Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
025Explain PD, LGD and EAD.Bank credit riskRating agencies
Say this
They're the three inputs to expected loss. Probability of default is how likely the borrower stops paying, loss given default is the fraction you don't recover, and exposure at default is how much is outstanding when it happens. Multiply the three and you have expected loss.
Then walk it
- PD is a probability over a horizon, usually one year, and it comes from a rating or a scorecard. Say the horizon, because a one-year PD and a lifetime PD are very different numbers.
- LGD is one minus the recovery rate, expressed on the exposure. It's driven by collateral, seniority and how good the legal enforcement regime is. Senior secured on a warehouse in a good jurisdiction might be 25 percent; unsecured sub debt is 70 to 90.
- EAD is what's actually outstanding at default. For a term loan it's roughly the drawn balance. For a revolver or a credit card it's the drawn amount plus a credit conversion factor on the undrawn part, because stressed borrowers draw their lines down before they default.
- Worked number: a 100 crore facility, PD of 2 percent, LGD of 40 percent gives expected loss of 0.8 crore, so 80 basis points. That's a provisioning and pricing number, not a capital number.
- The three are not independent, and that's the bit people miss. In a recession PD rises and recoveries fall at the same time, because collateral values are down and everyone is selling. That's downturn LGD, and Basel requires you to use it rather than a long-run average.
- For a derivative there's no drawn balance, so EAD has to be modelled from potential future exposure. That's a different exercise entirely, and it's why counterparty credit risk has its own framework.
Where candidates lose it
Getting the definitions right and missing that PD and LGD are correlated. Using an average recovery rate through a downturn understates loss badly, and downturn LGD is a specific Basel requirement. Also state the PD horizon; a PD without a horizon is not a number.
Expect next
- Why does Basel require downturn LGD?
- How do you estimate EAD on a revolver?
- How would you estimate PD for a borrower with no rating?
026What's the difference between expected and unexpected loss, and which one does capital cover?Bank credit riskRegulatory reporting
Say this
Expected loss is the average you lose in a normal year, and it's covered by provisions and priced into the loan spread. Unexpected loss is the deviation above that in a bad year, and that's what capital is for. Provisions cover the mean, capital covers the tail.
Then walk it
- Expected loss is PD times LGD times EAD. It's a cost of doing business, so it belongs in the price. If your spread doesn't cover EL plus funding plus operating cost plus a return on capital, you're lending at a loss.
- Unexpected loss is the distance from the mean to a high quantile of the loss distribution, usually 99.9 percent over one year in Basel's IRB framework. That's the one-in-a-thousand-year bad year the bank is supposed to survive.
- The distribution is heavily right-skewed, not normal, because defaults are correlated. Most years you lose a little, occasionally you lose a lot, and the asymmetry is driven entirely by that correlation.
- The mechanism is the asset correlation assumption. If defaults were independent, a large portfolio would have almost no unexpected loss and you'd need almost no capital. Basel's IRB formula bakes in correlations of roughly 12 to 24 percent for corporates, and it's that number, not PD, that creates the capital requirement.
- Numerical feel: a portfolio with 80 basis points of expected loss might carry a 99.9 percent loss of 5 or 6 percent. So capital is several times provisions, and that ratio widens for a concentrated book.
- The gap that matters in practice: IFRS 9 provisions and Basel expected loss are computed differently, so the two rarely agree, and the shortfall or excess adjusts CET1. That reconciliation is a real job in a bank's finance and risk function.
Where candidates lose it
Saying capital covers expected loss. It doesn't, provisions do, and mixing those up is a hard fail in a credit risk interview. The answer that stands out names asset correlation as the thing generating unexpected loss, because a candidate who says that understands why a diversified book still needs capital.
Expect next
- Why is the loss distribution skewed?
- What drives the size of unexpected loss more, PD or correlation?
- How does the IFRS 9 provision interact with regulatory capital?
027How would you approach building a delinquency model?Neuberger BermanRisk · Chicago · 2024
Say this
Define the target first, then build backwards. Delinquency is not default, so I'd fix the bad definition, say 90 days past due within twelve months, set an observation and performance window, and only then worry about features and model form.
