September 9, 2026 By Yodaplus
Aggregate exposure limits across groups and connected counterparties exist to prevent a bank from unknowingly concentrating risk in what looks, on paper, like several separate borrowers but is in practice a single point of failure. Under the Basel Committee’s large exposures framework, a bank must sum its exposures to a single counterparty and to any group of connected counterparties and keep that combined total below 25 per cent of its Tier 1 capital, with a tighter 15 per cent limit applying between global systemically important banks. Getting this aggregation right, correctly identifying which counterparties are actually connected, is the core challenge behind this calculation.
A bank might lend to three companies that appear entirely independent, have different names, are in different sectors, different locations, and still be carrying a single concentrated risk if those three companies share a parent, rely on the same key customer, or would fail together under the same set of conditions. The Basel Committee’s large exposures standard defines connected counterparties specifically as those that are interdependent and likely to fail simultaneously, a definition built around actual correlated risk rather than superficial corporate structure. Aggregating exposures across these connections is what prevents a bank from breaching the spirit of a concentration limit while technically staying within it at the level of any single named entity.
The purpose of large exposure limits is to constrain the maximum loss a bank could face from the sudden failure of a single counterparty or a connected group, protecting the bank’s ability to remain a going concern. This matters at two levels. At the level of an individual institution, it directly limits how much damage a single default or a single group’s simultaneous failure can inflict on the bank’s capital position. At the level of the broader financial system, the Basel Committee has been explicit that large exposure limits, especially between banks themselves, contribute directly to reducing systemwide contagion risk, limiting how a single firm’s distress can cascade into a broader crisis through a web of interconnected exposures.
Identifying a connected group starts with the more obvious relationships: parent-subsidiary structures, common ownership, and cross-guarantees, where a legal or economic control relationship makes shared failure risk apparent. It extends further into control relationships that are not always immediately visible in a standard corporate registry, shared management, cross-default clauses in financing agreements, and significant economic interdependency, such as a group of companies that all rely on the same single customer, supplier, or funding source. The economic interdependency test is often the harder judgement call, since it requires assessing whether financial distress in one entity would realistically trigger distress in another, not just whether they share a common owner on paper.
Once a connected group is identified, the aggregation itself needs to capture every relevant form of exposure, not just direct loans. This includes on-balance-sheet lending, off-balance-sheet commitments and guarantees, counterparty exposure from derivatives and securities financing transactions, and exposures arising through funds, securitisation structures, or collective investment vehicles where the underlying connected entity bears the ultimate risk. The Basel framework specifically extended coverage to these structures precisely because exposures routed through funds or securitisation vehicles can otherwise obscure a bank’s true aggregate exposure to a connected group.
Banks that manage this calculation well tend to maintain a continuously updated, centralised map of corporate relationships and economic interdependencies across their entire client base, rather than relying on a periodic manual review that can miss recently formed connections. They apply the economic interdependency test rigorously rather than narrowly, actively looking for shared risk that is not reflected in formal ownership structures. They monitor exposures continuously against the aggregate limit rather than only checking at the point a new exposure is originated, since a counterparty’s own financial position, and by extension the risk profile of its connected group, can shift meaningfully after a loan is already on the books. And they report any approach toward the limit early, since the Basel framework requires immediate reporting to supervisors and rapid rectification once a breach occurs, making early detection far preferable to a reactive scramble after the fact.
The most persistent challenge is identifying connections that are not formally documented. A bank can accurately aggregate exposure across a clearly disclosed corporate group while still missing an economic interdependency, several unrelated borrowers who all depend on a single common supplier or customer, that would cause them to fail together under the same stress scenario. Data fragmentation across different business lines within a bank presents a related challenge, since a corporate lending desk and a trading desk may each hold exposure to the same underlying connected group without either team having full visibility into the other’s exposure. Without a centralised view, the aggregate exposure calculation understates true risk simply because no single team sees the complete picture.
AI-driven data analysis can materially improve how banks identify connected counterparties and calculate aggregate exposure. Automated entity resolution and network analysis techniques can surface non-obvious connections, shared suppliers, common funding sources, and cross-default clauses buried in loan documentation that a manual review process focused mainly on formal ownership structures is more likely to miss. AI can also continuously monitor exposure across every business line simultaneously, consolidating a view of aggregate exposure to a connected group in near real time rather than depending on a periodic, manually assembled report that may already be outdated by the time it is reviewed.
Aggregate exposure limits across group and connected counterparties exist to ensure that a bank’s true concentration risk is measured accurately, not understated by treating interdependent borrowers as though they were unrelated. Correctly identifying connected groups, capturing every relevant form of exposure, and monitoring the aggregate continuously against the regulatory limit together protect both the individual institution and the broader financial system from the kind of concentrated, correlated failure these limits were designed to prevent.
Yodaplus supports this kind of rigorous, data-intensive risk analysis directly. It uses Agentic AI to automate financial statement analysis, scenario analysis, peer benchmarking, and report generation, helping institutions bring systematic, continuously updated data into complex exposure calculations while keeping analyst oversight and transparency central to every assessment produced.
Under the Basel Committee’s large exposures framework, a bank’s total exposure to a single counterparty or a group of connected counterparties must not exceed 25 per cent of its Tier 1 capital, with a tighter 15 per cent limit applying to exposures between global systemically important banks.
Connected counterparties are those that are interdependent and likely to fail simultaneously, which can include parent-subsidiary relationships, common ownership, cross-guarantees, and economic interdependencies like shared reliance on a single supplier or customer.
Economic interdependency requires assessing whether financial distress in one entity would realistically trigger distress in another, which is not always visible in a standard corporate registry the way ownership structures typically are.
The calculation includes off-balance-sheet commitments and guarantees, derivatives and securities financing exposure, and exposures routed through funds, securitisation structures, or collective investment vehicles where a connected entity bears the ultimate risk.
AI-driven network analysis can surface non-obvious connections between counterparties that manual review might miss and can consolidate exposure data across different business lines in near real time, giving a more complete and current view of aggregate risk.