Supervisory stress tests run on two published paths, a baseline and a severely adverse scenario, plus add-on shocks for firms with large trading books or major counterparty exposure. None of these are forecasts; they are hypothetical stress inputs for capital and resilience assessment. The immediate task for a risk team is to map every material exposure to the published variables, document every assumption behind that mapping, and validate the models before layering in bank-defined scenarios that reflect its own balance sheet.
TL;DR:
- Supervisory scenarios include a baseline reflecting private-sector forecasts and a severely adverse path designed to reveal vulnerabilities, with 28 macroeconomic variables analyzed over nine quarters.
- Global market shocks and largest-counterparty defaults layer on immediate, first-quarter impacts that compound over time, making layered modeling essential.
- Bank-specific scenarios must be tailored to the institution's unique concentration risks, funding structure, and risk appetite, incorporating multiple severity bands and hypothetical tail events.
- Accurate scenario development depends on recent, reliable data, detailed transmission mechanisms, and thorough validation, with assumptions carefully documented for examiner review.
- Automating and continuously updating scenario libraries using dedicated tools aids in producing audit-ready reports and improves internal risk management and supervisory compliance.
Automate Regulatory Model Risk Governance
Examine models against 32 qualitative criteria and resolve risk Tiers with pre-deployment checklists per OCC 2011-12 guidelines.
Table of Contents
- What Are Supervisory Stress Testing Scenarios for Banks?
- How Do Global Market Shock and Counterparty Default Components Work?
- Bank-Defined Scenarios: Building an Internal Scenario Library
- How Should Banks Design Credible Stress Test Scenarios?
- What Governance and Validation Do Supervisors Expect?
- DFAST and FR Y-14 Reporting: What Needs to Be Submitted?
- Stress Testing for Community and Midsize Banks: What Actually Matters
- How Do Regulatory Updates Change Scenario Development?
- Why Is Scenario Calibration So Difficult to Get Right?
- What Risk Teams Should Actually Do Next
- Turn Scenario Design Into an Audit-Ready Workflow With RiskInMind
- Sources
- FAQ
What Are Supervisory Stress Testing Scenarios for Banks?
Supervisors do not hand banks one number to plan around. They publish two distinct paths, and understanding the difference between them is the first real test of whether a risk team is reading the scenario correctly or just running the numbers through a model.
The baseline scenario tracks the average of private-sector forecasters' projections, essentially a consensus economic outlook with no particular stress built in. The severely adverse scenario is different in kind, not just degree. It is engineered specifically to expose vulnerabilities in capital, credit, and liquidity positions, and supervisors are explicit that it is not a forecast of what they expect to happen. Each scenario set includes 28 variables covering the full macroeconomic and financial landscape a bank might face.
Those variables cluster into a few families that any risk team should recognize immediately:
- Growth and labor measures: real GDP growth, the unemployment rate, and nominal disposable income growth.
- Asset price paths: house price indices, commercial real estate (CRE) price indices, and equity market indices.
- Rate and volatility measures: Treasury yields across the curve, mortgage rates, and a stress-implied volatility figure modeled on the VIX.
- Credit conditions: corporate bond yields and spreads over risk-free benchmarks, which drive loss estimates on commercial portfolios.
Pro Tip: Do not treat the 28 variables as a checklist to acknowledge and move past. Each one feeds a different part of your loss and revenue model, and skipping the interaction between, say, unemployment and CRE prices is where a lot of internal models quietly diverge from what examiners expect to see.
The 2026 severely adverse path illustrates why the distinction matters in practice. The Federal Reserve's finalized scenario depicts a severe global recession marked by sharp asset-price declines across equity and real estate markets, alongside a significant jump in the unemployment rate to a high level, a substantial increase from recent lows. House prices and commercial real estate values fall sharply in tandem, and market volatility spikes well above historical norms.
