Everything the engine computes, written out. Every symbol below corresponds to a field you can see in the workspace, and every equation to a column in the month-by-month schedule that opens when you click a facility.
One facility i is measured at one reporting date over months m = 1, 2, … H. Every quantity below is per facility unless stated otherwise; the portfolio figure is the sum over facilities, never a rate applied to a total.
| Symbol | Meaning | Where it comes from |
|---|---|---|
| B | Drawn balance at the reporting date | Loan book |
| U | Undrawn commitment | Loan book |
| c | Credit conversion factor, 0 ≤ c ≤ 1 | Loan book or assumption |
| E0 | Exposure at default at the reporting date | Derived |
| N | Remaining contractual term in months | Loan book |
| H | Measurement horizon in months | Derived from the stage |
| r | Effective interest rate, per annum | Loan book |
| d | Days past due | Loan book |
| h(m) | Conditional (hazard) probability of default in month m | PD term structure |
| S(m) | Probability of surviving to the start of month m | Derived from h |
| q(m) | Marginal (unconditional) probability of defaulting in month m | Derived |
| L | Loss given default, after collateral and costs | Derived |
| ℓ | Unsecured loss rate | Assumption or calibration |
| πs | Probability weight of scenario s | Assumption |
| αs, βs | Scenario multipliers on default probability and on loss rate | Fitted or assumption |
| ω | Management overlay rate | Assumption, approved |
The expected credit loss on a facility under one scenario is the present value of the loss expected in each month, summed over the horizon. A loss occurs in month m only if the facility survives to that month and then defaults; the amount lost is the exposure at that point multiplied by the loss rate; and the amount is discounted back at the facility’s own effective interest rate.
where qs(m) is the marginal probability of defaulting in month m, Ls the loss given default, E(m) the exposure outstanding in that month, and D(m) the discount factor.
Each term is defined below. The four are multiplied month by month and never in aggregate: multiplying an average default probability by an average exposure by an average loss rate gives a different — and generally smaller — answer than summing the products, because the three are correlated across the life of a facility.
The PD term structure supplies a conditional probability: the chance of defaulting in month m given that the facility has not defaulted before it. Converting that into the unconditional chance of defaulting in month m requires the survival function.
The marginals over the horizon sum to the cumulative probability of default, which is the quantity the twelve-month or lifetime PD refers to:
Losses are discounted at the effective interest rate of the facility, converted to a monthly rate. IFRS 9 requires the original effective rate, which is the rate at which the asset is carried; using a market rate would recognise a valuation change that is not a credit loss.
The stage decides the horizon, and the horizon is the only thing the stage changes in the arithmetic. There is no separate Stage 2 formula: the same identity is summed over more months.
The stage itself is the highest stage among the rules that fire, with one exception for probation:
where T is the set of active rules and g(t) is the stage that rule t assigns. If the result is Stage 1 but the facility cured within the probation period P, the stage is set to 2 instead.
The rules currently defined:
| Rule | Fires when | Assigns |
|---|---|---|
| Default indicator | the source record is flagged as in default | Stage 3 |
| Written off | the facility has been written off in whole or part | Stage 3 |
| Days past due — default | d ≥ θD (default backstop) | Stage 3 |
| Days past due — significant increase | d ≥ θS (significant-increase backstop) | Stage 2 |
| Restructuring | the facility has been restructured in distress | Stage 2 |
| Watchlist | an early-warning flag is set | Stage 2 |
| Relative lifetime PD | PDnow / PDorigination ≥ k | Stage 2 |
A facility that stops meeting the default criteria does not return immediately to a twelve-month basis. Writing u for months since cure and P for the probation period:
Without this, a facility that cured on the last day of the reporting period would be measured on a twelve-month basis on that day, and the staged population would swing on the timing of a single payment.
The engine consumes a monthly hazard, not an annual rate. Two forms are supported.
Where no curve has been fitted, an annual probability p is converted geometrically to a constant monthly hazard:
This recompounds exactly: applying the identity above for twelve months returns p. But a constant hazard assigns the same probability to every facility in a group and to every month of its life, so it carries no information about when risk arises and cannot rank one facility against another. A book measured this way will show a Gini coefficient of zero — not because the statistic is broken, but because a flat rate has nothing to discriminate with. The workspace labels such a measurement as anchored rather than calibrated.
The alternative is to fit the shape from history. Default counts by months on book give an empirical hazard directly:
where Dm is the number defaulting in month m on book and Rm the number still at risk at its start.
A parametric form is then fitted to that empirical curve so it can be extrapolated beyond the observed window. The Weibull hazard is used because it can rise or fall with age according to a single shape parameter:
k < 1 gives a falling hazard — risk concentrated early in the life of a facility, the usual shape in development lending. k > 1 gives a rising hazard. k = 1 is the memoryless case, in which a term structure adds nothing over an anchor. Parameters are chosen to minimise the squared deviation from the empirical hazard.
