Hope for the Best, Plan for the Worst: The Treasurer's Survival Checklist
Even the worst is never certain" is a comforting proverb, and a dangerous one for corporate treasury, where a single unrehearsed scenario can be existential. This article sets out ten classic "what if" situations every treasury should already have answered, from banking outages and cyberattacks to funding freezes and regulatory shocks, before turning to the less familiar territory of Taleb's black swans and the BIS/Banque de France's green swans. Drawing on the 2026 AFP Payments Fraud Survey and the Green Swan report, it argues that resilience is built through rehearsal, not prediction, and sets out the testing cadence that turns a business continuity plan into an actual capability.
Simply Treasury · Thought Leadership. By François Masquelier, CEO of Simply Treasury, Chairman of ATEL and Chair of EACT. 22 July 2026.
“Even the worst is never certain” is a comforting saying, and comforting sayings are exactly what treasurers cannot afford to trust. The proverb works for everyday life, where most feared outcomes never materialise. It fails for corporate treasury, where a single low-probability event, a frozen bank account, a ransomware attack on the payment factory, a customer default the week before a bond coupon, can be fatal regardless of how unlikely it looked on a risk matrix the month before. Treasurers are rarely blamed for the scenario nobody imagined. They are blamed for the scenario everybody could have imagined and nobody rehearsed.
The discipline that separates resilient treasuries from fragile ones is not forecasting the future. It is refusing to be surprised by it. That means maintaining a standing answer to a set of “what if” questions, tested well before the day they stop being hypothetical.
“Treasurers are rarely blamed for the scenario nobody imagined. They are blamed for the scenario everybody could have imagined and nobody rehearsed.”
François Masquelier, Chair of EACT
The most classic scenarios every treasurer should already have answered
Ten scenarios recur often enough across corporate treasury functions that they deserve to be treated as the baseline curriculum, not an aspirational one. What if a key banking partner suffers an outage or financial distress? The answer is structural: diversified banking relationships, no single point of failure on critical accounts, and backup connectivity so payments do not depend on one channel. What if a cyberattack disrupts systems or payment capability? Treasury needs a tested incident response plan and a genuine manual payment fallback, not a plan that assumes the same systems under attack. What if FX markets move violently overnight? Hedging programmes and pre-agreed limits, combined with real-time monitoring and periodic stress scenarios, absorb the shock instead of amplifying it. What if interest rates move faster than the forecast assumed? Stress-tested debt and investment portfolios, and liquidity buffers sized for a genuinely adverse case, are the answer, not a single base-case forecast. What if a major customer delays or defaults? Active credit monitoring, a diversified customer base and credit insurance limit the damage from any one counterparty. What if a key supplier, country or business unit is disrupted? Mapping concentration risk in advance, and having alternate suppliers or regional contingency plans on the shelf, turns a crisis into an inconvenience. What if the cash forecast is wrong by 20%? Rolling, driver-based forecasts built on multiple scenarios catch the miss early rather than at the moment cash actually runs short. What if the ERP or treasury management system becomes unavailable? Only a tested disaster recovery plan, with real data backups and a rehearsed manual workaround, prevents a technology outage from becoming a liquidity crisis. What if the company loses access to funding or capital markets? Committed, undrawn credit lines and deliberately built cash buffers are what stand between a market closure and a missed obligation. And what if a regulatory or compliance change lands on the desk with limited notice? Proactive monitoring of regulatory developments, and policies and systems designed to flex rather than break, are the only durable answer.
The most classic “what if” scenarios (non-comprehensive list):
- Banking partner outage or distress
- Cyberattack on systems or payments
- Sudden FX market moves
- Faster-than-expected rate moves
- Major customer delay or default
- Key supplier, country or business unit disruption
- Cash forecast wrong by 20%
- ERP / TMS unavailable
- Loss of access to funding or capital markets
- Regulatory or compliance shock
Preparation is never generic. Each of these ten scenarios demands its own playbook, owner and trigger, reviewed on a schedule rather than after the event that proves it was needed.
