Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
004Walk me through historical simulation VaR and tell me what breaks it.UBSRisk Management · Zurich · 2021
Say this
You take a window of past daily factor moves, apply each one to today's positions, and sort the resulting P&L. The 99% one-day VaR is the loss at the second or third worst day out of 250. What breaks it is the window.
Then walk it
- Step one is full revaluation, not a delta approximation, if you want it to be right for options. You reprice the book under each historical scenario.
- It assumes today's portfolio experienced yesterday's market. That's the point: you keep the real correlations and the real fat tails without assuming a distribution.
- The first failure is window length. A 250-day window drops the crisis as soon as it's a year old, so VaR falls exactly when complacency is building. Lengthen it and the model becomes slow to react to a new regime.
- The second failure is that every day gets equal weight. A move from fourteen months ago counts as much as yesterday's. Exponentially weighted or volatility-scaled historical simulation fixes that, at the cost of some transparency.
- The third is that your sample has no event you haven't lived through. If your factor never gapped, the model says it can't. That's why historical VaR has to sit next to stress testing, not replace it.
- One number to have ready: in March 2020, banks running 250-day windows saw VaR roughly double within a fortnight, purely because the new observations entered the sample. Procyclicality is not theoretical.
Where candidates lose it
Describing the mechanics cleanly and then having nothing to say about the window. The window choice is the whole model risk of historical simulation, and it is what the follow-up will be about. Name the procyclicality problem yourself.
Expect next
- How long a window would you choose and why?
- How would you weight recent observations?
- What does your VaR do the week after a crash, and is that useful?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
008What is expected shortfall?UBSRisk Management · Zurich · 2021
Say this
Expected shortfall is the average loss given that you have breached VaR. So a 97.5% ES is the mean of the worst 2.5 percent of outcomes, not the threshold at which they start. It answers the question VaR refuses to answer: how bad is bad?
Then walk it
- Computationally it's trivial once you have the loss distribution. In historical simulation, sort the 250 daily P&Ls, take the worst six or seven, and average them. That's your 97.5% ES.
- It's also called conditional VaR or expected tail loss. Same thing, different textbooks.
- ES is always at least as large as VaR at the same confidence level, and the gap tells you how fat your tail is. Two books with identical VaR and very different ES are not equally risky, and that difference is the whole reason to compute it.
- Basel's FRTB replaced 99% VaR with 97.5% expected shortfall for trading book capital, which is why this question turns up in every bank market risk interview now. The confidence level dropped because ES at 97.5% is roughly calibrated to VaR at 99% for a normal distribution.
- The catch worth volunteering: ES is harder to backtest. VaR gives you a clean binary breach count you can test with a simple frequency test. ES asks you to test the average size of rare events, so you need far more data for the same statistical power.
Where candidates lose it
Defining it as 'the loss beyond VaR' without the word average or conditional. ES is an expectation, not a threshold and not a worst case. And if you can't say why Basel moved to 97.5% rather than keeping 99%, you have read the definition and not the reason.
Expect next
- Why did Basel choose 97.5% for ES rather than 99%?
- How would you backtest an ES model?
- Is ES always bigger than VaR?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
047What is model risk?UBSRisk Management · Zurich · 2021
Say this
Model risk is the risk of loss from using a model that's wrong, or from using a right model in the wrong place. Two sources, and the second is the bigger one in practice: fundamental errors in the model itself, and correct models applied outside the conditions they were built for.
Then walk it
- The US Federal Reserve's SR 11-7 definition is the one to quote, because it splits it exactly that way: errors in design, and incorrect or inappropriate use.
- The error side includes bad theory, bad data, coding bugs and bad calibration. It's the side people think of and it's the side validation catches most easily.
- The misuse side is the one that hurts. A model calibrated on investment grade credit applied to high yield. A pricing model used for risk. A VaR model built for a linear book applied once options were added. Nothing is wrong with the model; the use is wrong.
- It compounds through the chain. Models feed models: a PD model feeds ECL, which feeds capital planning, which feeds the dividend decision. An error at the bottom is unrecognisable four steps up, which is why model inventories and dependency maps exist.
- Real examples worth naming: the Gaussian copula in structured credit, where the model was fine and the correlation assumption was not. The 2012 JPMorgan CIO losses, where a spreadsheet error and a newly approved VaR model both featured. Long-Term Capital Management, where the model was right about relationships and wrong about liquidity and leverage.
- How you manage it: an inventory of every model with a tier, independent validation proportionate to that tier, ongoing performance monitoring, documented limitations, and an owner. And the control that matters most is the simplest, writing down what the model may not be used for.
- The limitation to volunteer: you can't eliminate model risk, only bound it. The mitigant with the best return is not more validation, it's a stated range of applicability and a human who understands the model sitting between it and a decision.
Where candidates lose it
Defining it as 'the model being wrong'. That's half of it, and the smaller half. The answer that lands names misuse of a correct model as the larger source, and gives a concrete case. If you can cite SR 11-7, do, because it signals you've worked near a validation function.
Expect next
- Give me an example of a correct model used wrongly.
- How would you tier a model inventory?
- Can you eliminate model risk?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
080What is the broad range of risks a bank faces, and what is the greatest one?UBSPrivate Wealth Management · New York · 2026
Say this
Credit, market, liquidity and operational are the four you capitalise, then interest rate risk in the banking book, conduct, model, strategic and reputational risk on top. The greatest is liquidity, because it's the one that kills a bank in days rather than years.
Then walk it
- Credit risk is the largest by capital, usually 80 to 90 percent of a commercial bank's RWA, and it's the one that does most of the slow damage. Almost every banking crisis starts as a credit cycle.
- Market risk is small for most commercial banks and large for a trading house. Operational risk includes conduct, which has produced some of the biggest single losses in banking history.
- Liquidity risk is the answer to 'greatest', and the argument is about speed and irreversibility. A capital problem gives you quarters to raise equity or shrink. A funding problem gives you a day. Northern Rock, Lehman, Credit Suisse and SVB were all liquidity events at the end, whatever started them.
- The nuance that makes it a better answer: the cause is usually credit or rate risk and the mechanism of death is liquidity. So the greatest risk is the interaction, not any one silo. Solvency doubts cause funding to disappear, and forced sales turn doubts into insolvency.
- For a specific bank the answer changes and you should say so. For an Indian public sector bank it's concentrated corporate credit. For an NBFC it's asset-liability mismatch and wholesale funding dependence. For a custodian it's operational and technology risk. For a private bank it's conduct and suitability.
- The risk I'd flag as most underweighted relative to its importance: third-party and technology concentration. A handful of cloud providers, core banking vendors and payment rails now underpin the system, and that exposure sits in nobody's capital calculation.
- So my framing: capital protects you from credit and market losses, and only liquidity and governance protect you from the failure mode that actually happens.
Where candidates lose it
Listing risk types with no view. The question explicitly asks which is greatest, so refusing to pick is a fail. Pick liquidity, justify it on speed, then show sophistication by saying the cause is usually credit and the mechanism is liquidity, and that the answer depends on the institution.
Expect next
- Why liquidity and not credit?
- What's the greatest risk for a private wealth business specifically?
- Which risk do you think is most underpriced today?
Reported by candidates at UBS (Private Wealth Management, New York, 2026). Source: Wall Street Oasis.
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

