Most treasury teams can name their exposures. Far fewer can show, on demand, the policy clause that authorised the last hedge, the limit it was tested against, who approved it, which confirmation matched it, and what the audit committee saw afterwards. That evidence trail is the difference between a treasury risk framework and a set of informed opinions about the market.

The chain usually breaks at the seams. Exposure data sits in one system, the limit lives in a policy document nobody has reopened since the last refinancing, and the accounting treatment gets discovered after the trade. This guide follows the chain end to end across the six exposure classes a corporate treasury normally carries, and marks each point where a handoff has to leave treasury.

Quick answer

A treasury risk framework holds only where each exposure traces to a written limit, a named approver, a matched confirmation and a reported outcome; where that chain breaks, the exposure is unmanaged however well it was hedged.

Decision: Decide which exposures the treasury policy controls, how each is measured and limited, and who approves, confirms and reports every resulting action.

Key takeaways

  • The Association of Corporate Treasurers frames treasury policy as the company’s response to FX, interest-rate, commodity, counterparty, liquidity and funding risk, with operational treasury risk sitting underneath all six.
  • SEC Regulation S-K Item 305 gives three defensible ways to quantify market risk: a tabular presentation, a sensitivity analysis, or value at risk. Choosing one and stating what it hides beats running all three badly.
  • A corporate that elects the CFTC end-user exception must be hedging commercial risk rather than speculating, and an SEC filer has to disclose whether an appropriate board committee reviewed and approved that decision.
  • Recovery after a fraudulent transfer is partial: the FBI’s Recovery Asset Team froze 58% of funds in the incidents it worked in 2025, which makes verification before release the control that matters.

What a treasury risk framework has to control

Treasury risk management is the governed process by which a company identifies the financial exposures created by its operations, funding and cash, measures each one, bounds it with an approved limit, decides and executes a response, evidences that execution, and reports the residual position to the people accountable for it. It is an operating discipline, not a market view.

The Association of Corporate Treasurers describes a treasury policy as “the company’s response to a financial risk such as FX, interest rate, commodity, counterparty, liquidity or funding risk”, and sets out what each policy statement should contain: the cause and potential impact of the risk, the appetite for it, the response, the controls, and the system of risk reporting. That list is a useful test. If a framework cannot answer all five for a given exposure, that exposure is not yet managed. Read the ACT risk framework and treasury policy guidance alongside your own policy.

Six exposure classes cover most non-financial corporates: five are market and credit exposures taken on by operating, and the sixth is the risk that the process handling the other five fails.

Six exposure classes a corporate treasury normally carries, with the measurement and control usually attached to each.
Exposure classWhat creates itHow it is usually measuredThe control that bounds it
Foreign exchangeNon-functional-currency receivables, payables, purchase commitments, forecast flows and net investments in subsidiariesNet exposure by currency and horizon, then a sensitivity to a stated rate moveHedge-ratio band per exposure type and tenor, with a documented forecast-confidence test
Interest rateFloating-rate debt, fixed-rate debt in a falling-rate environment, revolver drawings and invested cashRepricing profile by bucket, then earnings sensitivity to a parallel and a non-parallel shiftFixed-to-floating mix range and a maximum repricing concentration in any one period
Liquidity and fundingTiming mismatch between receipts and obligations, facility maturities, covenant tests and trapped cashMinimum headroom over a stated horizon, plus time to breach under an adverse caseMinimum liquidity buffer, maximum maturity concentration and a committed-facility floor
Counterparty and bankOperating balances, deposits, investments, derivative mark-to-market and undrawn commitmentsExposure by counterparty and tenor against an internal or external credit assessmentPer-counterparty and per-rating-band limits, tenor caps and an approved instrument list
CommodityContracted or forecast physical purchase volumes with floating pricing, and indexed energy or freight termsExposed volume by delivery period multiplied by a stated price sensitivityCoverage band by delivery period, agreed jointly with procurement, and a defined pass-through assumption
Operational treasuryPayment initiation, standing settlement data, market-data feeds, system access and manual interventionException volume and ageing by failed stage, plus loss and near-miss historySegregation of duties, verified static-data change, dual release and mandatory confirmation matching

Ownership is where these frameworks go soft. Treasury usually owns FX, interest rate, liquidity and counterparty. Commodity exposure is often created by procurement and only hedged by treasury, so the exposure inventory and the coverage decision need one named joint owner rather than two partial ones. Operational treasury risk belongs to the process owner, not to the internal audit function that eventually finds the gap.