Beyond the classics: black swans, green swans and structural risk
The classic list, however, is not the whole list. Nassim Nicholas Taleb’s black swan describes a rare, high-impact event that is unforeseeable in advance but explainable in hindsight, the 2008 liquidity freeze is the textbook corporate treasury example. The green swan, a term coined by the Bank for International Settlements and Banque de France in their 2020 report, describes something structurally different: climate-related financial risk that is foreseeable in direction but radically uncertain in timing, magnitude and transmission, spanning both physical risk, a flooded plant, a disrupted logistics corridor, and transition risk, as carbon-intensive assets or financing suddenly reprice. A green swan does not arrive as a surprise the way a black swan does; it arrives as a slow-building certainty that most organisations still treat as a future problem until it becomes a present one. Between the classic scenarios and the swans sits a third category treasurers underweight at their own risk: geopolitical and counterparty-structural risk. Sanctions regimes that freeze a subsidiary’s banking access overnight. A bank bail-in that converts deposits into equity. The sudden departure of the one person who understands a legacy treasury system, with no documented succession plan behind them. None of these require a black swan’s rarity or a green swan’s slow burn, they are entirely foreseeable, and precisely for that reason, inexcusable to leave unaddressed.
- Black swan (Taleb, 2007): rare, extreme-impact event, unforeseeable in advance, rationalised only in hindsight, e.g. the 2008 liquidity freeze.
- Green swan (BIS / Banque de France, 2020): climate-related financial risk, foreseeable in direction but radically uncertain in timing and magnitude, combining physical and transition risk.
Why preparation beats prediction: testing turns a plan into a capability
Data on the frequency of these events keeps making the case for preparation more urgent rather than less. AFP’s 2026 Payments Fraud and Control Survey found that treasury is now the department most likely to both discover attempted fraud (83%) and confirmed fraud (55%), with 63% of organisations reporting they have been targeted by business email compromise. That is not a hypothetical exposure; it is close to a routine one. Preparation always prevents (some) risks. Preparation is always virtuous. Preparation on paper is not preparation. A business continuity plan that has never been tested is a document, not a capability. Good practice, drawn from both financial-sector regulators such as FINRA and treasury-specific guidance, points to a layered testing cadence: a quarterly tabletop exercise for the highest-probability scenarios (bank outage, cyberattack, forecast miss), an annual full technical failover test of the ERP or treasury management system, and an ad hoc review triggered whenever the risk landscape itself shifts, a new acquisition, a new banking partner, a new jurisdiction. Treasuries that treat this cadence as non-negotiable, rather than as the first item cut when resources tighten, are the ones still standing when a test scenario becomes a live one. However, you would be surprised to see that many treasuries of MNCs do not have a real and effectively tested and documented BCP, coupled to a company DRP.
“A business continuity plan that has never been tested is a document, not a capability.”
François Masquelier, CEO of Simply Treasury
The regulatory direction of travel, the EU’s Digital Operational Resilience Act (Regulation (EU) 2022/2554, applicable since 17 January 2025) is the clearest example, even though its direct scope is financial entities, is toward mandatory, evidenced testing of operational resilience, including third-party ICT dependencies, rather than self-certified readiness. Corporate treasuries that adopt the same discipline voluntarily, running tabletop exercises and live failover tests on a fixed calendar, consistently recover faster than those that do not, simply because the muscle memory already exists when the real event hits.
The other use cases on every treasurer’s watch list
Beyond the ten classic scenarios and the swans, several other situations belong permanently on a treasurer’s watch list: a sudden credit rating downgrade that triggers covenant or collateral clauses; an acquisition that is legally closed before its target’s cash and banking infrastructure is actually integrated, creating a liquidity blind spot at the worst possible moment; and trapped cash in a jurisdiction that abruptly tightens capital controls. Each shares the same structural lesson as the original ten: the response that works is the one designed and rehearsed before the pressure arrives, not improvised under it.
Prepared today, stronger tomorrow
Resilient treasury teams do not distinguish themselves by predicting more accurately than their peers. They distinguish themselves by having already answered the question before it is asked under pressure. That requires real-time visibility into cash and exposures, scenario planning that goes beyond the base case, genuine stress testing, documented playbooks with named owners, diversified banking and funding relationships, and a testing cycle that never stops. None of this eliminates the worst case. It ensures that when the worst case arrives, it is a bad day rather than an existential one.
References
- Bolton, P., Despres, M., Pereira da Silva, L.A., Samama, F., Svartzman, R., The Green Swan: Central Banking and Financial Stability in the Age of Climate Change, BIS / Banque de France, 2020. Link
- Taleb, N.N., The Black Swan: The Impact of the Highly Improbable, Random House, 2007.
- Association for Financial Professionals, 2026 AFP Payments Fraud and Control Survey Report, 2026 (as reported by PR Newswire / Morningstar). Link
- European Union, Regulation (EU) 2022/2554 on Digital Operational Resilience (DORA), Official Journal L 333, 27.12.2022. Link
- The Global Treasurer, “Building a Cyber-Resilient Treasury for a High-Threat Landscape”, 2025. Link
- FINRA, Business Continuity Planning (BCP). Link