Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
027How would you approach building a delinquency model?Neuberger BermanRisk · Chicago · 2024
Say this
Define the target first, then build backwards. Delinquency is not default, so I'd fix the bad definition, say 90 days past due within twelve months, set an observation and performance window, and only then worry about features and model form.
Then walk it
- Target definition is the decision that determines everything else. 30, 60 or 90 days past due, and over what horizon. Roll-rate analysis tells you where delinquency becomes effectively irreversible, and that's where you draw the line.
- Sampling: pick an observation point, take the borrower's state as at that date, then observe outcomes over the following twelve months. Strict separation, or you leak future information into features and get a model that looks brilliant in development and fails in production.
- Features in three families. Behavioural: utilisation trend, minimum-payment behaviour, recent missed payments, bounced mandates. Bureau: enquiry velocity, existing delinquency elsewhere, thin-file flags. Loan and demographic: loan-to-value, instalment-to-income, vintage, product, channel of origination.
- Model form: start with logistic regression on coarse-classified, weight-of-evidence binned variables. It's monotonic, explainable and passes validation. Then run a gradient boosting challenger to see how much signal the simple model leaves on the table. If the gap is small, ship the simple one.
- Validation: out-of-time as well as out-of-sample, because credit models degrade through the cycle not through the sample. Report Gini or AUC for ranking, and a calibration curve for whether the predicted rates match observed. A model can rank perfectly and be badly calibrated.
- Two traps specific to credit. Survivorship and selection bias: you only observe outcomes for people you approved, so the model is blind to the rejected population, and you need reject inference. And macro sensitivity: a model built on 2021 data has never seen a rate cycle, so the absolute PD level will be wrong even if the ranking holds.
- Then monitoring. Population stability index on the score distribution, drift on each feature, and a monthly actual-versus-expected. Most delinquency models fail from population shift rather than bad maths.
Where candidates lose it
Going straight to algorithms. In credit, the target definition, the observation window and the reject-inference problem are worth more than model choice, and interviewers who build these for a living are listening for exactly those. Also say the word calibration; ranking power alone doesn't let you price or provision.
Expect next
- How would you handle reject inference?
- How would you know the model had degraded?
- Would you use gradient boosting in production for this?
Reported by candidates at Neuberger Berman (Risk, Chicago, 2024). Source: Wall Street Oasis.
028How do you build a credit scorecard, and how do you prove it works?Bank credit riskGlobal capability centres
Say this
Bin every variable, convert to weight of evidence, fit a logistic regression, then scale the log odds into points. You prove it works on three axes: discrimination, calibration and stability, tested out of time, not just out of sample.
Then walk it
- Coarse classification first. Bin each variable so the bad rate is monotonic across bins and each bin has enough volume, usually at least 5 percent of the population. Then replace the bin with its weight of evidence, the log of the good-to-bad odds ratio.
- Information value tells you which variables to keep. Below about 0.02 is useless, 0.1 to 0.3 is useful, above 0.5 and I'd check for leakage rather than celebrate.
- Fit logistic regression on the WOE variables, then scale: points equal offset plus factor times log odds, calibrated so a chosen score doubles the odds every 20 points. That scaling is cosmetic but it's how credit officers read the output.
- Discrimination: Gini, or equivalently AUC, where Gini equals two times AUC minus one. A retail behavioural scorecard should hit 0.55 to 0.70 Gini; an application scorecard on a thin-file population might only get 0.35, and that can still be commercially valuable. Kolmogorov-Smirnov is the other standard, the maximum gap between the cumulative good and bad distributions.
- Calibration: plot predicted against observed bad rate by score band, and run a Hosmer-Lemeshow style test. Discrimination decides who you approve; calibration decides what you charge and what you provision. You need both.
- Stability: population stability index between development and current, per variable and on the score. Above 0.25 and the population has shifted enough that the model needs rebuilding, not just recalibration.
- And the governance point: build on a development sample, validate on a holdout, then validate again on a later time period the model never saw. An out-of-sample test on a random split proves almost nothing for a credit model, because the whole failure mode is time.
Where candidates lose it
Quoting a Gini target as if it were universal. A good Gini depends entirely on the population and the product, and someone who has built these knows that. The other failure is testing only discrimination. A model with 0.7 Gini and broken calibration will approve the right people and price them all wrong.
Expect next
- What Gini would you expect on a prime mortgage book?
- The Gini is stable but the bad rate has doubled. What happened?
- When do you recalibrate versus rebuild?
