Who Grades the Graders? - How the World's Most Trusted Financial Grade Became a Number for Sale

 

Picture a university where students hire their own examiners, pay them directly, and get to pick a new examiner if the first one grades too harshly. You'd assume the grades coming out of that system are, at best, generous. At worst, meaningless.

That, in essence, is how the global credit rating industry has worked for the last fifty years. And despite a financial crisis that was substantially caused by this exact arrangement, it's still how the industry works today.

Part 1: START WITH THE BASICS: WHAT A CREDIT RATING ACTUALLY IS

Strip away the jargon and a credit rating is a simple thing: a letter grade - AAA down to D - that estimates how likely a borrower is to pay back what it owes. Governments get rated. Corporations get rated. So do the complex bundles of loans that banks package and sell to investors.

These letters matter enormously, for a reason most people outside finance don't fully appreciate. A rating isn't just a helpful guide for investors doing their own homework - it's often a legal gatekeeper. Many pension funds, insurance companies, and money-market funds are only permitted, by their own charters or by regulation, to hold debt above a certain rating threshold. A single downgrade - say, from BBB- to BB+ - can force forced selling by every institutional investor no longer allowed to hold the paper. That one notch can move billions of dollars, not because anything about the underlying company changed overnight, but because the label attached to it did.

So who hands out these labels? Three companies, essentially. Moody's and S&P Global each control something like 40% of the global ratings market, and Fitch holds most of the rest - together the "Big Three" account for roughly 90-95% of credit ratings issued worldwide. This is not a crowded, competitive marketplace. It's closer to a regulated oligopoly wearing the costume of a market.

That oligopoly exists partly by regulatory design. In the US, an agency needs to be designated a Nationally Recognized Statistical Rating Organization (NRSRO) by the SEC before its ratings can be used to satisfy the regulatory requirements described above - and under global bank capital rules like Basel III, the rating on a bond determines how much capital a bank has to hold against it. A AAA bond eats up almost no regulatory capital; a junk bond eats up a lot. This is the detail that turns credit ratings from "useful opinion" into "regulatory input" - a distinction that matters a great deal for everything that follows.

Part 2: THE TWIST NOBODY BUDGETS FOR: WHO ACTUALLY PAYS

Here's where it gets interesting, and where most primers on credit ratings stop short of the uncomfortable part.

You'd reasonably assume that if a rating exists to protect investors, investors would be the ones paying for it - the way you pay a home inspector before you buy a house, not the seller. That was, in fact, how the industry worked for most of the 20th century. Investors paid for subscriptions to rating reports, and rating agencies had every incentive to be right, because their entire business was selling accurate information.

That changed in the 1970s. Photocopiers had made it trivially easy for a single subscriber to duplicate a rating report and pass it around for free, which quietly gutted the investor-pays subscription business. Around the same time, regulators began requiring public debt to carry a rating from a recognized agency, which meant every issuer suddenly needed one, guaranteed customer. The industry pivoted to a new model almost overnight: issuers would now pay for their own ratings.

Think about what that flips. The rating agency's paying customer is no longer the party trying to find safe, honest information - it's the party trying to borrow money as cheaply as possible. The examiner is now paid by the student. And once you see this shift, entire chapters of financial history start to read differently.

Part 3: THE STRESS TEST THE SYSTEM FAILED

The clearest evidence of what this conflict produces arrived in 2007 and 2008. In the run-up to the crisis, somewhere around 80-95% of a typical subprime mortgage-backed security was carved into slices carrying the highest possible AAA grade - the same grade assigned to the safest government debt on earth. Investment banks paid handsomely for these gold-star ratings because AAA-labeled paper could be sold to pension funds, insurers, and conservative money managers who were contractually barred from touching anything riskier.

Then reality caught up. By the time the dust settled, more than 90% of the AAA ratings handed out on mortgage-backed securities issued in 2006 and 2007 had been downgraded to junk. Some deals were wiped out completely - one subprime issuer saw every single one of its 75 AAA-rated securities from 2006 eventually collapse to junk status. The U.S. Financial Crisis Inquiry Commission, tasked with the official autopsy, put it about as bluntly as a government report ever does: the crisis, in its words, could not have happened without the rating agencies.

This wasn't primarily a case of agencies being duped by clever bankers, though that happened too. It was, in large part, a business model working exactly as its incentives suggested it would. The agencies were being paid by the very banks assembling these mortgage bonds, and there was always another rating agency willing to be more generous if one got too cautious - a dynamic known in the industry as rating shopping.

An issuer could quietly solicit a preliminary opinion from two or three agencies, see which one produced the friendliest grade, and only pay for (and publish) that one. The agency that said no simply never got hired again. In a market with only three real players, that's not a subtle disincentive - it's existential.

It also helps to understand "why" AAA was so achievable in the first place. Mortgage bonds aren't rated as one lump sum - they're sliced into layers called tranches, arranged in a "waterfall" where the top tranche gets paid first and absorbs losses last, while the bottom tranche absorbs losses first and gets paid last, if at all. This is called subordination, and it's the mechanism banks used to manufacture AAA ratings out of distinctly non-AAA mortgages: pile enough risky loans together, carve out a thin top slice protected by all the losses below it, and the rating models said that top slice was nearly bulletproof. The models were right about the mechanics of subordination in normal times and catastrophically wrong about how correlated mortgage defaults would become when a nationwide housing bust hit every tranche at once. Add the fact that the agencies bore essentially no legal liability for getting a rating wrong, and you have a textbook case of moral hazard - the incentive to take on more risk when someone else, or something else, absorbs the downside. 

Part 4: THE REFORM THAT WASN'T

Here's the part of the story that should bother you more than 2008 itself: this is still how it works.

