Risk-bearing capacity requires numbers

When Risk Becomes a Number


When Risk Becomes a Number: Risk-bearing capacity requires numbers Comment

In May 2026, BayWa AG, a Munich-based agricultural group, reported a "solid" liquidity position for the first quarter and an adjusted EBITDA above the targets set out in the restructuring plan. At the same time, the Group announced that it would revise the restructuring plan once again due to an adjusted medium-term plan for its subsidiary BayWa r.e.; a standstill agreement was concluded with the financing banks for this purpose, valid through fall 2026. Just three months earlier, the sale of Cefetra had reduced bank liabilities by more than 600 million euros, according to the company; combined with sales already completed in 2025, the reduction in bank liabilities totaled approximately 1.3 billion euros. The securities prospectus published in 2025 also described a unified restructuring financing package of 2.4 billion euros through the end of 2028, after high outflows from the commercial paper program, among other factors, had previously contributed to an extremely strained liquidity situation.

These figures illustrate why the question of whether the company's continued existence is at risk cannot be answered with terms such as "high financing risk," "tight situation," or a red dot in a risk matrix. Qualitative statements identify risk drivers. However, they do not indicate whether available liquidity is sufficient at a given point in time, whether credit covenants are being breached, whether a rating falls below a critical threshold, or whether multiple negative developments simultaneously exceed financial reserves. It is precisely this relationship—between the potential overall risk impact and available coverage resources—that lies at the heart of risk-bearing capacity. Such a metric says more about a company's "state of health" than lengthy, verbose risk reports filled with qualitative descriptions of its condition.

The Baywa example illustrates exactly what data such an assessment requires: maturities, cash flows, liquidity reserves, credit lines, earnings ranges, proceeds from asset sales, covenants, rating requirements, and the realistic impact of countermeasures. Without these metrics, "threat to continued operations" remains merely a label rather than an analysis.

Threat to continued existence is a financial ratio 

DIIR Auditing Standard No. 2, Version 2.2, makes this point exceptionally clear. Risk aggregation is defined there as the determination of the total risk exposure based on quantified individual risks, taking into account combination effects and stochastic dependencies. It is necessary to identify potential developments that could threaten the company's continued existence pursuant to Section 91(2) of the German Stock Corporation Act (AktG) and Section 1 of the German Act on the Restructuring of Companies (StaRUG). The standard also emphasizes that individual risks cannot simply be added together and cites Monte Carlo simulations as well as equivalent stochastic methods as suitable procedures.

This shifts the focus from the question "Which risks are high?" to the question "What future financial scenarios could result from these risks—and are equity and liquidity sufficient to withstand them?" This is more than just a methodological nuance. A qualitative heat map may classify two risks as "high" even though, in an extreme case, one causes a cash outflow of 2 million euros and the other 80 million euros. It is even less capable of reliably showing how five or fifty risks collectively impact earnings, the balance sheet, and the financial plan.

The Core Economic Question of Risk-Bearing Capacity

Risk coverage potential  ↔ aggregate total risk exposure

Probability of Exposure = P(aggregated risk impact > available coverage resources)

Risk aggregation as a quantitative core 

Version 2.2 of the auditing standard defines risk aggregation not as an optional analytical tool, but as part of the functional logic of an effective risk management system. In risk analysis, cause-and-effect relationships, probabilities of occurrence, and quantitative impacts must be examined. Impacts should not be understood as seemingly exact individual values, but rather as ranges or appropriate probability distributions. This is the prerequisite for meaningfully aggregating risks in the first place.

Internal audit should not merely verify whether an aggregation calculation exists. It should assess whether the method used is suitable for capturing combination effects and identifying potential threats to the company's continued existence. To this end, the standard requires a link to corporate planning. Risks must be translated into a common economic metric—such as profit, revenue, cash flow, or enterprise value. Only then can the total risk exposure be consistently determined and compared with the risk coverage potential.

