2025-07-18
Added · Updated
The Hong Kong Monetary Authority issues this statutory guideline to establish supervisory expectations for authorized institutions validating risk rating systems under the Internal Ratings-Based approach. The document mandates that institutions maintain robust qualitative controls and quantitative validation techniques to ensure the accuracy of probability of default, loss given default, and exposure at default estimates. Compliance with these requirements is essential for obtaining and retaining regulatory approval to calculate capital adequacy for non-securitization credit risk exposures.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 1 This module should be read in conjunction with the Introduction and with the Glossary, which contains an explanation of abbreviations and other terms used in this Manual. If reading on-line, click on blue underlined headings to activate hyperlinks to the relevant module. ————————— Purpose To set out the HKMA’s approach to the validation of AIs’ rating systems and its expectations for AIs to qualify for using the IRB approach to calculate credit risk for non-securitization exposures for capital adequacy purposes Classification A statutory guideline issued by the MA under the Banking Ordinance §7(3) Previous guidelines superseded CA-G-4 “Validating Risk Rating Systems under the IRB Approach” (V.2) dated 17.05.18 Application To all AIs incorporated in Hong Kong which use, or intend to use, the IRB approach to calculate credit risk for capital adequacy purposes Structure
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 2 3. Factors to be considered in validation process 3.1 Development and implementation of rating systems 3.2 Assigning ratings to obligors in connected group 3.3 Systems and controls 3.4 Data management 3.5 Accuracy of rating systems 3.6 Forward-looking capability of rating systems 3.7 Stress-testing 4. Corporate governance and oversight 5. Other systems of control 5.1 Independence 5.2 Transparency 5.3 Accountability 5.4 Use of rating systems 5.5 Internal audit function and external audit 5.6 Treatment of third-party vendor rating systems 5.7 Treatment of group-wide rating systems 6. Data management 6.1 Overview 6.2 Management oversight and control 6.3 IT infrastructure and data architecture 6.4 Data collection, storage, retrieval and deletion 6.5 Maintaining data for rating system development, implementation and validation, and regulatory reporting 6.6 Data processing 6.7 Reconciliation 6.8 Data quality assessment
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 3 6.9 Use of external and pooled data 6.10 Statistical issues 7. Accuracy of PD 7.1 Supervisory expectations for estimation of PD 7.2 Overview on validation of PD 7.3 Validation of discriminatory power 7.4 Validation of calibration 8. Accuracy of LGD 8.1 Supervisory expectations for estimation of LGD 8.2 Methods for assigning LGD to non-defaulted exposures 8.3 Assignment of LGD estimates to defaulted exposures 8.4 LGD estimation process for workout and market LGD 8.5 Issues specific to workout LGD 8.6 Validation of LGD estimates 9. Accuracy of EAD 9.1 Supervisory expectations for estimation of EAD 9.2 EAD estimation process for non-defaulted facilities 9.3 Validation of EAD estimates 10. Issues on LDPs 10.1 Types of LDPs 10.2 Implications for risk quantification and validation 11. Benchmarking 11.1 Overview 11.2 Use of benchmarking 11.3 Types of benchmarking 11.4 Selection of benchmark 11.5 Mapping to benchmark
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 4 Annex A: Quantitative techniques in validating discriminatory power Annex B: Statistical methodologies in validating calibration Annex C: Possible risk factors in estimation of EAD
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 5
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 6 “out-of-sample” means, in the context of validation of a rating system, employing observations that have not been used for developing the rating system; “out-of-time” means, in the context of validation of a rating system, employing observations that are not contemporary with the data used for developing the rating system; “Q&As:IV” means Chapter IV of Questions and Answers on Banking (Capital) Rules in respect of Credit Risk Framework; and “validation” means a range of processes and activities that contribute to an assessment of whether ratings generated by a rating system adequately differentiate risk, and whether the credit risk components estimated based on the rating system appropriately characterise the relevant aspects of risk. 1.2 Minimum requirements for use of IRB approach 1.2.1 Part 6 and Schedule 2 of the BCR set out the capital adequacy framework and minimum requirements for an AI to use the IRB approach to calculate its credit risk exposures within one or more IRB adoption classes. AIs are therefore advised to read this module in conjunction with the BCR. In case of any discrepancy between the BCR and this module, the former shall prevail. 1.2.2 In addition, the module should also be read in conjunction with Q&As:IV and other relevant documents issued by the HKMA. 1.2.3 An AI may submit an application under §8(1) of the BCR to use the IRB approach to calculate its credit risk for nonsecuritization exposures for one or more IRB adoption classes. The MA may grant approval to the AI under §8(2)(a), subject to any conditions that the MA thinks
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 7 proper in any particular case (see §33A of the BCR), to use the IRB approach if the AI demonstrates to the satisfaction of the MA that the minimum requirements specified in Schedule 2 to the BCR applicable to the AI are met. 1.2.4 In practice, based on an AI’s indication of its intent to make the application, the HKMA will arrange to undertake the IRB recognition process to assess the AI’s eligibility to use the IRB approach, including whether the AI’s overall credit risk management practices are consistent with the relevant provisions in the BCR, and the applicable guidelines and sound practices issued by the Basel Committee and the HKMA. Should approval be granted to the AI, the HKMA will conduct reviews of the AI from time to time to ascertain the AI’s continuous compliance with the applicable HKMA requirements. 1.2.5 Where an AI adopting the IRB approach is not in full compliance with the applicable HKMA requirements, or it has contravened a condition attached to its IRB approval, the MA may take one or more of the measures set out in §10(5) of the BCR1 . These include a requirement for the AI to: (i) use the STC approach (instead of the IRB approach) to calculate the credit risk for the concerned exposures; (ii) submit to the MA a remedial plan and implement that plan; (iii) reduce its credit exposures; (iv) hold additional capital under the supervisory review process; and/or
1 Provisions under §10(5) of the BCR are applicable to cases where an AI is non-compliant with the applicable HKMA requirements to the extent that if the AI were to make a fresh application to the MA under §8(1) of the BCR for using the IRB approach, the application would be refused by virtue of §8(3) (but insofar as Schedule 2 to the BCR is concerned, only §1 of the Schedule is to be taken into account). In other cases, the AI concerned will normally be required to rectify the issues, as discussed and agreed with the HKMA, within a reasonable period of time.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 8 (v) take other appropriate actions as required by the HKMA depending on the circumstances of each case. 1.3 Scope 1.3.1 This module sets out: (i) the HKMA’s approach to the validation of rating systems of AIs for the purposes of using the IRB approach; and (ii) the HKMA’s expectations for AIs using (or intending to use) the IRB approach by elaborating on the applicable HKMA requirements having regard to the publications of the Basel Committee, industry practices and the HKMA’s experience. 1.3.2 The requirements and supervisory expectations set out in this module apply to all rating systems for use under various IRB calculation approaches stipulated in Table 17 in §147(1) of the BCR, including rating systems that are obtained from a third-party vendor as well as group-wide rating systems (i.e. rating systems that have been used by a bank incorporated outside Hong Kong and this bank is a member of a group of companies of which the AI is also a member). 1.3.3 The scope of the applicable HKMA requirements, and the scope and intensity of the HKMA’s IRB recognition process and ongoing supervision, will depend on the specific circumstances of individual AIs, for instance, whether it is an application for the initial use of the IRB approach or for modifying an approved rating system, the nature and scale of the exposures being covered, and the IRB calculation approach being involved. 2. HKMA’s approach to validation
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 9 2.1 The HKMA’s approach to validation adheres to the principles promulgated by the Basel Committee 2 (“Basel IRB validation principles”) as follows: (i) Validation is fundamentally about assessing the predictive ability of a bank’s risk estimates and the use of ratings in credit processes; (ii) The bank has primary responsibility for validation; (iii) Validation is an iterative process; (iv) There is no single validation method; (v) Validation should encompass both quantitative and qualitative elements; and (vi) Validation processes and outcomes should be subject to independent review. 2.2 Consistent with the second principle, it is an AI’s responsibility to demonstrate to the satisfaction of the MA that its rating systems and the relevant processes meet the applicable HKMA requirements, including that the AI has a reliable system for validating regularly the accuracy and consistency of its rating systems as required by §1(i) of Schedule 2 to the BCR. This, together with other Basel IRB validation principles, forms the basis of the HKMA’s approach to validation that the AI is required to conduct its own validation, document clearly the validation processes and results, and share them with the HKMA for review in the IRB recognition process and ongoing supervision. 2.3 The HKMA’s approach to validation consists of two key components. Focusing on the qualitative aspects, the first component involves a review of the AI’s processes, procedures and controls that are in place for rating systems. This includes, for example, an assessment of whether these systems are
2 See Basel Committee Newsletter No. 4 “Update on work of the Accord Implementation Group related to validation under the Basel II Framework” issued in January 2005.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 10 subject to adequate oversight by the AI’s Board of Directors3 and senior management, both before and during use; whether adequate procedures are in place to ensure the integrity and reliability of the data used; and whether the rating systems are validated at an appropriate frequency by individuals who have relevant knowledge and experience to do so and are independent of the parties that have been involved in developing the rating systems. Internal and external auditors of the AI should also be involved in the processes. The expectations of the HKMA in these areas are set out in sections 4 to 6. 2.4 The second component of the HKMA’s approach to validation focuses on the regular use of at least some of the generally accepted quantitative techniques by the AI in assessing the performance of its rating systems and accuracy of the credit risk component estimates. The quantitative techniques presented in sections 7 to 11 reflect some common market practices in the estimation and validation of rating systems and the credit risk components. 2.5 In line with the fourth principle, the HKMA recognizes that there is no universal tool that can be used for the validation of all rating systems. It therefore expects the design of a validation methodology to depend on the type of rating system and the underlying portfolio. For example, back-testing may be useful for validating the credit risk component estimates for retail portfolios in general. However, it may be less applicable to portfolios with a small number of historical defaults where benchmarking may be a more useful validation tool. 2.6 The HKMA also notes that the techniques, especially the quantitative techniques, for validation of rating systems and the credit risk component estimates are very diverse, portfoliospecific and evolving. Therefore, the HKMA neither prescribes
3 Unless otherwise specified, “the Board of Directors” or “the Board” may mean its specialized committee established in accordance with section 5 of CG-1 “Corporate Governance of Locally Incorporated Authorized Institutions”.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 11 specific techniques nor sets precise quantitative minimum standards that should be employed for validation. AIs are expected to apply the validation techniques and practices 4 (including the parameters adopted for validation) that are commonly used in the industry for specific types of rating systems and portfolios. When an AI employs a validation technique which differs from that in widespread use by its peers, the HKMA expects it to be able to justify its choice. Where appropriate, the HKMA may require the AI to apply a specific validation technique to a rating system/portfolio and to submit the validation results for review. 2.7 The HKMA may require an AI to provide its credit risk component estimates and the relevant data for comparison with other AIs’ other estimates for similar obligors/facilities in order to identify potential outlying predictions. 2.8 The HKMA may request an AI to use an alternative approach to estimate the credit risk components (e.g. a different segmentation approach for retail exposures) and compare the results against the estimates generated by the method adopted or proposed by the AI. 2.9 Where the HKMA considers appropriate, it may require an AI to commission a report from its external auditors or other independent experts with the relevant expertise, experience and track record in such work to review the AI’s compliance with the applicable HKMA requirements. 3. Factors to be considered in validation process 3.1 Development and implementation of rating systems
4 For example, those set out in Chapter 3 of the document “Regulatory consistency assessment programme (RCAP) – Analysis of risk-weighted assets for credit risk in the banking book” issued by the Basel Committee in April 2016.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 12 3.1.1 Rating systems can be generally classified into two broad types, namely model-based and judgement-based. The former is a mechanical process, relying primarily on quantitative techniques such as credit scoring models, statistical default prediction models and specified objective financial analysis. The latter relies primarily on the personal experience and subjective judgement of credit officers5 . 3.1.2 Developing either type of rating systems requires an AI to adopt methods, choose risk factors, screen candidate systems and, where necessary, make adjustments to the chosen system. The validation process should therefore include an evaluation of the logic and conceptual soundness of the rating systems, as well as a thorough review of the developmental evidence for the rating systems demonstrating that the AI’s judgements made during the process are well-founded with proper regard to industry practices in the risk management field and its own circumstances. 3.1.3 An important aspect in assessing a rating system’s logic and conceptual soundness is its economic plausibility. The risk factors that are included in the rating system should be well grounded in the relevant economic and financial theory and in established empirical relationships, rather than spurious relationships which are purely driven by the underlying data. AIs should be able to provide valid explanations on why particular risk factors are included in the rating system. Where possible, AIs should assess the discriminatory power and predictive ability of individual risk factors, and analyse how individual factors behave and interact with other factors in the multivariate context in order to justify their inclusion. Other important aspects include the relevancy of data used to develop and
5 In practice, the distinction between the two types of rating systems is not clear. In many modelbased rating systems, personal experience and subjective judgement play a role in model development (e.g. in determining the weights assigned to the risk factors) and/or implementation (e.g. in constructing certain model inputs). In some cases, models are used to provide baseline ratings which serve as the starting point in judgement-based rating systems.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 13 calibrate the rating system (e.g. whether the data are representative of the population of the AIs’ actual obligors or facilities), and whether the criteria for system screening in the developmental stage are well supported in theory and evidence and are applied consistently. 3.1.4 AIs should be able to demonstrate that their rating systems and the associated credit risk component estimates take into account all relevant and material information. This includes, amongst others, the AIs’ lending practices or processes for pursuing recoveries, as well as any changes to such practices or processes, which may affect the accuracy of their rating systems and the associated credit risk component estimates. 3.1.5 Where human judgement forms part or all of the inputs to a rating system, or where judgement is combined with outputs of a model in determining the final ratings, there should be written guidelines on how the judgement and combination are exercised6 . Such guidelines should set out the risk factors that need to be considered and how they should be considered in the rating process, including the relative importance of these factors. AIs should have a robust monitoring and rating approval process to ensure that the judgement is properly, consistently and prudently exercised, and adheres to the established guidelines. 3.1.6 In relation to §159(1)(d), §161(1)(e), §164(4)(f), §177(1)(e), §178(1)(g) and §180(3)(b) of the BCR regarding the length of historical data period for estimation of the credit risk components, AIs should consider and use data with the longest period as appropriate irrespective of the data sources (external, internal, pooled data sources, or any combination of the three) if such data are relevant and material. The data
6 Concerning the overrides of ratings generated by a model-based rating system (including exclusion of certain input variables of the model or altering the values of certain input variables), an AI must have proper guidelines and processes for governing and monitoring cases where human judgement is exercised to override the ratings (§155(e) and §175(c) of the BCR).
