Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
004Walk me through historical simulation VaR and tell me what breaks it.UBSRisk Management · Zurich · 2021
Say this
You take a window of past daily factor moves, apply each one to today's positions, and sort the resulting P&L. The 99% one-day VaR is the loss at the second or third worst day out of 250. What breaks it is the window.
Then walk it
- Step one is full revaluation, not a delta approximation, if you want it to be right for options. You reprice the book under each historical scenario.
- It assumes today's portfolio experienced yesterday's market. That's the point: you keep the real correlations and the real fat tails without assuming a distribution.
- The first failure is window length. A 250-day window drops the crisis as soon as it's a year old, so VaR falls exactly when complacency is building. Lengthen it and the model becomes slow to react to a new regime.
- The second failure is that every day gets equal weight. A move from fourteen months ago counts as much as yesterday's. Exponentially weighted or volatility-scaled historical simulation fixes that, at the cost of some transparency.
- The third is that your sample has no event you haven't lived through. If your factor never gapped, the model says it can't. That's why historical VaR has to sit next to stress testing, not replace it.
- One number to have ready: in March 2020, banks running 250-day windows saw VaR roughly double within a fortnight, purely because the new observations entered the sample. Procyclicality is not theoretical.
Where candidates lose it
Describing the mechanics cleanly and then having nothing to say about the window. The window choice is the whole model risk of historical simulation, and it is what the follow-up will be about. Name the procyclicality problem yourself.
Expect next
- How long a window would you choose and why?
- How would you weight recent observations?
- What does your VaR do the week after a crash, and is that useful?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
005Calculate the one-day 99% VaR of a $100 million portfolio with 2 percent daily volatility.UBSRisk Management · Remote · 2020UBSRisk Management · Zurich · 2021
Say this
Parametric, assuming zero mean and normality: 2.33 times 2 percent times $100m, so about $4.66 million. Round it to $4.7m and say the assumptions out loud as you go.
Then walk it
- The z-score at 99% one-tailed is 2.326. I'd use 2.33. At 95% it's 1.645, worth knowing cold because interviewers switch between them mid-question.
- Daily volatility in money terms is 2 percent of $100m, so $2m. Multiply by 2.33 and you get $4.66m.
- I'm assuming a zero expected return over one day, which is standard for a short horizon, and that returns are normal, which is the assumption doing all the work.
- To scale to ten days, multiply by the square root of ten, about 3.16, so roughly $14.7m. That scaling needs independent and identically distributed returns, so it understates the number if volatility clusters or the market trends.
- And the caveat I'd volunteer: because the real distribution has fatter tails than normal, this figure is probably too low at 99%. Empirically the 99th percentile of equity returns sits closer to 2.6 or 2.7 sigma than 2.33.
Where candidates lose it
Using 1.645 for 99% or 2.33 for 95%, or reaching for a calculator. Know both z-scores by heart, state your two assumptions before you multiply, and flag that fat tails make the answer conservative in the wrong direction.
Expect next
- Now give me the ten-day number.
- What if the portfolio had a 10 percent annual expected return, does that change it?
- How would the answer change if the returns were t-distributed with five degrees of freedom?
Reported by candidates at UBS (Risk Management, Remote, 2020); UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
008What is expected shortfall?UBSRisk Management · Zurich · 2021
Say this
Expected shortfall is the average loss given that you have breached VaR. So a 97.5% ES is the mean of the worst 2.5 percent of outcomes, not the threshold at which they start. It answers the question VaR refuses to answer: how bad is bad?
Then walk it
- Computationally it's trivial once you have the loss distribution. In historical simulation, sort the 250 daily P&Ls, take the worst six or seven, and average them. That's your 97.5% ES.
- It's also called conditional VaR or expected tail loss. Same thing, different textbooks.
- ES is always at least as large as VaR at the same confidence level, and the gap tells you how fat your tail is. Two books with identical VaR and very different ES are not equally risky, and that difference is the whole reason to compute it.
- Basel's FRTB replaced 99% VaR with 97.5% expected shortfall for trading book capital, which is why this question turns up in every bank market risk interview now. The confidence level dropped because ES at 97.5% is roughly calibrated to VaR at 99% for a normal distribution.
- The catch worth volunteering: ES is harder to backtest. VaR gives you a clean binary breach count you can test with a simple frequency test. ES asks you to test the average size of rare events, so you need far more data for the same statistical power.
Where candidates lose it
Defining it as 'the loss beyond VaR' without the word average or conditional. ES is an expectation, not a threshold and not a worst case. And if you can't say why Basel moved to 97.5% rather than keeping 99%, you have read the definition and not the reason.
Expect next
- Why did Basel choose 97.5% for ES rather than 99%?
- How would you backtest an ES model?
- Is ES always bigger than VaR?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
011How do you backtest a VaR model?Bank market riskModel validation
Say this
Compare the daily VaR forecast to the actual next-day P&L and count the days the loss exceeded it. Then test whether that count and its timing are consistent with your confidence level. At 99% over 250 days, you expect about two or three exceptions.
Then walk it
- First fix the P&L definition. You backtest against hypothetical P&L, which holds the portfolio static, not actual P&L, which includes intraday trading and fees. Otherwise you're testing the traders, not the model.
- Unconditional coverage: the Kupiec proportion-of-failures test. Is the exception count statistically consistent with one percent? With 250 days, you can't reject much below five exceptions, so the test has weak power. Say that.
- Conditional coverage: are exceptions independent, or do they cluster? Christoffersen's test looks at that. Clustering means the model is slow to react to volatility regimes, which is the classic symptom of a long unweighted historical window.
- Basel's traffic light is the version supervisors actually use: green up to four exceptions in 250 days, amber five to nine with a rising capital multiplier, red at ten or more, which triggers a multiplier of four and a model review.
- Then diagnostics beyond the count. Which desks and which risk factors produced the breaches, and how big were the breaches relative to VaR. Ten small breaches and two enormous ones are different failures needing different fixes.
- The limitation I'd raise: a single year at 99% simply doesn't contain enough tail events to prove a model right. Backtesting can reject a bad model and cannot confirm a good one. That's why it sits alongside benchmarking and stress testing.
Where candidates lose it
Counting breaches and stopping. Two things get missed almost every time: using hypothetical rather than actual P&L, and saying that the test has low statistical power over 250 days. Both show you understand what backtesting can and cannot prove.
Expect next
- What is the Basel traffic light approach?
- Why hypothetical P&L and not actual?
- Zero exceptions in a year. Is the model good?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

