The views expressed are the author’s and do not necessarily represent those of the World Bank. This note summarizes Millischer (2026), “A Model Case for Simplification in Europe: Internal Ratings, Better Calibrated“, World Bank, September 2026.
Abstract
Regulatory simplification has become a central objective of European financial policy. While the proposed reforms trim process and reporting, one of the most complex and resource-intensive parts of the prudential framework, the Internal Ratings-Based (IRB) approach to credit risk, is touched only at the margin. Its design lets banks estimate the parameters that determine their own capital charges, creating a permanent incentive to underestimate risk and a costly regulatory and supervisory apparatus to contain it. This note proposes a “standardized IRB” approach: the regulator calibrates the credit risk models centrally on banks’ pooled loan-level data, keeping the Basel risk-weight function and bank-specific through-the-cycle calibration. A meaningful simplification of the IRB framework would have to satisfy five objectives: risk sensitivity, comparability across banks, cost efficiency, Basel compatibility and stability through the cycle. Of six IRB reform paths assessed against them, the standardized IRB approach is the only one that meets all five: most of the regulatory and supervisory apparatus around bank-developed models becomes redundant, while the level and risk sensitivity of capital requirements are largely unchanged. A pilot on one portfolio is proposed as the next step.
Regulatory simplification has become a central objective in European financial policy. The Draghi report identifies regulatory burden as a structural impediment to growth and calls for a systematic reduction in compliance costs [Draghi, 2024]. The European Commission’s targeted consultation on banking sector competitiveness devotes an entire chapter to the complexity and effectiveness of the regulatory framework, the ECB’s High-Level Task Force on Simplification has formulated recommendations for the prudential, supervisory and reporting framework, and the European Banking Authority (EBA) has published a discussion paper on the simplification of the credit risk framework [European Banking Authority, 2026a].
One of the most complex and resource-intensive layers of that framework, the Internal Ratings-Based (IRB) approach to credit risk, is largely absent from the debate. The reforms under way address reporting, approval processes and, inside the IRB framework, optional simplifications of individual estimation requirements. The structure that generates most of the burden, the bank-by-bank development, validation and supervisory approval of credit risk models, is left untouched.
That the IRB framework is too complex is not a new observation, and the institutions responsible for it have said so themselves. Haldane’s “dog and the frisbee” argued in 2012 that complex, model-based capital regulation was not merely costly but counterproductive [Haldane and Madouros, 2012]. After its Targeted Review of Internal Models (TRIM), the ECB now encourages banks to decommission models for portfolios that are difficult to model [European Central Bank, 2021]. The EBA’s discussion paper on the credit risk framework, cited above, acknowledges that “the burden on modeling and the related supervisory review process is high” [European Banking Authority, 2026a]. The Eurosystem’s response to the Commission’s consultation encourages banks to confine internal models to their strategic portfolios and to use the standardized approach elsewhere [Eurosystem, 2026], and the European Banking Federation calls the IRB approval process “very burdensome and lengthy for both banks and supervisory teams” [European Banking Federation, 2025]. All of these initiatives remain within the boundaries of the current framework.
This note argues that a small set of regulator-calibrated credit risk models can deliver comparable risk sensitivity at a fraction of the current cost, without raising or lowering the level of capital. The proposal is deliberately specific. Calls for simplification are easy to agree with and difficult to act on; a concrete alternative can be assessed, criticized and tested.
The IRB framework was built on a sound premise: capital calibrated to measured risk allocates bank capital more efficiently than any flat regulatory schedule. When a regulator assigns a single risk weight to a broad category of exposures, as the standardized approach does, prudence requires that the weight also cover the riskier borrowers in the bucket, and the safer ones pay for it. Granular measurement removes that blanket conservatism, and the Basel risk-weight formula adds a second, mechanical reward: it charges less for a portfolio of differentiated borrowers than for the same borrowers treated as one average. An unrated corporate carries a flat risk weight of 100 percent under the standardized approach (SA); under IRB, a high-quality corporate with a probability of default (PD) of 10 basis points and a loss given default (LGD) of 45 percent attracts about 30 percent, and a weaker one with a PD of 2 percent about 115 percent. Before the Basel III output floor, average risk-weight densities under IRB were roughly half those of comparable portfolios under the standardized approach [Pérez Montes et al., 2018]. It is this granularity, the ability to distinguish good risks from bad within each asset class, that constitutes the economic benefit of the IRB framework.