Timing matters as much as magnitude. Supervisory scenarios run on a multi-year horizon, typically nine quarters, starting from a defined "jump-off" date tied to recent balance sheet data. A bank that jumps off from stale numbers is effectively stress-testing a balance sheet it no longer has. Every quarter in that horizon compounds off the one before it, so an error in quarter one propagates through the entire projection window, distorting capital ratios in ways that are hard to trace back to their source.
The severely adverse case is intentionally punishing to find the balance sheet's real weak points. A scenario that a well-capitalized bank sails through without visible strain may not be sufficiently challenging.
How Do Global Market Shock and Counterparty Default Components Work?
Beyond the baseline and severely adverse macro paths, supervisors layer on special components for institutions with significant trading, market-making, or counterparty exposure. These are not gentler add-ons. They are often where the sharpest capital erosion in the whole exercise happens, because they hit all at once rather than unfolding over quarters.
The global market shock applies a set of hypothetical, instantaneous shocks to a broad range of market-risk factors, equity prices, interest rates, credit spreads, commodity prices, and foreign exchange rates among them. Unlike the gradual macro deterioration in the severely adverse path, this component assumes the shock hits trading books immediately. The Federal Reserve's 2026 scenario documentation specifies that losses from the global market shock are recognized in the first quarter of the projection horizon and then carried through every subsequent quarter of the nine-quarter window.
That carry-through mechanic trips up more modeling teams than it should. A trading-book loss booked entirely in quarter one does not just dent that quarter's capital. It sets a lower starting point for every quarter that follows, compounding against ongoing credit losses from the macro scenario. Treating the two shock types as separable but additive, rather than blending them into one smoothed trajectory, is the difference between a defensible capital projection and one an examiner flags on first read.
A second special component, the largest-counterparty-default scenario, applies specifically to firms with substantial derivatives, securities financing, or trading counterparty exposure. It assumes the sudden, unexpected default of the firm's single largest counterparty across all lines of business, with certain exposures and hedges typically excluded from the assumed default depending on netting and collateral arrangements.
Both components apply to a defined subset of institutions:
- Large banks with significant trading activity generally face the global market shock.
- The largest-counterparty-default component applies to a narrower set of firms with substantial derivatives and securities financing exposure.
- Most community and midsize banks fall outside both components' scope, though their internal scenario libraries should still consider concentrated counterparty risk qualitatively.
For institutions in scope, the practical lesson is this: model the market shock and the counterparty default as instantaneous, first-quarter events layered onto the gradual macro path, never as smoothed contributors to an average quarterly loss rate. Blending the two loses exactly the information supervisors designed the test to surface.
Bank-Defined Scenarios: Building an Internal Scenario Library
Supervisory scenarios are a floor, not a ceiling. A bank that only ever tests against the Fed's published paths is answering a question regulators asked, not the question its own balance sheet actually poses. That is where bank-defined scenarios, sometimes broken into a bank baseline and a bankstress case, come in.
The bank baseline mirrors the bank's own strategic plan and budget assumptions under normal conditions. The bankstress scenario is where the real work happens: a severity level, transmission path, and time horizon calibrated to the institution's specific concentrations, funding structure, and risk appetite, rather than borrowed wholesale from a supervisory template built for the largest banks in the country.
Interagency guidance is direct on this point: scenarios must be tailored to a bank's size, complexity, and risk profile, and should include a range of severities, some instantaneous shocks, and some prolonged stress periods rather than a single flavor of downturn.
A practical taxonomy for an internal scenario library typically covers seven categories:
- Macro recession scenarios that stress credit losses across commercial, consumer, and real estate portfolios over multiple quarters.
- Instantaneous market shock scenarios for banks with any trading or investment portfolio sensitivity, even modest ones.
- Deposit runoff and liquidity scenarios that test funding stability under both idiosyncratic and market-wide stress.
- Interest rate risk scenarios covering parallel and non-parallel shifts, measured through both net interest income (NII) and economic value of equity (EVE).
