Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
042What is operational risk, and what are the Basel event categories?Operational riskGlobal capability centres
Say this
Basel defines it as the risk of loss from inadequate or failed internal processes, people and systems, or from external events. It explicitly includes legal risk and excludes strategic and reputational risk. Seven event categories, and the money is concentrated in two of them.
Then walk it
- The seven Level 1 categories: internal fraud; external fraud; employment practices and workplace safety; clients, products and business practices; damage to physical assets; business disruption and system failures; and execution, delivery and process management.
- The distribution is extremely skewed. Clients, products and business practices is where the enormous losses sit, because that's mis-selling, market manipulation and conduct fines. Execution and process management is where the high-frequency, low-severity losses sit.
- That skew shapes the whole discipline. You need two lenses: a frequency lens for process errors, which you fix with controls and automation, and a severity lens for tail conduct events, which you manage through governance and culture rather than through controls.
- The measurement toolkit: internal loss data, external loss data for events you haven't had, scenario analysis for the tail, RCSAs for the forward-looking control view, and KRIs for early warning. Those five are the standard op risk framework and you should be able to name all five.
- Capital: Basel III's Standardised Measurement Approach replaced the old internal models. It's a Business Indicator Component scaled by a marginal coefficient, then multiplied by an Internal Loss Multiplier based on your ten-year average loss history. So your own losses now drive your capital, which is the incentive it was designed to create.
- The honest difficulty: operational risk loss data is sparse and non-stationary. Ten years of history contains very few tail events, and the risks that matter now, cyber and third-party concentration, barely appear in it. So scenario analysis carries weight that the maths can't support, and that's a judgement-heavy exercise.
Where candidates lose it
Reducing operational risk to fraud and system failure. The largest losses in banking history in this category are conduct and mis-selling, not rogue traders or outages. Naming 'clients, products and business practices' as the big-money bucket immediately shows you've looked at the loss data.
Expect next
- Which category holds the biggest losses historically?
- How is operational risk capital calculated now?
- Where does cyber risk fit in that taxonomy?
045Explain the three lines of defence.Operational riskGlobal capability centres
Say this
First line is the business, which owns and manages the risk it takes. Second line is risk and compliance, which sets the framework, sets limits and independently challenges. Third line is internal audit, which gives the board assurance that the first two are working.
Then walk it
- The first line's ownership is the part that's usually wrong in practice. The trader owns the market risk, the lending officer owns the credit decision, the operations head owns the process risk. If the business thinks risk management owns risk, the model has already failed.
- Second line has two jobs that sit in tension: it advises the business and it challenges the business. That's why independence matters, and why the CRO reports to the board risk committee and not just to the CEO.
- Third line is independent of both and reports to the audit committee. It does not run controls, it tests whether they exist and work. Audit sitting in management meetings designing controls destroys its own assurance value.
- The interesting judgement calls: where does a desk-embedded risk analyst sit? Where does model validation sit relative to model development? Where does finance sit? Getting those boundaries wrong is how conflicts creep in.
- The standard criticisms, worth volunteering. It creates a compliance mindset where the first line assumes the second line will catch things. Responsibilities blur in the middle. And it can become three layers of reporting rather than three layers of control.
- That's why the IIA updated it in 2020 into a 'three lines model' with less rigid boundaries and more emphasis on governance and alignment. Knowing the model has been revised, and why, is usually more than the interviewer expects.
Where candidates lose it
Reciting the three lines without saying the first line owns the risk. That single point is what the question is testing. And if you can name a real ambiguity, like where model validation sits, you show you've seen the model collide with an actual org chart.
Expect next
- Where does model validation sit?
- What's the main criticism of the model?
- Who does the CRO report to, and why does it matter?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

