Work · Risk · Portfolio

15 min From limit breach to an alert in someone’s hands

A lending portfolio is a set of promises about how concentrated it will get. We built a system that checks those promises continuously and puts a breach in front of the right person within 15 minutes, not at the next committee meeting.

15 min

Alerting

Limits

Concentration and exposure limits

Always on

Watched continuously

01The problem

Firms that lend or invest set limits on how much of the book can sit in one place. So much per borrower, per industry, per geography, per product. The limits live in a policy document. The book lives in a database. Nothing connects the two.

In practice, someone checks the limits by pulling data into a spreadsheet. That happens weekly or monthly, and it happens after the fact. A breach can sit unnoticed for weeks while new deals keep stacking exposure in the same corner of the book.

By the time the breach surfaces in a committee pack, it is no longer a small adjustment. It is a finding. It gets minuted, explained, and remediated under scrutiny that a quiet early fix would never have attracted.

02What we built

We turned the limit framework from a document into running code. Every limit in the policy, concentration by borrower, industry, geography, and product, became a rule the system evaluates against the live portfolio.

  • The portfolio is watched continuously. Every new position and every change to an existing one is checked against the full limit set as it lands, not on a reporting cycle.
  • Alerts route to the person who owns the limit, with the position, the limit, and the distance to breach in the message. No dashboard hunting required.
  • Warning thresholds fire before the hard limit does, so most alerts arrive while there is still room to steer.
  • Every check and every alert is logged, which gives risk and audit a clean record of when a breach happened and who knew.

Nothing about the firm's policy changed. The limits are the same ones the committee already approved. What changed is how often anyone looks.

03What changed

The gap between a limit breach and a human knowing about it went from weeks to 15 minutes. A breach now arrives as a message in someone's hands while it is still a small problem, not as a line in a committee pack after it has grown.

Concentration and exposure limits are watched continuously instead of sampled on a reporting cycle. There is no window where the book can drift out of policy unobserved.

Committee meetings changed shape. Instead of discovering breaches, the committee reviews how they were handled. The conversation moved from what happened to what we did about it.

The team stopped maintaining the spreadsheet. The hours that went into pulling and reconciling data each cycle now go into acting on what the system surfaces.

A real engagement, anonymized. Client details are withheld under confidentiality.

Next step

Have limits that only get checked at month end?

If your limit framework lives in a policy document and a spreadsheet, we can turn it into a system that watches the book continuously and tells the right person before a small problem becomes a committee problem.

More work