- Concentration scenarios targeting the bank's largest sector, geographic, or single-name exposures specifically.
- Operational and cyber scenarios, increasingly a supervisory expectation given the frequency of incidents flagged in FDIC risk reviews.
- Climate and physical risk scenarios, particularly for institutions with geographic concentration in exposure to flood, wildfire, or storm risk.
Each scenario needs to map cleanly to specific on-balance-sheet and off-balance-sheet exposures. A deposit-runoff scenario that ignores unfunded commitments understates the true liquidity draw; a CRE concentration scenario that does not tie back to specific loan vintages and geographies produces a number without a story behind it.
Severity bands should scale with the exposure being tested. A moderate band might reflect a one-in-ten-year event calibrated against the bank's own historical data; a severe band should approach or exceed the supervisory severely adverse case for the same risk factor. Escalation to an extreme tail scenario, one that stretches plausibility deliberately, belongs in the library too, reserved for testing whether the bank's risk appetite framework and capital triggers actually function when pushed past the design range of its everyday models. This kind of stress work builds directly on the portfolio-level stress testing practices that support both capital planning and supervisory engagement.
How Should Banks Design Credible Stress Test Scenarios?
A scenario is only as credible as the data point it starts from. Picking the jump-off value, the balance sheet and market data snapshot the projection launches from, is the first decision that determines whether everything downstream holds up under examiner scrutiny.
Jump-off values should reflect the most recent reliable data available, not a convenient quarter-end that happened to look favorable. Incorporating the latest loan performance, deposit composition, and market pricing data before the scenario horizon begins avoids the common failure mode of running a sophisticated stress model against an outdated starting balance sheet.
From there, the scenario needs a transmission mechanism, the causal chain connecting an initial shock to its eventual balance sheet impact. A typical chain runs from asset price declines, to funding cost increases, to credit rating downgrades, to liquidity pressure, and finally to capital erosion. Skipping a link in that chain, modeling asset declines without tracing through to funding costs, for instance, produces a capital number that looks clean but ignores a real channel of loss.
Plausibility testing catches the errors that pure model output cannot:
- Joint-variable consistency checks confirm that correlated variables move together; unemployment spiking while house prices hold flat, absent a specific narrative reason, signals a modeling error rather than a scenario feature.
- Historical analog comparisons benchmark the scenario's severity against past downturns, the 2008 financial crisis or the 2020 pandemic shock, to confirm the magnitude is defensible rather than arbitrary.
- Narrative coherence review asks a simple question: could a knowledgeable economist tell a believable story connecting the scenario's starting shock to its ending numbers? If not, the variables need rework.
Pro Tip: Document your haircuts, deposit betas, and recovery rate assumptions the moment you set them, not months later when an examiner asks where a number came from. An unexplained assumption is treated as a governance gap even when the final output looks entirely reasonable.
Every assumption behind a scenario, collateral haircuts, deposit beta and runoff rates, recovery rates on defaulted exposures, needs to carry a documented range of uncertainty, not a single point estimate presented as fact. That range itself becomes part of the model's audit trail, and it is frequently the first thing an examiner or independent validator asks to see.
What Governance and Validation Do Supervisors Expect?
Scenario outputs are model estimates, not observed facts, and supervisors evaluate the governance around those models almost as closely as the numbers themselves. The Federal Reserve's supervisory methodology materials are explicit that independent validation and senior oversight matter precisely because scenario results carry inherent model uncertainty that a single point estimate obscures.
A sound governance structure for scenario-based stress testing rests on a handful of core elements:
- Clear role separation between model developers, users, and independent validators, so no single team both builds a model and signs off on its output.
- A maintained model inventory documenting every scenario model's purpose, key assumptions, and known limitations in one place, not scattered across spreadsheets and memos.
- Version control on every model change, with a record of what changed, why, and who approved it.