Then walk it
- Target definition is the decision that determines everything else. 30, 60 or 90 days past due, and over what horizon. Roll-rate analysis tells you where delinquency becomes effectively irreversible, and that's where you draw the line.
- Sampling: pick an observation point, take the borrower's state as at that date, then observe outcomes over the following twelve months. Strict separation, or you leak future information into features and get a model that looks brilliant in development and fails in production.
- Features in three families. Behavioural: utilisation trend, minimum-payment behaviour, recent missed payments, bounced mandates. Bureau: enquiry velocity, existing delinquency elsewhere, thin-file flags. Loan and demographic: loan-to-value, instalment-to-income, vintage, product, channel of origination.
- Model form: start with logistic regression on coarse-classified, weight-of-evidence binned variables. It's monotonic, explainable and passes validation. Then run a gradient boosting challenger to see how much signal the simple model leaves on the table. If the gap is small, ship the simple one.
- Validation: out-of-time as well as out-of-sample, because credit models degrade through the cycle not through the sample. Report Gini or AUC for ranking, and a calibration curve for whether the predicted rates match observed. A model can rank perfectly and be badly calibrated.
- Two traps specific to credit. Survivorship and selection bias: you only observe outcomes for people you approved, so the model is blind to the rejected population, and you need reject inference. And macro sensitivity: a model built on 2021 data has never seen a rate cycle, so the absolute PD level will be wrong even if the ranking holds.
- Then monitoring. Population stability index on the score distribution, drift on each feature, and a monthly actual-versus-expected. Most delinquency models fail from population shift rather than bad maths.
Where candidates lose it
Going straight to algorithms. In credit, the target definition, the observation window and the reject-inference problem are worth more than model choice, and interviewers who build these for a living are listening for exactly those. Also say the word calibration; ranking power alone doesn't let you price or provision.
Expect next
- How would you handle reject inference?
- How would you know the model had degraded?
- Would you use gradient boosting in production for this?
Reported by candidates at Neuberger Berman (Risk, Chicago, 2024). Source: Wall Street Oasis.
028How do you build a credit scorecard, and how do you prove it works?Bank credit riskGlobal capability centres
Say this
Bin every variable, convert to weight of evidence, fit a logistic regression, then scale the log odds into points. You prove it works on three axes: discrimination, calibration and stability, tested out of time, not just out of sample.
Then walk it
- Coarse classification first. Bin each variable so the bad rate is monotonic across bins and each bin has enough volume, usually at least 5 percent of the population. Then replace the bin with its weight of evidence, the log of the good-to-bad odds ratio.
- Information value tells you which variables to keep. Below about 0.02 is useless, 0.1 to 0.3 is useful, above 0.5 and I'd check for leakage rather than celebrate.
- Fit logistic regression on the WOE variables, then scale: points equal offset plus factor times log odds, calibrated so a chosen score doubles the odds every 20 points. That scaling is cosmetic but it's how credit officers read the output.
- Discrimination: Gini, or equivalently AUC, where Gini equals two times AUC minus one. A retail behavioural scorecard should hit 0.55 to 0.70 Gini; an application scorecard on a thin-file population might only get 0.35, and that can still be commercially valuable. Kolmogorov-Smirnov is the other standard, the maximum gap between the cumulative good and bad distributions.
- Calibration: plot predicted against observed bad rate by score band, and run a Hosmer-Lemeshow style test. Discrimination decides who you approve; calibration decides what you charge and what you provision. You need both.
- Stability: population stability index between development and current, per variable and on the score. Above 0.25 and the population has shifted enough that the model needs rebuilding, not just recalibration.
- And the governance point: build on a development sample, validate on a holdout, then validate again on a later time period the model never saw. An out-of-sample test on a random split proves almost nothing for a credit model, because the whole failure mode is time.
Where candidates lose it
Quoting a Gini target as if it were universal. A good Gini depends entirely on the population and the product, and someone who has built these knows that. The other failure is testing only discrimination. A model with 0.7 Gini and broken calibration will approve the right people and price them all wrong.
Expect next
- What Gini would you expect on a prime mortgage book?
- The Gini is stable but the bad rate has doubled. What happened?
- When do you recalibrate versus rebuild?
