Skip to main content
Category: Risk Classification & Tiering

Systemic Risk

Also known as: systematic financial risk
Simply put

Systemic risk is the possibility that trouble at one company or in one part of a market could spread and destabilize or collapse an entire industry, market, or economy. Unlike a problem confined to a single firm, systemic risk is about widespread failure that cannot be avoided simply by spreading investments across different entities. It is most commonly discussed in the context of the financial sector.

Formal definition

In many financial-sector frameworks, systemic risk refers to the risk that instability becomes sufficiently widespread that it impairs the functioning of an entire financial system or market, as distinct from the idiosyncratic risk associated with any single entity. As commonly defined, it is a non-diversifiable, system-wide risk that can propagate through interconnections and contagion, such that a company-level event may destabilize the broader industry or economy. This entry describes the concept as used in financial supervision and monitoring (for example, in the context of the largest banks); its meaning and measurement can vary by jurisdiction and by the framework applying it, and the evidence provided here does not address any AI-specific or non-financial usage of the term.

Why it matters

Systemic risk matters because it captures a category of harm that ordinary risk management techniques cannot fully address. Diversification—spreading exposure across many entities—can reduce idiosyncratic risk tied to any single firm, but it offers little protection when instability propagates across an entire financial system or market. As commonly defined in the sources reviewed here, systemic risk concerns the possibility that a company-level event could destabilize or collapse an entire industry or economy, which makes it a supervisory concern rather than solely a firm-level one.

Because of this system-wide character, systemic risk is a focus of financial supervision and dedicated monitoring efforts. The U.S. Office of Financial Research, for example, maintains a Bank Systemic Risk Monitor described as a collection of key measures for monitoring systemic risks posed by the largest banks. This reflects a broader supervisory practice of tracking large, interconnected institutions whose distress could spread through the system, though the specific measures, thresholds, and institutions in scope vary by jurisdiction and by the framework applied.

It is important to be precise about scope. The evidence provided here addresses systemic risk as used in the financial sector and in financial supervision; it does not establish any AI-specific or other non-financial meaning of the term. Readers should not assume the financial-sector concept described here transfers directly to other domains without a framework that defines it for that context.

Who it's relevant to

Financial supervisors and central banks
Supervisory bodies monitor systemic risk to identify where instability could impair the functioning of a financial system. The evidence here reflects this in tools such as the OFR Bank Systemic Risk Monitor and in ECB discussion of widespread financial instability. The specific measures and institutions in scope vary by jurisdiction.
Large and interconnected financial institutions
Institutions whose distress could propagate across markets—such as the largest banks referenced in the OFR monitor—are a central focus of systemic risk analysis. For these firms, systemic considerations extend beyond firm-level, idiosyncratic risk to how their failure or distress might affect the broader system.
Risk managers and analysts
Those managing portfolio or institutional exposures should recognize that systemic risk is described as non-diversifiable, meaning it cannot be eliminated by spreading investments across entities. This distinguishes it from idiosyncratic risk and shapes how it must be treated in analysis.
Policy and regulatory specialists
Because the definition and measurement of systemic risk can differ by jurisdiction and framework, professionals working across regulatory regimes should confirm how the term is scoped in each context rather than assuming a single authoritative definition applies universally.

Inside Systemic Risk

Cross-system propagation
Systemic risk, as commonly framed, concerns harms that spread beyond a single model or institution to affect an interconnected system as a whole. It focuses on the potential for failures, correlated behaviors, or shocks to cascade across dependent components rather than remaining contained.
Interconnectedness and concentration
A central element is the degree to which entities, models, data sources, or providers are linked or concentrated. Widespread reliance on a shared model, dataset, or vendor can create a common point of failure that amplifies impact across the system.
Sector-specific meaning
The term carries distinct meanings across contexts. In financial regulation it historically refers to threats to the stability of the financial system; in certain AI regulatory discussions it may refer to risks posed by particularly capable or widely deployed models. These usages should not be assumed interchangeable.
Distinction from idiosyncratic or model-level risk
Systemic risk is typically contrasted with risk confined to an individual model or firm. Model risk management, as historically framed by guidance such as SR 11-7 / OCC 2011-12, primarily addresses risks arising from a given institution's model use, which is related to but narrower than system-wide risk.
Amplification and feedback dynamics
Systemic risk often involves feedback loops, herding, or correlated responses where many actors behave similarly, potentially magnifying an initial disturbance. This dynamic dimension distinguishes it from static, single-point assessments of risk.

Common questions

Answers to the questions practitioners most commonly ask about Systemic Risk.