- Independent validation covering conceptual soundness, implementation accuracy, and ongoing outcomes analysis, aligned with the model-risk expectations laid out in SR 11-7 style guidance.
- Senior management and board-level sign-off on final scenario results before submission, with documented evidence that leadership understood and challenged the assumptions.
Examiners consistently flag the same gaps across institutions of very different sizes. Unexplained haircuts on asset values, default curves with no documented derivation, and deposit-decay assumptions pulled from a prior cycle without revalidation all surface repeatedly in OCC reporting reviews, even when the resulting capital ratio looks entirely plausible on its face. A plausible number built on an undocumented assumption is still a governance failure.
Validation of scenario-driven outputs differs from validating a static credit model. Reviewers need to confirm the model behaves sensibly across the full range of scenario severity, not just at the base case, and that its sensitivity to key variables matches economic intuition. A model that shows credit losses barely moving between the baseline and severely adverse case is a red flag regardless of how well it performed historical backtesting.
Before any submission goes out the door, senior management sign-off should confirm four things: that assumptions are documented with sources, that independent validation findings have been addressed or formally accepted as residual risk, that the model inventory reflects the current version in use, and that results have been reviewed against the prior cycle for unexplained swings. A framework like the step-by-step risk assessment approach many institutions already use for broader risk governance extends naturally to this sign-off process.
DFAST and FR Y-14 Reporting: What Needs to Be Submitted?
Translating a well-built scenario into a compliant submission is its own discipline, separate from the modeling work itself. The Dodd-Frank Act stress testing (DFAST) framework and its associated FR Y-14 reporting schedules define exactly what needs to reach supervisors, and the OCC's reporting instructions lay out the schedules in detail, though specific thresholds and requirements vary by institution size and charter type.
The core schedules cluster around a few reporting families: projected income statements, balance sheet composition, trading and counterparty credit risk (CCR) exposures for firms in scope of the market shock components, pre-provision net revenue (PPNR) projections, operational risk loss estimates, and CECL-related allowance projections that connect stress outputs to current expected credit loss modeling.
A pre-submission process that catches problems before they reach an examiner's desk generally runs through five checkpoints:
- Reconcile source data against the general ledger and loan-level systems to confirm the jump-off balance sheet matches what the institution actually reported for the same period.
- Confirm file format compliance against the current DFAST-14A specification, since even a correctly calculated figure in the wrong field triggers a resubmission request.
- Complete qualitative documentation for every material assumption, matching the standard OCC examiners look for on internal projections.
- Secure validation sign-off from independent model risk staff before the package moves to senior management.
- Run a peer or secondary review of the full package, specifically checking for internal consistency between schedules that should tie to the same underlying numbers.
The most common errors triggering resubmission are mundane rather than exotic: schedule totals that do not reconcile to each other, missing qualitative support for a line item that swung materially from the prior cycle, and as-of dates on supporting data that do not match the scenario's stated jump-off date. None of these require a modeling fix. They require someone checking the package against itself before it goes out. Institutions building out their CECL data infrastructure often find the same reconciliation discipline pays off directly in stress test submission quality, since both processes draw on the same underlying loan and allowance data.
Stress Testing for Community and Midsize Banks: What Actually Matters
Community and midsize banks rarely face the global market shock or counterparty default components, but that does not make their stress testing simpler. It makes it different, concentrated in a smaller number of risk drivers that carry outsized weight.
A scenario pairing that surfaces real vulnerability for most community banks combines the severely adverse macro path with a deposit-runoff scenario and a parallel interest rate shock run simultaneously, rather than as three separate exercises. Deposit outflows under stress rarely happen in isolation from rate moves. Testing them together, with credit losses from the macro scenario layered on top, produces a far more honest picture of combined capital and liquidity strain than three siloed tests ever will.
