All methodology pages

How an asset's impairment risk is estimated

How the eleven permanent-loss mechanisms, their evidence basis, buffers and recovery combine into one asset impairment probability, and how that loss reaches a vault.

Each collateral asset carries one headline figure: the chance that it suffers a permanent-impairment event within one year. This page explains where that figure comes from, what evidence sets it, and how a loss on the asset becomes a loss for a vault.

The eleven mechanismsLink to this section: The eleven mechanisms

An asset can lose value permanently through one of eleven mechanisms. Each is modelled as its own loss channel with an annual probability and a severity if it happens.

  • Backing. The reserves or assets behind the token lose value or go missing.
  • Strategy. A strategy the token depends on loses money.
  • Slashing. A staked position is penalised by the network it secures.
  • Custody. A custodian fails, is compromised, or withholds assets.
  • Bridge. A bridge that carries the asset between chains is exploited or halts.
  • Counterparty. A named counterparty defaults on an obligation the asset relies on.
  • Waterfall. A loss is allocated to this tranche before others by the issuer's own rules.
  • Contract. The token's own contract code fails or is exploited.
  • Governance. A privileged party changes the terms under the holders.
  • Redemption. The route to convert the token into its reference asset stops working.
  • Settlement. A dated claim fails to settle into the asset it promised at maturity.

Not every mechanism applies to every asset. The asset page lists only the mechanisms the assessment admitted for that asset, with the basis each one rests on.

Measured rates, policy priors and class priorsLink to this section: Measured rates, policy priors and class priors

Each mechanism's probability rests on one of four kinds of evidence, and the asset page names which.

Measured. Cork counted qualifying incidents over the exposure years of the asset's own bound record, and the annual rate is the posterior rate from that count. This is the strongest basis.

Class prior. A reviewed release placed the asset in one of Cork's documented collateral risk classes, and the channel uses the stated prior for that class. It is not a measurement of this asset. A bound incident history or a measured reserve attestation for the asset replaces it.

Policy prior. No class and no bound record applies, so the channel uses a named assumption Cork declared for that kind of risk. The assumption is stated, not measured.

Mapped underlying. The asset passes part of its risk to a backing asset nobody has reviewed, and the channel uses Cork's stated prior for an unreviewed backing identity.

Severity rests on the same bases. A prior severity means the mean loss given the event under that prior, not a measurement of this asset.

Beside each mechanism the page shows the annual probability and mean severity it was composed on, the evidence keys that set them, and, where the calibration record states one, the reviewer's own note on what evidence would replace the prior. Where the record states none, the page says so.

The page also opens with a short reviewed description of the asset's class: what the class is, how it can be permanently impaired, and how a liquidator gets out. It describes the class, not the asset, and it sets no figure.

The assumption traceLink to this section: The assumption trace

Where an assessment was made under Cork's asset risk rubric, every mechanism that is being priced carries a short account of its own figure: the annual chance and the mean loss the model actually used, where that figure came from, and what would replace it.

A mechanism with nothing found about it still gets a row. "We looked and found nothing that changes this" and "nobody has written an assumption down" are different statements, and only the second is a gap. The row says which it is, in plain words.

Each modelled loss has exactly one owner. A broad reserve-backing assumption already covers assets lost at a custodian, subordinated away, or never settled, so Cork does not price those separately alongside it unless the broad assumption has been explicitly narrowed. Two assumptions covering the same money would charge for that money twice, and drawing them from the same random event does not fix that.

What evidence can and cannot changeLink to this section: What evidence can and cannot change

Evidence changes a figure by selecting a different one of Cork's own standing assumptions. It never supplies a number of its own, and no source, brand, token name or address selects a favourable figure.

A finding has to be one of a closed list of rules Cork publishes, and it has to cite evidence Cork actually admitted for the run. A claim nobody can resolve to admitted evidence is recorded as context and changes nothing. Several descriptions of the same control count once.

