How a local loss becomes a network event, and why the most important connection may be the one no balance sheet labels clearly.
Failure becomes systemic through a connection
If a restaurant closes, its suppliers and employees may suffer, but the financial system can usually replace the service. A failure becomes systemically important when other participants cannot substitute quickly and their own actions transmit the shock. A counterparty may be unable to pay, a lender may sell similar assets, a payment utility may stop settling, or depositors may withdraw because they expect others to do so.
The BIS defines systemic risk as the risk of disruption to financial services caused by impairment of all or part of the financial system, with serious consequences for the real economy. That definition is deliberately about function, not a fixed list of institutions. It also means that systemic risk is jurisdictional and time-dependent: substitutability, regulation, and network structure can change.
Several channels carry the shock
| Channel | How the shock travels | What a simple exposure measure misses |
|---|---|---|
| Direct contract | A counterparty cannot pay or deliver collateral | Netting, collateral quality, and timing of settlement |
| Common asset | Several institutions sell the same asset and depress its price | Who must sell under stress and how much liquidity remains |
| Funding | Withdrawals or margin calls force rapid asset conversion | Concentration, speed, and the behavior of other funders |
| Operational infrastructure | A payment, clearing, cloud, or settlement service becomes unavailable | Substitutability and the time needed to reroute activity |
| Information and behavior | A public signal coordinates withdrawals or defensive actions | How beliefs change before losses appear in accounts |
These channels can reinforce each other. A falling asset price weakens collateral, which prompts a margin call, which forces another sale. A payment outage can make a solvent firm appear unable to pay, causing customers to conserve cash and extending the outage.
AIG in 2008: interconnectedness mattered
AIG is a documented case of a large institution whose failure could have propagated beyond its own shareholders. The Federal Reserve's account describes exposures through credit-default swaps, securities lending, commercial paper, retirement plans, and banks and insurers that relied on AIG. A default could have forced counterparties to recognize losses and disrupted short-term funding markets at a moment when confidence was already weak.
The case does not show that every large insurer is systemic or that a rescue was the only possible policy. It shows why authorities looked beyond AIG's consolidated assets: the timing of collateral calls, the identity of counterparties, and the lack of immediate substitutes mattered. The same company could have been less dangerous with different contracts, more collateral, or a more resolvable structure.
Why “too big to fail” is incomplete
Size can increase the volume of a shock, but a small clearing utility, specialized insurer, or dominant payment processor may have higher substitutability risk. Conversely, a large firm with separable units and credible resolution plans may be easier to replace than a smaller but tightly connected intermediary.
Network measures also have limits. Reported bilateral exposures omit common customers, rehypothecation, off-balance-sheet guarantees, operational dependencies, and correlated behavior. Models can estimate possible cascades, but a model output is not an observed future. Stress tests therefore need scenarios that include timing, liquidity, substitution, and feedback rather than only capital ratios.
What reduces contagion
- Buffers. Capital, collateral, liquid assets, and operational slack absorb a first loss.
- Transparency. Reliable information can prevent rumors from coordinating unnecessary withdrawals, while disclosure of real exposures enables correction.
- Substitution. Multiple providers, interoperable systems, and tested recovery plans shorten the period in which one failure can block a critical service.
- Separation. Ring-fenced activities and resolvable legal entities can stop a problem in one function from consuming every other function.
- Rules and authority. A contingency plan matters only if someone can activate it, fund it, and access the required systems during stress.
How an investor should reason about systemic risk
Start with the service, not the institution. Identify what the company supplies, who depends on it, and what would happen in the first hour, week, and quarter after interruption. Map direct claims and shared infrastructure, then identify credible substitutes and the resources needed to switch. Distinguish losses that the company bears from losses it can transmit to customers, counterparties, workers, or the public.
Contagion is a mechanism of propagation, not a dramatic synonym for risk. Systemic importance is an inference about network consequences under a specified stress. The more precise conclusion is that resilience depends on the connections, buffers, and substitutes that remain available when participants stop behaving normally.