Two exposures tend to dominate outcomes for this segment more than any macro variable does:
- Non-maturity deposit (NMD) behavior, specifically how quickly deposit betas move and how much runoff occurs, drives NII and EVE outcomes more than most banks' models initially assume. OCC interest rate risk data shows wide variability in parallel-shock outcomes across bank size groups, underscoring why generic deposit assumptions borrowed from peer averages often miss an individual bank's actual behavior.
- Commercial real estate concentration, particularly in construction and land development or in specific geographic submarkets, frequently accounts for a disproportionate share of projected losses relative to portfolio size.
For institutions without a large quantitative modeling staff, a few conservative shortcuts hold up reasonably well under examiner review: apply deposit betas at the higher end of the plausible range rather than the average observed in recent low-rate years, assume slower recovery timelines on CRE collateral values than historical averages suggest, and read NII and EVE results together rather than in isolation, since a scenario that looks fine on one measure can conceal serious strain on the other. Institutions further along in adopting CECL methodologies often find their allowance data doubles usefully as a starting point for these stress calibrations, since both draw on the same loss-history inputs.
How Do Regulatory Updates Change Scenario Development?
Scenario design is not static, and treating last cycle's variables and severity levels as permanently correct is one of the more common oversights in bank-defined stress testing. Supervisors revise the published scenario set annually, adjusting variable definitions, severity calibrations, and occasionally adding new special components as market structure and risk concentrations evolve.
The 2026 cycle's severely adverse scenario reflects updated views on global recession dynamics and asset-price correlation that differ meaningfully from earlier cycles. A bank that simply rolls forward its prior year's bank-defined scenarios without checking them against the current supervisory publication risks testing against an outdated notion of what "severe" looks like.
Interagency guidance also evolves in response to emerging risk categories. Climate-related financial risk and cyber threat scenarios have moved from optional additions to expected components of a comprehensive scenario taxonomy over the past several cycles, a shift that shows up directly in what examiners now ask to see documented. Institutions that update their internal scenario libraries only when forced to by an exam finding are perpetually a step behind institutions that track supervisory publications proactively and adjust each cycle.
The practical response is a standing annual process: review the newly published supervisory scenarios against the prior year's variables and severity levels, assess whether the bank's own taxonomy needs new categories or revised severity bands, and document the rationale for any changes made or not made. That documentation becomes valuable evidence of an active, responsive risk management process rather than a compliance exercise repeated on autopilot.
Why Is Scenario Calibration So Difficult to Get Right?
Calibrating a bank-defined scenario to the right severity is harder than it looks, and the difficulty rarely comes from a lack of modeling sophistication. It comes from data.
Most community and midsize banks lack a long internal loss history covering a genuine severe downturn, which means calibrating severity requires borrowing from external benchmarks, peer data, or supervisory scenarios never designed with that specific institution's portfolio mix in mind. A bank with a concentrated agricultural or energy-sector loan book, for instance, cannot fully validate its severity assumptions against a national supervisory scenario built around a generalized economic downturn.
Correlation assumptions between variables present a similar problem. Historical data showing how, say, local CRE prices moved during the last severe recession may be thin, outdated, or drawn from a market that has since changed structurally. Assuming today's correlations mirror 2008's or 2020's is a convenience, not a certainty, and every scenario built on that assumption inherits its uncertainty.
Deposit behavior is arguably the hardest variable of all to calibrate confidently. Betas and runoff rates observed during a decade of historically low interest rates provide limited insight into how depositors actually behave during a genuine liquidity event, since so few recent cycles have tested that behavior under real stress. Peer benchmarking against institutions with comparable deposit franchises, drawing on industry-wide benchmarking data, offers a partial substitute, but it is still an estimate standing in for a data point the bank does not have.

The honest response to these limitations is not paralysis. It is documented conservatism: when the data does not support precision, choose the more severe assumption and record why.
