Systemic Scenarios Without Action Thresholds: The Risk Reinsurers Miss
On this page
- Why Systemic Scenario Testing Still Leaves Reinsurers Exposed
- What does it mean for a systemic scenario to run without an action threshold?
- Why do reinsurers keep producing scenario output that nobody is required to act on?
- Which systemic scenarios are most likely to lack a threshold today?
- How does this gap actually surface inside a renewal cycle?
- What early signals show a scenario has drifted out of the decision loop?
- How do rating agencies and regulators view scenario testing that has no attached action?
- What separates a properly thresholded scenario from a reporting exercise?
- What does a working action-threshold framework actually look like in practice?
- Does this gap cost more in a hard market or a soft market?
- Sources
- Frequently Asked Questions
Why Systemic Scenario Testing Still Leaves Reinsurers Exposed
Most reinsurers already run systemic scenarios covering cyber catastrophe, cloud concentration, or pandemic-style shocks. Far fewer can say what specific decision changes the moment one of those scenarios crosses a defined line, and that gap is the real exposure.
What does it mean for a systemic scenario to run without an action threshold?
It means the scenario produces a modeled loss number, but no predefined level of that number forces a specific underwriting, pricing, or capital response.
Lloyd's own Realistic Disaster Scenarios illustrate the pattern at industry scale. The framework exists, in Lloyd's words, "to stress test both individual syndicates and the market as a whole," and results feed into a process where "Lloyd's monitors the total of all syndicate losses." That is a genuine and valuable monitoring function, but monitoring is not the same as an action rule. Nothing in the published RDS framework specifies that a syndicate's own scenario result crossing a given level must trigger a particular underwriting or capital move.
Why do reinsurers keep producing scenario output that nobody is required to act on?
Because building the scenario itself already satisfies most external reporting and audit requirements, so the harder step of attaching a decision often gets skipped.
Actuarial and catastrophe modeling teams are measured on producing credible loss estimates, not on whether those estimates change behavior downstream. Cyber aggregation modeling can now surface a systemic loss estimate for a portfolio in days rather than weeks, which paradoxically makes the gap worse. Faster scenario output without a faster decision process just means more frequent reports landing on desks that were never restructured to act on them. The result is a scenario function that is technically excellent and organizationally disconnected from the decisions it should inform.
Which systemic scenarios are most likely to lack a threshold today?
Cloud concentration, technology supply-chain accumulation, and cross-treaty cyber event definitions are the three most common blind spots.
These scenarios are newer than traditional natural catastrophe modeling, so the governance muscle around them has not caught up. Cyber event definitions that vary across multiple treaties already make it hard to know when one systemic scenario has actually occurred, which makes attaching a clean threshold to it even harder. By contrast, natural catastrophe scenarios usually do have thresholds, because decades of hurricane and earthquake modeling forced the industry to build attachment points, retention levels, and capital triggers around them long ago. Cyber and technology scenarios are still catching up to that level of decision discipline.
How does this gap actually surface inside a renewal cycle?
It shows up as a scenario slide that changes numerically each year while the treaty terms sitting next to it stay the same.
A renewal presentation might show a modeled systemic cyber loss growing 15 to 20 percent year over year, described as a risk that "warrants continued monitoring." Yet the treaty's aggregate limit, reinstatement provisions, and pricing basis remain unchanged from the prior year. Reinstatement provisions are exactly the kind of treaty mechanic that should move when a systemic scenario result moves, and when they do not, that is the clearest sign the scenario has become decorative. Cedants and brokers notice this pattern too, and it quietly signals that the reinsurer's own scenario work is not driving its terms.
What early signals show a scenario has drifted out of the decision loop?
Three signals stand out: unchanged terms despite a rising modeled number, no named owner for the scenario's action plan, and no record of a past decision tied to a past breach.
If nobody in the room can point to a specific instance where a scenario crossing a level actually changed a bound line, a price, or a capital allocation, the scenario is functioning as documentation rather than as risk management. An operational risk appetite alignment check run against the stated risk appetite statement often exposes this quickly, since the appetite language and the scenario metrics turn out to use different units or definitions entirely. Another reliable signal is a scenario owned by catastrophe modeling alone, with no underwriting or capital signature on the action plan. Ownership split across functions without a single accountable owner is a structural reason thresholds never get set in the first place.
Does this differ by scenario type?
Yes, slower-building scenarios like regulatory or supply-chain risk drift out of the loop faster than sudden-onset scenarios like a single catastrophic cyber event.
A sudden, headline-grabbing event forces an immediate reaction almost by default, even without a formal threshold. A slow-building scenario, like accumulating cloud dependency, rarely produces that same forcing moment, so it needs an explicit threshold precisely because nothing else will create urgency.
How do rating agencies and regulators view scenario testing that has no attached action?
Increasingly skeptically, since supervisors are now designing their own stress tests specifically to test the action, not just the number.
