Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
033Your loan book has 22 percent of exposure in commercial real estate. How do you think about that?Bank credit riskIndian bank risk and treasury
Say this
Concentration is the risk that diversification math ignores, and 22 percent in one cyclical sector is a real number. I'd measure it, work out how much of a tail loss it drives, then decide between limits, hedging and pricing rather than just flagging it.
Then walk it
- Measure it properly first. Sector share is the headline, but the useful metrics are a Herfindahl index on single names, the top-20 exposure as a share of CET1, and the correlated cluster, because CRE developers, construction firms and building materials all fail together.
- Then quantify the capital impact. The IRB formula assumes an infinitely granular, single-factor portfolio, so it systematically understates concentrated books. A granularity adjustment or a multi-factor economic capital model is how you show the board the real number, and this is a classic Pillar 2 add-on.
- Stress it specifically. Property values down 30 percent, vacancy up, refinancing unavailable at maturity. CRE defaults are refinancing events far more than they are cash-flow events, so the maturity profile matters more than current interest coverage.
- Look at what's inside the 22 percent. Office in one city is a different animal from warehousing and retail across ten. Loan-to-value distribution, debt-service coverage, single-tenant concentration, and how much matures in the next 18 months.
- Then the actions, in order of cost. Tighten new-origination limits by sub-sector, price the concentration into new deals, syndicate or sell down the largest names, and buy protection or securitise if a market exists. In India that last option is thin, so limits do most of the work.
- And the governance line: 22 percent may be entirely within appetite if the board decided that deliberately and is paid for it. Concentration isn't automatically a fault. What is a fault is concentration that accumulated without anyone setting a limit.
Where candidates lose it
Saying 'that's too high' without a benchmark or a measurement. And forgetting that the IRB capital formula assumes a granular portfolio, so regulatory capital alone will not show the concentration. That granularity point is what a credit risk interviewer is waiting for.
Expect next
- How would you measure concentration in a single number?
- Why doesn't the IRB formula capture it?
- What limit would you set, and on what basis?
034Describe what distressed debt is.Oaktree Capital ManagementRisk · Los Angeles · 2022
Say this
Debt of a company in or near financial distress, trading at a deep discount, usually quoted in cents on the dollar rather than on a yield. The convention is a spread over 1,000 basis points or a price under 70, and the analysis shifts from yield to recovery.
Then walk it
- The mental switch is the key point. For performing credit you underwrite the probability of getting paid the coupon. For distressed you underwrite what the asset is worth in a restructuring and where in the capital structure you sit when it's divided up.
- So the work is a valuation exercise plus a legal one. Build an enterprise value under a restructured plan, then walk the waterfall: secured, then unsecured, then sub debt, then equity. The fulcrum security is the one where value runs out, and owning it is how you end up controlling the reorganised equity.
- Two strategies, and they're different businesses. Passive: buy mispriced paper and wait. Active or loan-to-own: buy the fulcrum, lead the creditor committee, negotiate the plan, convert to equity.
- Risk factors specific to it: process risk, because the outcome depends on a court and on other creditors, not just on the business. Duration risk, because restructurings take years. Illiquidity. And documentation risk, since covenant and intercreditor terms often matter more than the financials.
- From a risk-management seat in a distressed fund, the hard problems are valuation of assets with no observable price, position concentration, the fact that VaR is meaningless on paper that doesn't trade, and side-pocket or gate mechanics if investors want out.
- The Indian dimension is worth a line: the Insolvency and Bankruptcy Code created a real distressed market after 2016, with ARCs and stressed-asset funds buying from banks. Average haircuts through the IBC have been steep and resolution timelines have run well past the statutory 330 days, which is exactly the process risk you're underwriting.
Where candidates lose it
Defining it by price alone and never mentioning the fulcrum security or the capital structure waterfall. Distressed investing is a legal and structural discipline as much as a financial one, and a candidate who can't say what a fulcrum security is has read a definition, not a deal.
Expect next
- What is the fulcrum security and why do you want it?
- How would you value a company in bankruptcy?
- How would you risk-manage a portfolio of illiquid distressed positions?
Reported by candidates at Oaktree Capital Management (Risk, Los Angeles, 2022). Source: Wall Street Oasis.
