Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
004Walk me through historical simulation VaR and tell me what breaks it.UBSRisk Management · Zurich · 2021
Say this
You take a window of past daily factor moves, apply each one to today's positions, and sort the resulting P&L. The 99% one-day VaR is the loss at the second or third worst day out of 250. What breaks it is the window.
Then walk it
- Step one is full revaluation, not a delta approximation, if you want it to be right for options. You reprice the book under each historical scenario.
- It assumes today's portfolio experienced yesterday's market. That's the point: you keep the real correlations and the real fat tails without assuming a distribution.
- The first failure is window length. A 250-day window drops the crisis as soon as it's a year old, so VaR falls exactly when complacency is building. Lengthen it and the model becomes slow to react to a new regime.
- The second failure is that every day gets equal weight. A move from fourteen months ago counts as much as yesterday's. Exponentially weighted or volatility-scaled historical simulation fixes that, at the cost of some transparency.
- The third is that your sample has no event you haven't lived through. If your factor never gapped, the model says it can't. That's why historical VaR has to sit next to stress testing, not replace it.
- One number to have ready: in March 2020, banks running 250-day windows saw VaR roughly double within a fortnight, purely because the new observations entered the sample. Procyclicality is not theoretical.
Where candidates lose it
Describing the mechanics cleanly and then having nothing to say about the window. The window choice is the whole model risk of historical simulation, and it is what the follow-up will be about. Name the procyclicality problem yourself.
Expect next
- How long a window would you choose and why?
- How would you weight recent observations?
- What does your VaR do the week after a crash, and is that useful?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
005Calculate the one-day 99% VaR of a $100 million portfolio with 2 percent daily volatility.UBSRisk Management · Remote · 2020UBSRisk Management · Zurich · 2021
Say this
Parametric, assuming zero mean and normality: 2.33 times 2 percent times $100m, so about $4.66 million. Round it to $4.7m and say the assumptions out loud as you go.
Then walk it
- The z-score at 99% one-tailed is 2.326. I'd use 2.33. At 95% it's 1.645, worth knowing cold because interviewers switch between them mid-question.
- Daily volatility in money terms is 2 percent of $100m, so $2m. Multiply by 2.33 and you get $4.66m.
- I'm assuming a zero expected return over one day, which is standard for a short horizon, and that returns are normal, which is the assumption doing all the work.
- To scale to ten days, multiply by the square root of ten, about 3.16, so roughly $14.7m. That scaling needs independent and identically distributed returns, so it understates the number if volatility clusters or the market trends.
- And the caveat I'd volunteer: because the real distribution has fatter tails than normal, this figure is probably too low at 99%. Empirically the 99th percentile of equity returns sits closer to 2.6 or 2.7 sigma than 2.33.
Where candidates lose it
Using 1.645 for 99% or 2.33 for 95%, or reaching for a calculator. Know both z-scores by heart, state your two assumptions before you multiply, and flag that fat tails make the answer conservative in the wrong direction.
Expect next
- Now give me the ten-day number.
- What if the portfolio had a 10 percent annual expected return, does that change it?
- How would the answer change if the returns were t-distributed with five degrees of freedom?
Reported by candidates at UBS (Risk Management, Remote, 2020); UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
008What is expected shortfall?UBSRisk Management · Zurich · 2021
Say this
Expected shortfall is the average loss given that you have breached VaR. So a 97.5% ES is the mean of the worst 2.5 percent of outcomes, not the threshold at which they start. It answers the question VaR refuses to answer: how bad is bad?
Then walk it
- Computationally it's trivial once you have the loss distribution. In historical simulation, sort the 250 daily P&Ls, take the worst six or seven, and average them. That's your 97.5% ES.
- It's also called conditional VaR or expected tail loss. Same thing, different textbooks.
- ES is always at least as large as VaR at the same confidence level, and the gap tells you how fat your tail is. Two books with identical VaR and very different ES are not equally risky, and that difference is the whole reason to compute it.
- Basel's FRTB replaced 99% VaR with 97.5% expected shortfall for trading book capital, which is why this question turns up in every bank market risk interview now. The confidence level dropped because ES at 97.5% is roughly calibrated to VaR at 99% for a normal distribution.
- The catch worth volunteering: ES is harder to backtest. VaR gives you a clean binary breach count you can test with a simple frequency test. ES asks you to test the average size of rare events, so you need far more data for the same statistical power.
