Skip to main content

How to Structure a Reverse Stress Testing Narrative for PRA Board Attestation

This guide sets out how to build a Reverse Stress Testing (RST) narrative that credibly supports board attestation under PRA expectations. After reading, you will know how to sequence the analysis, frame the point of non-viability, and present findings in a way that survives supervisory challenge.

Reverse Stress Testing is where the PRA finds out whether your board actually understands how the firm fails. Most RST submissions read like ICAAP appendices: mechanical, capital-centric, and reverse-engineered to reassure. That is precisely what supervisors are trained to spot. A credible RST narrative starts from business model failure, not from a capital number, and it forces the board to confront scenarios management would rather not name.

Key Executive Takeaways

  • The PRA judges RST on whether the board has genuinely engaged with the point of non-viability, not on the sophistication of the modelling.
  • The narrative must define failure in business model terms first, then translate into capital, liquidity and franchise consequences, not the other way round.
  • Board attestation is credible only when the paper trail shows challenge, iteration, and explicit linkage to risk appetite and recovery triggers.

Start with a defensible definition of failure

The single most common weakness is a vague or self-serving definition of non-viability. "Breach of minimum capital requirements" is not sufficient. The PRA expects a definition that captures the point at which the business model ceases to be viable, which typically occurs before regulatory minima are breached: loss of wholesale funding access, withdrawal of a critical counterparty, mass client attrition, or franchise damage that makes recapitalisation impossible.

Write the definition in one paragraph. Have the board debate it. Minute the debate. That minute is the foundation of attestation.

Work backwards, but show the work

RST is reverse by design, but the narrative should not read as if the answer was known first. Present the scenario development as a structured search: what combinations of macro, idiosyncratic and operational shocks could plausibly reach the failure point? Show the scenarios you considered and rejected, and why. Supervisors read RST submissions comparatively; a paper that only presents the surviving scenario looks curated.

Aim for two or three scenarios that reach non-viability through genuinely different mechanisms. A credit shock, a conduct-driven franchise event, and an operational or cyber scenario is a defensible spread for most firms. Monoline firms need sharper differentiation within their core exposure.

Make plausibility the central argument

The PRA's frequent challenge is that RST scenarios are too severe to be useful or too mild to be honest. Address plausibility explicitly. For each scenario, state the assumed probability range, the historical or hypothetical analogues, and the assumptions that most affect severity. If a scenario requires simultaneous tail events, say so, and justify the correlation assumption.

What good looks like: a plausibility section that a supervisor could challenge line by line and that management could defend without retreat.

Connect RST to the risk framework, visibly

RST that sits in isolation is a red flag. The narrative should show, with specific cross-references, how RST outputs have shaped: risk appetite thresholds, early warning indicators, recovery plan triggers, and ICAAP or ILAAP scenario selection. If the RST identifies a vulnerability that does not appear in the recovery plan menu, explain why. If a recovery option is assumed to work in the RST, it must be credible under the same conditions.

This is where most firms lose credibility. The RST says the firm fails through funding withdrawal; the recovery plan assumes access to the same funding markets. Supervisors notice.

Structure the board's engagement, don't perform it

Attestation requires evidence of substantive board engagement, not a single sign-off meeting. The pack should show: an early scenario-setting discussion, a challenge session on plausibility and severity, and a final review of management actions and mitigants. Non-executive challenge should be minuted with specificity. "The Board discussed and approved" is worthless; "The Board challenged the assumed 40% deposit outflow as insufficient given 2023 experience and requested sensitivity at 55%" is attestable.

What most firms get wrong

Three recurring errors: treating RST as a capital exercise rather than a viability exercise; using scenarios that are severe but implausible, which lets management dismiss the findings; and failing to identify management actions that would actually be taken, as opposed to those that sound reassuring.

The next decision

Before your next RST cycle begins, decide who owns the definition of non-viability. If it is the CRO alone, the exercise will drift toward capital. If it is the CEO with board sponsorship, it will address business model risk. That single sequencing choice determines whether attestation is credible or ceremonial.

Frequently Asked Questions

How many scenarios should an RST include?

Two to four is typical. Fewer than two suggests insufficient search; more than four often signals a lack of prioritisation. Each scenario should reach non-viability through a distinct causal chain.