Start with the policy the rest of the process obeys

A treasury policy is an authorisation document. It says what treasury may do without asking again, what it must escalate, and what it may never do. Six things have to be fixed in writing before measurement or hedging work is worth doing.

  • Mandate and scope. Which entities, currencies, instruments and balance-sheet items the policy covers, and what is deliberately outside it.
  • Risk appetite. Expressed as a tolerable outcome, not a sentiment. “Earnings impact from a 10% adverse move in any single currency pair stays below a stated threshold” is testable; “we are conservative on FX” is not.
  • Permitted instruments. A closed list. Anything not on it requires a policy amendment rather than a judgement call at the point of execution.
  • Limits. Notional, tenor, counterparty, concentration and hedge-ratio bands, each with the measurement basis attached.
  • Delegated authority. Who may approve what, at which value, and what happens when the approver is unavailable.
  • Reporting. What goes to the treasury committee, at what frequency, and what triggers an out-of-cycle report.

Two things should stay out. The first is market opinion, which changes faster than the document can be re-approved. The second is a universal hedge ratio: this guide gives none, and neither should a template. The defensible ratio depends on forecast confidence, natural offsets, margin structure, pricing power and the appetite the board actually signed, and a number lifted from another company’s policy carries none of that. Fix the band and the evidence required to sit anywhere within it.

Identify exposures before you try to measure them

An exposure inventory is the working record of what the company is actually exposed to, refreshed on a stated cycle, built from source systems rather than memory, and reconcilable back to the ledger and the forecast.

Record every exposure with the same minimum fields: legal entity, exposure type, currency or index, gross amount, expected timing, source system, and whether the amount is contracted or forecast, with its confidence if forecast. That last distinction is not administrative. A firm commitment and a probable forecast transaction justify different coverage and, downstream, different accounting treatment.

Three separations do most of the work in FX:

  1. Transaction exposure from booked receivables, payables and commitments, which settles in cash and is the normal hedging target.
  2. Translation exposure from consolidating foreign operations, which moves equity and reported results without an immediate cash effect.
  3. Economic exposure from competitive position and pricing power, which rarely has a clean instrument and is usually managed commercially rather than financially.

Then remove what is already offset. Natural offsets between receipts and payments in the same currency, entity and period reduce the exposure before any instrument is considered, and netting rules belong in writing rather than in practice. Liquidity exposure comes from timing rather than balances, so it needs a forward view: a controlled 13-week cash forecast supplies the near-term shape, with facility maturities and covenant test dates layered over it.

Finally, state the perimeter. Cash the group cannot move without a tax or regulatory consequence is not available liquidity, balances at entities outside the treasury mandate are not covered, and exposures below a stated materiality floor are excluded on purpose, with that floor set in the policy. Feed completeness is itself a control: the choice between APIs, SWIFT and host-to-host determines how quickly a missing account becomes visible.

Measure each exposure with a method you can defend

US registrants already have a defensible menu. SEC Regulation S-K Item 305 requires market risk to be quantified in one of three formats: a tabular presentation of market-risk-sensitive instruments with fair values and contract terms sufficient to determine future cash flows; a sensitivity analysis expressing “the potential loss in future earnings, fair values, or cash flows” from selected hypothetical rate, currency or commodity price changes; or value at risk over a period with a selected likelihood of occurrence. It names interest rate, foreign currency exchange rate and commodity price risk explicitly, and separates instruments held for trading from the rest.

Even without a filing obligation, that framing forces the two questions internal measurement usually skips: what basis is this number on, and what does it exclude?

What each method is good for, and what it hides

A tabular presentation is the honest starting point for interest-rate and debt exposure. Laying out principal by repricing or maturity bucket, with rate and terms attached, shows concentration that a single summary metric conceals. It says nothing about probability.

A sensitivity analysis is the most useful default for corporate FX and commodity work: it converts an exposure into an earnings or cash number a non-specialist can act on. Its weakness is the assumed move. A uniform percentage applied to every currency understates correlated stress, so run at least one non-parallel and one correlated case.

Value at risk compresses a portfolio into one figure at a stated confidence level. It aids comparison across instrument types, but says nothing about the tail beyond that level and depends heavily on the historical window. If used, the window and confidence level belong next to the number every time it is reported.

Liquidity is measured in time rather than value: minimum headroom over a horizon, and the date at which a stated adverse case would breach a covenant or exhaust committed facilities. Item 303 of Regulation S-K asks a registrant to discuss much the same thing, requiring identification of “any known trends or any known demands, commitments, events or uncertainties” that materially affect liquidity, a description of internal and external sources of liquidity, and the remedy proposed where a deficiency exists. Software can carry the calculation, but the requirements it satisfies belong to treasury: that is where a liquidity management software evaluation starts.