Is systemic risk just another term for a large or high-impact model risk?
No. High impact at the level of a single model or institution is not the same as systemic risk. Systemic risk, as commonly framed, concerns the potential for failures to propagate across interconnected entities or markets and threaten the stability of the broader system, rather than the severity of harm confined to one organization. A model can carry high inherent risk to its owner without being systemically significant, and conversely, individually modest exposures can aggregate into systemic concern. Treat the two as related but distinct.
Does the term 'systemic risk' mean the same thing in banking regulation as it does under the EU AI Act?
Not necessarily, and professionals frequently conflate these usages. In financial-stability contexts the term typically refers to risks that could destabilize the financial system. Some AI-specific instruments use 'systemic risk' language in connection with certain high-capability or widely deployed models, which is a different framing tied to that instrument's scope. Because the definitions are context- and jurisdiction-dependent, you should identify which framework's meaning applies before relying on the term, and avoid assuming the definitions are interchangeable.
How should we distinguish systemic risk from institution-level model risk in our risk taxonomy?
In many frameworks it helps to record whether a risk is contained within the organization or has propagation potential across counterparties, shared infrastructure, common models, or correlated behavior. Institution-level model risk is typically captured through inherent and residual risk assessments for individual models. Systemic considerations, where relevant to your mandate, are usually a separate dimension addressing interconnection and concentration. Keeping these as distinct fields, rather than a single severity score, reduces the risk of collapsing the two concepts.
Who typically owns responsibility for identifying potential systemic exposures across models?
Ownership varies by organization and is not universally prescribed. Under a common three-lines-of-defense structure, first-line owners understand individual model use, while second-line functions such as risk management often aggregate exposures to assess concentration and interconnection. Where systemic questions extend beyond the institution, they may fall to enterprise risk, compliance, or external supervisory bodies rather than a single model owner. Confirm the allocation against your own governance policies rather than assuming a standard assignment.
What kinds of indicators do teams commonly monitor when assessing systemic exposure?
Practices differ, but organizations frequently look at concentration (reliance on a shared model, vendor, or data source), interconnection (how outputs feed downstream systems or counterparties), and correlation (whether many actors would respond similarly under stress). These indicators help characterize propagation potential rather than the severity of a single failure. Note that monitoring supports the management and reduction of such risk; it does not eliminate it, and the appropriate indicators depend on your sector and mandate.
How does systemic risk relate to our existing model validation and monitoring activities?
Validation and ongoing monitoring typically assess whether an individual model is sound and performing as intended, which is necessary but not sufficient for systemic questions. Systemic assessment generally requires looking across models and beyond the organization at aggregation, shared dependencies, and interconnection—dimensions that per-model validation is not designed to capture. Many teams therefore treat systemic considerations as a complementary, portfolio- or enterprise-level activity layered on top of standard model risk management, and scope it according to what their regulatory obligations actually require.

Common misconceptions

Systemic risk is just the sum of individual model risks aggregated across an organization.
Systemic risk is not simply an aggregation of model-level risks. It arises from interconnectedness, concentration, and correlated behavior across systems or institutions, and can emerge even where each individual component appears adequately controlled. Managing model risk at the entity level does not, on its own, address system-wide dynamics.
The term "systemic risk" means the same thing in every regulatory and technical context.
The term has contested and sector-specific meanings. Its use in financial stability contexts differs from usages that may appear in AI-specific regulatory discussions, and these should not be treated as equivalent. Practitioners should confirm which definition applies within their jurisdiction and framework.
Strong AI governance and model risk controls eliminate systemic risk.
Governance structures and risk controls are measures that can reduce or help manage systemic risk, not eliminate it. Because systemic risk depends on factors beyond any single organization's controls, residual system-wide risk can persist despite robust internal oversight.

Best practices

Clarify at the outset which definition of systemic risk applies in your context, distinguishing financial-stability usage from AI-specific usage, and document the jurisdiction and framework you are relying on.
Assess interconnectedness and concentration explicitly, identifying shared models, datasets, providers, or dependencies that could act as common points of failure across the system.
Complement entity-level model risk management with analysis of correlated behavior and propagation pathways, recognizing that controls adequate at the individual model level may not address system-wide dynamics.
Coordinate assessment across governance and model risk management functions, keeping their roles distinct while ensuring system-level concerns are not left unowned between them.
Frame governance and control measures as tools that reduce or manage systemic risk rather than eliminate it, and track residual system-wide exposure accordingly.
Reassess periodically, since interconnections, concentrations, and the regulatory treatment of systemic risk can evolve over time and vary by sector.