The IRB approach entrusts banks with estimating the very parameters that determine their own capital charges: the PD and, under the advanced variant, the LGD and the exposure at default (EAD). Lower estimates translate mechanically into lower risk weights, less capital and a higher return on equity. The framework therefore contains a permanent incentive to underestimate risk.
For a mid-sized European bank with EUR 100 billion of credit risk-weighted assets, a uniform reduction of 10 basis points in estimated PDs, from 1.0 to 0.9 percent, lowers risk weights by about 3.5 percentage points, frees some EUR 570 million of capital and saves roughly EUR 40 million a year in funding costs. For a large bank with EUR 500 billion of credit risk-weighted assets the annual saving approaches EUR 195 million, about 2 percent of net income. The effect is strongest for the safest borrowers, where a small change in PD moves the risk weight most, and that is precisely the investment-grade segment where banks compete hardest on price.
In the early years of IRB adoption, banks were found to follow that incentive: IRB risk weights were associated with higher subsequent default rates than their level implied, the reduction in risk weights after IRB approval was largest among weakly capitalized banks, and banks with lower capital ratios reported systematically lower PDs for the same borrowers than better-capitalized peers [Behn, Haselmann and Vig, 2022; Mariathasan and Merrouche, 2014; Abbassi and Schmidt, 2018].
Figure 1. Self-reported speed

Following these findings and the global financial crisis, regulators set out to repair the framework, first through the Basel Committee’s post-crisis reforms and then, in the EU, through the EBA’s harmonization of estimation methodologies and the ECB’s review of every significant bank’s internal models in TRIM. The repair has worked where it can be verified. In high-default portfolios, those with enough defaults to test estimates against outcomes, estimated PDs now exceed observed default rates on aggregate across all major asset classes [European Banking Authority, 2025]. In low-default portfolios, such as exposures to large corporates or financial institutions, where defaults are too rare for such a test, whether the incentive is contained cannot be established from data at all. And the repair has required an apparatus of considerable size.
The apparatus has three layers: the rules that constrain the models, the supervisors who inspect them, and the staff and consultants in banks who build, validate and defend them. The regulatory layer has grown by layering constraint upon constraint on the modeling process. At the international level, the Basel Committee introduced input floors on PD and LGD estimates, an aggregate output floor that caps the capital benefit of internal models at 27.5 percent relative to the standardized approach, and a leverage ratio that bypasses risk weighting altogether. Each of these expresses distrust in bank-produced risk estimates. At the European level, the principal regulatory and supervisory texts governing IRB models, from the Capital Requirements Regulation through the EBA’s technical standards and guidelines to the ECB’s Guide to Internal Models, amount to over 1,000 pages, excluding Q&As, national guidance and consultation papers. Within them, margins of conservatism, ex-ante notification requirements and prescriptive estimation methodologies constrain the modeler’s degrees of freedom at every step.
The supervisory infrastructure needed to police the framework is substantial. At the ECB, a dedicated Internal Model Investigations Division exists to assess and challenge bank-developed IRB models. In a normal year the ECB launches 70 to 100 internal model investigations, each lasting several months. TRIM, conducted from 2017 to 2021, involved 161 on-site investigations of credit risk models across 65 significant institutions, identified more than 5,800 deficiencies [European Central Bank, 2021]; with about 15 percent of the SSM budget invested in it, TRIM was the largest single project investment in the history of ECB Banking Supervision [European Central Bank, 2017]. Every major national authority maintains comparable structures. Across the EU, the supervisory workforce dedicated to IRB oversight likely exceeds five hundred, and the IMF’s 2025 assessment of the euro area still found internal model oversight structurally under-resourced, with the ECB compelled to operate a triage system [International Monetary Fund, 2025].
The bank side carries the larger part of the cost. Each IRB institution maintains separate model development, independent validation and internal audit functions, as the regulation requires. In a large bank operating IRB models across several countries and asset classes, the dedicated IRB workforce typically numbers 60 to 80 full-time equivalents, and exceeds 100 in some cross-border groups. A substantial consulting industry supplements this effort: every major advisory firm maintains a dedicated IRB practice in Europe, and specialist firms have built their business models around IRB compliance. Taken together, bank staff, external consulting and the supervisory apparatus described above are estimated to cost the European banking system EUR 0.7 to 1.2 billion a year. Beyond the direct cost, the framework ties up thousands of quantitative specialists in banks, supervisors and consultancies whose task is to develop, validate or review models whose outputs are then overridden by floors, margins and supervisory add-ons.
