Tool/Operations and Risk/No. 0993

Stress Testing

Stress testing is a method of checking how a system copes with severe, defined conditions. Used in engineering and risk management, it exposes weak points and tests resilience, while leaving open what may happen under conditions the test did not cover.

a tool: pick it up

01You've seen this when…

  1. in life

    You sketch next month’s bills with one paycheck missing. Rent clears, but a car repair would push the account below zero.

  2. at work

    Your team tests the checkout service at ten times its usual traffic. It holds until the payment provider slows, then orders pile up.

  3. out in the world

    A city runs an emergency drill with two hospitals unavailable. Ambulances reach the remaining sites, but the receiving wards run out of beds.

02The idea

A household budget, a banking system and a backup generator can all work comfortably under ordinary conditions. Stress testing asks how much of that performance survives when conditions become severe.

Specify a demanding situation, expose the system to it, and measure what happens. The test might use equipment, a computer model, a spreadsheet or a rehearsal. Its value comes from making the pressure concrete: a lost paycheck plus an urgent expense; heavy traffic plus a slow dependency; falling asset prices plus customers withdrawing cash.

Every result is conditional: given these conditions and assumptions, this is how the system behaves. A successful test leaves conditions outside its scope unresolved.

Scenario planning develops different possible futures. Stress testing takes specified conditions and checks their consequences for performance or survival. Sensitivity analysis examines how outputs change as inputs vary; a stress test often combines several changes into one severe situation.

The direction also matters. In reverse stress testing, start with a defined failure and search for conditions that would produce it. Ordinary stress testing starts with conditions and traces their effects.

03How to use it

  1. Define an observable failure. Pick the service or obligation that must survive. A household must cover essential bills. A website must complete purchases within an agreed time. Specify the threshold before seeing results, including how long a temporary breach can last.
  2. Draw the system and its dependencies. Include suppliers, staffing, funding, power, communications and recovery arrangements. Check which supposedly separate safeguards depend on the same resource. A backup that shares the primary system’s power supply offers limited protection against a power failure.
  3. Specify severe conditions. Give each stress a size, duration and sequence. For example: revenue falls 30% for six months while a major customer pays late. Explain why the combination belongs in the test. Include conditions beyond recent experience when the consequences justify examining them.
  4. Choose a safe way to run it. Use a model, isolated test environment or controlled drill as appropriate. Set safety limits, permissions and stop rules. Testing a live hospital or payment system requires protections against harming the people who depend on it.
  5. Measure the path to failure. Record bottlenecks, accumulating backlogs, depleted reserves and recovery time. Follow knock-on effects: retries can overload a struggling service, creating a cascading failure. Vary uncertain assumptions to see whether the conclusion survives.
  6. Change something and test again. Assign an owner to each consequential weakness. Add capacity, reduce dependencies, improve fallback arrangements or revise the plan. Rerun the test after changes, and preserve the assumptions and results so later teams can reproduce them.

Keep the decision attached to the test: what result would trigger extra reserves, a redesign, a smaller commitment or a delay?

04A worked example

In 2009, US supervisors ran the Supervisory Capital Assessment Program, commonly called the bank stress tests. They examined 19 large bank holding companies under baseline and more adverse economic conditions over a two-year horizon. The adverse scenario included higher unemployment and further declines in house prices.

What it looks like A calculation of how much capital each bank would need if the economy deteriorated further. The published results identified 10 firms needing additional capital buffers totaling $74.6 billion.

What’s actually going on Supervisors connected economic conditions to estimated loan losses, earnings and remaining capital. The question was whether banks would retain adequate buffers while absorbing losses and continuing to lend. That required assumptions about both damage and the resources available to absorb it.

What made it work Common scenarios and supervisory review gave the exercise a shared basis, and identified shortfalls led to requirements to strengthen capital. Publishing the framework and results also made the assumptions available for scrutiny. The exercise demonstrates how a test can produce a specific action; it cannot establish that the tested scenario covered every threat or that stress testing alone stabilized the banking system.

05When to reach for it

06When it misleads

  • The chosen stress is too convenient. A team tests a manageable traffic spike while leaving out the slow supplier that would amplify it. Get someone outside the design team to propose difficult combinations and challenge exclusions.
  • The model carries yesterday’s relationships forward. Customers, markets and operators may react differently under pressure. Model risk grows when estimates are pushed beyond the conditions used to build them. Examine alternative assumptions and compare model behavior with observations wherever possible.
  • The test ends before reserves run out. A generator can pass a short drill while fuel supply remains unresolved. A company can absorb one bad month and fail after six. Include duration, replenishment and recovery.
  • People perform differently during the drill. Extra staff, advance warning and unusually attentive operators can flatter the result. Record these advantages and test the arrangements available during ordinary staffing.
  • Passing becomes a blanket certificate. Record the tested conditions beside the result. Keep separate judgments about untested hazards, uncertainty and acceptable risk.

A severe scenario can reveal a vulnerability without providing a reliable estimate of its probability. Use the result to judge exposure and improve resilience; estimate likelihood separately when the decision requires it.

07Roots

At NASA, systems engineers face a practical problem: spacecraft hardware must survive a rocket launch before it can do anything in orbit. Vibration equipment and temperature-controlled chambers let teams examine hardware under demanding loads and environments while it is still on the ground. NASA’s systems engineering handbook places testing within the broader process of verifying that a system meets its requirements.

Stress testing belongs to this older engineering tradition of examining performance under demanding conditions. It has no single generally recognized inventor. Engineers developed different procedures for structures, machines and electrical equipment; computing teams applied related methods to overloaded software and networks. The shared problem was finding weaknesses before operating conditions exposed them at greater cost.

Banks and supervisors developed their own versions around financial losses, funding and capital. The financial crisis exposed weaknesses in pre-crisis practices, including narrow scenarios and poor integration with management decisions. The Basel Committee’s 2009 guidance called for broader coverage and stronger governance. That year’s US bank tests brought the method into public view, and later supervisory standards formalized its use. Across these settings, the technique became most useful when findings changed what people built, held in reserve or prepared to do.

08How solid is this?

ContestedMixedUsefulEstablished

Established as an engineering and supervisory risk-assessment method. Physical tests support claims about the tested conditions; simulation results depend on models and inputs. Neither establishes safety across every possible stress.

09Connections

confused withconfused withconfused withconfused withcounterscounterscounterscounterscounterscountersStress TestingRed TeamingScenarioPlanningSensitivityAnalysisNot written yetReverseStress TestingFat-TailedDistributionsRisk of RuinNot written yetNormalcy BiasNot written yetModel RiskOptimism BiasNot written yetCascadingFailure

+ 2 more in the list

10Origin and sources

Developed across engineering and risk-management traditions, without a single generally recognized inventor. Banking supervisors formalized financial stress testing, with prominent applications during the 2009 US bank assessments.

  1. [1]National Aeronautics and Space Administration (2016). NASA Systems Engineering Handbook. NASA/SP-2016-6105 Rev2.
  2. [2]Board of Governors of the Federal Reserve System (2009). The Supervisory Capital Assessment Program: Overview of Results. May 7.
  3. [3]Basel Committee on Banking Supervision (2009). Principles for sound stress testing practices and supervision. Bank for International Settlements.
  4. [4]Basel Committee on Banking Supervision (2018). Stress testing principles. Bank for International Settlements.

Suggest an edit· Updated 2026-10-02