothing in either story is a failure of attention, diligence or skill, and any account of it that lands on a person has misread it. No route existed: no mechanism connected a routine refusal to anything that could look at it twice, and no mechanism turned a caught data staleness into an entry that somebody had to close. The failure is a design failure, and it sits in the absence of a route rather than in anybody's work.

Notice what this does to indicator K10, near misses recorded, sitting green on the dashboard. As a count of near misses recorded, K10 is a lagging count and a perfectly honest one: it moves when a near miss has already been logged. The leading signal is not in the count at all. The leading signal is in the linking, and linking is the step this bank never built. Recording a near miss is a count; connecting it to what it resembles is a signal, and only the first of those was ever on the dashboard.

Every household has its own version of this. The car makes an unfamiliar noise on a Tuesday and stops making it on Wednesday, so nobody mentions it again. A month later the same part fails on a highway. Nobody was careless on the Tuesday: they heard it, they registered it, and there was no place to put it.

TWO NEAR MISSES, TWO INCIDENTS, AND NO ROUTE BETWEEN THEM Every figure belongs to the invented bank. The months are the case's own numbered months. NEAR MISS N3, MONTH 6 Stale collateral feed, caught by a data quality check. Never raised as an issue. 4 MONTHS INCIDENT I10, MONTH 10 The same feed, stale for 11 working days. 340 loans wrongly marked, net Rs 1.4 crore. NEAR MISS N4, MONTH 7 Forged document set, refused by a checker. Logged as a routine refusal. 1 MONTH INCIDENT I13, MONTH 8 The same forgery pattern, discovered one month later. Net Rs 15.4 crore. BOTH CONTROLS WORKED. BOTH PEOPLE DID THEIR JOBS CORRECTLY. What did not exist was a route: nothing carried a caught staleness into an issue anybody had to close, and nothing carried a routine refusal to a second look. The failure sits in the missing route, not in the checking.
Each of these two catches was a control doing its job correctly, and each was followed within months by the very failure it had already seen once, so what the year exposes is the absence of any path from a routine refusal to a second look rather than any shortfall in the checking.
Ratio Analysis That Says Something teaches you to choose ratios that answer a question rather than fill a template.

Is an indicator the same thing as a warning?

An indicator is not a warning, and the difference is one sentence long. The same invented bank runs a second set of measures entirely: seven early warning indicators, numbered W1 to W7, sitting in its liquidity material. Each one of the seven carries a defined action against a defined trigger. Crossing it starts something without anybody having to decide whether it should. The sixteen indicators K1 to K16 do something different. The sixteen report a position to a committee.

An indicator with no action attached is a measurement, not a warning, and this bank has sixteen of the first and seven of the second. That is not a criticism of either set. Reporting a position to a committee is a real job and a dashboard that does it well is worth having. The distinction is only a statement about what each object can do. A measurement informs a decision that somebody still has to take. A warning is a decision already taken, in advance, in a calmer room, and stored against a level so that the crossing releases it. The whole of the difference is whether anything happens on its own when the line is crossed.

How the seven are triggered, what actions hang off each of them, and where their levels sit is set out under early warning indicators and triggering action before the limit. Only the distinction belongs here. Two of the seven are triggered at this bank's month 12, W4 red and W7 amber, and what follows from each of those belongs under triggering action before the limit.

Everyday version. A smoke alarm and a thermometer both measure the same physical thing. The thermometer reports the temperature, accurately, whenever anybody looks at it. The alarm has a level written into it and a siren wired to that level, so it acts whether or not anybody is looking. Nobody thinks the thermometer is broken. A thermometer is simply not the object fitted in a corridor.

TWO CHAINS THAT SHARE EVERYTHING EXCEPT THE LAST LINK THE SAME MEASUREMENT, TAKEN THE SAME WAY, FROM THE SAME SOURCE AS A KEY RISK INDICATOR a trigger set by the institution a colour on the dashboard a committee reads it THE CHAIN ENDS HERE somebody must still decide what to do AS AN EARLY WARNING INDICATOR a trigger set by the institution a colour, and a defined action beside it CROSSING IT STARTS THE ACTION the decision was taken in advance
Both chains begin at an identical reading and run through an identical trigger, and they part only at the final link, where one produces a colour for somebody to consider and the other releases a decision that was made before anybody was under pressure.
Try it out

What is the difference between a key risk indicator and an early warning indicator?

What does one measurement sitting on both lists prove?

The invented bank supplies the cleanest possible demonstration, and it does it by accident. The certificate of deposit roll rate, meaning the share of certificates rolled at each auction, is one of the sixteen indicators, sitting as K16 and green. The same measurement is also early warning indicator W2, with amber below 90 per cent, red below 75, and an action attached to it. One measurement. One bank. Two lists.

The overlap is not a duplication and not an error in anybody's record. Look at what is actually identical and what is not. The definition is identical. The source is identical. The number on any given day is identical. As indicator K16 it reports a position to a committee and nothing follows from it, and as early warning indicator W2 it carries levels with an action against them, so crossing it starts something. The measurement was never the difference between the two objects, and this overlap is the proof, because here the measurement is held constant and the two objects are still different.

