Counterparty Credit Risk: The Desk Meant to See the Whole Client
Surya · 11 min read
Think of one customer quietly taking out a car loan from one department of a bank, a credit card from a second, a personal loan from a third and a business loan from a fourth — each department running its own approval, each one seeing only its own piece, none of them checking what the other three already lent the same person. It's the same bank. It's the same customer. And unless someone forces the four departments to compare notes, the bank's true total exposure to that one customer exists nowhere, in no single report, until someone builds the function whose only job is comparing notes.
Prime brokerage ends with a version of that problem playing out across five different banks, none of whom could see what the others were financing for Archegos Capital Management. Counterparty Credit Risk is the function built to solve the same problem inside one bank. At Credit Suisse, on that exact client, the function existed. It had already raised concerns a full year before the loss. The bank still lost roughly $5.5 billion.
What counterparty credit risk actually measures
Counterparty credit risk is the risk that the party on the other side of a trade fails to meet its obligation before the trade is complete — distinct from market risk, which is the risk that the trade itself moves against you. A bank managing it needs to know two things at once: how likely is this counterparty to default, and how much would the bank actually lose if it did, right now, today.
That second question is harder than it sounds, and it's the part that separates counterparty credit risk from an ordinary loan. Lend someone ₹10 lakh and your exposure is simple: it's whatever principal is still outstanding. Enter a swap or a derivative with a counterparty instead, and your exposure moves every single day the market does — a swap that owes you nothing today can owe you a great deal next month if the underlying price moves in your favor, and owe you nothing again if it reverses. Banks measure that moving target using Potential Future Exposure (PFE): a statistical estimate, recalculated regularly, of how large that mark-to-market exposure could realistically grow before the trade matures.
The other half is Credit Valuation Adjustment (CVA): the market price, right now, of the counterparty's default risk on that exposure — booked as its own line on the bank's P&L and adjusted as the counterparty's own creditworthiness moves, the same way a bond's price adjusts when the issuer looks shakier. During the 2008 crisis, the Basel Committee found that roughly two-thirds of banks' counterparty-credit-risk losses came from CVA markdowns — counterparties getting riskier, not actually defaulting — rather than from outright default itself. That finding is why Basel III added a dedicated CVA capital charge on top of ordinary default-risk capital: a bank can lose real money on a counterparty relationship well before that counterparty ever misses a payment.
Indian banks compute the same CVA charge, not a watered-down local version of it. RBI's own Basel III capital adequacy framework requires banks to hold capital against CVA risk on their OTC derivative books using the Basel Committee's standard, so an Indian bank pricing counterparty risk into a corporate's uncleared interest rate swap is running the identical calculation, against the identical global finding, as a US or European bank pricing the same risk into a hedge fund's total return swap.
Why some trades carry this risk and others don't
Not every trade carries counterparty credit risk equally, and the difference comes down to who stands on the other side of it. A cleared trade — the kind covered in Novation: How a Clearinghouse Becomes Everyone's Counterparty — routes through a central counterparty that stands behind both sides, backed by daily margin and a mutualized default fund; an Indian trader running SLB through NSE Clearing, or a US trader on a listed future, is genuinely not exposed to the individual creditworthiness of whoever is on the other side of the trade.
A bilateral, uncleared trade has no clearinghouse standing in the middle. The bank and the client face each other directly, and whatever exposure builds up between them sits fully on both balance sheets until the trade closes. This isn't an exotic arrangement reserved for hedge funds — an Indian exporter hedging next quarter's dollar receivables through a forward booked directly with its relationship bank, under RBI's foreign exchange derivative regulations, carries exactly this kind of bilateral counterparty exposure on both sides, with no clearinghouse absorbing it, at a fraction of the size and none of the concentration.
Archegos ran the identical structure, just built entirely from total return swaps at five separate banks instead of one forward at one bank, with no central counterparty absorbing the risk at any of them — each bank carrying its own uncleared, unnetted exposure to the same underlying stocks. ISDA Master Agreements let a bank net offsetting trades with the same counterparty down to a single number in a default — but netting only works within one counterparty relationship. It does nothing to shrink the exposure sitting at four other banks the netting agreement never touches.
The function that's supposed to catch it
| Piece | What it does | Indian example | Global example |
|---|---|---|---|
| Exposure measurement (PFE) | Estimates how large a counterparty's exposure could grow before the trade matures | An Indian bank's risk desk calculating potential exposure on an FPI's derivative book under RBI's standardized exposure methodology | A US bank's counterparty risk team running PFE models across a hedge fund's swap portfolio |
| CVA desk | Prices and hedges the market cost of counterparty default risk, distinct from the trading desk that put the position on | A large private-sector Indian bank's dedicated CVA desk pricing counterparty risk into a corporate hedge quote | A bulge-bracket bank's CVA desk buying protection, often through credit default swaps, on its own biggest counterparties |
| Single-counterparty limits | Caps how much exposure the bank will carry to one client or connected group, regardless of what any individual desk wants to book | RBI's Large Exposures Framework, capping exposure to a single counterparty at a set share of the bank's Tier 1 capital | The Basel Committee's Large Exposures standard, adopted by most G20 regulators including Switzerland's FINMA |
| Consolidated reporting | Rolls a client's exposure across every desk and product into one number, refreshed often enough to matter | A custodian and clearing member under one Indian banking group sharing an FPI's exposure into one internal risk feed | Credit Suisse's own Investment Bank risk function, whose job was consolidating Archegos's exposure across its Prime Services business |
The whole point of the fourth row is that it's supposed to make the other three actually work together. A PFE model, a CVA price and a single-counterparty limit are each individually useless if nobody is consolidating them into one live view of what a single client owes the bank, across every desk that client touches, updated on a timeline fast enough to catch a position that's still growing.
