What Are Credit Risk Models? Types & Approaches

What Are Credit Risk Models? Types & Approaches

Credit risk models are quantitative tools that estimate how likely a borrower is to default. They also estimate how much a lender could lose if default occurs. Banks use them to approve loans, price risk, hold enough capital and set aside provisions for expected losses.

So, what are credit risk models made of, and how do they differ from one another? This guide explains the core parameters, the main model types and the regulatory approaches banks follow. If you are new to the subject, start with our pillar guide, What is Credit Risk?, and then return here.

What Are Credit Risk Models and Why Do Banks Use Them?

Every loan is a forecast. When a bank lends, it predicts that the borrower will repay on time. Credit risk models turn that prediction into numbers that managers, auditors and supervisors can test.

Put simply, the answer to what are credit risk models used for comes down to four decisions:

  • Lending decisions: approve, decline or refer an application based on its estimated risk.
  • Risk-based pricing: charge a higher rate or fee where expected losses are higher.
  • Regulatory capital: calculate risk-weighted assets (RWAs) under the Basel framework, which set the minimum capital a bank must hold.
  • Provisioning: estimate expected credit losses (ECL) under IFRS 9, or under CECL in the United States.

Each use places different demands on the same model. For example, Basel IRB models rely on long-run average PDs and downturn LGDs. By contrast, IFRS 9 requires point-in-time, forward-looking estimates that reflect current conditions and economic forecasts. Banks must also weight these estimates across several economic scenarios. Stage 1 loans carry 12-month ECL, while lifetime ECL applies once credit risk has increased significantly since initial recognition.

Consequently, many banks keep one core rating system and calibrate its outputs separately for each purpose.

The Building Blocks: PD, LGD and EAD

Most PD LGD EAD models feed one simple equation. Each parameter answers a different question:

Together, they produce Expected Loss (EL):

Expected Loss = PD × LGD × EAD

Consider a simple example. A bank lends $1,000,000 to a mid-sized manufacturer. Its rating model assigns a PD of 2%, and the collateral supports an LGD of 40%. Because the term loan is fully drawn, EAD equals $1,000,000.

EL = 0.02 × 0.40 × $1,000,000 = $8,000

Pricing should cover this average expected loss, while capital absorbs unexpected losses above it. Note that this is a one-period view. IFRS 9 provisions add further steps, such as lifetime PDs for Stage 2 loans and discounting. For a deeper look at the first parameter, see PD Estimation Methods for Credit Risk.

Types of Credit Risk Models

Banks and analysts usually group credit risk models into five types:

  1. Credit scoring models – rank borrowers by default risk using borrower data.
  2. Structural models – link default to the value of a firm’s assets.
  3. Reduced-form (intensity) models – treat default as a random event driven by a hazard rate.
  4. Portfolio models – estimate losses across a whole loan book, including correlation.
  5. Machine learning models – use algorithms such as gradient boosting to find non-linear patterns.

These categories overlap, since they group models by purpose, theory or technique.

1. Credit Scoring Models

Credit scoring models are the workhorse of retail and SME lending. Application scorecards assess new applicants using income, credit bureau history and loan-to-value. Behavioural scorecards, meanwhile, track existing customers through repayment patterns, limit utilisation and arrears.

Most banks still build scorecards with logistic regression, often on Weight of Evidence (WoE) binned variables. The method is transparent, stable and easy to explain to regulators. Moreover, analysts convert its output into points, so a credit officer can see exactly why a score changed. A separate calibration step then maps scores to PDs for pricing, capital and IFRS 9. To see the mechanics, read How to Calculate Probability of Default.

2. Structural Models (Merton / KMV)

Structural models treat a company’s equity as a call option on its assets. In Robert Merton’s 1974 framework, a firm defaults when its asset value falls below its debt at maturity. PD then depends on the gap between asset value and debt, scaled by asset volatility.

KMV, later acquired by Moody’s, commercialised this idea. Its model sets the default point at short-term debt plus half of long-term debt. It then maps the resulting distance to default to an Expected Default Frequency (EDF) using historical default data. Because inputs come from share prices, the model reacts quickly to market news. However, it works best for listed firms with traded equity.

3. Reduced-Form (Intensity) Models

Reduced-form models do not ask why a firm defaults. Instead, they treat default as a surprise event that arrives at a random time. A hazard rate, or default intensity, sets how likely that event is in each period.

Analysts usually calibrate the hazard rate to credit default swap (CDS) spreads or bond prices. As a result, these models suit credit derivative pricing and counterparty credit risk. Note, however, that market-implied PDs are risk-neutral, so they usually exceed historical default rates. Jarrow–Turnbull (1995) and Duffie–Singleton (1999) remain the classic references.

4. Portfolio Models (CreditMetrics, CreditRisk+)

Single-loan models miss one critical fact: defaults tend to cluster. Portfolio models therefore estimate the full loss distribution of a loan book, including correlation between borrowers.

J.P. Morgan’s CreditMetrics, launched in 1997, simulates rating migrations as well as defaults. Credit Suisse First Boston’s CreditRisk+, released the same year, borrows an actuarial approach from insurance. Both produce credit Value-at-Risk for economic capital and limit setting. Notably, the Basel IRB capital formula itself rests on a portfolio model, the Asymptotic Single Risk Factor (ASRF) model.

