The warning rarely arrives as a dramatic default notice. More often, your largest customer pays late, your supplier stops answering, a margin call turns into a dispute, or a software provider suffers an outage just when your operations depend on it. Cash leaves faster than expected, goods fail to arrive, and the management team starts asking the same uncomfortable question: how much of our business depends on another party doing what it promised?
That question sits at the centre of counterparty risk, the danger that a customer, supplier, lender, insurer, investment partner, derivatives dealer, or outsourced provider can’t or won’t meet its contractual obligations. The damage can spread beyond an unpaid invoice. A failed counterparty can interrupt production, trigger borrowing pressure, create an insurance claim, expose weak disclosures, or leave your finance team arguing over collateral and loss calculations.
Many businesses assume their credit checks, contracts, and annual accounts provide enough protection. They often don’t. The most serious failures I see arise when finance, procurement, legal, treasury, and operations each hold part of the exposure but nobody joins the evidence together.
When Your Trading Partner Becomes Your Biggest Threat
A mid-market manufacturer may have a preferred supplier for a specialist component, a major customer with extended payment terms, and a bank providing foreign exchange or interest-rate hedging. On paper, each relationship looks manageable. In practice, the business may have one operational dependency, one cash-flow dependency, and one financial-market exposure that deteriorate at the same time.
The first signs look ordinary. An invoice remains unpaid. A supplier asks for faster payment. A trading partner requests amended collateral terms. A service provider reports a “temporary” disruption. Your team treats each event separately because procurement owns the supplier, sales owns the customer, treasury owns the derivative, and IT owns the outsourced platform.
That separation creates the blind spot. Counterparty risk becomes dangerous when exposure accumulates faster than management sees it.
Practical rule: A counterparty problem isn’t limited to the amount on an overdue invoice. Measure the operational and financial cost of replacing the relationship as well.
The failure chain inside a real business
Suppose a key supplier stops delivering. Your operations team buys replacement stock at a higher price, production slows, customers receive late orders, and working capital tightens. The business may then breach a banking covenant or miss a debt payment. If an insurer later reviews a business interruption claim, it may ask whether the loss arose from an insured event, a contractual failure, or a known financial weakness.
A customer default creates a different chain. The unpaid receivable reduces liquidity, the sales team continues supplying because it wants to preserve the relationship, and the finance team records an expected loss without testing whether the customer has connected entities or other payment channels. By the time directors act, the exposure has grown.
Derivatives introduce another route to loss. A counterparty may dispute a margin calculation, delay collateral, or fail while markets move sharply. The legal balance and the accounting balance may not match, especially where netting, settlement timing, and collateral documentation differ.
Why the risk now reaches beyond credit
Supply disruption, reliance on outsourced infrastructure, and stricter margin processes have made counterparty assessment more operational. The UK’s critical third-party regime took effect on 1 January 2025, formalising supervisory attention on important outsourced providers and infrastructure dependencies, not only on traditional financial counterparties. The Bank of England’s financial market infrastructure reporting also shows why central market infrastructure can reduce bilateral exposure while creating a concentration point for systemic risk.
The practical lesson is direct. A counterparty can damage your business by failing to pay, failing to deliver, failing to process, or failing to provide evidence when a dispute begins. Your response needs to identify all four routes before a missed obligation becomes a solvency problem.
Types of Counterparty Risk and Where They Hide
A supplier can create several exposures at once. It may hold an advance payment, provide a critical component, and have no practical replacement. Finance teams that review each contract separately can miss the combined threat.
Four risks finance teams should separate
Credit risk concerns whether the other party will pay or meet a financial obligation. It appears in trade receivables, loans, deposits, guarantees, insurance recoveries, and derivatives. A healthy balance sheet may provide limited comfort if cash is trapped in another group company or payment depends on an internal transfer.
Settlement risk arises between agreement and completion. Your business may deliver goods, currency, securities, or services before receiving the agreed consideration. Incorrect payment instructions, cut-off times, failed reconciliations, and mismatched settlement records can turn a sound-looking transaction into unsecured exposure.
