With GIRR fully built across Articles 9A and 9B, we move to the second risk class: credit spread risk on non-securitised instruments, commonly shortened to CSR non-securitisations. This covers spread risk on ordinary corporate and sovereign bonds and credit default swaps — everything credit-spread-related that does not fall inside the securitisation framework we will cover in Articles 11 and 12.
Unlike GIRR, this risk class fits comfortably in a single article — dense in places, particularly the bucket and correlation structure, but manageable as one connected piece.
The Risk Factor Structure
CSR non-securitisation risk factors are defined across delta, vega and curvature, each with its own dimensional structure.
| Risk Measure | Dimensions | Structure |
| Delta | 2 | The relevant issuer credit spread curves (both bond-inferred and CDS-inferred) × five tenors: 0.5, 1, 3, 5 and 10 years. |
| Vega | 1 | Option maturity only, mapped to one or several of the same five tenors: 0.5, 1, 3, 5 and 10 years. The underlying risk factor is the implied volatility of options referencing the relevant credit issuer names (bond and CDS). |
| Curvature | 1 | The relevant issuer credit spread curve only — with an important nuance below on how “curve” is defined. |
| Why Curvature Treats Bond and CDS Curves as One For curvature specifically, the standard makes a deliberate simplification: the bond-inferred spread curve of an issuer and the CDS-inferred spread curve of that same issuer should be considered a single spread curve, not two separate ones. When calculating curvature sensitivities, all tenors defined for CSR are shifted in parallel together, for that combined curve. This is narrower than delta, where bond and CDS curves for the same issuer are tracked as genuinely separate risk factors (which is exactly why the correlation formula later in this article includes a “same curve” factor at 99.90% rather than 100% — bond and CDS curves for the same name are highly, but not perfectly, correlated under delta). |
Sourced from MAR21.9, including all three sub-points.
The Sensitivity Formula: CS01 (A Quick Recap)
We covered the CS01 formula in full back in Article 8C, alongside the other five delta sensitivity formulas, so we won’t repeat the full derivation here. For completeness: the CSR sensitivity is defined as the CS01 — shift the credit spread cst at tenor t by 1 basis point (0.0001 in absolute terms), and divide the resulting change in the instrument’s market value by 0.0001. This same CS01 definition applies identically across all three CSR sub-classes: non-securitisations, securitisations (non-CTP), and securitisations (CTP).
| s_(k,cst) = [ V_i(r_t, cs_t + 0.0001) − V_i(r_t, cs_t) ] ÷ 0.0001 |
Sourced from MAR21.20 — see Article 8C for the complete treatment alongside the other five delta sensitivity formulas.
The Bucket Structure: Credit Quality and Sector Together
For delta CSR non-securitisations, buckets are defined along two dimensions at once — credit quality and sector — giving 18 buckets in total. Sensitivities must first be assigned to one of these buckets before a risk weight is applied.
| Bucket | Credit Quality | Sector |
| 1 | Investment grade (IG) | Sovereigns including central banks, multilateral development banks |
| 2 | Investment grade (IG) | Local government, government-backed non-financials, education, public administration |
| 3 | Investment grade (IG) | Financials including government-backed financials |
| 4 | Investment grade (IG) | Basic materials, energy, industrials, agriculture, manufacturing, mining and quarrying |
| 5 | Investment grade (IG) | Consumer goods and services, transportation and storage, administrative and support service activities |
| 6 | Investment grade (IG) | Technology, telecommunications |
| 7 | Investment grade (IG) | Health care, utilities, professional and technical activities |
| 8 | Investment grade (IG) | Covered bonds |
| 9 | High yield (HY) & non-rated (NR) | Sovereigns including central banks, multilateral development banks |
| 10 | High yield (HY) & non-rated (NR) | Local government, government-backed non-financials, education, public administration |
| 11 | High yield (HY) & non-rated (NR) | Financials including government-backed financials |
| 12 | High yield (HY) & non-rated (NR) | Basic materials, energy, industrials, agriculture, manufacturing, mining and quarrying |
| 13 | High yield (HY) & non-rated (NR) | Consumer goods and services, transportation and storage, administrative and support service activities |
| 14 | High yield (HY) & non-rated (NR) | Technology, telecommunications |
| 15 | High yield (HY) & non-rated (NR) | Health care, utilities, professional and technical activities |
| 16 | Other sector | Credit quality is not a differentiating consideration for this bucket |
| 17 | — | IG indices |
| 18 | — | HY indices |
Sourced from MAR21.51 (Table 3), including footnote [15] defining covered bonds by reference to the Basel Committee’s large exposures framework, and footnote [16].