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 14 should include a representative mix of good and bad years of the economic cycle relevant to the portfolio. 3.1.7 AIs should have adequate procedures for reviewing the ratings generated by their rating systems, with a focus on identifying and mitigating weaknesses of the rating systems, as part of the AIs’ ongoing efforts to improve the performance of the systems. 3.1.8 In addition to the above, AIs using a model-based rating system should be able to demonstrate that: (i) the model exhibits good predictive power, and its use does not result in distortion in regulatory capital requirements, with evidence showing that the model outputs do not have material biases as compared to the actual outcomes and are accurate on average across the range of obligors or facilities to which the AIs are exposed; and (ii) the model relationship is reasonable and stable with the input variables forming an adequate set of predictors having acceptable explanatory capability. 3.1.9 Certain modelling techniques are particularly prone to the issues of instable model relationships and hence model outputs (including both the ratings and the credit risk component estimates generated by the model). This is especially the case where the model development process is highly data-driven, or where it is difficult to demonstrate the appropriateness and stability of the relationship between the model outputs and input variables. In these cases, the HKMA expects AIs to demonstrate that the inherent model risks are immaterial by assessing the potential impacts of variations in model structure and parameters on the model outputs and capital charge through, for instance, sensitivity analysis. 3.1.10 AIs should have in place a system to monitor the status of defaulted exposures. If an AI considers that the status of a previously defaulted exposure is such that the trigger of the definition of default no longer applies, the AI should
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 15 rate the obligor (and facility where appropriate) and estimate the credit risk component(s) as it would for a non-defaulted facility. Should the prescribed definition of default be subsequently triggered, a second default would be deemed to have occurred. For the purposes of rating system development and validation, AIs may include second default observations in the relevant data sets. In these cases, AIs are expected to evaluate whether these observations are valid for such purposes and document the evaluation as appropriate. 3.2 Assigning ratings to obligors in connected group7 3.2.1 In relation to §154(d) of the BCR on assigning ratings to individual obligors in a connected group, an AI may recognize the potential support from the parent company or other entities of the group to the obligors (“group support”), provided that the AI: (i) clearly defines what constitutes a connected group with strong justification and proper documentation on the grouping criteria; and (ii) establishes and justifies the criteria for recognizing the group support, and the extent to which such support is reflected, in determining the obligor grades of individual obligors within the connected group by assessing all relevant factors 8 , which include, but are not limited to: the source, nature, form and the potential availability of the group support; the identification of, and justification for, those obligors within a connected group in respect of which the obligor grades will be adjusted to reflect the strength of support provided by the group;
7 This subsection is relevant to corporate, sovereign and bank exposures. 8 AIs may also draw reference to analogous requirements in the credit risk mitigation frameworks set out in the BCR (e.g. §77) or CR-G-7 on “Collateral and guarantees”.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 16 the willingness, ability and past behaviour of the support provider in honouring assurances to the relevant obligors or comparable commitments to similar beneficiaries, in both normal and stressed times; any material wrong-way risk and interconnectedness between the obligors and the support provider; the potential obligations, whether contractual or not, of the “beneficiary” obligors in question to lend support to other group members; and the ability and the effectiveness of the AI to validate or benchmark its process, methodology and data for incorporating group support into the ratings of individual obligors in a connected group, and the resulting adjustments made to the stand-alone ratings of such obligors. 3.2.2 In cases where the support provider and the beneficiary obligors fall under the purview of different regulators and/or are located in different jurisdictions, any crosssector and cross-border restrictions and country risk (e.g. exchange controls, liquidity constraints, supervisory ringfencing measures) that may hinder the availability of the support should be taken into account. 3.2.3 AIs should exercise prudence, conservatism and consistency in rating individual obligors in a connected group, in order not to under-estimate the default risk of such obligors. 3.2.4 There should not be any double-counting of the credit risk mitigating benefits incorporated into the internal ratings of obligors in a connected group pursuant to §154(c) and (d) of the BCR and those recognized under the credit risk mitigation frameworks of the BCR. 3.2.5 As in the case of rating systems and other established policies, an AI should subject the group support framework to proper approval procedures, monitoring of
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 17 the application of the framework, regular independent reviews and validation, and timely updates where necessary. 3.3 Systems and controls 3.3.1 The HKMA places substantial emphasis on the system and control environment in which rating systems are operated. It includes the extent of Board and senior management oversight and review of the design, implementation, performance monitoring of the rating systems, and remedial actions to address identified deficiencies. 3.3.2 The HKMA does not require an AI’s directors and senior management to have a thorough in-depth knowledge of all of the technical aspects of the rating systems, but expects them to: (i) take a leading role in determining the design of the rating systems that the AI plans to adopt based on the technical support of internal staff expertise and/or external parties; (ii) ensure the adequacy of the skills and knowledge of their staff; and (iii) clearly delineate and assign responsibilities, and establish the necessary policies, procedures and organisational structures to safeguard the independence of the rating system review work. As part of its assessment of the adequacy of Board and senior management oversight, the HKMA evaluates the effectiveness of the rating system review staff in bringing issues to their attention as appropriate, and the adequacy of their responses to such issues. 3.3.3 AIs should be able to demonstrate that: (i) their rating systems are subject to independent validation, and ratings generated by such systems are subject to an independent approval process;
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 18 (ii) the rating systems are transparent and fully documented; (iii) there are clear lines of accountability for all aspects of rating accuracy and performance; (iv) the use test requirement is met; (v) the AIs’ internal and external auditors play their roles properly; and (vi) they validate third-party vendor rating systems and group-wide rating systems properly. 3.4 Data management 3.4.1 How an AI manages its data for development, implementation and validation of its rating systems is key to whether the systems are able to produce accurate and reliable credit risk component estimates. AIs should be able to demonstrate to the HKMA that they have proper systems and controls surrounding their IT infrastructure, data collection, processing, maintenance, reconciliation and quality control, as well as use of external and pooled data and statistical techniques for constructing data sets for uses related to their rating systems. 3.5 Accuracy of rating systems 3.5.1 Another important factor affecting an AI’s eligibility for using the IRB approach is whether the AI has a robust system in place to validate the accuracy and consistency of its rating systems, processes, and the associated credit risk component estimates, and whether the validation process enables the AI to assess the performance of its rating systems consistently and meaningfully. 3.5.2 Specifically, AIs should regularly compare realized default rates with their estimates of PD for each grade (or each pool for retail exposures) and be able to demonstrate that the realized default rates are within the expected range for that grade (or pool). AIs using the advanced and retail IRB approaches should perform such analysis for their
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 19 estimates of LGD and EAD. Such comparisons should make use of relevant and material historical data that are over as long a period as possible. AIs should clearly document the methods and data used in such comparisons, and update the analysis and documentation at least annually. 3.5.3 AIs should also use other quantitative validation tools and comparisons with relevant external data sources (see section 11 on benchmarking). The analysis should be based on data that are appropriate to the portfolio, are updated regularly, and cover a relevant observation period. AIs’ assessments of the performance of their rating systems should be based on long data histories, covering a range of economic conditions, and ideally one or more complete economic cycles. 3.5.4 AIs may use the quantitative validation methods cited in this module or other methods for performing the above analyses. For the latter, the AIs should be able to demonstrate to the HKMA that the techniques are theoretically sound, well-documented, consistently applied and able to meet the standards applicable to the generally accepted quantitative techniques. The AIs should be able to provide the rationale for choosing the techniques and demonstrate the appropriateness of using such techniques. 3.5.5 AIs should demonstrate that their quantitative validation methods and other validation methods do not vary systematically with the economic cycle. Changes in methods and data (both data sources and periods covered) should be justified and clearly documented. 3.5.6 AIs should have well-articulated internal standards for situations where deviations in realized values of the credit risk components from expectations become significant enough to call the validity of the estimates into question. These standards should take account of economic cycles and similar systematic variability in the AIs’ default and loss experiences. AIs should put in place a framework for
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 20 revising the credit risk component estimates upward to reflect their default and loss experiences when realized values continue to be higher than the expected values. 3.5.7 In practice, the HKMA expects AIs to establish tolerance limits for the differences between credit risk component estimates and the realized values. AIs should have a clearly documented policy that requires remedial actions to be taken when the tolerance limits are exceeded. The internal tolerance limits and remedial actions should be commensurate with the risk that the computed capital requirement would not be adequate to cover the default risk and credit loss incurred. In setting its internal standards and determining any remedial actions to a breach of those standards, an AI should be able to demonstrate that it has taken into account a range of factors, including but not limited to the relative sizes of the portfolios to which the rating systems are applied, the AI’s risk appetite in respect of the portfolios, the distribution of the portfolios amongst rating grades (or pools for retail exposures), and the inherent risk characteristics of the portfolios. 3.5.8 In general, estimates of the credit risk components are likely to involve unpredictable errors. In order to avoid over-optimism, AIs should add to their estimates a margin of conservatism that is related to the likely range of errors. Where performance of a rating system, and the methods and data used are less satisfactory and the likely range of errors is larger, the margin of conservatism should be larger9 . 3.5.9 An AI must also have a set of procedures to evaluate the appropriateness of the method or data used in estimation of the credit risk components, and there is a mechanism for adjusting the estimates in response to uncertainty stemming from the data, processes or methodologies
9 See section 6 of Q&As:IV for the guidance on the application of margin of conservatism to the credit risk components to account for potential deficiencies in data capturing climate-related financial risks.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 21 used by the AI (e.g. by adding a margin of conservatism for any likely range of errors). 3.5.10 Where AIs rely on supervisory estimates of LGD and EAD, rather than their own internal estimates, they are encouraged to compare the realized values of LGD and EAD to the supervisory estimates. The information on the realized values of LGD and EAD should form part of the AIs’ assessment of economic capital. 3.6 Forward-looking capability of rating systems 3.6.1 While estimation of the credit risk components is required to be grounded in historical experience, the resulting estimates are intended to be forward-looking and conservative. AIs’ rating systems and relevant processes therefore should be able to take into account economic conditions and market developments, as well as risk profile of their obligors and facilities, from a forwardlooking perspective especially if historical experience is not sufficient to capture unfavourable development of the relevant risks. 3.6.2 AIs should incorporate forward-looking elements in their rating systems and/or rating processes. Such elements can be applied in various forms (e.g. ranging from risk factors forming part of a rating system, to judgemental overlays/overrides of ratings generated by a rating system) and complemented by a more dynamic approach to rating reviews (e.g. ad hoc reviews of a certain group of obligors due to abrupt and adverse changes to the business environment of these obligors). 3.6.3 The use of forward-looking elements may involve statistical forecasts, judgemental projections or a combination of both. In this connection, AIs should put in place adequate guidelines and a robust mechanism to ensure such use is prudent, consistent, properly
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 22 documented and subject to adequate monitoring and management oversight. 3.7 Stress-testing 3.7.1 As part of the IRB recognition process and ongoing supervision, the HKMA reviews AIs’ stress-testing programme to ascertain whether such programme is appropriate and effective for assessing the AIs’ capital adequacy in and their ability to withstand stressed business conditions. The supervisory expectations in this regard are set out in Q&As:IV. 4. Corporate governance and oversight 4.1 Effective oversight by an AI’s Board of Directors and senior management is critical to a sound rating system. In addition to the provisions set out in this module, AIs should also refer to CG1 "Corporate Governance of Locally Incorporated Authorized Institutions" and IC-1 "Risk Management Framework" for details of their risk management responsibilities. Many of the provisions and practices therein have a general application which is relevant to the use of the IRB approach. 4.2 The HKMA expects the Board and senior management of an AI to be actively involved in the implementation of the IRB approach at inception and on an ongoing basis, although the degree of attention and the level of detail that the Board and senior management need to comprehend will vary depending on their particular oversight responsibilities. At a minimum, the Board and senior management of an AI must approve all the key elements of, and any material changes to, the AI’s rating systems; possess an adequate understanding of the design and operations of, and the management reports generated on aspects related to the AI’s rating systems; and exercise oversight sufficient to ensure the AI’s compliance with the applicable HKMA requirements. The approval for the key elements of a rating system to be adopted by the AI should normally rest with the Board, or the regional or head office in the case of local subsidiaries.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 23 4.3 For the initial adoption of the IRB approach or any subsequent significant overhauls of the constituent rating systems, the Board of an AI may delegate an appropriate party (e.g. a project steering committee or implementation team comprising senior management from the relevant business, credit, finance, IT, operations, and other support or control functions) to oversee and ensure the proper implementation of the IRB approach or any significant changes to it according to a pre-defined plan. Such delegation may come directly from the regional or head office for local subsidiaries. 4.4 The Board should ensure that sufficient resources are provided for implementing the project and that it is regularly kept informed of the progress in implementation and any slippages. Where the AI is a local subsidiary, efforts must be made locally to meet this requirement10 . Where slippages in the project implementation plan are likely to have a significant effect on the AI’s ability to comply with the applicable HKMA requirements, the Board and the HKMA should be informed as soon as possible. 4.5 AIs are expected to conduct a comprehensive and independent validation of their rating systems at least annually, or when there are material changes in the market environment or business activities of the institutions that might have a significant impact on the use of the rating systems. Nonetheless, it will be acceptable for an AI to conduct the validation exercise on a rolling basis, provided that the arrangements are justified by valid operational considerations, approved by the senior management, and the validation cycle for each portfolio (or component of a rating system, depending on the AI’s design of its validation programme) is initiated no more than 12 months and finished within 18 months after the completion of the previous cycle. An AI should be able to demonstrate to the HKMA that the performance of its rating systems is robust and stable over time. Regardless of how an AI
10 Depending on the complexity and scale of an IRB approach implementation project, individual AIs may need to appoint a full-time manager to take charge of the project. Also, the project implementation plan may need to be divided further into smaller parts or work streams for easier project management and accomplishment of the required tasks. The responsibilities of the respective committee, project manager and staff taking charge of individual work streams should, as the case may be, be clearly defined and documented in the form of committee terms of reference or job descriptions.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 24 implements its validation programme to meet this annual requirement, reports containing adequate information on the validation results should be reviewed and subject to deliberation by the Board. 4.6 Senior management are responsible for the day-to-day operations of an AI, and should have a good general understanding of the AI’s rating systems. Except in the case of local subsidiaries, which may need to adopt group-developed rating systems, senior management should take a leading role in determining the rating systems that the AI plans to adopt based upon the technical support of internal staff and/or external parties with the relevant expertise. 4.7 To ensure that the rating systems work consistently and as intended on an ongoing basis, senior management of an AI should: (i) allocate and maintain sufficient resources (including IT) and internal staff expertise for the development, implementation, support, review and validation of the rating systems to ensure continuing compliance with the applicable HKMA requirements; (ii) clearly delineate and assign the responsibilities and accountabilities for the effective operations and maintenance of the rating systems to the respective business, credit, finance, IT, operations and other support or control functions, or personnel; (iii) ensure that adequate training on the rating systems is provided for staff in the relevant business, credit, finance, IT, operations and other support or control functions; (iv) make necessary changes to the existing policies and procedures as well as systems and controls in order to integrate the use of the rating systems into the AI’s credit risk management processes and culture; (v) ensure that the rating systems are put to use properly; (vi) ensure that the usage of the rating systems extends beyond purely regulatory capital reporting to decision-making and
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 25 monitoring processes including credit approval, limits setting, credit monitoring and reporting, pricing, internal capital allocation, provisioning etc. (see subsection 5.4); (vii) approve and track material differences between the established policies and actual practices (e.g. policy exceptions or overrides); (viii) review the performance and predictive ability of the rating systems at least quarterly through MIS reports; (ix) meet regularly with staff in the relevant business, credit, finance, IT, operations and other support or control functions to discuss the performance and operations of the rating systems, areas requiring improvement, and the status of efforts to remediate previously identified deficiencies; and (x) advise the Board of material changes or exceptions from established policies that may materially impact the operations and performance of the AI’s rating systems. 4.8 As regards the applicable HKMA requirements for quarterly review of the performance and predictive ability of the rating systems, the HKMA recognizes that an increase in the number of defaulted cases over a three-month period may not be significant, especially for certain portfolios with low frequency of default events. In this case, it will be sufficient for senior management to examine only the default and rating migration statistics in the quarterly review exercise, provided that the AI is able to justify its approach with empirical evidence. In addition, the quarterly review of the default and rating migration statistics should include comparisons with expectations and historical figures. 4.9 Information on the internal ratings should be reported to the Board and senior management regularly. The depth and frequency of reporting may vary with the significance and type of information, and the oversight responsibilities of the recipients. The reports should, at a minimum, cover the following information: (i) risk profile of the AI’s obligors by grade (or pool for retail exposures);
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 26 (ii) risk rating migration across grades (or pools) and comparison with expectations; (iii) estimates of the relevant credit risk components per grade (or pool); (iv) comparison of realized default rates (and LGD and EAD where applicable) against estimates; (v) changes in regulatory and economic capital, and identification of sources of the changes; (vi) results of credit risk stress-testing; and (vii) reviews of the effectiveness of the rating systems and processes (including the results of validation, and reports on policy exceptions and overrides) by internal audit function and other independent control functions. 4.10 For AIs extending the use of rating systems to their operations and credit risk exposures outside Hong Kong for regulatory capital reporting to the HKMA, they should exercise effective oversight and governance of the relevant subsidiaries/branches to ensure these entities’ compliance with the applicable HKMA requirements and the AIs’ established policies for implementing the IRB approach. 4.11 The HKMA will look for evidence of the Board and senior management involvement in IRB implementation, and their understanding of the rating systems during both the initial IRB recognition process and the ongoing review of such systems to ensure continuous compliance with the applicable HKMA requirements. 5. Other systems of control 5.1 Independence Independent credit risk control 5.1.1 In relation to the minimum requirements on an AI’s credit risk control unit set out in §1(c) of Schedule 2 to the BCR
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 27 for using the IRB approach, the AI should be able to demonstrate that such unit: (i) actively participates in the development, selection, implementation and validation of the AIs’ rating systems, including testing and monitoring of internal grades (or pools for retail exposures); (ii) assumes oversight and supervision responsibilities for any rating systems used in the rating process, and ultimate responsibility for the ongoing review and alterations to rating systems; (iii) implements procedures to verify that rating definitions are consistently applied across departments and geographic areas of the AI; (iv) reviews and documents any changes to the rating processes, including the reasons for the changes; (v) reviews the rating criteria to evaluate if they remain predictive of risk, and makes sure that any changes to the rating criteria or individual rating parameters are documented and retained for the HKMA’s review; and (vi) produces and analyses summary reports on aspects related to the AI’s rating systems covering historical default data sorted by rating at the time of default and one year prior to default, grade (or pool for retail exposures) migration analysis, and monitoring of trends in key rating criteria. Independent rating approval process 5.1.2 An independent rating approval process is where the parties 11 responsible for approving ratings and transactions are separate from those responsible for
11 AIs may take advantage of techniques or other approaches for rating approval that the parties responsible for approving ratings may not necessarily be a physical person (e.g. an automated rating approval process based on certain predetermined criteria). In such cases, the parties (e.g. system owner) responsible for overseeing the operations of the relevant systems and processes for rating approval should be independent of those responsible for credit initiation.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 28 credit initiation (such as sales and marketing). The purpose is to achieve more objective and accurate risk rating assignment. 5.1.3 Rating processes vary by AI and by portfolio but generally involve a rating “assignor” and a rating “approver”. For a judgement-based rating system, the HKMA expects that credit officers should normally be the party responsible for approving ratings. Their independence should be safeguarded through independent and separate functional reporting lines, and well-defined performance measures (e.g. adherence to policy, rating accuracy and timeliness). 5.1.4 In some cases, ratings are assigned and approved within sales and marketing by staff (although at perhaps different levels of seniority) whose compensation is tied to the volume of business they generate. The HKMA does not normally consider that such arrangements can achieve an adequate degree of independence in the rating approval process. However, the HKMA may, in both the initial IRB recognition process and the ongoing review process of the rating systems, take into account the size and nature of the portfolio to which these arrangements are applied, and the compensating controls in place to mitigate the inherent conflict of interest (such as restrained credit limits, independent post-approval review of ratings, and more frequent internal audit coverage, to prevent any bias in the rating assignment and approval processes). 5.1.5 The above requirements are primarily intended to apply to cases where expert judgement forms part of the inputs to the rating assignment or approval processes. If the rating assignment and approval processes are highly automated and all the rating criteria are based on objective factors (i.e. expert judgement does not form any part of the rating process), the independent review should at a minimum include a process for verifying the accuracy and completeness of the data inputs.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 29 Independent validation of rating system 5.1.6 To ensure the integrity of rating systems (including risk quantification), AIs should have a comprehensive and independent validation process. The unit(s) responsible for validation should be functionally independent of the staff and management functions responsible for developing the underlying rating systems and performing risk quantification activities, and have sufficient stature in the organisational hierarchy to challenge effectively the work of the rating system developers. The activities of this validation process may be distributed across multiple functions or housed within one unit. AIs may choose a structure that fits their management and oversight framework. However, to maintain the independence of the validation process, cross-validations, whereby two or more separate units validate the rating systems developed by one another, should be avoided. Individuals performing the validation should possess the requisite technical skills and expertise. The validation of rating systems should encompass the following aspects: (i) compliance with the applicable HKMA requirements; (ii) compliance with the AIs’ established policies and procedures; (iii) quantification process and accuracy of the credit risk component estimates12; (iv) rating system development and usage13;
12 The performance tests and back-testing should take place at the aggregate rating system level as well as at more granular grade or segment level. The review should also include an evaluation of the risks associated with the use of models (e.g. incorrect estimation of the credit risk components due to improper model design) and exercise of human judgement (e.g. biases and inconsistencies), together with an evaluation of the appropriateness of margins of conservatism to cope with these risks and data imperfections. 13 Including an evaluation of use of the rating systems, such as whether there are limitations on input data, how overrides are exercised and documented, how rating system users are trained and how feedback from such users is addressed.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 30 (v) changes to the rating process and rating system, and documentation thereof, including reasons for the changes; (vi) adequacy of data systems and controls; and (vii) adequacy of staff skills and experience. 5.1.7 The independent validation unit(s) should formulate a plan to define the validation activities and review processes to be performed. The plan should be modified as appropriate having regard to findings identified in the validation processes. The independent validation unit(s) should perform its own tests of all material aspects of the rating systems, including their performance, quality of databases used, and data cleansing. These tests should also cover those already performed by the model developers to check their reliability. 5.1.8 The validation processes should seek to identify any weaknesses, make recommendations and ensure that corrective actions are taken accordingly. Significant findings identified from the validation processes must be reported to the Board and senior management. 5.1.9 AIs that at present lack sufficient in-house expertise to be able to perform the validation function adequately should make appropriate use of external support that is independent and has relevant knowledge and experience. Those AIs that already have the needed skills and resources in-house should nonetheless consider the benefits of supplementing their internal processes with external reviews. External reviewers are likely to possess a broader perspective on the use of rating systems in different jurisdictions and in different institutions, and they may possess more comprehensive data sets to support the cross-testing of rating systems. Notwithstanding that some validation activities are outsourced to external parties, AIs’ internal independent validation unit(s) should retain full and ultimate responsibility for the validation activities and results.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 31 5.2 Transparency 5.2.1 AIs’ rating systems should be transparent to enable third parties, such as rating system reviewers, internal or external auditors, and the HKMA, to understand the design, operations and accuracy of the rating systems, and to evaluate whether the systems are performing as intended. Transparency is an ongoing requirement and should be achieved through comprehensive documentation with regular and timely reviews, and updates as appropriate (e.g. as and when modifications are made to the rating systems). This underlies the minimum requirements stipulated in §1(e) of Schedule 2 to the BCR. 5.2.2 An AI should document in writing the design of its rating systems and related operations as evidence of its compliance with the applicable HKMA requirements. 5.2.3 The AI’s documentation should provide a description of the overarching design of the rating systems, including: (i) the purpose of the rating systems; (ii) portfolio differentiation; and (iii) the rating approach (i.e. how quickly ratings are expected to migrate in response to economic cycles) and implications for the AI’s capital planning process14 . 5.2.4 Rating criteria and definitions should be clearly documented. These include: (i) the relationship between obligor grades (or pools for retail exposures) in terms of the level of risk each grade (or pool) implies, and the risk of each grade (or pool) in terms of both a description of the probability of default typical for obligors assigned the grade (or pool) and the criteria used to
14 For example, if an AI chooses a rating approach under which economic cycles would lead to material rating migrations, its capital management policy should be designed to avoid capital shortfalls in times of economic stress.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 32 distinguish that level of credit risk; (ii) the relationship between facility grades (or pools) in terms of the level of risk each grade (or pool) implies, and the risk of each grade (or pool) in terms of both a description of the expected severity of the loss upon default and the criteria used to distinguish that level of credit risk; (iii) the methodologies and data used in assigning ratings; (iv) the rationale for the choice of the rating criteria and procedures, including analyses demonstrating that those criteria and procedures are able to provide meaningful risk differentiation; (v) definitions of default and loss, demonstrating that they are consistent with those stipulated in the BCR; and (vi) the definition of what constitutes a rating exception (including an override). 5.2.5 Documentation of the rating process and rating system operations should include the following: (i) the organisation of rating assignment/approval; (ii) responsibilities of parties that rate obligors and facilities; (iii) parties that have the authority to approve ratings and that have the authority to approve exceptions (including overrides); (iv) situations where exceptions and overrides can be approved and the procedures for such approval; (v) the rating criteria and procedures (including the frequency of rating reviews); (vi) the process and procedures for updating obligor and facility information; and (vii) the rationale and criteria for assigning obligors (or
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 33 facilities) to a particular rating system if multiple rating systems are used. 5.2.6 In respect of internal control structure, the documentation should be able to demonstrate that: (i) the Board and senior management have adequate oversight of the rating systems and rating process; (ii) independence of the rating assignment/approval process is achieved and ensured; (iii) there are proper audit trails on the history of major changes to the rating process and criteria, in particular to support identification of changes made to the rating process and criteria subsequent to the last supervisory review15; and (iv) there are established procedures (including frequency, parties responsible and reporting of results) and performance standards for reviewing the rating systems in respect of rating accuracy, rating criteria and rating processes in order to determine whether they remain fully applicable to the current portfolio and to external conditions, and that these procedures are adhered to. 5.2.7 Where judgement is used in the rating process, how personal experience and subjective assessment are deployed is less transparent. AIs should offset this shortcoming by applying greater independence in the rating approval process and an enhanced rating system review. 5.2.8 Where an AI employs a statistical model in the rating process and/or estimation of the credit risk components, its documentation should include: (i) the theory, assumptions and/or mathematical and empirical basis of the assignment of
15 The supervisory review could be a review conducted by either the HKMA or the home supervisor of the AI if it is a local subsidiary.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 34 obligors/facilities to grades (or pools for retail exposures) and estimation of the associated credit risk components, and the sources of data used to develop the model; (ii) what data are used as inputs to the model, how the data are transformed, weighted and aggregated to generate the ratings and the associated credit risk component estimates, so that third parties are able to replicate the ratings and the associated credit risk component estimates based on the documentation; (iii) the procedures for human review of model-based rating assessments, focusing on identifying and limiting errors associated with the use of the model; (iv) a rigorous statistical process (including out-of-time and out-of-sample validation) for testing the performance of the model; and (v) any circumstances under which the model does not work effectively. 5.2.9 Use of a model obtained from a third-party vendor that claims proprietary technology is not a justification for exemption from documentation or any other applicable HKMA requirements. The burden is on the vendor and the AI to satisfy the applicable HKMA requirements. 5.3 Accountability 5.3.1 To ensure proper accountability, AIs should have policies that specify individuals or parties responsible for rating accuracy and rating system performance, and establish performance standards in relation to their responsibilities. 5.3.2 The responsibilities (including lines of reporting and the authority of individuals) must be specific and clearly defined. The performance standards should be measurable against specific objectives, with incentive compensation tied to these standards.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 35 5.3.3 For example, performance measures of personnel responsible for rating assignment may include number and frequency of rating errors, significance of errors (e.g. multiple downgrades), and proper and consistent application of criteria, including override criteria. 5.3.4 Staff who assign and approve ratings, derive the credit risk component estimates, or oversee rating systems must be held accountable for complying with rating system policies and ensuring that those aspects of the rating systems under their control are unbiased and accurate. For accountability to be effective, these staff must have the knowledge and skills, and tools and resources necessary to discharge their responsibilities. 5.3.5 If AIs use models in the rating assignment process, a mechanism should be in place to maintain an up-to-date inventory of models16, and an accountability chart of the roles of the parties within the AIs responsible for every aspect of the models including the design, development, use, data updating, data checking, and validation of the models. 5.3.6 A specific individual at sufficiently senior level should have the responsibility for the overall performance of the rating systems. This individual must ensure that the rating systems and all of their components (rating assignments, estimation of the credit risk components, data collection, control and oversight mechanisms etc.) are functioning as intended. When these components are distributed across multiple units of the AI, this individual should be responsible for ensuring that the parts work together effectively and efficiently. 5.4 Use of rating systems Areas of use
16 The inventory of models should include a comprehensive list of models used by the AI, their scopes, materiality, and brief descriptions of modelling methodologies and approval conditions.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 36 5.4.1 In relation to the minimum requirements set out in §(1)(b)(v) and (vi) and §2(b) of Schedule 2 to the BCR, an AI should be able to demonstrate that its rating systems from which ratings and estimates of the credit risk components are generated for regulatory capital calculation are used in such a way as to exert a direct and observable influence on the AI’s decision-making and actions. It is not acceptable if an AI’s rating systems and estimates are designed and implemented exclusively for the purpose of regulatory capital calculation. 5.4.2 In particular, the HKMA expects the AI to apply its internal ratings and estimates of the credit risk components for internal decision-making purposes for at least three years 17 , covering credit approval, credit monitoring, reporting of credit risk information to the AI’s Board of Directors and senior management, and the majority of the following areas: (i) pricing; (ii) setting of limits for individual exposures and portfolios; (iii) determining provisioning; (iv) modelling and management of economic capital; (v) assessment of total capital requirements in relation to credit risks under the AI’s Capital Adequacy Assessment Process (“CAAP”); (vi) stress testing; (vii) assessment of risk appetite; (viii) formulating business strategies (e.g. acquisition strategy for new exposures and collection strategy for problem loans); (ix) setting of, and assessment against, profitability and performance targets;
17 See the relevant guidance in Q&As:IV.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 37 (x) determining performance-related remuneration (e.g. for staff responsible for rating assignment and/or approval); and (xi) other aspects of the AI’s risk management (e.g. IT systems, skills and resources, and organisational structure). Justifications for using different ratings and estimates 5.4.3 AIs may not necessarily use exactly the same ratings and estimates for both regulatory capital calculation and internal purposes. Where there are differences, however, AIs should document the differences and their justifications. The justifications should include: (i) a demonstration of consistency amongst the risk factors and rating criteria used in generating the credit risk component estimates for regulatory capital calculation and those for internal purposes; (ii) a demonstration of consistency amongst the ratings and estimates used in regulatory capital calculation and those for internal purposes; and (iii) qualitative and quantitative analyses of the logic and rationale for the differences. 5.4.4 The justifications should be reviewed by the credit risk control unit and approved by senior management. The document detailing the differences and the justifications should be provided to the HKMA for review upon request. 5.4.5 The HKMA notes that some AIs may maintain more than one rating system for the same portfolio. For example, one system might be used for the purpose of calculating regulatory capital and another for the purpose of benchmarking. These rating systems may all have been developed in-house, or obtained from external sources, or a combination of both. In all such cases, the HKMA expects an AI to provide documented justification for its application of a specific rating system for a specific purpose, and for the role it has assigned to that system in
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 38 its credit management process. In its assessment of whether the “use test” for rating systems has been met, the HKMA will consider the extent to which an AI makes internal use of all the rating systems as a whole, rather than applying the test on an individual system basis. 5.5 Internal audit function and external audit Internal audit function18 5.5.1 Internal audit function should review at least annually an AI’s rating systems and their operations (including the validation process and the estimation of the credit risk components) and the operations of the credit function and its related credit risk control unit. The purpose is to verify whether the control mechanisms over the rating systems are effective, adequate and functioning as intended and the AI is in compliance with the applicable HKMA requirements. The internal audit function should document the findings and report them to the Board and senior management. 5.5.2 The areas of review should include the independence of the credit risk control unit, the depth, scope and quality of work conducted by it in respect of the AI’s use of the IRB approach, as well as the actions taken by AI to address deficiencies identified from the validation of the rating systems. 5.5.3 The internal audit function should give an opinion on: (i) the continuing appropriateness, relevance and comprehensiveness of the existing control mechanisms; (ii) the adequacy of expertise of staff responsible for the operations of the credit risk control unit; (iii) the resources available to these staff; and
18 The independent review or audit in respect of an AI’s rating systems can be conducted by independent external parties which have the relevant experience and knowledge of doing so.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 39 (iv) the AI’s compliance with the applicable HKMA requirements. 5.5.4 In respect of the adequacy of the internal audit function, the AI should be able to demonstrate to the HKMA that in particular: (i) the internal audit staff are equipped with the required skill sets and are provided with relevant resources adequately; and (ii) the audit programme is comprehensive, and the assessment of compliance with the applicable HKMA requirements is covered in the annual audit plan. 5.5.5 Under the IRB recognition process, AIs are required to submit self-assessment questionnaires and relevant supporting documents for review by the HKMA. The HKMA expects internal audit function to be one of the parties signing off on the completed self-assessment as evidence that it has verified an AI’s adherence to all the applicable HKMA requirements. External audit 5.5.6 As part of the process of certifying financial statements, external auditors should gain comfort from an AI that its rating systems are measuring credit risk appropriately and that its regulatory capital position is fairly presented. External auditors should also seek to assure themselves that the AI’s internal controls relating to the calculation of regulatory capital are compliant with the applicable HKMA requirements. 5.6 Treatment of third-party vendor rating systems19 5.6.1 AIs commonly make use of outside expertise to develop rating systems for decision-making or risk management purposes. In the context of the IRB approach, a third-
19 The guidance in this subsection is in line with the principles set out in Basel Committee Newsletter No. 8 “Use of vendor products in the Basel II IRB framework” issued in March 2006.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 40 party vendor rating system (“vendor system”) is a rating system developed by a third party vendor and used by an AI to assign its credit risk exposures to rating grades (or pools for retail exposures) or to estimate the credit risk components of its exposures. 5.6.2 The use of a rating system obtained from a third-party vendor that claims proprietary technology is not a justification for exemption from documentation or any other applicable HKMA requirements in respect of the rating system. Thus, these systems generally have to fulfil the same applicable HKMA requirements as rating systems produced in-house. In addition, senior management should ensure that the outsourced activities performed by third-party vendors are supported by sufficient quality control measures to ensure that the applicable HKMA requirements are met on a continuous basis. AIs may refer to SA-2 “Outsourcing” for further guidance. 5.6.3 The burden is on the AI to satisfy the HKMA that it complies with these applicable HKMA requirements. The HKMA’s assessment regarding a vendor system will focus on the transparency of the system and on its linkage to the AI’s internal information used in the rating process. Where the HKMA considers appropriate, it may request the AI and the third-party vendor to provide detailed information for the HKMA’s assessment. 5.6.4 AIs should demonstrate that they have the in-house knowledge to understand the key aspects of the vendor systems. In particular, they should be able to demonstrate a good understanding of the development (e.g. the overarching design, assumptions, data used, methods and criteria for risk factor selection and determination of the associated weights) and the appropriate use of vendor systems. This requires thirdparty vendors to document the development of the systems and the fundamentals of their validation processes in a way that permits other parties to
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 41 understand the methodologies applied, and to assess whether the systems perform adequately on the AI’s current portfolios. AIs should identify and consider in the course of monitoring their systems all the limitations of the systems and the circumstances in which the systems do not perform as expected. 5.6.5 Where AIs make use of vendor systems, they should ensure that they possess sufficient in-house expertise to support and assess these systems. Staff who are vendor system users should be provided with adequate training in the use of these systems. 5.6.6 Where parts of a vendor system are used simultaneously with parts developed in-house in the rating process, AIs need to be clear about the nature and content of the information (data) that is processed in the vendor system. They should ensure that this information is appropriately linked to information that is processed by the parts developed in-house, so that the aggregation of the different parts of the system does not result in an inconsistent rating method. 5.7 Treatment of group-wide rating systems 5.7.1 In relation to §9(1)(d) of the BCR on an AI’s use of a groupwide rating system, the AI is expected to demonstrate that the system is suitable for calculating the credit risk of its exposures for regulatory capital reporting. The AI should assess that the data used and assumptions adopted for developing the rating system are relevant to its exposures, and that the system performs satisfactorily on its exposures in respect of both risk differentiation and accuracy of the credit risk components. The AI should conduct these assessments on an ongoing basis as part of its regular performance monitoring and independent validation. 5.7.2 An AI’s rating system (or part of the rating system) may be centrally developed and monitored on a group basis. In assessing whether the AI meet the applicable HKMA