Operational risk concerns the counterparty’s ability to keep delivering. Cloud platforms, freight agents, payroll providers, clearing members, and specialist manufacturers all qualify. An outage, cyber incident, or failed hand-off can cause a loss while the provider remains solvent. For a UK SME, dependence on one logistics platform or outsourced finance process can turn a routine disruption into missed customer obligations.
Concentration risk appears when too much exposure sits with one customer, supplier, bank, insurer, jurisdiction, or service provider. Management may approve every contract individually and still miss the aggregate position. Third-party concentration often hides in shared cloud infrastructure, common subcontractors, or several suppliers owned by the same group.
Wrong-way risk requires separate testing. It occurs when your exposure rises as the counterparty’s ability to pay weakens. A business relying on a struggling customer for both sales and financing can face that pattern. A derivative linked to the counterparty’s sector or currency can create a similar problem.

UK rules turn the risk into a control obligation
UK EMIR requires firms to report derivative contracts to a registered or recognised trade repository, clear eligible OTC derivatives through a central counterparty, and apply operational and margin risk-mitigation techniques to uncleared bilateral trades. The FCA’s UK EMIR overview explains how reporting, post-trade infrastructure, and collateral controls sit alongside credit assessment.
FCA MIFIDPRU rules attach explicit factors to counterparty exposure. The K-TCD counterparty risk factor is 1.6% for central governments, central banks, public sector entities, credit institutions, and investment firms, and 8% for other counterparties, as set out in the FCA MIFIDPRU counterparty risk rules. The same material uses a 1.5 CVA factor for most transactions, affecting how firms account for valuation adjustment risk.
Cross-border contracts require testing of governing law, insolvency treatment, payment systems, and settlement mechanics. the strategic guide to cross border deals offers a starting point for identifying those differences before a dispute limits recovery.
Supplier review should test dependencies, not just financial statements. A structured supply chain audit can map fund flows, delivery control, connected parties, and single-provider exposure. That exercise often reveals the operational failure capable of turning a credit concern into an immediate business interruption.
Measuring Exposure Before It Becomes a Loss
A counterparty limit cannot rest on a credit score alone. Finance teams need four answers: how much is exposed, how likely default is, what recovery may look like, and how quickly the position could worsen. For UK SMEs and mid-market firms, operational disruption belongs in that assessment. A supplier failure can create replacement costs, delayed deliveries, disputed invoices, and a cash shortfall before the accounting loss is confirmed.
Start with the exposure itself
For a straightforward receivable, exposure may start with the unpaid invoice. Derivatives require closer analysis because market values change, netting sets may reduce the amount at risk, and collateral may cover part of the position. The core measures are:
- Probability of default, or PD, the assessed likelihood that the counterparty will fail.
- Loss given default, or LGD, the loss after recoveries, collateral, netting, and insolvency distributions.
- Expected positive exposure, the amount that could remain owed to your business across future market movements.
- Wrong-way exposure, where the counterparty’s financial weakness and the value of your claim move in the same harmful direction.
Separate current exposure from potential future exposure. A derivative with little present value can still create a material replacement cost if the market moves before closure. The same principle applies to a critical outsourced provider. A low invoice balance does not capture the cost of finding a replacement, restoring systems, or meeting customer obligations.
Apply the correct regulatory method
The BIS analysis of UK counterparty credit risk rules notes that simplified SA-CCR is available only when a bank’s derivatives business is at or below 10% of total assets and GBP 260 million, while the original exposure method is available only up to 5% of total assets. Above the relevant limits, more sensitive exposure modelling captures volatility, netting, and collateral effects.
Margin provides a practical control for eligible trades. Variation margin covers current market value exposure. Initial margin covers potential losses between the last margin exchange and the point when the surviving party replaces or hedges the position after default, as explained in the UK EMIR margin technical standards.
A minimum transfer amount can avoid very small collateral movements, but the agreed threshold cannot exceed EUR 500,000, or its equivalent in another currency. Once the amount due exceeds that threshold, the collecting counterparty must collect the full amount due without deducting it, under the PRA and FCA margin framework. In practice, collateral disputes often arise from stale valuations, missing notices, or slow settlement instructions. Those are operational failures with direct cash consequences.
