Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
021A trader tells you his book is delta neutral. It lost $4 million yesterday on a 3 percent market move. What happened?Bank market riskDerivatives risk
Say this
Almost certainly short gamma. Delta neutral only holds for an infinitesimal move; if he's short options, delta turns against him as the market runs, so he's rehedging at worse and worse prices all the way. The move being 3 percent is the clue.
Then walk it
- The mechanism: short gamma means delta moves against you. Market rallies, your delta goes short, you buy to rehedge, market falls back, your delta goes long, you sell. You buy high and sell low mechanically all day.
- Rough size check: for a book with gamma of minus $2m per percent, a 3 percent move costs about half times gamma times move squared, so around $9m of gamma P&L. A $4m loss is entirely consistent with a modest short gamma position.
- Second candidate, vega. A 3 percent move usually comes with implied vol up several points. If he's short vol, that's a separate loss on top, and on a big book vega loss can dwarf gamma loss.
- Third, delta neutral in what. Neutral to the index but long a basket of single names is a beta hedge, not a delta hedge. Dispersion or a basis between the hedge instrument and the underlying gives you exactly this.
- Fourth, the hedge was neutral at the close and not during the day. Intraday delta drift with no rehedging looks flat on both snapshots and loses money in between.
- So the questions I'd ask him, in order: what's your gamma and vega, what did implied vol do, what instrument are you hedged in, and when was the last rehedge. And the control conclusion: a delta limit alone was never going to catch this, which is why you need gamma and vega limits.
Where candidates lose it
Saying 'he must have been wrong about being delta neutral'. He probably wasn't. The whole point is that delta neutrality is a local property and says nothing about second-order risk. Name gamma first, vega second, and then draw the control conclusion about limits.
Expect next
- How would you size a gamma limit?
- How do you explain to a trader that delta neutral isn't neutral?
- What if implied vol had fallen instead?
022Which equities have duration?BlackRockRisk and Quantitative Analysis · New York · 2026
Say this
Equity duration is how sensitive a stock's price is to the discount rate, and it's driven by how far out the cash flows sit. Long-duration equities are the ones whose value is mostly terminal value: high-growth tech, biotech with no earnings, and long-dated infrastructure and utilities.
Then walk it
- Mechanically it's the same idea as bond duration. Discount cash flows, compute the weighted average time to those cash flows, and that's your rate sensitivity. A company earning nothing today with all the value in year fifteen has enormous duration.
- So the long-duration buckets: unprofitable growth software, early-stage biotech, anything valued on a distant terminal value, plus regulated utilities and infrastructure where the cash flows are bond-like and stretch for decades.
- The short-duration buckets: value names, banks, energy, cyclicals with high near-term free cash flow and low reinvestment. Their value is front-loaded, so the discount rate matters less.
- The empirical check: 2022 is the cleanest natural experiment. As real yields rose, the Nasdaq underperformed value by a huge margin even though earnings held up. That is duration doing the work, not fundamentals.
- There's a twist that matters for a risk seat: for financials the rate effect goes the other way through earnings. Banks' net interest margins improve with rates, so their effective duration can be negative. You can't apply a single sign to the whole market.
- And utilities are the interesting case, because they have long-duration cash flows and leverage, so they trade as rate proxies. Many managers hold them as bond substitutes and then get surprised when they behave like bonds.
Where candidates lose it
Treating this as a trick question or saying equities don't have duration. The interviewer is testing whether you can move a fixed income concept into equities and name the cohorts. And the answer that stands out mentions financials as the exception where the sign flips.
Expect next
- Why did long-duration equities sell off so hard in 2022?
- Do banks have positive or negative equity duration?
- How would you hedge the rate sensitivity of a growth equity portfolio?
Reported by candidates at BlackRock (Risk and Quantitative Analysis, New York, 2026). Source: Wall Street Oasis.
023Explain duration and convexity.Bank market riskTreasury and ALM
Say this
Duration is the first-order sensitivity of a bond's price to yield, convexity is the second-order correction. Duration is the slope of the price-yield curve and convexity is its curvature, which is why a duration-only estimate always understates the price rise and overstates the fall.
Then walk it
- Macaulay duration is the weighted average time to cash flow, in years. Modified duration is that divided by one plus the yield, and it's the one you use: price change is roughly minus modified duration times the yield change.
- Worked number: a bond with modified duration of 7 and a 100 basis point yield rise loses about 7 percent. With convexity of 60, you add half times 60 times 0.01 squared, which is 0.3 percent, so the real loss is closer to 6.7 percent.
- Convexity is positive for a plain vanilla bond, which is good for the holder. Your gains from a rally exceed your losses from an equal sell-off.
- Negative convexity is the thing to watch. A callable bond or a mortgage-backed security has it, because when rates fall the issuer or homeowner prepays and you don't get the upside. That's the whole story of mortgage hedging, and it's why MBS books need dynamic hedging.