032What is structured finance, how would you evaluate it, and what are the credit risks?Moody'sCredit Risk · New York · 2024
Say this
Structured finance is taking a pool of cash-flow-generating assets, putting it in a bankruptcy-remote vehicle, and slicing the cash flows into tranches of different seniority. You evaluate it in three layers: the collateral, the structure, and the parties.
Then walk it
- Layer one, the collateral. Pool composition, weighted average life, seasoning, geographic and obligor concentration, historical default and prepayment behaviour, and how the underwriting was done. Everything downstream depends on this, and it's where the 2007 failure actually was.
- Layer two, the structure. Where does the cash go, and in what order. Credit enhancement comes from subordination, excess spread, overcollateralisation and reserve accounts. Then the triggers: performance triggers that turn a pro-rata waterfall sequential, and cash-trapping mechanics.
- Layer three, the parties. Originator, servicer, trustee, swap counterparty. Servicer quality drives recoveries, and servicer failure has broken deals whose collateral was fine. Then the legal question: is the true sale robust, and is the SPV actually bankruptcy remote?
- How I'd analyse it: model the pool, run default and prepayment scenarios, and see at what cumulative loss each tranche takes its first rupee of loss. That break-even loss compared with the expected loss is the real measure of a tranche's safety.
- The credit risks specific to tranching. Correlation risk: a senior tranche is a bet on correlation, not just on average defaults, because it only fails if losses cluster. Cliff risk: a mezzanine tranche goes from untouched to wiped out over a narrow loss range, so it's far more convex than its rating suggests.
- Then prepayment and extension risk on the timing, basis risk if the assets and liabilities reprice off different benchmarks, and originator alignment. Skin in the game is why post-crisis rules require the sponsor to retain a slice.
- The Indian version worth naming: pass-through certificates and direct assignments on NBFC loan pools, where the live risks are servicer concentration, priority-sector motivation on the buyer side, and the 2018 to 2019 NBFC liquidity episode showing how quickly refinancing assumptions fail.
- And the honest limitation: the rating of a structured tranche is far more model-dependent than a corporate rating. Small changes in a correlation assumption move a AAA to a BBB, and that is exactly what happened to CDOs.
Where candidates lose it
Explaining tranching and stopping. The two things a credit risk interviewer at a rating agency wants are the sensitivity of senior tranches to correlation rather than to average default rates, and the cliff-risk convexity of mezzanine. Naming the servicer and the true-sale question shows you've read a deal document, not a textbook.
Expect next
- Why is a senior tranche a bet on correlation?
- What actually went wrong with CDO ratings in 2007?
- How would you analyse an Indian NBFC pass-through certificate?
Reported by candidates at Moody's (Credit Risk, New York, 2024). Source: Wall Street Oasis.
033Your loan book has 22 percent of exposure in commercial real estate. How do you think about that?Bank credit riskIndian bank risk and treasury
Say this
Concentration is the risk that diversification math ignores, and 22 percent in one cyclical sector is a real number. I'd measure it, work out how much of a tail loss it drives, then decide between limits, hedging and pricing rather than just flagging it.
Then walk it
- Measure it properly first. Sector share is the headline, but the useful metrics are a Herfindahl index on single names, the top-20 exposure as a share of CET1, and the correlated cluster, because CRE developers, construction firms and building materials all fail together.
- Then quantify the capital impact. The IRB formula assumes an infinitely granular, single-factor portfolio, so it systematically understates concentrated books. A granularity adjustment or a multi-factor economic capital model is how you show the board the real number, and this is a classic Pillar 2 add-on.
- Stress it specifically. Property values down 30 percent, vacancy up, refinancing unavailable at maturity. CRE defaults are refinancing events far more than they are cash-flow events, so the maturity profile matters more than current interest coverage.
- Look at what's inside the 22 percent. Office in one city is a different animal from warehousing and retail across ten. Loan-to-value distribution, debt-service coverage, single-tenant concentration, and how much matures in the next 18 months.
- Then the actions, in order of cost. Tighten new-origination limits by sub-sector, price the concentration into new deals, syndicate or sell down the largest names, and buy protection or securitise if a market exists. In India that last option is thin, so limits do most of the work.
- And the governance line: 22 percent may be entirely within appetite if the board decided that deliberately and is paid for it. Concentration isn't automatically a fault. What is a fault is concentration that accumulated without anyone setting a limit.
Where candidates lose it
Saying 'that's too high' without a benchmark or a measurement. And forgetting that the IRB capital formula assumes a granular portfolio, so regulatory capital alone will not show the concentration. That granularity point is what a credit risk interviewer is waiting for.
Expect next
- How would you measure concentration in a single number?
- Why doesn't the IRB formula capture it?
- What limit would you set, and on what basis?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

