Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
006How does Monte Carlo VaR work, and when is it worth the extra cost?UBSRisk Management · Zurich · 2021
Say this
You specify a stochastic process for each risk factor, simulate a large number of joint paths, revalue the portfolio on every path, and take the percentile of the simulated P&L. It's worth the cost when the payoff is non-linear or path dependent, and not otherwise.
Then walk it
- The inputs are a process per factor, usually a drift and volatility, plus a dependence structure, usually a correlation matrix or a copula. Then you draw correlated shocks, typically via a Cholesky decomposition.
- Full revaluation is the expensive part, not the random numbers. If revaluing one exotic takes a second, ten thousand paths across a thousand trades is a real overnight compute problem.
- It's the only method that handles path dependency properly. A barrier option, a cliquet, a callable bond, a CVA number on a swap portfolio, all of those depend on the path and not just the endpoint.
- It also lets you choose the distribution. You can simulate from a t distribution, or use a copula to get tail dependence that a normal correlation matrix cannot produce.
- Its weakness is that it is only as good as the assumed process. Historical simulation is wrong in a way you can see; Monte Carlo is wrong in a way buried in a calibration file. That's why it needs the heaviest model validation of the three.
- So my rule: linear portfolio, don't bother, parametric or historical is fine. Options book, structured credit, or anything with optionality in the funding, Monte Carlo earns its keep.
Where candidates lose it
Describing it as 'generating random scenarios' without naming the two things you have to assume, the process and the dependence structure. That's where all the model risk lives, and naming it is what separates someone who has built one from someone who read about it.
Expect next
- How many paths do you need, and how would you know?
- How would you introduce tail dependence into the simulation?
- How would you validate a Monte Carlo VaR engine?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
007Which assumption inside parametric VaR fails first, and what does that do to your number?UBSRisk Management · Zurich · 2021
Say this
Normality fails first, and it makes VaR too small exactly when you need it. Real return distributions are leptokurtic, so the true 99th percentile sits further out than 2.33 sigma, and the deeper into the tail you go the worse the understatement gets.
Then walk it
- Assumption one, normality. Equity index daily returns have kurtosis well above three. At 99% the error is modest, maybe 10 to 20 percent; at 99.9% parametric VaR can be off by a factor.
- Assumption two, a stable covariance matrix. Correlations rise in a sell-off, so the diversification benefit the matrix gives you evaporates in the scenario the number is supposed to protect you from.
- Assumption three, linearity. Parametric VaR uses deltas, so it prices an option position as if it were stock. Short gamma looks harmless and short a straddle can even show negative risk.
- Assumption four, independent returns. Volatility clusters, so square-root-of-time scaling understates multi-day risk during a stress period.
- The order matters for the answer: normality is the one people name, but linearity is the one that produces catastrophically wrong numbers, because it can be wrong by a sign rather than a percentage.
- Fixes in ascending order of effort: a t distribution or Cornish-Fisher adjustment for the tail, EWMA covariance for the clustering, delta-gamma for mild convexity, and full revaluation once the book has real optionality.
Where candidates lose it
Saying 'it assumes normality' and stopping. Every candidate says that. The differentiator is naming the linearity assumption and explaining that for an options book parametric VaR can get the direction of risk wrong, not just the magnitude.
Expect next
- How would you adjust it for fat tails without going to full simulation?
- What does delta-gamma VaR fix and what does it still miss?
- Would you ever show a board a parametric number? When?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
009What are the advantages and disadvantages of expected shortfall compared with VaR?UBSRisk Management · Zurich · 2021
Say this
ES wins on theory and loses on practice. It's coherent, it sees the whole tail, and it can't be gamed by moving risk past the threshold. But it's harder to backtest, less stable, and more sensitive to the handful of observations that drive it.
Then walk it
- Advantage one, it's subadditive, so it's a coherent risk measure. Adding two books can never raise ES above the sum of their parts, which means you can allocate it down to desks and the numbers add up sensibly.
- Advantage two, it sees tail depth. VaR is blind beyond the quantile, so a desk can sell far out-of-the-money options and report the same VaR with vastly more real exposure. ES prices that in.
- Advantage three, it removes the incentive to optimise against the measure. Optimising a portfolio to minimise VaR tends to push loss into the tail; minimising ES doesn't reward that.
- Disadvantage one, backtesting. A VaR breach is binary and you can test the count with a Kupiec or traffic-light test. ES needs you to test conditional magnitudes, which needs far more observations, so supervisors still backtest VaR even under an ES capital regime.
- Disadvantage two, estimator noise. At 97.5% over 250 days, ES is the average of six observations. Change one bad day and the number jumps. It's less robust and less stable period to period, which makes limit management awkward.
- Disadvantage three, communication. Traders understand 'I lose more than this one day in a hundred'. 'The average of my worst six days' takes longer to land, and risk numbers nobody understands don't change behaviour.
- My summary line: ES is the better measure of risk and VaR is the better test of your model. Most banks now report both for exactly that reason.
Where candidates lose it
Giving only the coherence advantage. That's half the answer and the easy half. The interviewer is testing whether you know the practical cost, and the backtesting problem is the answer. Saying 'ES is strictly better' is the wrong answer, because if it were, Basel would have dropped VaR backtests too.
Expect next
- If ES is coherent and VaR is not, why do supervisors still backtest VaR?
- How many observations would you want to estimate ES reliably?
- Which would you set a desk limit on?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
010Why is VaR not a coherent risk measure?UBSRisk Management · Zurich · 2021
Say this
Because it fails subadditivity. The VaR of a combined portfolio can exceed the sum of the individual VaRs, which means diversification can appear to increase risk. Coherence needs four properties, and that's the one VaR breaks.