Figure 2. Supervised self-measurement

Despite this apparatus, the framework fails to deliver consistent risk measurement across banks. The EBA’s benchmarking exercises document persistent and wide dispersion in the PDs that different banks assign to similar exposures. Less than half of that cross-bank variation can be explained by differences in observed default rates; the remainder reflects modeling choices, calibration horizons and prudential adjustments [European Banking Authority, 2025]. The dispersion is largest in low-default portfolios, where defaults are too rare to validate any model against outcomes and where, consequently, the incentive to underestimate cannot be controlled after the fact.
The inconsistency also distorts competition. A bank that achieves lower PDs for the same borrower, whether through better insight or more aggressive calibration, holds less capital and can price more keenly, most of all in the investment-grade segment. Banks on the standardized approach cannot follow: facing a flat 100 percent risk weight on an unrated corporate, they cannot match the pricing of an IRB bank holding a third of the capital for the same loan. Access to lower capital requirements is decided by whether a bank can afford an IRB apparatus; the risk of its lending plays a secondary role.
Where does this leave the design of an alternative? The discussion so far points to three objectives that any simplification of the IRB framework should meet: it should preserve risk sensitivity, restore cross-bank comparability and reduce cost. Two further objectives follow from the constraints under which European regulation operates: compatibility with the Basel framework and stability of capital requirements through the cycle. The five are stated here in their own right, before any solution is introduced, because they apply to every reform initiative, including those assessed in section 6.
The first is risk sensitivity: capital charges must reflect the underlying risk of each exposure. This is the economic contribution of the IRB framework and the reason it was introduced; when capital reflects the creditworthiness of each borrower, banks can extend more credit for a given amount of loss-absorbing capital without adding to financial stability risk. An alternative meets this objective when its risk weights reflect differences in default risk that can be demonstrated statistically against observed outcomes.
The second is cross-bank comparability: two institutions holding similar portfolios should face similar capital charges. Some variation in estimated parameters is inherent to modeling under uncertainty and does not by itself indicate failure. In high-default portfolios it is bounded, because estimates can be backtested against realized defaults; in low-default portfolios no such discipline exists, and that is where cross-bank variation is largest today. An alternative meets this objective when the variation that remains can be traced to observable differences in risk rather than to unverifiable modeling choices.
The third is cost efficiency: the resources devoted to the framework should be proportionate to the risk sensitivity they deliver. The current apparatus absorbs an estimated EUR 0.7 to 1.2 billion a year and thousands of quantitative specialists. An alternative meets this objective when it delivers comparable risk sensitivity at substantially lower aggregate cost.
The fourth is compatibility with the Basel framework. The EU’s prudential standards derive part of their credibility from consistency with internationally agreed norms, and any departure invites scrutiny under the Basel Committee’s consistency assessments and doubts about the comparability of EU capital ratios. An alternative meets this objective when it can be implemented within the existing Basel architecture, preserving the risk-weight function and the minimum standards for parameter estimation, without reopening the international agreement.
The fifth is through-the-cycle stability: capital requirements should remain broadly stable across the economic cycle. Procyclical requirements force banks to raise capital or cut lending precisely as the economy weakens. The Basel framework addresses this by requiring long-run average and downturn parameters under IRB and by assigning largely flat risk weights under the standardized approach. An alternative meets this objective when risk-weight densities do not rise in a downturn.
These objectives are not ranked. Section 6 applies all five to the proposal and to five competing reform paths.
The proposal keeps the formula and changes who calibrates it: the EBA estimates the credit risk models centrally on banks’ pooled loan-level data, and the Commission adopts them through regulatory technical standards; banks supply the data and apply the models. The result can be called a “Standardized IRB approach”: the same institutional logic as the standardized approach, in which the regulator sets the parameters and banks apply them, but with a calibrated model in place of a table. Banks should meanwhile keep running their own, unconstrained internal models for underwriting, pricing and monitoring, rather than the heavily constrained regulatory ones. Good risk management requires point-in-time, agile models, and the proposal frees banks to build them.
