What is risk management?
Risk management in a financial firm is the discipline of identifying the sources of loss to which the firm is exposed, measuring the magnitude of those exposures, monitoring them in real time, and taking action to control them within an explicit risk appetite. The discipline is quantitative at its core: every modern risk measure is a number produced by a model, with explicit assumptions and explicit data inputs (Jorion, 2007).
The four standard risk categories are: market risk (the risk of losses from changes in market prices equity, rates, FX, credit, commodity and from the volatility of those prices), credit risk (the risk of loss from a counterparty failing to meet its obligations, including both default and credit spread migration), operational risk (the risk of loss from internal failures people, processes, systems, external events including fraud, model error, legal liability, and business disruption), and liquidity risk (the risk of being unable to meet obligations as they come due without incurring unacceptable costs). The first three are the dominant categories in market-facing firms; the fourth is dominant in banking and asset management.
Risk management is not the same as risk avoidance. A firm that takes no risk makes no profit; the role of risk management is to ensure that the risks being taken are the risks the firm intends to take, in the magnitudes it intends to take them, and that the unintended risks (model error, operational error, concentration, counterparty exposure) are bounded. The dominant frame is the risk appetite statement, which sets the firm's tolerance for each risk category, and the limit framework, which operationalises the appetite as a set of measurable limits (VaR, expected shortfall, stress loss, P&L drawdown, factor exposure, counterparty exposure) that are monitored in real time and trigger escalation when breached (Jorion, 2007).
What is market risk?
Market risk is the risk of loss from changes in the prices of financial instruments and the parameters that drive those prices. The standard market risk measures are: sensitivity-based measures (delta, gamma, vega, theta for derivatives; PV01, DV01 for rates; FX delta, credit CS01), VaR (Value at Risk, the loss threshold at a given confidence level over a given horizon), Expected Shortfall (ES, the average loss conditional on the loss exceeding the VaR threshold), and stress-test loss (the loss under a specific extreme scenario).
VaR is the most widely reported single number in risk management. It is the loss threshold such that the probability of the loss exceeding the threshold over the holding period is (typically) 1%. The standard 1-day, 99% VaR is the headline number on most trading desks. The three dominant calculation methods are: parametric (variance-covariance, assuming returns are normal), historical simulation (using the empirical distribution of past returns), and Monte Carlo (simulating from a fitted model). Each has characteristic failure modes. Parametric VaR assumes normality and underestimates tail risk. Historical simulation is anchored to the realised window and is slow to adapt to new regimes. Monte Carlo is flexible but model-specification dependent. Expected Shortfall (also called Conditional VaR, or CVaR) addresses the principal failure of VaR (that it ignores loss severity beyond the threshold) and is a coherent risk measure (Jorion, 2007).
The post-2008 regulatory framework has substantially reshaped market risk capital. The Fundamental Review of the Trading Book (FRTB), finalised by the Basel Committee in 2016 and revised in 2019, replaced VaR with Expected Shortfall at 97.5% over ten days, added a stressed-ES requirement calibrated to a continuous 12-month period of significant financial stress, and introduced a default risk charge, a non-modellable risk factors charge, and a stress scenario component. The implementation of FRTB is the dominant market risk project in major banks between 2019 and 2025, and is the most-cited example of how a research-grade risk measure (Expected Shortfall) becomes a binding regulatory standard over the course of a decade (BCBS, 2019).
What is credit risk?
Credit risk is the risk of loss from a counterparty failing to meet its obligations, including both default (the counterparty fails to make a payment) and credit spread migration (the counterparty's credit quality deteriorates and the market value of the firm's positions falls). The dominant credit risk measures are: Probability of Default (PD), Loss Given Default (LGD), Exposure at Default (EAD), and Expected Loss (EL = PD × LGD × EAD). The dominant regulatory capital standard is the Internal Ratings-Based (IRB) approach under Basel II/III, in which the firm estimates its own PD, LGD, and EAD models, subject to regulatory approval.
Counterparty credit risk (CCR) is the credit risk on derivative positions, distinct from lending because the exposure is dynamic and bilateral. The dominant CCR measure is the Credit Valuation Adjustment (CVA), which is the difference between the value of a derivative assuming a risk-free counterparty and the value assuming the actual counterparty (with its own default probability and recovery rate). CVA is a real P&L line at every major dealer and is the subject of the Basel III CVA capital charge. The dominant academic reference on credit risk modelling is Duffie & Singleton (2003).
