Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
071Here is a book of credit exposures and a default history. Analyse it using dynamic probability metrics.Jane StreetCredit Risk · London · 2025
Say this
Dynamic means the probabilities have to be conditional and updating, not a static average. So I'd build a hazard-rate view: probability of default in the next period given survival so far, conditioned on observable state, and then update it as new information arrives.
Then walk it
- Start with the data audit before any modelling. Definition of default, observation window, censoring, survivorship, and whether exposures enter and leave the sample. Most of the wrong answers in credit analytics come from the panel being constructed badly, not from the maths.
- Then the right framing: survival analysis rather than a single-period classification. Estimate a hazard function, the instantaneous default rate conditional on having survived, using a Cox proportional hazards or discrete-time hazard model. That handles censoring properly and gives you a term structure of default rather than one number.
- Make it conditional on state. Time-varying covariates: rating migration, spread level, utilisation, macro variables. A default probability that changes when the world changes is what 'dynamic' means here.
- Then update sequentially. Bayesian updating, or a Kalman-filtered latent credit factor, so each new month of data revises the estimate rather than triggering a full refit. For sparse default data, a Bayesian approach with an informative prior from external data is far more stable than maximum likelihood on twelve observations.
- Dependence, which is what makes a credit book different from a set of single names. Estimate a common factor and its loading, because portfolio loss is driven by correlation, not by average PD. Report the loss distribution, the 99th percentile and expected shortfall, not just expected loss.
- Validation appropriate to sparse data: time-series calibration tests, a binomial or Vasicek test given the low default counts, discriminatory power via a time-dependent AUC, and a comparison against market-implied hazard rates from CDS where they exist.
- Then say what you'd report. Not a single PD. A term structure of conditional default probabilities, the portfolio loss distribution with tail measures, the top contributors to tail loss, and an explicit statement of how much of the answer is driven by the correlation assumption.
- And the honest limitation: with a short history and few defaults, the tail of the loss distribution is an assumption rather than an estimate. I'd say that up front rather than present a confident 99.9th percentile.
Where candidates lose it
Reaching for a classifier and reporting AUC. The word 'dynamic' is doing the work in the question: it's asking for conditional, time-varying, updating probabilities, which means hazard models and Bayesian updating, not a static logistic fit. And in a credit book the correlation assumption drives the tail more than the PD does.
Expect next
- How would you handle the sparsity of defaults?
- How would you estimate the common factor loading?
- How would you present the uncertainty in the tail?
Reported by candidates at Jane Street (Credit Risk, London, 2025). Source: Wall Street Oasis.
082A new trading desk is being set up. How would you build its limit framework?Bank market risk
Say this
Start from the mandate, not from the metrics. Understand what the desk is supposed to do and how it makes money, then set limits that allow that strategy and block everything else. Then layer loss limits on top, because risk limits alone don't stop a desk bleeding.
Then walk it
- First the mandate: which products, which currencies, which maturities, which counterparty types, and where the edge comes from. A market-making desk and a relative-value desk with identical VaR need completely different limits.
- Then the aggregate risk limit, usually VaR or expected shortfall, sized off the capital allocated and the expected return. A desk allocated 100 crore of economic capital with a target return might get 5 crore of VaR, and you sanity-check that the implied risk-return is credible.
- Then granular sensitivity limits, because aggregate VaR is nettable and hides structure. DV01 by curve bucket, gamma, vega by expiry and by strike bucket, credit spread sensitivity by rating, single-name concentration, and FX delta by pair. These are what a trader actually manages to.
- Then loss limits, which are separate and essential. A daily stop, a month-to-date and a year-to-date drawdown trigger, each with a defined action: reduce, review, or stop trading. Risk limits control exposure; loss limits control the bleed when the strategy is simply wrong.
- Then stress limits, because VaR won't catch the scenario that matters. A cap on loss under the prescribed stress scenarios, which is often the binding constraint for a desk selling tail options.
- Then the boundaries that aren't about size: a product whitelist, tenor caps, a concentration cap as a share of market open interest or average daily volume, and a liquidity limit on days-to-exit. New products need explicit approval, which is how you stop mandate creep.
- Calibration approach for a brand new desk with no history: use a comparable desk's profile, size conservatively, and review after three and six months against actual usage. A limit used at 20 percent is wasted capital; a limit at 95 percent every day is being managed to rather than respected.
- And the governance wrapper: who can approve an excess and at what level, pre-trade blocks where possible rather than post-trade reports, and an automatic escalation after a second breach in a rolling period. Say that, because it's where limit frameworks actually fail.
Where candidates lose it
Setting a VaR limit and calling it done. VaR nets, so a desk can sit inside it with enormous concentrated positions. The complete answer has aggregate, sensitivity, loss, stress and liquidity limits, plus a product whitelist. And the loss limit is the one candidates most often forget.
Expect next
- Why do you need loss limits if you already have VaR limits?
- How would you calibrate the limits with no trading history?
- The desk is at 95 percent of its limit every day. Good or bad?
083A senior trader tells you your risk number is wrong, that you don't understand his book, and that you are blocking a profitable trade. What do you do?Bank market risk
Say this
Take the challenge seriously and hold the line separately. Those are two different things: he may genuinely be right about the number, and that doesn't change whether the trade is inside the limit. I'd work the number with him and escalate the limit question through the proper route.
Then walk it
- First, assume he might be right. Traders often do understand their book better than the risk system does, and the most common cause of a disputed number is a real modelling issue: a mismapped risk factor, a stale correlation, a proxy that stopped working, a position booked in the wrong bucket.
- So I'd ask him to show me where the number is wrong, specifically. Which position, which factor, what the number should be. A trader who can point at it is doing me a favour. A trader who only says 'it's wrong' is negotiating, not correcting.
- Then separate the two questions out loud. Question one is whether the model is right, which I will investigate today. Question two is whether the trade is inside the limit as the approved model currently measures it. Until the model changes through governance, the limit applies to the number we have.
- I would not change a risk number under pressure in the moment. That's the whole point. If it's wrong, it gets fixed through a documented model change, which also fixes it for everyone else and leaves a record.
- I'd offer a route rather than just a no: a temporary limit increase through the market risk committee with the rationale documented, or a structure that achieves most of his economics inside the limit. Risk managers who only ever say no get worked around.
- On the tone: no escalating in public, no defending the number I can't explain, and no pretending to more certainty than I have. 'I don't know yet, I'll have it by four o'clock, and until then the limit stands' is a completely defensible position.
- And I'd escalate to my own management the same day, before it becomes a complaint about me. Not to report him, but because a senior trader disputing a control needs to be visible. If I lose the argument at the committee, that's a legitimate outcome I'll implement.
- The thing I'd say last, because it's what interviewers are listening for: the P&L of the trade is not my consideration. If the limit is wrong for the business, change the limit through governance. Profitable is not an exception.
Where candidates lose it
Either caving or digging in. Both fail. The answer they want separates the question of whether the model is right, which you investigate genuinely and fast, from whether the limit applies, which isn't negotiable in the moment. And you must say that profitability is not a reason to allow a breach.
Expect next
- What if you investigate and he's right?
- What if your own boss tells you to let it through?
- How do you build a working relationship with a desk that sees you as an obstacle?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