Then walk it
- The four axioms are monotonicity, translation invariance, positive homogeneity and subadditivity. VaR satisfies the first three.
- The classic counterexample is two independent digital or deep out-of-the-money option positions. Each has a small probability of a large loss, say 0.6 percent. Individually, at 99% confidence, the loss sits beyond the quantile, so each has near-zero VaR.
- Put them together and the probability of at least one blowing up is now above one percent, so the combined VaR jumps to the full loss. Two positions with almost no VaR each combine into a large one. That's the violation.
- Why it matters operationally: if the measure isn't subadditive, you can't safely allocate a firm limit down to desks, because desk limits summing to the firm limit no longer bound the firm's risk. And a trader can reduce measured VaR by taking on tail risk.
- For elliptical distributions, including the normal, VaR is subadditive, which is why the problem never shows up in a textbook example. It shows up in real books with credit and optionality, which is exactly where it matters.
- ES is subadditive at every confidence level and for every distribution, which is the theoretical reason Basel moved to it.
Where candidates lose it
Naming subadditivity without being able to construct the counterexample. The interviewer will ask for an example, and 'two out-of-the-money digital options that each blow up 0.6 percent of the time' is the one that works. Also worth avoiding: claiming VaR is never subadditive. For normal distributions it is.
Expect next
- Give me a concrete two-position counterexample.
- Is VaR subadditive under any conditions?
- What practical problem does this create for limit setting?
Reported by candidates at UBS (Risk Management, Zurich, 2021). Source: Wall Street Oasis.
012Your 99 percent one-day VaR model produced nine exceptions in the last 250 days. Walk me through what you do.Bank market riskModel validation
Say this
Nine is amber, one short of red, so two things happen in parallel: the capital multiplier steps up and I open a model investigation. But before either, I check that the exceptions are real and not a data or P&L-attribution problem.
Then walk it
- Step one, validate the exceptions. Bad marks, a stale curve, a missing trade feed, or backtesting against actual instead of hypothetical P&L can all manufacture breaches. I've seen a whole amber month turn out to be one mispriced illiquid bond.
- Step two, look at clustering. Nine breaches spread evenly across the year says the model is calibrated too low. Nine in a three-week window in March says the model is fine in normal times and slow to react to a volatility regime shift. Completely different fixes.
- Step three, attribute. Which desk, which risk factor, which side. If eight of the nine come from one credit desk, it's not a firmwide VaR problem, it's a missing risk factor or a proxy that stopped working.
- Step four, size them. Breaches at 1.1 times VaR are a calibration issue. Breaches at three times VaR mean the tail shape is wrong, which points at normality or at unmodelled optionality.
- Step five, the regulatory and capital consequence. Under the Basel backtesting framework nine exceptions sits in the amber zone with a multiplier around 3.65 rather than 3.0, and it's a disclosable model performance issue. I'd tell the CRO and the supervisor rather than wait to be asked.
- Step six, the fix, and it should be the smallest defensible one: reweighting the window or moving to volatility-scaled historical simulation for clustering, adding a missing factor for a desk problem, moving to full revaluation for an optionality problem. Then re-run the backtest on the corrected model over the same period.
- And the interim control while the fix is validated: a VaR add-on or a tightened desk limit. You don't get to run unlimited with a broken model while the remediation is in flight.
Where candidates lose it
Jumping straight to 'recalibrate the model'. The first move is always to check whether the exceptions are real, and the second is to look at their pattern. A candidate who recalibrates without diagnosing has just fitted the model to a data error, and that is the exact failure the interviewer is probing for.
Expect next
- What if all nine were in the same fortnight?
- What's the capital consequence of amber versus red?
- Would you tell the regulator before or after you had a fix?
014Desk A has $10 million of VaR and Desk B has $10 million of VaR. What is the firm's VaR, and which desk is using more of the limit?Bank market riskBuy-side risk
Say this
Anywhere from zero to $20m, depending on correlation. If they're perfectly correlated it's $20m, if perfectly offsetting it's zero, and if independent it's about $14.1m. And neither desk is necessarily using half the limit, which is the real point of the question.
Then walk it
- Under normality, combined VaR is the square root of the sum of squares plus twice the covariance term. Two $10m desks at zero correlation gives $10m times root two, so $14.1m. At 0.5 correlation it's about $17.3m.
- That gap between $20m and $14.1m is the diversification benefit, and allocating it is the political heart of a risk manager's job.
- Component VaR is how you split it. You compute each desk's contribution so the components sum exactly to firm VaR. It's marginal VaR times position size, and it's the number you use for limits and for risk-adjusted performance.
- Marginal VaR is the derivative: how much firm VaR changes for a small increase in that desk. Incremental VaR is the discrete version, firm VaR with the desk minus firm VaR without it.
- Here's the counterintuitive part that makes it a good interview question. A desk hedging the rest of the firm can have positive standalone VaR and negative component VaR. It genuinely reduces firm risk, and a naive standalone limit framework would penalise it.
- So the answer to 'which desk uses more limit' is: whichever has the higher component VaR, and you cannot tell from the standalone numbers. You need the covariance with everything else.
Where candidates lose it
Answering $20m, or answering $14.1m as though independence were given. The interviewer wants the range and the word correlation, then the distinction between standalone and component VaR. The hedging-desk case, where component VaR is negative, is the answer that gets remembered.
Expect next
- Can a desk have negative component VaR?
- How would you allocate the diversification benefit between the two desks?
- Does this decomposition still work for expected shortfall?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

