Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
011How do you backtest a VaR model?Bank market riskModel validation
Say this
Compare the daily VaR forecast to the actual next-day P&L and count the days the loss exceeded it. Then test whether that count and its timing are consistent with your confidence level. At 99% over 250 days, you expect about two or three exceptions.
Then walk it
- First fix the P&L definition. You backtest against hypothetical P&L, which holds the portfolio static, not actual P&L, which includes intraday trading and fees. Otherwise you're testing the traders, not the model.
- Unconditional coverage: the Kupiec proportion-of-failures test. Is the exception count statistically consistent with one percent? With 250 days, you can't reject much below five exceptions, so the test has weak power. Say that.
- Conditional coverage: are exceptions independent, or do they cluster? Christoffersen's test looks at that. Clustering means the model is slow to react to volatility regimes, which is the classic symptom of a long unweighted historical window.
- Basel's traffic light is the version supervisors actually use: green up to four exceptions in 250 days, amber five to nine with a rising capital multiplier, red at ten or more, which triggers a multiplier of four and a model review.
- Then diagnostics beyond the count. Which desks and which risk factors produced the breaches, and how big were the breaches relative to VaR. Ten small breaches and two enormous ones are different failures needing different fixes.
- The limitation I'd raise: a single year at 99% simply doesn't contain enough tail events to prove a model right. Backtesting can reject a bad model and cannot confirm a good one. That's why it sits alongside benchmarking and stress testing.
Where candidates lose it
Counting breaches and stopping. Two things get missed almost every time: using hypothetical rather than actual P&L, and saying that the test has low statistical power over 250 days. Both show you understand what backtesting can and cannot prove.
Expect next
- What is the Basel traffic light approach?
- Why hypothetical P&L and not actual?
- Zero exceptions in a year. Is the model good?
012Your 99 percent one-day VaR model produced nine exceptions in the last 250 days. Walk me through what you do.Bank market riskModel validation
Say this
Nine is amber, one short of red, so two things happen in parallel: the capital multiplier steps up and I open a model investigation. But before either, I check that the exceptions are real and not a data or P&L-attribution problem.
Then walk it
- Step one, validate the exceptions. Bad marks, a stale curve, a missing trade feed, or backtesting against actual instead of hypothetical P&L can all manufacture breaches. I've seen a whole amber month turn out to be one mispriced illiquid bond.
- Step two, look at clustering. Nine breaches spread evenly across the year says the model is calibrated too low. Nine in a three-week window in March says the model is fine in normal times and slow to react to a volatility regime shift. Completely different fixes.
- Step three, attribute. Which desk, which risk factor, which side. If eight of the nine come from one credit desk, it's not a firmwide VaR problem, it's a missing risk factor or a proxy that stopped working.
- Step four, size them. Breaches at 1.1 times VaR are a calibration issue. Breaches at three times VaR mean the tail shape is wrong, which points at normality or at unmodelled optionality.
- Step five, the regulatory and capital consequence. Under the Basel backtesting framework nine exceptions sits in the amber zone with a multiplier around 3.65 rather than 3.0, and it's a disclosable model performance issue. I'd tell the CRO and the supervisor rather than wait to be asked.
- Step six, the fix, and it should be the smallest defensible one: reweighting the window or moving to volatility-scaled historical simulation for clustering, adding a missing factor for a desk problem, moving to full revaluation for an optionality problem. Then re-run the backtest on the corrected model over the same period.
- And the interim control while the fix is validated: a VaR add-on or a tightened desk limit. You don't get to run unlimited with a broken model while the remediation is in flight.
Where candidates lose it
Jumping straight to 'recalibrate the model'. The first move is always to check whether the exceptions are real, and the second is to look at their pattern. A candidate who recalibrates without diagnosing has just fitted the model to a data error, and that is the exact failure the interviewer is probing for.
Expect next
- What if all nine were in the same fortnight?
- What's the capital consequence of amber versus red?
- Would you tell the regulator before or after you had a fix?
013Take me through the basic concepts in market risk. What are the main types?ScotiabankRisk · Toronto · 2025
Say this
Market risk is the risk of loss from moves in market prices, and it splits by the factor driving it: interest rate, equity, foreign exchange, credit spread and commodity. Then volatility risk sits across all of them once you hold options.
Then walk it
- Interest rate risk is usually the biggest for a bank, and it has shape as well as level: parallel shifts, steepening and flattening, and basis between curves.
- Credit spread risk is separate from interest rate risk even though both show up in a bond price. One is the risk-free curve moving, the other is the spread over it, and they often move in opposite directions in a flight to quality.
- Equity, FX and commodity risk are more straightforward directionally, but FX carries a funding dimension too, because a cross-currency basis move hits you even with no net FX position.
