Risk Management interview preparation
Market, credit and operational risk, plus model validation, regulatory capital, liquidity and ALM, the statistical foundations and the Indian regulatory syllabus. Every question is either traced to a named firm from a public candidate report, or tagged at desk level when we could not trace it — and answers lead with the point, then the mechanism, then the limitation.
100 questions, mapped to the firms that asked them
- Questions
- 100
- Traced to a firm
- 37
- Firms
- 12
- Updated
- September 2026
014Desk A has $10 million of VaR and Desk B has $10 million of VaR. What is the firm's VaR, and which desk is using more of the limit?Bank market riskBuy-side risk
Say this
Anywhere from zero to $20m, depending on correlation. If they're perfectly correlated it's $20m, if perfectly offsetting it's zero, and if independent it's about $14.1m. And neither desk is necessarily using half the limit, which is the real point of the question.
Then walk it
- Under normality, combined VaR is the square root of the sum of squares plus twice the covariance term. Two $10m desks at zero correlation gives $10m times root two, so $14.1m. At 0.5 correlation it's about $17.3m.
- That gap between $20m and $14.1m is the diversification benefit, and allocating it is the political heart of a risk manager's job.
- Component VaR is how you split it. You compute each desk's contribution so the components sum exactly to firm VaR. It's marginal VaR times position size, and it's the number you use for limits and for risk-adjusted performance.
- Marginal VaR is the derivative: how much firm VaR changes for a small increase in that desk. Incremental VaR is the discrete version, firm VaR with the desk minus firm VaR without it.
- Here's the counterintuitive part that makes it a good interview question. A desk hedging the rest of the firm can have positive standalone VaR and negative component VaR. It genuinely reduces firm risk, and a naive standalone limit framework would penalise it.
- So the answer to 'which desk uses more limit' is: whichever has the higher component VaR, and you cannot tell from the standalone numbers. You need the covariance with everything else.
Where candidates lose it
Answering $20m, or answering $14.1m as though independence were given. The interviewer wants the range and the word correlation, then the distinction between standalone and component VaR. The hedging-desk case, where component VaR is negative, is the answer that gets remembered.
Expect next
- Can a desk have negative component VaR?
- How would you allocate the diversification benefit between the two desks?
- Does this decomposition still work for expected shortfall?
019Your model says that was a one-in-ten-thousand-year event, and it has now happened twice this decade. What is wrong?Model validationBank market risk
Say this
The model is wrong, not the world. Two ten-thousand-year events in ten years is overwhelming evidence against the distribution, and the usual culprit is a normal assumption applied to a market that isn't normal.
Then walk it
- First, the arithmetic. Under the model, the probability of two such events in a decade is vanishingly small. Bayes says you should abandon the model long before you conclude you got unlucky twice.
- Most likely cause one, the wrong distribution. Normal tails decay far faster than real financial tails. A move that is 6 sigma under a normal is roughly a 1-in-500-million-day event; under a t distribution with four degrees of freedom it's something you see every few years.
- Cause two, non-stationarity. The model was calibrated on a regime that no longer applies. Volatility clusters and regimes shift, so an unconditional distribution fitted over twenty years will call a high-volatility regime impossible.
- Cause three, a dependence assumption. Individually plausible moves become impossible jointly if you've assumed low correlation. In a crisis correlations go to one and the joint event is far more likely than the model thinks.
- Cause four, the mundane one that is often the real answer: the event was outside the model's domain entirely. A sovereign default, a currency peg breaking, a negative oil price. The factor wasn't allowed to do that, so the model assigned it probability zero rather than a small number.
- And the professional answer to 'what do you do': stop quoting return periods you can't support. Report the scenario and the loss, drop the implied probability, and say the model is uninformative beyond the range where you have data.
Where candidates lose it
Defending the model by saying markets got unusual. That's the answer a regulator hears from a bank that is about to fail. The point of the question is whether you will update your beliefs against a model you built, and the credible answer names fat tails, regime change and the correlation assumption specifically.
Expect next
- How would you re-estimate the tail with so little data?
- Would extreme value theory help here?
- How would you communicate this to a board that has been shown the old number for three years?
037You just traded a five-year interest rate swap at par. What is your counterparty exposure today and over the life of the trade?Bank credit riskDerivatives risk
Say this
Today it's zero, because at par the swap has no value to either side. Over its life the expected exposure rises, peaks somewhere around a third of the way in, and then falls to zero at maturity. That humped shape is the thing to be able to draw.
Then walk it
- Two forces set the shape. Diffusion: the longer you wait, the further rates can have wandered, so potential exposure grows with roughly the square root of time. Amortisation: as the swap ages, fewer cash flows remain, so a given rate move is worth less.
- Diffusion dominates early and amortisation dominates late, so the profile humps. For a vanilla five-year swap the peak sits around year one and a half to two.
- Rough magnitude: the exposure is roughly the DV01 of the remaining swap times a stressed rate move. At year two, three years remain, DV01 on a 100 crore notional is about 2.8 lakh per basis point, and a 95th percentile two-year rate move of maybe 150 basis points gives potential future exposure of roughly 4 crore, so about 4 percent of notional.
- Contrast it with a cross-currency swap, where notional is exchanged at maturity, so exposure keeps growing to the end and peaks at maturity. Same product family, completely different profile, and that's the follow-up they'll ask.
- The measures to name: current exposure is today's positive mark-to-market. Expected positive exposure is the average of positive exposures over time. Potential future exposure is a high quantile, typically 95 or 99 percent, and effective EPE is the regulatory input to the capital calculation.
- What changes the shape in practice: a CSA with daily margin collapses the profile to a few days of margin period of risk, so you're left with gap risk rather than five-year diffusion. Netting against offsetting trades with the same counterparty cuts it further.