The core of the Basel IRB approach is unchanged. Risk weights remain a function of borrower-level PD and exposure-level LGD through the unchanged Basel risk-weight function at the unchanged 99.9 percent confidence level; risk sensitivity at the level of the individual borrower is retained; and calibration remains bank-specific and through the cycle. The classification of portfolios into high-default and low-default segments, and the definition of model perimeters within them, become central regulatory decisions rather than bank-by-bank choices.
The proposal starts with PD. For high-default portfolios (residential mortgages, small and medium-sized enterprises, consumer credit and mid-market corporates), the EBA calibrates one logistic PD model per portfolio every five years on anonymized loan-level data pooled from all participating banks, using five to ten standardized explanatory variables. Each bank then sets a single constant every year so that the average PD of its current portfolio equals its own long-run average default rate, computed over at least ten years and adjusted by the supervisor where the window contains no stress episode. The same model therefore operates at every bank and ranks borrowers by the same criteria; the level of PDs is bank-specific. The mechanism is self-correcting, since a bank whose lending is riskier accumulates a higher default rate and a higher constant; it requires no supervisory judgment about model conservatism, and involves no model development, no validation infrastructure and no model approval at the bank. Because the constant is anchored to a long-run average, a single bad year moves it by at most a tenth of its magnitude, which is what keeps capital requirements stable through the cycle. The concept is not without precedent: seven euro-area central banks already run in-house credit assessment systems, which estimate PDs for non-financial corporations with statistical models calibrated on financial-statement and credit-register data, complemented by expert judgment, under common Eurosystem guidelines.
For low-default portfolios (large corporates, institutions, sovereigns and specialized lending), the case for changing how PDs are estimated is strongest. Banks using the foundation IRB approach (F-IRB) in these portfolios obtain large capital relief: a single-A rated corporate carries a risk weight of 50 percent under the standardized approach and about 22 percent under foundation IRB, using the long-run default rate for that rating grade and the supervisory LGD [S&P Global Ratings, 2025]. Yet the PD models underpinning the relief cannot be validated, because defaults are too rare to backtest them. The most common type of model in these portfolios, the shadow rating model, is a statistical approximation of the agency ratings it seeks to replicate, built on fewer variables, without the qualitative overlay, and validated against the very ratings it copies; there is no evidence that such models predict default better than the ratings themselves. The proposal therefore derives PDs for rated borrowers directly from long-run default rates by rating grade, with no bank-specific model. For unrated borrowers, the EBA maintains a single shadow rating model mapping firm fundamentals to default rates, functionally equivalent to the dozens of bank-specific models it replaces, so that similar firms receive similar capital requirements whether rated or not. Specialized lending moves entirely to supervisory slotting. A minimum risk weight applies where the risk-weight function is steepest and adjacent rating grades cannot be told apart with any realistic sample. The reliance on external ratings is not new: the current framework already treats them as the benchmark that bank models replicate; the proposal removes the bank-specific noise around them. Unlike at the time of the global financial crisis, rating agencies in the EU are now subject to registration, mandatory methodology validation and public performance disclosure.
For LGD and EAD, the proposal follows the foundation-IRB logic of supervisory parameters, with more structure. The recovery on the collateralized part of an exposure is computed from the recorded collateral value, reduced by an EU-wide supervisory haircut per collateral type calibrated by the EBA on pooled loss data, and discounted over the bank’s own average time to foreclosure for that collateral class and jurisdiction. The recovery on the uncollateralized part is the bank’s long-run average recovery on fully unsecured exposures, an observable quantity that requires no model. A minimum LGD applies as a backstop. Credit conversion factors, whose bank-specific models the EBA itself finds to have low discriminatory power [European Banking Authority, 2026a], become supervisory flat rates by product type. Risk differentiation survives through collateral type, coverage, foreclosure times and workout experience; what disappears are the bank-specific regression models and the supervisory review of them.
Figure 3. Nobody asks drivers how fast they were going

Governance is correspondingly simpler. The EBA validates each model on held-out samples of the pooled data before endorsement. Bank-level backtesting, which today exists to police an agency problem, largely falls away, since the only bank-specific inputs are observable averages that cannot be optimized. A bank qualifies for the centrally calibrated models on three conditions: loan-level data handling in the format the EBA requires, a verified default history of at least five years, and a supervisory assessment of its data infrastructure and governance. A bank that does not yet meet them, because it is new or has no default history for a given portfolio, applies the standardized approach to that portfolio and moves to the standardized IRB approach once it qualifies; a bank that does not wish to invest in the infrastructure simply stays there.
