Skip to main content
The state of ai impact assessment
Category: Risk Assessment & Analysis

Risk Correlation

Also known as: Correlation Risk, Correlation in Risk Models
Simply put

Risk correlation refers to the tendency of different risks to move together, so that when one risk increases or materializes, related risks may increase or materialize as well. Because risks are often connected rather than independent, ignoring these relationships can cause an organization to underestimate its overall exposure. Understanding how risks relate to one another helps produce a more realistic picture of total risk than viewing each risk in isolation.

Formal definition

Risk correlation is the statistical relationship between two or more risk variables that causes them to move in a related manner, whether positively or negatively. In risk modeling, correlation is a parameter that influences aggregate risk estimates; treating correlated risks as independent typically understates measures such as portfolio loss distributions derived through methods like Monte Carlo simulation. In a financial context, correlation risk is often described more specifically as the risk of loss arising from adverse changes in the correlation between financial variables, and it is closely linked to concentration and diversification effects. Correlation assumptions are commonly subjected to correlation stress testing and scenario analysis, since correlations are not static and may shift, particularly under stressed conditions. The precise treatment and quantification of correlation vary by framework, model, and context, and specifics should be verified against the primary source and appropriate technical guidance.

Why it matters

Risk correlation matters because organizations that assess risks in isolation can materially understate their total exposure. When related risks tend to move together, a single triggering event or stressed condition can cause several exposures to increase or materialize at once, producing losses larger than the sum of independently assessed risks would suggest. This is one reason correlation is frequently described in financial risk literature as among the most important risk factors, influencing everything from the assumed benefits of diversification to the effectiveness of hedging and other risk treatments.

A common failure mode is assuming that risks are independent when they are in fact connected. Under normal conditions, exposures may appear only loosely related, but correlations are not static and can shift, often becoming stronger under stressed conditions when diversification is most needed. If risk models embed correlation assumptions that hold in calm periods but break down in a crisis, aggregate risk estimates and portfolio loss distributions may prove too optimistic precisely when accuracy matters most. Understanding correlation is therefore closely tied to understanding concentration and diversification effects.

The practical consequence is that decisions about capital, limits, and risk appetite built on independence assumptions may not be defensible. Treating correlated risks as unrelated typically understates measures such as portfolio loss distributions, which can leave an organization holding less of a buffer than its true exposure warrants. Recognizing and testing correlation assumptions helps produce a more realistic picture of total risk, though the appropriate treatment varies by framework, model, and context and should be verified against primary sources and appropriate technical guidance.

Who it's relevant to

Risk Managers
Risk managers rely on correlation assumptions when aggregating exposures and producing enterprise or portfolio-level risk estimates. Understanding correlation helps them avoid understating total exposure and informs how they interpret diversification and concentration effects within their risk models.
Financial and Market Risk Professionals
In financial contexts, correlation is frequently cited as one of the most important risk factors, driving diversification, hedging effectiveness, and the risk of loss from adverse movements in the correlation between financial variables. These professionals apply correlation stress testing and scenario analysis because correlations can shift, particularly under stressed conditions.
Quantitative Analysts and Model Owners
Those who build and validate risk models set and test correlation parameters that influence outputs such as portfolio loss distributions derived through methods like Monte Carlo simulation. They are responsible for examining whether independence assumptions are appropriate and for subjecting correlation assumptions to stress testing, recognizing that the precise treatment varies by model and framework.
Internal Auditors and Model Validators
Auditors and independent reviewers assess whether correlation assumptions embedded in risk models are reasonable, tested, and documented. Their scrutiny helps confirm that an organization is not understating aggregate exposure by treating connected risks as independent, and that correlation assumptions have been evaluated under stressed as well as normal conditions.

Inside Risk Correlation

Dependency Between Risks
Risk correlation describes the degree to which two or more risks tend to move together or influence one another, such that the occurrence or severity of one risk relates to the occurrence or severity of another. This relationship may be positive (risks tend to materialize together), negative (one risk offsets another), or negligible.
Common Drivers and Shared Causes
Correlation often arises because distinct risks share an underlying driver, such as a macroeconomic factor, a common vendor, a single technology platform, or a geographic concentration. Identifying these shared causes typically helps explain why risks may cluster during stress events.
Aggregation Effects
Correlation affects how individual risks combine at the portfolio or enterprise level. Where risks are positively correlated, aggregate exposure may be greater than the simple sum of standalone assessments would suggest; where negatively correlated, diversification may reduce aggregate exposure. This bears on enterprise risk aggregation and on assessing whether combined exposures remain within risk appetite.
Directional and Strength Characteristics
A correlation has both a direction (positive or negative) and a strength (from weak to strong). Some frameworks and quantitative methods express strength as a coefficient, though many organizations assess correlation qualitatively through expert judgment, scenario analysis, or dependency mapping rather than through precise statistical measures.
Relationship to Risk Assessment and Scenario Analysis
Correlation is often examined as part of risk assessment, stress testing, and scenario analysis, where practitioners consider how multiple risks might materialize concurrently rather than in isolation. It sits within the broader risk management pillar of identifying and evaluating uncertainty against objectives.