029What is the difference between a point-in-time and a through-the-cycle rating, and when does it matter?Bank credit riskRating agencies
Say this
A point-in-time PD reflects the borrower's risk right now, including where we are in the cycle. A through-the-cycle rating strips the cycle out and asks how the borrower would do on average across one. PIT moves a lot, TTC barely moves.
Then walk it
- Agency ratings are broadly through-the-cycle by design. That's why an investment grade issuer doesn't get downgraded every recession, and why agencies talk about rating through a trough.
- IFRS 9 needs point-in-time, because expected credit loss is supposed to be a current, forward-looking estimate conditioned on today's macro forecast.
- Basel IRB regulatory capital leans through-the-cycle, deliberately, to stop capital requirements swinging with the cycle. If PDs were fully PIT, RWAs would balloon in a recession precisely when banks can't raise capital.
- That's the procyclicality argument and it's the real content of this question. A PIT capital regime amplifies the cycle: losses rise, RWAs rise, capital ratios fall twice over, lending contracts, the recession deepens.
- The practical consequence is that a bank runs two PD scales and a mapping between them, and the conversion is genuinely hard. You need a macro model to shift a TTC PD to a PIT PD for a given scenario.
- The honest caveat: no real rating system is purely one or the other. Agency ratings do migrate in downturns, and IRB models do have cyclical components. It's a spectrum, and the useful question about any model is how much of the cycle it passes through.
Where candidates lose it
Defining both and not explaining why anyone cares. The payoff is procyclicality: why regulators want TTC for capital and accountants want PIT for provisions, and why the same borrower carries two different PDs in the same bank on the same day.
Expect next
- Which does IFRS 9 need, and why?
- How would you convert a TTC PD to a PIT PD?
- Is procyclicality a real problem or a theoretical one?
030Explain IFRS 9 expected credit loss staging.Bank credit riskRegulatory reporting
Say this
Three stages. Stage 1 is performing, and you provide twelve-month expected loss. Stage 2 is a significant increase in credit risk since origination, and you jump to lifetime expected loss. Stage 3 is credit impaired, lifetime loss with interest recognised on the net carrying amount.
Then walk it
- The whole model is forward-looking and unbiased, probability-weighted across at least a couple of macro scenarios. That's the break from the old incurred-loss model, which waited for evidence of impairment before providing.
- The cliff is the interesting bit. Moving from Stage 1 to Stage 2 changes the horizon from twelve months to lifetime, so on a twenty-year mortgage the provision can jump by a multiple overnight without a single missed payment.
- The trigger for Stage 2 is a significant increase in credit risk, judged on relative change in lifetime PD since origination, not an absolute level. There's a 30-days-past-due backstop presumption and a low credit risk exemption.
- Stage 3 is default, aligned in most banks to the 90-day past due and unlikely-to-pay definitions. Interest revenue then accrues on the carrying amount net of the provision, which is the effective-interest change people forget.
- Practical machinery: you need lifetime PD curves, LGD, EAD profiles, discounting at the effective interest rate, and macro scenario weights. Then a management overlay, because in 2020 every model built on pre-pandemic data produced numbers nobody believed.
- The criticism to volunteer: the Stage 2 cliff makes provisions lumpy and procyclical, and the scenario weights are a judgement that moves the P&L by a lot. Two banks with identical books can report materially different provisions, which is exactly what IFRS 9 was supposed to reduce.
Where candidates lose it
Getting the stages right and missing the twelve-month versus lifetime switch, which is the whole economic content. Also don't call Stage 2 'past due'. It's a relative deterioration in credit risk; 30 days past due is only a backstop.
Expect next
- Why is the Stage 2 transition criticised?
- How do you set macro scenario weights?
- How does this differ from Basel expected loss?
031How does IFRS 9 expected credit loss differ from Basel regulatory expected loss?Bank credit riskRegulatory reporting
Say this
Different purposes, so different parameters. IFRS 9 is accounting: point-in-time, forward-looking, neutral, and lifetime for Stage 2 and 3. Basel is prudential: through-the-cycle PD, downturn LGD, twelve-month horizon, and deliberately conservative.
Then walk it
- Horizon. Basel EL is always twelve months. IFRS 9 is twelve months in Stage 1 and lifetime in Stages 2 and 3.