- Volatility risk comes free with any option book: vega for the level of implied vol, and then the shape, skew and term structure.
- Then the two that candidates forget. Basis risk, where your hedge and your exposure are driven by different but correlated factors. And market liquidity risk, where the price you can actually transact at is worse than the mark.
- The way a desk measures all of it is sensitivities plus VaR plus stress. Sensitivities for daily trading decisions, VaR for aggregation and limits, stress for the scenarios VaR can't see.
Where candidates lose it
Giving four factor names and stopping. Two things lift the answer: separating credit spread risk from interest rate risk, and naming basis risk and market liquidity risk as market risks in their own right. Those are the ones that actually generate P&L surprises.
Expect next
- Which of those is largest for a commercial bank, and why?
- Is credit spread risk market risk or credit risk?
- Now tell me about counterparty credit risk.
Reported by candidates at Scotiabank (Risk, Toronto, 2025). Source: Wall Street Oasis.
014Desk A has $10 million of VaR and Desk B has $10 million of VaR. What is the firm's VaR, and which desk is using more of the limit?Bank market riskBuy-side risk
Say this
Anywhere from zero to $20m, depending on correlation. If they're perfectly correlated it's $20m, if perfectly offsetting it's zero, and if independent it's about $14.1m. And neither desk is necessarily using half the limit, which is the real point of the question.
Then walk it
- Under normality, combined VaR is the square root of the sum of squares plus twice the covariance term. Two $10m desks at zero correlation gives $10m times root two, so $14.1m. At 0.5 correlation it's about $17.3m.
- That gap between $20m and $14.1m is the diversification benefit, and allocating it is the political heart of a risk manager's job.
- Component VaR is how you split it. You compute each desk's contribution so the components sum exactly to firm VaR. It's marginal VaR times position size, and it's the number you use for limits and for risk-adjusted performance.
- Marginal VaR is the derivative: how much firm VaR changes for a small increase in that desk. Incremental VaR is the discrete version, firm VaR with the desk minus firm VaR without it.
- Here's the counterintuitive part that makes it a good interview question. A desk hedging the rest of the firm can have positive standalone VaR and negative component VaR. It genuinely reduces firm risk, and a naive standalone limit framework would penalise it.
- So the answer to 'which desk uses more limit' is: whichever has the higher component VaR, and you cannot tell from the standalone numbers. You need the covariance with everything else.
Where candidates lose it
Answering $20m, or answering $14.1m as though independence were given. The interviewer wants the range and the word correlation, then the distinction between standalone and component VaR. The hedging-desk case, where component VaR is negative, is the answer that gets remembered.
Expect next
- Can a desk have negative component VaR?
- How would you allocate the diversification benefit between the two desks?
- Does this decomposition still work for expected shortfall?
015What is stress testing, and how is it different from VaR?Bank market riskRegulatory reporting
Say this
VaR is statistical and stress testing is conditional. VaR asks what the distribution of outcomes looks like given recent history; stress testing asks what happens if this specific thing occurs, with no probability attached. They answer different questions and neither substitutes for the other.
Then walk it
- VaR is probabilistic and backward-looking. It needs history and it gives you a likelihood. Stress testing is a what-if: rates up 300 basis points, equities down 40 percent, the rupee at 95, and here is the P&L.
- Stress testing lets you ask about things that have never happened. VaR structurally cannot, because it has no data on them.
- It also handles non-linearity honestly. A large prescribed shock reveals gamma and correlation breakdown that a one-day 99% move never touches.
- Three flavours worth naming: sensitivity tests on one factor at a time, scenario tests with a coherent joint move across many factors, and reverse stress tests that start from failure and work backwards.
- The weakness is that stress testing has no probability. A scenario that loses $2bn is only actionable if you have a view on how likely it is, and scenario design is where the judgement, and the political pressure, sits.
- In practice the two are complements at different confidence levels. VaR and expected shortfall set day-to-day limits; stress tests and ICAAP set capital and inform the risk appetite. A bank that only ran VaR in 2007 saw nothing coming.
Where candidates lose it
Framing stress testing as 'a bigger VaR'. It isn't a confidence level, it's a different epistemology: conditional and judgement-driven rather than statistical. And you should volunteer the weakness, that scenarios carry no probability, before being asked.
Expect next
- Who should design the scenarios, risk or the business?
- How do you stop scenario design becoming a negotiation?
- What is reverse stress testing?
016Design a stress scenario for a book that is long Indian corporate bonds and short interest rate futures.Indian bank risk and treasuryBank market risk
Say this
The scenario has to break the hedge, not just move the market. The position is long credit and short duration, so the pain case is spreads widening while the risk-free curve rallies, which is precisely what a flight to quality does.
