Liquidity Risk Fundamentals for Bank Treasury and Risk Teams
Video description: Why a profitable, well capitalised bank can still fail in days, and the liquidity tools (buffers, HQLA, FTP, LCR and NSFR) used to stop it.
The video above runs through the fundamentals of liquidity risk in about the time it takes to drink a coffee. Read on here for the practitioner detail, the worked examples, and the context you will need when you get to the desk.
This is Session 1 of the Liquidity Management course. It stands on its own. The aim is simple: by the end you will understand why a bank that is profitable and well capitalised can still fail in days, and what the people around you are actually doing to stop that happening.
What liquidity actually means
Liquidity is the ability to meet your obligations as they fall due. That is the whole definition. When a depositor asks for their money, when a loan needs to be funded, when a margin call lands, when a bond you issued matures, you need cash in the right currency, in the right place, at the right time.
Notice what that definition does not mention: profit, capital, or the value of your assets. Those things matter enormously, but they are separate questions. Liquidity is about timing and access. You can own a building worth ten million and still be unable to pay a taxi fare with it this afternoon. Banks face the same problem at scale.
A useful way to think about it: liquidity is a flow, not a stock. It is about whether cash arrives before it is needed, not whether the total assets exceed the total liabilities.
Solvency is not liquidity
This is the distinction that trips people up, so it is worth being precise.
Solvency means your assets are worth more than your liabilities. It is a balance sheet question measured over quarters and years. Capital ratios, CET1, the ICAAP: these all live in the world of solvency.
Liquidity means you can pay what you owe today. It is a cash flow question measured over days and hours.
A bank can be solvent and illiquid at the same time. Its loan book is sound, its capital is healthy, but it cannot turn enough of that value into cash quickly enough to meet a wave of withdrawals. That is not a theoretical edge case. It is the ordinary way modern banks fail.
Solvency tells you whether a bank should survive. Liquidity tells you whether it will survive the week. Both can be true at once, and the second one moves faster.
Maturity transformation: the built in vulnerability
The reason liquidity risk exists at all is structural. It is baked into what a bank does.
Banks take deposits that can be withdrawn on demand and use them to fund mortgages, business loans, and other long dated assets. They borrow short and lend long. This is maturity transformation, and it is genuinely useful. It lets savers keep instant access while borrowers get twenty five year mortgages. The economy runs on it.
But it creates a gap. Your liabilities can leave overnight. Your assets cannot be recalled overnight. A thirty year mortgage does not care that half your depositors want out by Friday.
Consider a simplified bank (all figures illustrative, in millions):
- 100 in customer deposits, withdrawable on demand
- 90 lent out as five year loans
- 10 held as cash and liquid assets
A weekly note on treasury, liquidity and practical Python. No spam, unsubscribe any time.
On paper this is fine. The loans are performing, the bank is solvent. But if 20 of those deposits walk out the door, you have 10 in cash and a 10 shortfall. The loans are worth 90, but you cannot get 90 of cash for them by close of business. That gap is liquidity risk, and it exists in every bank that does maturity transformation, which is all of them.
Why liquidity moves faster than other risks
Credit risk and market risk are slow by comparison. A loan book deteriorates over quarters as borrowers miss payments. A trading position bleeds as prices move, and you usually have time to react. You can see these coming.
Liquidity risk is different because it is driven by confidence, and confidence collapses in hours.
Deposits do not leave on a schedule. They leave when people stop believing the bank is safe. Once that belief goes, everyone rushes for the exit at once, because being last in the queue is the worst place to be. The behaviour is reflexive: the fear of a run causes the run.
An illustrative example makes the speed concrete. In a normal month a retail bank might see a small, predictable share of deposits move for ordinary reasons, well under one per cent a day. In a stress event that same bank could lose a double digit percentage of deposits in a single day. If deposits go out at, say, twenty per cent in twenty four hours, no realistic buffer of liquid assets survives more than a couple of days. The maths is brutal and it is fast.
This is why regulators frame liquidity requirements around short, sharp windows. The LCR requires a bank to hold enough HQLA to cover its net cash outflows over a thirty day period of severe stress, so the test is about net outflows, not just gross survival. If you want the mechanics, see how the LCR really works, which walks through the numerator and denominator in detail. For the source rules, the Basel Committee's LCR standard is the authoritative reference.
Two banks that ran out of time
Two failures make the point better than any theory.
Northern Rock (2007)
Northern Rock was solvent. Its mortgage book was reasonable and it was profitable. Its weakness was on the funding side. It relied heavily on wholesale funding and securitisation rather than stable retail deposits. When the wholesale markets froze in the summer of 2007, that funding simply stopped rolling over.
