The Statutory Tollbooth: Sovereign Moats, Private Credit Frontiers, and the Compounding Cash Machines of Global Debt
1. The Friday Night Downgrade: How Three Companies Became the Tollkeepers of Capital
On Friday, 5 August 2011, after American equity markets had closed for the week, a committee at Standard & Poor's did something no major credit rating agency had ever done. It lowered the long-term sovereign credit rating of the United States of America from AAA to AA+, and attached a negative outlook to it.1
The stated reasons were not arithmetic. S&P did not claim the Treasury would miss a coupon. It cited the prolonged political fight over the statutory debt ceiling, and its judgment that the fiscal consolidation package Congress and the administration had just agreed fell short of what was needed to stabilise the government's debt burden.1 The downgrade, in other words, was an opinion about the governability of the United States, published by a private company headquartered in lower Manhattan.
What happened next is the single most useful fact in this entire industry, and it is almost always told backwards.
When markets reopened on Monday, 8 August, equities fell hard β the worst session for US stocks since the 2008 crisis.2 But the securities that had actually been downgraded went up. Investors, frightened by the downgrade, bought Treasuries. Yields fell. The asset S&P had just declared less creditworthy became more expensive to buy.
Read that carefully, because it dismantles the intuitive theory of what a rating agency does. If ratings were primarily forecasts of default probability that investors used to price risk, a downgrade would raise the borrower's cost of funds. That is not what happened. What happened instead was that a piece of regulatory plumbing shifted, portfolios that referenced the AAA designation had to be reviewed, mandates had to be checked, collateral schedules had to be re-run β and in the resulting scramble, capital fled to the deepest, most liquid market on earth, which happened to be the one that had just been downgraded.
The rating did not change the credit. It changed the paperwork. And the paperwork is the business.
This is the central tension that a professional investor has to hold in mind when looking at credit ratings as an industry. The output is an opinion β legally protected as such, frequently wrong, occasionally catastrophically wrong. The demand for it is a legal requirement. Those two facts do not sit comfortably together, and the space between them is where roughly eight billion dollars of annual operating profit lives.
Three firms occupy that space. S&P Global Ratings, a division of S&P Global Inc. (NYSE: SPGI). Moody's Investors Service, the ratings arm of Moody's Corporation (NYSE: MCO). And Fitch Ratings, part of Fitch Group, which is wholly owned by the Hearst Corporation β the same privately held family company that owns Cosmopolitan and the Houston Chronicle.3 As of 31 December 2025, ten credit rating agencies were registered with the US Securities and Exchange Commission as Nationally Recognized Statistical Rating Organizations, or NRSROs β the federal designation that makes a rating usable for regulatory purposes.4 Three of them account for the overwhelming majority of everything that gets rated.
The customer relationship runs in a direction that surprises people new to the sector. The issuer pays. A corporation, a sovereign, a bank, or a special-purpose vehicle assembling a pool of loans hires the agency, hands over confidential information, and pays a fee to be evaluated. The investors who use the rating β BlackRock, PIMCO, Vanguard, every insurance general account and pension plan on earth β mostly do not pay for it at all. They consume it through data feeds and, more importantly, through the investment guidelines and capital rules that reference it.
The economics that result are close to unique in the listed universe. For the twelve months to December 2025, Moody's Investors Service reported an adjusted operating margin of 63.6%, an expansion of 350 basis points year on year.5 S&P Global's Ratings division reported comparable profitability on a slightly larger revenue base.6 Neither business requires factories, inventory, or meaningful physical capital. Capital expenditure across both parent companies runs at a low single-digit percentage of revenue. The principal input is analysts, and analysts are a fixed cost that does not scale with the size of the bond being rated. Rating a $3 billion issue costs very little more than rating a $300 million issue.
So here is the puzzle a thematic investor arrives with. If these businesses are structurally protected by statute, why does the market repeatedly treat them as cyclical proxies for bond issuance volumes? In February 2026, S&P Global reported full-year revenue growth of 7.9%, adjusted operating margin expansion of 140 basis points to 50.4%, and adjusted diluted earnings per share of $17.83 β above the top of its own guidance range. Its shares fell nearly 15% in pre-market trading, extending a peak-to-trough decline of more than 34% from the prior year's high.7
A business with 60%-plus divisional margins and a legal moat does not usually trade like that. Either the market is systematically misreading a compounding franchise, or the market can see something in the structure of demand that the margin line conceals. Working out which of those is true requires going back to the reason the toll exists at all β and to the much larger economic shift that is currently pushing more traffic through the gate than at any point in the industry's history.
2. The Upstream Engine: Bank Disintermediation, the $4.5 Trillion Refinancing Wall, and the Private Credit Surge
Every December, the Financial Stability Board publishes an exercise that almost nobody outside central banking reads, and that explains this industry better than any equity research note. The FSB collects data from 29 jurisdictions representing more than 90% of global GDP and measures how much of the world's financial intermediation now happens outside banks.
The December 2025 edition put non-bank financial intermediation assets at $256.8 trillion at the end of 2024, up 9.4% in a single year β roughly double the growth rate of the banking sector β and equal to 51.0% of total global financial assets.8 The "narrow measure," which captures entities doing bank-like credit intermediation that authorities consider capable of transmitting financial stability risk, grew 12% to $76.3 trillion.9 For the first time in the series, the non-bank system is more than half the financial system.
That single ratio is the upstream belief this article exists to test, and it can be stated as one falsifiable proposition:
The intermediation of global credit is migrating structurally and durably from bank balance sheets to capital markets and private credit vehicles; because those channels lack a lender who does its own underwriting and holds the loan, they require a standardised third-party assessment of credit risk that is written into law and mandate; and therefore the demand for accredited credit ratings scales with the stock of global debt rather than with the profitability of any individual borrower.
That is a proposition, and it can be wrong. It has three independent evidence streams behind it, and they do not depend on each other.
The first is the FSB's own aggregate, described above: the non-bank share crossing half of global financial assets, and doing so at double the banking sector's growth rate.8 This is regulatory data, collected by supervisors, not vendor marketing. The mechanism behind it is unglamorous and well documented β post-crisis bank capital and liquidity rules made it expensive for a commercial bank to hold long-dated, illiquid corporate credit on its own balance sheet. A loan that consumes risk-weighted capital and stable funding at a bank consumes neither at an insurance general account or a private credit fund. Credit therefore moved to where the capital charge was lowest.
The second stream is the shape of the asset class that absorbed it. Private credit β direct lending, asset-based finance, and adjacent structures β crossed $2 trillion in assets under management for the first time in 2024 and is estimated at roughly $2.28 trillion for 2025, with projections running toward $4.5 trillion by 2030.10 Around half of that sits in direct loans to middle-market companies. US middle-market direct lending volume compounded at roughly 22% a year over the thirteen years to 2023.10 These are loans that a decade earlier would have been syndicated bank paper.
The third stream is the one that closes the causal loop, and it comes from the regulators of the buyers. US insurers are the single largest institutional home for this migrated credit, because long-dated private loans match long-dated policyholder liabilities. The National Association of Insurance Commissioners β the body that sets risk-based capital charges for US insurance investment portfolios β reported insurer holdings of collateralised loan obligations alone at $276.8 billion at year-end 2024, about 5.1% of insurer bond portfolios, with roughly 80% of those holdings rated investment grade and about 39% rated AAA.11 An insurer cannot hold that paper efficiently without a designation, and the designation flows from a rating.
Now the transmission mechanism into this industry's revenue line.
When a bank lends, it underwrites the borrower itself, prices the loan, and keeps it. There is no third party in the transaction and no rating is needed. When that same credit is packaged as a bond or sold into a fund whose ultimate owner is an insurer or a pension plan, four separate parties suddenly need a common, portable, regulator-recognised statement of credit quality: the issuer, who must market the paper; the underwriter, who must place it; the investor, whose mandate specifies minimum ratings; and the investor's regulator, who sets capital charges by rating band. The rating is the shared vocabulary that makes the trade legal and the capital charge calculable. Disintermediation therefore does not merely move credit β it manufactures rating demand out of credit that previously generated none.
And here the FSB report contains a detail that is almost comic in its usefulness. The 2025 monitoring report explicitly flags severe limitations in the availability of regulatory data on private credit.9 The world's financial supervisors, working together across 29 jurisdictions, cannot see clearly into the fastest-growing pool of credit on earth. Opacity of that kind is precisely what creates commercial demand for a paid, accredited, standardised opinion. The less the regulator can see directly, the more it relies on the intermediary that can.
Layered on top of this structural shift is a cyclical accelerant that is frequently mistaken for the structure itself: the refinancing wall. SIFMA's fixed income statistics put US corporate bonds outstanding at $11.5 trillion at the end of the fourth quarter of 2025, up 3.5% year on year, with 2024 US corporate bond issuance of $2.0 trillion.12 Corporate bonds do not mature evenly, but a stock of that size with typical tenors implies well over a trillion dollars of US corporate maturities alone each year, and market estimates of global corporate maturities across 2026β2028 cluster around $4.5 trillion. That figure is an estimate assembled from issuer maturity schedules rather than an official published series, and should be read as an order of magnitude rather than a precise number.