Modern credit risk management uses a combination of market-implied credit measures (Credit Default Swap spreads, bond spreads) and structural credit models (Merton, 1974) to produce a forward-looking, market-consistent view of credit risk. The integration of market-implied and structural credit measures is one of the dominant research areas in the field. The post-2008 increase in regulatory capital for trading book CCR particularly under the SA-CCR (Standardised Approach for Counterparty Credit Risk) and the CVA capital charge has substantially changed the economics of dealer market-making in less liquid instruments.
What is operational risk?
Operational risk is the risk of loss from internal failures people, processes, systems, and external events. The Basel Committee's operational risk framework (BCBS, 2014) defines it as the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events, including legal risk. The standard measurement approach is the Loss Distribution Approach (LDA), which combines internal loss data, external loss data (from consortiums like ORX), scenario analysis, and business environment factors to produce an operational Value at Risk and an operational capital charge.
The single largest source of operational risk in modern financial firms is model risk: the risk that a model is wrong, is used inappropriately, or is misused. The SR 11-7 supervisory guidance from the Federal Reserve (2011) is the standard reference; it requires firms to maintain an effective model risk management function with three components: development (rigorous model construction, including validation by an independent party), implementation (controls on the use of the model in production, including access control, change management, and override procedures), and outcomes analysis (ongoing monitoring of model performance against realised outcomes). The model risk management function is, in most major banks, of comparable seniority to the market risk function.
Beyond model risk, the dominant operational risk concerns are cyber (a ransomware attack on a settlement system is now a top-three operational risk at most firms), conduct (the risk of fines, settlements, and reputational damage from employee misconduct), and technology (the risk of an outage in a production system, typically from a software change gone wrong). The cost of operational risk events in the industry is large the cumulative fines and settlements from the 2008 financial crisis exceed $300 billion globally and the management of operational risk is now a board-level concern at most major financial firms (BCBS, 2014).
What is liquidity risk?
Liquidity risk is the risk of being unable to meet obligations as they come due without incurring unacceptable costs. It has two standard sub-types. Funding liquidity is the risk that the firm cannot roll its short-term funding repo, commercial paper, margin calls when it comes due. Market liquidity is the risk that the firm cannot exit a position at a price close to the prevailing mid, due to the absence of counterparties or to the absence of the firm's own willingness to provide liquidity in a stressed market. The two are tightly correlated in a crisis: a market liquidity event (no one will buy the position) often triggers a funding liquidity event (margin call, forced sale, no rollover), and vice versa.
The standard regulatory framework for bank liquidity risk is the Liquidity Coverage Ratio (LCR) and the Net Stable Funding Ratio (NSFR), introduced under Basel III. The LCR requires banks to hold enough high-quality liquid assets to meet 30 days of stressed net cash outflows. The NSFR requires banks to fund their long-term assets with stable long-term funding, reducing the maturity mismatch that was at the heart of the 2008 financial crisis. Both are blunt instruments, and the calibration of both has been the subject of intense industry debate (BCBS, 2014).
For asset managers and hedge funds, liquidity risk is managed through the redemption terms of the fund (notice periods, gates, side-pockets), the liquidity of the underlying portfolio (the bid-ask spread, the volume-weighted average price, the on-exchange order book depth), and the stress-tested behaviour of the fund under redemptions (how much of the portfolio can be liquidated within the redemption notice period without breaching the cost budget). The Amihud (2002) illiquidity ratio is the standard empirical measure of asset-level illiquidity, and is one of the dominant inputs to the fund-level stress test. The 2020 COVID-induced redemption wave was a major live-fire test of the industry's liquidity risk frameworks (Jorion, 2007).
What are the key risk models in practice?
The dominant risk models in market risk are: parametric VaR (assuming multivariate normal returns, with the variance-covariance matrix estimated from a recent window typically 1-3 years, exponentially weighted to emphasise recent observations), historical simulation VaR (using the empirical distribution of recent returns, typically 1-3 years, without distributional assumptions), Monte Carlo VaR (simulating from a fitted model, typically a multivariate t or skewed-t for fat tails), and Expected Shortfall (the average of the worst α% of scenarios in the historical or Monte Carlo distribution).