At most one finding sets a mechanism's figure. Where a weakness and a strength are both established, the weakness decides. Every other admitted finding stays on the record so a reader sees the whole picture, and none of them earns any further credit.

A protection against something happening does not also make it cheaper when it happens: the chance and the loss given the event are separate assumptions. A finding that only affects how quickly a holder can get out is recorded against exit and recovery, not against permanent loss, and the row names which of the two spent it.

Where a documented replacement of one of these figures exists, it enters through a versioned, published calibration release that names the exact assumption it replaces. An author's name and a written explanation do not by themselves authorise a different number.

Low and high stress figuresLink to this section: Low and high stress figures

Beside the figure it used, Cork publishes a deliberately low and a deliberately high version of the same assessment. The low case halves every chance and every mean loss; the high case doubles each chance and raises each mean loss by half. Both are capped at certainty.

These are stress tests, not a confidence interval and not an estimate of how uncertain Cork is. They answer one question: if the standing assumptions are wrong by this much, how different is the answer. Both cases are run through the same model, on the same random draws, with every assumption moved together — so they are joint cases, and the individual factors in them do not add up to anything.

Only assumptions are stressed. Where a figure is fitted from incidents that were actually recorded, Cork holds it exactly where it is and says so beside it. Halving and doubling a measured rate would be a statement about the data rather than about an assumption, and this test has nothing to say about the data. Such a mechanism shows its fitted figures and no range, which is not a gap: it is the difference between something Cork assumed and something Cork counted.

An asset whose figures are all fitted therefore has no assumption to stress, and Cork shows no low-and-high comparison for it at all. Where a page mixes the two, only the assumptions move.

Cork shows these two figures only where it has actually run them. Where it has not, nothing is shown rather than a range worked out from the middle figure.

Buffers and recovery nettingLink to this section: Buffers and recovery netting

A mechanism's raw severity is reduced by the buffers that stand in front of holders and by what a holder recovers after the event. Over-collateralisation, an insurance fund, and a junior tranche are buffers. The recovery rate is the share of value a holder gets back through redemption, settlement or sale after the loss. The severity used in the estimate is the loss after these are netted.

The one percent thresholdLink to this section: The one percent threshold

An asset counts as impaired when its value against its economic reference falls by more than one percent and stays there at the one-year horizon. This is the same permanent-impairment event the vault rating uses, at the asset level. A price move that recovers before the horizon is not an impairment. The definition is in the glossary.

The headline probability is the posterior mean of the combined chance that any admitted mechanism causes such an event within the year. The expected-loss effect of each mechanism is the change in the asset's expected loss when that mechanism is removed and everything else is held. These effects do not add to a total, and the interaction residual is recorded beside them.

Adverse sensitivityLink to this section: Adverse sensitivity

The adverse sensitivity is the same estimate read at the ninety-fifth percentile of the posterior instead of its mean. It uses the same admitted mechanisms and the same evidence. It shows how much the headline could move if the evidence supports a higher rate than the mean suggests. It is not a separate scenario and it adds no new assumption.

From asset loss to vault lossLink to this section: From asset loss to vault loss

A vault does not lose money because an asset is impaired. It loses money when the impairment leaves bad debt. The model applies the asset loss as a terminal gap on the collateral path at the end of the year. That gap flows through the market's liquidation rules and the recovery routes described in Asset risk and recovery. If liquidation and recovery repay the loan, the vault's loss is zero. If they do not, the shortfall is bad debt and the vault carries its share of it.

The vault page states this chain for each position: the chance the asset itself is impaired, the chance that bad debt remains if it is, and the average vault loss when it does.

Allocation and loss contribution differLink to this section: Allocation and loss contribution differ

A position's allocation is its share of the vault today. Its loss contribution is the change in the vault's modelled expected loss when the position is removed. A large allocation in a well-covered market can contribute little. A small allocation with thin recovery can contribute much. The two are shown side by side on the vault page and are never combined into one figure.