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 42 requirements for using the IRB approach, the HKMA will co-ordinate with the home supervisor (or other relevant supervisors) of the banking group regarding the groupwide rating system adopted by the AI. To minimise duplication and overlap in the validation process of the home and host supervisors of the AI, the HKMA will, to the extent practicable and reasonable, take into account the assessment of the home supervisor (or other relevant supervisors) as to the accuracy, verifiability, internal consistency and integrity of the rating system, and the appropriateness of the system for assessing the credit risk characteristics of the AI’s exposures (see paragraph 5.7.1 above). This is, however, on condition that the HKMA is satisfied that the capital adequacy standards adopted by the AI’s home supervisor (or other relevant supervisors) for assessing credit risk under the IRB approach are not materially different from those laid down in the BCR. 6. Data management 6.1 Overview 6.1.1 An AI should: (i) have an effective system to collect, store, process, retrieve and utilize data on obligor and facility characteristics and default and loss information in respect of the AI’s exposures in a reliable and consistent manner20; (ii) ensure that the internal or external data it uses in estimating the credit risk components are representative of the AI’s long run default and loss experience and are based on relevant economic or market conditions; and (iii) have in place a process for vetting data inputs into the rating systems, including an assessment of the
20 The guidance in subsection 5.2 of IC-1 “Risk Management Framework” is generally applicable here.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 43 accuracy, completeness and appropriateness of data. 6.1.2 The HKMA recognizes that the approach to data management varies by AI and, on many occasions, by type of exposures within an AI. However, regardless of the approach they adopt, AIs should adhere to the provisions in this section in respect of the following aspects: (i) management oversight and control; (ii) IT infrastructure and data architecture; (iii) data collection, storage, retrieval and deletion; (iv) maintaining data for rating system development, validation and implementation, and for regulatory reporting; (v) data processing; (vi) data quality assessment; (vii) reconciliation between the data used for regulatory capital calculation and the accounting data; (viii) use of external and pooled data; and (ix) application of statistical techniques. 6.1.3 An AI should provide the HKMA with a summary of its approach to data management in relation to the above aspects. The summary should include a diagram of the data architecture covering the collection and storage of data, all data flows between systems, and how relevant data are collated for regulatory capital calculation purposes. 6.2 Management oversight and control 6.2.1 Senior management of an AI have the responsibility for establishing and maintaining a consistent standard of sound practices for data management across the AI. In particular, senior management are responsible for:
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 44 (i) establishing polices, standards and procedures for the collection, maintenance, delivery, updating and use of data, and ensuring their effective implementation; (ii) establishing a clear organisational structure specifying the accountability for data collection and management so as to ensure proper segregation of duties amongst and within various business units to support data management tasks; (iii) assessing on an ongoing basis the risks arising from potential poor quality data and ensuring that appropriate risk mitigation measures have been undertaken; (iv) ensuring sufficient staffing with relevant expertise and experience to handle present and expected work demand; (v) formalising internal audit programmes, the scope of which should include assessments of both the numbers produced and the processes used in data management; and (vi) ensuring that outsourced activities performed by third-party vendors are supported by sufficient quality control measures to ensure that the applicable HKMA requirements are met on a continuous basis. 6.2.2 Where data management-related activities are performed on behalf of the AI by another entity in the same banking group, such as an office outside Hong Kong, the management of the AI are responsible for ensuring that the standards of data management employed by the group entity are consistent with the applicable HKMA requirements, and that the respective responsibilities of the entity and the AI are documented (e.g. policies, procedures or service agreements) and properly implemented.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 45 6.3 IT infrastructure and data architecture 6.3.1 An AI should have an adequate IT infrastructure (e.g. data warehouse or data mart) in place to support the management of data. In particular, AIs should store data in electronic format so as to allow timely retrieval for analysis and validation of rating systems. The infrastructure should also support comprehensive data quality control measures including data validation and error detection, data cleansing, reconciliation and exceptions reporting. 6.3.2 AIs’ data architecture should be scalable, secure and stable21. Scalability ensures that growing needs due to lengthening data history and business expansion can be met. AIs should test systems’ security and stability in the development of data architecture and IT systems. The HKMA expects AIs to have policies, standards and measures, including audit trails, in place to control access to the data. AIs should also have complete back-up, recovery and contingency planning to protect data integrity in the event of emergency or disaster22 . 6.3.3 AIs are expected to perform adequate user acceptance tests to ascertain that new or changes to IT systems (including those arising from adoption of a new rating system or modifications to an existing rating system) will perform as intended. 6.4 Data collection, storage, retrieval and deletion 6.4.1 AIs should have clear and documented policies, standards (including IT standards) and procedures regarding the collection and maintenance of data in
21 For ensuring the stability and security of IT systems, AIs should follow the guidance set out in TM-G1 “General Principles for Technology Risk Management” and the relevant documents issued by the HKMA (https://www.hkma.gov.hk/eng/regulatory-resources/regulatory-guides/by-subjectcurrent/technology-risk-management/?t=1716643666179). 22 The guidance set out in TM-G-2 “Business Continuity Planning” is applicable here.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 46 practice, such that data availability can be ensured over time to meet the anticipated demands in the medium and long run, and the data stored include sufficient details so as to enable the AIs to comply with the applicable HKMA requirements in relation to data management. 6.4.2 Data should be updated at least annually or more frequently as required in accordance with the relevant minimum updating requirement for estimation of the credit risk components23 . AIs should be able to demonstrate that their procedures to ensure that the frequency with which data items are updated are sufficient to reflect the risk inherent in their current portfolios. For example, data for obligors with higher default risk or delinquent exposures should be subject to higher updating frequency. 6.4.3 The HKMA also expects AIs to: (i) establish clear and comprehensive documentation for data definition, collection and aggregation, including data sources, updating and aggregation routines; (ii) establish standards and conduct relevant tests on the accuracy, completeness, timeliness and reliability of data; (iii) ensure that data collected have the scope, depth and reliability to support the operations of rating systems, overrides, back-testing, regulatory capital calculation and relevant management and regulatory reporting; (iv) in cases where the necessary data items are absent in the collection process (i.e. data gaps), identify and document such gaps, specify the interim solutions in respect of the rating assignment and risk quantification processes and set up a plan to fill the gaps;
23 See the relevant guidance set out in Q&As:IV on the regulatory requirements on data.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 47 (v) establish standards, policies and procedures around the cleansing of data, and ensure consistent applications of the techniques; (vi) establish procedures for identifying and reporting data errors and problems in data transmission and delivery; (vii) ensure that data collection, storage and retrieval are secure, and at the same time not forming unnecessary obstacles to data users (including the HKMA for supervisory purposes); (viii) ensure that access controls and data distribution have been validated by internal audit function; and (ix) establish documented policies and procedures addressing storage, retention and archival, including the procedures for deletion of data and destruction of data storage media. 6.5 Maintaining data for rating system development, implementation and validation, and regulatory reporting 6.5.1 An AI should collect and store data on key obligor and facility characteristics to provide effective support to its internal credit risk measurement and management process and to enable it to meet the applicable HKMA requirements. The data collection and IT systems should serve the following purposes: (i) improve the AI’s internally data for development of rating systems and estimation of the credit risk components, and validation of both; (ii) provide an audit trail to check adherence to the rating criteria; (iii) enhance and track performance of the rating systems; (iv) modify risk rating definitions to more accurately address the observed drivers of credit risk; and (v) serve as a basis for regulatory reporting.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 48 6.5.2 The data should be sufficiently detailed to allow retrospective reallocation of obligors and facilities to grades or pools for retail exposures (e.g. if it becomes necessary to have finer segregation of portfolios in future). 6.5.3 The data should also enable the AI to comply with the Banking (Disclosure) Rules. Corporate, sovereign and bank exposures 6.5.4 AIs should maintain complete rating histories on obligors and credit protection providers, which include: (i) the ratings since the obligor/guarantor was assigned an internal grade; (ii) the dates the ratings were assigned; (iii) the methodology and key data used to derive the ratings and PD estimates; (iv) the person/rating system responsible for the rating assignment; (v) the identity of obligors and facilities that have defaulted, and the date and circumstances of such defaults; and (vi) data on the PD estimates and realized default rates associated with rating grades and rating migration. 6.5.5 AIs using the advanced IRB approach should also collect and store a complete history of data on LGD and EAD estimates associated with each facility. These include: (i) the dates the ratings were assigned and the estimates done; (ii) the key data and methodology used to derive the facility ratings and estimates; (iii) the person/rating system responsible for the rating assignment and estimates; (iv) data on the estimated and realized LGDs and EADs associated with each defaulted facility;
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 49 (v) data on the LGD of the facility before and after evaluation of the credit risk mitigating effects of any recognized guarantee/credit derivative contracts; and (vi) information about the components of loss or recovery for each defaulted exposure, such as amounts recovered, source of recovery (e.g. collateral, liquidation proceeds and guarantees), time required for recovery, and administrative costs. 6.5.6 AIs utilizing supervisory estimates under the foundation IRB approach are encouraged to retain relevant data (e.g. data on loss and recovery experience for corporate, sovereign, and bank exposures under the foundation IRB approach; and data on realized losses for specialized lending exposures where the supervisory slotting criteria approach is applied). Retail exposures 6.5.7 AIs should collect and store the following data: (i) data used in the process of allocating exposures to pools, including data on obligor and transaction risk characteristics used either directly or through use of a rating system, as well as data on delinquency; (ii) data on the estimated credit risk components associated with each pool of exposures; (iii) the identity of obligors and details of exposures that have defaulted; and (iv) data on the pools to which defaulted exposures were assigned over the year prior to default and the realized outcomes on LGD and EAD. 6.6 Data processing 6.6.1 Data processing covers a wide range of manual or automated activities including data conversion through
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 50 multiple systems, transmissions, data validation and reconciliation. In this regard, the HKMA expects AIs to: (i) limit reliance on manual data manipulation in order to mitigate the risk related to human errors; (ii) establish standards and data processing infrastructure for life-cycle tracking of credit data including, but not limited to, relevant history covering features of obligors and facilities, ratings and overrides, repayments, rollovers and restructuring; (iii) ensure that data are validated and cleansed, and reconciled with accounting data (see subsection 6.7), such as sample checking on manually input financial statement information; (iv) establish adequate controls to ensure processing by authorized staff acting within designated roles and authorities; (v) modify the control procedures when there are changes in the processing environments, conduct testing and parallel processing, and obtain sign-offs by staff at appropriately senior level before full implementation; and (vi) provide back-up, process resumption and recovery capabilities to mitigate loss of data and/or data integrity in the event of emergency or disaster24 . 6.7 Reconciliation 6.7.1 The HKMA expects AIs to conduct reconciliation, where possible, between accounting data and the data used in the risk quantification process under the IRB approach. This would require AIs to identify from the risk quantification data set those data items that can be reconciled with accounting data, and establish the procedures for doing so.
24 The guidance set out in TM-G-2 “Business Continuity Planning” is applicable here.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 51 6.7.2 Both an AI’s rating systems and its accounting systems take data inputs and transform them into data outputs. Therefore, reconciliation between these systems may focus on inputs, outputs (e.g. expected loss under the IRB approach and relevant accounting provisions) or both. At a minimum, AIs should conduct reconciliation on data inputs. 6.7.3 AIs should document the reconciliation process and results (i.e. the amount of the difference between the two data sets), as well as the explanations for why and how the difference arises. The explanations should be sufficiently detailed (e.g. how much of the difference is attributable to non-identical treatments for regulatory capital calculation and accounting purposes) and supported by sufficient evidence to facilitate internal audit function in verifying enterprise-wide consistency in the use of data and assessing data accuracy, completeness and appropriateness. 6.7.4 AIs should document the treatment for non-reconciled items (i.e. the amount of difference that cannot be fully explained). In addition, as non-reconciliation may be an indication of deficiency in data quality, AIs should establish standards to address this, and enhance their data management process and apply conservatism in regulatory capital calculation when there are discrepancies. The HKMA may not approve an AI’s rating systems if, in its opinion, the discrepancies are of such significance as to cast doubt on the reliability of the systems. 6.8 Data quality assessment 6.8.1 In addition to qualitative assessments on the adequacy of the aspects described in subsections 6.2 to 6.7, the HKMA expects AIs to apply quantitative measures in assessing data accuracy (e.g. error rates in sample checking of data accuracy), completeness (e.g. proportion of observations with missing data) and
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 52 timeliness (e.g. proportion of data updated later than scheduled). 6.8.2 The data quality assessment should be included as part of the independent review and validation of the rating assignment and risk quantification processes. While the reviewers may either be internal or external parties, they must not be accountable for the work being reviewed. 6.8.3 The data quality assessment should be conducted at least annually, matching the minimum frequency of validation of rating systems by independent validation unit(s) and the review of adherence to all applicable HKMA requirements by internal audit function. In addition, AIs are expected to track how the previously identified deficiencies, if any, have been treated and addressed. 6.8.4 The methods employed and analyses conducted in the assessment should be fully documented. The assessment results should be reported to senior management, and further investigation and follow-up actions should be fully documented. 6.8.5 To facilitate quality assessment and identification of problems, AIs should ensure that there are clear audit trails on data (information on where the data are collected, how they are processed and stored, and used in the rating assignment and risk quantification processes etc.). 6.9 Use of external and pooled data 6.9.1 AIs that use external or pooled data in rating system development and validation, rating assignment and/or risk quantification processes must be able to demonstrate that the data are applicable and relevant to the portfolio to which they are being applied. AIs should be able to demonstrate that data definitions are consistent between the external or pooled data, and AIs’ internal portfolio data, and that distributions of the key risk characteristics (e.g. industry and company size) are similar.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 53 6.9.2 AIs should be able to demonstrate that the arrangements for data management by third-party vendors in relation to external or pooled data used by the AIs meet the same standards required for data management by the AIs. In addition, AIs should have policies and procedures in place to assess and control the risk arising from the use of external or pooled data. In particular, AIs are expected to: (i) understand how the third-party vendors collect the data; (ii) understand the quality control programmes used by the third-party vendors and evaluate the adequacy thereof; (iii) establish data cleansing procedures for the external or pooled data; (iv) check the external or pooled data against multiple sources no less than once every 12 months to ensure the accuracy, completeness and timeliness of data; and (v) conduct reviews no less than once every 12 months to assess the appropriateness of continuing the use of the external or pooled data. 6.9.3 The process of managing the use of external or pooled data, including the activities described above, should be documented and subject to review by the AIs’ internal audit function. 6.9.4 When outsourcing activities are involved in the data management process, AIs should follow the guidance set out in SA-2 “Outsourcing” and section 7 of TM-G-1 “General Principles for Technology Risk Management”. 6.10 Statistical issues 6.10.1 Where AIs use statistical techniques (e.g. sampling, smoothing and sample truncation to remove outlying observations) in the preparation of the development and
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 54 validation data sets, and in the operations of rating systems, their application should be justified and based on sound scientific methods. AIs should be able to demonstrate a full understanding of the properties and limitations of the statistical techniques they use, and the applicability of these techniques to different types of data. 6.10.2 AIs should be able to demonstrate that the occurrences of missing data are random and that they do not have systematic relationships with default events or credit losses. Where it is necessary to remove observations with missing data, AIs should provide sound justifications, as these observations may contain important information on default events or credit losses. The HKMA does not normally consider that an AI has a robust rating system if a large number of observations with missing data have been removed from the data sets used in the development, validation and operations of the system. 7. Accuracy of PD 7.1 Supervisory expectations for estimation of PD Corporate, sovereign and bank exposures 7.1.1 For the purposes of §159(2)(b) of the BCR regarding the use of multiple techniques in PD estimation, AIs should recognize the importance of judgments in combining the results of different techniques and in making adjustments for limitations of the techniques and information. Mechanical application of a technique without supporting analysis is not acceptable. 7.1.2 AIs may use one or more of the three techniques in PD estimation, namely internal default experience, mapping to external data and statistical default prediction models. For all of them, AIs must estimate a PD for each rating grade based on the observed historical average oneyear default rate that is a simple average based on number
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 55 of obligors (count weighted). Other weighting approaches, such as EAD weighting, are not permitted. 7.1.3 If an AI uses data on internal default experience for the estimation of PD, it should: (i) demonstrate in its analysis that the estimates are reflective of underwriting standards and of any differences in the rating system that generated the data and the current rating system; (ii) add a greater margin of conservatism in its PD estimates where only limited data are available, or where underwriting standards or rating systems have changed; and (iii) in case of using pooled data across institutions, demonstrate that the rating systems and criteria of other institutions contributing to the pooled data are comparable with its own. 7.1.4 If an AI associates or maps it internal grades to the scale used by an external credit assessment institution or a similar institution (“external institution”), and attributes the default rates observed for the external institution's grades to its grades, the AI should: (i) perform the mappings based on a comparison of its internal rating criteria to the criteria used by the external institution, and on a comparison of the internal and external ratings of any common borrowers; (ii) avoid any biases or inconsistencies in the mapping approach or underlying data; (iii) ascertain that the external institution’s criteria underlying the data used for quantification are oriented to the default risk of borrowers and do not reflect transaction characteristics; (iv) include a comparison of the default definitions used having regard to the definition stipulated in §149 of
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 56 the BCR, and an analysis of the implication for the PD assigned to its internal grades; (v) document the basis for the mapping; and (vi) consider whether the scale used by the external institution reflects material climate-related financial risks25 . 7.1.5 If an AI uses a statistical default prediction model for PD estimation, it may use a simple average of the defaultprobability estimates generated by the model for individual obligors in a given grade for the calculation of credit risk of exposures to such obligors. Estimation techniques for retail exposures 7.1.6 In general, AIs are expected to estimate the PD of their retail exposures based on their internal default experience or statistical default prediction models, and paragraphs 7.1.3 and 7.1.5 are applicable as appropriate. 7.2 Overview on validation of PD 7.2.1 There are two key stages in the validation of PD: validation of the risk differentiation capability (i.e. discriminatory power) of a rating system and validation of the calibration of a rating system (accuracy of the PD quantification). For each stage, the HKMA expects AIs to be able to demonstrate that they employ one or more of the quantitative techniques listed in subsections 7.3 and 7.4 respectively (see Annexes A and B for details). The procedures and assumptions used in applying the techniques must be documented and consistently applied. 7.2.2 If an AI intends to use techniques not included in subsections 7.3 and 7.4, it should observe the requirements set out in paragraph 3.5.4.
25 AIs may refer to FAQ1 under paragraph CRE36.78 of Chapter CRE36 (IRB approach: minimum requirements to use IRB approach) of the Basel framework for details.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 57 7.2.3 The HKMA expects AIs to validate both the discriminatory power and calibration of their rating systems no less than once every 12 months. Such validations should be conducted based on the definition of default stipulated in §149 of the BCR, notwithstanding any alternative definitions for default AIs may employ for their own internal risk management purposes. 7.3 Validation of discriminatory power 7.3.1 The HKMA expects AIs to demonstrate that they use one or more of the following methodologies in assessing the discriminatory power of a rating system: (i) Cumulative Accuracy Profile (“CAP”) and its summary index, the Accuracy Ratio (“AR”); (ii) Receiver Operating Characteristic (“ROC”) and its summary indices, the ROC measure, the Pietra Index and Kolmogorov-Smirnov (“KS”) test statistic; (iii) Bayesian error rate (“BER”); (iv) Conditional entropy, Kullback-Leibler distance, and Conditional Information Entropy Ratio (“CIER”); (v) Information value (“IV”); (vi) Kendall’s and Somers’ D (for shadow ratings); (vii) Brier score (“BS”); and (viii) Divergence. Stability analysis 7.3.2 The HKMA expects AIs to demonstrate that their rating systems exhibit stable discriminatory power. Therefore, in addition to in-sample validation, AIs should be able to demonstrate their rating systems’ discriminatory power on an out-of-sample and out-of-time basis. This is to ensure that the discriminatory power is stable on data sets that are cross-sectionally or temporally independent of,
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 58 but structurally similar26 to, the development data set. If out-of-sample and out-of-time validations cannot be conducted due to data constraints, AIs are expected to employ statistical techniques such as k-fold cross validation27 or bootstrapping28 for this purpose. When an AI uses these statistical techniques, it should be able to provide the rationale for using these techniques and demonstrate the appropriateness of the chosen techniques, and understand the limitations, if any, of these techniques. Establishment of internal tolerance limits and responses 7.3.3 Consistent with the expectations set out in paragraph 3.5.7, the HKMA expects AIs to establish internal standards for assessing the discriminatory power of their rating systems. Breaches of these standards, together with the associated responses, should be fully documented. The HKMA expects to see a range of responses from an increase in validation frequency to redevelopment of the rating systems, depending on the results of the assessments. 7.3.4 The HKMA expects an AI’s internal standards for its rating systems’ discriminatory power, and its responses to breaches of these standards, to be commensurate with the potential impact on the AI’s financial soundness of a failure of its rating systems to discriminate adequately between defaulting and non-defaulting obligors. 7.4 Validation of calibration
26 “Structurally similar” means that distributions of obligors’ key characteristics (e.g. industry and company size) in the independent data set for validation are similar to those in the development data set. 27 “K-fold cross validation” is a kind of test employing resampling techniques. Specifically, a data set is divided into k subsets. Each time, one of the k subsets is used as the validation data set and the other k-1 subsets are put together to form the development data set. By repeating the procedures k times, the targeted test statistic across all k trials is then computed. 28 “Bootstrapping” is a resampling technique with replacement of the data sampled, aiming to generate information on the distribution of the underlying data set.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 59 7.4.1 The HKMA expects AIs to demonstrate the use of either or both of the following methodologies in assessing the accuracy of its estimates of PD: (i) Binomial test with assumption of independent default events; and (ii) Binomial test with assumption of non-zero default correlation. AIs may also assess the accuracy of PD estimates for multiple rating grades (or pools for retail exposures) by using other methodologies such as Chi-square test. However, the AIs should also adopt methodologies which are aimed for assessing the accuracy of the PD estimates for individual grades (or pools) in order to satisfy the requirement set out in paragraph 3.5.2. Establishment of internal tolerance limits and responses 7.4.2 For the purposes of paragraph 3.5.7, AIs may construct the tolerance limits (and the associated policy on remedial actions) around the confidence levels used in the tests in paragraph 7.4.129 . However, AIs should refrain from using this approach if the resulting tolerance limits are excessively high as compared to the PD estimates (i.e. the realized default rates will need to be very high as compared to the PD estimates in order to constitute a breach of the internal standards). 8. Accuracy of LGD 8.1 Supervisory expectations for estimation of LGD
29 For example, if a Binomial test is used, AIs can set tolerance limits at confidence levels of 95% and 99%. Deviations of the estimates of PD from the realized default rates below a confidence level of 95% may not be regarded as significant and remedial actions may not be needed. Deviations at a confidence level higher than 99% may be regarded as significant and the PD estimates must be revised upward immediately. Deviations which are significant at confidence levels between 95% and 99% may be put on a watch list, and upward revisions to the PD estimates may be made if the deviations persist.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 60 Definition of loss 8.1.1 The definition of loss for LGD estimation is economic loss, as reflected in the requirement set out in §161(2)(b) and §178(2)(b) of the BCR. AIs should not simply use accounting loss as their LGD estimates, although they should be able to compare accounting and economic losses. Recognition of recovery and collateral 8.1.2 An AI’s own workout and collection approach as well as the relevant expertise can significantly influence its recovery of defaulted exposures and therefore should be reflected in its LGD estimates as appropriate. However, AIs should take account of such approach and expertise conservatively (e.g. until there is sufficient empirical evidence showing the positive impact of the expertise). 8.1.3 In relation to §161(1)(c) and §178(1)(e) of the BCR, AIs incorporating the risk mitigating effect of collateral in LGD estimation should recognize their potential inability to gain both control of the collateral and liquidate it expeditiously. AIs should establish a robust framework for managing collateral and ascertaining the legal certainty surrounding the control of collateral, with a set of comprehensive policies, operational procedures and risk management processes that are generally consistent with those required for the foundation IRB approach. 8.1.4 In relation to §161(2)(c) and (d), and §178(2)(c) and (d) of the BCR, an AI should in its LGD estimation consider: (i) the extent of dependence between the default risk of the obligor and the risks associated with the collateral or collateral provider. AIs should address any material dependence in a conservative manner; and (ii) any currency mismatch between the collateral and the underlying obligation and treat such mismatch conservatively.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 61 Downturn LGD30 8.1.5 For certain types of facilities (or pools for retail exposures), loss severities may exhibit significant cyclical variability and LGD estimates may differ materially from the long run default-weighted average. For these facility types and pools, AIs should incorporate the impact of economic downturn conditions into their LGD estimates as required by §161(1)(a) and §178(1)(a) of the BCR. 8.1.6 In the process of identifying economic downturn conditions for estimation of LGD, AIs may make reference to the averages of loss severities observed during periods of high credit losses, forecasts (or extrapolation) based on appropriately conservative assumptions, or other similar methods (e.g. regression models). Appropriate estimates of LGD during periods of high credit losses can be formed using internal data, external data or a combination of both. 8.1.7 An AI should have a rigorous and well-documented process for assessing the effects of economic downturn conditions on recovery rates and for producing LGD estimates consistent with these conditions. The process must consist of the following components: (i) the identification of appropriate downturn conditions for the AI’s exposures of each IRB class within each jurisdiction; (ii) the identification of adverse dependencies, if any, between default rates and recovery rates; and (iii) the incorporation of adverse dependencies, if identified, between default rates and recovery rates so as to produce LGD parameters for the AI’s exposures consistent with the identified downturn conditions.
30 The expectations set out in this subsection reflect the principles issued by the Basel Committee in July 2005 on “Guidance on Paragraph 468 of the Framework Document”. AIs may refer to this document for details.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 62 8.1.8 An AI should provide the HKMA with the long-run defaultweighted average loss rate given default for every relevant facility type unless the AI can demonstrate to the HKMA that: (i) its estimate of loss rate given default under downturn conditions is consistent with paragraphs 8.1.6 and 8.1.7 above; and (ii) it is not practical to report a separate estimate of long-run default-weighted average loss rate given default. 8.2 Methods for assigning LGD to non-defaulted exposures 8.2.1 The HKMA expects AIs to use one of the following methods to assign LGD to non-defaulted exposures: (i) workout LGD which is based on observations of the discounted cash flows resulting from the workout process for defaulted facilities; (ii) market LGD which is derived from observations of market prices on defaulted bonds or marketable loans soon after default; (iii) implied historical LGD which is inferred from an estimate of the expected long-run loss rate (which is based on the experience of total losses) of a portfolio (or a segment of a portfolio) and the PD estimate of that (segment of) portfolio. This method is only allowed for deriving the LGD of retail exposures; and (iv) implied market LGD which is derived from nondefaulted risky bond prices through an asset-pricing model. 8.2.2 For both the workout LGD and market LGD methods, AIs should be able to demonstrate to the HKMA that they have established appropriate methods to: (i) determine which defaulted facilities are to be included in the development data set;
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 63 (ii) determine and measure the realized LGD of the defaulted facilities in the development data set; and (iii) assign LGD to the non-defaulted facilities in the AIs’ current portfolios based on the information obtained from the process in (ii). Further elaborations of the HKMA’s expectations for these areas are provided in subsections 8.4 and 8.5. 8.2.3 For the implied historical LGD method for retail exposures, the validity of an LGD estimate will depend on that of the estimate of the expected long-run loss rate and that of the PD estimate. Therefore, AIs should be able to demonstrate to the HKMA that the estimates of the expected long-run loss rate and the PD are appropriately determined. 8.2.4 For the implied market LGD method, credit spreads of non-defaulted risky bonds are used. The credit spreads, among other things, are decomposed into PD and LGD with an asset-pricing model. The AIs should therefore be able to demonstrate to the HKMA the appropriateness of: (i) the non-defaulted facilities that are included in the development data set; and (ii) the method used to decompose credit spreads into PD and LGD (i.e. the soundness of the asset-pricing model used). 8.2.5 The HKMA expects AIs to be able to justify their choice of method for LGD estimation, and demonstrate a full understanding of the properties and limitations of the methods they use, and the applicability of these methods to different types of facilities (or pools for retail exposures). 8.3 Assignment of LGD estimates to defaulted exposures 8.3.1 In relation to §161(1)(d) and §178(1)(f) of the BCR, the LGD assigned to a defaulted exposure should reflect the possibility that an AI would have to incur additional, unexpected losses during the recovery period. The AI
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 64 must also construct its best estimate of the expected loss on each defaulted exposure based on current economic circumstances and facility status as required by §220(2)(b) of the BCR. The amount, if any, by which the LGD assigned to the defaulted exposure exceeds the AI’s best estimate of the expected loss on the exposure represents the capital requirement for that exposure according to §156(4) and §176(5) of the BCR as appropriate. Instances where the best estimate of the expected loss on a defaulted exposure is less than the sum of specific provisions and partial charge-offs for that exposure must be justified. The details and the justification should be well documented for the HKMA’s scrutiny upon request.31 8.4 LGD estimation process for workout and market LGD32 Construction of a development data set 8.4.1 The first step in LGD estimation is to construct a development data set containing the relevant information on defaulted facilities such as loss, recovery, risk factors etc. An AI should be able to demonstrate to the HKMA that in constructing the development data set: (i) there are no potential biases in selecting the defaulted facilities; (ii) data for years with relatively frequent defaults and high realized LGD are included;
31 This subsection does not apply to an AI using the supervisory estimate for the LGD as the EL for its corporate, sovereign and bank exposures which are in default. 32 The estimation process outlined in this subsection is directly related to the market LGD and workout LGD methods. Where applicable, however, AIs using the implied historical and implied market LGD methods should follow the guidance set out in this subsection. For example, an AI using the implied market LGD method should ensure that there are no potential biases in selecting the non-defaulted bonds for constructing the development data set, and that the transaction characteristics of these bonds are similar to those of the AI’s portfolio. Similarly, an AI using the implied historical LGD method should ensure that the estimate of the expected long-run loss rate is consistent with the concept of economic loss under which all the aspects discussed in subsection 8.5 should be taken into account.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 65 (iii) the risk factors/transaction characteristics in the development data set and those used by the AI in assigning facility rating or segmentation are the same or similar; and (iv) the definition of default used in the development data set for LGD estimation is consistent with the one used for PD estimation. Measuring the realized LGD for the defaulted facilities 8.4.2 After constructing the development data set, the realized LGD for each defaulted facility included in the development data set must be measured. For workout LGD, this should involve all the aspects discussed in subsection 8.5. For market LGD, an AI should be able to demonstrate that issues surrounding liquidity of the relevant markets for defaulted facilities and comparability of the instruments in the development data set to the AI’s portfolio have been adequately considered. Assignment of LGD estimates to non-defaulted facilities 8.4.3 AIs should be able to demonstrate that they have conducted an analysis of the empirical distribution of realized LGD to detect problems related to outlying observations, changes in segmentation, and temporal homogeneity of the facilities included in the development data set. 8.4.4 The HKMA expects AIs to evaluate the variability of realized LGD in the development data set as well as that of newly defaulted facilities for each facility type33 . The LGD assigned to the non-defaulted facilities should be adjusted upward if the variability is high, for instance, relative to the mean.
33 For the purposes of validation, AIs are expected to perform validation at an appropriate level of granularity having regard to the design of their rating system in order to demonstrate the robustness and accuracy of the LGD estimates. AIs are also expected to perform validation of key parameters used in their rating systems (e.g. haircut applied on collateral).
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 66 8.4.5 AIs may use modelling techniques (e.g. a regression model) to directly derive, or to refine the LGD estimates. When models are used, the HKMA expects AIs to perform both out-of-time and out-of-sample tests in order to assess their true predictive power. 8.4.6 Expert judgement should only be used to fine-tune the LGD estimates to the extent that the reasons for adjustments have not been taken into account in the estimation process. The process of exercising expert judgement should be prudent, transparent, welldocumented and closely monitored. 8.4.7 AIs should compare the LGD estimates with the long-run default-weighted average loss rate given default for every relevant facility type to ensure that the former is not lower than the latter. 8.5 Issues specific to workout LGD 8.5.1 Workout LGD is the most commonly used method in the industry. The definition of when a workout ends, measurements of recoveries and costs, and the assumption on discount rates are crucial to computing the realized LGD for the defaulted facilities in the development data set. Definition of the end of a workout 8.5.2 The HKMA expects AIs to define when a workout is finished using one of the following four options: (i) a recovery threshold (e.g. when the remaining nonrecovered value is less than 5% of the EAD); (ii) a given time threshold (e.g. one year from the date of default); (iii) an event-based threshold (e.g. when repossession occurs); and (iv) a combination of (i), (ii) and/or (iii) (e.g. the earlier of one year from the date of default and when repossession occurs).
