Why traffic-light risk ratings may be running out of time

risk

Every major risk category in banking has its own number, except one. Credit risk relies on probability of default (PD) and loss given default (LGD), market risk uses value at risk (VaR), and liquidity is measured through the liquidity coverage ratio (LCR).

According to Corlytics, non-financial risk (NFR), which drives the largest operational losses and almost every conduct fine, is still assessed using red, amber and green ratings.

This creates a real problem for decision-makers. Risk and control self-assessment (RCSA) processes often produce a single colour, which leaves business heads and risk owners struggling to decide whether to accept, mitigate or avoid a given exposure.

The lack of practical modelling that could deliver even directionally defensible figures also reflects how manual the RCSA process remains. For a global bank, running it typically costs between $10m and $50m a year. Pressure is building too, as regulators, particularly across EMEA, increasingly expect quantifiable methods and outputs.

RegTech firm Corlytics believes it has found a way through. The company has launched its Emerging Risk Quantification (ERQ) engine, which brings together four capabilities developed independently over the past decade.

These include structured, machine-readable regulatory obligations under continuous curation; codified policy content mapped granularly to those obligations; controls linked to policies and back to obligations, making completeness objective and testable; and 12 years of global enforcement data captured at event level, with 150 data points per event.

Each of these tools was originally built to solve a separate problem. Combined, they form the inputs to a model. Obligations define the risk surface, controls define mitigation, enforcement defines severity and horizon scanning shows the direction of travel. According to Corlytics, the missing piece was AI that offers both precision and traceability, since a figure that cannot be traced cannot be attested to.

To test the concept, Corlytics partnered with a global bank, and promising early results turned the project into a co-build. The trial also suggests that between 50% and 70% of the RCSA process could be automated. Rather than replacing subject-matter experts, this shifts their role away from filling in spreadsheets and towards challenging an explainable, modelled output.

The result is an RCSA that delivers an expected annual loss and a 95th-percentile tail figure in dollars, with visible drivers, versioned assumptions and the probability and severity of enforcement. The bank then applies its own judgement and control effectiveness to determine residual risk, with clear sight of which controls are lacking and why.

Corlytics points to its unified data model, integrated platform, proprietary enforcement evidence and peer weighting as key differentiators. Looking ahead, the firm sees a networked future. No single bank holds enough internal loss events to credibly calibrate tail risk, but peer-weighted industry data would allow each institution to benchmark against a wider population rather than its own limited history.

Read the full Corlytics post here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.