Which gives the fastest test anybody can run on their own institution's dashboard. For any row, the question is what happens, automatically, on the day it changes colour. If the honest answer is that it gets discussed at the next meeting, the row is a measurement. If the honest answer names an action and the person who starts it, the row is a warning. Most rows on most dashboards answer the first way, and there is nothing wrong with that as long as nobody is under the impression that the dashboard is protecting them.

Try it out

The certificate of deposit roll rate is indicator K16 and is also early warning indicator W2. Is that a duplication?

Who actually picks up a dashboard, and what do they do with it?

Four readers, four different uses, and none of them is re-checking the arithmetic.

The chief risk officer, Sunanda Ravikumar in this invented bank, reads it for composition before she reads it for colour. She is not going to recompute any of the sixteen. In one minute she can count how many rows could move before a loss, and this month the answer is five. The single most useful question anybody can ask of a dashboard is how many of these rows are capable of telling me something I do not already know. The second most useful is the absence question: which live breach has no indicator at all?

An analyst at another institution, looking at this bank from the outside as a counterparty rather than from inside it, reads it for what the choice of rows reveals. Sixteen indicators with eleven counts is a description of what the bank believes it can control and what it has settled for observing. The composition changes which questions are worth asking on a call, and none of those questions is about the colours. The useful one is: what would have had to move, and when, for this dashboard to have flagged the bank's largest loss of the year?

The operational risk head, Purnima Ganeshan here, reads it for the one row that is about to become a problem and is currently amber. Amber is where all of the useful information sits, precisely because red means the argument is over. Indicator K3 at Rs 43.8 crore of Rs 60.0 crore, and indicator K4 at 31 open issues past their date out of 92, are the two rows where the next month's work is actually decided, and neither is red.

A lender or an investor reading a published risk section cannot see the sixteen rows at all, so the same task is harder. Either of them can still apply the type test to whatever measures are disclosed. A section that reports losses, breaches and complaints has told them what happened. A section that reports staff turnover in the units taking risk, the age of unresolved access rights, or the share of transactions going round the automated route has told them something about what might happen next. Reading a disclosure by type rather than by tone is a five minute skill that survives every change of format.

And the household version takes an evening and is worth it. A person writes down the five or six things they actually watch about their own money, and marks against each whether it moves before the problem or after it. Most people find that all of them move after: the balance falling, the card outstanding rising, the instalment bouncing. The next step is to work out what would have moved first in each case, and write that down as well. The first mover will be something like the employer paying salaries three days late, or the number of months of expenses in reserve, or an insurance renewal drifting past its date. The exercise turns up no new fact, only how much notice had been bought, and for most people that proves to be none.

India

What is named here, and where the binding version lives

Nobody outside a bank sets its indicators or its trigger levels. Every indicator, every trigger level, every colour and every count belongs to the invented Vindhya Commercial Bank Limited, and each is that bank's own decision. An indicator set, a trigger level, a reporting frequency and an effective date are each a decision one institution made about itself, and none of them transfers to another.

The expectation that risk reporting is timely, accurate and forward looking, and the idea that an institution should be able to aggregate its own risk data reliably, come from the Basel Committee on Banking Supervision at the Bank for International Settlements, bis.org, in its principles for risk data aggregation and risk reporting. A standard is not what binds an Indian bank, so naming only the global standard is the confident and common error. What actually binds a bank in India, on what it must compute, on what it must report and to whom, comes from the Reserve Bank of India at rbi.org.in, and the binding wording is the wording that body issues.

A threshold, a reporting requirement and an effective date all change on dates the issuing body sets, so the issuer's own text is the only current version.

Which questions belong elsewhere?

Risk monitoring as an activity, meaning the work of watching a position between meetings, belongs with the enterprise risk management material. Early warning indicators W1 to W7, their triggers and the actions attached to them are set out under triggering action before the limit. How a dashboard is actually built, step by step, from choosing a candidate measure to agreeing its trigger, is set out under building a risk dashboard. The monthly risk report itself, its thirty eight printed sides and what a committee needs from them, is treated separately, as is the wider question of turning data into a decision. Every exposure the sixteen indicators measure belongs to somebody else: sector and single name concentration to the credit and counterparty risk material, the backtesting exceptions and the value at risk utilisation to the market risk material, the depositor and wholesale funding concentrations to the liquidity material, and the loss events, issues and near misses to the operational risk material. Their numbers appear here as things being indicated and are derived in those places. What a certificate of deposit, a journal entry, a privileged access right or a letter of credit is belongs elsewhere too.

Sources

SourceDocumentSite
Bank for International SettlementsThe Basel Committee principles for risk data aggregation and risk reporting, being the origin of the expectation that risk reporting is timely, accurate and forward lookingbis.org
Reserve Bank of IndiaWhat actually binds a bank in India on what it must compute, on what it must report and to whom, and on the governance around that reportingrbi.org.in

Vindhya Commercial Bank Limited, Nirjhar Industries Limited, Sunanda Ravikumar, Devendra Achar, Manjari Sondhi and Purnima Ganeshan are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.