The Bank of England's Prudential Regulation Authority built its dynamic general insurance stress test around exactly this idea, stating its objectives include assessing "the effectiveness of insurers' risk management and management actions following an adverse scenario." During the live exercise, firms are "presented with a sequential set of adverse events over a three-week period and asked to react to these as they would to real events, providing initial financial impact assessments following each event and following their expected management action plans." That design choice is a direct signal from a major regulator that scenario output without a demonstrated action plan is now considered an incomplete risk management practice. Reinsurers that cannot show the same discipline internally risk falling behind what their own supervisors already expect.
What separates a properly thresholded scenario from a reporting exercise?
A named metric, a specific numeric trigger level, a predefined action, and a named accountable owner, all agreed before the scenario is ever run for real.
| Element | Reporting-only scenario | Threshold-linked scenario |
|---|---|---|
| Output | Modeled loss estimate | Modeled loss estimate plus trigger comparison |
| Owner | Catastrophe modeling team | Named CUO/CRO joint owner |
| Action on breach | None specified | Pre-agreed pricing, limit, or capital action |
| Board involvement | Reviews the number | Approves the threshold and action in advance |
| Renewal impact | Often none | Directly feeds treaty terms |
Moody's research on capital adequacy assessment makes the same point in a different regulatory context, noting that a risk process "should continuously trigger management decisions and actions" rather than functioning as a periodic report. That principle applies just as directly to systemic scenario testing as it does to broader capital assessment.
What does a working action-threshold framework actually look like in practice?
It looks like a short, board-approved table that names each systemic scenario, its trigger level, and the exact action that follows automatically once that level is crossed.
Building this does not require new modeling capability in most cases, since the scenario output already exists. Risk appetite alignment tooling can help translate an existing risk appetite statement into the specific numeric thresholds a scenario needs, closing the gap between stated appetite and operational trigger. The harder part is organizational: getting underwriting, capital, and the board to pre-commit to an action before the number is known, rather than negotiating a response after the fact under pressure. Reinsurers that make this shift stop treating systemic scenario testing as a compliance artifact and start treating it as a live input into how the book is actually run, a theme explored further in the balance-sheet consequences of leaving this gap open.
Does this gap cost more in a hard market or a soft market?
It costs more in a soft market, since a hard market forces discipline on its own while a soft market removes the external pressure that would otherwise expose the gap.
In a hard market, capacity is scarce enough that pricing and terms tighten across the board, which can accidentally compensate for a missing threshold even without one being formally set. In a soft market, competitive pressure pushes the other way, and a reinsurer without a real action threshold has nothing internal stopping it from writing into a systemic exposure it already knows is building. Reinsurance market cycles tend to mask this exact weakness for years at a time, right up until a market-wide loss event forces every participant to explain their exposure at once. By that point, the reinsurers with a pre-agreed threshold can point to a documented decision process, while the rest are left reconstructing their reasoning after the fact under scrutiny.
Systemic scenario testing has matured fast on the modeling side and much more slowly on the decision side. Closing that gap is not a modeling project, it is a governance decision that most reinsurance boards can make in a single cycle if they choose to. The scenario capability already exists in most organizations; what is missing is the short list of trigger levels and pre-agreed actions that turn that capability into something the business actually uses.
Sources
- Lloyd's, "Realistic Disaster Scenarios"
- Bank of England Prudential Regulation Authority, "General insurance stress test in 2025"
- Moody's, "ORSA: A Capital Adequacy Assessment Process for Insurers"
Frequently Asked Questions
Who inside a reinsurer should be accountable for turning a systemic scenario result into a decision?
The Chief Underwriting Officer or Chief Risk Officer, jointly, since the scenario touches both what gets bound and how much capital sits behind it.
What is the practical difference between a scenario report and a risk appetite trigger?
A report describes a possible loss; a trigger names the exact metric, threshold, and action that follows automatically once that metric is crossed.
How should a CUO test whether a scenario is actually threshold-linked?
Ask what specific underwriting or capital action happened the last time the scenario's modeled loss moved materially, and see if anyone can answer.
What renewal-season signal shows a scenario has drifted into a compliance exercise?
The same scenario slide appears with an updated number each renewal, but the treaty terms, limits, and pricing around it stay unchanged year over year.
Should action thresholds be set at the treaty level or the portfolio level?
Both, since a treaty-level threshold catches concentration in a single cedant while a portfolio-level threshold catches aggregation across the whole book.
How often should action thresholds attached to systemic scenarios be recalibrated?
At minimum annually at renewal, and immediately after any event that reveals the scenario's assumptions were meaningfully wrong.
What is the board's role in approving action thresholds versus reviewing scenario output?
The board should approve the thresholds and the actions tied to them in advance, then simply confirm during the year that breaches were acted on as agreed.
Does having an action threshold guarantee the right decision gets made?
No, but it guarantees a decision gets forced at a known point, replacing an open-ended judgment call with a pre-committed process.

Hitul Mistry
CEO, Insurnest
An InsurTech leader with more than a decade of experience across insurance and technology, focused on solving business problems with the help of technology. Has worked with brokers, insurance carriers, and reinsurance firms across the India, UAE, and US markets.
View LinkedIn profile →