- Duration also assumes a parallel shift. A steepening curve can hurt you badly on a barbell that looks duration-matched, which is why you look at key rate durations by bucket, not one number.
- And the term to have ready: DV01, or price value of a basis point, is the same idea in money rather than percent, and it's what a rates desk actually manages to.
Where candidates lose it
Defining duration as 'time to maturity'. It isn't, except for a zero-coupon bond, and the interviewer is listening for that error. The second differentiator is negative convexity on callables and mortgages, because that's where the real risk management problem sits.
Expect next
- What is DV01?
- Why does a mortgage-backed security have negative convexity?
- Two portfolios have the same duration. How can their risk differ?
024What is basis risk? Give me an example.Bank market riskTreasury and ALM
Say this
Basis risk is the risk that your hedge and your exposure don't move together, so you're left with residual P&L even though you think you're flat. It's what's left after you've hedged the first-order factor.
Then walk it
- The classic example: you hold a corporate bond and hedge the rate risk with a government bond future. Now you're exposed to the spread between corporate and government yields, which is exactly the thing that moves in a credit event.
- Product basis: hedging a jet fuel exposure with crude futures because jet fuel futures are illiquid. The crack spread becomes your risk, and airlines have lost real money on that.
- Tenor and calendar basis: hedging a three-month exposure with a one-month contract and rolling. Each roll re-prices the basis, and in a stressed market that roll cost blows out.
- Location and currency basis: cross-currency basis on a dollar funding swap. In March 2020 that basis widened by more than 100 basis points, which made hedged dollar funding dramatically more expensive for non-US banks holding dollar assets.
- In a bank's banking book it shows up as repricing basis: your loans reprice off the repo-linked benchmark and your deposits reprice off something else entirely, so a rate move that looks neutral on a gap report still hits net interest margin.
- The way you manage it is to measure it explicitly, set a separate basis limit, and stress it. The failure mode is that VaR often shows a hedged book as low risk because the basis has been quiet, right up until it isn't.
Where candidates lose it
Defining it abstractly without a concrete pair. Interviewers want an instrument and its hedge named. And the risk-manager point to add is that basis risk is systematically understated by VaR, because the basis is stable for long stretches and then jumps.
Expect next
- How would you measure and limit basis risk?
- Why does VaR tend to understate it?
- What happened to cross-currency basis in March 2020?
025Explain PD, LGD and EAD.Bank credit riskRating agencies
Say this
They're the three inputs to expected loss. Probability of default is how likely the borrower stops paying, loss given default is the fraction you don't recover, and exposure at default is how much is outstanding when it happens. Multiply the three and you have expected loss.
Then walk it
- PD is a probability over a horizon, usually one year, and it comes from a rating or a scorecard. Say the horizon, because a one-year PD and a lifetime PD are very different numbers.
- LGD is one minus the recovery rate, expressed on the exposure. It's driven by collateral, seniority and how good the legal enforcement regime is. Senior secured on a warehouse in a good jurisdiction might be 25 percent; unsecured sub debt is 70 to 90.
- EAD is what's actually outstanding at default. For a term loan it's roughly the drawn balance. For a revolver or a credit card it's the drawn amount plus a credit conversion factor on the undrawn part, because stressed borrowers draw their lines down before they default.
- Worked number: a 100 crore facility, PD of 2 percent, LGD of 40 percent gives expected loss of 0.8 crore, so 80 basis points. That's a provisioning and pricing number, not a capital number.
- The three are not independent, and that's the bit people miss. In a recession PD rises and recoveries fall at the same time, because collateral values are down and everyone is selling. That's downturn LGD, and Basel requires you to use it rather than a long-run average.
- For a derivative there's no drawn balance, so EAD has to be modelled from potential future exposure. That's a different exercise entirely, and it's why counterparty credit risk has its own framework.
Where candidates lose it
Getting the definitions right and missing that PD and LGD are correlated. Using an average recovery rate through a downturn understates loss badly, and downturn LGD is a specific Basel requirement. Also state the PD horizon; a PD without a horizon is not a number.
Expect next
- Why does Basel require downturn LGD?
- How do you estimate EAD on a revolver?
- How would you estimate PD for a borrower with no rating?
026What's the difference between expected and unexpected loss, and which one does capital cover?Bank credit riskRegulatory reporting
Say this
Expected loss is the average you lose in a normal year, and it's covered by provisions and priced into the loan spread. Unexpected loss is the deviation above that in a bad year, and that's what capital is for. Provisions cover the mean, capital covers the tail.
Then walk it
- Expected loss is PD times LGD times EAD. It's a cost of doing business, so it belongs in the price. If your spread doesn't cover EL plus funding plus operating cost plus a return on capital, you're lending at a loss.