The distinction between the structural force and the cyclical accelerant matters enormously for how you price these businesses. A refinancing wall is a timing phenomenon: it pulls issuance forward or pushes it back, and it exhausts itself. Disintermediation is a change in the plumbing of the financial system, and it does not reverse unless bank capital rules reverse. The bull case that rests on the wall is a two-year trade. The bull case that rests on the plumbing is a decade.
One more thing about the wall, because it is the crux of the bear-versus-bull argument on issuance. Bears argue that elevated benchmark rates freeze refinancing and starve the agencies of transaction fees. That argument works for opportunistic issuance β the leveraged buyout, the dividend recap, the opportunistic pre-funding. It works far less well for maturities. A bond that matures must be repaid or refinanced, and companies that cannot repay from cash refinance at whatever rate is available. Maturity is not a decision. This is why ratings revenue has a floor that discretionary capital markets activity does not.
The same upstream belief implicates several adjacent industries an investor should be aware of without chasing here: private credit asset managers such as Ares, Blue Owl and Apollo, who originate the paper; financial market infrastructure and index businesses such as LSEG, ICE and CME, who process and benchmark it; and enterprise regulatory-compliance software vendors such as Wolters Kluwer, who help the buyers document it.
The migration of credit out of banks expands the rating agencies' addressable market from a mature public bond market into a $2 trillion private one where fewer than a fifth of assets currently carry a formal public rating. To understand why that expansion is so profitable, you have to understand a decision made in a very different world, in the early 1970s, about who pays.
3. Mechanics of a License to Tax: How Credit Ratings Work, Pricing Cards, and the Switch to Issuer-Pays
In 1909, John Moody published Analysis of Railroad Investments, applying letter grades to the bonds of American railway companies. He sold it the obvious way: as a book, to investors, for money. For six decades that was the industry's business model. Rating agencies were publishers. Their customers were the people who read the ratings.
Two things killed that model at almost the same moment.
The first was the Penn Central bankruptcy in 1970, which defaulted on commercial paper that the market had regarded as safe, and which produced a sudden institutional appetite for formal, continuously monitored credit assessment of short-term paper. The second was the photocopier. A subscription research product whose entire value sits on a single page is unusually easy to steal. The SEC's own historical review of the sector documents the industry's migration to charging issuers rather than investors during this period.13
The switch looks administrative. It was the most consequential business model change in the history of financial services.
Under investor-pays, revenue is a function of how many subscribers you can sign and how much each will pay for a research product. That is a linear, capped, distribution-constrained business β the economics of a magazine. Under issuer-pays, revenue is a function of the size of the thing being rated. An agency charging a percentage of principal issued is no longer selling information. It is levying an ad valorem toll on capital formation.
Before going further, it is worth being precise about what the product actually is, because the misunderstanding is expensive.
A credit rating is an ordinal ranking. AAA is safer than AA, which is safer than A, and so on down to D for default. It is a statement about relative likelihood of default and, at some agencies, expected loss given default. It is explicitly not a cardinal probability, not a recommendation to buy, not a statement about price, and not a claim about liquidity or market value. An AAA-rated bond can lose half its market value without the rating being wrong, because the rating never spoke to price.
A workable analogy: a credit rating functions like a building's fire-safety certificate. You cannot legally let tenants occupy the building without one; the inspector is paid by the landlord, not the tenants; and the certificate makes a standardised statement about a specific hazard under specified assumptions. The analogy's limit, and it matters: a fire-safety inspector applies a code written by the state, whereas a rating agency writes its own methodology and merely discloses it. The state mandates that you have a rating. It does not, mostly, tell the agency how to produce one. That gap β mandated demand, private methodology β is simultaneously the source of the industry's profitability and the source of every scandal it has ever had.
Now the money. Fee schedules are commercially confidential and neither Moody's nor S&P Global publishes a rate card, so the take-rate has to be inferred. Industry convention places initial rating fees in the range of roughly three to five basis points of principal issued, with floors and caps, plus an annual surveillance fee for as long as the rating remains outstanding. Treat those numbers as a well-established industry estimate rather than a disclosed figure; the agencies do not confirm them.
Even as an estimate, the arithmetic is instructive. Three to five basis points on the multi-trillion-dollar annual flow of rated global debt implies a core rating fee pool of roughly $12 billion to $14 billion a year. That is a small toll on an enormous flow β which is exactly why it survives. No treasurer has ever cancelled a bond offering to save four basis points. The fee is trivial relative to the transaction and non-negotiable relative to market access, which is the textbook profile of inelastic demand.
The surveillance fee deserves separate attention because it is where the recurring revenue hides in plain sight. Once a bond is rated, the agency charges annually to maintain that rating for the life of the instrument, typically five to thirty years. This converts a one-time transaction into an annuity attached to the outstanding stock of debt rather than the flow of new issuance. It is the reason ratings revenue does not collapse to zero in a frozen issuance year, and it is systematically underweighted by models that treat the segment as a pure issuance derivative.
S&P Global's own fourth-quarter 2025 disclosure quantifies the effect. For the full year, Ratings division revenue grew 8%, composed of 10% growth in non-transaction revenue and 6% growth in transaction revenue.7 The recurring half of the ratings business grew faster than the deal-driven half, in a year of healthy issuance. That is not the revenue signature of a cyclical broker.
The cost side completes the picture. The dominant expense is analyst compensation, plus compliance and technology platform costs. All of it is fixed with respect to deal size. When issuance rises, the incremental revenue arrives against a cost base that barely moves, and flow-through to operating income is extremely high. When issuance falls, the reverse is true, and margins compress β which is precisely the sensitivity bears point to. In 2025, the leverage worked in the industry's favour: Moody's Investors Service expanded its adjusted operating margin by 350 basis points to 63.6% on roughly 9% revenue growth.5 Moody's fourth-quarter revenue rose 17% year on year, driven particularly by investment-grade activity within corporate finance.5
Compare this to an ordinary enterprise software business with similar gross margins. The software company must spend continuously on sales and marketing to win each renewal against substitutes, because the customer can switch. The rating agency's customer frequently cannot switch, and the reason has nothing to do with the quality of the analysis.
That reason was invented in a conference room at the Securities and Exchange Commission in 1975.
4. The Statutory Wall: 1975, the SEC's NRSRO Creation, and the Two-Rating Network Effect
The SEC did not set out to create an oligopoly. It set out to fix a technical problem in broker-dealer capital adequacy.
Under Rule 15c3-1 β the net capital rule promulgated under the Securities Exchange Act of 1934 β broker-dealers must apply haircuts to the securities they hold, with riskier debt attracting larger haircuts. In 1975, needing a workable way to sort debt by risk without the Commission itself grading every bond in America, the SEC adopted the concept of the "nationally recognized statistical rating organization." Ratings from an NRSRO would determine the capital charge.14
Then came the detail that made three companies rich. The staff, in consultation with the Commissioners, determined that the ratings of the three dominant agencies β Standard & Poor's, Moody's, and Fitch β were nationally used, and therefore that they were NRSROs for the purposes of the rule. The Commission never defined the term. It never specified a process by which a rating agency might become one. Between 1975 and 2000, it added just four more.14 The SEC's approach has been fairly described as "we know it when we see it."
Consider what that meant commercially. A brand-new rating agency could hire better analysts, build better models, charge less, and be right more often β and none of it would matter, because its ratings would not reduce a broker-dealer's capital charge. The regulator had converted "being well known" into a legal privilege, and then made "being well known" the criterion for obtaining the privilege. The barrier to entry was reputation, and reputation was defined circularly by incumbency.
From there, the designation propagated. Federal and state rules referencing NRSRO ratings spread into bank capital regulation, money market fund eligibility, pension fund investment restrictions, and insurance company risk-based capital. Europe built a parallel architecture: the European Securities and Markets Authority directly supervises credit rating agencies under Regulation (EC) No 1060/2009 and its successors, and the European Central Bank maintains the Eurosystem Credit Assessment Framework β ECAF β which determines which agencies' ratings make collateral eligible for central bank refinancing operations.15 A rating that is not ECAF-eligible cannot help a European bank raise liquidity from the ECB, regardless of how accurate it is.
But regulation alone would have produced a licensed cartel of seven. What produced a duopoly at the top was a market convention that no regulator ever wrote down.
Institutional investment guidelines and underwriting practice converged on a two-rating standard for benchmark corporate debt: to be broadly placeable, an issue should carry ratings from at least two major agencies. The commercial consequence is subtle and enormous. It means S&P and Moody's are not substitutes. An issuer does not choose between them. It hires both, and then decides whether to add Fitch as a third. Competition between the two largest agencies is therefore not competition for the same dollar; each is competing to be one of the two mandatory slots, and both usually win.
This is worth stating precisely in the language of competitive strategy, because the frameworks are frequently applied to this industry as decoration. Under Porter's five forces, buyer power should be high here β the buyers are the largest corporations and sovereigns on earth, and they are price-sensitive negotiators in every other procurement they conduct. It is not high, because the buyer's alternative to paying the fee is not paying a lower fee; it is failing to place the bond. Threat of substitutes should be significant β investors could run their own credit analysis, and the large ones do. It is not significant, because the investor's internal view does not change the regulatory capital charge or satisfy the mandate. Rivalry between S&P and Moody's should be intense given only two significant players. It is muted, because the two-rating convention means share gains at each other's expense are structurally limited.
In Hamilton Helmer's taxonomy, the operative power is closest to a cornered resource: the NRSRO and ECAI designations are assets the incumbents hold and rivals cannot manufacture, obtained through a historical accident rather than through capability. Scale economies reinforce it β the fixed cost of a global compliance and methodology apparatus is spread across far more issues at S&P than at a challenger. Switching costs matter less than people assume at the issuer level and enormously at the investor level, where mandate documents, risk systems, and index rules reference specific agencies by name.
The natural test of whether a moat is real is what happens when someone attacks it with maximum force. The credit rating industry has been attacked with maximum force, twice.
The first attack was legal and political. After the 2008 crisis, in which agencies had assigned AAA ratings to residential mortgage-backed securities and CDOs that subsequently collapsed, Congress responded through the Dodd-Frank Act. Section 932 required the SEC to establish an Office of Credit Ratings β the standing supervisory body that now examines every registered NRSRO annually20 β imposed new reporting, disclosure and examination requirements; mandated public disclosure of rating methodologies; required rating analysts to pass qualifying examinations; gave the SEC authority to deregister an NRSRO; required board approval of procedures and methodologies; and eliminated the safe harbour from expert liability under Rule 436(g) of the Securities Act.16 Congress also directed regulators to remove statutory references to credit ratings wherever a suitable alternative existed.14
The second attack was financial. In 2015, the Department of Justice, nineteen states and the District of Columbia reached a $1.375 billion settlement with Standard & Poor's and its then-parent McGraw Hill, resolving allegations that S&P had knowingly issued inflated ratings on RMBS and CDOs between at least 2004 and 2007.17 In 2017, the Department of Justice, twenty-one states and the District of Columbia secured a settlement of nearly $864 million with Moody's arising from the same era of conduct.18
Now the read-through, which is the single most important thing to understand about this industry's durability. Those settlements were the largest legal penalties in the sector's history, imposed following the most damaging reputational failure imaginable, by an activist Justice Department, alongside the most comprehensive regulatory overhaul the sector has ever faced. Against Moody's 2025 ratings-division operating profit, the $864 million settlement represents roughly four months of segment earnings.5 And the market structure it was meant to reform is, fifty-one years after 1975, essentially unchanged. Ten NRSROs are registered.4 Three of them dominate.
The reason is that Dodd-Frank attacked the agencies' conduct and disclosure, not the demand for their product. Removing statutory references from federal rules did not remove ratings from private investment mandates, from index inclusion rules, from insurance capital frameworks, or from the two-rating underwriting convention. The regulator can stop requiring a rating; it cannot stop the buy-side from requiring one. Regulation created the moat, and then private contract made it self-sustaining without regulation's help.
Which raises the question of what an incumbent does with a licence to tax when it generates far more cash than the licence itself can absorb.
5. The Anatomy of a 60% Margin: Value Chain Economics, Capital Cycles, and Non-Transaction SaaS Conversion
Start with the physical reality of the asset. A credit rating agency owns essentially nothing. It has offices, laptops, a data centre footprint, and several thousand analysts. Capital expenditure at both listed parents runs at a low single-digit percentage of revenue. Working capital is minimal, and often favourable, because surveillance fees are billed in advance. Returns on invested capital, calculated before the goodwill created by acquisitions, are not merely high β they are close to meaningless, because the denominator approaches zero.
That is a wonderful problem and a genuine strategic one. A business generating billions in free cash flow with no internal reinvestment need must either return all of it or buy something. Both Moody's and S&P Global chose to do both, and the choices they made about what to buy have driven the divergence in how the two companies now look.
Moody's built Moody's Analytics β a collection of credit data, default models, economic forecasting, insurance risk modelling and workflow software, assembled substantially through acquisition, most notably the Bureau van Dijk private-company database and the RMS catastrophe risk modelling business.19 S&P Global went larger and broader, merging with IHS Markit to create a multi-asset information business spanning market data, commodity price assessments, mobility data and indices.6
The strategic logic in both cases is the same, and it is more interesting than "diversification." A rating agency sits on a proprietary asset that has nothing to do with the rating itself: it holds decades of standardised, comparable, confidential credit information on virtually every material borrower on earth, along with the default histories that resulted. Sold once as a rating, that information is a transaction. Fed into a subscription database that a bank's credit risk team, an insurer's actuarial team, and a regulator's supervisory team all need continuously, it becomes an annuity.
Here is how that shows up in the numbers.
Exhibit 1 β Moody's Corporation and S&P Global Inc., full-year 2025 Definition: reported consolidated and segment figures for the twelve months ended 31 December 2025, USD. Both companies report on a calendar year, so periods are directly comparable. Adjusted figures are company-defined and exclude items management deems non-recurring; they are not GAAP measures.
| Metric (FY2025) | Moody's Corporation | S&P Global Inc. |
|---|---|---|
| Total revenue | ~$7.7bn, +9% YoY5 | +7.9% YoY organic; Q4 revenue $3.916bn, +9%7 |
| Group adjusted operating margin | 51.1%, +300bps5 | 50.4%, +140bps7 |
| Ratings division adjusted operating margin | 63.6% (MIS), +350bps5 | Ratings the largest division; Q4 revenue +12%7 |
| Ratings revenue mix, full year | Ratings and analytics each +9%5 | Ratings +8%: non-transaction +10%, transaction +6%7 |
| Adjusted diluted EPS | β | $17.83, above guidance of $17.60β$17.857 |
| Capital returned | β | 113% of adjusted free cash flow7 |
| Highest-margin division | MIS at 63.6%5 | S&P Dow Jones Indices at 68.8% operating margin7 |
Sources: Moody's Corporation and S&P Global Inc. fourth-quarter and full-year 2025 earnings releases, February 2026. Evidence status: company-reported, audited period.
Read that aloud and three things jump out.
First, the two ratings franchises are running at essentially identical, extraordinary profitability, and both expanded margins in 2025. Moody's expansion of 350 basis points at the ratings division is the operating leverage described earlier working at full stretch in a strong issuance year.
Second, S&P Global's most profitable division is not ratings at all. S&P Dow Jones Indices ran at a 68.8% operating margin with 14% revenue growth.7 Anyone describing S&P Global as "a rating agency with some other stuff attached" has the causality backwards; the ratings business is the largest division, but the index franchise is the higher-margin one and grew faster. This is the clearest available evidence for why Moody's, with ratings at roughly 56% of revenue, is the purer expression of the credit rating theme, and why S&P Global is better understood as a diversified financial infrastructure company in which ratings is the biggest single exposure.
Third, and most important for the thesis: at S&P Global, non-transaction ratings revenue grew faster than transaction revenue in a good issuance year.7 Non-transaction revenue is surveillance fees, programme fees, and subscriptions β the part that persists when new issuance stops. If it were merely a cushion, you would expect it to grow more slowly during a boom. It did not.
Now trace the money from the top of the chain to the bottom.
Exhibit 2 β The credit ratings profit-pool waterfall (annual, global, order-of-magnitude estimate) Definition: an analytical bridge from global rated debt issuance to free cash flow retained by listed parents. Geography: global. Period: annual run-rate as at mid-2026. Evidence status: Layers 1 and 2 are estimates derived from published issuance statistics and industry-convention fee ranges, not disclosed figures; Layers 3 and 4 are anchored on company-reported segment margins and cash conversion.
| Layer | Estimate | Basis |
|---|---|---|
| 1. Rated global debt issuance | Multi-trillion annual flow; US corporate bond issuance alone was $2.0tn in 2024, with $11.5tn outstanding at 4Q25 | SIFMA fixed income statistics12 |
| 2. Core rating fee pool | ~$12β14bn | Industry-convention take-rate of ~3β5bps on principal; not a disclosed figure |
| 3. Ratings-division operating profit pool | ~$7.5β8.8bn | Applying reported segment margins of ~63β64% at MIS and S&P Ratings57 |
| 4. Free cash flow retained by listed parents | Substantially all of it, then distributed | S&P Global returned 113% of adjusted free cash flow to shareholders in 20257 |
The estimate ranges in Layers 2 and 3 should be treated as bounded arithmetic, not measurement.
The spoken version: a toll of perhaps four basis points on the world's debt creation produces something in the order of twelve to fourteen billion dollars of revenue, of which roughly sixty-three cents in every dollar becomes operating profit, of which almost all becomes free cash flow, of which β in S&P Global's case in 2025 β more than 100% was handed back to shareholders through buybacks and dividends.7 That last figure is worth pausing on. Returning 113% of free cash flow means the company distributed more than it generated in the year. That is a management team explicitly declaring it has no better use for the money, which is both a compliment to the business and a constraint on it.
This is what the capital cycle looks like in an industry that has no capital cycle. There is no capacity to add, no fab to build, no fleet to expand. Entry is blocked by designation rather than by capital, so the classic sequence of installation, overbuild, shakeout and consolidation simply does not run. The industry sits permanently in the deployment-and-maturity phase, generating cash it cannot reinvest in its own core.
Which is why the analytics acquisitions are the real capital allocation story β and why they deserve more scepticism than they usually get. When a 63%-margin business buys a 30%-margin business, group margins fall. Moody's group adjusted margin of 51.1% sits twelve and a half points below its ratings division precisely because Moody's Analytics is structurally less profitable than Moody's Investors Service.5 The bull argument is that analytics revenue is recurring, contractually sticky, and less cyclical, and therefore deserves a higher multiple per dollar despite the lower margin. The bear argument is that a company with an unassailable monopoly used its monopoly cash flows to buy its way into competitive markets β private company data, catastrophe modelling, market data β where it faces genuine rivals including Bloomberg, LSEG, FactSet and MSCI, and where it has no statutory protection whatsoever.
Both arguments are correct at the same time, and the resolution depends on a question a sharp long/short investor would press hard: is analytics growth being driven by underlying demand, or by acquisitions and price increases layered onto a maturing subscriber base? Moody's reported roughly 9% growth in both ratings and analytics in 2025.5 Morningstar's much smaller credit business grew 21.7% reported and 20.9% organic in the same year.21 The gap between reported and organic growth is the number to watch, and it is disclosed. Where a company reports only the former, that omission is itself information.
The other thing the analytics build-out does is change what a downturn looks like. In the pre-2008 configuration, a frozen bond market hit essentially all of a rating agency's revenue. In the current configuration, roughly half of group revenue at both companies is recurring subscription and surveillance income that continues regardless. The earnings floor is structurally higher than the historical cycle would suggest. That is the strongest single argument in the entire bull case, and it is an argument about business architecture rather than about the debt cycle.
It also raises an obvious follow-on. If the incumbents are busy building software businesses, who is attacking the ratings business itself?
6. The Competitive Field: Big Three Hegemony, Structured Finance Challengers, and the European Fracture
On 2 November 2023, the Governing Council of the European Central Bank decided to accept Scope Ratings GmbH, a Berlin-headquartered agency, as a new External Credit Assessment Institution for the purposes of the Eurosystem Credit Assessment Framework.15 The acceptance covered sovereign, corporate, financial institution and covered bond ratings, and followed an assessment against quantitative and qualitative acceptance criteria, with supervisory input from ESMA.15 The ECB noted that integration into Eurosystem IT infrastructure would take several months; the go-live date was pre-announced separately, and Scope's asset-backed securities ratings were subsequently brought into the framework.22
For the first time in the ECAF's history, a European agency could make European collateral eligible at the European central bank.
The commercial consequence arrived quickly and in a form that tells you exactly how this industry works. German BundeslΓ€nder β sub-sovereign borrowers with large, regular funding programmes β mandated Scope following the ECB's acceptance.22 Deka, the asset management arm of the German savings banks, moved to integrate Scope's ratings into its processes.22 Scope did not win that business by producing better analysis than S&P. It won it by acquiring a regulatory designation, at which point European institutions with a political and practical preference for a European provider were finally able to act on it.
This is the general law of the sector, stated as clearly as the evidence ever states it: share in credit ratings is won by obtaining designations, not by winning analytical arguments. Every credible challenger story in the industry is a designation story.
Consider the field in that light.
Fitch Ratings is the third global agency and by some distance the most interesting corporate structure in the sector, because it is not a public company. Fitch Group is wholly owned by Hearst, the family-controlled American media company.3 Hearst reported revenue of $13.5 billion for 2025, up 3%, and record profit, with chief executive Steven Swartz attributing the strength substantially to Fitch, whose earnings "far exceeded" 2024 as a robust bond market lifted both Fitch Ratings and its data and analytics sibling Fitch Solutions.3 Hearst's business media operations, of which Fitch is the dominant component, now account for 60% of total company profit, up from less than 10% fifteen years earlier.23
Pause on that. A company most people associate with magazines derives the majority of its profit from a credit rating agency. It is also a reminder of a real limitation in this analysis: Hearst does not report a standalone Fitch profit and loss, so no like-for-like margin comparison with MIS or S&P Ratings is possible. Directionally, the disclosure that Fitch drove record profit at a $13.5 billion revenue group is consistent with high-margin economics, but the specific number is not public and should not be assumed.
Morningstar DBRS β the credit arm of Morningstar, Inc. (NASDAQ: MORN) β is the most quantifiable challenger, because Morningstar reports it as a segment. Morningstar Credit generated full-year 2025 revenue of $354.4 million, up 21.7% reported and 20.9% organic, with adjusted operating income of $114.8 million and an adjusted operating margin of 32.4%.21 Growth was attributed to strength in corporate ratings globally and structured finance ratings in the US and Europe.21 In the fourth quarter, 61% of Morningstar Credit revenue came from structured finance β ABS, CMBS and RMBS β roughly 33% from corporate and fundamental credit ratings including Canadian corporates, middle-market lending and private ratings outside Canada, and about 6% from licensed data.24 DBRS itself passed fifty years of rating activity, having built its franchise from a Canadian base.25
Two observations follow. First, a 32.4% margin against MIS's 63.6% is the price of subscale in this industry: the fixed cost of methodology, compliance and global coverage does not shrink proportionally for a challenger. Second, that margin is rising fast on 20%-plus organic growth, which is what genuine share capture looks like when it happens. Morningstar Credit is roughly 15% of Morningstar's $2.4 billion group revenue,21 so an investor buying MORN for credit exposure is buying a minority of a company whose main business is investment research and wealth software β real optionality, diluted exposure.
KBRA, the Kroll Bond Rating Agency, is privately held and therefore invisible in the financial data, but highly visible in the market. Founded after the financial crisis on the explicit proposition that the incumbents had failed structured finance investors, KBRA has issued more than 80,000 ratings across more than 6,300 entities covering over $3.8 trillion, and held roughly 13.7% of the US asset-backed securities market at the end of 2025.26 Its expansion into private credit is the most thematically significant challenger move in the industry: KBRA reports more than 1,000 ratings of transactions and issuers in the private capital universe, work with over 100 sponsors, and record rated net asset value lending issuance in 2025.26 It opened its first Asia-Pacific office, in Tokyo, in 2025, alongside existing Dublin and London operations.26
Why can KBRA compete in structured finance and private credit when it cannot compete in benchmark investment-grade corporates? Because the two-rating convention is weakest precisely where the deal is bespoke. A CLO manager or a direct lender assembling a private credit facility is not selling into a broad index-tracking bid governed by a decades-old mandate; it is selling to a small number of sophisticated buyers who care about the analytical framework and the turnaround time. Where the buyer set is concentrated and expert, the incumbency premium falls. Where the buyer set is diffuse and mandate-driven, it does not.
Scope Ratings, discussed above, is backed by European institutional shareholders including AXA, BPCE, CrΓ©dit Agricole and DekaBank, which gives it both capital and a natural client base. Its ECAF acceptance is a genuine structural change in the European competitive map. Whether it converts into material share depends on something not yet observable: whether European issuers begin substituting Scope for one of their two existing ratings, or simply add it as a third. Adding a third rating expands the fee pool without damaging the incumbents at all.
Three smaller NRSROs round out the map and are worth knowing about because each illustrates a boundary condition. Egan-Jones Ratings is the industry's most prominent investor-pays survivor, and its continued small scale after decades of operation is the most direct available evidence that the investor-pays model cannot fund a competitive global rating apparatus. HR Ratings de MΓ©xico holds NRSRO registration and focuses on Mexican and Latin American sovereign, sub-sovereign and corporate credit β a demonstration that regional specialisation is a viable niche where local knowledge is genuinely differentiating. Demotech rates property and casualty insurer financial stability, serving a segment the majors under-cover, which is the classic profile of a niche that persists because it is too small to be worth attacking.
Exhibit 3 β Challenger scoreboard, latest disclosed period Definition: most recent publicly disclosed operating figures. Note that these entities disclose on different bases; Morningstar Credit is a reported segment of a listed company, KBRA is private and discloses activity metrics only, Scope and Fitch disclose neither. Direct ranking across these rows is not valid.
| Entity | Disclosure basis | Latest disclosed figures | Where it actually competes |
|---|---|---|---|
| Morningstar Credit (DBRS) | Reported segment, FY2025 | Revenue $354.4m, +21.7% (+20.9% organic); adj. operating margin 32.4%21 | US/EU structured finance (61% of Q4 revenue), Canadian corporates, middle-market and private ratings24 |
| KBRA | Private; activity metrics only | 13.7% US ABS market share at end-2025; 80,000+ ratings; 1,000+ private capital ratings; 100+ sponsors26 | US ABS/CMBS, private credit, NAV lending, fund finance |
| Scope Ratings | Private; no financials disclosed | ECAF acceptance 2 Nov 2023; ABS ratings added subsequently; German BundeslΓ€nder and Deka mandates followed1522 | European sovereign, sub-sovereign, corporate, covered bonds, ABS |
| Fitch Ratings | Parent-level commentary only | Hearst 2025 revenue $13.5bn, +3%, record profit; business media incl. Fitch = 60% of group profit323 | Global corporates, financial institutions, structured finance |
Sources as footnoted. Evidence status: Morningstar figures are audited segment disclosure; KBRA and Scope figures are company activity claims and regulator announcements; Fitch has no standalone financial disclosure.
The spoken takeaway: the challengers are real, they are growing faster than the incumbents, and they are almost entirely concentrated in structured finance, private credit, and regional pockets where the two-rating convention is weak or where a new designation has just been granted. Nobody is meaningfully attacking the benchmark global corporate bond franchise, because there is no available angle of attack. A challenger cannot undercut on price into a market where the buyer's constraint is mandate eligibility rather than cost.
The one place where challengers have won at scale, over decades, without a designation fight, is where the domestic market never used the American agencies in the first place.
7. Asian Frontiers and Domestic Gatekeepers: The Growth Engine in India, Japan, and China
A treasurer at an Indian manufacturing group preparing a rupee bond issue does not call New York. Neither does a Japanese utility issuing yen paper, nor a Chinese state-owned enterprise placing onshore renminbi debt. Local currency debt markets are rated by local agencies, under local scales, for local investors and local regulators. Roughly speaking, an AAA on the Indian domestic scale means "the best credit in India," which is a different statement from "the best credit in the world."
This creates the most economically interesting structure in the industry: the majors do not compete in these markets. They own the winners.
India. CRISIL Limited, listed in Mumbai, is majority-owned by S&P Global, which holds 66.64% and acquired control in 2005.27 For the year to December 2025, CRISIL reported income from operations of βΉ3,649 crore, up 11.9%, profit before tax of βΉ1,041 crore, up 12.4%, and profit after tax of βΉ766 crore, up 12.0%, with a total dividend of βΉ61 per share.27
Now the detail that reframes what CRISIL actually is. Its Ratings Services segment generated revenue of βΉ1,078.7 crore, up 18.4%, with a segment margin of 44.3%. Its Research, Analytics and Solutions segment generated βΉ2,572.4 crore, up 9.4%, at a 22.0% margin.27 Ratings is under 30% of revenue. The larger business is an analytics and research operation, a substantial part of which is the Crisil Global Analytics Centre providing analytical and operational support to S&P Global Ratings itself.27
That is a genuinely important correction to how CRISIL is often described. An investor buying CRISIL as "the Indian credit ratings pure play" is buying, by revenue, mostly an offshore analytics services business whose largest relationship is with its own parent. The ratings segment is the higher-margin half β 44.3% versus 22.0% β and grew twice as fast in 2025, so the mix is improving. But the exposure attribution has to be honest: roughly 30% of revenue at a 44% margin is credit ratings, and roughly 70% at a 22% margin is knowledge-process work bought partly by a related party. Recent acquisitions including PriceMetrix and momentum from Coalition Greenwich have pushed the mix further toward analytics.27
There is also a cyclical caveat worth recording: CRISIL noted a muted Indian corporate bond issuance environment in the period despite improving bank asset quality.27 Indian corporates still borrow overwhelmingly from banks. The Indian bond market deepening story is real and long-dated, and it is also slower than the enthusiasm around it.
ICRA Limited, in which Moody's holds approximately 51.86% as of March 2025, reported consolidated revenue from operations of βΉ599.51 crore for the year to March 2026, up 20.4%, with profit after tax of βΉ182.53 crore, up 6.6% β growth assisted by the acquisition of Fintellix India, which contributed particularly to the research and analytics segment.2829 Note the comparability problem immediately: ICRA reports on an April-to-March fiscal year while CRISIL reports on a calendar year, so the two sets of figures do not cover the same twelve months and should not be ranked against each other without adjustment. Note also that ICRA's profit growth of 6.6% ran well below its revenue growth of 20.4%, which is what buying growth rather than generating it usually looks like in the first year.
The ranking of Indian agencies is contested and depends heavily on the measure used. CRISIL is consistently identified as the domestic leader, with share estimates ranging from roughly 40% to over 60% depending on whether one counts rated volume, number of instruments, or revenue.30 Whether ICRA or CARE Ratings β the largest independent Indian agency, unaffiliated with a global major β holds second place is genuinely disputed, with recent commentary suggesting CARE has overtaken ICRA on some measures.30 An investor should treat any precise Indian market share figure with suspicion unless the denominator is specified.
Japan. The Japanese market is the clearest demonstration that domestic incumbency, once established, is nearly as durable as a regulatory designation. Japan Credit Rating Agency and Rating and Investment Information β the latter owned by Nikkei Inc., the publisher of the Nihon Keizai Shimbun (ζ₯ζ¬η΅ζΈζ°θ) β dominate domestic yen issuance. JCR holds both NRSRO registration in the United States and ECAI recognition in Europe, which lets Japanese paper it rates travel internationally. Neither is listed separately, so there is no public expression of the Japanese domestic ratings market for an equity investor.
China. Moody's owns 30% of China Chengxin International Credit Rating, the largest domestic Chinese agency, held through Moody's China (B.V.I.) Limited, with the remaining 70% held domestically.3132 Moody's originally acquired 49% in 2006, with Ministry of Commerce approval that August, and subsequently reduced its holding to the current minority position.32 Lianhe Credit Rating is the principal domestic rival, and Dagong Global is state-controlled.
The Chinese arrangement should be read as a strategic option rather than a financial exposure. A 30% non-controlling stake in a domestic agency operating on a domestic rating scale, in a market where the overwhelming majority of rated issuers carry AAA or AA domestic ratings, contributes little to Moody's consolidated economics and confers no control over methodology. Its value is positional: it keeps Moody's inside the world's second-largest bond market at a time when the political direction of travel is toward domestic providers. In May 2023, CCXI published a downgrade of the United States sovereign rating β a reminder, if one were needed, that ratings in a fragmenting world are partly instruments of financial statecraft.33
Across all three markets, the same pattern holds: the Western majors captured emerging-market growth through ownership rather than through competition, and in doing so accepted a lower-margin, higher-growth, locally regulated business alongside their global franchise. It is a sensible use of surplus cash, and it is not where the thesis lives.
The thesis lives in what a public-market investor can actually buy, and at what price.
8. Stock Expressions and the Variant Wedge: S&P Global, Moody's, and the Public Market Mispricing
Start with the decision context, because the answer changes with it. The frame here is general institutional public-equity research over a multi-year thematic horizon, global listed expressions, no position sizing and no recommendation. A long-only benchmark-relative investor and a long/short absolute-return investor face different problems with the same facts, and where that matters below, it is flagged.
The observable event that makes this section necessary happened on 10 February 2026. S&P Global reported a year in which revenue grew 7.9%, adjusted operating margin expanded 140 basis points to 50.4%, adjusted diluted EPS of $17.83 came in above the top of guidance, the Ratings division grew 8% with non-transaction revenue up 10%, the Indices division grew 14% at a 68.8% operating margin, and the company returned 113% of adjusted free cash flow to shareholders. Guidance for 2026 called for 6.0% to 8.0% organic constant-currency revenue growth and adjusted EPS of $19.40 to $19.65, or 9% to 10% growth.7
The shares fell 14.89% in pre-market trading to $378.04, against a 52-week high of $579.05 β a peak-to-trough decline of more than 34%.7 The proximate trigger was an adjusted EPS miss of two cents in the fourth quarter, $4.30 against an expectation of $4.32.7
That is the mispricing mechanism in its purest observable form. It is worth being careful about what it does and does not prove. It does not prove the market is wrong. A one-third de-rating in a business whose earnings grew is an expression of a changed view about duration β about how long the growth and the margin can persist, and what discount rate applies to a long-duration cash flow stream. The market did not conclude that 2026 earnings would be lower. It concluded that the stream was worth less.
So: what does the current price require to be true, and where might the market and a thematic investor legitimately disagree?
Moody's Corporation (MCO) is the purest listed expression. Ratings β Moody's Investors Service β represents roughly the majority of revenue and carries a 63.6% adjusted operating margin; Moody's Analytics carries the balance at a materially lower margin.5 The exposure proof is direct and quantified in segment disclosure: an investor buying MCO is buying, above all, the transaction and surveillance fee stream on global debt issuance, with a subscription analytics business attached. Growth in 2025 ran at roughly 9% in both segments.5 The optionality is in private credit ratings and in embedding generative AI into analytics workflow, both of which are real initiatives with disclosed products and neither of which yet has separately disclosed revenue that would allow an investor to size it.
The first smart reason a senior investor rejects MCO is straightforward: it is the highest-beta expression of the debt cycle in the group. A genuine multi-year freeze in high-yield and leveraged finance β the segments with the highest fee intensity β would hit MCO harder than SPGI, because MCO has less non-ratings revenue to absorb the shock. What would need to become true for the thesis to merit deeper work is that non-transaction and private credit revenue continue growing through a weak issuance period, demonstrating the earnings floor rather than asserting it. What would kill the company-level thesis is straightforward and observable: MIS adjusted operating margin falling and staying below 55%, or analytics organic growth decelerating below mid-single digits, either of which would indicate that the pricing power and the recurring-revenue conversion are weaker than the 2025 results imply.
S&P Global Inc. (SPGI) is a diversified beneficiary rather than a pure play. Ratings is the largest division but not the majority of revenue, and the company's highest-margin, fastest-growing division in 2025 was Indices, not Ratings.7 For a thematic investor, that dilution cuts both ways: it damps the exposure to the credit ratings theme while adding a genuinely excellent, structurally growing asset-management-linked franchise. The first smart rejection is that an investor seeking credit ratings exposure is paying for four other businesses, two of which β Market Intelligence and Mobility β compete in genuinely contested markets without any statutory protection. What would kill the company-level thesis is evidence that the non-ratings divisions are consuming the cash the ratings division generates without earning an adequate return on it, which would show up as declining group returns on capital alongside continued acquisitions.
Morningstar Inc. (MORN) offers the highest-growth credit ratings exposure and the lowest exposure purity. Morningstar Credit grew 20.9% organically to $354.4 million with a 32.4% adjusted operating margin β a genuinely impressive share-capture story β but represents roughly 15% of a $2.4 billion group whose main businesses are investment research, indexes and wealth software.21 An investor buying MORN for credit ratings exposure is making a 15% bet inside an 85% bet on something else. The first smart rejection is exactly that: the exposure is real, disclosed, and too small to drive the security.
CRISIL Limited and ICRA Limited are regional expressions with the exposure caveats set out in the previous section: CRISIL's ratings segment is under 30% of revenue, and ICRA's recent growth was acquisition-assisted with profit growth well below revenue growth.2729 Both are majority-owned by their global parents, which means minority shareholders hold a non-controlling position in a subsidiary whose largest commercial relationship is with its controlling shareholder β a governance structure that requires the investor to accept related-party pricing on faith. CARE Ratings is the independent Indian alternative without that structural conflict, and correspondingly without a global parent's technical and referral support.
Two categories should be actively excluded from the theme, because they are commonly and wrongly included.
Financial data terminals and analytics vendors β Bloomberg, LSEG, FactSet β sell into overlapping customers and are frequently grouped with the rating agencies as "financial information." They hold no NRSRO or ECAI designation. Nothing in any regulation or mandate requires anyone to buy their product. They compete on price, functionality and data quality in an open market, which is a fundamentally different competitive position, and their multiples should not be read across.
Consumer credit bureaus β Equifax, Experian, TransUnion, and the scoring provider FICO β are frequently treated as the same industry because they also produce credit scores. Their revenue is driven by consumer lending origination volumes, principally mortgage and auto, which makes them a levered bet on consumer credit cycles and mortgage rates. Their business model, customer base, regulatory framework and margin structure differ materially from issuer-pays corporate ratings, and the two should not be compared or substituted.
Where a variant view is genuinely supportable. Three specific gaps are established by evidence rather than assertion:
Pricing indexation. The agencies raise base rating and subscription prices annually. That price growth compounds independently of issuance volumes, which means a model built purely on volume forecasts systematically undercounts revenue in flat-volume years. The evidence for this is the observed gap between issuance trends and revenue growth over multi-year periods. The caveat is that neither company discloses realised price increases separately from mix, so the magnitude is inferred rather than measured.
The recurring floor. S&P Global's 2025 disclosure that non-transaction ratings revenue grew 10% against transaction revenue's 6% is direct, dated evidence that the recurring base is growing faster than the cyclical base.7 A model that treats ratings as an issuance derivative will be wrong in both directions β too pessimistic in troughs, too optimistic about the cyclical upside.
Private credit monetisation. The addressable market expansion into a $2.28 trillion private credit pool with sub-20% rated penetration is real, and the observable evidence of it β Morningstar Credit's 20.9% organic growth, KBRA's 1,000-plus private capital ratings β is running at rates far above the incumbents' group growth.2126 The caveat is that the challengers are capturing a disproportionate share of it, so this is a market expansion whose benefit does not accrue proportionally to the largest incumbents.
Where a variant view is not supportable. The claim that generative AI will expand ratings margins to the high sixties is an aspiration with no disclosed evidence behind it. Neither company has quantified AI-driven cost savings in ratings. Until they do, that leg of the bull case should be treated as unpriced optionality rather than as a forecast.
On crowding. The question of whether these names are crowded is asked constantly and answered carelessly. Both MCO and SPGI screen in the top decile on quality and profitability factors, which means they appear in the same quantitative and quality-growth strategies across the industry. That is a structural observation about factor construction, not a positioning measurement. Without direct evidence from ownership data, flow data or short interest, the honest statement is that valuation and expectations in this pair have historically left limited room for execution error β which the February 2026 reaction to a two-cent miss demonstrated more clearly than any positioning dataset could.
The bear case that a serious investor should be able to state as well as the bull is not about issuance at all. It is about who decides that a rating is required.
9. Game Changers, Systemic Risks, and AI Protocols: Where the Tollbooth Could Break or Migrate
There are four plausible ways this industry changes materially. Only one of them is the one people talk about.
The one people talk about: automated credit assessment.
The technical premise is sound. Large language models trained on public filings, transaction data and market prices can generate continuous default probability estimates at near-zero marginal cost, updated in real time rather than at committee cadence. The analytical quality of such systems, on liquid public issuers with rich disclosure, is genuinely competitive with a ratings committee, and on the dimension of timeliness it is plainly superior β a model updates on the filing, whereas a rating updates when a committee meets.
The popular conclusion drawn from this is that AI will disintermediate the rating agencies. The evidence does not support it, and the reason is worth stating carefully because it is the load-bearing wall of the entire investment case.
The rating agencies do not sell credit analysis. They sell a designation. When a European bank pledges collateral to the ECB, the eligibility test is whether the rating comes from an accepted ECAI under the Eurosystem Credit Assessment Framework.15 When a US insurer calculates its risk-based capital charge, the test references NRSRO ratings and NAIC designations.11 When a bond enters an index, the rules specify agencies by name. A model that is more accurate than Moody's does not satisfy any of these tests, and a firm that wants to satisfy them must register as an NRSRO and be accepted as an ECAI β at which point it is a rating agency, competing on the incumbents' terms, with the incumbents' compliance cost base.
Where AI genuinely bites is one layer down, in analytics. Moody's Analytics and S&P Global Market Intelligence sell credit research, models and workflow tools into exactly the use cases that generative models attack most effectively: summarising documents, extracting financials, generating first-draft credit memoranda. That is a competitive market with no statutory protection, and it is where roughly a third to a half of group revenue sits. The incumbents are responding by embedding AI into their own products rather than resisting it, which is the correct strategic response and also an admission that the pricing of standalone research content is under pressure. The observable milestone to watch is not an AI product launch β those have already happened β but whether analytics organic revenue growth and margins hold as those products scale.
The one that actually matters: the insurance regulator.
The largest single institutional buyer of the credit that has migrated out of banks is the US insurance industry, and the body that determines how those holdings are capitalised is the NAIC. Historically, the NAIC's "filing exempt" process allowed insurers to convert an NRSRO rating directly into an NAIC designation, and therefore into a capital charge, with minimal independent review. That was, functionally, the NAIC outsourcing capital regulation to private rating agencies.
The NAIC has been visibly walking that back. It has established a Credit Rating Provider Working Group tasked with identifying improvements to the filing exempt process through implementation of a credit rating provider due diligence framework, and with implementing policies on NAIC staff administration of rating agency ratings used in NAIC processes β explicitly including staff discretion over the applicability of their use in the administration of filing exempt status.34 In parallel, the NAIC's Structured Securities Group took on responsibility for financially modelling CLO securities and evaluating tranche-level losses under calibrated collateral stress scenarios in order to assign NAIC designations directly, with insurers required to report financially modelled CLO designations beginning with year-end 2025 statutory filings.11
Read those two developments together and the mechanism is clear. For CLOs β a $276.8 billion insurer exposure at year-end 2024 β the NAIC is no longer taking the agencies' word for it.11 It is modelling the securities itself, with the stated goal of ensuring that the aggregate capital charge for owning all tranches of a CLO equals the charge for owning the underlying loans, eliminating the capital arbitrage that made rated tranches attractive in the first place.11
This is the single most important risk in the sector, and it is the inverse of the AI story. AI attacks the agencies' analytical value while leaving the designation intact. The NAIC attacks the designation while conceding the analysis. If a US insurance regulator can assign designations without reference to an NRSRO rating, then for that asset class the statutory demand simply disappears β and the private credit expansion that underpins the growth half of the thesis is precisely the asset class in question.
The beneficiaries and losers are asymmetric. A stricter, model-based NAIC regime hurts the agencies that specialise in insurance-facing private credit ratings β KBRA and Morningstar DBRS most directly β more than it hurts the global corporate franchises of S&P and Moody's, whose core business faces no equivalent regulator. It also, perversely, could increase demand for analytics: insurers required to conduct independent due diligence rather than relying on ratings need models and data to do it with, and the agencies sell those.
Geopolitical fragmentation. The third pathway is slower and harder to observe. If Chinese, Indian, Gulf and other domestic capital markets continue deepening, an increasing share of the world's debt will be rated by domestic agencies on domestic scales, outside the Big Three's economics except through minority stakes. CCXI's publication of a US sovereign downgrade in 2023 is a small but real signal that rating scales are becoming instruments of statecraft as well as of finance.33 The observable milestone is whether major cross-border issuance β the paper that must appeal to global investors β continues to require Big Three ratings. So far it does, because global institutional mandates reference global scales. Fragmentation of the mandate architecture, not of the issuance, is what would matter.
Tokenised debt and on-chain credit. The fourth pathway is the most speculative and the furthest from commercial scale. Tokenised real-world assets on blockchain rails could in principle carry embedded, continuously updated credit assessments produced by decentralised protocols. The hurdles are not technical. They are that institutional buyers of scale are governed by mandates and capital rules that reference accredited agencies, that smart contract enforceability in insolvency remains unsettled across jurisdictions, and that central bank collateral frameworks have no mechanism to recognise a protocol as an ECAI. Announced pilots are not evidence of adoption, and there is currently no disclosed revenue at any listed company attributable to on-chain credit assessment.
There is a fifth risk that belongs here and is rarely listed: structural separation. Both S&P Global and Moody's now run large analytics businesses that sell to the same institutions their ratings divisions rate and to the investors who consume those ratings. Regulators have historically been alert to conflicts between the commercial and analytical sides of a rating agency, and Dodd-Frank explicitly addressed firewalls between sales and analysis.16 A future requirement to structurally separate ratings from analytics would hit both companies simultaneously and would fall hardest on the strategic logic β converting rating relationships into analytics subscriptions β that justifies the entire capital allocation of the past decade. There is no current proposal to that effect. It is a tail risk with a well-defined mechanism, which is the kind worth writing down.
What unites all five is that none of them is a competitive threat in the ordinary sense. Nobody is going to out-analyse Moody's and take its business. The risk in this industry is always that somebody with a rulebook decides the stamp is no longer required.
10. The Evidence Dashboard: Crux KPIs, Dated Kill Criteria, and the Thematic Investment Decision
Return to the proposition this article set out to test: that credit intermediation is migrating structurally from banks to capital markets and private credit, and that this migration manufactures legally mandated demand for accredited third-party credit assessment which scales with the stock of global debt.
As of July 2026, the evidence says that belief is holding at the level of the structural force and fraying at the level of the regulatory guarantee.
The structural force is confirmed by the strongest available data. Non-bank financial intermediation reached $256.8 trillion and 51.0% of global financial assets in 2024, growing at roughly double the banking sector's rate, with the narrow credit-intermediating measure up 12% to $76.3 trillion.89 Private credit crossed $2 trillion and is projected to approach $4.5 trillion by 2030.10 Both listed rating franchises expanded margins in 2025 while growing revenue at 8β9%, with the recurring component growing faster than the transactional one.57 Challengers grew faster still, in the specific segments the theory predicts they would.2126
The fraying is at the NAIC. The body that determines capital treatment for the largest institutional buyer of migrated credit is actively building the capability to assign designations without relying on rating agency output, and has required insurers to report NAIC-modelled CLO designations from year-end 2025.1134 The theory says regulation manufactures demand. That regulator is manufacturing less of it.
Both things are true simultaneously, which is why the thesis needs indicators rather than conviction.
Here is the hierarchy. At the structural level, the FSB's annual non-bank intermediation measure and the trajectory of private credit AUM tell you whether the migration continues; these lead by years and update annually. At the adoption level, private credit rating penetration and the NAIC's treatment of ratings tell you whether the new addressable market converts; these lead by quarters. At the industry level, corporate bond issuance and outstanding tell you the near-term revenue environment; these are coincident and update monthly. At the company level, segment margins and the transaction/non-transaction revenue split tell you whether pricing power and recurring conversion are working; these lag and update quarterly.
Four of those observables carry the thesis. They are set out below, and the discipline in choosing them is that each must move before revenue does, and each must discriminate between a specific bull and bear claim.
Exhibit 4 β Crux KPIs Definition: four leading observables selected because each sits on a binding constraint of the thesis. Latest readings are dated; where no single official global series exists, the limitation is stated and a bounded proxy used.
| KPI | What it measures, and why it leads | Bull vs bear claim it settles | Source and cadence | Latest dated reading | Confirm / break threshold |
|---|---|---|---|---|---|
| 1. Non-transaction share and growth of ratings revenue | The proportion of ratings revenue that is surveillance, programme and subscription fees, and its growth rate. Leads because it reveals the earnings floor before an issuance downturn arrives to test it. | Bears: ratings is an issuance derivative. Bulls: half the revenue persists through a freeze. | S&P Global and Moody's quarterly segment disclosure57 | FY2025: S&P Ratings non-transaction revenue +10% vs transaction +6%7 | Confirms while non-transaction growth β₯ transaction growth. Breaks if non-transaction growth falls below 4% for two consecutive quarters. |
| 2. Ratings-division adjusted operating margin | Segment operating income over segment revenue. Leads the pricing-power question because price increases hit margin before they are visible in revenue mix. | Bears: analyst wage and compliance inflation compress margins. Bulls: annual price increases outrun cost inflation. | Quarterly segment disclosure, MCO and SPGI57 | FY2025: MIS 63.6% adjusted, +350bps5 | Confirms while sustained above 60%. Breaks below 55% for more than two quarters. |
| 3. NAIC treatment of rating-agency output for insurer capital | Whether the NAIC administers filing-exempt status using NRSRO ratings, or assigns designations from its own models. Leads because a rule change precedes the revenue effect by years. | Bears: the statutory demand is revocable by a single standard-setter. Bulls: no regulator has a workable substitute at scale. | NAIC Credit Rating Provider Working Group and Structured Securities Project; continuous, with National Meeting cadence1134 | CLO designations financially modelled by NAIC, required in year-end 2025 insurer filings; staff discretion over filing-exempt applicability under active implementation1134 | Breaks the private-credit growth leg if NAIC modelling extends from CLOs to broader private placements. Confirms if filing exempt remains rating-referenced for the bulk of insurer private credit. |
| 4. Challenger share capture in structured and private credit | Organic revenue growth and market share at the specialist agencies competing where the two-rating convention is weak. Leads because share loss appears in challenger growth before it appears in incumbent revenue. | Bears: challengers will undercut on fee and erode pricing power. Bulls: challenger gains are confined to segments the majors under-serve. | Morningstar segment disclosure (quarterly); KBRA activity disclosure (periodic)2126 | FY2025: Morningstar Credit +20.9% organic, 32.4% adj. margin; KBRA 13.7% US ABS share at end-20252126 | Breaks the pricing-power leg if challenger gains coincide with incumbent ratings margins falling below 60%. Confirms if incumbent margins hold while challengers grow β i.e. market expansion rather than share transfer. |
Note on measurement limitations: there is no single official series for global rated debt issuance. SIFMA publishes US corporate bond issuance and outstanding on a monthly and quarterly basis β $2.0 trillion issued in 2024, $11.5 trillion outstanding at 4Q25 β and that series is used here as a bounded proxy for the issuance environment rather than as a global measure.12 Likewise, no regulator publishes a count of private credit ratings; the challenger disclosures above are the best available observable and are company-reported.
The spoken version: watch whether the recurring half keeps outgrowing the deal half, whether margins hold above sixty, whether the American insurance regulator keeps deferring to ratings, and whether the challengers' growth comes out of the incumbents' margins or out of a bigger pie. Two of those come from audited segment disclosure every quarter. One comes from a standard-setter's committee papers. One requires reading a challenger's disclosure to learn something about an incumbent.
Now separate the two kinds of kill criteria, because conflating them is how thematic investors lose money on correct forecasts.
The theme dies if the statutory requirement for accredited third-party credit assessment is materially withdrawn β through NAIC model-based designation extending beyond CLOs to the broad private placement market, through a European or US move to strip rating references from bank and insurance capital frameworks with a workable replacement, or through structural separation requirements that break the ratings-to-analytics economic model. Watch the rulebooks, not the earnings.
The securities die for different and more mundane reasons. MCO fails if MIS margins break below 55% or analytics organic growth decelerates to mid-single digits. SPGI fails if group returns on capital decline while acquisitions continue, indicating the ratings franchise is subsidising value-destructive expansion. MORN's credit thesis fails on a simple arithmetic ceiling β the segment is too small to move a $2.4 billion company, and the failure mode is dilution rather than deterioration.21 CRISIL fails on related-party exposure: if S&P Global's transfer pricing for global analytics centre work compresses, minority holders bear it, and the disclosure available to them will not explain it in advance.27
On common factor exposure, three duplications deserve flagging. First, MCO and SPGI are the same bet on the same driver with the same regulatory tail risk; holding both diversifies company execution risk and diversifies nothing else. Second, both sit in the top decile of quality and profitability factor screens, which means they will be sold together in a factor unwind irrespective of fundamentals. Third β and least appreciated β both are long-duration equities whose valuations are directly sensitive to real yields, which makes them a levered bet on interest rates in an unusual way: higher rates simultaneously compress the multiple and, if sustained enough to freeze discretionary issuance, reduce the earnings. That is a correlated rather than an offsetting exposure, and it is what produced the 34% peak-to-trough decline in SPGI shares by February 2026.7
Rotation logic follows from the mechanism rather than from the tickers. If the statutory requirement erodes, the economic value of underwriting credit does not disappear; it moves to whoever holds the credit risk and can price it β private credit asset managers such as Ares, Blue Owl and Apollo β and to the software vendors that help institutions document independent due diligence they can no longer outsource to a rating. That is a coherent analytical pathway, and it is worth noting that a stricter NAIC is simultaneously bearish for insurance-facing rating agencies and demanding of exactly the analytics products the same companies sell. The offsetting exposure sits inside the same firms.
Which brings the argument back to where it started, on a Friday evening in August 2011, when a committee at a private company changed a letter on a sovereign and the market bought the downgraded asset.
The credit rating industry's defining characteristic is that its product's commercial value has been decoupled from its predictive value for fifty-one years. The 1975 designation, the two-rating convention, and the capital frameworks built on top of them mean that being required matters more than being right. That is an uncomfortable thing for an analyst to say about an analytical industry, and it is the most reliable fact about it.
The migration of credit out of banks is real, it is measured by the world's financial supervisors, and it is generating more traffic through the tollbooth every year β including into a private credit market where rated penetration remains low and the growth rates are consequently high. The upstream belief is holding. But the same migration has drawn the attention of the one authority with both the mandate and the incentive to build a substitute: the regulator of the institution that ends up holding the paper. The NAIC is not trying to replace credit ratings out of principle. It is doing it because insurers now hold enough migrated private credit that outsourcing the capital charge to a private vendor has become a supervisory problem.
The industry's greatest strength and its only real vulnerability turn out to be the same fact. Everything depends on somebody writing "shall be rated by a nationally recognized statistical rating organization" into a rule. Those words have survived a financial crisis, an act of Congress, two billion-dollar fraud settlements, and half a century of academic criticism. Whether they survive the private credit boom is the question worth monitoring β and it will be answered in committee papers long before it appears in an earnings release.
Glossary
NRSRO (Nationally Recognized Statistical Rating Organization) β A credit rating agency registered with the US Securities and Exchange Commission under Section 15E of the Securities Exchange Act of 1934. The designation originated in 1975 within the broker-dealer net capital rule and is what makes a rating usable for US regulatory capital purposes. Ten agencies held the registration as of 31 December 2025. It is the single most valuable asset in the industry.
ECAI (External Credit Assessment Institution) β The European equivalent designation. An agency recognised by European authorities whose ratings can be used to determine bank capital weights and, under the ECB's framework, central bank collateral eligibility. Obtaining ECAI status is the only viable route to competing at scale in Europe.
ECAF (Eurosystem Credit Assessment Framework) β The European Central Bank's framework defining which credit assessments make collateral eligible for Eurosystem refinancing operations. Acceptance into ECAF converts an agency from a commentator into a gatekeeper, which is why Scope Ratings' acceptance in November 2023 mattered commercially far more than any analytical achievement.
Issuer-pays model β The dominant business model, in which the borrower rather than the investor pays for the rating. Adopted in the early 1970s, it converted rating agencies from publishers into levy collectors on capital formation, because fees scale with the size of the debt being rated. It also creates the industry's structural conflict of interest: the party being graded pays the grader.
Investor-pays model β The original model, in which subscribers buy access to ratings and research. It survives at the margins, most visibly at Egan-Jones. Its persistent small scale is the best available evidence that subscription revenue cannot fund a globally competitive rating apparatus.
Surveillance fee β The annual fee an issuer pays to keep a rating live for the life of the instrument. This is the recurring annuity attached to the stock of outstanding debt rather than the flow of new issuance, and it is the main reason ratings revenue does not go to zero when issuance freezes.
Non-transaction revenue β The agencies' term for surveillance, programme, and subscription revenue as distinct from deal-driven initial rating fees. Its growth rate relative to transaction revenue is the cleanest public test of whether the recurring earnings floor is real.
Credit estimate β A confidential, typically unmonitored, point-in-time credit assessment provided for an unrated asset. Widely used in private credit and middle-market CLOs, where a full public rating is unwanted or uneconomic. Its regulatory acceptability is exactly what the NAIC is currently reconsidering.
Filing exempt (FE) β The NAIC process by which a US insurer converts an eligible rating agency rating directly into an NAIC designation, and therefore a capital charge, without independent NAIC review. The scope of filing exempt status is the specific policy lever that determines how much of the private credit ratings market actually exists.
NAIC designation β The risk category assigned to an insurer's bond holding, which determines its risk-based capital charge. Historically derived from ratings via filing exempt; increasingly, for CLOs, produced by the NAIC's own financial models.
Two-rating convention β The market practice, embedded in underwriting norms and investment guidelines rather than in statute, that benchmark corporate debt should carry ratings from at least two major agencies. It is the reason S&P and Moody's are complements rather than substitutes, and it is why fee competition between them barely exists.
Refinancing wall β The aggregate volume of corporate debt maturing within a defined future window. It matters to this industry because maturities force issuance regardless of the prevailing interest rate, unlike opportunistic issuance which does not.
Disintermediation β The shift of borrowing away from bank balance sheet loans toward bonds and non-bank private credit. It is the upstream force behind the entire thesis, because credit held by a bank needs no rating while credit sold to institutions does.
Non-bank financial intermediation (NBFI) β The Financial Stability Board's measure of credit intermediation occurring outside the banking system, reported annually across 29 jurisdictions. It crossed half of total global financial assets in 2024, which is the single best available proxy for the structural driver of rating demand.
References
-
Understanding the S&P Downgrade β Committee for a Responsible Federal Budget, 10 August 2011 ↩↩
-
S&P downgrades U.S. credit rating β CNN Money, 5 August 2011 ↩
-
Hearst posts record profit, citing strength of Fitch bond agency β Bloomberg, 17 February 2026 ↩↩↩↩
-
Nationally Recognized Statistical Rating Organizations (NRSROs) β U.S. Securities and Exchange Commission ↩↩
-
Moody's Corporation, fourth quarter and full year 2025 earnings release β SEC EDGAR, February 2026 ↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩
-
S&P Global Q4 2025 slides: revenue growth solid but EPS miss triggers stock plunge β Investing.com, February 2026 ↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩↩
-
FSB reports continued growth in nonbank financial intermediation in 2024 to $256.8 trillion β Financial Stability Board, December 2025 ↩↩↩
-
Global Monitoring Report on Nonbank Financial Intermediation 2025 β Financial Stability Board, December 2025 ↩↩↩
-
Private credit in 2025: a maturing industry navigates change β McKinsey Global Private Markets Report ↩↩↩
-
Structured Securities Project β National Association of Insurance Commissioners ↩↩↩↩↩↩↩↩
-
Rating Agencies and the Use of Credit Ratings Under the Federal Securities Laws β U.S. Securities and Exchange Commission, June 2003 ↩
-
Credit Rating Agencies: Background and Regulatory Issues β Congressional Research Service, IF11916 ↩↩↩
-
ECB accepts Scope Ratings within Eurosystem Credit Assessment Framework β European Central Bank, 10 November 2023 ↩↩↩↩↩
-
Dodd-Frank Act Rulemaking: Credit Rating Agencies β U.S. Securities and Exchange Commission ↩↩
-
Justice Department and State Partners Secure $1.375 Billion Settlement with S&P β U.S. Department of Justice, February 2015 ↩
-
Justice Department and State Partners Secure Nearly $864 Million Settlement With Moody's β U.S. Department of Justice, January 2017 ↩
-
Office of Credit Ratings β U.S. Securities and Exchange Commission ↩
-
Morningstar, Inc. reports fourth-quarter and full-year 2025 financial results β Morningstar Newsroom, February 2026 ↩↩↩↩↩↩↩↩↩↩↩
-
ECB to include Scope's ABS ratings in ECAF β Scope Group ↩↩↩↩
-
Hearst posts record revenues and profits as B2B business grows β Axios, 17 February 2026 ↩↩
-
AI moat, credit mix and segment growth outlined by Morningstar (NASDAQ: MORN) β StockTitan 8-K summary ↩↩
-
Morningstar DBRS marks 50 years of credit ratings β Yahoo Finance ↩
-
Crisil FY2025 results and corporate presentation summary ↩↩↩↩↩↩↩↩
-
ICRA Ltd FY26 revenue jumps 20.4% to βΉ599.51 crore β Whalesbook ↩↩
-
Best credit rating stock: CARE Ratings vs CRISIL vs ICRA β Equitymaster, October 2024 ↩↩
-
Moody's Corporation β subsidiaries and equity investments, SEC filing ↩
-
China Chengxin International Credit Rating downgrades United States credit rating β Caproasia, May 2023 ↩↩
-
Credit Rating Provider (E) Working Group β National Association of Insurance Commissioners ↩↩↩↩