Counterparty exposure is measured by concentration and tenor, not rating alone. Include operating balances, term deposits, investments, undrawn commitments and derivative mark-to-market in one view, because they aggregate to a single bank even when they sit in different systems. Deposit protection is a floor, not a plan: the FDIC insures deposits to at least $250,000 per depositor, per insured bank, per ownership category, and does not insure mutual funds, money market mutual funds, stocks or bonds. The working control for corporate cash is a per-counterparty limit, not insurance.

Set limits and run scenarios that force a decision

A limit is only a control if a breach produces a required action. Limits that are reported but never enforced train everyone to treat them as commentary.

Set each limit with four attributes: measurement basis, threshold, observation frequency, and the named consequence of a breach. A counterparty limit measured on month-end balances behaves very differently from one measured on daily peak exposure, and that difference should be a decision rather than an accident of whichever report existed.

Scenarios convert a limit into a decision before the breach arrives. Design them around the company’s own failure modes rather than generic market shocks: a delayed collection from the largest customer, a facility unavailable at renewal, a currency pair that moves while a forecast receipt slips a quarter, a commodity index that resets before a contracted pass-through takes effect, a bank unusable for a week. Each should return the changed position, the first limit breached, the date, the responses actually available, and the owner of each.

Define breach handling in advance: which breaches are passive and self-correcting, which require a report within a stated period, which require a corrective action plan with a deadline, and which require the position to be closed. Record every breach even when corrected quickly, because breach frequency signals a limit set at the wrong level.

Decide, approve and execute a hedge without becoming a trading desk

The line between hedging and speculating is not a matter of intent, and in the US it has a regulatory expression. Under the CFTC end-user exception at 17 CFR 50.50, a non-financial counterparty may elect not to clear a swap used to hedge or mitigate commercial risk, which the rule ties to being “economically appropriate to the reduction of risks in the conduct and management of a commercial enterprise” and not “used for a purpose that is in the nature of speculation, investing, or trading”. The election also carries reporting obligations, including how the entity meets its financial obligations on the swap.

The governance consequence is direct. Where the electing counterparty is an SEC filer, the disclosure includes whether an appropriate committee of the board, or an equivalent body, has reviewed and approved the decision to enter into swaps exempt from clearing. A standing authorisation, minuted and periodically refreshed, is a materially different control from one reconstructed after the fact.

Before execution, the decision record should already contain the exposure and its source, the limit tested and the result, the instrument type and tenor, the rationale for the coverage level chosen within the policy band, the counterparties considered, and the named approver. The record is written before the trade because it is the only version not influenced by the outcome.

At execution, treat the dealer relationship as a control rather than a convenience. Requesting comparable pricing from more than one approved counterparty produces execution evidence and spreads counterparty exposure at once. Dealers also owe disclosure: CFTC Regulation 23.431 requires a swap dealer to disclose material risks, the material characteristics of the swap including its price and material economic terms, any material incentives or conflicts of interest, and a daily mark for uncleared swaps not subject to daily variation margining. Retain those disclosures with the deal record as evidence that the price was understood rather than accepted.

This guide recommends no instrument. Whether a forward, a collar, an option or no hedge at all is appropriate for a given exposure depends on facts specific to the company, and that decision needs the company’s own advisers rather than a published framework.

Confirmations, settlement and the accounting handoff

Execution controls only hold if what was agreed is what gets confirmed, settled and recorded. Three separate failures live here, and they need three separate controls.

Confirmation matching catches a mismatch between the internal deal record and the counterparty’s, and there is a ready-made clock for it. CFTC Regulation 23.501 requires a swap dealer facing a counterparty that is neither a dealer nor a major swap participant to send an acknowledgement “as soon as technologically practicable, but in any event by the end of the first business day following the day of execution”, and to maintain procedures to execute a confirmation by the end of the second business day. A corporate that lets confirmations age past that window has given up its cheapest error detection, and should track unmatched confirmations by age as a standing exception.

Static data control catches the fraud no market limit will stop. Standing settlement instructions, beneficiary bank details and counterparty records should be change-controlled like a payment: requested by one person, verified against a contact detail the company already held rather than one supplied in the request, approved by another, and time-stamped. Payment instruction changes arriving by email are the standard vector, and the losses are not small: the FBI’s Internet Crime Complaint Center recorded business email compromise as the second-largest cyber-enabled fraud category by loss in 2025, at just over $3.04 billion, in a year when total reported losses passed $20 billion.