Much of the apparatus disappears. Model development, validation and supervisory model approval at the level of the individual bank are no longer required; the bank’s burden shifts to data quality and to the integrity of its reported default and loss histories. Because the central parameters function as regulatory values inside the IRB framework, as foundation IRB and supervisory slotting already do, the proposal fits within the Basel architecture as a European implementation choice.
The proposal is one of several ways to reform the IRB framework. Five others have been put forward by regulators or in the academic literature. Each is described below and assessed, together with the proposal and the status quo, against the five objectives in Table 1.
Incremental reform is the path European institutions are on: optional fallbacks for margins of conservatism, downturn LGD and credit conversion factors; fewer model changes requiring prior approval [European Banking Authority, 2026b; European Central Bank, 2026]; internal models confined to banks’ most material portfolios. It removes friction. The core apparatus remains, banks still develop and validate their own models, the incentive to underestimate persists, and cost efficiency improves only at the margin.
Universal foundation IRB would extend supervisory LGD and credit conversion factors to all portfolios, including retail, where Basel does not foresee a foundation approach. This eliminates LGD and EAD modeling and its cross-bank variability, and follows the same institutional logic as the proposal. It leaves PD estimation with banks, and PD is the parameter that drives the largest share of risk-weight variation and of modeling cost, together with the rating systems, validation functions and inspections built around it.
A full return to the standardized approach removes internal models entirely and achieves maximum simplicity. Some differentiation survives through exposure classes, external ratings and loan-to-value ratios, but for the corporate book it matters little: about three quarters of EU exposures to larger corporates are to unrated borrowers, which attract a flat 100 percent risk weight regardless of creditworthiness. Within each bucket the safest borrowers are penalized most. Risk sensitivity is what the approach gives up.
A granular standardized approach is the alternative closest to the proposal. The regulator defines a risk-weight grid along the two strongest risk drivers per portfolio, for instance leverage and delinquency for corporates, or debt-service-to-income and loan-to-value ratios for mortgages, and calibrates the cells from the Basel formula. Comparability is full and cost efficiency high. A grid with two drivers and discrete buckets differentiates more coarsely than a model drawing on a fuller set of variables. Because the drivers are point-in-time indicators, exposures migrate to higher-risk cells in a downturn and risk weights rise with it. And the grid effectively defines a new standardized table outside the Basel text.
A binding leverage ratio, as advocated by Admati and Hellwig (2024), abolishes risk weighting altogether. Comparability is perfect and cost minimal. A government bond and a speculative-grade loan then carry the same capital charge, which recreates the incentive to shift toward riskier assets that Basel I produced, and the approach abandons the risk-based minimum at the core of the Basel framework.
Table 1. Assessment of the status quo, the proposal and five alternatives against the five objectives

The standardized IRB approach proposed here is the only configuration that combines risk sensitivity, comparability and cost efficiency within the Basel framework. Two concessions belong in the assessment. First, the proposal uses fewer, standardized explanatory variables than a bespoke bank model, and may lose some portfolio-specific signal. The loss is partly offset by a pooled sample far larger than any single bank’s, which improves precision and out-of-sample stability, and the credit-scoring literature consistently finds that simple logistic models with a few well-chosen variables capture the large majority of achievable discriminatory power [Lessmann et al., 2015]. Whether anything is lost is an empirical question, and section 7 says how to answer it. Second, a single centrally calibrated model concentrates model risk: a systematic error would affect every bank at once. The mitigants are published specifications and coefficients open to public scrutiny, observable out-of-sample performance, independent validation before endorsement and the minimum risk weight. Today’s model diversity is no safeguard against this risk, since every bank has the same incentive to estimate low; the observed dispersion reflects calibration aggressiveness rather than independent, unbiased estimates.