038What is CVA, and who ends up paying for it?Bank credit riskDerivatives risk
Say this
Credit valuation adjustment is the market value of counterparty default risk on a derivative: the discounted expected loss if they default, integrated over the life of the trade. It's a deduction from the risk-free value of the trade, and the client pays it in the price.
Then walk it
- The formula in words: for each future time bucket, take the expected positive exposure, multiply by the marginal probability of default in that bucket and by loss given default, discount, and sum. Exposure from the market model, default probability from the CDS curve.
- It's a P&L line, not just a risk number. A CVA desk holds it, marks it daily, and hedges the credit component with CDS and the market component with the underlying. When a client's spread widens, the CVA desk takes a loss that day even if nobody defaults.
- DVA is the mirror image, the adjustment for your own default risk, which is a gain to you. It's controversial precisely because your P&L improves as your own credit deteriorates, which is an uncomfortable thing to book.
- Then FVA for the funding cost of uncollateralised trades, MVA for initial margin funding, and KVA for the capital. Collectively the XVAs, and pricing a derivative now means pricing all of them.
- Who pays: the client, embedded in the spread quoted. That's why an uncollateralised corporate client pays materially more for the same swap than a hedge fund posting daily margin. The corporate is often shocked by that and it's a real commercial conversation.
- The number worth knowing: Basel added a CVA capital charge after the crisis because roughly two-thirds of counterparty credit losses in 2008 to 2009 were CVA mark-to-market losses rather than actual counterparty failures. That's why it's capitalised separately from default risk.
Where candidates lose it
Describing CVA as a reserve rather than a traded, hedged, marked-daily P&L line. And the detail that shows real understanding is that CVA depends on the correlation between exposure and the counterparty's credit, which is wrong-way risk, so a simple product of independent expectations is an approximation.
Expect next
- What is DVA and why is it controversial?
- How would you hedge CVA?
- Why does a collateralised counterparty get a better price?
039What is wrong-way risk? Give me a real example.Bank credit riskDerivatives risk
Say this
Wrong-way risk is when your exposure to a counterparty grows at the same time as their credit deteriorates, so the two go bad together. It turns a manageable expected loss into a concentrated one, because the bad outcomes coincide by construction.
Then walk it
- Specific wrong-way risk is a direct structural link. The textbook case: you buy protection on a company from a bank that is heavily exposed to that same company. When the reference entity deteriorates, your protection is worth more and your protection seller is weaker. That's the monoline insurer story in 2008 in one sentence.
- Another clean example: an oil producer sells you oil forward to hedge. Oil collapses, so your position with them is deeply in the money, and the same collapse is destroying their ability to pay. Energy banks lost money exactly this way in 2015 and 2020.
- General wrong-way risk is looser, driven by a common macro factor. Lending to emerging market banks in local currency while they've sold you dollars: a currency crisis hits your exposure and their solvency simultaneously.
- Also collateral correlation: taking a counterparty's own shares, or its home sovereign's bonds, as collateral. Exactly when you need to liquidate, the collateral is worth least. Basel bans own-issue collateral for this reason.
- How you handle it: model exposure and default jointly rather than multiplying independent expectations. Basel's standard workaround is an alpha multiplier, 1.4 by default, on the exposure input to cover correlation. That's crude and everyone knows it.
- The better controls are structural: don't take correlated collateral, set tighter limits on structurally linked counterparties, use break clauses, and stress the joint scenario explicitly rather than trusting the model.
- And the reason it matters more than its size suggests: wrong-way risk defeats diversification. You can't average it away across counterparties, because the correlation is the exposure.
Where candidates lose it
Giving a definition with no example. Interviewers want a named structure, and the monoline case or the oil producer case both work. The second thing they listen for is that standard CVA calculations assume independence between exposure and default, and that the Basel alpha multiplier is a crude patch for exactly this.
Expect next
- How does wrong-way risk affect your CVA number?
- What collateral would you refuse to take, and why?
- Is the Basel alpha of 1.4 adequate?
