Structuring a Reverse Stress Testing Narrative for the PRA
This guide explains how to build a Reverse Stress Testing (RST) narrative that credibly identifies business model vulnerabilities without inviting Pillar 2A or Pillar 2B add-ons. It covers the framing choices, sequencing, and evidentiary anchors that separate a supervisor-credible RST from one that either underwhelms or overexposes.
Reverse Stress Testing is the one supervisory exercise where being too honest and being too polished are both punished. The PRA expects firms to identify the point at which the business model becomes unviable, and to show they understand it. But an RST that reads as a confession of fragility invites a capital overlay, and one that reads as reassurance invites disbelief. The craft lies in the middle: a narrative that demonstrates severe self-awareness while showing that management actions, governance, and existing buffers already address the vulnerabilities identified.
Key Executive Takeaways
- The PRA rewards firms that identify non-obvious, model-specific failure points, not generic macro scenarios, but the identified vulnerabilities must be paired with credible, pre-existing mitigants to avoid triggering a Pillar 2 response.
- Separate the point of non-viability analysis from the capital adequacy narrative. Conflating the two is what most often produces add-ons.
- The document should be structured to be read by a supervisor in fifteen minutes and defended in a two-hour meeting. Both audiences matter.
Frame the exercise as strategic diagnostic, not capital calibration
The first judgement call is positioning. RST under SS31/15 and the wider ICAAP framework is a business model viability test, not a capital sizing tool. Firms that write it as though it were a Pillar 2B stress produce numbers that supervisors then anchor to. Once a specific capital shortfall figure appears in an RST narrative, it becomes very hard to argue it should not inform the PRA buffer.
Write the RST as a strategic diagnostic: what combination of conditions would render the current business model unviable, and what does that tell us about concentration, dependency, and optionality. Capital consumption is an output of the scenario, not its purpose.
Choose vulnerabilities that are real but already governed
The most common mistake is selecting a scenario the firm has not thought about before. Supervisors read this as evidence the risk framework missed something. The second most common mistake is selecting a scenario so remote it looks like theatre.
Good practice: identify two or three genuine vulnerabilities the board has already discussed, ideally with minutes to prove it. Fee compression combined with client attrition in a specific franchise. Funding concentration in a specific counterparty class. A technology dependency whose failure would collapse a revenue line. These are defensible because the firm can show the risk is monitored, the appetite is set, and management actions exist.
Avoid: cyber catastrophe, sovereign default, pandemic redux. These invite the response that the firm has not done the work.
Sequence the narrative to disarm the add-on reflex
Structure the document in this order. First, the business model on a page: revenue drivers, cost base, funding, capital. Second, the vulnerabilities identified through reverse engineering, with an explicit statement that these are scenarios of non-viability, not scenarios of stress. Third, the path from current state to non-viability, showing the sequence of failures required. Fourth, the mitigants: governance triggers, existing management actions, recovery options. Fifth, the residual insight: what the exercise taught the board about the model.
Capital numbers appear only in section three, and only as a consequence of the scenario. They should not appear in the executive summary.
Handle the management actions section carefully
This is where firms overreach. Listing recovery plan actions as RST mitigants creates a circularity the PRA will notice: if the firm reaches non-viability, recovery actions are by definition insufficient. Distinguish clearly between actions that prevent the scenario crystallising (early warning triggers, appetite limits, hedging) and actions that respond once it has. The former belong in the RST. The latter belong in the recovery plan and should be cross-referenced, not restated.
What good looks like
A good RST leaves the supervisor with three impressions: the board understands its model at a granular level; the vulnerabilities identified are specific and monitored; the firm has thought about non-viability without being fatalistic about it. It does not leave the supervisor with a number they feel obliged to act on.
Next step
Before drafting, hold a closed session with the CRO, CFO, and Chair of the Risk Committee to agree the two or three vulnerabilities that will anchor the narrative. If that conversation cannot produce consensus in ninety minutes, the RST is not ready to be written.