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 67 When formulating the definition, AIs should consider the resulting impact on the development data set, and be able to justify their choice. For example, many defaulted facilities in the recent years may be excluded from the development data set if only data of completed workouts are considered or if a 10-year time threshold is adopted. AIs should refrain from adopting such definition if reliability of the resulting LGD estimates is compromised because of such exclusion. Measurement of recoveries 8.5.3 Recoveries from a workout process can be cash recoveries and/or non-cash recoveries. (i) Cash recoveries are relatively easy to measure and incorporate into the LGD calculations. (ii) Non-cash recoveries, especially those resulting from repossessions, are more difficult to track and are typically treated on a case-by-case basis for individual defaulted facilities in the development data set. 8.5.4 There are two options for AIs to measure non-cash recoveries resulting from repossessions. (i) The first option is to consider the recovery process complete at the time of the repossession. (ii) The second option is to consider the recovery process complete only when the repossessed asset has been sold to a third party. 8.5.5 If AIs choose to adopt the first option, they should apply a haircut coefficient to the book value of the repossessed asset to convert the associated non-cash recovery into an artificial cash recovery. AIs should calibrate the haircut coefficient based on historical experience (e.g. historical volatility of asset value and time required for selling the asset to a third party), taking into account the impact of economic downturn conditions as appropriate.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 68 Measurement and allocation of costs 8.5.6 AIs must include all the costs, including both direct costs and indirect costs, of the workout process in the calculation of LGD, taking account of the possibility that AIs will have to incur unexpected costs during the debt recovery period. (i) Direct costs are those associated with a particular facility (e.g. a fee for an appraisal of collateral). (ii) Indirect costs are those necessary to carry out the recovery process but not associated with individual facilities (e.g. overheads associated with the office space for the workout department). 8.5.7 The HKMA generally expects AIs to identify the key recovery costs for each product, to model them using a sample of defaulted facilities for which the true costs (both direct and indirect costs) are known, and to allocate the costs of recoveries out of the sample using the model. Choice of discount rate 8.5.8 To calculate the economic loss of a defaulted facility, it is necessary to discount the observed recoveries and costs back to the date of default using some discount rates. The HKMA recognizes two options that can be used by AIs: historical discount rates and current discount rates. (i) Historical discount rates are fixed for each defaulted facility, regardless of the date on which the LGD is being estimated. All of the cash flows associated with a defaulted facility are discounted using a rate determined at a particular date in the life of the defaulted facility. Alternatively, at the date of default a discount rate curve can be constructed with rates for each date over the expected life of the workout and the cash flows can be discounted using the curve. Typically, the discount rate is defined as either the risk-free rate plus a spread at the default
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 69 date for the average recovery period, a suitable rate for an asset of similar risk at the default date, or a zero-coupon yield plus a spread at the default date. (ii) Current discount rates are fixed on each date on which LGD is being estimated. All the cash flows associated with a defaulted facility are discounted by using a rate, or a curve, that is determined at the current date. These rates can be either average rates computed at the moment when the LGD is being calculated (such as the average risk-free rate plus a spread during the last economic cycle or the average rate of similar risky assets over the last economic cycle) or spot rates plus a spread existing at that moment. 8.5.9 The HKMA expects AIs to use either method of calculating discount rates in a consistent and conservative manner. The guiding principle is that the selected discount rates should reflect the cost of holding defaulted assets over the workout period and include an appropriate risk premium which is commensurate with the risks of the recovery. Specifically, the higher the uncertainty about the recovery in respect of a defaulted facility, the higher the discount rate that will be expected. 8.5.10 The discount rate applied should reflect the underlying risk of the transaction and the type and nature of the security available to the AI. A risk-free rate should only be used when the recovery is: (i) expected to come from liquidation of cash collateral with certainty; or (ii) converted to a certainty-equivalent cash flow34 . 8.5.11 In cases where the recovery is expected to arise from entering into a new contract to pay (e.g. restructuring) or
34 “Certainty-equivalent cash flow” means the cash payment required to make a risk-averse investor indifferent between (i) receiving that cash payment with certainty at the payment date and (ii) receiving an asset yielding an uncertain payout whose distribution at the payment date is equal to that of the uncertain cash flow.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 70 from enforcing the existing contract, the discount rate should be higher than the original contractual rate. This is to reflect the heightened risk evidenced by the default. Where possible, reference should be made to yields on defaulted facilities of similar structure. 8.5.12 When the recovery is expected to come from a third party (e.g. a guarantor), the discount rate should reflect the risk associated with that third party. 8.5.13 The HKMA does not generally expect AIs to use the cost of capital, the cost of funding or the cost of equity as the discount rates, as these rates do not reflect the risk of recovery of a defaulted facility. The HKMA generally expects that the discount rate used by an AI will vary by type of product/facility in order to reflect the differences in the risk of recovery. However, the HKMA may consider permitting an AI to use the same discount rate across different products/facilities, provided that it is able to demonstrate to the HKMA that: (i) such rate is sufficiently conservative as regards the products/facilities to which the rate is applied; or (ii) the products/facilities share a similar level of risk in their recoveries. 8.6 Validation of LGD estimates 8.6.1 AIs should be able to demonstrate that they have performed the following analyses and tests on their estimates of LGD: (i) Stability analysis: To assess if LGD estimates are stable and robust, AIs should analyse: how changes in the development data set (e.g. use of sub-samples) and changes in the assumptions made for determining the realized LGD and/or parameters of the model impact the LGD estimates; and
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 71 the volatility of the LGD estimates when the timeframe of the development data set changes. (ii) Comparisons between realized LGD of newly defaulted facilities and their LGD estimates: AIs should: compare the actual outcomes with their internal estimates; employ statistical test(s) 35 to back-test their internal LGD estimates against the realized LGD of the new defaulted facilities if there are a sufficient number of such facilities for performing statistical test(s) meaningfully (paragraph 3.5.4 is also applicable); and establish internal tolerance limits for the differences between the estimates and the realized LGD, and have a policy that requires remedial actions to be taken when such limits are exceeded36 (see paragraph 3.5.7). (iii) Risk differentiation analysis: AIs should perform analyses to demonstrate that the categorisation of facilities into different types (or segmentation of retail exposures into different pools) and the associated LGD estimates provide a meaningful differentiation of risk. Such analyses can be quantitative (e.g. test(s) to demonstrate that the LGD estimates for different facility types are statistically different from each other), qualitative having regard to the transaction characteristics, or a combination of both.
35 Based on the development data set, AIs may assume a distribution on the LGD for performing statistical test(s) (e.g. t-test). 36 For example, AIs can assume a parametric distribution on the LGD estimate for a certain type of facilities. Based on this distribution, AIs can establish confidence intervals around the LGD estimate. The tolerance limits and remedial actions then can be constructed on different confidence intervals in which the realized default-weighted average LGD of the new defaulted facilities may fall. The issue noted in paragraph 7.4.2 is also applicable here.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 72 (iv) Comparisons between internal LGD estimates and relevant external data sources: Where possible, AIs should compare their internal LGD estimates with relevant external data sources. When conducting the comparison, the AIs should take into account the differences in default definition, potential biases in the external data sample (e.g. arising from differences in workout practices, facility types etc.), and different measures of recoveries/losses and discount rates. 9. Accuracy of EAD37 9.1 Supervisory expectations for estimation of EAD Credit management 9.1.1 EAD can be sensitive to the way that AIs manage credits and changes therein. The HKMA expects AIs to: (i) have a process in place for ensuring that estimates of EAD take into account these practices and relevant changes. In particular, an AI should raise its EAD estimates immediately if such changes are expected to cause credit conversion factors (CCFs) of the relevant facility types to increase materially. However, downward adjustments to CCFs that may potentially result from such changes should be made only after a significant amount of actual experience has been accumulated to justify such adjustments;
37 This section sets out the supervisory expectations for estimation and validation of EAD of AIs’ noncounterparty credit risk exposures, and exposures for which AIs are allowed to use their own estimates of EAD for the purposes of regulatory capital calculation under the BCR (e.g. this section is not applicable to AIs’ non-revolving undrawn commitments). For transactions that expose AIs to counterparty credit risk, estimates of EAD must fulfil the requirements set forth in Part 6A of the BCR and the relevant regulatory guidance.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 73 (ii) pay due consideration to their specific policies and strategies adopted in respect of account monitoring and payment processing; (iii) consider their ability and willingness to prevent further drawings in circumstances short of payment default, such as covenant violations or other technical default events; (iv) have adequate systems and procedures in place to monitor facility amounts, current outstanding amounts against committed lines and changes in outstanding amounts per obligor and per grade (or per pool for retail exposures); and (v) be able to monitor outstanding balances on a daily basis. Consideration of economic downturn 9.1.2 For the purposes of §164(4)(c) and (ca) of the BCR, the supervisory expectations set out in paragraphs 8.1.6 to 8.1.8 are also applicable to EAD estimation in general. For AIs which are able to develop their own EAD models, this could be achieved by, for example, considering the cyclical nature, if any, of the drivers of such models. AIs which do not have sufficient data but have to rely on external data in their assessment of the impact of economic downturn should make use of such data conservatively. 9.2 EAD estimation process for non-defaulted facilities 9.2.1 The estimation process of EAD for non-defaulted facilities in general involves the following steps: (i) A development data set 38 storing information on defaulted facilities (including the relevant risk factors) is first constructed (see paragraphs 9.2.4 to 9.2.7).
38 This is also called “reference data set” in Chapter CRE36 of the Basel Framework (IRB approach: minimum requirements to use IRB approach).
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 74 (ii) CCF of each of these defaulted facilities is then calculated. (iii) The relationship between the CCF and the risk factors is established (in the form of, for example, a regression model or classification based on the risk factors). (iv) The CCF and hence EAD for the non-defaulted facilities in the current portfolio is then estimated based on this relationship. 9.2.2 An AI’s EAD estimates should be based on data that reflect the obligor, facility and its management practice characteristics of the exposures to which the estimates are applied. Consistent with this principle, EAD estimates should be based on appropriately homogenous segments, or based on an estimation approach that effectively disentangles the impact of the different characteristics exhibited within the development data set. On the other hand, EAD estimates applied to particular exposures should not be based on data that comingle the effects of disparate characteristics or data from exposures that exhibit different characteristics, such as: (i) same broad product grouping but different customers that are managed differently by the AI (e.g. SME/middle market data being applied to large corporate obligors); (ii) data from commitments with small unused credit limits being applied to facilities with large unused limits; (iii) data from obligors already identified as problematic at observation point (e.g. obligors who were already delinquent, put on the AI’s watch list, blocked from further drawdowns, subject to recent limit reduction initiated by the AI or other types of collection activities etc. at 12 months before such obligors defaulted) being applied to current obligors with no known issues; and
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 75 (iv) data that have been materially affected by changes in obligors’ mix of borrowing and other credit-related products (i.e. product profile transformation) over the observation period (i.e. the period between the observation point and date of default) without any measures to mitigate the potential distortion arising from such changes (see paragraph 9.2.7). 9.2.3 The expectations set out in paragraphs 8.4.3 to 8.4.7 on LGD estimation are also applicable to the estimation of CCF for non-defaulted facilities. Construction of development data set 9.2.4 AIs should use the 12-month fixed-horizon approach to construct their development data sets for EAD estimation, i.e. for each observation in the development data set, default outcomes must be linked to relevant obligor and facility characteristics twelve months prior to default. As an example, with a 12-month fixed interval, if a default event occurred on 15 July 2024, then in addition to the outstanding amount upon default, information about risk factors of the defaulted facility 12 months ago (the observation point is then 15 July 2023) is to be used. 9.2.5 EAD data must not be capped to the principal amount outstanding or facility limits. Accrued interest, other due payments and limit excesses should be included in the EAD data. 9.2.6 Data of facilities that have defaulted, but have subsequently been recovered, should also be included. 9.2.7 For EAD data which have been affected by product profile transformation over the observation period, an AI should be able to demonstrate to the HKMA that it has a detailed understanding of the impact of the transformation on their CCF/EAD estimates, and that the impact is immaterial or has been effectively mitigated within the AI’s EAD estimation process. The HKMA in general does not consider the following as effective mitigating measures:
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 76 (i) setting floors to CCF or EAD observations; (ii) use of obligor-level estimates that do not fully cover the relevant product transformation options or inappropriately combine products with very different characteristics (e.g. revolving and nonrevolving products); (iii) adjusting only material observations affected by product profile transformation; and (iv) generally excluding observations affected by product profile transformation. Criteria for deriving EAD estimates 9.2.8 In relation to §164(4)(e)(ii) and §180(1) of the BCR, the criteria or risk factors considered by an AI in deriving its CCF/EAD estimates must be plausible and intuitive, and represent what the AI believes to be the material drivers of EAD. The HKMA expects the AI to demonstrate that its choices are supported by credible internal analysis, and be able to provide a breakdown of its EAD experience by the factors it sees as the drivers of EAD. The AI should use all relevant and material information in deriving its CCF/EAD estimates, and review these estimates across facility types when material new information becomes available and at least on an annual basis. 9.2.9 AIs are recommended to take into account the following types of factors in their EAD estimation process: (i) factors affecting the obligor’s demand for funding/facilities; (ii) factors affecting the AI’s willingness to supply funding/facilities; (iii) the attitude of third parties (e.g. other AIs, money lenders, trade creditors and owners if the obligor is a company) who can act as alternative sources of funding supply available to the obligor; and
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 77 (iv) the nature of the particular facility and the features built into it (e.g. covenant protection). Some possible risk factors that AIs may consider in the estimation of EAD are given in Annex C39 . Expectations on certain approaches to CCF estimation 9.2.10 An AI may use obligors’ outstanding balances (including accrued but unpaid interest and fees) at the reporting dates of capital adequacy ratios as its EAD estimates for facility types which only involve on-balance sheet exposures (e.g. term loans). For facilities with off-balance sheet exposures (e.g. credit lines, commitments and guarantees), an AI may take 100% of credit limits 40 at the reporting date as the EAD estimates. An AI using either or both of these methods should demonstrate that the estimated aggregate EAD amount for each of the facility types is higher than the realized aggregate EAD amount for that facility type (see paragraph 9.3.2). An AI using 100% of credit limits as the EAD estimates for facilities with off-balance sheet exposures should develop a plan agreeable to the HKMA to estimate the CCFs for such facilities. 9.2.11 The undrawn limit factor (ULF) approach41 is a commonly used method in estimating CCF for facilities with off-
39 The list of risk factors in Annex C is not intended to be exhaustive. The HKMA expects AIs to take into account additional risk factors that may influence EAD. 40 If an obligor’s outstanding balance (including accrued but unpaid interest and fees) at the reporting date is higher than the credit limit, the outstanding balance should be used as the EAD estimate for the relevant facility. 41 ULF is a type of CCF, where predicted additional drawings in the lead-up to default are expressed as a percentage of the undrawn limit that remains available to the obligor under the terms and conditions of a facility, i.e. EAD = Bt + ULF x [Lt – Bt], where Bt = current balance (for EAD estimation) or balance at observation point (for realized EAD in development data set); Lt = current limit (for EAD estimation) or limit at observation point (for realized EAD in development data set).