What actually failed at Credit Suisse
This is the part that makes Archegos a harder case than "the rule didn't exist." Basel's Large Exposures Framework — the global standard India's RBI adopted almost verbatim, effective April 2019 — deliberately does not let a bank use its own internal risk models to calculate exposure for large-exposure-limit purposes. It mandates a standardized measurement approach instead, precisely so a bank's own models can't quietly understate how concentrated a single client's risk has become. RBI's version caps a bank's exposure to a single counterparty at 20% of its Tier 1 capital, rising to 25% only with board approval in defined exceptional circumstances, and 25% for a group of connected counterparties — a hard ceiling that doesn't bend to what any one desk's internal model says the risk looks like.
Credit Suisse had a comparable large-exposure regime, a dedicated risk function, and — this is the detail that matters — had already flagged Archegos as a concern roughly a year before the loss. An independent investigation into the collapse, commissioned by Credit Suisse's own board and published in July 2021, found that the bank's risk committee had raised worries about the concentration and volatility of Archegos's positions as early as 2020, that internally agreed margin and exposure terms were repeatedly not enforced, and that the bank's risk function lacked a timely, consolidated view of Archegos's total exposure across its various trading and prime services businesses. The investigators' own conclusion was blunt: the Archegos matter represented, at its core, a failure of management and controls, not an absence of rules.
That's the sharper lesson than "Credit Suisse had no limit." Credit Suisse had a limit. It had a risk committee that used it correctly, once, to raise the alarm. What it didn't have, in time, was a process that turned "the risk desk is worried" into "the exposure actually gets reduced" before the position's underlying stocks fell and took the collateral down with them.
Where India's design removes a specific kind of discretion
RBI's insistence on a standardized, non-internal-model exposure calculation for large-exposure-limit purposes is aimed exactly at the gap the Credit Suisse investigation described: a bank's own risk models, run by the same organization whose relationship revenue benefits from not flagging a big client, are the wrong place to leave the final call on how large that client's exposure is allowed to get. Requiring one prescribed calculation, rather than each bank's discretionary model, doesn't remove the human step of actually enforcing a limit once it's calculated — nothing regulatory removes that step — but it does remove one of the specific ways the Credit Suisse failure took shape: a number that was allowed to look smaller, internally, than the position actually was.
It doesn't remove the other half of what failed. A hard regulatory ceiling on exposure is still only as useful as the bank's willingness to act once its own risk committee says the ceiling is being approached — and that willingness is an organizational, not a regulatory, variable. India's framework narrows where a bank can hide from its own numbers. It can't force a risk committee's warning to actually change what a trading desk does next.
Why this matters for a Business Analyst
Go back to the four departments lending to the same customer, and add a fifth department — the one whose whole job is comparing notes — that compared them correctly, wrote down what it found, and still watched the number climb anyway.
A BA building an exposure or limits system tends to treat "build the consolidated view" as the finish line: get every desk's numbers into one feed, calculate PFE consistently, flag breaches against the regulatory limit. Credit Suisse had all of that. The system Credit Suisse was actually missing wasn't a measurement system — it was an escalation system with teeth: a defined, non-optional consequence that fires the moment a flagged breach isn't resolved within a set window, rather than a flag that a risk committee can note and a business line can quietly decline to act on. A limits system that stops at "produce the correct number and alert the right people" is solving the measurement half of counterparty credit risk and leaving the enforcement half as a matter of institutional will — which is exactly the half that failed here, and exactly the half a BA's requirements document is least likely to specify, because "make sure people actually act on this" doesn't look like a testable acceptance criterion until you've seen what happens when nobody does.
This holds regardless of which side of the India/global split the BA is sitting on. An Indian bank's system inherits RBI's standardized exposure calculation instead of a discretionary internal model, which closes off one way a number can end up quietly wrong — but it still needs the same escalation logic a global bank's system needs, because RBI's framework no more automates "and therefore the desk reduces the position" than Basel's does. The measurement side of the requirement changes with the regulator. The enforcement side is the same open question everywhere.
Lighthouse Insight
Back to the customer with four loans at four departments of the same bank — and now picture the fifth department that noticed, said so in writing, and watched the other four keep lending anyway.
Counterparty credit risk isn't primarily a measurement problem. Credit Suisse could measure it. It had the models, the desk, the limit and, a year out, the warning. What it didn't have was a structure where that warning was the end of the discussion rather than the start of one nobody was required to finish. A consolidated view of a client's exposure is necessary. Archegos is the proof that it was never sufficient on its own.
Continue the system
A curated path through the next concept, so one essay becomes a map.