A working capital view for CFOs
| Counterparty Type | Risk Factor | Typical Exposure |
|---|---|---|
| Central governments, central banks, public sector entities, credit institutions, and investment firms | 1.6% | Receivables, deposits, derivatives, and other financial exposure |
| Other counterparties | 8% | Trade balances, contractual claims, and non-financial obligations |
The table shows a regulatory factor, not the amount your business will recover. Internal assessment still needs contract terms, collateral quality, payment history, concentration, and replacement cost. It should also identify shared banks, logistics providers, technology vendors, or parent groups that create third-party concentration across apparently separate counterparties.
For certain central counterparty calculations, UK rules use a 10-business-day margin-period-of-risk standard and require initial margin to be allocated proportionally across mixed accounts without including initial margin in the proportional exposure calculation. The relevant UK legislation matters when legal and accounting teams reconstruct loss after default.
A practical business risk assessment matrix can bring these measures together, provided contract, collateral, settlement, and dependency data remain current.
For firms reviewing the concepts visually, this video provides additional context:
Mitigation Strategies That Deliver Results
No single control eliminates counterparty risk. Due diligence may expose a weak customer, but it cannot protect cash already paid under a poor contract. A termination clause may create a legal remedy, yet it will not replace a specialist supplier quickly.
Match the control to the exposure
For an SME, concentration visibility often delivers the greatest immediate benefit. List the main customers, suppliers, banks, insurers, freight agents, and outsourced technology providers. Then assess what happens if each party stops performing tomorrow. Record replacement time, cash impact, contractual rights, and management ownership.
Mid-market firms usually need a formal limit framework. Set approval thresholds, review connected entities, request updated financial information for material relationships, and document exceptions. Diversification can reduce dependence, but it may raise procurement costs or reduce volume discounts. That trade-off is justified when one failure could stop production.
Financial institutions face more demanding controls. Netting agreements, collateral eligibility, valuation dispute procedures, segregation arrangements, and model governance require specialist oversight. These controls cost money and skilled staff, but informal spreadsheets and undocumented judgement leave greater exposure when markets move quickly.
Contract design matters more than many teams admit
A sound agreement should address payment timing, representations, collateral, default triggers, set-off, netting, termination, governing law, and access to records. Define who calculates collateral, how disputes escalate, and what evidence proves delivery or settlement. Clear terms reduce the risk that a collateral disagreement becomes an unexpected cash loss.
The UK EMIR framework makes reporting, clearing, operational processes, and margining central to derivative risk management. For non-financial contracts, the same discipline remains useful. A contract cannot guarantee recovery, but it can define what each party must do and which remedies are available.
Operational resilience adds another layer. The UK critical-third-party regime took effect on 1 January 2025, so firms should map important outsourced providers, identify substitution options, test continuity arrangements, and retain evidence of oversight. This assessment asks whether the business can continue if a vendor fails, not merely whether that vendor carries insurance.
A cheap supplier is not cheap if replacing it takes long enough to stop your revenue.
Procurement teams seeking to cut supply chain costs should include resilience, payment protection, and substitutability in the assessment. A lower headline price can conceal a much larger concentration loss, especially where one provider also handles logistics, technology, or settlement.

Monitoring and Reporting That Catches Problems Early
A counterparty register only helps if people update it when exposure changes. The finance team should connect contracts, invoices, collateral, settlement records, service dependencies, and disputes in one reporting process. Otherwise, the business may know that a supplier is late, but not that the same group also holds an advance payment and provides a critical logistics service.
Build a dashboard around decisions
A useful dashboard should show:
- Ageing and payment behaviour, including overdue balances, broken promises, payment-plan requests, and unusual changes in settlement patterns.
- Exposure by legal entity, not just by trading name, so connected parties don’t disappear across group structures.
- Collateral status, including calls issued, calls received, disputes, settlement dates, segregation, and eligibility.
- Concentration, measured across customers, suppliers, banks, insurers, jurisdictions, and outsourced providers.
- Operational dependency, showing which services have no tested alternative and which interruptions would affect revenue or production.
- Control evidence, including approvals, reconciliations, exception decisions, and the person responsible for each review.
UK EMIR requires derivative reporting to a trade repository and clearing of OTC derivatives subject to a mandatory clearing obligation through a CCP. Uncleared bilateral trades require risk-mitigation techniques, including operational processes and margining. These obligations should feed the dashboard rather than sit in a separate compliance file.