Should RST assume management actions succeed?

No. RST identifies the point at which management actions and recovery options are exhausted or ineffective. Assuming successful mitigation defeats the purpose. Test recovery actions separately and show why they are insufficient in the RST scenario.

How does RST differ from severe-but-plausible stress testing?

Severe-but-plausible tests ask whether the firm survives a defined shock. RST asks what shock would cause the firm to fail. The direction of inference is opposite, and so is the analytical starting point.

What triggers a PRA challenge on RST?

Common triggers include: a non-viability point defined solely by capital ratios, scenarios that mirror the ICAAP severe case, absence of operational or conduct-driven scenarios, and recovery plan assumptions inconsistent with RST conditions.

How often should RST be refreshed?

Annually at minimum, with interim refreshes when the business model, risk profile or external environment shifts materially. A static RST across multiple cycles is itself a supervisory concern.

Frequently asked questions

How many scenarios should an RST include?

Two to four is typical. Fewer than two suggests insufficient search; more than four often signals a lack of prioritisation. Each scenario should reach non-viability through a distinct causal chain.

Should RST assume management actions succeed?

No. RST identifies the point at which management actions and recovery options are exhausted or ineffective. Assuming successful mitigation defeats the purpose. Test recovery actions separately and show why they are insufficient in the RST scenario.

How does RST differ from severe-but-plausible stress testing?

Severe-but-plausible tests ask whether the firm survives a defined shock. RST asks what shock would cause the firm to fail. The direction of inference is opposite, and so is the analytical starting point.

What triggers a PRA challenge on RST?

Common triggers include: a non-viability point defined solely by capital ratios, scenarios that mirror the ICAAP severe case, absence of operational or conduct-driven scenarios, and recovery plan assumptions inconsistent with RST conditions.

How often should RST be refreshed?

Annually at minimum, with interim refreshes when the business model, risk profile or external environment shifts materially. A static RST across multiple cycles is itself a supervisory concern.

Related guides

Boards, Governance & Defensibility

Positioning a Consumer Duty Review for Board and Regulator Audiences

This guide sets out how to structure a Consumer Duty implementation review so it works for both your board and the FCA without compromising either audience. You will finish with a clear approach to framing, evidence, and sequencing that avoids the common trap of producing two conflicting narratives.

Regulatory submissionBoardsRegulators
3 min readRead guide →
Regulation & Regulatory Change

How to Structure a Threshold Conditions Self-Assessment That Pre-empts FCA Withdrawal Risk

This guide sets out how boards and senior managers should structure a Threshold Conditions self-assessment that identifies authorisation withdrawal risk before the FCA does. After reading, you will know how to sequence the assessment, where the real judgement calls sit, and what evidence a supervisor expects to see.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

How to Structure a Consumer Duty Board Report That Withstands FCA Scrutiny

This guide sets out how to build a Consumer Duty board report that demonstrates genuine oversight rather than compliance theatre. After reading, you will know what evidence to include, how to structure judgements, and where FCA scrutiny is most likely to bite.

Regulatory submissionBoardsRegulators
4 min readRead guide →
Regulation & Regulatory Change

Stakeholder Risk Management for FCA Regulated Firms: A Practical Guide

This guide sets out how senior leaders at FCA regulated firms should identify, assess, and manage stakeholder risk in a way that stands up to supervisory scrutiny. After reading it, you will know how to structure a stakeholder risk framework that aligns with Consumer Duty, SM&CR, and Threshold Conditions, and where firms typically fail.

Regulatory submissionRegulatorsBoards
4 min readRead guide →
Boards, Governance & Defensibility

What Makes a Decision Defensible to Regulators: A Practical Guide

This guide explains what regulators actually look for when they test a major decision after the fact, and how to build defensibility into the decision itself rather than reconstruct it later. You will finish with a clear view of what to document, who to involve, and where most firms leave themselves exposed.

Regulatory submissionRegulatorsBoards
4 min readRead guide →

Where internal consensus may be mistaken for validation

Polar Insight's Decision Rooms bring outside challenge to a live decision, so blind spots and untested assumptions surface before commitment, not after.

Explore Decision Rooms