Skip to main content

How to Build a Credible ICAAP Narrative That Withstands Supervisory Scrutiny

This guide explains how to construct an ICAAP document that reads as a genuine articulation of risk, capital adequacy and board ownership rather than a compliance artefact. After reading, you will know what supervisors actually test for, where most narratives fall apart, and how to sequence the work so the story holds together under challenge.

Supervisors do not read an ICAAP looking for errors in arithmetic. They read it to find out whether the board understands its own risks, has set capital at a level that reflects them, and can defend the judgements involved. A credible narrative is one where the numbers, the risk assessment, the stress testing and the board's conclusions all point in the same direction and sound like they came from the same institution.

Key Executive Takeaways

  • A credible ICAAP is a coherent argument linking business model, material risks, stress outcomes and capital conclusions, not a stitched-together set of departmental submissions.
  • Supervisors probe the joints: where Pillar 1 ends and Pillar 2 begins, where stress assumptions were chosen, and where management actions are claimed. These are the places to invest judgement, not boilerplate.
  • The board must be able to speak to the document in its own words. If the narrative cannot survive a thirty-minute conversation with a non-executive director, it will not survive supervisory challenge.

Start with the argument, not the template

Most ICAAPs fail the credibility test because they are assembled bottom-up: risk teams populate their sections, finance plugs in projections, treasury adds the stress overlay, and someone writes an executive summary at the end. The result reads as a catalogue, not an argument.

Start instead with the single question the document must answer: given this business model, these risks, and these plausible stresses, why is this the right amount and quality of capital? Draft a two-page answer first. Everything else in the document should be evidence for that answer. If a section does not support it, cut it or rewrite it.

Get the risk identification right, because everything else depends on it

The weakest point in most ICAAPs is the material risk assessment. Firms list the usual categories, score them on a heat map, and move on. Supervisors notice when the risk inventory does not match what the business actually does, or when risks that have shown up in incident logs, audit findings or board minutes are quietly absent.

Test your inventory against three sources: the last two years of operational loss data, internal audit reports, and the issues the board has actually spent time on. Any divergence between those sources and your material risk list needs explaining, or correcting.

Make Pillar 2A assessments defensible, not conservative-by-default

Adding a buffer because it feels safer is not a methodology. Supervisors will ask how you sized concentration risk, interest rate risk in the banking book, pension risk or operational risk, and they will expect a method, inputs, and a sensitivity view. Where you use a simple approach, say so and justify why it is proportionate. Where you use a model, be ready to explain its limitations as clearly as its outputs.

The worst outcome is a Pillar 2A number that no one in the room can derive from first principles.

Stress testing: choose scenarios that bite

A stress scenario that does not meaningfully threaten the firm is not a stress test. If your severe-but-plausible scenario leaves CET1 comfortably above requirements with no management action, the scenario is too weak or the assumptions too generous. Supervisors increasingly reverse-stress-test the ICAAP: what would it take to breach? If you have not asked that question yourself, they will ask it for you.

Be specific about management actions. "Reduce discretionary spend" is not an action. Quantify the amount, name the owner, state the lead time, and acknowledge the second-order effects.

Build board ownership into the process, not at the end

An ICAAP signed off at the final board meeting without prior engagement is visible to supervisors within minutes. Board challenge should be documented through the drafting cycle: on risk appetite calibration, on scenario severity, on the capital conclusion. Minutes matter. So does the quality of the questions asked.

The test: can a non-executive director explain, in their own words, why the capital number is what it is, and what would change it?

What good looks like

A strong ICAAP is shorter than a weak one. It has a clear argument, a defensible risk inventory, stress scenarios that genuinely threaten the firm, management actions that are specific and credible, and visible board fingerprints throughout. It does not oversell the control environment, and it is honest about limitations.

Next action

Before the next drafting cycle begins, write the two-page argument first and circulate it to the board. If it does not generate real challenge, the document is not yet ready to be built around it.