The treatment of interdependencies is particularly important. Risks are neither independent nor always positively correlated. A decline in sales, falling prices, an increase in working capital, and higher financing costs can intensify during a crisis. Other effects may partially offset one another. Simply adding up maximum losses is therefore just as problematic as adding up expected loss values. One approach may grossly overstate the extent of risk, while the other may obscure existential tail scenarios.

Risk-bearing capacity: The margin to the critical zone

The DIIR consistently distinguishes between total risk exposure, risk coverage potential, risk-bearing capacity, and risk tolerance. Risk coverage potential can be determined, on the one hand, by the equity base available to cover losses, but primarily by liquidity reserves, including available or additional credit lines. The standard explicitly emphasizes that liquidity reserves are usually the decisive factor for the company's continued existence.

Risk-bearing capacity arises from the ratio of this coverage potential to the aggregate total risk exposure. It does not provide an abstract answer as to whether a company is "risky", but rather indicates the safety margin relative to a development that could threaten its continued existence. Risk tolerance lies one level above this: it is a deliberately more cautious safety target set by management. A company may therefore still be legally and economically viable, but may have already exceeded its internal tolerance threshold.

It is precisely this distinction that is central to risk management. Anyone who waits to react until available liquidity is mathematically completely depleted is reacting too late. The DIIR therefore requires thresholds at which countermeasures must be initiated and supervisory bodies must be informed. The effectiveness of these countermeasures, in turn, should be assessed based on whether they actually reduce the total risk exposure and thus the level of threat.

Why Liquidity Is Often More Important Than Equity

A threat to a company's continued existence often does not first manifest itself as excessive debt on the balance sheet, but rather as a lack of solvency. A company may have substantial equity on its balance sheet and yet still face a crisis if it cannot meet due payments, credit lines expire, covenants are breached, or its credit rating drops so sharply that financing becomes unavailable or more expensive. For this reason, an "equity buffer" is generally insufficient as a risk-bearing capacity concept.

DIIR Version 2.2 explicitly addresses this mechanism. To assess risk-bearing capacity, not only potential losses but also minimum requirements for credit ratings and covenants—as well as their impact on liquidity—must be examined. This makes the financial plan the nervous system of the viability analysis: It shows when funds will be received, when payments are due, and what buffer the company still has under various risk scenarios.

Aggregation and Viability as Assessment Criteria

The IDW Standard PS 340 (as amended) also places a clear emphasis on risk aggregation and risk-bearing capacity in the audit of the early risk detection system pursuant to Section 91(2) of the German Stock Corporation Act (AktG). The standard requires that risks be considered not only individually but also in aggregate against the backdrop of risk-bearing capacity, and that potential interdependencies be taken into account. Risk-bearing capacity is understood here as the maximum level of risk that the company can bear without jeopardizing its continued existence.

Methodological flexibility is key: IDW PS 340 does not prescribe a specific calculation method for risk-bearing capacity. However, the methodology must be defined, documented, and comprehensible to knowledgeable third parties. In practice, this means that earnings and liquidity metrics, as well as restrictions imposed by capital providers, must be integrated into a consistent framework. Additionally, the standard distinguishes between gross and net risks: risk management measures must be taken into account in the net assessment but must not obscure the original risk dimension.

A key distinction when comparing with DIIR is that PS 340 primarily asks whether the early risk detection system is suitable for identifying developments that threaten the entity's continued existence at an early stage. The DIIR auditing standard is broader. It examines the risk management system, including risk control, reporting, effectiveness, and—particularly evident in Version 2.2—the integration of risk information into significant business decisions. DIIR also adheres more explicitly to quantitative and stochastic methods.

Early Crisis Detection Begins with Corporate Planning

With IDW S 16, the IDW published in 2025 its first standalone standard for the design of early crisis detection and crisis management in accordance with Section 1 of the StaRUG. Its central message is planning-oriented: Appropriate, continuously updated business planning and a functioning planning process form the foundation for identifying developments that threaten the company's continued existence in a timely manner. The standard is therefore aimed not only at large stock corporations but at all limited-liability business entities in general, although the specific implementation should be scaled according to size and complexity.