Then walk it
- Start by naming the real exposures. Net duration is small by design, so a parallel shift is not the risk. The live risks are credit spread, the government-bond-to-swap basis, the futures-to-cash basis, and liquidity in the corporate leg.
- So the core shock: AAA and AA corporate spreads widen 150 to 250 basis points, while the ten-year G-sec yield falls 75 basis points. You lose on both legs at once. That is the textbook flight-to-quality asymmetry and it happened in March 2020.
- Layer in the basis. The bond futures may not track the cash bond you hold, and the cheapest-to-deliver can switch. Add 25 to 50 basis points of adverse basis independent of the spread move.
- Layer in liquidity. Indian corporate bond secondary volumes are thin outside the top names, so add a bid-offer widening of two to four times normal and assume you can only exit 20 percent of the position in a week. Then mark the rest at the stressed exit price, not the matrix price.
- Layer in funding. Repo haircuts on corporate paper rise, margin on the futures short goes up as volatility spikes, and both hit the same day. That is the mechanism that turns a mark-to-market loss into a forced sale.
- Add a name-specific tail: one issuer in the book is downgraded below investment grade, which triggers forced selling by mandate-constrained funds and moves the whole rating bucket. The IL&FS episode in 2018 is the live Indian precedent, and the credit-fund redemption spiral that followed is the second-round effect.
- Then report it properly: P&L by leg, the funding call in rupees, days to unwind, and which limits break. A scenario that produces one aggregate number is not decision-useful.
Where candidates lose it
Designing a parallel rate shock. The book is deliberately hedged against that, so the scenario shows nothing and you have proved you didn't look at the position. A good stress scenario attacks the assumption the hedge relies on, which here is spread-to-rate correlation, and it must include liquidity and funding, not just price.
Expect next
- How would you calibrate the size of the spread move?
- What second-round effects would you add?
- How would you present this to a treasurer who says the book is hedged?
017What is reverse stress testing, and why do supervisors like it so much?Bank market riskRegulatory reporting
Say this
You start from the outcome, business failure, and work backwards to find what would cause it. Supervisors like it because it removes the bank's ability to choose a comfortable scenario. You can't pick a shock that happens to be survivable if the shock is defined as the one you don't survive.
Then walk it
- Define failure first, and precisely. Not just insolvency, but the point where the business model is no longer viable: CET1 through the requirement, or losing access to wholesale funding, or a rating downgrade that kills the franchise.
- Then solve for the scenario. Search across risk factors for combinations that get you there, and rank them by plausibility rather than by size.
- The output is not a loss number. It's a set of vulnerabilities and a judgement on whether the required shock is remote or uncomfortably close. If your bank fails on a 120 basis point spread widening, that's an urgent finding no matter what probability you assign.
- It's also how you find concentrations nobody wrote down. Reverse stress testing frequently surfaces that failure runs through one funding counterparty, one collateral type, or one country, which no forward scenario was built to test.
- Then it feeds the recovery plan. Each identified path needs a management action and a trigger, which is the actual regulatory point. It's a bridge between risk measurement and resolution planning.
- The hard part, and worth saying: the search space is enormous and the answer is sensitive to which factors you allow to move together. The exercise is only as honest as the people running it, and it's very easy to make the required shock look implausible.
Where candidates lose it
Describing it as 'a very severe stress test'. Severity isn't the distinguishing feature, direction is. Forward tests go from cause to effect, reverse tests go from failure to cause. And if you don't define failure precisely at the start, the exercise has no answer.
Expect next
- How would you define failure for a broker-dealer versus a deposit-taking bank?
- What do you do with the output?
- How do you stop management dismissing the scenario as implausible?
018How would you run an ICAAP, and how does it relate to the supervisory stress tests?Regulatory reportingBank credit risk
Say this
ICAAP is the bank's own answer to 'how much capital do you actually need', as opposed to the minimum the rules prescribe. You identify all material risks, quantify them including the ones Pillar 1 ignores, stress the plan, and conclude with a capital number and a plan to hold it.
Then walk it
- Start with a risk identification and materiality assessment across everything, not just credit, market and operational. Concentration, interest rate risk in the banking book, pension, reputational, strategic and model risk are the Pillar 2 gaps, and IRRBB and concentration are usually the two biggest.
- Quantify each, then stress the three-year business plan under a baseline and at least one severe but plausible adverse scenario. The adverse case has to be internally consistent: if GDP falls, credit costs rise, fee income falls and RWAs inflate through downgrades, all at once.
- Project the capital path, not just the end point. The trough quarter is what matters, and it usually sits in year two because provisions lag the macro.
