FRM Exam Part II · Early Warning Indicators
Designing Metrics, Thresholds and Triggers for Early Warning Indicators
Updated 11 October 2026 · Fact-checked
An early warning indicator (EWI) is a metric that signals rising risk before losses or a liquidity shortfall occur. To design one, choose a metric, calibrate thresholds to history and stress, set tiered escalation levels, weigh false alarms against missed signals, and tie each trigger to a named action and owner.
Understand Designing Metrics, Thresholds and Triggers
An early warning indicator is a measurable signal that moves before a problem becomes serious. In liquidity risk, examples are the share of deposits from a few large clients, funding spreads over a benchmark, falling credit rating outlook, or rising use of central bank facilities. The aim is time. You want enough lead time to act before the contingency funding plan (CFP) has to be fully used.
A metric alone is not enough. You need a threshold, which is the level at which the metric is considered abnormal. Thresholds are usually tiered. A common design has a green zone (normal), an amber zone (early warning, monitor and report) and a red zone (trigger, act). Each zone has an escalation level: who is told, how fast, and who has authority to decide.
Calibration links thresholds to evidence. You look at the history of the indicator in normal times and in past stress, including peers' events. You also use the bank's own stress tests. If a metric reaches amber at a level that, in stress tests, still leaves a long survival horizon, the threshold is reasonably set. If it only reaches amber after the survival horizon has shrunk badly, it is too loose.
Every threshold involves a trade-off. A tight threshold catches more real events but also gives false positives (alarms with no real stress). A loose threshold gives fewer false alarms but risks false negatives (missed real stress). In liquidity risk, a missed signal is usually costlier than a false alarm, so thresholds tend to lean sensitive. But too many false alarms cause alert fatigue, and people stop responding.
Finally, a trigger is a threshold breach that forces a pre-agreed action. Good triggers state the action (for example, convene the crisis committee, raise buffers, cut wholesale funding reliance, test contingent lines), the owner, and the deadline. Triggers should be reviewed regularly, because business mix, funding structure and market conditions change.
Key formulas to remember
- False positive rate
- False positive rate = false alarms ÷ (false alarms + correct non-alarms)
- Share of calm periods in which the indicator still signalled. Making the threshold less sensitive (later-triggering) reduces it.
- False negative rate (miss rate)
- Miss rate = missed events ÷ (missed events + signalled events)
- Share of real stress events with no prior signal. Equals 1 − hit rate. Making the threshold more sensitive (earlier-triggering) reduces it.
- Hit rate (sensitivity)
- Hit rate = signalled events ÷ total real events
- Making the threshold more sensitive (tighter, earlier-triggering) raises hit rate but usually raises false alarms too.
- Threshold from a percentile
- Threshold = percentile p of the indicator's historical distribution (e.g. 90th or 95th)
- A starting point only. Adjust using stress results and judgment.
- Tier rule
- Green: below amber level. Amber: amber ≤ value < red. Red: value ≥ red level (for indicators where higher means worse)
- Reverse the inequalities for indicators where lower means worse, such as a liquid asset ratio.
- Trade-off rule
- More sensitive (earlier-triggering) threshold → fewer false negatives, more false positives. Less sensitive threshold → fewer false positives, more false negatives.
- Here 'tighter' means more sensitive, not a higher or lower number. The two error types move in opposite directions for a given indicator.
How to solve Designing Metrics, Thresholds and Triggers questions
Use this sequence for any question on designing or judging indicators, thresholds and triggers.
- 1Identify the risk and the indicator. Decide whether higher or lower values signal worse conditions.
- 2Check lead time. Does the indicator move early enough to act, or does it only confirm stress already under way?
- 3Read the calibration basis: history, stress tests, peer events or judgment. Ask whether it covers a stress period.
- 4Check the tiers and escalation. Look for amber and red levels, clear owners, speed and decision authority.
- 5Classify errors. A signal with no stress is a false positive. Stress with no signal is a false negative.
- 6Weigh the cost of each error. In liquidity risk, a miss usually costs more, so lean sensitive but avoid alert fatigue.
- 7Link to action. Each trigger needs a pre-agreed response tied to the CFP, with owner and timing.
- 8Choose the answer that is specific, tested and reviewed, not vague or purely manual.
Quickest way: Four-question screen
When to use it: Use when a multiple-choice question asks which design is best or which problem is present, and time is short.
- Direction: is the breach direction right for the metric?
- Error type: does the stem describe a false alarm or a miss?
- Fix: for misses, make the threshold more sensitive (tighter, earlier-triggering). For false alarms, make it less sensitive, or require a confirming indicator before red action. A confirming requirement can cut false alarms but may add misses, so it should be back-tested. Only genuinely better indicators or combinations improve both error types.
- Action: pick the option where a breach leads to a named action and escalation, not just a report.
Common mistakes in Designing Metrics, Thresholds and Triggers
Swapping false positives and false negatives.
The words 'positive' and 'negative' feel like good and bad news.
Fix: Positive means the indicator signalled. A false positive is a signal with no real stress. A false negative is no signal despite real stress.
