After SS20/15: What Losing the Rulebook Really Means for How Societies Manage Risk

For a decade, SS20/15 did something building societies rarely had to think about: it told them, in reasonably precise terms, where the lines were. Treasury limits. Lending guardrails. A structured framework that, whatever its frustrations, gave societies a shared answer to the question: “how much risk is too much?”

That answer is gone.

With the PRA’s Building Society Sourcebook withdrawn, the prescriptive scaffolding has been removed, and with it, a certain kind of comfort. Societies are no longer being told where the boundaries sit. They’re expected to know, define and prove them for themselves.

But perhaps the more interesting question is not simply how societies replace SS20/15.

It’s what they choose to replace it with.

Freedom with a catch

The PRA’s reasoning was that risk management across the sector has matured enough that it no longer needs to be told how to behave. That’s a compliment, in its way. It’s also a test.

The sourcebook wasn’t just a set of rules. It was a fallback. If a decision sat within the prescribed limits, it was defensible almost by definition. That defence has been withdrawn along with the document. What replaces it isn’t a new checklist. It’s judgement.

And judgement has to be evidenced, not asserted. A board that says “we manage risk prudently” now has to show precisely how, in terms it can defend to a regulator who no longer has a shared script to check them against.

But this creates an opportunity as well as an obligation.

So, what is your risk appetite?

There are broadly two ways a society could respond.

The first is to play it safe. Take the old SS20/15 limits as the starting point, maintain broadly similar guardrails and continue to operate within familiar parameters. There’s nothing inherently wrong with that. For many societies, it may be entirely appropriate.

The second is to ask a more fundamental question:

Now that the rules no longer prescribe the boundaries, what risks are we actually prepared to take?

Perhaps a society wants to lend more aggressively in a particular market. Perhaps it sees an opportunity to take a different approach to treasury management, concentration or funding. Perhaps its mutual model, capital position and strategic objectives mean that the old limits were more restrictive than necessary.

Equally, perhaps the conclusion is that the old limits remain exactly right.

The important point is that the choice is now yours.

This is where risk appetite becomes much more than a document produced for governance purposes.
It becomes a strategic decision about how a society wants to operate – and the reporting needs to reflect that decision.

Where the burden lands

This is where the real shift happens, and it’s less about risk appetite itself than about the reporting underneath it.

A prescriptive rulebook meant that a society’s risk position was, to some extent, self-evident from compliance.
Without it, risk appetite needs to be visible in the data, continuously, not just at audit time.

If you choose to stay broadly within the old SS20/15 parameters, your reporting needs to demonstrate that you are doing so.

If you choose to push beyond them, your reporting needs to demonstrate why those new boundaries are appropriate, where you currently sit against them, and what happens if you approach or exceed them.

Either way, the underlying requirement is the same: you need to understand and evidence your position.

That means boards need reporting that shows current exposure against their own defined limits, not last quarter’s snapshot. It means being able to answer a regulator’s question about lending concentration, treasury exposure or another key risk with evidence pulled together in minutes, rather than reconstructed from spreadsheets after the fact.

It means analytics stops being a back-office reporting exercise and becomes part of the mechanism through which a society demonstrates sound governance.

The new guardrail is internal

None of this is really about replacing one document with another. It’s a shift in where the proof of good risk management sits: from an external rulebook to a society’s own internal reporting, analytics and governance capability.

And that means there is no longer necessarily a single “correct” risk position for every society.
One society may decide that the safest course is to retain limits that look very familiar to SS20/15.
Another may decide that its strategy, capital strength and mutual objectives justify taking a different approach.

Both can be valid, provided the society understands the risks, has defined its appetite, monitors it effectively and can demonstrate that its decisions are informed and controlled.

The real danger is not necessarily taking more risk. It’s taking risk without being able to see it, understand it or explain it.

Societies that treat the end of SS20/15 as a formality risk finding out the hard way that “we always managed this sensibly”
isn’t the same as being able to demonstrate it, on demand, to a board, auditor or regulator.

The societies that get ahead of this won’t necessarily be the ones that recreate the old rulebook most faithfully.

They’ll be the ones that take the opportunity to define their own risk appetite, whether that means staying close to the
old boundaries or deliberately pushing beyond them, and then build the reporting capability to monitor and evidence
those decisions with confidence.

What does your risk appetite look like?

At Connexica, we believe the end of prescriptive SS20/15 reporting presents an opportunity for building societies
to take a fresh look at how they understand and report risk.

Rather than simply recreating the reports of the past, why not start with the decisions you actually need your board to make?

What are your key risks? Where do you want your boundaries to sit? What would you need to see if you were approaching them?
And how quickly could you demonstrate your position today?

The rules may have changed. Your appetite is yours to define.

Connexica helps building societies turn fragmented data into live, board-ready reporting that makes

risk visible, measurable and actionable.

Get in touch to discuss what your risk reporting could look like in the post-SS20/15 environment.

Next
Next

What the Board Actually Needs to See: Cutting Through Data Noise for Better Governance Decisions