← Back to blog

Stop Missing Liquidity Risk: CFaR vs VaR for Treasuries (€10M FX)

October 1, 2026
Stop Missing Liquidity Risk: CFaR vs VaR for Treasuries (€10M FX)

Value at Risk quantifies the maximum expected loss on a portfolio from market moves over a set horizon and confidence level. Cash Flow at Risk translates that same market volatility into a distribution of possible future cash flows. Corporates typically use VaR for market risk aggregation and regulatory reporting, and CFaR for liquidity planning and budgeting, with Expected Shortfall and scenario analysis filling the gaps both leave behind.


TL;DR:

  • VaR primarily measures potential daily or short-term losses, while CFaR assesses cash flow deviations over longer planning horizons of up to a year.
  • VaR calculations often rely on market data using methods like parametric models, historical simulation, or Monte Carlo, each with different tradeoffs in speed and realism.
  • Accurate CFaR modeling depends heavily on reliable internal forecasts and comprehensive mapping of cash flows to market scenarios, making forecast errors a key weakness.
  • Combining VaR, CFaR, and Expected Shortfall provides a more complete risk picture, especially for tail events and liquidity stress scenarios.
  • Building credible models requires robust governance, proper data management, documentation of assumptions, and consistent backtesting to avoid flaws and surprises later.

Corphedge
Bring Currency Risk Into View
CorpHedge helps companies monitor currency positions and apply risk management strategies to reduce volatility’s impact on profitability and cash flow.
Explore CorpHedge

Table of Contents

VaR and CFaR: what each one actually captures

VaR and CFaR answer different questions, even though both start from the same market data. VaR asks: how much could this portfolio lose over the next day, week, or month, at a given confidence level? CFaR asks: how much could our actual cash position deviate from plan once currency, rate, or commodity moves work their way through the business?

That difference in framing changes almost everything downstream, from who calculates the number to who reads it.

Definitions and outputs. Value at Risk produces a single loss-quantile figure, commonly expressed as "95% VaR" or "99% VaR," summarizing the worst expected loss that should not be exceeded more than a stated percentage of the time. CFaR instead produces a full distribution of projected cash flows, built by mapping market scenarios onto a company's actual receipts and payments. One is a point estimate of loss; the other is a shape describing possible outcomes for the treasury function to plan against.

Typical users and inputs. Trading desks and banks lean on VaR because their books are marked to market daily and their risk factors (rates, spreads, volatilities) are already in a form VaR models consume directly. Corporate treasury teams building CFaR instead start with a budget or forecast, then overlay currency, commodity, or interest rate scenarios onto anticipated cash flows over the fiscal period, which usually means combining market data with sales forecasts, procurement schedules, and debt service calendars.

CFaR horizons stretch to match the planning cycle, often a quarter or a full fiscal year, because that is the period over which a shortfall would actually strain liquidity or covenant compliance.

The practical differences show up quickly once you compare them side by side:

  • Time horizon: VaR typically spans a day to two weeks; CFaR usually spans a quarter to a year, matching the budget cycle.
  • Primary audience: VaR serves trading desks, market risk committees, and prudential regulators; CFaR serves treasurers, CFOs, and lenders concerned with liquidity.
  • Output format: VaR delivers a single loss threshold at a chosen confidence level; CFaR delivers a distribution of cash-flow outcomes against a forecast baseline.
  • Data foundation: VaR relies on market price and volatility histories; CFaR relies on those same inputs plus internal sales, procurement, and financing forecasts.
  • Known weakness: VaR says nothing about the severity of losses beyond its threshold; CFaR is highly sensitive to the accuracy of the underlying business forecast.

Neither metric is complete on its own. VaR's biggest limitation, well documented by the European Central Bank, is that it says nothing about what happens once losses cross the threshold: two portfolios can share an identical VaR while one has a far worse tail. That is why the ECB recommends coherent measures like Expected Shortfall alongside VaR rather than as a replacement. CFaR carries a parallel weakness: it is only as good as the cash-flow forecast feeding it, and errors in that forecast propagate directly into the risk distribution. A corporate that reports CFaR without stress-testing its sales assumptions is measuring the wrong kind of uncertainty.

How VaR and CFaR get calculated in practice

VaR and CFaR both start with a market view, but the calculation paths diverge quickly depending on the sophistication a team needs and the data it has on hand.

VaR approaches. Three methods dominate practice, each with a different tradeoff between speed and realism.

  1. Parametric (variance-covariance) VaR assumes returns follow a known distribution, usually normal, and calculates loss quantiles from volatility and correlation estimates; it is fast to compute but understates risk when returns have fat tails.
  2. Historical simulation reruns the current portfolio through actual past market moves, avoiding distributional assumptions but depending heavily on the historical window chosen.
  3. Monte Carlo simulation generates thousands of hypothetical market paths from modeled distributions, capturing nonlinear exposures (like options) that the first two methods handle poorly.
  4. CAViaR and extreme value theory (EVT) augmented models estimate the loss quantile directly rather than through a full return distribution, which ECB research shows can improve accuracy under heavy-tailed return behavior, though finite-sample limitations persist at extreme confidence levels.