- PD. Basel wants a long-run average, through-the-cycle PD. IFRS 9 wants a point-in-time PD conditioned on a macro forecast.
- LGD. Basel requires downturn LGD, a stressed recovery assumption. IFRS 9 wants a neutral, expected LGD with no prudential margin.
- Discounting. IFRS 9 discounts cash shortfalls at the effective interest rate. Basel EL is undiscounted.
- Then the reconciliation, which is where real work happens. For IRB banks, if accounting provisions exceed Basel EL, the excess counts in Tier 2 up to a cap of 0.6 percent of credit RWA. If provisions fall short, the shortfall is deducted straight from CET1. So the two frameworks meet in the capital ratio.
- For standardised-approach banks it's different again: general provisions can count in Tier 2 up to 1.25 percent of credit RWA, and specific provisions reduce the exposure value.
- And the transitional arrangements matter historically. When IFRS 9 came in, supervisors allowed a phase-in of the day-one CET1 hit precisely because the provision increase was large enough to be destabilising.
Where candidates lose it
Treating them as the same number with different labels. Naming the four parameter differences is table stakes; the answer that lands explains the CET1 shortfall deduction and the Tier 2 excess cap, because that's the bit that actually affects a bank's capital ratio.
Expect next
- What happens to CET1 if provisions are below Basel EL?
- Why is Basel LGD downturn and IFRS 9 LGD neutral?
- Which framework produced a bigger provision in 2020?
032What is structured finance, how would you evaluate it, and what are the credit risks?Moody'sCredit Risk · New York · 2024
Say this
Structured finance is taking a pool of cash-flow-generating assets, putting it in a bankruptcy-remote vehicle, and slicing the cash flows into tranches of different seniority. You evaluate it in three layers: the collateral, the structure, and the parties.
Then walk it
- Layer one, the collateral. Pool composition, weighted average life, seasoning, geographic and obligor concentration, historical default and prepayment behaviour, and how the underwriting was done. Everything downstream depends on this, and it's where the 2007 failure actually was.
- Layer two, the structure. Where does the cash go, and in what order. Credit enhancement comes from subordination, excess spread, overcollateralisation and reserve accounts. Then the triggers: performance triggers that turn a pro-rata waterfall sequential, and cash-trapping mechanics.
- Layer three, the parties. Originator, servicer, trustee, swap counterparty. Servicer quality drives recoveries, and servicer failure has broken deals whose collateral was fine. Then the legal question: is the true sale robust, and is the SPV actually bankruptcy remote?
- How I'd analyse it: model the pool, run default and prepayment scenarios, and see at what cumulative loss each tranche takes its first rupee of loss. That break-even loss compared with the expected loss is the real measure of a tranche's safety.
- The credit risks specific to tranching. Correlation risk: a senior tranche is a bet on correlation, not just on average defaults, because it only fails if losses cluster. Cliff risk: a mezzanine tranche goes from untouched to wiped out over a narrow loss range, so it's far more convex than its rating suggests.
- Then prepayment and extension risk on the timing, basis risk if the assets and liabilities reprice off different benchmarks, and originator alignment. Skin in the game is why post-crisis rules require the sponsor to retain a slice.
- The Indian version worth naming: pass-through certificates and direct assignments on NBFC loan pools, where the live risks are servicer concentration, priority-sector motivation on the buyer side, and the 2018 to 2019 NBFC liquidity episode showing how quickly refinancing assumptions fail.
- And the honest limitation: the rating of a structured tranche is far more model-dependent than a corporate rating. Small changes in a correlation assumption move a AAA to a BBB, and that is exactly what happened to CDOs.
Where candidates lose it
Explaining tranching and stopping. The two things a credit risk interviewer at a rating agency wants are the sensitivity of senior tranches to correlation rather than to average default rates, and the cliff-risk convexity of mezzanine. Naming the servicer and the true-sale question shows you've read a deal document, not a textbook.
Expect next
- Why is a senior tranche a bet on correlation?
- What actually went wrong with CDO ratings in 2007?
- How would you analyse an Indian NBFC pass-through certificate?
Reported by candidates at Moody's (Credit Risk, New York, 2024). Source: Wall Street Oasis.
