Credit risk is the risk that a counterparty fails to pay what it owes. For a lender that is a loan that stops performing; for a supplier it is an invoice issued on open terms that is never settled. Both are the same exposure with different paperwork, and both are managed the same way: understand who the counterparty is, quantify how likely they are to fail, size the exposure accordingly, and keep watching after the decision is made.
The main types of credit risk
The counterparty stops paying entirely — insolvency, liquidation or abandonment of the obligation.
Too much exposure to one customer, one sector or one country, so a single failure is material.
Invoices issued on open terms that are settled late or never — the dominant form of credit risk for B2B suppliers.
Payment fails for reasons outside the company: capital controls, currency shortage, sanctions or political disruption.
The counterparty does not default but deteriorates, so the exposure becomes more expensive or harder to insure.
How credit risk assessment works
A credit assessment is an evidence chain, not an opinion. Four inputs carry most of the signal:
- Financial strength. Filed accounts read for liquidity, leverage, profitability and — most importantly — cash generation.
- Payment behaviour. How the company actually pays, versus how it promises to pay. Slow payment is the earliest reliable warning of distress.
- Structure and ownership. Group structure, shareholders and ultimate beneficial owners, so exposure is aggregated to the group rather than scattered across subsidiaries.
- External context. Sector conditions, country risk, sanctions exposure and adverse media — the factors that override an otherwise healthy balance sheet.
The metrics that quantify it
The chance the counterparty defaults over a defined horizon, usually 12 months.
The share of exposure you would not recover after a default, net of security and recoveries.
The amount outstanding at the moment of default, including undrawn but committed lines.
PD × LGD × EAD — the loss you should price into terms rather than treat as a surprise.
Key credit ratios
| Ratio | Calculation | What it tells you |
|---|---|---|
| Current ratio | Current assets ÷ current liabilities | Short-term ability to pay what falls due |
| Quick ratio | (Current assets − inventory) ÷ current liabilities | Liquidity without relying on selling stock |
| Gearing | Net debt ÷ equity | How much of the business is funded by borrowing |
| Interest cover | EBIT ÷ interest expense | Whether trading profit covers the cost of debt |
| DSO | Receivables ÷ revenue × 365 | How long the company itself waits to be paid |
| Operating cash flow | Cash generated by operations | Whether profit converts into cash |
A credit risk management framework in six steps
- 1. Credit policy & risk appetite
Write down what you will accept: maximum exposure per counterparty, per sector and per country, acceptable payment terms, and the score thresholds that trigger security, prepayment or refusal.
- 2. Identification & verification
Confirm who the counterparty actually is — registered entity, ownership, group structure and ultimate beneficial owners — before any financial analysis. A clean score on the wrong legal entity is worthless.
- 3. Assessment & scoring
Combine financials, payment behaviour, structure and external context into a score and a recommended limit, using the same method for every counterparty so decisions are comparable and defensible.
- 4. Decision & terms
Translate the score into commercial terms: limit, payment days, prepayment, guarantees or credit insurance. Record who approved exceptions and why.
- 5. Monitoring
Track the portfolio continuously and alert on score movement, new filings, insolvency events, ownership changes and adverse media — not once a year.
- 6. Collections & recovery
Escalate on defined ageing triggers, and feed actual payment outcomes back into scoring so the model learns from your own book.
Why one-off checks fail
Most bad debt is not caused by a bad decision at onboarding — it is caused by a good decision that was never revisited. A counterparty approved on last year's accounts can lose a major customer, change ownership, or fall under sanctions without you hearing about it. Credit risk management only works when the assessment is continuous and aggregated across the group, and when it sits alongside the other exposures a counterparty brings: compliance, cyber, ESG and country risk.
Credit risk case studies
Four publicly documented corporate failures — Carillion (2018), Wirecard (2020), Greensill Capital (2021) and Thomas Cook (2019) — show how credit risk management breaks in practice: supplier terms used as funding, group structure hiding cash, concentration in a single client group, and leverage running out of time. Each case sets out the signals that were public beforehand, with sources.
Read the case studiesLatest credit risk insights
- Business intelligence for risk teams: from raw company data to decisions7 September 2026
- Third-party risk assessment: building a programme that actually runs7 September 2026
- Ultimate beneficial ownership: how to trace who really controls a company6 September 2026
- What is KYB? Know Your Business verification explained6 September 2026
Frequently asked questions
- What is credit risk?
- Credit risk is the risk of financial loss when a counterparty fails to meet its payment obligations — a borrower missing loan repayments, or a customer not paying an invoice on agreed terms. It covers both outright default and slower deterioration such as chronic late payment.
- What is credit risk management?
- Credit risk management is the end-to-end process of identifying, measuring, limiting and monitoring that exposure: setting a credit policy and risk appetite, assessing each counterparty before onboarding, assigning credit limits and terms, and monitoring the portfolio for changes after the decision is made.
- How is credit risk assessed?
- Assessment combines financial statement analysis (liquidity, leverage, profitability, cash generation), payment behaviour, corporate structure and ownership, and external context such as sector and country risk. Those inputs are condensed into a credit score and a recommended credit limit.
- What is the difference between a credit score and a credit limit?
- A score expresses the likelihood that a company fails to pay. A limit expresses how much exposure you should carry against that company at one time. A strong score with a small limit is common for young companies with thin balance sheets.
- How often should credit risk be reviewed?
- Risk changes between reviews, so annual re-scoring alone leaves gaps. Continuous monitoring with alerts on score changes, filings, insolvency events and ownership changes is the practical standard for any portfolio beyond a handful of accounts.
Score, credit limit, financial ratios and payment behaviour — with continuous monitoring on top.
Stay ahead of KYB & AML change
Monthly briefing: new regulations, sanctions waves, country-risk shifts and product updates. No fluff, unsubscribe in one click.