Frequently Asked Questions
Should we quantify the probability of the reverse stress scenario?
No. SS31/15 does not require it, and any probability estimate invites challenge. State that the scenario is, by construction, of very low likelihood and focus on the mechanics.
How do we handle it if the RST reveals a genuine, previously unrecognised vulnerability?
Disclose it, but pair the disclosure with the remediation plan and timeline already agreed by the board. Supervisors respond badly to surprises presented without a response. They respond well to surprises presented with ownership.
Should the RST be signed off by the board or by the Risk Committee?
The board. RST is a business model exercise, not a risk technicality. Board minutes should record substantive challenge, not ratification.
How often should the scenarios be refreshed?
Annually for the narrative, but the underlying vulnerabilities should be reviewed whenever the strategy, funding mix, or client concentration materially shifts. A stale RST is worse than none.
Can we use the same scenarios as our ICAAP stress tests?
No. If your RST scenario is your severe ICAAP scenario, you have not done reverse stress testing. The RST scenario must, by definition, be more severe than the point at which capital is exhausted under normal stress.
Frequently asked questions
Should we quantify the probability of the reverse stress scenario?
No. SS31/15 does not require it, and any probability estimate invites challenge. State that the scenario is, by construction, of very low likelihood and focus on the mechanics.
How do we handle it if the RST reveals a genuine, previously unrecognised vulnerability?
Disclose it, but pair the disclosure with the remediation plan and timeline already agreed by the board. Supervisors respond badly to surprises presented without a response. They respond well to surprises presented with ownership.
Should the RST be signed off by the board or by the Risk Committee?
The board. RST is a business model exercise, not a risk technicality. Board minutes should record substantive challenge, not ratification.
How often should the scenarios be refreshed?
Annually for the narrative, but the underlying vulnerabilities should be reviewed whenever the strategy, funding mix, or client concentration materially shifts. A stale RST is worse than none.
Can we use the same scenarios as our ICAAP stress tests?
No. If your RST scenario is your severe ICAAP scenario, you have not done reverse stress testing. The RST scenario must, by definition, be more severe than the point at which capital is exhausted under normal stress.
Related guides
How to Structure a Threshold Conditions Self-Assessment That Pre-empts FCA Withdrawal Risk
This guide sets out how boards and senior managers should structure a Threshold Conditions self-assessment that identifies authorisation withdrawal risk before the FCA does. After reading, you will know how to sequence the assessment, where the real judgement calls sit, and what evidence a supervisor expects to see.
Scoping a Section 166 Review: How to Limit Remit Without Looking Obstructive
This guide sets out how to shape the scope of a Skilled Persons Review so that reviewer remit stays proportionate and defensible. After reading, you will know how to engage the FCA on scoping, framing and lot selection in a way that protects the firm without triggering supervisory suspicion.
How to Respond to a Dear CEO Letter Without Self-Incriminating
This guide sets out how to structure a response to an FCA Dear CEO letter that credibly engages with thematic findings while protecting the firm from admissions of specific control failures. It equips senior leaders to calibrate tone, sequencing, and evidence so the response advances remediation without creating supervisory or enforcement exposure.
How to Structure a RegData Resubmission Narrative That Avoids Past Business Review
This guide sets out how to frame a RegData resubmission so that corrections are accepted as routine remediation rather than treated as evidence of systemic control failure. After reading, you will know how to sequence the disclosure, calibrate the narrative, and pre-empt the supervisory questions that typically escalate a correction into a past business review.
How to Structure an FCA VoP Application That Avoids Full Re-Authorisation
This guide explains how to frame a Variation of Permission application so the FCA treats it as a scope adjustment rather than a de facto re-authorisation. You will learn how to sequence the narrative, evidence pack, and stakeholder engagement to keep the review contained.
Where a specific question needs an outside answer, quickly
Polar Insight's Expert Network connects leadership teams with practitioners who can speak to a precise regulatory, commercial, or stakeholder question before a decision is finalised.
Explore Expert Network