040How do netting and collateral reduce counterparty exposure, and what's the difference between initial and variation margin?Bank credit riskClearing and margin
Say this
Netting lets you offset what you owe against what you're owed with the same counterparty, so exposure is one net figure rather than the sum of the positive trades. Collateral then covers most of that net figure. Variation margin covers today's mark-to-market; initial margin covers the move you'd suffer between their default and your close-out.
Then walk it
- Close-out netting under an ISDA master with a valid netting opinion in the relevant jurisdiction is what makes it legally real. Without an enforceable opinion you have to hold gross exposure, and that's a country-by-country legal question, not a modelling one.
- The arithmetic is big. A portfolio of 100 trades, half positive and half negative, might have gross positive exposure of 800 crore and net exposure of 40 crore. Netting is the single most powerful mitigant there is.
- Variation margin: exchanged daily, equal to the change in net mark-to-market, so it keeps current exposure near zero. It's a transfer of value, and it eliminates exposure you've already suffered.
- Initial margin: held against future moves during the close-out period. It covers the gap between the last margin call and actually liquidating the portfolio, and it's sized off a high quantile, typically 99 percent over a 10-day margin period of risk for bilateral trades under the uncleared margin rules.
- So the residual risks after all that: gap risk if the market jumps between calls, margin period of risk being longer than assumed in a stressed close-out, disputes over valuation, collateral haircut adequacy, and wrong-way collateral correlation.
- Then the liquidity consequence, which candidates miss. Collateralisation converts credit risk into liquidity risk. You now have to fund margin calls in cash on the day, and a large adverse move means a large same-day cash outflow. That's what caused the UK gilt LDI crisis in 2022 and the 2021 nickel episode.
- And the Indian angle: the exchange-traded and cleared side is heavily margined under SEBI and the clearing corporations, while the bilateral OTC market is smaller and more collateral-light, so netting enforceability and CSA coverage vary a lot by counterparty type.
Where candidates lose it
Treating collateral as a free reduction in risk. It converts credit risk into funding liquidity risk, and the entities that blew up in 2022 were solvent and margin-called to death. Saying that out loud is what distinguishes a risk manager from someone quoting a mitigant list.
Expect next
- What is the margin period of risk and what would you assume for it?
- What risk does collateralisation create?
- What haircut would you apply to a corporate bond posted as collateral?
041Why does a central counterparty reduce risk, and what new risk does it create?Clearing and marginBank credit risk
Say this
A CCP replaces a web of bilateral exposures with a hub and spoke, so it multilaterally nets, standardises margin and mutualises losses. In exchange you've created a single point of failure and turned counterparty risk into liquidity risk for every member.
Then walk it
- Multilateral netting is the big win. If A owes B, B owes C and C owes A, bilaterally there are three exposures; through a CCP there's almost nothing. G20 reform after 2008 pushed standardised OTC derivatives to clearing for exactly this reason.
- It also standardises: daily variation margin, initial margin on a model everyone can see, a default fund, and a documented waterfall. That removes the dispute and delay problem that made Lehman's unwinding so slow.
- The default waterfall in order: the defaulter's margin, the defaulter's default fund contribution, the CCP's own skin in the game, then the surviving members' default fund, then assessments or variation margin gains haircutting. Being able to recite that is what a clearing risk interviewer wants.
- New risk one, concentration. The CCP is systemically critical infrastructure. If it fails, everything fails, and it has no meaningful equity relative to the exposures it faces.
- New risk two, mutualisation. As a clearing member you are exposed to other members' defaults through the default fund. You've swapped a known bilateral counterparty for an unknown pool of them.
- New risk three, procyclical margin. Margin models raise requirements when volatility rises, so the CCP demands the most cash exactly when cash is scarcest. That's a liquidity amplifier, and it's what the 2020 and 2022 episodes were about.
- New risk four, the member-client link. If you clear for clients, you stand between them and the CCP, so you have to fund their margin calls intraday. The LME nickel episode in 2022 showed that a CCP can also change the rules under stress, which is a governance risk you can't model.
- So the honest summary: clearing has reduced credit risk and increased liquidity risk, and it has concentrated tail risk into a small number of institutions. Better on balance, not free.
