Market Risk, Limits & Controls
How to read this chapter
Market risk is usually introduced as the risk of loss from movements in market prices. That definition is correct, but it is too small for real banking. In a bank, market risk is not only a number produced by a model. It is a full control system around trading activity, treasury activity, liquidity portfolios, hedge books, securities, derivatives, foreign exchange and balance-sheet exposures. It tells the bank which risk can be taken, which risk must be hedged, which risk must be capitalised, which risk must be escalated and which risk must not be allowed at all.
A trader looks at price opportunity. A treasury dealer looks at liquidity, funding and hedge execution. A market risk manager looks at sensitivity, stress loss, VaR, expected shortfall, limit headroom and concentration. Product control looks at valuation evidence and daily P&L explain. Model risk looks at assumptions, validation and model limitations. Finance looks at official books and accounting impact. Compliance looks at conduct and market abuse. Senior management looks at appetite, exceptions and survival under stress. Market risk joins all of these views into one controlled banking discipline.
This chapter connects the product chapters to independent risk measurement and control. Money-market desks create short-rate, funding and liquidity-linked exposure. Fixed-income desks create duration, curve, credit-spread and liquidity risk. FX desks create currency, basis, option and settlement risk. Derivatives books create rates, volatility, credit, collateral, counterparty and model risk. ALM creates banking-book interest-rate and valuation exposure. Market Risk, Limits & Controls is where those activities become measurable, explainable and governable.
The Basel Committee’s minimum capital requirements for market risk describe the regulatory market-risk framework, including the boundary between trading book and banking book, the standardised approach, the internal models approach, risk-factor treatment, default risk and residual risks (Basel minimum capital requirements for market risk). The BIS executive summary of the revised market-risk framework explains key ideas such as expected shortfall, market illiquidity and the stronger treatment of trading desk model eligibility (BIS revised market-risk executive summary). Those references are regulatory anchors. The practical job inside a bank is to translate those ideas into desk mandates, risk limits, valuation controls, model governance, breach workflow, reporting and management decisions.
This chapter is written for banking business analysts, developers, testers, operations teams, risk teams, product owners, architects and students. It deliberately avoids treating market risk as a mathematical classroom topic only. The formulas matter, but the banking reality matters more. A risk number is useful only if trades are complete, market data is reliable, models are approved, valuation is independently challenged, limits are meaningful, breaches are acted upon and senior management can understand what changed.
Learning objectives
By the end of this chapter, you should be able to explain market risk across interest rates, FX, equity, credit spread, commodity, volatility, basis, optionality and liquidity dimensions. You should understand DV01, PV01, delta, gamma, vega, theta, credit spread sensitivity, curvature, basis risk, VaR, expected shortfall, stress testing and scenario analysis in banking language. You should be able to explain how limits work as behaviour controls, how P&L explain reveals the drivers of profit and loss, how independent price verification protects valuation quality and how model risk management protects the bank from false confidence. You should also be able to design requirements and testing scenarios for trade feeds, market data, sensitivities, limit monitoring, breach workflow, P&L explain, valuation adjustments, model approvals and management reporting.
1. What market risk means in a bank
Market risk appears when changes in market variables change the value of a position. A bond loses value when yields rise. A swap changes value when discount or projection curves move. An FX forward changes value when spot rates, forward points and interest-rate differentials move. An option changes value when the underlying price, volatility, time and rates change. A credit book loses value when credit spreads widen. A commodity exposure moves with oil, gas, metals, power or agricultural prices. The common theme is that the bank is exposed to external market prices.
The bank does not exist to eliminate every market risk. A bank that makes markets must hold inventory. A bank that supports corporate FX clients must quote and manage currency exposure. A bank that offers hedging products must manage residual risk after client trades. Treasury must hold liquid assets, execute funding transactions and sometimes hedge the balance sheet. ALM may accept interest-rate risk in the banking book because customer loans and deposits do not naturally reprice in perfect symmetry. The objective is not zero risk. The objective is approved, understood, measured, controlled and survivable risk.
A useful practical distinction is between intended market risk and accidental market risk. Intended risk is risk taken under an approved strategy, mandate and limit. Accidental risk appears because something is wrong: a trade is booked to the wrong book, a hedge is missing, a market data feed is stale, a maturity is incorrect, a model mapping is wrong, a desk trades outside its authorised product list or a position remains after a client flow should have been squared. Real banks spend a large amount of control effort detecting accidental risk because it can look small until markets move.
Market risk is also not limited to the trading floor. Treasury liquidity portfolios can carry duration and credit-spread risk. A securities portfolio held for liquidity can still lose fair value when rates rise. Foreign-currency funding can create FX and basis exposure. Derivative hedges can reduce earnings volatility but create collateral calls. Banking-book products can create interest-rate risk even when they are not marked through daily trading P&L. This is why market risk, ALM, treasury, finance and liquidity risk must speak to each other.
The strongest practical question is simple: if the market moves tomorrow, do we know how much we can lose, why we can lose it, whether it is inside appetite, whether we can exit or hedge it, whether our valuation is reliable and who must act if the limit is crossed? If the bank cannot answer those questions, the market-risk framework is incomplete.