A loss allowance must reflect what is expected, not only what has happened. The link is estimated in two steps: fit the relationship between observed default behaviour and the economy, then evaluate it at a forecast.
yt is the observed default rate in month t; x1 and x2 are the economic drivers; ℓ is a lag, because default responds to the economy with a delay.
The multiplier applied under scenario s is the default rate the fitted relationship predicts at that scenario’s forecast, relative to the long-run average:
and it is applied to the monthly hazard, not to an annual rate before conversion:
The loss rate is estimated from what was actually recovered on facilities that did default. Recoveries arrive over a workout lasting years, so incomplete cohorts must be developed to their ultimate value before they can be compared with complete ones.
Let Ci,j be the cumulative recovery on cohort i after j development periods. The development factor from period j to j+1 is the volume-weighted ratio across every cohort observed at both:
Ultimate recoveries are discounted back to the date of default at the original effective rate, and costs are applied separately so that the effect of security and the effect of cost can each be seen:
Rt is the recovery received t months after default and κ the total workout cost rate. Recovering the same cash later is a real loss: the discount term is what measures it.
Security reduces the loss, but only what can be realised and only when it can be realised. For each item of security j with valuation Vj, haircut γj and expected months to realisation τj:
Three properties are enforced rather than assumed:
A negative balance — a customer in credit — is floored at zero: a customer in credit carries no credit exposure. The original value is retained so the import rules can report it rather than have it silently disappear.
Exposure is then projected forward over the horizon. Where the loan book carries a contractual repayment schedule that schedule is used; where it does not, exposure amortises straight-line:
For a credit-impaired facility the loss is not in doubt — only its timing. The schedule collapses to a single certain loss discounted over the expected recovery lag λ:
with h(m) = 1: the probability of default on a facility that has already defaulted is one, and the workspace checks that this is so on every such facility rather than assuming it.
The whole book is measured under each scenario and the results are probability-weighted. Weighting happens after each facility has been capped at its own exposure, so a facility cannot be pushed above its balance by the downside.
The weights must total exactly one; the measurement refuses to validate otherwise. The overlay ω is zero unless positively decided, and a run that applies one without a named approver fails its checks.
This is also why sensitivity is a re-measurement, never a scaling. The identity is not linear in its inputs: exposure caps, collateral caps and stage-dependent horizons all bind. Scaling a reported figure by a stressed rate gives the wrong answer precisely in the scenarios that matter.
Every estimate carries the diagnostics that say whether it should be used.
Ties take the average rank, so a model that assigns the same score to everything scores 0.5 — which is the correct answer for a model that does not discriminate, and is exactly what a flat PD anchor produces.
reliability is calibration error and is better small; resolution is discriminating power and is better large; uncertainty is ō(1 − ō), a property of the sample and not of the model. The skill score is 1 − BS / uncertainty.
Below 0.10 no material shift; 0.10 to 0.25 moderate; above 0.25 the model is being applied to a different population from the one it was fitted on.
gb and bb are the shares of performing and defaulted facilities in bucket b. Below 0.02 a variable carries no signal; above 0.5 it is worth asking whether it is restating the answer.
A grouping earns its place by explaining variation in outcome between groups while leaving little unexplained within them. Grouping by delinquency scores highly on the first and tells you nothing, because delinquency is most of the definition of default: the groups are being defined by the answer.
These are not conventions. Each is enforced by the code and checked on every run.
| Property | Why it matters | How it is enforced |
|---|---|---|
| The engine is a pure function of its arguments | A figure that depends on a clock, a database or a configuration file cannot be re-derived later | The measurement layer imports no framework and can reach no external state |
| Facilities are immutable once constructed | Two facilities with the same values are the same facility, and nothing can change one after it is measured | Frozen value objects with invariants enforced at construction |
| Row order cannot change the answer | The same book presented in a different order must fingerprint and measure identically | Facilities are sorted by identifier before measurement; the fingerprint sorts before hashing |
| The fingerprint covers every field that can affect the result | A hash over a subset lets a materially different book look identical | The field list is derived from the object definition, so a new field is covered automatically |
| Assumption sets are versioned and immutable | A run’s stated assumptions must not be able to change after the run | Saving over an existing version is refused; every change makes a new version |
| A run can be re-derived from its own inputs | A figure that cannot be reproduced must not be the reported figure | The book is re-measured from the stored inputs and compared facility by facility to the last digit |
| A conclusion is derived from checks that ran | A validation that reports a pass without executing anything is worse than none | A run with no checks reports not validated; the conclusion is computed from the results |
| A period locks only on three signatures and a reproduction | Segregation of duties, and a figure proven re-derivable before it is fixed | Three different people, three roles, and a successful reproduction are all required |