Where candidates lose it
Listing the benefits and stopping at 'it's safer'. The interviewer wants the default waterfall and at least two created risks, with procyclical margin the most important. And you should say that clearing trades credit risk for liquidity risk rather than eliminating risk.
Expect next
- Walk me through the default waterfall.
- How would you stress test your exposure to a CCP?
- Is procyclical initial margin fixable?
043What is an RCSA, and how would you actually run one?Operational riskGlobal capability centres
Say this
A risk and control self-assessment is the business identifying its own risks, rating them before and after controls, and owning the gap. Run badly it's a spreadsheet nobody reads. Run well it's the only forward-looking view of operational risk you have.
Then walk it
- Start from processes, not from a risk list. Map the end-to-end process, find the failure points, and derive risks from those. Starting from a generic taxonomy produces generic risks that nobody recognises as theirs.
- For each risk, rate inherent likelihood and impact, then identify the controls, test whether they actually work, and rate residual risk. The distinction between design effectiveness and operating effectiveness matters: a beautifully designed control that is performed late every month is not effective.
- Then compare residual risk to appetite. Anything above appetite needs an action with an owner and a date, or a formal risk acceptance signed at the right level. That is the actual output; the ratings are just how you get there.
- Who does it: the first line owns it, the second line facilitates and challenges. If risk management fills in the RCSA, the business hasn't assessed anything and you've built a document rather than a control.
- Where it fails, and I'd say this without prompting. Everything gets rated amber, because nobody wants to own a red. Ratings never change year to year. The workshop runs after a fine rather than before. And it never reconciles against actual loss events, so a process with twelve losses last year is rated low risk.
- So the tests I'd apply to an RCSA: does it reconcile to the loss database, does it reconcile to audit findings, has anything moved since last year, and can a process owner explain their own top risk without reading the sheet.
- Practical numbers: for a mid-sized operation, expect 15 to 40 risks per process area. Hundreds means it's a control inventory dressed up as a risk assessment, and nobody will use it.
Where candidates lose it
Describing the template instead of the process. Two things separate a real answer: saying the first line must own it with the second line challenging, and naming the amber-everywhere failure mode. And reconciling the RCSA against actual loss data is the check almost no candidate mentions.
Expect next
- Who should own the RCSA?
- How do you stop everything being rated amber?
- How does the RCSA connect to your loss data?
044Design three key risk indicators for a payments operation, and tell me what makes a KRI good.Operational riskGlobal capability centres
Say this
A good KRI is leading, measurable without manual effort, and has a threshold that triggers a specific action. For payments I'd use the unreconciled item count and ageing, the manual intervention rate on straight-through processing, and the failed or returned payment rate by corridor.
Then walk it
- Unreconciled items over two days old, by value and count. It's leading, because loss events start as breaks nobody chased, and it's cheap to produce from the reconciliation system.
- Manual touch rate on payments that should be straight-through. Every manual touch is a keystroke error waiting to happen, so this is a direct proxy for the frequency of process losses. A rise from 2 to 6 percent is a red flag before any loss appears.
- Failed and returned payment rate, split by corridor and by cause. It picks up upstream data quality problems, sanctions-screening false positives and correspondent bank issues, each of which needs a different fix.
- What makes a KRI good: leading not lagging, objectively measurable from a system rather than from a survey, sensitive enough that it actually moves, owned by someone with the authority to act, and attached to an amber and red threshold with a pre-agreed response.
- What makes a bad one: loss count, which is lagging and tells you the failure already happened. Headcount, which is context rather than risk. Anything requiring a manual monthly collection, because it degrades into a copy-paste exercise.
- Thresholds should be calibrated off the historical distribution, not picked round. Amber at roughly the 90th percentile of the last two years, red at the 99th, then reviewed annually. And each threshold needs a named action, or breaching it changes nothing.
- The failure mode to name: KRI inflation. A dashboard with 120 indicators gets ignored. Eight to twelve real ones per business, reviewed monthly by someone who can act, beats a hundred reported to nobody.
Where candidates lose it
Proposing lagging indicators. Loss count, number of incidents and audit findings are all after the fact, and they are what most candidates offer. A KRI is supposed to give you time to act, so lead with something that moves before the loss, and attach a threshold and an action to each.