CFaR steps. Building a CFaR model follows a different sequence, closer to budgeting than to trading-desk analytics:

  1. Identify which cash flows are exposed to market risk, typically foreign-denominated revenue, input costs, or floating-rate debt service.
  2. Map market scenarios (currency moves, rate shifts, commodity price paths) onto those exposures over the planning horizon.
  3. Aggregate the resulting cash-flow impacts across business units and discount them to a common valuation date.
  4. Produce a cash-flow-at-risk distribution showing the range of likely outcomes against the budgeted baseline.

Expected Shortfall sits alongside both approaches rather than replacing either. Where VaR reports a threshold and CFaR reports a distribution, ES asks what the average loss looks like once you are already past the worst-case boundary, a question the Basel Committee's market risk framework has pushed internal models toward answering directly. Scenario analysis complements both by testing specific, named events (a rate shock, a currency devaluation) rather than relying purely on statistical distributions.

Pro Tip: Run CFaR scenarios on the same market shocks used in your VaR model so the two outputs stay comparable when presented to the same audience.

A short FX example. Say a company expects to collect €10 million in receivables over the next quarter, converting to its home currency at a budgeted rate.

FX receivables flowing through scenario paths

Standard note: VaR modeling research indicates that CAViaR and EVT-augmented approaches can sharpen tail-quantile estimation for heavy-tailed return series, a detail that matters most for portfolios with option exposure or currency pairs prone to sudden moves.

Choosing between VaR and CFaR for your treasury

The right metric depends less on sophistication and more on the question you are trying to answer. A checklist helps narrow it down quickly:

  • Objective: if the goal is capital adequacy or trading limit enforcement, start with VaR; if the goal is liquidity planning or covenant protection, start with CFaR.
  • Path dependence: VaR assumes a static portfolio snapshot; CFaR must account for cash flows arriving at different times, which makes it more sensitive to timing assumptions.
  • Data availability: VaR needs clean market price and volatility histories; CFaR needs a reliable internal forecast, which many corporates do not yet have at the granularity required.
  • Stakeholder audience: boards and lenders often want CFaR framed in currency terms tied to the budget, while risk committees and regulators expect VaR framed in statistical confidence terms.

Example mappings. A treasury team building next year's budget uses CFaR to size a cash buffer against currency volatility. A hedging desk designing forward contracts uses VaR to size the notional it is willing to leave unhedged. A finance committee setting trading limits for an in-house FX desk uses VaR because it aggregates cleanly across instruments and matches how limits are typically expressed.

Combining the two produces the most useful picture for a corporate board: VaR sets the boundaries for how much market exposure the company tolerates on any given day, while CFaR translates that exposure into what it means for the next quarter's cash position. Neither should be presented alone to senior management. Adding Expected Shortfall or a targeted stress test (a specific currency devaluation, a rate shock) rounds out the picture for the tail scenarios that VaR alone cannot describe and that CFaR's forecast-driven structure can understate if the forecast itself is too conservative.

Pro Tip: Report VaR and CFaR together on the same dashboard cadence so stakeholders see market risk and liquidity risk as one connected story, not two competing metrics.

Building a credible model: data, assumptions, and governance

A VaR or CFaR figure is only as credible as the data and assumptions behind it, and this is where most implementations quietly fail.

Data requirements. VaR needs clean historical price series, volatility surfaces, and correlation matrices refreshed on a schedule that matches the model's rebalancing frequency. CFaR needs all of that plus internal data that is often harder to standardize: sales forecasts by currency, procurement schedules, forward curves for each exposed currency pair, and a cash-flow calendar mapped to when receipts and payments actually settle.

Assumptions to document. Every model rests on choices that should be written down, not buried in a spreadsheet formula: the discounting convention applied to future cash flows, the correlation assumptions between risk factors, how scenarios were selected (historical, hypothetical, or regulator-prescribed), and how path dependence is handled when cash flows arrive at different points in the horizon.

  • Discounting convention: which curve and compounding basis converts future cash flows to present value.
  • Correlation structure: whether risk factors are assumed independent, historically correlated, or stressed to a worst-case correlation.
  • Scenario selection: historical window length for VaR, or scenario set design for CFaR and stress tests.
  • Path dependence: how timing mismatches between exposure and settlement are treated in the cash-flow aggregation.

Backtesting and governance. The Basel framework sets clear expectations for internal VaR models: regular backtesting against realized outcomes, documented model validation, and a defined escalation process when breaches exceed the expected frequency. Corporates without a regulatory mandate should still adopt a version of this discipline, backtesting at a set cadence (monthly or quarterly) and keeping a documentation trail an auditor or lender could follow without needing the model's author in the room.

Common pitfalls.