For risk analysis, IDW S 16 requires the systematic identification of risks that, individually or in combination, could threaten the company's going concern. Risks must be quantitatively assessed and aggregated; interdependencies must be analyzed; and the findings must be reflected in corporate planning. Risk-bearing capacity also serves as the reference framework here: it describes the maximum risk impact that the company can bear without jeopardizing its going concern. As a crisis draws nearer, the liquidity trend derived from planning takes on particular importance.

Methodologically, IDW S 16 remains more open-ended than the DIIR auditing standard. Although the final version has included the Monte Carlo simulation—at least as a potentially useful method, particularly for large companies—it does not mandate it as the standard approach. This is precisely where an important professional debate lies: Is integrated, scenario-based planning with stress and sensitivity analyses sufficient, or is a stochastic simulation regularly required to reliably determine the probability of a risk event? The DIIR takes a clearer stance in favor of stochastic aggregation; IDW S 16 allows for more flexibility.

TopicDIIR 2.2IDW PS 340 (revised version)IDW S 16
Audit/Regulatory PurposeAudit of the entire RMS by Internal Audit; Adequacy and EffectivenessStatutory Auditor: Audit of the early-warning system pursuant to Section 91(2) of the German Stock Corporation Act (AktG)Guideline on Early Crisis Detection and Crisis Management pursuant to Section 1 of the StaRUG
Risk AggregationExplicitly centralized; quantified risks, combination effects, stochastic dependenciesRequired; individual and overall risk relative to risk-bearing capacity; take interdependencies into accountSystematic aggregation and consideration of interdependencies within the framework of corporate planning
MethodsMonte Carlo simulation or equivalent stochastic methods explicitly mentionedOpen to any method; transparency and suitability are decisiveOpen to any method; Monte Carlo and stochastic methods are particularly useful for large companies
Risk-bearing capacityComparison of the aggregate total risk exposure with equity and, in particular, liquidity coverage resourcesMaximum risk exposure without jeopardizing the company's continued existence; methodology to be defined and documentedMaximum risk impact without jeopardizing the company's continued existence; liquidity trends become increasingly important as a crisis approaches
Corporate PlanningAggregation should be based on planning to accurately reflect interdependencies and coverage potentialThe link to planning and liquidity is essential in the viability conceptCorporate planning is the starting point and core of early crisis detection
Covenants / RatingsExplicitly addressed as potential triggers of a critical liquidity situationAddressed much more extensively in the revised versionGiven greater consideration as relevant financial mechanisms in the final version
Decision-Making GuidanceBroad: also includes the impact of significant business decisions on the overall risk profileNot the core focus of the audit Relation to management's duties and countermeasures; however, the focus is on early crisis detection

Table 01: Three standards, all with a focus on risk-bearing capacity

Why qualitative risk analyses alone fall short

Qualitative methods still have their place: They help with risk identification, root cause analysis, governance issues, and prioritization. They become problematic when they are used to draw conclusions about the company's continued existence. "Red" or "critical" provides no information about how many euros in earnings or liquidity losses might occur, when they might occur, how closely risks are interrelated, or what coverage resources are available at that same time. Furthermore, qualitative statements do not allow for an economically sound assessment of the effectiveness of measures. What is an executive board supposed to make of the following statement: "If we invest 5 million EUR in a firewall, the risk will be reduced from ‘red' to ‘not quite as red'!" A more meaningful statement would be: "If we invest 1 million euros in business continuity management, the recovery time after an operational disruption will be reduced from the original 25 days to 3 days. And that means we won't have to absorb a revenue shortfall of 25 million euros, but only 3 million euros."

A simple example illustrates the dilemma that arises when risks are considered in isolation. A company has 25 million euros in freely available liquidity reserves. Under simplified assumptions, three major risks could result in liquidity impacts of 15 million, 10 million, and 8 million euros. Each risk on its own would be manageable. If multiple risks occur simultaneously, the resulting strain could exceed the buffer. A heat map can neither determine the probability of this combination nor show whether positive variances from the plan might offset it. Only by linking these factors with probabilities, ranges, dependencies, and financial planning can a reliable conclusion be drawn.