The dominant credit risk models are: Merton's structural model (Merton, 1974), which treats equity as a call option on the firm's assets and infers the probability of default from the firm's capital structure and asset volatility; reduced-form credit models (Jarrow & Turnbull, 1995), which model default as a Poisson process with intensity calibrated to Credit Default Swap spreads; and the Basel IRB framework, which is the regulatory standard for capital. The integration of market-implied credit (from CDS spreads) with structural credit (from equity prices and balance sheet data) is the standard research-grade credit risk model.
The dominant operational risk models are: the Loss Distribution Approach (LDA), which fits separate frequency and severity distributions to internal and external loss data, with the operational VaR computed by Monte Carlo convolution; scenario-based approaches, in which expert judgement is used to construct plausible but extreme scenarios; and the Bayesian network approach, which is increasingly used for cyber and conduct risk. The dominant liquidity risk models are: the LCR and NSFR (regulatory), the cash-flow-at-risk framework (Brunnermeier & Pedersen, 2009), and the funding-adjusted VaR, which combines market risk and funding risk into a single measure. Each of these models is the subject of an active research community and a substantial industry of vendor and in-house implementations (Jorion, 2007).
How is risk management operationalised?
The risk management function in a major financial firm is organised around three standard components. The risk identification and measurement function owns the risk models and produces the daily risk reports. The risk monitoring and control function operates the limit framework, monitors limit utilisation in real time, and triggers escalation or trading halts when limits are breached. The risk governance function owns the risk appetite statement, the limit framework, the model risk management framework, and the reporting to the board risk committee and the relevant regulators.
The standard limit framework combines multiple limit types: VaR limits (the firm-wide VaR is limited to a specific dollar amount or fraction of capital, and each desk has a sub-limit), stress loss limits (the firm's loss under a specific stress scenario is limited to a specific amount), P&L drawdown limits (the cumulative loss over a defined period is limited to a specific amount), factor exposure limits (the firm's exposure to each common factor is limited to a specific dollar amount or beta), counterparty exposure limits (the firm's exposure to each counterparty is limited to a specific amount, typically as a fraction of the counterparty's credit limit), and concentration limits (the firm's exposure to any single name, sector, or country is limited to a specific amount). The limit framework is the operational manifestation of the risk appetite statement.
The day-to-day operation of risk management is dominated by the production risk run. At the start of each trading day, the risk function pulls the end-of-day positions from the firm's position master, runs them through the risk models, and produces the daily risk report (firm-wide VaR, desk-level VaR, factor exposures, top counterparty exposures, top stress losses). During the day, real-time risk monitoring is performed on the live position, with limit utilisation displayed on the trading floor and escalation triggered automatically. At the end of the day, the back-testing run is performed: the realised P&L is compared against the VaR forecast, and any exceptions are investigated. The back-testing exception rate is the standard input to the regulatory validation of the firm's internal VaR model (Jorion, 2007).
What are the honest limits of risk management?
The honest limits of risk management are the same as the honest limits of any model-based discipline. The first is the model: every risk model is a model, with explicit assumptions, and the assumptions are sometimes wrong. The most common assumption failure in market risk is the normality assumption in parametric VaR: the empirical evidence is that financial returns are not normally distributed but are heavy-tailed, and VaR based on the normal distribution systematically understates the true tail risk (Mandelbrot, 1963). The response of the industry has been to shift to Expected Shortfall and to stress testing, but the underlying model uncertainty remains.
The second limit is the data. Credit risk models require long histories of default events, which are rare by construction; the resulting PD estimates are imprecise. Operational risk models require long histories of operational loss events, which are even rarer and are subject to severe reporting bias. Liquidity risk models require long histories of stressed market conditions, which are by definition rare. Each of these data limitations is the principal constraint on the precision of the corresponding risk measure, and is the reason that the regulatory framework uses a combination of model-based and standardised approaches rather than relying on a single model.
The third limit is the human. Risk management is a discipline of vigilance; the standard risk report is produced by a model, but the decision to act on the report is a human decision, and the model is only as good as the human's interpretation of it. The most common single source of major losses in the risk management function is a known risk that was not escalated, a known limit that was not enforced, or a known model that was overridden. The honest practitioner designs for the human failure, not against it (Jorion, 2007).