Common questions

Answers to the questions practitioners most commonly ask about Risk Correlation.

Does a correlation between two risks mean that one risk causes the other?
No. Correlation describes a statistical or observed tendency for risks to move together, but it does not by itself establish that one risk causes the other. Two risks may move together because both respond to a shared underlying driver, because of coincidence in a limited data set, or because of a genuine causal link. Distinguishing correlation from causation typically requires additional analysis of the mechanisms involved, and treating correlation as proof of causation can lead to misdirected controls. Where the relationship matters for decision-making, the underlying drivers should be examined rather than inferred from co-movement alone.
If two risks appear uncorrelated in historical data, is it safe to assume they are independent?
Not necessarily. An absence of observed correlation in historical data does not guarantee that risks are independent, particularly under stressed or unprecedented conditions. Correlations often change over time and may strengthen precisely when multiple risks materialize together, so relationships that appear weak in normal periods can intensify during adverse events. Historical measures are also limited by the data available and the period examined. For this reason, many risk practitioners supplement historical correlation estimates with scenario analysis and stress testing, and treat assumed independence with caution.
How should risk correlation be reflected when aggregating risks across a portfolio or enterprise?
When aggregating risks, correlation affects whether individual exposures offset, remain independent, or compound one another. Simply summing individual risk measures typically assumes a relationship that may not hold and can overstate or understate aggregate exposure depending on the correlations present. Many aggregation approaches incorporate correlation assumptions explicitly, and the resulting estimate is only as reliable as those assumptions. It is generally good practice to document the correlation assumptions used, test their sensitivity, and consider how aggregate exposure would behave if assumed relationships changed. Specific methodologies vary by framework, sector, and organization, and quantitative approaches should be validated against the primary sources and modeling standards applicable to the context.
What sources of information can support estimating correlation between risks?
Correlation estimates can draw on historical loss or event data, scenario analysis, expert judgment, and the identification of common underlying drivers such as shared processes, dependencies, or market conditions. Where quantitative data is sparse, structured qualitative approaches and workshops involving subject-matter experts are often used to reason about how risks might move together. Each source has limitations: historical data may not capture future conditions, and expert judgment can carry bias. Combining multiple sources and documenting the basis for estimates typically produces more defensible results than relying on any single method.
How can risk correlation be considered when designing controls?
Where risks are correlated, a single event or driver may affect several risks at once, so controls addressing only individual risks in isolation may leave concentrated exposure unaddressed. Considering correlation can help identify shared drivers where a control might mitigate multiple related risks, as well as points where the failure of one control could coincide with the materialization of several correlated risks. It is generally useful to review whether controls are themselves subject to common causes of failure. Control design decisions should reflect the organization's risk appetite and the applicable framework, and no control should be assumed to eliminate correlated exposure entirely.
How often should correlation assumptions be reviewed?
Because correlations can shift with changing market, operational, and environmental conditions, correlation assumptions are typically reviewed periodically and reassessed following significant events or structural changes that could alter relationships between risks. The appropriate frequency depends on factors such as the volatility of the environment, the materiality of the exposures involved, and any applicable framework or regulatory expectations. Documenting when and why assumptions were last reviewed supports transparency and helps ensure that aggregation and reporting continue to rest on current rather than outdated relationships. Specific review requirements vary by jurisdiction, sector, and organization and should be confirmed against applicable standards.

Common misconceptions

Correlation between risks means one risk causes the other.
Correlation indicates that risks tend to move together, but it does not by itself establish causation. Correlated risks may share a common driver, may influence each other, or may co-move coincidentally. Treating correlation as proof of causation can lead to misdirected controls; the underlying relationship typically needs to be examined separately.
Risks assessed individually can simply be summed to understand total exposure.
Summing standalone risk assessments can misstate aggregate exposure when risks are correlated. Positive correlation may cause exposures to compound during stress events, while negative correlation may provide offsetting effects. Aggregation methods often need to account for these dependencies rather than assuming independence.
Correlation relationships are fixed and can be measured once.
Correlations between risks are often context-dependent and can change over time, particularly under stress conditions when historically weak relationships may strengthen. Relationships observed in normal periods may not hold during crises, so correlation assumptions typically warrant periodic review.

Best practices

Map shared drivers, dependencies, and concentrations (such as common vendors, platforms, or geographies) that could cause otherwise distinct risks to materialize together, rather than assessing each risk in isolation.
Use scenario analysis and stress testing to explore how multiple risks might occur concurrently, giving particular attention to whether correlations may strengthen under adverse conditions.
Document the basis for correlation assumptions, whether derived from data, expert judgment, or dependency mapping, and record their limitations so they can be challenged and reviewed.
Reflect correlation effects when aggregating risks to the enterprise level, and consider whether combined exposures remain within stated risk appetite and tolerance rather than relying on the sum of standalone assessments.
Review correlation assumptions periodically and after significant internal or external changes, recognizing that relationships observed in stable periods may not hold during stress events.
Where quantitative correlation measures are used, be transparent about their assumptions and confidence, and complement them with qualitative judgment rather than treating any coefficient as a precise or permanent value.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps