Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
093Tell me about your Python experience and what you have actually built with it.BlackRockRisk and Quantitative Analysis · New York · 2026
Say this
Be specific and be honest about the level. Name the libraries, describe one thing you built end to end, say what broke and what you'd do differently. A concrete small project beats a claimed proficiency every time.
Then walk it
- Set the level honestly with a self-assessment they can verify: comfortable with pandas and numpy, have used statsmodels and scikit-learn, can write a class and a test, not a software engineer. Overclaiming is fatal because the next question is usually technical.
- Then one project in detail. For a risk role the ideal one is risk-adjacent: pulled daily prices for a twenty-stock portfolio, computed historical and parametric VaR, backtested the exceptions over three years, and showed the parametric version under-reporting breaches in the volatile period. That's a real answer and it's a week of work.
- Say what the data did to you, because that's the honest part of any data project. Corporate actions, missing days, tickers that changed, timezone alignment. Anyone who's done real work has a data-cleaning story, and its absence is a tell.
- Name the specific libraries per task: pandas for the data, numpy and scipy for the maths, statsmodels for regression and time series, matplotlib for output, and pytest if you've written tests. Vague 'I know Python' invites a hard follow-up.
- Have a view on tooling practices, briefly: version control, a requirements file, functions rather than one long notebook, a couple of assertions on the data. Risk teams care about reproducibility because a number that can't be reproduced can't be signed off.
- If your experience is thin, say so and say what you've done about it. 'I've done the CS50 problem sets and built this one project, I'm not fast yet' is respected. Claiming pandas and then failing to describe a groupby is not.
- Close with the risk-relevant framing: the reason a risk function wants Python is to check the vendor system's number independently. Being able to build a rough independent calculation is a control, not a convenience, and saying that shows you understand why they asked.
Where candidates lose it
Claiming a level you can't demonstrate. Buy-side risk interviews frequently follow this with a screen-share or a whiteboard question, so calibrate honestly. And the answer that wins is one small finished project described in detail, not a list of libraries.
Expect next
- Walk me through how you'd compute historical VaR in pandas.
- What went wrong in that project?
- Have you used SQL, and for what?
Reported by candidates at BlackRock (Risk and Quantitative Analysis, New York, 2026). Source: Wall Street Oasis.
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