The opposite error is also possible. Three risks may appear "high" in qualitative terms, even though their effects occur at different times, are negatively correlated, or can be offset by available measures. Without quantitative aggregation, therefore, there is a risk of both false security and false alarms.

Stochastics: Not an End in Itself, but a Response to Non-Additivity

The particular strength of stochastic tools and simulation lies in their ability to generate many possible future scenarios while systematically accounting for occurrence frequencies or probabilities, ranges, and dependencies. The result is not a single "correct" future, but a distribution of possible outcomes. And only such a range of scenarios reflects a serious approach to uncertainty. A single point in a risk matrix indicates an unsound approach to uncertainty, because in reality, a risk is never a single point in the sense of a single scenario. From this range of scenarios, risk measures such as Value at Risk or Expected Shortfall can be derived, as well as the probability that certain liquidity, equity, covenant, or rating limits will be breached.

However, the method is only as good as its model. Incorrectly chosen distributions, unfounded correlations, outdated data, or overly optimistic management assumptions can produce results that appear highly precise but are economically worthless. This is precisely why the DIIR's audit requirement is so important: What matters is not the existence of a simulation file, but rather the suitability of the methodology, data integrity, traceability of assumptions, plausibility of dependencies, and correct integration into corporate planning.

Info Box: What Internal Audit Should Specifically Examine

→ Whether all material risks can be described quantitatively and mapped to a common financial target.
→ Whether ranges and probability distributions are appropriately derived, documented, and regularly updated.
→ Whether relevant interdependencies between risks are taken into account—including common risk drivers and potential offsetting effects.
→ Whether risk aggregation is technically and correctly linked to corporate planning and consistently reflects impacts on earnings, the balance sheet, and liquidity.
→ Whether the risk coverage potential is robustly determined from both an equity and a liquidity perspective, and whether credit lines are realistically available.
→ Whether covenants, rating requirements, refinancing maturities, and other financial triggers are included in the scenarios.
→ Whether a suitable risk metric and clear thresholds for risk tolerance, countermeasures, and escalation have been defined.
→ Whether the effectiveness of countermeasures is quantitatively demonstrated and not merely described in qualitative terms.
→ Whether the results of the aggregation are reported clearly to the Executive Board and Supervisory Board and are taken into account in major decisions.
→ Whether model risks, data errors, and assumptions themselves are subject to quality assurance, sensitivity analysis, and independent review.

From the Risk Matrix to Financial Management Logic

The common thrust of DIIR 2.2, IDW PS 340 (as amended), and IDW S 16 is clearer than their different target audiences might suggest. An effective system must not only identify risks but also make their future financial consequences visible. This requires corporate planning, robust quantification, aggregation, and a comparison with what the company can actually withstand.

The DIIR auditing standard articulates this logic most consistently in quantitative terms. IDW PS 340 makes aggregation and sustainability the criteria for assessing the statutory early risk detection system. IDW S 16 embeds early crisis detection in ongoing corporate planning and applies this logic to limited-liability companies under Section 1 of the StaRUG. The methods differ in the degree of prescriptiveness. The core economic question, however, is identical: Are the financial reserves sufficient if risks occur not individually but in realistic combinations?

This also highlights the limitations of purely qualitative risk management. Qualitative assessments can sharpen one's perspective. However, they can neither calculate the probability of a risk nor determine the safety margin against insolvency. Anyone seeking to assess a threat to the company's continued existence must therefore inevitably put numbers on the table.

 

[ Source of cover photo: Generated with AI ]
Risk Academy

The seminars of the RiskAcademy® focus on methods and instruments for evolutionary and revolutionary ways in risk management.

More Information
Newsletter

The newsletter RiskNEWS informs about developments in risk management, current book publications as well as events.

Register now
Solution provider

Are you looking for a software solution or a service provider in the field of risk management, GRC, ICS or ISMS?

Find a solution provider
Ihre Daten werden selbstverständlich vertraulich behandelt und nicht an Dritte weitergegeben. Weitere Informationen finden Sie in unseren Datenschutzbestimmungen.