Dodd-Frank, the sprawling 2010 reform law written explicitly in response to the crisis, took direct aim at the ratings industry. It created a dedicated SEC Office of Credit Ratings. It mandated formal studies into alternatives to the issuer-pays model - including a genuinely interesting proposal where a neutral board would randomly assign which agency rated which deal, removing the issuer's ability to shop for a friendly grade. Congress even gave the SEC explicit authority to implement that random-assignment system by rule, without needing to come back for further legislation.

The SEC studied it. The GAO studied it. Regulators held a public roundtable in 2013 to debate the merits. And then, by the SEC's own later admission, the agency simply never acted. No business model was ever recommended. The random-assignment system was never implemented. More than a decade on, issuer-pays remains the dominant compensation structure across the industry, largely unchanged in its basic architecture from the model blamed for the worst financial crisis in eighty years.

Why did reform stall? Partly because the alternatives have real flaws of their own - the SEC's own analysis found that even random assignment might not fully kill rating shopping, since issuers could still hire additional agencies for supplementary opinions. Partly because the Big Three, having survived the crisis with their market position essentially intact, had every incentive to lobby quietly and wait the reform momentum out. And partly because - this is the uncomfortable structural point - regulators themselves have leaned on credit ratings for decades to set capital requirements and eligible-investment rules. The system is now load-bearing. Ripping out issuer-pays without a workable replacement risks a bigger mess than leaving a flawed thing standing.

Part 5: WHY THIS ISN'T JUST A 2008 STORY

It's tempting to file this under "historical curiosity" - a scandal that got its punishment in the form of collapsed banks and a decade of regulatory hand-wringing. But the same structural conflict is quietly present every time you read a headline about a country's sovereign rating being cut, or a corporation issuing a fresh bond.

Sovereign ratings are a particularly sharp version of the same tension. Rating agencies assess government creditworthiness while simultaneously courting relationships with those same governments' debt offices, their central banks, and the investment banks that structure sovereign bond sales. A downgrade can genuinely move a country's borrowing costs and, by extension, its fiscal room to maneuver - which means the agency doing the grading is never fully insulated from the politics of the grade it hands out.

And at the level of ordinary corporate debt, the same quiet incentive persists on every single issuance: the agency wants the repeat business, the issuer wants the friendliest defensible grade, and the investor relying on that letter to make a decision is not the one writing the check.

Part 6: SO WHAT WOULD ACTUALLY FIX THIS?

None of this means credit ratings are useless - they aggregate real analytical work, and most of the time issuer-pays ratings are directionally accurate. The problem isn't that the system fails constantly; it's that it fails predictably at the worst possible moments, precisely when the incentive to be lenient is strongest - during a boom, when issuance volume (and fee revenue) is highest and everyone least wants to hear "no."

The GAO, tasked by Dodd-Frank with actually cataloguing the alternatives, came back with a shortlist. It's worth walking through each one properly, because they fail and succeed in genuinely different ways - this is where the interesting trade-offs live.

a. Random assignment model. A neutral body - not the issuer - decides which NRSRO rates a given deal. This is the model Dodd-Frank explicitly authorized the SEC to implement without further legislation, and it kills rating shopping in its purest form. But the SEC's own 2012 study found the flaw baked in: an issuer can still privately commission an unofficial second opinion from a non-assigned agency and use it as leverage even if it never becomes the official rating.

b. Investor - pays model. Flips the money flow back to the pre-1970s structure - the institutions relying on the rating fund it directly. This already exists: Egan-Jones Ratings, an NRSRO since 2007, runs largely on subscriber fees. But a 2023 academic study found the opposite conflict re-emerging - more optimistic ratings and slower downgrades for bonds more heavily held by its own paying subscribers. Flip the direction of the money and the conflict doesn't disappear; it relocates.

c. Designation model. The agency is still picked and paid the way it is today, but securities holders - not the issuer - designate which agency receives the fee. It keeps issuer-side funding while giving investors the power to reward or punish a track record, though it requires dispersed bondholders to coordinate, something they're historically poor at.

d. Platform or utility-style ratings. The most structurally radical option: a non-profit or public utility issues a baseline rating funded by industry-wide fees, similar to how an exchange or clearinghouse operates as shared infrastructure rather than a for-profit gatekeeper. It most cleanly removes the profit motive - but nobody has built one at scale to find out what new problems that creates.

Notice the pattern across all four: every fix solves the "specific" conflict it targets and introduces a "different" one somewhere else. That's not an argument for inaction - the issuer-pays model's failure mode is the best-documented and most catastrophic of the bunch, which is exactly why it's the one Congress singled out. But it explains, more honestly than "regulatory capture" alone, why a fifteen-year-old mandate to fix this has produced studies, roundtables, and no rule.

What would move the needle without waiting for Washington to pick a single model: mandatory dual ratings from differently-compensated agencies on structured products, pairing one issuer-paid rating with one subscriber-paid or platform rating so the two conflicts at least point in opposite directions rather than the same one; hard liability for rating agencies when a rating is later shown to have ignored known, documented deterioration, closing the "just an opinion" legal shield that has historically protected agencies from lawsuits; and regulators gradually stripping ratings out of hard-coded capital rules - something Dodd-Frank also mandated and only partially delivered - so a single letter grade stops being the sole gatekeeper for how much capital an institution must hold.

None of these needs a single perfect model to be chosen. They need the two-decade-old political will to actually legislate a functioning fix, rather than fund a well-documented shelf of studies about one.

The next time a headline tells you a company or a country just got upgraded or downgraded, it's worth asking the same question you'd ask of any grade: not just what the score is, but who's paying the person holding the red pen - and whether the fix on the table quietly hands the pen to someone with a different, but equally real, reason to be generous.

Comments