⏱ What You'll Learn
I’ve spent over a decade in bank risk management, and if there’s one question that keeps popping up, it’s this: What exactly is an exposure limit, and how do you set it properly? In this article, I’ll break down the concept in plain English, share real-world examples, and point out traps I’ve seen banks fall into again and again.
What Is an Exposure Limit in Banking?
An exposure limit is a pre-defined ceiling on the amount of risk a bank can take with a single counterparty, asset class, or market factor. Think of it as a guardrail: it stops the bank from concentrating too much risk in one place.
There are three main types:
- Credit exposure limit – maximum amount lent to one borrower (e.g., a corporate or sovereign).
- Market risk limit – cap on losses from price movements (e.g., value-at-risk limit).
- Operational risk limit – rarely explicit, but embedded in transactional caps.
In practice, most people refer to credit exposure limits when they talk about banking. That’s the focus here.
Why Banks Need Exposure Limits
Without limits, a single default could wipe out a bank’s capital. The 2008 crisis taught us that lesson hard. Limits also help with:
- Regulatory compliance – Basel III mandates large exposure limits (e.g., 25% of Tier 1 capital per counterparty).
- Portfolio diversification – forces the bank to spread risk across sectors and geographies.
- Capital efficiency – high exposures consume more capital, so limits keep capital usage optimised.
How Banks Calculate Exposure Limits
There’s no one-size-fits-all formula. Banks use a mix of quantitative models and expert judgment. Below is a typical breakdown for credit exposure limits.
| Limit Type | Calculation Method | Typical Threshold | Example |
|---|---|---|---|
| Single Counterparty | % of Tier 1 capital (Basel large exposure rule) | 25% (max) / 5-10% (internal cautious) | Bank X sets limit for Company A at $200M (8% of capital) |
| Industry Sector | Portfolio concentration model + stress testing | 15-20% of total loan book per sector | Limit oil & gas exposure to 12% of total loans |
| Country (Sovereign) | Country risk rating + GDP correlation | Varies; often 5-15% of capital | Limit to emerging markets at 8% of capital |
Step-by-step: Setting a counterparty limit
- Assign internal credit rating (e.g., AAA to D).
- Estimate probability of default (PD) and loss given default (LGD).
- Calculate expected loss = PD × LGD × exposure.
- Compare with risk appetite – if expected loss exceeds 0.5% of capital, reduce exposure.
- Stress test – increase PD by 3 standard deviations; if loss exceeds 2% of capital, cap limit lower.
Warning: Many banks forget step 5. They use historical averages, which almost always underestimate tail risk.
Regulatory Requirements for Exposure Limits
The Basel Committee’s Large Exposure Framework is the global standard. Key rules:
- Individual exposure to a counterparty ≤ 25% of Tier 1 capital.
- Sum of all large exposures (≥10% of capital) ≤ 800% of Tier 1 capital.
- Interbank exposures get a tighter 15% limit.
Regional regulators add their own twists. For example, the European Union’s CRR sets 25% for non-banks and 15% for banks. The U.S. uses a 15% limit for national banks (OCC rules).
I find that the 25% rule is often misinterpreted. It applies to all exposures to the same economic group, not just a legal entity. I’ve seen banks trip up here by treating subsidiaries of a parent as separate counterparties.
Common Mistakes When Setting Exposure Limits
Other traps I’ve witnessed:
- Ignoring correlation – limits on individual counterparties are fine, but if they’re all in the same sector (e.g., real estate), the portfolio limit is blown.
- Using gross exposure instead of net – collateral and hedges should reduce exposure. I audited a bank that set limits on gross notional; they had huge unused capacity but real risk was double counted.
- Over-relying on ratings – a AAA-rated bank in 2007 looked safe; we all know what happened. Qualitative judgment and stress testing are non-negotiable.
Best Practices for Managing Exposure Limits
Based on what I’ve seen work (and fail), here’s my checklist:
- Dynamic limits – adjust quarterly, or even monthly for volatile sectors.
- Limit utilisation alerts – set thresholds at 80% for escalation, 95% for hard block.
- Link limits to risk appetite – if the board wants a low-risk profile, limits should be proportional.
- Automated monitoring – use real-time dashboards to track aggregate exposure.
- Stress test scenarios – not just regulatory ones; imagine a sector crash, a sovereign default, or a liquidity freeze.
One practice that’s underrated: limit exception tracking. Every time a manager overrides a limit (even temporarily), log it. Pattern of overrides? Time to tighten the policy.
Reader Comments