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 78 balance sheet exposures. AIs using this approach should be able to demonstrate that they have taken effective measures to address the issue about instability of their CCF estimates associated with facilities close to being fully drawn at observation point. For instance, an AI may consider switching to another method (e.g. limit factor (LF), balance factor (BF) or additional utilization factor (AUF) approach42) as the region of instability approaches. The HKMA in general considers it ineffective if an AI attempt to address the instability issue by capping or flooring the observed CCF of defaulted facilities in the development data set (e.g. capping the CCF at 100% or flooring the CCF at 0%), or omitting observations that are judged to be affected by such issue. 9.3 Validation of EAD estimates 9.3.1 AIs should be able to demonstrate that they have conducted the same types of analyses and tests used for assessing LGD estimates (see paragraph 8.6.1) in their assessment of the accuracy of EAD estimates in terms of CCF. The expectations set out in paragraph 3.5.7 are also applicable to the validation of CCF. 9.3.2 Where AIs use obligors’ outstanding balances as EAD estimates for facilities which only involve on-balance sheet exposures, or use obligors’ credit limits as EAD estimates for facilities which involve off-balance sheet exposures (see paragraph 9.2.10), the HKMA does not normally expect them to conduct the analyses and
42 LF is a type of CCF, where the predicted balance at default is expressed as a percentage of the total limit that is available to the obligor under the terms and conditions of a credit facility, i.e. EAD = LF x Lt, where Lt = current limit (for EAD estimation) or limit at observation point (for realized EAD in development data set). BF is another type of CCF, where the predicted balance at default is expressed as a percentage of the current balance that has been drawn down under a credit facility, i.e. EAD = BF x Bt. AUF is also a type of CCF, where predicted additional drawings in the lead-up to default are expressed as a percentage of the total limit that is available to the obligor under the terms and conditions of a credit facility, i.e. EAD = Bt + AUF x Lt.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 79 assessments described in paragraph 9.3.1 for validating the accuracy of the relevant EAD estimates. However, AIs should be able to demonstrate no less than once every 12 months that these EAD estimates are sufficiently conservative43. In particular, the HKMA expects AIs to: (i) compare the estimated aggregate EAD amount for the subject facility type with the realized aggregate EAD amount for that facility type; and (ii) monitor the safety margin under these approaches, where safety margin can be defined as:
43 There can be situations where the realized EAD is larger than the credit limit at observation point for facilities that involve off-balance sheet exposures (e.g. upward revision to credit limit after observation point), and where the realized EAD is larger than the outstanding balance for facilities that only involve on-balance sheet exposures (e.g. accumulation of accrued but unpaid interest and fees). 44 Although the focus of the recommendations is mainly on PD estimation and validation, they can be applied to other credit risk components. AIs may also refer to Basel Committee Newsletter No. 6 “Validation of low-default portfolios in the Basel II Framework” issued in September 2005 for further details.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 80 In practice, there are several types of portfolios that may qualify as LDPs, including but not limited to: (i) portfolios that historically have experienced low numbers of defaults and are generally considered to be relatively low-risk (e.g. sovereigns, banks, insurance companies, large corporations); (ii) portfolios that are relatively small in size either globally or at an individual bank level (e.g. project finance, shipping); (iii) portfolios for which an AI is a recent market entrant; and (iv) portfolios that have not incurred recent losses but historical experience or analysis suggests that there is a greater likelihood of default (or losses) than is captured in recent data (e.g. retail residential mortgages in a number of jurisdictions). 10.2 Implications for risk quantification and validation 10.2.1 An AI should consider whether any of its portfolios have the characteristics of an LDP. If so, the AI should design specific risk quantification and validation methodologies appropriate for such portfolios, as each type of LDPs has quite different risk characteristics with varying implications for risk quantification and validation. In particular, AIs should be able to demonstrate that they have taken into account the considerations in paragraphs 10.2.3 to 10.2.6, which extend the Basel IRB validation principles. 10.2.2 AIs should note that the techniques outlined in paragraphs 10.2.3 to 10.2.6 are tools to enhance the reliability of the credit risk component estimates for LDPs. The applicability of a particular technique is likely to vary between AIs. AIs may also use techniques other than those described in this module. In all cases, AIs will need to justify their chosen techniques, document the
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 81 limitations and apply conservatism to the results where necessary. Forward-looking and predictive risk estimates 10.2.3 Credit risk component estimates are intended to be forward-looking. Therefore, the relative scarcity of historical default and loss data in some circumstances may not be a serious impediment to developing PD and, where applicable, LGD and EAD estimates. Where, for example, there is a lack of recent loss data, but other analysis suggests that the potential risk of loss in a portfolio is not negligible (type (iv) in paragraph 10.1.1), AIs may base the credit risk component estimates not solely on recent loss data, but also on additional information about the drivers of default and losses. For example, AIs can use default and loss experience of similar asset classes in other geographical locations in risk quantification or validation. Taking a longer run of data would be another option provided that the data are available. Data-enhancing techniques 10.2.4 Where the problem of limited loss data exists at the level of an individual AI, the HKMA expects the AI to make use of techniques such as pooling of data with other financial institutions or market participants, acquire and utilize data from other external sources, or apply market measures of risk, to compensate for its lack of internal loss data. An AI would need to satisfy itself and the HKMA that the external or pooled data are relevant to its own situation (see subsection 6.9). This technique is especially relevant to small portfolios (type (ii) in paragraph 10.1.1) and to portfolios where an AI is a recent market entrant (type (iii) in paragraph 10.1.1). 10.2.5 For some portfolios, such as type (i) in paragraph 10.1.1 above, there may be limited loss data not just at the level of an individual AI, but also across the industry. In these cases, the HKMA expects AIs to demonstrate the use of
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 82 some or all of the following techniques to enhance data richness45: (i) combining internal portfolio segments with similar risk characteristics for estimating and validating the credit risk components. For example, an AI may have a broad portfolio with adequate default history that, if more narrowly segmented, may result in the creation of a number of LDPs. In these cases, AIs that use narrower segmentation for internal use might be expected to combine the sub-portfolios for the purposes of estimating or validating the credit risk components for the calculation of regulatory capital requirements; (ii) combining different rating grades (or pools for retail exposures), and estimate or validate the credit risk components for the combined grade (or pool). This technique is especially useful for AIs using a rating system that maps to a rating agency’s grades, for example, to combine AAA, AA, and A-rated credits, or to combine BBB+, BBB, and BBB-rated credits; (iii) calculating a multi-year PD and then annualize the resulting figure where defaults are spread out over a number of years. (iv) using the lowest non-defaulted rating as a proxy for default if low default rates in a particular portfolio are the result of credit support (e.g. government bailout of distressed state-owned enterprises, banks, investment firms, thrifts, pension funds and insurance firms); and (v) analysing intra-year rating migrations as separate rating movements to infer the annualized PD.
45 These tools are also applicable to other types of LDPs.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 83 Effective use of benchmarking tools 10.2.6 When AIs do not have sufficient default and loss data (even if data-enhancing techniques are used) to back-test the accuracy of their rating systems including the associated credit risk component estimates, the HKMA expects them to use benchmarking tools to demonstrate that their rating systems and the credit risk component estimates are accurate. Section 11 gives details on the use of benchmarking tools in validation. 11. Benchmarking 11.1 Overview 11.1.1 In the context of validation, benchmarking refers to the comparison of an AI’s internal ratings and credit risk component estimates obtained from the AI’s rating systems with those obtained from other sources or using other techniques (the “benchmarks”). 11.1.2 In the validation of rating systems and the associated credit risk component estimates for LDPs, back-testing may not be applicable due to insufficient amount of default and loss data. In these cases, the HKMA expects AIs to use and integrate benchmarking into their validation processes and conduct relevant assessments as part of their annual validation. 11.1.3 Generally, the HKMA expects AIs to obtain their benchmarks from third parties, provided that relevant external benchmarks for a specific portfolio are available. The HKMA will not accept an AI using cost implications as the sole justification for not obtaining external benchmarks to validate its rating systems and the relevant credit risk components for LDPs. 11.1.4 Where a relevant external benchmark is not available for its LDPs, an AI should develop an internal benchmark. For example, to benchmark against a model-based rating system, an AI may employ internal rating reviewers to re-
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 84 rate a sample of credits on an expert-judgement basis or use an alternative model to generate the ratings and credit risk component estimates. If an AI is able to demonstrate to the HKMA that it has other compensating measures to ensure that the internal ratings and credit risk component estimates are credible and sufficiently conservative, this requirement may be waived. 11.1.5 If an AI has a sufficient amount of default and loss data to back-test its rating systems and credit risk component estimates, it is not required to use benchmarking to validate such systems and estimates. Nevertheless, the HKMA would encourage the AI to use benchmarking to supplement its back-testing analyses especially if benchmarks from third parties are available. 11.2 Use of benchmarking 11.2.1 AIs should be able to explain the differences between the internal ratings/estimates and the benchmarks, and take necessary actions (e.g. review the rating criteria) if the differences are significantly larger than expected. To achieve the effective use of benchmarking, AIs should establish internal tolerance limits for the differences, and the remedial actions when the limits are breached. The form of the tolerance limits should depend on the type of benchmarking. The general expectations for AIs in establishing their internal tolerance limits and remedial actions for back-testing (see paragraphs 3.5.7, 7.3.3 and 7.3.4) are also applicable to benchmarking. 11.2.2 An AI should be able to demonstrate to the HKMA that its use of benchmarking is appropriate and effective on a portfolio-specific basis. In particular, the HKMA will have regard to the following in assessing whether the use of benchmarking by an AI is appropriate: (i) suitability of the types of benchmarking chosen for the portfolio; (ii) quality of the benchmarks in terms of their accuracy in predicting default and/or loss;
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 85 (iii) comparability of the benchmarks with the AI’s internal estimates in terms of, for example, the definition of default and assessment horizon; (iv) consistency and appropriateness of the mapping procedures, if these procedures are required in the benchmarking exercise; (v) adequacy of the use of the benchmarking results in relation to the AI’s risk management policies; (vi) level of oversight exercised by the Board and senior management on the benchmarking exercise and the results thereof; and (vii) adequacy of the AI’s internal audit of its benchmarking exercise. 11.3 Types of benchmarking 11.3.1 Benchmarking can take a variety of forms, generally depending on the relevant types and characteristics of exposures. This could be in the form of different data used, and methods of rating assignment and risk quantification etc. The following is a list of the types of benchmarking that the HKMA normally expects AIs to use in validating their rating systems and internal estimates: (i) comparison of internal ratings or estimates with benchmarks with respect to a common or similar set of obligors/facilities; (ii) comparison of internal ratings and migration matrices with the ratings and migration matrices of third parties such as rating agencies; (iii) comparison of internal ratings with external expert judgements, for example, where a portfolio has not experienced recent losses but historical experience suggests that the risk of loss is greater than zero; (iv) comparison of internal ratings or estimates with market-based proxies for credit quality, such as
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 86 equity prices, bond spreads, or premiums for credit derivatives; (v) analysis of the rating characteristics of similarly rated exposures; and (vi) comparison of the average rating output for the portfolio as a whole with actual experience for the portfolio rather than focusing on credit risk component estimates for individual obligors/facilities. 11.3.2 The above list of benchmarking techniques is not intended to be exhaustive. The HKMA expects an AI to demonstrate the use of a wide variety of benchmarking techniques and their appropriateness for specific portfolios in providing assurance regarding the accuracy of its rating systems and the associated credit risk component estimates. 11.3.3 The HKMA notes that AIs may maintain more than one rating system for the same portfolio, for example one for the purpose of the regulatory capital calculation and another for benchmarking. In such cases, the HKMA expects AIs to provide documented justifications for their application of a specific rating system to a specific purpose (see subsection 5.4 above). 11.4 Selection of benchmark 11.4.1 AIs should be able to demonstrate that the selection of a benchmark is based on an assessment of its qualities in adequately representing the risk characteristics of the portfolio under consideration. Such qualities include: (i) definition of default; (ii) rating criteria; (iii) data quality; (iv) frequency of rating updates; and (v) assessment horizon.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 87 11.4.2 To accept an AI’s benchmark for validation purposes, it should be able to demonstrate an adequate level of equivalence between the rating system and the benchmark rating system in the above aspects. This is to ensure that the ratings or credit risk component estimates generated from the two rating systems are comparable. 11.4.3 The HKMA generally recognizes a benchmark for validation purposes subject to the following conditions: (i) the AI should be able to demonstrate an adequate level of equivalence between the rating system and the benchmark rating systems; (ii) both the equivalence and the differences in properties between the AI’s rating system and the benchmark rating systems are well-documented; and (iii) any differences between the rating systems are taken into account in the analyses of the benchmarking results. 11.4.4 AIs should also assess the accuracy of the benchmark rating systems in comparison with their rating systems. 11.4.5 Before conducting the regular benchmarking exercise, AIs should reassess the appropriateness of the types of benchmarking and methodologies chosen taking into account changes in the AIs’ portfolio characteristics and the external environment. 11.5 Mapping to benchmark 11.5.1 In designing the mapping procedures, where required in conducting the benchmarking exercise, an AI should ensure consistency between the properties of its rating systems and the benchmark rating systems. 11.5.2 The HKMA recognizes that there might not be a one-toone mapping between internal ratings and benchmark ratings. In this case, the AI should be able to demonstrate the appropriateness of the mapping methodology
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 88 adopted, and how the mapping methodology would affect the benchmarking results and analyses thereof. 11.5.3 In designing a consistent mapping to a master scale, AIs should be able to demonstrate the appropriateness of the granularity of the master scale. A balance needs to be struck between meaningful risk differentiation and having so many grades (or pools for retail exposures) with too few exposures falling into a single grade (or pool), thereby significantly reducing the reliability of the benchmarking results.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 89 Annex A: Quantitative techniques in validating discriminatory power A1. Generating the data set for validation A1.1 In order to generate the data set for validation, an AI needs to define two cut-off dates with an interval of at least 12 months (the assessment horizon or observation period). The rating information (obligor grade, credit score or pool for retail exposures) on a predefined set of obligors as of the earlier cut-off date (the observation point) is collected. Then the associated performance information (i.e. default or not) on these obligors as of the later cut-off date is added. A1.2 The set of obligors chosen as the validation data set determines whether the validation is in-sample, out-of-sample or out-of-time. Regardless of the type of validation, the validation data set should be structurally similar to the AI’s actual portfolio in terms of the obligors’ characteristics such as industry, company size, residency and income. A1.3 Information on obligors that have defaulted before the first cut-off date cannot be used. Cases for which the loans were properly repaid during the assessment horizon should be included and are classified as “nondefault”. Cases for which no rating information as of the first cut-off date is available (e.g. new accounts) cannot be included in the sample. Updated rating information on the obligors between the cut-off dates cannot be used. Figure A1 depicts how a validation data set is generated. A1.4 Based on the information collected, the distributions of defaulters and non-defaulters as per obligor grade (or score or range of scores, or pool for retail exposures) can be obtained and used for validation. A1.5 Data of different pairs of cut-off dates can be pooled for validation. This is especially necessary when the sample size within each pair of cut-off dates is not large enough. But the resulting measures will be an indication of the average discriminatory power over the relevant period. A1.6 Out-of-sample and out-of-time validation to a certain extent can verify the stability of a rating system. Besides, an AI can generate subsamples from the validation data set or use various assessment horizons (e.g. two years), and check whether the discriminatory power of a rating system is stable across the sub-samples or different assessment horizons.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 90 Figure A1. Generating the data set for validation A2. Cumulative Accuracy Profile (“CAP”) and Accuracy Ratio (“AR”) CAP A2.1 CAP is also known as the Gini curve, Power curve or Lorenz curve. It is a visual tool whose graph can be drawn if two samples of obligor grades (or scores, or pools for retail exposures) for defaulters and nondefaulters are available. A2.2 Consider a rating model that is intended to produce higher rating scores for obligors of lower default probability. To obtain a CAP curve, all obligors are first rank-ordered by their respective scores, from the riskiest to the safest, i.e. from the obligor with the lowest score to the obligor with the highest score. The CAP curve is then constructed by plotting the cumulative percentage of all obligors on the horizontal axis and the cumulative percentage of all defaulters on the vertical axis, as illustrated in figure A2. A2.3 Concavity of a CAP curve is equivalent to the property that the conditional probabilities of default given the underlying scores form a 12 months Cut-off date 1 Cut-off date 2 Rating information Performance information Default Complete repayment More recent rating cannot be used. Non-default Non-default Default Case cannot be used, as the rating information is not available on cut-off date 1. Non-default