Make collateral timing visible
The PRA’s counterparty credit risk guidance says firms permitted to use the relevant CRR approach must capture margining effects in effective expected positive exposure. It also states that firms don’t have to estimate initial expected exposure using collateral that has only settled at the calculation time. The PRA supervisory statement on counterparty credit risk therefore has a direct forensic implication: teams must record when collateral legally and operationally counts.
Treasury should own the exposure calculation, legal should own enforceability and default rights, operations should own settlement evidence, and internal audit should test whether the records reconcile. A control that exists only in a policy document won’t withstand a dispute.
The PRA delayed implementation of changes affecting pension obligation risk, market risk, and counterparty credit risk to 1 July 2026, as set out in the PRA’s policy statement and appendix. Firms still adapting should document their transition decisions, identify model and data dependencies, and explain which reports remain provisional.

When Counterparty Risk Becomes a Legal or Insurance Dispute
A failed counterparty quickly changes the question from “how exposed are we?” to “what loss can we prove?” That distinction matters in litigation, insolvency, insurance claims, and shareholder disputes.
A supplier failure may support a business interruption claim, but the claimant still needs to establish the insured trigger, the affected revenue, saved costs, mitigation, and the period of interruption. A contract dispute may turn on whether a margin call was valid, whether collateral had transferred, or whether a party applied the correct netting arrangement.
Forensic accountants reconstruct the timeline. They trace invoices, purchase orders, delivery records, bank movements, margin calls, valuations, correspondence, system logs, and management decisions. Then they separate the counterparty’s breach from losses caused by market movements, pre-existing weakness, avoidable delay, or an unrelated operational event.
The evidence that changes the outcome
Variation margin should cover current market value exposure. Initial margin addresses potential losses between the last exchange and replacement or hedging after default. If the parties used the wrong margin type, calculated the amount incorrectly, or treated unsettled collateral as legally effective too early, the loss analysis can change materially.
Mixed accounts create another problem. UK rules require initial margin allocation proportionally across mixed accounts without using initial margin in the proportional exposure calculation. That allocation can affect insolvency analysis, recoveries, and the amount assigned to individual contract categories.
Internal teams often struggle because they prepared records for operations, not for contested reconstruction. A forensic accountant can test the source data, identify inconsistencies, quantify alternative scenarios, and explain the calculation clearly to solicitors, insurers, directors, or a court. For a practical route into a supplier conflict, see supplier dispute resolution support.
A credible loss model must explain not only what was lost, but why that loss followed from the counterparty event.
Your Counterparty Risk Action Plan
The right first step depends on your role.
- SME owners: List every relationship that could stop revenue, production, delivery, or payment. Identify the largest concentration and the fastest replacement option.
- CFOs: Reconcile receivables, derivatives, collateral, guarantees, and connected entities. Review whether exposure reports use settled collateral correctly and whether exceptions have clear owners.
- Legal teams: Check netting, set-off, termination, governing law, default triggers, evidence requirements, and the enforceability of collateral arrangements.
- Insurers and claims handlers: Establish the counterparty event, insured trigger, mitigation steps, revenue loss, saved costs, and documentation supporting the claimed period.
Cost is a common objection. So is time. Some finance teams believe they can handle the review internally, especially when staff already maintain spreadsheets and contract files. That approach may work for a contained exposure, but it often misses connected-party relationships, duplicated losses, inconsistent valuation dates, and operational dependencies outside finance.
Ask any specialist how they’ll scope the work, protect independence, test source data, handle uncertainty, and present findings to a non-financial audience. Lighthouse Consultants uses a structured engagement model based on free discovery, a scoped action plan, and results reporting. The firm provides forensic accounting, due diligence, risk assessment, internal audit, and loss quantification services for complex financial problems and disputes.
If a supplier, customer, derivatives counterparty, or outsourced provider has created uncertainty, speak with Lighthouse Consultants for a confidential discussion about the exposure, evidence, and practical next steps. Their forensic accountants can help test counterparty controls, quantify financial and insurance losses, and prepare independent analysis that supports negotiation, board decisions, or litigation.