Recovery, when it works, is partial. The 2025 IC3 annual report records 3,900 Financial Fraud Kill Chain incidents against $1.16 billion of attempted theft, of which $679 million was frozen, a 58% success rate, and stresses that a company discovering a fraudulent transfer should immediately contact its financial institution and request a recall. That supports two controls: verification before release, and a rehearsed recall procedure with the bank contacts already known. Recovering half the money is not a control objective.

Segregation of duties catches the internal case. Deal capture, confirmation matching, settlement release, static-data maintenance and reconciliation sign-off should not collapse into one role, and system administration should not quietly defeat the separation. Where automation does the work, the control question becomes who owns the rule and who reviews overrides: the design problem treasury automation has to solve rather than assume.

The accounting handoff is a boundary, not a step. Treasury owns the exposure, the decision and the execution evidence. Whether the relationship qualifies for hedge accounting, how it is designated and documented at inception, and how effectiveness is assessed are accounting determinations needing a qualified practitioner. Pass the deal record across with the hedged item, the risk being hedged, the objective and the strategy already identified, and let hedge accounting software and its designation controls own the rest. Discovering after execution that a relationship cannot be designated is a treasury planning failure, not an accounting one.

Monitor, escalate exceptions and report

Monitoring is the part most frameworks describe and fewest evidence. Fix the cadence by exposure class rather than running everything monthly: cash position and payment exceptions daily, counterparty concentration and limit utilisation weekly, exposure refresh and hedge effectiveness monthly, policy and limit calibration annually or on a material business change.

Keep one exception register across all six exposure classes rather than a list per system. Each entry should record the exposure or instruction affected, the stage that failed, amount and currency, age, current owner, escalation deadline, action taken and the evidence closing it. An exception closed without evidence appropriate to the failed stage has been filed, not resolved.

Escalation needs named levels and time limits agreed before they are used: a first level inside treasury with a same-day deadline; a second to the group treasurer or CFO for any policy-limit breach or payment irregularity; a third to the treasury or audit committee for a breach that cannot be corrected within the reporting period, a suspected fraud, or a counterparty event. Publish the ladder. A route invented under pressure is not a control.

Reporting runs in two directions. Internally, the treasury committee pack should show exposure by class against limit, utilisation trend, breaches opened and closed, hedge coverage against the policy band, counterparty concentration, liquidity headroom and time to breach under the standing adverse case, and open exception ageing. Externally, US registrants describe their primary market risk exposures, how those exposures are managed including objectives, general strategies and instruments, and changes in either. Under Exchange Act Rule 13a-15, management also evaluates disclosure controls and procedures each fiscal quarter and internal control over financial reporting annually. Treasury processes feeding the financial statements sit inside that scope, which is a practical reason to keep the evidence in a state an external reviewer could follow.

Where systems fit, and where they do not

Nothing here requires a specific product, and no system supplies the policy, the appetite or the approval. What software changes is the cost of running the chain reliably: aggregating exposures from source systems, applying limits at the moment of decision, holding the deal record and its evidence together, and surfacing exceptions while they are cheap to fix.

Treat the tooling question as a separate decision taken after the framework exists. Category scope and evaluation approach belong to a treasury management system selection; cash availability and movement sit with the liquidity software evaluation above; the limit, concentration and stress layer is evaluated in liquidity risk management software; FX category selection and evidence handoffs sit with FX risk management solutions; and automation design and control ownership sit with the automation guide. This page owns the operating framework those systems execute, and stops where product selection begins.

Frequently asked questions

What is a treasury risk?

A treasury risk is a financial exposure created by a company’s operations, funding or cash holdings that can change earnings, cash flow or access to liquidity. The Association of Corporate Treasurers groups these as FX, interest rate, commodity, counterparty, liquidity and funding risk. Operational treasury risk, the risk that the process handling them fails, sits underneath all six.

Who has to approve a corporate hedge before it is executed?

Approval authority comes from the treasury policy, which should name who may approve what at which value. Board involvement can also be a regulatory question: an SEC filer electing the CFTC end-user clearing exception must disclose whether an appropriate board committee reviewed and approved the decision to enter into swaps exempt from clearing.

How quickly should a derivative confirmation be matched?

Use the dealer’s own regulatory clock as the internal target. CFTC Regulation 23.501 requires a swap dealer facing a non-dealer counterparty to send an acknowledgement by the end of the first business day after execution, and to have procedures to execute a confirmation by the end of the second. Track anything unmatched beyond that as an exception.

Continue your research

Keep the decision path moving.