Once the bank asked the Bank of England for support and the news broke, retail depositors queued outside branches to withdraw their money. That was the first major bank run in Britain in well over a century, the last comparable episode being Overend Gurney in 1866. The trigger was not bad loans. It was a funding model that depended on markets staying open, and markets closed.
Silicon Valley Bank (2023)
SVB was a US bank supervised by US regulators, not the PRA, so the thirty day LCR framing described above did not apply to it in the same way. It looked different on the surface but failed for familiar reasons. It had taken in a large volume of deposits from technology firms and invested heavily in long dated government bonds. Those bonds were high quality, but their market value fell sharply as interest rates rose. To raise cash, SVB had to sell some at a loss, which it announced alongside a plan to raise capital.
That announcement broke confidence. Its depositor base was concentrated, well connected, and fast moving. Word spread through group chats and calls, and depositors tried to pull tens of billions in a single day. The withdrawal speed was extraordinary, far beyond anything the traditional models assumed. The bank could not meet it and was closed within days.
The common thread: both banks were solvent, or close to it, when they failed. What killed them was speed of withdrawal meeting a funding structure that could not respond fast enough.
The toolkit: buffers, HQLA, FTP and stress testing
So how do banks defend against this? A working list of the tools you will meet:
- Liquidity buffers. A pool of cash and assets held specifically to absorb outflows in stress. This is your first line of defence when funding dries up.
- High quality liquid assets (HQLA). The assets in that buffer must actually be liquid under stress. Central bank reserves and top rated government bonds qualify because you can sell or repo them quickly, even in a crisis, without a large price haircut. SVB is the cautionary tale: bonds can be high quality yet still cost you dearly if you must sell at the wrong moment.
- The LCR and NSFR. These are the two regulatory ratios you will meet most. The LCR is the short term test: enough HQLA to cover net outflows over a thirty day stress. The NSFR is the longer, roughly one year structural test: enough stable funding to support your longer dated assets. One protects against a sudden run, the other against a fragile funding profile.
- Funds transfer pricing (FTP). The internal pricing mechanism that charges business lines for the liquidity they consume and rewards those who bring stable funding. Good FTP makes the cost of liquidity visible so the bank does not accidentally build a fragile funding profile.
- Treasury cash management. The day to day work of making sure cash is in the right entity and currency, that intraday obligations are met, and that funding is arranged before it is needed.
- Stress testing. Modelling what happens under severe but plausible scenarios, including deposit run off assumptions. This feeds the ILAAP, which is where a firm sets out its own view of its liquidity adequacy. For an approachable walk through, see ILAAP without the panic.
Who does what: Treasury, Risk and Finance
Three internal teams sit at the centre, and they interact constantly with external funding markets.
Treasury owns the position. It manages the buffer, arranges funding, handles cash across currencies and entities, and is the team on the phone to the market when conditions tighten. Treasury is the first responder.
Risk sets and monitors the limits, owns the stress testing framework, and independently challenges the assumptions Treasury and the business are working to. When someone asks whether a run off assumption is realistic, that is Risk.
Finance produces the numbers that everything else depends on, reconciles the balance sheet, and drives regulatory reporting such as the LCR, NSFR and PRA110. If the data is wrong, every decision built on it is wrong.
Under stress, these three teams work against the clock while the external picture shifts: wholesale lenders pull back, counterparties tighten terms, and the cost of funding jumps. The internal and external worlds are connected by confidence, and confidence is exactly the thing that fails fast.
What to take onto the desk
Carry three ideas into your first weeks.
First, keep solvency and liquidity separate in your head. When something goes wrong, ask which one you are looking at, because the response and the timescale are completely different.
Second, respect the speed. Liquidity events do not build politely over quarters. They arrive in a day. That is why the buffer, the reporting, and the stress assumptions all have to be ready before you need them, not after.
Third, learn to read a live position quickly. When you can look at cash flows by bucket and currency and see where the gap is, you understand the bank in a way that a monthly report never gives you. A practical starting point is reading a liquidity position with pandas, which builds a simple bucketed view from raw cash flow data.
Next session we move from the why to the how, and start putting numbers against outflows so you can see where the pressure builds. Watch, on the job, for how your own firm funds itself and how stable that funding really is. That question sits underneath everything else in this course.
Get the next one in your inbox
A weekly note on treasury, liquidity and practical Python. No spam, unsubscribe any time.
Practitioner notes on treasury, liquidity, regulatory reporting and practical Python.