What Risk Teams Should Actually Do Next
The workflow that holds up across every scenario type discussed here is the same four steps in the same order: map exposures to the published supervisory variables first, design bank-specific scenarios that reflect what the supervisory set leaves out, validate the resulting models independently, and only then report. Skipping ahead to reporting without the mapping and validation steps is exactly how a technically compliant submission ends up full of examiner findings anyway.
What gets underweighted in most conversations about stress testing is how much of the credibility problem is a documentation problem, not a modeling problem. A defensible haircut poorly documented looks worse to an examiner than a slightly conservative one clearly explained. Platforms built specifically for financial institutions include CECL modeling and regulatory reporting tools designed to close that documentation gap systematically rather than leaving it to whoever happens to write the memo that cycle.
If there is one habit worth building into next cycle's process, it is the annual scenario review discussed above. Institutions that treat their bank-defined scenario library as a living document, revisited every cycle against the newest supervisory publication, consistently produce cleaner submissions than those that update only when an exam forces the issue. Start there. A pilot review of one scenario category, or a tabletop exercise walking through last cycle's submission against this cycle's published variables, is a reasonable place to begin.
— Raj
Turn Scenario Design Into an Audit-Ready Workflow With RiskInMind
Everything covered above, mapping exposures to 28 supervisory variables, layering in market shock components, documenting deposit betas and recovery rates, only pays off if the output survives an examiner's second look. RiskInMind is built around exactly that gap: an AI-powered platform where scenario libraries, CECL modeling, and regulatory reporting run on the same underlying data instead of three disconnected spreadsheets that never quite reconcile.

CECL Modeling and Regulatory Agent tools can generate audit-ready documentation as a byproduct of the modeling work itself, not a separate task someone has to remember to do before submission. For portfolio managers and lending directors specifically, the AI solutions built for that role connect scenario outputs directly to the concentration and IRR data that most often drives community bank capital strain. Some platforms operate as in-house automation layers with bank-grade security controls, so scenario data never has to leave an institution's control to get the analysis done.
If your current process still relies on scattered assumptions and manual reconciliation before each DFAST cycle, request a look at current pricing and plan options or explore the full product lineup to see where a pilot fits your reporting calendar.
Sources
FAQ
What are the Fed's scenarios for the 2026 stress test?
The Federal Reserve's 2026 supervisory scenarios include a baseline path following private-sector forecaster consensus and a severely adverse path featuring a severe global recession, sharp asset-price declines, and unemployment rising to about 10 percent. Firms with significant trading activity also apply a global market shock, and certain large firms add a largest-counterparty-default component.
What is a stress test scenario?
A stress test scenario is a hypothetical set of economic and financial conditions, covering variables like GDP, unemployment, and asset prices, used to project how a bank's capital, earnings, and liquidity would hold up under that specific stress path. It is explicitly not a forecast of what regulators expect will happen; it is a tool for finding vulnerabilities before they become real losses.
What is the stress test for banks?
Bank stress testing is a supervisory and internal risk management process that projects capital and financial performance under adverse economic conditions, structured around the Dodd-Frank Act stress testing framework and reported through FR Y-14 and DFAST-14A schedules. Banks combine the supervisory baseline and severely adverse scenarios with their own bank-defined scenarios tailored to specific concentrations and exposures.
Which banks passed the stress test?
Supervisory stress test results are published by the Federal Reserve on a scenario-by-scenario basis, showing each participating firm's projected capital ratios under the severely adverse case relative to required minimums. Results and pass thresholds vary by cycle and by each firm's specific risk profile, so current-cycle outcomes should be checked directly against the Federal Reserve's published results for that year rather than assumed from a prior cycle.
How does RiskInMind support bank-defined scenario design?
RiskInMind's CECL Modeling and Regulatory Agent tools help risk teams document scenario assumptions, connect stress outputs to allowance calculations, and generate the qualitative support examiners expect on internal projections. Current plan details and pricing are available on the RiskInMind pricing page.