- And the caveat: all of this is a model output. The distribution of rates you assume, and the margin period of risk you assume in a stressed close-out, move the number by multiples.
Where candidates lose it
Saying the exposure is zero because the swap is at par. That's only true today. The question is testing whether you understand exposure as a profile through time, and whether you can name why a cross-currency swap humps differently. Draw the shape if there's a whiteboard.
Expect next
- Now draw it for a cross-currency swap.
- How does a daily-margined CSA change the profile?
- What is the margin period of risk and what would you assume for it?
072A fraud test is 99 percent accurate and fraud occurs in one transaction in ten thousand. The test flags a transaction. What is the chance it's really fraud?Operational riskModel validation
Say this
About one percent. Out of a million transactions, 100 are fraud and the test catches 99 of them, but it also falsely flags one percent of the 999,900 clean ones, which is about 9,999. So 99 true positives against roughly 10,000 flags means a 1 percent hit rate.
Then walk it
- Set it up with counts rather than Bayes' formula. A million transactions, 100 frauds, 999,900 clean. It's faster and you won't fumble the algebra out loud.
- True positives: 99 percent of 100, so 99. False positives: 1 percent of 999,900, so 9,999. Total flags about 10,098, of which 99 are real. That's 0.98 percent.
- The lesson is the base rate. When the event is rare, even a very accurate test produces overwhelmingly false alarms, because the clean population is so much larger. This is the base rate fallacy and it's the entire point of the question.
- This is not a puzzle, it's the daily reality of transaction monitoring and sanctions screening. Real AML alert systems run false positive rates above 95 percent, which is why banks employ thousands of people to clear alerts, and it's a genuine operational risk and cost problem.
- So the design conclusion: for rare events, headline accuracy is the wrong metric. You care about precision and recall, and about the cost asymmetry between a missed fraud and an investigated false alarm. Then you tune the threshold to that cost, not to accuracy.
- How you improve it in practice: raise the prior before you apply the test by segmenting on risk, so you're testing a population with a much higher base rate. Or stack models so an expensive accurate check only runs on things a cheap screen flagged. Both raise precision far more than improving the test itself would.
- And the number worth remembering as a reasonableness check: with a 1-in-10,000 base rate you need a false positive rate around 1 in 10,000 to get to a 50 percent hit rate. That is a far harder test than 99 percent accurate.
Where candidates lose it
Answering 99 percent. That's the reflex answer and it's what the question is designed to catch. Use counts on a million, and then draw the operational conclusion about alert volumes, because in a risk interview the business implication is worth as much as the arithmetic.
Expect next
- What accuracy would you need for a 50 percent hit rate?
- How would you reduce false positives in practice?
- How do you set the threshold if a missed fraud costs 500 times an investigation?
079Estimate next year's credit cost for a mid-sized Indian bank's unsecured personal loan book.Indian bank risk and treasuryBank credit risk
Say this
I'd build it bottom-up from vintage delinquency. For a mid-sized Indian unsecured book, I'd expect credit cost somewhere in the 3 to 5 percent range of the book, and I'd build to that number rather than assert it, then say which assumption moves it most.
Then walk it
- Structure: credit cost equals flow rate into default times loss given default, applied to the average book, plus the change in provision stock on existing stages. Keep it as a flow, because a stock-based estimate hides the growth effect.
- Size the book and its mix. Say 20,000 crore of unsecured personal loans, average ticket 3 lakh, tenor three to four years, so roughly a third of the book amortises each year and new origination is a large share. A fast-growing book has a young average vintage, which understates delinquency until it seasons.
- Flow rate: start from observed 30-plus delinquency and apply roll rates. If 30-plus is 4 percent and roughly 60 to 70 percent of 30-plus rolls to 90-plus over the following quarters, forward flow into NPA is roughly 2.5 to 3 percent annualised. Bureau data and RBI's Financial Stability Report give you a system benchmark to sanity-check against.
- LGD: unsecured, so recovery is low. Collections and settlements might recover 15 to 25 percent over two years, so LGD of 75 to 85 percent. Multiply: 3 percent flow times 80 percent LGD gives roughly 2.4 percent, then add the provision build on the growing performing book and you get to 3 to 4 percent.
- Then the adjustments that actually decide the answer. Seasoning: if origination grew 40 percent last year, next year's delinquency is set by that cohort, and personal loan defaults peak 12 to 24 months after disbursal. Vintage curves, not current delinquency, are the honest input.
- Macro and policy overlay: RBI raised risk weights on unsecured consumer credit to 125 percent in late 2023 specifically because growth was running far ahead of secured lending. That slows origination and tightens underwriting, which improves next year's cohort and worsens the growth denominator.
- Segment sensitivity: new-to-credit borrowers, fintech-sourced and app-based loans, and small-ticket loans run multiples of the delinquency of salaried, bureau-scored, existing-customer lending. A weighted average across a book with a rising fintech share drifts upward even if each segment is stable.
- So I'd give the range, name my two swing assumptions, roll rate and the fintech-sourced share, and say what I'd need to tighten it: vintage curves by origination channel and the bureau's segment-level delinquency trend.
Where candidates lose it
Producing a single confident number. The interviewer wants a structure, two or three named assumptions and a range, plus awareness that a fast-growing unsecured book looks artificially clean because the loans haven't seasoned. Vintage analysis is the concept that has to appear.
Expect next
- Why does a fast-growing book look clean?
- What did RBI's risk weight increase actually change?
- How would you split this by origination channel?
Firm tags come from public, anonymous candidate reports on Wall Street Oasis: strong signal, not sworn testimony. Firms are named as the places a question was reported, not as partners of Fin Maverick. Answers are written for this page to show how to think out loud; they are not scripts to recite.