  • Treating VaR as a proxy for liquidity risk, when it says nothing about whether cash will actually be available when a loss materializes.
  • Ignoring path dependence in CFaR, which understates risk when exposures and cash settlements do not line up in time.
  • Weak calibration and documentation, which supervisory guidance and practitioner experience both flag as the main reason models fail review, more often than the underlying math being wrong.
  • Skipping backtesting once a model is in production, which lets calibration drift go unnoticed until a breach exposes it.

Teams that treat calibration as a one-time setup step tend to be the ones surprised by their own numbers a year later. Mapping exposures to cash flows in particular tends to surface hidden timing mismatches that only become visible once the model has run through a full cycle or two.

How platforms and advisory support speed up implementation

Getting a VaR or CFaR model from spreadsheet to production usually takes longer than the math suggests, mostly because of the operational layer around it: data feeds, access controls, and reporting that has to hold up under audit.

A platform built for this work should offer a few capabilities as a baseline:

  • Exposure mapping that links market positions and forecasted cash flows to a single data structure, avoiding duplicate manual entry.
  • Scenario simulation that lets a team run the same market shocks through both VaR and CFaR views for consistent reporting.
  • Automated reporting that generates the documentation trail regulators and auditors expect without rebuilding it each cycle.
  • Real-time alerts that flag when exposures or model breaches cross a defined threshold.

Operational controls matter as much as the modeling itself. Role-based access controls, a full audit trail of assumption changes, and scheduled backtesting with standardized templates all reduce the chance that a model's credibility gets questioned during a review, a point the Basel framework's move toward Expected Shortfall for internal models makes explicit: regulators expect the process around the number, not just the number itself.

CorpHedge builds its platform around this operational layer, combining exposure tracking with VaR-based hedging simulations and reporting templates so treasury teams are not assembling these pieces from scratch. Advisory support and structured training shorten the curve further, particularly for teams calibrating a CFaR model for the first time, where the biggest time cost is usually documenting cash-flow mapping assumptions well enough that a lender or board will trust the output.

Where treasury teams should start

The teams that get the most value from VaR and CFaR are not the ones with the most sophisticated models. They are the ones who mapped their data correctly before adding complexity.

Start with governance and data mapping, not model choice. A CAViaR model built on a poorly documented cash-flow forecast will not outperform a simple parametric VaR paired with a clean exposure map. Pick one exposure type, FX cash flows are usually the cleanest starting point, and run a pilot that validates the mapping and reporting before expanding to interest rate or commodity exposures.

Report both metrics to stakeholders rather than picking one. VaR tells the board what the trading or hedging book could lose; CFaR tells them what that loss means for next quarter's cash position. Add Expected Shortfall or a named stress scenario when the audience is senior management or a lender, since neither VaR nor CFaR alone answers what happens in the tail.

— Bartas

Putting VaR and CFaR to work with CorpHedge

Building this out internally usually means stitching together market data feeds, a forecasting model, and a reporting layer from separate tools. The Corphedge platform puts exposure tracking, VaR-based hedging simulation, and reporting in one place, which cuts the setup work described above down to configuration rather than construction.

Corphedge

Teams that want a second opinion on assumptions or model structure can bring in CorpHedge's operational expert advice, including Risk Safari Tours for hands-on walkthroughs of exposure mapping. Staff building VaR and CFaR literacy from the ground up can work through the FX hedging course for €220, a one-off purchase covering the practical mechanics this article outlines. CorpHedge is expanding into additional European markets, adding reach for treasury teams operating across those currencies. Check the platform's use cases to see which fits your exposure profile.

Where to go deeper on VaR and CFaR

For the regulatory foundation, the Basel Committee's market risk framework and the ECB's discussion of VaR and Expected Shortfall cover model expectations and tail-risk measurement. For calculation detail, the ECB's working paper on VaR models examines CAViaR and EVT approaches. CorpHedge's own guides on FX VaR modeling and cash flow at risk walk through practical application.

Sources

FAQ

What is the difference between VaR and CVaR?

VaR reports a single loss threshold at a given confidence level, while CVaR, also called Expected Shortfall, reports the average loss expected once results fall beyond that threshold. The ECB recommends CVaR as a coherent complement to VaR because VaR alone says nothing about the severity of tail losses.

Is discounted cash flow analysis the same as net present value?

Discounted cash flow analysis is the method used to arrive at a net present value figure, so the two are closely linked but not identical terms. DCF describes the process of projecting and discounting future cash flows, while NPV is the resulting single number after subtracting the initial investment.

What does 95% VaR mean in practice?

It leaves a real, if smaller, chance that losses on the remaining days will be worse than the reported figure.

What does 5% CVaR represent?

It gives a fuller picture of tail severity than VaR alone, which is why the Basel framework has pushed internal models toward reporting it.

How does CorpHedge support VaR and CFaR reporting?

The Corphedge platform combines exposure tracking, VaR-based hedging simulation, and reporting templates so treasury teams can build both metrics without assembling separate tools. Teams can also access operational advisory support or the FX hedging course to build internal calibration and documentation practices.