Frequently Asked Questions

How long should an ICAAP document be?

Short enough that the argument is visible, long enough that the evidence is complete. For most mid-sized firms, the core narrative should be fifty to eighty pages, with technical appendices separate. Length is not a proxy for rigour.

How do we handle risks we cannot easily quantify?

Say so, explain the qualitative basis for your assessment, and describe what would need to change for quantification to become possible. Supervisors are more comfortable with acknowledged uncertainty than with false precision.

What is the single most common weakness supervisors cite?

The disconnect between the risk assessment and the capital conclusion. Firms describe risks in detail and then arrive at a capital number through a parallel process that does not visibly draw on that assessment.

How much should the ICAAP change year to year?

It should change where the business, the risks or the environment have changed. A document that is substantially identical to last year's suggests the process is mechanical. One that is wholly rewritten suggests instability in the firm's view of itself. Neither is reassuring.

Who should own the drafting?

A named senior executive, usually the CFO or CRO, with explicit accountability for the integrity of the narrative. Delegating authorship to a working group without a single owner is a reliable way to produce an incoherent document.

Frequently asked questions

How long should an ICAAP document be?

Short enough that the argument is visible, long enough that the evidence is complete. For most mid-sized firms, the core narrative should be fifty to eighty pages, with technical appendices separate. Length is not a proxy for rigour.

How do we handle risks we cannot easily quantify?

Say so, explain the qualitative basis for your assessment, and describe what would need to change for quantification to become possible. Supervisors are more comfortable with acknowledged uncertainty than with false precision.

What is the single most common weakness supervisors cite?

The disconnect between the risk assessment and the capital conclusion. Firms describe risks in detail and then arrive at a capital number through a parallel process that does not visibly draw on that assessment.

How much should the ICAAP change year to year?

It should change where the business, the risks or the environment have changed. A document that is substantially identical to last year's suggests the process is mechanical. One that is wholly rewritten suggests instability in the firm's view of itself. Neither is reassuring.

Who should own the drafting?

A named senior executive, usually the CFO or CRO, with explicit accountability for the integrity of the narrative. Delegating authorship to a working group without a single owner is a reliable way to produce an incoherent document.

Related guides

Regulation & Regulatory Change

How to Prepare for a Regulator Meeting When Rules Are Open to Interpretation

A practical guide for senior leaders preparing to meet a regulator on matters where the published rules leave genuine room for judgement. Covers how to build a defensible interpretation, sequence the conversation, and demonstrate the quality of your reasoning, not just your conclusion.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

What Regulators Look For in a Submission: A Practical Guide

This guide explains what regulators actually assess when reviewing a formal submission, from authorisation applications to Section 166 responses and thematic returns. After reading it, you will know how to structure a submission that reflects genuine control, sound judgement and credible governance.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Section 166 Skilled Person Review Response

This guide sets out how senior leaders in regulated firms should structure their response to a Section 166 skilled person review, from the moment the requirement notice arrives to the remediation phase. It covers governance, evidence, stakeholder handling, and the judgement calls that determine whether the firm emerges credibly or damaged.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Prepare a Regulatory Filing With Stakeholder Risk Assessment

A practical guide for senior leaders on integrating stakeholder risk assessment into a regulatory filing so it reads as evidence of genuine control, not compliance theatre. After reading, you will know how to sequence the work, what to include, and where filings typically fall short under supervisory review.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Regulation & Regulatory Change

How to Structure a Recovery Plan Playbook That Passes PRA Credibility Tests

This guide sets out how to build a Recovery Plan playbook that meets the PRA's credibility, usability and timeliness expectations without creating documents that could damage confidence if they surface externally. After reading, you will know how to sequence indicators, options and governance triggers so the plan works as a live management tool rather than a compliance artefact.

Regulatory submissionRegulatorsBoards
4 min readRead guide →

Where internal confidence may exceed external evidence

Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.

Explore Stakeholder Proximity