Where candidates lose it
Defining it as 'the loss beyond VaR' without the word average or conditional. ES is an expectation, not a threshold and not a worst case. And if you can't say why Basel moved to 97.5% rather than keeping 99%, you have read the definition and not the reason.
Expect next
- Why did Basel choose 97.5% for ES rather than 99%?
- How would you backtest an ES model?
- Is ES always bigger than VaR?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
011How do you backtest a VaR model?Bank market riskModel validation
Say this
Compare the daily VaR forecast to the actual next-day P&L and count the days the loss exceeded it. Then test whether that count and its timing are consistent with your confidence level. At 99% over 250 days, you expect about two or three exceptions.
Then walk it
- First fix the P&L definition. You backtest against hypothetical P&L, which holds the portfolio static, not actual P&L, which includes intraday trading and fees. Otherwise you're testing the traders, not the model.
- Unconditional coverage: the Kupiec proportion-of-failures test. Is the exception count statistically consistent with one percent? With 250 days, you can't reject much below five exceptions, so the test has weak power. Say that.
- Conditional coverage: are exceptions independent, or do they cluster? Christoffersen's test looks at that. Clustering means the model is slow to react to volatility regimes, which is the classic symptom of a long unweighted historical window.
- Basel's traffic light is the version supervisors actually use: green up to four exceptions in 250 days, amber five to nine with a rising capital multiplier, red at ten or more, which triggers a multiplier of four and a model review.
- Then diagnostics beyond the count. Which desks and which risk factors produced the breaches, and how big were the breaches relative to VaR. Ten small breaches and two enormous ones are different failures needing different fixes.
- The limitation I'd raise: a single year at 99% simply doesn't contain enough tail events to prove a model right. Backtesting can reject a bad model and cannot confirm a good one. That's why it sits alongside benchmarking and stress testing.
Where candidates lose it
Counting breaches and stopping. Two things get missed almost every time: using hypothetical rather than actual P&L, and saying that the test has low statistical power over 250 days. Both show you understand what backtesting can and cannot prove.
Expect next
- What is the Basel traffic light approach?
- Why hypothetical P&L and not actual?
- Zero exceptions in a year. Is the model good?
015What is stress testing, and how is it different from VaR?Bank market riskRegulatory reporting
Say this
VaR is statistical and stress testing is conditional. VaR asks what the distribution of outcomes looks like given recent history; stress testing asks what happens if this specific thing occurs, with no probability attached. They answer different questions and neither substitutes for the other.
Then walk it
- VaR is probabilistic and backward-looking. It needs history and it gives you a likelihood. Stress testing is a what-if: rates up 300 basis points, equities down 40 percent, the rupee at 95, and here is the P&L.
- Stress testing lets you ask about things that have never happened. VaR structurally cannot, because it has no data on them.
- It also handles non-linearity honestly. A large prescribed shock reveals gamma and correlation breakdown that a one-day 99% move never touches.
- Three flavours worth naming: sensitivity tests on one factor at a time, scenario tests with a coherent joint move across many factors, and reverse stress tests that start from failure and work backwards.
- The weakness is that stress testing has no probability. A scenario that loses $2bn is only actionable if you have a view on how likely it is, and scenario design is where the judgement, and the political pressure, sits.
- In practice the two are complements at different confidence levels. VaR and expected shortfall set day-to-day limits; stress tests and ICAAP set capital and inform the risk appetite. A bank that only ran VaR in 2007 saw nothing coming.
Where candidates lose it
Framing stress testing as 'a bigger VaR'. It isn't a confidence level, it's a different epistemology: conditional and judgement-driven rather than statistical. And you should volunteer the weakness, that scenarios carry no probability, before being asked.
Expect next
- Who should design the scenarios, risk or the business?
- How do you stop scenario design becoming a negotiation?
- What is reverse stress testing?
017What is reverse stress testing, and why do supervisors like it so much?Bank market riskRegulatory reporting
Say this
You start from the outcome, business failure, and work backwards to find what would cause it. Supervisors like it because it removes the bank's ability to choose a comfortable scenario. You can't pick a shock that happens to be survivable if the shock is defined as the one you don't survive.
Then walk it
- Define failure first, and precisely. Not just insolvency, but the point where the business model is no longer viable: CET1 through the requirement, or losing access to wholesale funding, or a rating downgrade that kills the franchise.
- Then solve for the scenario. Search across risk factors for combinations that get you there, and rank them by plausibility rather than by size.