033Your loan book has 22 percent of exposure in commercial real estate. How do you think about that?Bank credit riskIndian bank risk and treasury
Say this
Concentration is the risk that diversification math ignores, and 22 percent in one cyclical sector is a real number. I'd measure it, work out how much of a tail loss it drives, then decide between limits, hedging and pricing rather than just flagging it.
Then walk it
- Measure it properly first. Sector share is the headline, but the useful metrics are a Herfindahl index on single names, the top-20 exposure as a share of CET1, and the correlated cluster, because CRE developers, construction firms and building materials all fail together.
- Then quantify the capital impact. The IRB formula assumes an infinitely granular, single-factor portfolio, so it systematically understates concentrated books. A granularity adjustment or a multi-factor economic capital model is how you show the board the real number, and this is a classic Pillar 2 add-on.
- Stress it specifically. Property values down 30 percent, vacancy up, refinancing unavailable at maturity. CRE defaults are refinancing events far more than they are cash-flow events, so the maturity profile matters more than current interest coverage.
- Look at what's inside the 22 percent. Office in one city is a different animal from warehousing and retail across ten. Loan-to-value distribution, debt-service coverage, single-tenant concentration, and how much matures in the next 18 months.
- Then the actions, in order of cost. Tighten new-origination limits by sub-sector, price the concentration into new deals, syndicate or sell down the largest names, and buy protection or securitise if a market exists. In India that last option is thin, so limits do most of the work.
- And the governance line: 22 percent may be entirely within appetite if the board decided that deliberately and is paid for it. Concentration isn't automatically a fault. What is a fault is concentration that accumulated without anyone setting a limit.
Where candidates lose it
Saying 'that's too high' without a benchmark or a measurement. And forgetting that the IRB capital formula assumes a granular portfolio, so regulatory capital alone will not show the concentration. That granularity point is what a credit risk interviewer is waiting for.
Expect next
- How would you measure concentration in a single number?
- Why doesn't the IRB formula capture it?
- What limit would you set, and on what basis?
034Describe what distressed debt is.Oaktree Capital ManagementRisk · Los Angeles · 2022
Say this
Debt of a company in or near financial distress, trading at a deep discount, usually quoted in cents on the dollar rather than on a yield. The convention is a spread over 1,000 basis points or a price under 70, and the analysis shifts from yield to recovery.
Then walk it
- The mental switch is the key point. For performing credit you underwrite the probability of getting paid the coupon. For distressed you underwrite what the asset is worth in a restructuring and where in the capital structure you sit when it's divided up.
- So the work is a valuation exercise plus a legal one. Build an enterprise value under a restructured plan, then walk the waterfall: secured, then unsecured, then sub debt, then equity. The fulcrum security is the one where value runs out, and owning it is how you end up controlling the reorganised equity.
- Two strategies, and they're different businesses. Passive: buy mispriced paper and wait. Active or loan-to-own: buy the fulcrum, lead the creditor committee, negotiate the plan, convert to equity.
- Risk factors specific to it: process risk, because the outcome depends on a court and on other creditors, not just on the business. Duration risk, because restructurings take years. Illiquidity. And documentation risk, since covenant and intercreditor terms often matter more than the financials.
- From a risk-management seat in a distressed fund, the hard problems are valuation of assets with no observable price, position concentration, the fact that VaR is meaningless on paper that doesn't trade, and side-pocket or gate mechanics if investors want out.
- The Indian dimension is worth a line: the Insolvency and Bankruptcy Code created a real distressed market after 2016, with ARCs and stressed-asset funds buying from banks. Average haircuts through the IBC have been steep and resolution timelines have run well past the statutory 330 days, which is exactly the process risk you're underwriting.
Where candidates lose it
Defining it by price alone and never mentioning the fulcrum security or the capital structure waterfall. Distressed investing is a legal and structural discipline as much as a financial one, and a candidate who can't say what a fulcrum security is has read a definition, not a deal.
Expect next
- What is the fulcrum security and why do you want it?
- How would you value a company in bankruptcy?
- How would you risk-manage a portfolio of illiquid distressed positions?
Reported by candidates at Oaktree Capital Management (Risk, Los Angeles, 2022). Source: Wall Street Oasis.
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

