ICAAP fundamentals: Can traditional and non-financial risks be aggregated?

Capital is the oldest risk control in banking and still the most honest one. Shareholders put their own money behind the risks the institution takes with depositors' money, and if a manageable shock arrives, that equity absorbs it before anyone else is asked to. It is skin in the game, and it has survived every fashion in risk management because it is simple.
Pillar 1 works for the same reason. It covers credit, market and operational risk because those are the risks where a standardised, data-rich measure of unexpected loss is achievable across the industry. Lending and treasury look broadly alike from one bank to the next; the data is transactional and abundant; the methods have been argued over for twenty years. Pillar 1 is narrow by design, and its narrowness is the source of its authority.
The trouble begins when the ICAAP is asked to do what Pillar 1 was built not to do: combine credit, market, liquidity, operational and geopolitical risk into one number, without producing something unmanageable or falsely precise. The request is reasonable. The failure it describes almost always comes from one mistake: treating those five labels as five risks to be summed, when they are five ways of describing where a single event ends up.
Quick summary:
- Pillar 2 add-ons should be simple and conservative, addressing risks Pillar 1 misses without unjustified diversification benefits or double-counting.
- Stress scenarios must trace a single trigger through cascading consequences, booking each loss only once to avoid counting the same event multiple times across different risk channels.
- Plausible scenarios require experienced judgement and knowledge of your institution's specific vulnerabilities. The greatest risk is failing to imagine the scenario that could actually destroy your bank.
Risk categorisation: Pillar 1 or Pillar 2?
Liquidity is the clearest example. It is the most important risk a bank runs, the fuel without which nothing else operates, and it does not attract a capital charge, because a liquidity shortfall is not a loss. It is a balancing problem, which is exactly why regulators have gone after it with ratios, monitoring and structural balance-sheet rules rather than with capital. Liquidity enters the ICAAP only as the cost of surviving a liquidity stress: the haircut on assets sold under pressure, the spread paid on emergency funding. Model it as a cost line, not a capital line, and half the double counting disappears.
Pillar 2 exists to address what Pillar 1 misses:
- concentration
- interest rate risk in the banking book
- the adequacy of provisioning
- the gap between standardised credit RWA and what a more risk-sensitive internal-ratings measure of the same book would produce
- the growing family of non-financial risks that never sat comfortably in an RWA
Pillar 2 add-ons should be additive, simple and deliberately conservative. No diversification credit that cannot be evidenced. No correlation matrix estimated from data that has never seen a full cycle. If a diversification benefit cannot be explained to a supervisor in plain language, it should not be in the number.
Interaction between risks belongs to the stress testing framework, and nowhere else. This is the distinction most ICAAPs blur. Add-ons are for measurement; scenarios are for transmission.
One event, cascading consequences
A scenario is not a list of shocks applied in parallel. It is a narrative with a single trigger and a traced chain of consequences. A rate shock is one event. It appears as repricing loss in the banking book, as revaluation of the bond portfolio, as deterioration among borrowers who can no longer service floating-rate debt, and as deposit migration once customers notice what money markets are paying. If those four effects are booked as four separate risks and then aggregated, the same event has been paid for four times.
The discipline is single booking. Every loss in the scenario is attributed to one channel, once, and the ICAAP carries a visible ledger showing where it landed. Geopolitical risk shows why this matters. It is not a risk category at all; it is a trigger. Its only means of costing a bank money is through credit, market, liquidity and operational channels, so a separate capital line “for geopolitical risk” is double counting by construction. The correct treatment is to make it the opening line of a scenario and follow the money.
The real test: What plausible events can uncover your book’s weaknesses?
Stress testing has a reputation as a compliance exercise, and it has earned it, because it is usually run as one: an isolated annual event, detached from the balance sheet it claims to describe. The reason is uncomfortable. Building a plausible scenario is the hardest task in the ICAAP, and it cannot be outsourced. It requires memory of past events and, more importantly, an intimate knowledge of where the current book is vulnerable. External advisers, including the largest firms, rarely hold that knowledge, and structurally cannot. It lives with the material risk takers who have carried the exposures through a bad year, and with the control functions who have had to act while they did.
A tool that can generate a thousand correlated scenarios overnight has not solved plausibility.
The same scenario can be entirely plausible for one institution and absurd for another. A small, conservative, deposit-funded bank with a plain-vanilla treasury does not share the vulnerabilities of a large trading house, and an ICAAP that borrows the trading house's scenarios has answered a question nobody asked. In the Gulf, where the rate cycle is imported through the peg and few institutions hold deposit behaviour data through a genuine stress, the temptation to import scenarios along with the rate cycle is strong. Borrowed scenarios, usually arriving in a consultant's template, are the single most common reason stress testing frameworks are poorly designed. They should be resisted at the door.
Credit and market scenarios remain the more tractable part of the exercise, because the data exists. The real animal is operational and non-financial risk: cyber, information security, model and AI risk, climate, and reputational risk as the consequence of all of them. This is where the industry's recent losses have actually occurred, and where historical data is thin by definition. A bank that has not sat down and imagined a particular failure happening to it has no protection against that failure, however much capital it holds against the failures it has imagined.
Judgement is not the fallback
None of this argues against data. Modern scenario design runs on analytical capability, internal and external, linked to the specific character of the business, and regulators are right to treat stress testing as a primary input to strategy rather than a footnote to it. A profit target that has not been tested against the bank's own severe-but-plausible scenario is a wish.
But data measures a channel. It does not choose the scenario, set its severity or decide what management would actually do on the third day. Those decisions belong to judgement, and specifically to experienced judgement, which is a different thing from subject-matter knowledge. Judgement sits at the front of the process and at the back; models sit in the middle.
The scenario you never wrote costs you the bank.
The arrival of AI in risk modelling sharpens this rather than softening it. A tool that can generate a thousand correlated scenarios overnight has not solved plausibility; it has industrialised the production of implausible ones, and added a model-risk channel to the ledger that most banks have not yet booked. The more capable the model, the more the front and back of the process need someone who has lived through a bad year and can say, with authority, which of the thousand is the one that would actually happen to us.
Complexity is justified inside a channel that is understood. It is never justified in the joins between channels, because that is where false precision is manufactured.
Poor scenario design cuts both ways. It overstates capital and starves the business, or it understates capital and flatters it. Either error is recoverable. The third outcome is not. The scenario you overstate costs you capital. The scenario you never wrote costs you the bank.