- The output is not a loss number. It's a set of vulnerabilities and a judgement on whether the required shock is remote or uncomfortably close. If your bank fails on a 120 basis point spread widening, that's an urgent finding no matter what probability you assign.
- It's also how you find concentrations nobody wrote down. Reverse stress testing frequently surfaces that failure runs through one funding counterparty, one collateral type, or one country, which no forward scenario was built to test.
- Then it feeds the recovery plan. Each identified path needs a management action and a trigger, which is the actual regulatory point. It's a bridge between risk measurement and resolution planning.
- The hard part, and worth saying: the search space is enormous and the answer is sensitive to which factors you allow to move together. The exercise is only as honest as the people running it, and it's very easy to make the required shock look implausible.
Where candidates lose it
Describing it as 'a very severe stress test'. Severity isn't the distinguishing feature, direction is. Forward tests go from cause to effect, reverse tests go from failure to cause. And if you don't define failure precisely at the start, the exercise has no answer.
Expect next
- How would you define failure for a broker-dealer versus a deposit-taking bank?
- What do you do with the output?
- How do you stop management dismissing the scenario as implausible?
018How would you run an ICAAP, and how does it relate to the supervisory stress tests?Regulatory reportingBank credit risk
Say this
ICAAP is the bank's own answer to 'how much capital do you actually need', as opposed to the minimum the rules prescribe. You identify all material risks, quantify them including the ones Pillar 1 ignores, stress the plan, and conclude with a capital number and a plan to hold it.
Then walk it
- Start with a risk identification and materiality assessment across everything, not just credit, market and operational. Concentration, interest rate risk in the banking book, pension, reputational, strategic and model risk are the Pillar 2 gaps, and IRRBB and concentration are usually the two biggest.
- Quantify each, then stress the three-year business plan under a baseline and at least one severe but plausible adverse scenario. The adverse case has to be internally consistent: if GDP falls, credit costs rise, fee income falls and RWAs inflate through downgrades, all at once.
- Project the capital path, not just the end point. The trough quarter is what matters, and it usually sits in year two because provisions lag the macro.
- Set the internal capital requirement above the regulatory minimum, with a management buffer sized so that you don't breach the buffer requirement in the adverse case and get dividend restrictions.
- Then the management actions, with triggers. Which of those are credible under stress is the question a supervisor will push on hardest, because cutting dividends works and issuing equity in a crisis usually doesn't.
- The relationship with supervisory tests: the regulator's exercise, CCAR in the US, the EBA's in Europe, and the RBI's stress-testing guidance in India, uses common prescribed scenarios so banks can be compared. ICAAP is idiosyncratic and covers risks the common scenario ignores. Under the SREP the supervisor uses your ICAAP to set a Pillar 2 requirement on top of Pillar 1.
- Governance is half the assessment. An ICAAP the board has clearly never read fails regardless of the modelling quality. The board's sign-off on the risk appetite and the capital plan is the artefact supervisors look for first.
Where candidates lose it
Describing ICAAP as a document rather than a process, and forgetting Pillar 2 risks. If you can't name interest rate risk in the banking book and concentration as the two big risks outside Pillar 1, you have not understood why ICAAP exists at all.
Expect next
- Which Pillar 2 risk is usually the largest?
- How would you size a management buffer?
- What management actions would a supervisor refuse to credit?
024What is basis risk? Give me an example.Bank market riskTreasury and ALM
Say this
Basis risk is the risk that your hedge and your exposure don't move together, so you're left with residual P&L even though you think you're flat. It's what's left after you've hedged the first-order factor.
Then walk it
- The classic example: you hold a corporate bond and hedge the rate risk with a government bond future. Now you're exposed to the spread between corporate and government yields, which is exactly the thing that moves in a credit event.
- Product basis: hedging a jet fuel exposure with crude futures because jet fuel futures are illiquid. The crack spread becomes your risk, and airlines have lost real money on that.
- Tenor and calendar basis: hedging a three-month exposure with a one-month contract and rolling. Each roll re-prices the basis, and in a stressed market that roll cost blows out.
- Location and currency basis: cross-currency basis on a dollar funding swap. In March 2020 that basis widened by more than 100 basis points, which made hedged dollar funding dramatically more expensive for non-US banks holding dollar assets.