Assigning an Issuer to a Sector
To assign a risk exposure to a sector, banks must rely on a classification that is commonly used in the market for grouping issuers by industry — not an internal, bespoke categorisation. Each issuer must be assigned to one, and only one, of the sector buckets in the table above. Where a bank genuinely cannot classify an issuer this way, that risk position must default to the other sector bucket — bucket 16.
Sourced from MAR21.52.
Risk Weights by Bucket
For calculating weighted sensitivities, each of the 18 buckets carries its own flat risk weight, applied identically across all five tenors within that bucket — unlike GIRR, there is no tenor-by-tenor variation here.
| Bucket | Risk Weight |
| 1 | 0.5% |
| 2 | 1.0% |
| 3 | 5.0% |
| 4 | 3.0% |
| 5 | 3.0% |
| 6 | 2.0% |
| 7 | 1.5% |
| 8 | 2.5% (or 1.5% for AA- or higher-rated covered bonds, at the bank’s discretion) |
| 9 | 2.0% |
| 10 | 4.0% |
| 11 | 12.0% |
| 12 | 7.0% |
| 13 | 8.5% |
| 14 | 5.5% |
| 15 | 5.0% |
| 16 | 12.0% |
| 17 | 1.5% |
| 18 | 5.0% |
Sourced from MAR21.53 (Table 4) and footnote [17].
https://www.bis.org/basel_framework/chapter/MAR/21.htm?inforce=20230101&published=20260323
Correlation Within a Bucket: Buckets 1 Through 15
For buckets 1 through 15, the correlation ρkl between two weighted sensitivities within the same bucket is built from three separate factors, multiplied together.
| Factor | Value When Matching | Value Otherwise |
| Name (same issuer?) | 100% if the two names are identical | 35% if the names differ |
| Tenor (same tenor?) | 100% if the two tenors are identical | 65% if the tenors differ |
| Basis (same curve?) | 100% if both sensitivities relate to the same curve | 99.90% if they relate to different curves (e.g. bond vs CDS for the same issuer) |

| The Source Document’s Own Worked Example A sensitivity to the five-year Apple bond curve and a sensitivity to the ten-year Google CDS curve: different names, different tenors, different curves (in fact different issuers entirely, so different curves too). The correlation is 35% × 65% × 99.90% = 22.73%. |
Sourced from MAR21.54, including footnote [18] with the worked example.
https://www.bis.org/basel_framework/chapter/MAR/21.htm?inforce=20230101&published=20260323
Correlation Within a Bucket: Buckets 17 and 18 (Index Buckets)
The two index buckets use the identical three-factor structure, but with one different value: the name factor uses 80% instead of 35% when names differ, reflecting that index constituents tend to move more closely together than individual corporate names.
| Factor | Value When Matching | Value Otherwise |
| Name (same issuer?) | 100% if the two names are identical | 80% if the names differ |
| Tenor (same tenor?) | 100% if the two tenors are identical | 65% if the tenors differ |
| Basis (same curve?) | 100% if both sensitivities relate to the same curve | 99.90% if they relate to different curves |

Sourced from MAR21.55.
https://www.bis.org/basel_framework/chapter/MAR/21.htm?inforce=20230101&published=20260323
The Other Sector Bucket Exception
None of the correlation formulas above apply to bucket 16, the other sector bucket. Instead, this bucket uses a much simpler, more conservative aggregation method that assumes no diversification benefit at all between its risk positions.