- Unexpected loss is the distance from the mean to a high quantile of the loss distribution, usually 99.9 percent over one year in Basel's IRB framework. That's the one-in-a-thousand-year bad year the bank is supposed to survive.
- The distribution is heavily right-skewed, not normal, because defaults are correlated. Most years you lose a little, occasionally you lose a lot, and the asymmetry is driven entirely by that correlation.
- The mechanism is the asset correlation assumption. If defaults were independent, a large portfolio would have almost no unexpected loss and you'd need almost no capital. Basel's IRB formula bakes in correlations of roughly 12 to 24 percent for corporates, and it's that number, not PD, that creates the capital requirement.
- Numerical feel: a portfolio with 80 basis points of expected loss might carry a 99.9 percent loss of 5 or 6 percent. So capital is several times provisions, and that ratio widens for a concentrated book.
- The gap that matters in practice: IFRS 9 provisions and Basel expected loss are computed differently, so the two rarely agree, and the shortfall or excess adjusts CET1. That reconciliation is a real job in a bank's finance and risk function.
Where candidates lose it
Saying capital covers expected loss. It doesn't, provisions do, and mixing those up is a hard fail in a credit risk interview. The answer that stands out names asset correlation as the thing generating unexpected loss, because a candidate who says that understands why a diversified book still needs capital.
Expect next
- Why is the loss distribution skewed?
- What drives the size of unexpected loss more, PD or correlation?
- How does the IFRS 9 provision interact with regulatory capital?
027How would you approach building a delinquency model?Neuberger BermanRisk · Chicago · 2024
Say this
Define the target first, then build backwards. Delinquency is not default, so I'd fix the bad definition, say 90 days past due within twelve months, set an observation and performance window, and only then worry about features and model form.
Then walk it
- Target definition is the decision that determines everything else. 30, 60 or 90 days past due, and over what horizon. Roll-rate analysis tells you where delinquency becomes effectively irreversible, and that's where you draw the line.
- Sampling: pick an observation point, take the borrower's state as at that date, then observe outcomes over the following twelve months. Strict separation, or you leak future information into features and get a model that looks brilliant in development and fails in production.
- Features in three families. Behavioural: utilisation trend, minimum-payment behaviour, recent missed payments, bounced mandates. Bureau: enquiry velocity, existing delinquency elsewhere, thin-file flags. Loan and demographic: loan-to-value, instalment-to-income, vintage, product, channel of origination.
- Model form: start with logistic regression on coarse-classified, weight-of-evidence binned variables. It's monotonic, explainable and passes validation. Then run a gradient boosting challenger to see how much signal the simple model leaves on the table. If the gap is small, ship the simple one.
- Validation: out-of-time as well as out-of-sample, because credit models degrade through the cycle not through the sample. Report Gini or AUC for ranking, and a calibration curve for whether the predicted rates match observed. A model can rank perfectly and be badly calibrated.
- Two traps specific to credit. Survivorship and selection bias: you only observe outcomes for people you approved, so the model is blind to the rejected population, and you need reject inference. And macro sensitivity: a model built on 2021 data has never seen a rate cycle, so the absolute PD level will be wrong even if the ranking holds.
- Then monitoring. Population stability index on the score distribution, drift on each feature, and a monthly actual-versus-expected. Most delinquency models fail from population shift rather than bad maths.
Where candidates lose it
Going straight to algorithms. In credit, the target definition, the observation window and the reject-inference problem are worth more than model choice, and interviewers who build these for a living are listening for exactly those. Also say the word calibration; ranking power alone doesn't let you price or provision.
Expect next
- How would you handle reject inference?
- How would you know the model had degraded?
- Would you use gradient boosting in production for this?
Reported by candidates at Neuberger Berman (Risk, Chicago, 2024). Source: Wall Street Oasis.
028How do you build a credit scorecard, and how do you prove it works?Bank credit riskGlobal capability centres
Say this
Bin every variable, convert to weight of evidence, fit a logistic regression, then scale the log odds into points. You prove it works on three axes: discrimination, calibration and stability, tested out of time, not just out of sample.
Then walk it
- Coarse classification first. Bin each variable so the bad rate is monotonic across bins and each bin has enough volume, usually at least 5 percent of the population. Then replace the bin with its weight of evidence, the log of the good-to-bad odds ratio.
- Information value tells you which variables to keep. Below about 0.02 is useless, 0.1 to 0.3 is useful, above 0.5 and I'd check for leakage rather than celebrate.
- Fit logistic regression on the WOE variables, then scale: points equal offset plus factor times log odds, calibrated so a chosen score doubles the odds every 20 points. That scaling is cosmetic but it's how credit officers read the output.
- Discrimination: Gini, or equivalently AUC, where Gini equals two times AUC minus one. A retail behavioural scorecard should hit 0.55 to 0.70 Gini; an application scorecard on a thin-file population might only get 0.35, and that can still be commercially valuable. Kolmogorov-Smirnov is the other standard, the maximum gap between the cumulative good and bad distributions.