The next step is a pilot. A natural roll-out would begin with low-default portfolios, where the statistical case against current models is strongest, the capital impact of PD differentiation is largest and implementation is simplest, since PDs derive from external ratings without any bank-specific calibration; a quantitative impact study comparing the proposed treatment with current IRB outcomes for large corporates would provide the evidence base. In parallel, a pilot on one high-default segment, residential mortgages for instance, would test the central calibration end to end: data pooling, perimeter definition, variable selection, estimation and the annual recalibration of the bank-specific constant. The pilot would settle empirically whether a centrally calibrated model with a small set of standardized variables matches the discriminatory power of bank-specific models, tested out of sample.
The proposal creates more winners than losers. Banks on the standardized approach gain access to risk-sensitive, hence lower, capital requirements without building an IRB function, provided they can supply the data; the efficiency gains of risk sensitivity extend to a larger share of the European banking system. IRB banks face transition costs as they wind down modeling, validation and audit functions the framework no longer requires; these costs are bounded in time and dwarfed by the recurring savings. Over 1,000 pages of IRB regulation and guidance become largely superfluous. The supervisory structures built to police bank-developed models narrow to a mandate focused on data quality. This is simplification without deregulation: the level of capital is unchanged and its risk sensitivity is preserved.
When the IRB framework was introduced in the early 2000s, banks may have needed a regulatory incentive to invest in what was then novel data and modeling infrastructure. Two decades later, credit scoring models are computationally trivial, and the scarce input has become an unbiased calibration. The standardized IRB approach redirects the framework accordingly: banks contribute data, and the regulator ensures that the models built on those data serve prudential objectives rather than capital optimization. Calls for regulatory simplification often stall on the concern that fewer requirements mean weaker safeguards. Here that trade-off does not arise. The risk-weight function, the confidence level and borrower-level risk differentiation stay in place, while the agency problem and the apparatus built to manage it largely disappear. The IRB framework thereby offers a model case for simplification without deregulation.
The next step is to test it.
Abbassi, P. and M. Schmidt (2018). A comprehensive view on risk reporting: Evidence from supervisory data. Journal of Financial Intermediation 36, 74–85.
Admati, A. and M. Hellwig (2024). The Bankers’ New Clothes, new and expanded edition. Princeton University Press.
Behn, M., R. Haselmann and V. Vig (2022). The limits of model-based regulation. Journal of Finance 77(3), 1635–1684.
Draghi, M. (2024). The future of European competitiveness. European Commission.
European Banking Authority (2025). Report on the 2024 credit risk benchmarking exercise. EBA/REP/2025/13.
European Banking Authority (2026a). Discussion paper on the simplification and assessment of the credit risk framework. EBA/DP/2026/01.
European Banking Authority (2026b). EBA streamlines supervisory approvals of IRB model changes. Press release, March 2026.
European Banking Federation (2025). Simply competitive: How simplification can strengthen the EU banking sector.
European Central Bank (2017). Targeted Review of Internal Models (TRIM): Media briefing conference call, presentation slides. ECB Banking Supervision.
European Central Bank (2021). Targeted Review of Internal Models: Project report. ECB Banking Supervision.
European Central Bank (2026). ECB streamlines how it supervises banks’ internal models. Press release, 30 March 2026.
Eurosystem (2026). Eurosystem response to the EU Commission’s targeted consultation on the competitiveness of the EU banking sector.
Haldane, A. G. and V. Madouros (2012). The dog and the frisbee. Speech at the Federal Reserve Bank of Kansas City symposium, Jackson Hole.
International Monetary Fund (2025). Euro area: Financial Sector Assessment Program, detailed assessment of observance of the Basel Core Principles. IMF Country Report 25/215.
Lessmann, S., B. Baesens, H.-V. Seow and L. C. Thomas (2015). Benchmarking state-of-the-art classification algorithms for credit scoring: An update of research. European Journal of Operational Research 247(1), 124–136.
Mariathasan, M. and O. Merrouche (2014). The manipulation of Basel risk-weights. Journal of Financial Intermediation 23(3), 300–321.
Millischer, L. (2026). A model case for simplification in Europe: Internal ratings, better calibrated. World Bank, Financial Sector Advisory Center. documents.worldbank.org.
Pérez Montes, C., C. Trucharte Artigas, M. E. Cristófoli and N. Lavín San Segundo (2018). The impact of the IRB approach on the risk weights of European banks. Journal of Financial Stability 39, 147–166.
S&P Global Ratings (2025). Default, transition, and recovery: 2024 annual global corporate default and rating transition study.