- Set the internal capital requirement above the regulatory minimum, with a management buffer sized so that you don't breach the buffer requirement in the adverse case and get dividend restrictions.
- Then the management actions, with triggers. Which of those are credible under stress is the question a supervisor will push on hardest, because cutting dividends works and issuing equity in a crisis usually doesn't.
- The relationship with supervisory tests: the regulator's exercise, CCAR in the US, the EBA's in Europe, and the RBI's stress-testing guidance in India, uses common prescribed scenarios so banks can be compared. ICAAP is idiosyncratic and covers risks the common scenario ignores. Under the SREP the supervisor uses your ICAAP to set a Pillar 2 requirement on top of Pillar 1.
- Governance is half the assessment. An ICAAP the board has clearly never read fails regardless of the modelling quality. The board's sign-off on the risk appetite and the capital plan is the artefact supervisors look for first.
Where candidates lose it
Describing ICAAP as a document rather than a process, and forgetting Pillar 2 risks. If you can't name interest rate risk in the banking book and concentration as the two big risks outside Pillar 1, you have not understood why ICAAP exists at all.
Expect next
- Which Pillar 2 risk is usually the largest?
- How would you size a management buffer?
- What management actions would a supervisor refuse to credit?
019Your model says that was a one-in-ten-thousand-year event, and it has now happened twice this decade. What is wrong?Model validationBank market risk
Say this
The model is wrong, not the world. Two ten-thousand-year events in ten years is overwhelming evidence against the distribution, and the usual culprit is a normal assumption applied to a market that isn't normal.
Then walk it
- First, the arithmetic. Under the model, the probability of two such events in a decade is vanishingly small. Bayes says you should abandon the model long before you conclude you got unlucky twice.
- Most likely cause one, the wrong distribution. Normal tails decay far faster than real financial tails. A move that is 6 sigma under a normal is roughly a 1-in-500-million-day event; under a t distribution with four degrees of freedom it's something you see every few years.
- Cause two, non-stationarity. The model was calibrated on a regime that no longer applies. Volatility clusters and regimes shift, so an unconditional distribution fitted over twenty years will call a high-volatility regime impossible.
- Cause three, a dependence assumption. Individually plausible moves become impossible jointly if you've assumed low correlation. In a crisis correlations go to one and the joint event is far more likely than the model thinks.
- Cause four, the mundane one that is often the real answer: the event was outside the model's domain entirely. A sovereign default, a currency peg breaking, a negative oil price. The factor wasn't allowed to do that, so the model assigned it probability zero rather than a small number.
- And the professional answer to 'what do you do': stop quoting return periods you can't support. Report the scenario and the loss, drop the implied probability, and say the model is uninformative beyond the range where you have data.
Where candidates lose it
Defending the model by saying markets got unusual. That's the answer a regulator hears from a bank that is about to fail. The point of the question is whether you will update your beliefs against a model you built, and the credible answer names fat tails, regime change and the correlation assumption specifically.
Expect next
- How would you re-estimate the tail with so little data?
- Would extreme value theory help here?
- How would you communicate this to a board that has been shown the old number for three years?
020Explain the Greeks to me.Bank market riskDerivatives risk
Say this
They're the partial derivatives of an option's value with respect to each input. Delta is sensitivity to spot, gamma is how delta changes, vega is sensitivity to implied volatility, theta is time decay and rho is sensitivity to rates.
Then walk it
- Delta, first derivative in spot. Roughly 0.5 for an at-the-money option, and it's also the hedge ratio, so it tells you how much stock to short.
- Gamma, second derivative in spot. It's the curvature, it's largest at the money and near expiry, and it's the reason a static delta hedge stops working when the market moves.
- Vega, sensitivity to implied vol. Largest for long-dated at-the-money options, because there's more time for volatility to matter. A one-point vol move on a big vega book is real money.
- Theta, the passage of time. A long option position bleeds theta and collects gamma; a short position collects theta and is short gamma. That trade-off is the whole economics of an option book.
- Rho for rates, and for anything with a dividend or a carry you also need the sensitivity to that. On FX options you have two rho-like terms, one per currency.
- From a risk seat the ones that cause incidents are gamma and vega, not delta. Delta is easy to see and easy to hedge. Gamma and vega are where a book that looks flat loses money.
Where candidates lose it
Reciting definitions without saying which ones matter to a risk manager. Delta is the one traders talk about and the one risk cares least about, because it's hedgeable intraday. Say that gamma and vega are where the losses come from and you sound like you've sat on a desk.
Expect next
- Which Greek is hardest to hedge, and why?
- What is the relationship between gamma and theta?
- How would you set a limit framework on an options book?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

