Quantification

Heat-maps lie. What capital-grade risk numbers look like

The 5×5 red-amber-green grid is the most recognizable artifact in operational risk. It is also one of the most misleading. It looks like measurement. It is closer to a mood ring.

Heat maps earn their place because they are easy to produce and easy to read in a meeting. But the qualities that make them convenient are exactly the ones that make them dangerous when real capital decisions ride on the output.

Likelihood × ImpactTwo ordinal axes, twenty-five buckets, three colors. Every risk in the firm gets compressed into one of a handful of cells — and the arithmetic that produced the cell cannot survive contact with a capital model.

Three lies the grid tells

It pretends ordinal scores are numbers. A “4” on impact is not twice a “2.” The scale has no units, so you cannot add, average, or aggregate across risks without inventing math the scale never supported. A portfolio of “mediums” has no defined total.

It throws away the tail. The grid’s top-right cell holds a once-a-decade catastrophe and a merely-bad quarter in the same square. Operational risk lives in that tail — and a model that cannot distinguish a P95 outcome from a P99.9 one is silent on exactly the events that determine solvency.

It cannot speak to the CFO. A board can act on “this exposure has a 1-in-20 chance of costing more than $18 million.” No one can allocate capital against “amber.”

A heat map answers “how worried should we be?” A capital-grade number answers “how much should we hold, and what would it cost us if we are wrong?”

What capital-grade looks like

The alternative is the same approach actuaries have used for insurance and that banks use for credit risk: model the frequency of loss events and the severity of each, then simulate the combined distribution thousands of times to see the full shape of what could happen — not just the average, but the tail.

Mean / expected loss P99 P99.9
$ loss →The decisions live in the tail, not at the mean

Done properly, that produces a row of numbers a capital committee can actually use:

Instead of a colorYou get
Loss frequencyNegative Binomial — captures the overdispersion a Poisson model hides
Loss severityLog-Normal with a calibrated heavy right tail
Full distribution5,000 + 10,000 Monte Carlo runs, convergence-gated
The tail itselfP99.9 via a GPD / Hill estimator above the P95 threshold
Thin data, handledBühlmann credibility blends your history with an industry prior
A capital figureBasel IV SMA capital, straight from the same model

The point is not the acronyms. It is that every one of these outputs has units, can be aggregated across the portfolio, and converts a register entry into a dollar figure with a confidence level attached. The same risk that was “amber” becomes “expected loss $2.1M, P99.9 tail $18.4M, capital charge $X” — and now it belongs in the same conversation as credit and market risk.

Keep the picture, lose the lie

None of this means heat maps disappear. A colored grid is still a fine way to show a result to a non-technical audience. The mistake is letting it be the computation — letting the limits of a four-color scale define the limits of what your risk function can say. Compute in dollars and distributions; render in whatever picture helps the room. Just never confuse the picture for the number underneath it.

C
Compler Team
AURA actuarial engine · Compler

Put a dollar figure on every risk

See AURA quantify your register — 35+ actuarial fields per assessment, from frequency and severity fits to a Basel IV SMA capital figure.