- In a bank's banking book it shows up as repricing basis: your loans reprice off the repo-linked benchmark and your deposits reprice off something else entirely, so a rate move that looks neutral on a gap report still hits net interest margin.
- The way you manage it is to measure it explicitly, set a separate basis limit, and stress it. The failure mode is that VaR often shows a hedged book as low risk because the basis has been quiet, right up until it isn't.
Where candidates lose it
Defining it abstractly without a concrete pair. Interviewers want an instrument and its hedge named. And the risk-manager point to add is that basis risk is systematically understated by VaR, because the basis is stable for long stretches and then jumps.
Expect next
- How would you measure and limit basis risk?
- Why does VaR tend to understate it?
- What happened to cross-currency basis in March 2020?
029What is the difference between a point-in-time and a through-the-cycle rating, and when does it matter?Bank credit riskRating agencies
Say this
A point-in-time PD reflects the borrower's risk right now, including where we are in the cycle. A through-the-cycle rating strips the cycle out and asks how the borrower would do on average across one. PIT moves a lot, TTC barely moves.
Then walk it
- Agency ratings are broadly through-the-cycle by design. That's why an investment grade issuer doesn't get downgraded every recession, and why agencies talk about rating through a trough.
- IFRS 9 needs point-in-time, because expected credit loss is supposed to be a current, forward-looking estimate conditioned on today's macro forecast.
- Basel IRB regulatory capital leans through-the-cycle, deliberately, to stop capital requirements swinging with the cycle. If PDs were fully PIT, RWAs would balloon in a recession precisely when banks can't raise capital.
- That's the procyclicality argument and it's the real content of this question. A PIT capital regime amplifies the cycle: losses rise, RWAs rise, capital ratios fall twice over, lending contracts, the recession deepens.
- The practical consequence is that a bank runs two PD scales and a mapping between them, and the conversion is genuinely hard. You need a macro model to shift a TTC PD to a PIT PD for a given scenario.
- The honest caveat: no real rating system is purely one or the other. Agency ratings do migrate in downturns, and IRB models do have cyclical components. It's a spectrum, and the useful question about any model is how much of the cycle it passes through.
Where candidates lose it
Defining both and not explaining why anyone cares. The payoff is procyclicality: why regulators want TTC for capital and accountants want PIT for provisions, and why the same borrower carries two different PDs in the same bank on the same day.
Expect next
- Which does IFRS 9 need, and why?
- How would you convert a TTC PD to a PIT PD?
- Is procyclicality a real problem or a theoretical one?
030Explain IFRS 9 expected credit loss staging.Bank credit riskRegulatory reporting
Say this
Three stages. Stage 1 is performing, and you provide twelve-month expected loss. Stage 2 is a significant increase in credit risk since origination, and you jump to lifetime expected loss. Stage 3 is credit impaired, lifetime loss with interest recognised on the net carrying amount.
Then walk it
- The whole model is forward-looking and unbiased, probability-weighted across at least a couple of macro scenarios. That's the break from the old incurred-loss model, which waited for evidence of impairment before providing.
- The cliff is the interesting bit. Moving from Stage 1 to Stage 2 changes the horizon from twelve months to lifetime, so on a twenty-year mortgage the provision can jump by a multiple overnight without a single missed payment.
- The trigger for Stage 2 is a significant increase in credit risk, judged on relative change in lifetime PD since origination, not an absolute level. There's a 30-days-past-due backstop presumption and a low credit risk exemption.
- Stage 3 is default, aligned in most banks to the 90-day past due and unlikely-to-pay definitions. Interest revenue then accrues on the carrying amount net of the provision, which is the effective-interest change people forget.
- Practical machinery: you need lifetime PD curves, LGD, EAD profiles, discounting at the effective interest rate, and macro scenario weights. Then a management overlay, because in 2020 every model built on pre-pandemic data produced numbers nobody believed.
- The criticism to volunteer: the Stage 2 cliff makes provisions lumpy and procyclical, and the scenario weights are a judgement that moves the P&L by a lot. Two banks with identical books can report materially different provisions, which is exactly what IFRS 9 was supposed to reduce.
Where candidates lose it
Getting the stages right and missing the twelve-month versus lifetime switch, which is the whole economic content. Also don't call Stage 2 'past due'. It's a relative deterioration in credit risk; 30 days past due is only a backstop.
Expect next
- Why is the Stage 2 transition criticised?
- How do you set macro scenario weights?
- How does this differ from Basel expected loss?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