Assuming tightening a threshold cuts both error types.
Students think a stricter threshold is simply better.
Fix: For one indicator, tightening reduces misses but raises false alarms. Only better indicators or combinations improve both.
Calibrating only to calm-period history.
Data from normal times is plentiful, stress data is scarce.
Fix: Include stress episodes, peer events and stress test results. Calm-period percentiles alone give thresholds that trigger too late.
Treating a trigger as just a report.
Monitoring and action are confused.
Fix: A trigger forces a pre-agreed action with an owner and timeline. An amber warning may only need monitoring, but red should require action.
Using a single indicator or only lagging indicators.
Simple dashboards are easier to run.
Fix: Combine market, funding and institution-specific indicators, and favour those that lead stress. Lagging ones confirm what has already happened.
Setting thresholds once and never reviewing them.
Calibration feels like a one-time project.
Fix: Review thresholds after stress events, business changes and market shifts, and back-test hit and false alarm rates.
Worked examples
Example 1
A bank tracks a wholesale funding indicator over 20 past periods. Real liquidity stress occurred in 5 periods. The indicator signalled in 4 of those 5 stress periods. It also signalled in 3 of the 15 calm periods. What are the hit rate, miss rate and false positive rate?
Show the solution
- Hit rate = signalled stress events ÷ total stress events = 4 ÷ 5 = 0.80.
- Miss rate = 1 − 0.80 = 0.20, which is 1 missed event out of 5.
- False positive rate = false alarms ÷ calm periods = 3 ÷ 15 = 0.20.
- Interpretation: the indicator catches 80% of stress but still raises alarms in 20% of calm periods.
Answer: Hit rate 80%, miss rate 20%, false positive rate 20%.
Example 2
A treasury team finds its amber threshold on a deposit outflow indicator is breached 12 times a year, but only once did stress follow. Management wants fewer alerts but worries about missing real events. What should the bank do, and what is the risk?
Show the solution
- Diagnose: the alerts have low precision. Of 12 alerts, 11 were not followed by stress, and only 1 was. Alert fatigue is a danger.
- Note the limit of the data: the false positive rate is a share of calm periods, so it cannot be computed without the number of calm periods.
- Option 1: loosen the threshold. This reduces false alarms but raises the chance of false negatives.
- Option 2: keep amber as a monitoring level but make the red trigger depend on a confirming indicator, for example a funding spread widening, so action needs two signals. This can cut false alarms but may add misses, because real stress that moves only one indicator would not trigger red.
- Check the cost trade-off: a missed liquidity event usually costs more than a false alarm, so avoid loosening so far that lead time is lost.
- Back-test the revised design against past stress episodes, including peer events, and confirm hit rate stays acceptable.
- Document owners and actions: amber means report to the treasurer, red means convene the crisis committee and review the CFP.
Answer: The problem is low precision: 11 of 12 alerts were not followed by stress. The false positive rate cannot be computed without the number of calm periods. Keep amber sensitive for monitoring, require a confirming indicator for red action, and back-test the change for added misses. Simply loosening the threshold lowers false positives but risks missing real stress.
Exam tips
- Read the stem for the error type first. 'No signal before stress' means false negative.
- In liquidity questions, expect the answer to favour sensitivity but also to warn about alert fatigue.
- Prefer options that tie breaches to named actions, owners and the CFP over options that only add reporting.
- Watch for calibration answers that ignore stress periods. They are usually wrong.
- Check direction: for coverage-type metrics, lower is worse, so breach means falling below the threshold.
Practice questions from Early Warning Indicators
- Which of the following is an inherent limitation of relying on EWIs for liquidity risk management?
- A treasurer sets a single-level threshold on the 3-month unsecured funding spread. During back-testing, the indicator breached the threshold…
- A bank's EWI dashboard has produced several amber signals over the past year, none followed by actual liquidity stress. Management proposes …
- A bank sets a three-tier traffic-light scheme for its ratio of wholesale funding maturing within 30 days to total funding: green below 18%, …
- A bank's EWI dashboard relies on a single indicator: the loan-to-deposit ratio. It stayed stable while the bank rapidly increased reliance o…
Designing Metrics, Thresholds and Triggers: frequently asked questions
How do you set thresholds for liquidity early warning indicators?
Start with the indicator's history and a percentile, then adjust using stress test results, peer events and judgment. Set tiers such as amber and red, and check that a breach leaves enough time to act before the survival horizon shrinks.
What is the difference between a false positive and a false negative in early warning indicators?
A false positive is a signal when no real stress follows. A false negative is no signal when real stress occurs. Tightening a threshold lowers false negatives but increases false positives.
What is a trigger in a contingency funding plan?
A trigger is a defined breach of an indicator level that forces a pre-agreed action. It names who is escalated to, who decides and what steps follow, such as convening a crisis committee or activating contingent funding.
Why do thresholds need regular review?
Funding mix, business strategy and market conditions change, so a threshold that worked before may become too loose or too tight. Back-testing hit rates and false alarm rates after events keeps calibration sound.