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 91 decreasing function of the scores. Non-concavity indicates sub-optimal use of information in the specification of the scoring function. A2.4 A perfect rating model will assign the lowest scores to the defaulters. In this case, the CAP curve will increase linearly (i.e. OA in figure A2) and then stay at 100% (i.e. AB). For a random model without any discriminatory power, the percentage of all obligors with rating scores below a certain level (i.e. the X co-ordinate) will be the same as the percentage of all defaulters with rating scores below that level (i.e. the Y co-ordinate). In this case, the CAP curve will be identical to the diagonal (i.e. the straight line OB). In reality, the CAP curve of a rating system will be somewhere in between these two extremes (i.e. the arch OB). Figure A2. Cumulative Accuracy Profile (CAP) AR A2.5 AR (also known as the Gini coefficient and Powerstat) is a summary index of a CAP. It is defined as the ratio of the area aR between the CAP of the rating system being validated and the CAP of the random model, and the area aP (area of triangle AOB) between the CAP of the perfect rating model and the CAP of the random model, i.e.: Cumulative percentage of all defaulters Cumulative percentage of all obligors Perfect model A 100% aR aP B Random model Model under consideration O 0% 100%
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 92 P R a a AR . A2.6 In practice, there are many approaches to the calculation of the areas. The HKMA does not prescribe a particular method but an AI should apply a theoretically sound method and use the same method consistently. A2.7 AR is always between 0% and 100% for any rating system better than random assignment of ratings. The better the rating system, the closer is AR to 100%. A3. Receiver Operating Characteristic (“ROC”), ROC measure and Pietra Index ROC A3.1 Like CAP, ROC is a visual tool that can be constructed if two samples of obligor grades (or scores, or pools for retail exposures) for defaulters and non-defaulters are available. To plot this curve, the rating grade (or pool) or score distribution for defaulters, on the one hand, and for nondefaulters, on the other, is determined.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 93 Frequency Rating score Defaulters C Non-defaulters Figure A3. Distribution of rating scores for defaulters and nondefaulters A3.2 For a perfect rating model, the left distribution and the right distribution in figure A3 would be separate. In reality, a rating system with perfect discrimination is unlikely, and the two distributions will overlap partially as illustrated in figure A3. A3.3 Assume that an AI has to find out from the rating scores which obligors will not default during the assessment horizon and which obligors will default. One possibility for the AI would be to introduce a cut-off value C as in figure A3, and to classify obligors with rating scores lower than C as potential defaulters and obligors with rating scores higher than C as potential non-defaulters. Then four decision results would be possible. If the rating score of an obligor is below the cut-off value C and the obligor defaults subsequently in the assessment horizon, the decision was correct (i.e. “hit”). Otherwise, the AI wrongly classified a nondefaulter as a defaulter (i.e. “false alarm”). If the rating score is above the cut-off value and the obligor does not default, the classification was correct. Otherwise, a defaulter was incorrectly assigned to the nondefaulters’ group. A3.4 To plot the ROC curve, hit rate HR(C) is defined as:
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 94 ND H C HR C , where H(C) is the number of defaulters predicted correctly with the cutoff value C, and ND is the total number of defaulters in the sample. This means that the hit rate is the fraction of defaulters that was classified correctly for a given cut-off value C. The false alarm rate FAR(C) is defined as: NND F C FAR C , where F(C) is the number of false alarms, i.e. the number of nondefaulters that were classified incorrectly as defaulters by using the cutoff value C. NND is the total number of non-defaulters in the sample. In figure A3, HR(C) is the area to the left of the cut-off value C under the score distribution of the defaulters (the coloured area), while FAR(C) is the area to the left of C under the score distribution of the non-defaulters (the chequered area). A3.5 The quantities HR(C) and FAR(C) are computed for all cut-off values C that are contained in the range of the rating scores. The ROC curve is a plot of HR(C) versus FAR(C). This is illustrated in figure A4. Figure A4. Receiver Operating Characteristic (ROC) curve Hit rate False alarm rate 1 Perfect model 1 Random model 0 Model under consideration ROC measure
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 95 A3.6 As with CAP, concavity of a ROC curve is equivalent to the conditional probabilities of default being a decreasing function of the underlying scores and non-concavity indicates sub-optimal use of information in the specification of the scoring function. The better a rating model’s performance, the steeper is the ROC curve at the left end and the closer is the ROC curve’s position to the point (0, 1). ROC measure A3.7 The ROC measure (also known as the area under the curve, “AUC”) is defined as the area below the ROC curve, including the triangle below the diagonal of the unit square. A random model without discriminatory power has a ROC measure equal to 50%, and a perfect model would have a ROC measure equal to 100%46 . A3.8 As with AR, there are many approaches to the calculation of the areas in practice. The HKMA does not prescribe a particular method but an AI should apply a theoretically sound method and use the same method consistently. Pietra Index A3.9 Geometrically, the Pietra Index can be defined as the maximum area of a triangle that can be inscribed between the ROC curve and the diagonal of the unit square. In case of a concave ROC, the Pietra Index can be calculated as follows: max HRC FARC 4 2 Pietra Index C . KS test statistic A3.10 The maximum term HR(C) - FAR(C) in the calculation of the Pietra Index is the KS test statistic of the distribution functions HR(C) and FAR(C). The expression |HR(C) – FAR(C)| can take values between zero and one. The better a rating model’s performance, the closer is the value to
46 The AR and ROC measure have a linear relationship: AR = 2 (ROC measure) - 1.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 96 one. This expression can also be interpreted as the maximum difference between the cumulative frequency distribution of defaulters and that of non-defaulters. Confidence intervals and tests for the ROC measure and Pietra Index A3.11 The ROC measure has statistical properties coincident with the MannWhitney statistic. Therefore, AIs can construct confidence intervals for the ROC measure of a rating system and test the difference between the ROC measures of two rating systems which are validated on the same data set47, 48 . A3.12 As with the ROC measure, testing for the dissimilarity in discriminatory powers between two rating systems can be conducted. A4. Bayesian error rate (“BER”) A4.1 BER, also known as the classification error or minimum error, is the proportion of the whole sample which remains misclassified when the rating system is in the optimal use. A4.2 Denote with pD the default rate of the sample, and hit rate HR(C) and the false alarm rate FAR(C) as in section A3 above. For a concave ROC curve, the BER can be calculated as: BER min pD 1 HRC 1 pD FARC C . A4.3 For a perfect rating model, the BER will have a value of zero. In reality, a model’s BER will depend on pD (the proportion of default in the sample). In particular, for technical reasons it might sometimes be necessary to develop a scoring function on a sample which is not representative in terms of the proportion of defaulters and non-defaulters. The
47 The relevant formulas are not given here, as the methods have been integrated into most of the commonly-used statistical software packages. Therefore, this should not be a constraint for AIs in computing the confidence intervals of a ROC measure or conducting a statistical comparison of the ROC measures of two rating systems based on the same data set. 48 With the linear relationship between AR and ROC measure (see footnote 46), AIs using the former in assessing rating systems’ discriminatory powers can calculate the confidence intervals and conduct statistical tests as with the ROC measure.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 97 assumption on pD and hence the BER will then vary accordingly. In practice, the BER is often applied with a fictitious pD of 50%. Then, the BER can be expressed as: maxHRC FARC 2 1 2 1 BER p 50% C D . In this case, the BER is a linear transformation of the Pietra Index and the Kolmogorov-Smirnov test statistic can be applied accordingly. A5. Conditional entropy, Kullback-Leibler distance, and Conditional Information Entropy Ratio (“CIER”) A5.1 Entropy is a concept from information theory that is related to the extent of uncertainty eliminated by an experiment. In application to validating a rating system’s discriminatory power, entropy measures assess the information gained (or uncertainty reduced) by using the rating system in predicting default of an obligor. A5.2 Let information entropy IE(p) of an event with probability p as: IEp plog p 1 plog 1 p 2 2 . Figure A5 depicts the relationship between IE(p) and p.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 98 Figure A5. Information entropy as a function of probability A5.3 IE(p) takes its maximum at p = 50%, the state with the greatest uncertainty. If p equals zero or one, either the event under consideration itself or its complementary event will occur with certainty. Conditional entropy A5.4 Consider a rating model assigning obligors to a set of k obligor grades (or scores, or pools for retail exposures) K = {K1, K2, … , Kk}, and define ce(Ki) as the conditional entropy that measures the remaining uncertainty conditional on obligor grade Ki, i.e.: ceKi pD|Ki log2 pD|Ki 1 pD|Ki log2 1 pD|Ki , where p(D | Ki) is the probability that an obligor defaults given the rating grade Ki. If there are NDi defaulters and NNDi non-defaulters for obligor grade Ki, p(D | Ki) can be defined as: Di NDi Di i N p D | K . Information entropy, IE(p) Probability, p 0% 10% 20% 30% 40% 50% 60% 70% 80% 90% 100% 0.7 0.6 0.5 0.4 0.3 0.2 0.1 0
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 99 A5.5 Across all obligor grades, the conditional entropy CE(K) is defined as the average of ce(Ki) weighted by the observed frequencies of obligors across the rating grades, i.e.: k i 1 Di NDi k i 1 Di NDi i N ce K CE K . CE(K) corresponds to the remaining uncertainty with regard to the future default event after application of the rating model. Kullback-Leibler distance A5.6 To derive the amount of information gained (or the uncertainty reduced), CE(K) needs to be compared with the entropy where the rating model is not used. In particular, using the entropy CE(p) defined above with the assumption of p as the default rate of the sample (pD), the KullbackLeibler distance can be calculated as: Kullback - Leibler distance CEp CEK D , where k i 1 Di NDi k i 1 Di D N p . A5.7 The Kullback-Leibler distance is bounded between zero and CE(pD). The longer the distance, the more is the information gained, and the better is a rating model in differentiating risk. CIER A5.8 The range of values that the Kullback-Leibler distance can take depends on the unconditional probability of default. In order to arrive at a common scale for any underlying population, the Kullback-Leibler distance can be normalized to produce CIER: D D CE p CE p CE K CIER .
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 100 A5.9 CIER will be closer to one when more information on the future default event is contained in the obligor grades K (i.e. the rating model is better). A random model will have CIER equal to zero. A6. Information value (“IV”) A6.1 IV is another entropy-based measure of discriminatory power. It measures the difference between the distribution of defaulters and that of non-defaulters across obligor grades (or scores, or pools for retail exposures). In this sense, it is similar to the Pietra Index. A6.2 Consider a rating model assigning obligors to a set of k obligor grades K = {K1, K2, … , Kk}. For obligor grade Ki, assume that there are NDi defaulters and NNDi non-defaulters. The distributions (observed frequencies) of defaulters and non-defaulters across the obligor grades are d = {d1, d2, … , dk} and nd = {nd1, nd2, … , ndk} respectively, where: k i 1 Di Di i N N d , and k i 1 NDi NDi i N N nd . A6.3 The IV is defined as the sum of: (1) the relative entropy of the non-defaulters’ distribution with respect to the defaulters’ distribution; and (2) the relative entropy of the defaulters’ distribution with respect to the non-defaulters’ distribution; i.e.: k i 1 i 2 i 2 nd log d nd IV nd log . A6.4 IV takes the value of zero for a random rating model (i.e. the distributions of defaulters and non-defaulters are the same). The higher the IV, the more is the separation of the distributions (see figure A3), and the better is the discriminatory power of a rating model. However, there is no theoretical upper bound to its range.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 101 A7. Kendall’s and Somers’ D A7.1 A shadow rating system is one that generates ratings (the shadow ratings) that are intended to duplicate external ratings (e.g. of a rating agency), but can be applied to obligors for which the external rating is not available. On obligors for which both the shadow ratings and external ratings are available, the degree of concordance of the two rating systems can be measured with two rank-order statistics, Kendall’s and Somers’ D. The shadow rating system will inherit the discriminatory power of the external rating system if: (1) there is high concordance of the shadow ratings and the external ratings; and (2) the portfolio under consideration and the rating agency’s portfolio are structurally similar. A7.2 For both statistics, tests can be performed and confidence intervals can be calculated49. Statistical inferences can be made on the quality of a shadow rating system or the relative performance of shadow ratings with respect to the reference ratings50 . A8. Brier score (“BS”) A8.1 BS is defined as: N j 1 2 j PDj N 1 BS , where N is the number of rated obligors, PDj is the forecast default probability of obligor j, and j is defined as one if the obligor defaults and zero otherwise. A8.2 BS is always between zero and one. The closer BS is to zero, the better is the discriminatory power of a rating model.
49 As with the Mann-Whitney test statistic for the ROC measure and Kolmogorov-Smirnov test statistic for the Pietra Index, the relevant formulas for Kendall’s and Somers’ D are not given here. This is because the methods have been integrated into the commonly-used statistical software packages. 50 Rank-ordering statistics like Kendall’s and Somers’ D can also be used in benchmarking, for comparing the concordance of rank-ordering of an internal rating system with that of an external rating system.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 102 A8.3 The value of BS depends on the default frequency of the overall sample (pD, with the same definition as in paragraph A5.6 above). Therefore, the BS of a rating model can be measured against the BS of a “trivial forecast” of which pD is assigned to all obligors. In particular, the BS of the trivial forecast ( BS ) is given by: BS 1 pD pD . A9. Divergence A9.1 Divergence is defined as: 2 D 2 2 ND 1 2 ND D Divergence , where ND (and D ) and 2 ND (and 2 D ) are respectively the mean and variance of an attribute, such as the credit scores, of non-defaulters (and defaulters). A9.2 The higher the value of divergence, the better is the power of the attribute to discriminate defaulters from non-defaulters. The divergence has a lower bound value of zero but there is no theoretical upper bound to its range.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 103 Annex B: Statistical methodologies in validating calibration51 B1. Binomial test with assumption of independent default events B1.1 Consider a rating model assigning obligors to a set of k obligor grades (or pools for retail exposures) K = {K1, K2, … , Kk}. For obligor grade Ki, assume that there are NDi defaulters and NNDi non-defaulters. For each obligor grade (or pool for retail exposures, but not score), the binomial test with assumption of zero default correlation can be conducted based on the following hypotheses: Null hypothesis (H0): The PD of an obligor grade is correct. Alternative hypothesis (H1): The PD of an obligor grade is underestimated. B1.2 Given a confidence level q (e.g. 99%), the null hypothesis is rejected if the number of observed defaults NDi in obligor grade Ki is greater than a critical value NDi* , which is defined as: NDi i i 0 N i Di * Di PD 1 PD q i N N min N | , where PDi is the forecast of default probability for the obligor grade and Ni is the number of obligors assigned to the obligor grade (i.e. NDi + NNDi). The critical value NDi* can be approximated by: i
that is allowed at maximum:
51 The procedures in generating the data set for validating discriminatory power and for validating calibration are similar. But the data set used in the latter must be out-of-time (i.e. with cut-off dates later than those for calibration) and include all relevant obligors in the AI’s actual portfolio.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 104 i
, it can be concluded with a confidence level q that the PD is underestimated. B2. Binomial test with assumption of non-zero default correlation B2.1 In reality, defaults are correlated. Even if the correlation is small, the true Type I error (i.e. the probability of rejecting erroneously the null hypothesis of a correct PD forecast) can be much larger than the normal level. To circumvent this problem, the calculations of critical values NDi* and PDi
Di , and 1 q PD PD i 1 1 * i . B2.2 The interpretations of NDi* () and PDi * () are the same as those of NDi* and PDi * in section B1 above, except the assumption on correlation. B2.3 AIs have latitude in selecting the assumption of for different asset classes and different obligor grades (or pools for retail exposures). But the value should not be higher than that stipulated in the risk-weight functions used in the calculation of regulatory capital requirements under the IRB approach as specified in the BCR. B2.4 For example, for residential mortgages, the assumption in cannot be higher than 0.15 for all rating grades (or pools) and 0.04 for qualifying
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 105 revolving retail exposures (“QRRE”). For other retail exposures and small business retail exposures, the upper bound of depends on the PD forecast (i.e. PDi ) of a particular obligor grade (pool): 35 35 PD 35 35 PD 1 e 1 e 0.16 1 1 e 1 e Max 0.03 i i . B3. Chi-square test B3.1 In general, the Binomial test is applied to one obligor grade (or pool for retail exposures) at a time. To simultaneously test the PD forecasts of several obligor grades, AIs can apply the Chi-square (or HosmerLemeshow) test. B3.2 Let PD1 , PD2 , … , PDm denote the forecasts of default probabilities of obligor grades K1, K2, … , Km (m can be smaller than or equal to k as defined in paragraph B1.1 above). Define the statistic: m i 1 i 2 Di m N PD 1 - PD N PD N T , with Ni and NDi having the same definitions as in section B1 above. B3.3 The statistic Tm has a chi-square distribution with m-2 degrees of freedom. Therefore, the p -value of the Chi-square test with m-2 degrees of freedom could serve as a measure of the accuracy of the forecasts of default probabilities: the closer the p-value is to zero, the worse are the forecasts.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 106 Annex C: Possible risk factors in estimation of EAD C1. Type of obligor C1.1 The differentiation of obligor types is relevant with regard to varying behaviour in credit line utilization. For example, for large-scale obligors (such as large corporates and banks), lines of credit are often not completely utilized at the time of default. In contrast, retail customers and SMEs are more likely to overdraw (or fully utilize) the approved lines of credit. C2. Relationship between an AI and obligor in adverse circumstances C2.1 EAD often depends on how the relationship between an AI and obligor evolves in adverse circumstances, when the obligor may decide to draw unused commitments. C3. Alternative sources of funds available to the obligor C3.1 The more the obligor has access to alternative sources and forms of credit, the lower the EAD is expected to be. For example, retail customers and SMEs in general have less access to alternative sources than large corporate obligors and banks. In cases where this factor cannot be observed, AIs may apply the “type of obligor” factor as a proxy for it. C4. Covenants C4.1 Some empirical findings indicate that the draw-down of a credit line at the time of default tends to decrease with the quality of the obligor’s credit rating at the time the commitment was granted. This observation may be due to the fact that a bank is more likely to require covenants for obligors with lower credit quality which restrict future draw-downs in cases where the credit quality has declined.
Supervisory Policy Manual CA-G-4 Validating Risk Rating Systems under the IRB Approach V.3 – 18.07.25 107 C5. Restructuring C5.1 If an obligor experiences payment difficulties or is in default, credit restructuring may result in stricter covenants and make the obligor less likely to use the unused portion of a commitment. C6. Time to maturity C6.1 The longer the time to maturity, the higher is the probability that the credit quality will decrease, and the obligor has both an increased opportunity and an increased need to draw down the remaining credit line.