For delta and vega risk within bucket 16, the risk position is simply the sum of the absolute values of the net weighted sensitivities allocated to that bucket:

For curvature risk within bucket 16, the risk position takes the larger of the summed positive CVRk+ values or the summed positive CVRk− values:

Sourced from MAR21.56, including both formulas in full.
https://www.bis.org/basel_framework/chapter/MAR/21.htm?inforce=20230101&published=20260323
Correlation Across Buckets 1 Through 16
The cross-bucket correlation parameter γbc for aggregating risk positions across buckets 1 through 16 is also built from a multiplicative structure, this time with two factors.
| Factor | Value |
| Rating (“rating” component) | 50% where the two buckets are both within buckets 1–15 and have a different rating category (one IG, one HY/NR). Otherwise, 100%. |
| Sector (“sector” component) | 100% if the two buckets belong to the same sector. Otherwise, the specific value shown in Table 5 below. |
| γ_bc = γ_bc^(rating) × γ_bc^(sector) |
Table 5 gives the sector component values for every pairing of bucket groups that belong to different sectors. Note how buckets 1 and 9 are paired together in the table (both are the sovereign sector, just different rating categories), and this pattern repeats for each sector through buckets 7/15:
| 1/9 | 2/10 | 3/11 | 4/12 | 5/13 | 6/14 | 7/15 | 8 | 16 | 17 | 18 | |
| 1/9 | — | 75% | 10% | 20% | 25% | 20% | 15% | 10% | 0% | 45% | 45% |
| 2/10 | — | 5% | 15% | 20% | 15% | 10% | 10% | 0% | 45% | 45% | |
| 3/11 | — | 5% | 15% | 20% | 5% | 20% | 0% | 45% | 45% | ||
| 4/12 | — | 20% | 25% | 5% | 5% | 0% | 45% | 45% | |||
| 5/13 | — | 25% | 5% | 15% | 0% | 45% | 45% | ||||
| 6/14 | — | 5% | 20% | 0% | 45% | 45% | |||||
| 7/15 | — | 5% | 0% | 45% | 45% | ||||||
| 8 | — | 0% | 45% | 45% | |||||||
| 16 | — | 0% | 0% | ||||||||
| 17 | — | 75% | |||||||||
| 18 | — |
Sourced from MAR21.57, including both formula components and the complete Table 5. The matrix above is symmetric; only the upper triangle is populated in the source table, with blank cells mirroring the corresponding value on the other side.
What This Means in Practice
A few patterns are worth drawing out from Table 5. Bucket 16 (other sector) has 0% correlation with every other sector bucket — the standard treats it as genuinely unrelated to any classified sector, consistent with the no-diversification treatment it already receives internally under MAR21.56. The two index buckets (17 and 18) correlate at 45% with every non-index sector bucket, and at 75% with each other — reflecting that index instruments, whatever their precise sector composition, share more in common with each other than with any single specific sector.
Looking Ahead
With the full non-securitisation CSR structure now covered — risk factors, sensitivities, buckets, weights, and both layers of correlation — the next two articles turn to credit spread risk on securitised instruments, starting with the correlation trading portfolio (CTP), which borrows most of this article’s structure directly.
Frequently Asked Questions
How many buckets does CSR non-securitisation use?
18 buckets in total, defined along two dimensions: credit quality (investment grade vs high yield/non-rated) and sector, plus a catch-all “other sector” bucket and two index buckets.
What happens if a bank can’t classify an issuer into a sector?
The exposure must default to bucket 16, the “other sector” bucket, which uses a simple sum of absolute sensitivities rather than the standard correlation formula — assuming no diversification benefit at all.
Why is the correlation between a bond curve and CDS curve for the same issuer 99.90% rather than 100%?
The standard treats bond-inferred and CDS-inferred spread curves for the same issuer as related but not identical risk factors under delta, reflecting the small basis risk that exists between bond and CDS markets even for the same underlying name.
Link to Previous Article