Expect next
- How would you calibrate the thresholds?
- What do you do when a KRI turns red?
- Give me a KRI for cyber risk.
047What is model risk?UBSRisk Management · Zurich · 2021
Say this
Model risk is the risk of loss from using a model that's wrong, or from using a right model in the wrong place. Two sources, and the second is the bigger one in practice: fundamental errors in the model itself, and correct models applied outside the conditions they were built for.
Then walk it
- The US Federal Reserve's SR 11-7 definition is the one to quote, because it splits it exactly that way: errors in design, and incorrect or inappropriate use.
- The error side includes bad theory, bad data, coding bugs and bad calibration. It's the side people think of and it's the side validation catches most easily.
- The misuse side is the one that hurts. A model calibrated on investment grade credit applied to high yield. A pricing model used for risk. A VaR model built for a linear book applied once options were added. Nothing is wrong with the model; the use is wrong.
- It compounds through the chain. Models feed models: a PD model feeds ECL, which feeds capital planning, which feeds the dividend decision. An error at the bottom is unrecognisable four steps up, which is why model inventories and dependency maps exist.
- Real examples worth naming: the Gaussian copula in structured credit, where the model was fine and the correlation assumption was not. The 2012 JPMorgan CIO losses, where a spreadsheet error and a newly approved VaR model both featured. Long-Term Capital Management, where the model was right about relationships and wrong about liquidity and leverage.
- How you manage it: an inventory of every model with a tier, independent validation proportionate to that tier, ongoing performance monitoring, documented limitations, and an owner. And the control that matters most is the simplest, writing down what the model may not be used for.
- The limitation to volunteer: you can't eliminate model risk, only bound it. The mitigant with the best return is not more validation, it's a stated range of applicability and a human who understands the model sitting between it and a decision.
Where candidates lose it
Defining it as 'the model being wrong'. That's half of it, and the smaller half. The answer that lands names misuse of a correct model as the larger source, and gives a concrete case. If you can cite SR 11-7, do, because it signals you've worked near a validation function.
Expect next
- Give me an example of a correct model used wrongly.
- How would you tier a model inventory?
- Can you eliminate model risk?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
048How would you validate a model?Model validationGlobal capability centres
Say this
Three pillars: conceptual soundness, outcomes analysis and ongoing monitoring. So does the theory make sense for this use, does it perform against reality, and will you know when it stops working. And it has to be done by someone independent of whoever built it.
Then walk it
- Conceptual soundness first, and it's the part that gets skipped. Read the documentation, check the theory is appropriate for the intended use, check the assumptions are stated and reasonable, and review the data: source, quality, representativeness, and whether the development sample looks like today's population.
- Then replicate. Independently rebuild at least the core of it from the documentation. If you can't reproduce the results from the document, the documentation fails, and that's a finding in itself.
- Outcomes analysis: backtesting against realised outcomes, benchmarking against an alternative model or a simpler challenger, and sensitivity analysis to see which inputs the output actually depends on. Stress the inputs to the edge of plausibility and see if it breaks gracefully or catastrophically.
- Then the boundary work: what is this model not valid for. A validated model with no stated limitations is a hazard, because the next user will apply it to something new and assume it's approved.
- Ongoing monitoring: performance thresholds, population stability, and a revalidation cycle tiered by materiality. Tier 1 models annually, lower tiers less often, and any material change triggers a revalidation regardless of the cycle.
- Governance: findings rated by severity, owners and deadlines, and a model approval that can be conditional or refused. A validation function that has never refused an approval isn't independent, and that's the question I'd ask about any validation team I joined.
- Sizing it honestly: full validation of a Tier 1 pricing model is weeks of work for two people. Proportionality is the whole design problem, because validating everything to the same depth means validating nothing well.
Where candidates lose it
Going straight to backtesting. Backtesting is one third of it and it's the third that needs data you often don't have. Conceptual soundness and the explicit statement of limitations are what prevent the misuse that causes most model losses. And say the word independent, because organisational independence is the first thing a supervisor checks.
Expect next
- What would you do if you couldn't backtest because there was no data?
- How do you validate a vendor model you can't see inside?
- How would you tier models for validation intensity?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

