Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
072A fraud test is 99 percent accurate and fraud occurs in one transaction in ten thousand. The test flags a transaction. What is the chance it's really fraud?Operational riskModel validation
Say this
About one percent. Out of a million transactions, 100 are fraud and the test catches 99 of them, but it also falsely flags one percent of the 999,900 clean ones, which is about 9,999. So 99 true positives against roughly 10,000 flags means a 1 percent hit rate.
Then walk it
- Set it up with counts rather than Bayes' formula. A million transactions, 100 frauds, 999,900 clean. It's faster and you won't fumble the algebra out loud.
- True positives: 99 percent of 100, so 99. False positives: 1 percent of 999,900, so 9,999. Total flags about 10,098, of which 99 are real. That's 0.98 percent.
- The lesson is the base rate. When the event is rare, even a very accurate test produces overwhelmingly false alarms, because the clean population is so much larger. This is the base rate fallacy and it's the entire point of the question.
- This is not a puzzle, it's the daily reality of transaction monitoring and sanctions screening. Real AML alert systems run false positive rates above 95 percent, which is why banks employ thousands of people to clear alerts, and it's a genuine operational risk and cost problem.
- So the design conclusion: for rare events, headline accuracy is the wrong metric. You care about precision and recall, and about the cost asymmetry between a missed fraud and an investigated false alarm. Then you tune the threshold to that cost, not to accuracy.
- How you improve it in practice: raise the prior before you apply the test by segmenting on risk, so you're testing a population with a much higher base rate. Or stack models so an expensive accurate check only runs on things a cheap screen flagged. Both raise precision far more than improving the test itself would.
- And the number worth remembering as a reasonableness check: with a 1-in-10,000 base rate you need a false positive rate around 1 in 10,000 to get to a 50 percent hit rate. That is a far harder test than 99 percent accurate.
Where candidates lose it
Answering 99 percent. That's the reflex answer and it's what the question is designed to catch. Use counts on a million, and then draw the operational conclusion about alert volumes, because in a risk interview the business implication is worth as much as the arithmetic.
Expect next
- What accuracy would you need for a 50 percent hit rate?
- How would you reduce false positives in practice?
- How do you set the threshold if a missed fraud costs 500 times an investigation?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