- Calibration: plot predicted against observed bad rate by score band, and run a Hosmer-Lemeshow style test. Discrimination decides who you approve; calibration decides what you charge and what you provision. You need both.
- Stability: population stability index between development and current, per variable and on the score. Above 0.25 and the population has shifted enough that the model needs rebuilding, not just recalibration.
- And the governance point: build on a development sample, validate on a holdout, then validate again on a later time period the model never saw. An out-of-sample test on a random split proves almost nothing for a credit model, because the whole failure mode is time.
Where candidates lose it
Quoting a Gini target as if it were universal. A good Gini depends entirely on the population and the product, and someone who has built these knows that. The other failure is testing only discrimination. A model with 0.7 Gini and broken calibration will approve the right people and price them all wrong.
Expect next
- What Gini would you expect on a prime mortgage book?
- The Gini is stable but the bad rate has doubled. What happened?
- When do you recalibrate versus rebuild?
029What is the difference between a point-in-time and a through-the-cycle rating, and when does it matter?Bank credit riskRating agencies
Say this
A point-in-time PD reflects the borrower's risk right now, including where we are in the cycle. A through-the-cycle rating strips the cycle out and asks how the borrower would do on average across one. PIT moves a lot, TTC barely moves.
Then walk it
- Agency ratings are broadly through-the-cycle by design. That's why an investment grade issuer doesn't get downgraded every recession, and why agencies talk about rating through a trough.
- IFRS 9 needs point-in-time, because expected credit loss is supposed to be a current, forward-looking estimate conditioned on today's macro forecast.
- Basel IRB regulatory capital leans through-the-cycle, deliberately, to stop capital requirements swinging with the cycle. If PDs were fully PIT, RWAs would balloon in a recession precisely when banks can't raise capital.
- That's the procyclicality argument and it's the real content of this question. A PIT capital regime amplifies the cycle: losses rise, RWAs rise, capital ratios fall twice over, lending contracts, the recession deepens.
- The practical consequence is that a bank runs two PD scales and a mapping between them, and the conversion is genuinely hard. You need a macro model to shift a TTC PD to a PIT PD for a given scenario.
- The honest caveat: no real rating system is purely one or the other. Agency ratings do migrate in downturns, and IRB models do have cyclical components. It's a spectrum, and the useful question about any model is how much of the cycle it passes through.
Where candidates lose it
Defining both and not explaining why anyone cares. The payoff is procyclicality: why regulators want TTC for capital and accountants want PIT for provisions, and why the same borrower carries two different PDs in the same bank on the same day.
Expect next
- Which does IFRS 9 need, and why?
- How would you convert a TTC PD to a PIT PD?
- Is procyclicality a real problem or a theoretical one?
030Explain IFRS 9 expected credit loss staging.Bank credit riskRegulatory reporting
Say this
Three stages. Stage 1 is performing, and you provide twelve-month expected loss. Stage 2 is a significant increase in credit risk since origination, and you jump to lifetime expected loss. Stage 3 is credit impaired, lifetime loss with interest recognised on the net carrying amount.
Then walk it
- The whole model is forward-looking and unbiased, probability-weighted across at least a couple of macro scenarios. That's the break from the old incurred-loss model, which waited for evidence of impairment before providing.
- The cliff is the interesting bit. Moving from Stage 1 to Stage 2 changes the horizon from twelve months to lifetime, so on a twenty-year mortgage the provision can jump by a multiple overnight without a single missed payment.
- The trigger for Stage 2 is a significant increase in credit risk, judged on relative change in lifetime PD since origination, not an absolute level. There's a 30-days-past-due backstop presumption and a low credit risk exemption.
- Stage 3 is default, aligned in most banks to the 90-day past due and unlikely-to-pay definitions. Interest revenue then accrues on the carrying amount net of the provision, which is the effective-interest change people forget.
- Practical machinery: you need lifetime PD curves, LGD, EAD profiles, discounting at the effective interest rate, and macro scenario weights. Then a management overlay, because in 2020 every model built on pre-pandemic data produced numbers nobody believed.
- The criticism to volunteer: the Stage 2 cliff makes provisions lumpy and procyclical, and the scenario weights are a judgement that moves the P&L by a lot. Two banks with identical books can report materially different provisions, which is exactly what IFRS 9 was supposed to reduce.
Where candidates lose it
Getting the stages right and missing the twelve-month versus lifetime switch, which is the whole economic content. Also don't call Stage 2 'past due'. It's a relative deterioration in credit risk; 30 days past due is only a backstop.
Expect next
- Why is the Stage 2 transition criticised?
- How do you set macro scenario weights?
- How does this differ from Basel expected loss?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