5. Machine Learning Models

Machine learning models such as gradient boosting (XGBoost, LightGBM) and random forests capture non-linear patterns that logistic regression can miss. Banks use them for fraud detection, early-warning systems and, increasingly, credit underwriting.

However, accuracy comes at a cost. Complex models are harder to explain, validate and defend in front of a supervisor. Explainability tools such as SHAP values help, yet many banks still run ML as a challenger alongside a traditional scorecard. In addition, the EU AI Act classes AI systems that assess the creditworthiness of individuals as high-risk. Similarly, US lenders must still give specific reasons when they decline credit, whatever the algorithm.

Credit Risk Modeling Approaches

Credit risk modeling approaches differ on two levels: the regulatory route for capital and the estimation technique.

Under Basel, the Standardised Approach applies fixed risk weights set by the regulator, often linked to external ratings. It is simple to run, but less sensitive to risk. Alternatively, the Internal Ratings-Based (IRB) approach lets approved banks use their own models. Under Foundation IRB, the bank estimates PD, while supervisory values apply for LGD and EAD. Under Advanced IRB, the bank estimates PD, LGD and EAD itself. For retail exposures, there is no Foundation option. IRB can lower capital for low-risk books. However, it demands at least five years of data, strong governance and supervisory approval.

The finalised Basel III reforms narrowed this freedom. They removed Advanced IRB for exposures to large corporates, banks and other financial institutions. They also introduced an output floor. Under it, a bank’s total RWAs cannot fall below 72.5% of the standardised-approach figure (BIS, Basel III: Finalising post-crisis reforms). Implementation also varies by country. The EU applies these rules through CRR3. Meanwhile, a March 2026 US re-proposal would replace internal credit risk models with a standardised approach for the largest banks. In India, banks use the Standardised Approach.

On the technique side, three families dominate:

  • Statistical models fit data-rich portfolios such as mortgages and credit cards.
  • Machine learning models fit large, high-frequency data sets, such as digital lending.
  • Expert judgement models fit low-default portfolios, such as sovereigns or project finance, where too few defaults exist for reliable statistics.

In practice, most banks blend all three.

Real-World Example: The ECB’s Review of Internal Models

Between 2016 and 2021, the European Central Bank ran its Targeted Review of Internal Models (TRIM). ECB Banking Supervision called it its largest project ever. Supervisors conducted 200 on-site investigations at 65 significant banks, covering credit, market and counterparty credit risk models.

TRIM produced more than 5,000 findings for banks to remediate. Overall, it raised risk-weighted assets for the investigated models by about 12%, or roughly €275 billion. Consequently, the average CET1 ratio of banks using internal models fell by about 70 basis points (2018–2021) (ECB press release, April 2021).

The lesson is clear. Models drive real capital outcomes, so weak data and loose assumptions eventually reach the balance sheet.

Challenges and Model Validation

Even well-built models face persistent challenges. First, poor data quality, such as missing default flags or patchy recovery records, weakens every estimate. Second, model risk arises when a model is wrong or misused. The Federal Reserve’s SR 11-7 and the UK PRA’s SS1/23 set widely used standards for managing it. Third, banks must test discrimination (Gini or AUC), calibration (predicted versus observed defaults) and stability (PSI) regularly. Finally, supervisors review models before approval and throughout their life. Strong, independent validation is therefore not a formality; it is what keeps a model in use.

Conclusion

So, what are credit risk models in a single line? They are the tools that turn borrower data into PD, LGD and EAD, and then into prices, provisions and capital. From scorecards to gradient boosting, each type serves a specific purpose. Mastering them, alongside Basel and IFRS 9 rules, opens doors at banks, consultancies and regulators.

Explore our Credit Risk Modeling Certification Training to master Risk Analytics

 

FAQ

Which credit risk model do banks use most?

Logistic regression scorecards remain the standard credit risk model for retail and SME lending at most banks. They are transparent, stable and easy to explain to regulators and customers. Many banks now test machine learning models alongside them as challengers, rather than replacing scorecards outright.

How do Basel and IFRS 9 credit risk models differ?

Both use PD, LGD and EAD, but for different goals. Basel IRB models set regulatory capital using long-run average PDs and downturn LGDs. IFRS 9 models set accounting provisions using point-in-time, forward-looking estimates, with 12-month or lifetime expected credit loss depending on the loan’s stage.

Can banks use machine learning for regulatory credit risk models?

Yes, but with conditions. Supervisors expect any model, including machine learning, to be explainable, well documented and independently validated. Because complex algorithms are harder to interpret, many banks use them as challengers or in early-warning systems, while scorecards remain the primary approved model.

 

Explore Dexlab Analytics’ Credit Risk Modeling certification program to build PD, LGD, and EAD models from scratch, work through IFRS 9 ECL frameworks, and learn model validation techniques used by practicing risk teams.


.

October 1, 2026 1:28 pm Published by

, , , , , , , , , , , , , , ,

Comments are closed here.

...

Call us to know more

×