2. The main families of market risk
Interest-rate risk is exposure to movements in interest rates and yield curves. It appears in bonds, loans, deposits, swaps, futures, FRAs, caps, floors, swaptions, securities portfolios and hedge books. The risk may come from a parallel rate move, a curve steepening, a curve flattening, a basis move between indices, a change in inflation expectations or a change in volatility. Rates risk is often measured with DV01 or PV01, but mature banks also look at key-rate durations, curve buckets, basis sensitivities, gamma, vega and stress.
Foreign exchange risk is exposure to exchange-rate movements. It appears in spot, forwards, swaps, options, foreign-currency cash accounts, nostro balances, foreign securities, foreign-currency funding, cross-currency swaps and translated earnings. FX risk can be outright, where the bank is long or short a currency, or basis related, where the cost of swapping one currency into another changes. FX also carries settlement risk, especially where payment-versus-payment protection is absent or cut-off timings create exposure.
Credit spread risk is exposure to changes in the market spread demanded for credit exposure. A corporate bond can lose value even when the issuer has not defaulted, simply because the market requires a wider spread. Bank bonds, covered bonds, securitisations, sovereigns, credit indices and credit derivatives all carry spread risk. Credit trading also carries jump-to-default and migration risk, where a credit event or rating deterioration creates loss beyond smooth spread movement.
Equity risk is exposure to equity prices, equity indices, dividends, volatility and correlation. Some commercial banks have limited direct equity trading, while investment banks may have large equity derivative books. Equity-linked notes, structured products, hedges and employee benefit exposures can also bring equity sensitivity.
Commodity risk is exposure to commodity prices and related curves. Energy, metals, agriculture, power and emissions products can have strong seasonal behaviour, storage constraints, delivery location risk and liquidity issues. Commodity risk can behave very differently from rates or FX risk because physical constraints and event risk can dominate normal statistical patterns.
Volatility risk appears when implied or realised volatility changes. Options books are the obvious example, but callable bonds, mortgage products, structured notes and embedded optionality also create volatility exposure. A desk may be delta hedged and still lose money when volatility changes. That is why vega, gamma, theta and scenario analysis matter.
Basis risk appears when two related prices do not move together. A bond hedged with an interest-rate swap still has credit spread and asset-swap basis risk. A funding desk using FX swaps has cross-currency basis risk. A product priced against one benchmark and hedged with another has index basis risk. A credit portfolio hedged with an index has single-name versus index basis. Basis risk is often what remains after a hedge looks clean at first glance.
Liquidity in the market-risk sense is the risk that a position cannot be exited, hedged or valued at the assumed price. Bid-offer spreads widen in stress. Market makers step back. Broker quotes become indicative. Observable prices disappear. Valuation uncertainty rises. Basel market-risk reforms explicitly recognise market illiquidity, and banks must recognise it in management controls as well.
3. Risk factors and sensitivities
A risk factor is a market variable that affects the value of a position. For a simple fixed-rate government bond, risk factors may include points on the government yield curve. For a corporate bond, they may include interest-rate curve points and credit spread curve points. For an FX option, they may include spot, domestic rates, foreign rates, volatility surface points and time. For a cross-currency swap, they may include two interest-rate curves, FX spot, FX forward basis and discounting assumptions.
Sensitivities translate a position into measurable reactions to risk-factor movements. DV01 or PV01 measures value change for a one-basis-point rate move. Key-rate duration breaks that exposure into tenor buckets such as one year, two years, five years, ten years and thirty years. Delta measures sensitivity to the underlying price or rate. Gamma measures how delta changes as the underlying moves. Vega measures sensitivity to volatility. Theta measures time decay. Credit spread sensitivity measures value change for spread movement. Curvature captures non-linear loss that simple delta cannot capture.
In real banking, sensitivities are not just educational measures. They drive hedging, limit monitoring, trader decisions, P&L explain, stress design, capital calculations and management reporting. A rates trader may reduce five-year DV01 while accepting ten-year DV01. A credit trader may hedge index exposure while keeping single-name spread risk. An FX options trader may manage delta daily but review vega and gamma under stress. A treasury portfolio manager may shorten duration to reduce OCI volatility or economic value sensitivity.
Sensitivities are also a data-quality test. If a bond has no maturity date, wrong coupon, wrong day-count convention or wrong curve mapping, DV01 will be wrong. If an option has stale volatility data, vega will be wrong. If a credit instrument is mapped to the wrong issuer, spread sensitivity will be wrong. If a trade is missing from the risk engine, all downstream measures are wrong. Risk managers therefore spend significant time on population completeness, reference data quality and mapping control.
A good risk report should never show only a single total. It should show the drivers behind the total. If a desk loses money, management should know whether the loss came from rates, FX, spread, volatility, carry, time decay, new trades, valuation reserves, model changes or unexplained movement. Sensitivities are the language that makes this possible.
Sensitivity units and signs before aggregation
Always state currency, quote convention, bump size and sign. One basis point is 0.0001 in a decimal interest rate. For this example, signed PV01 is V(y + 1bp) − V(y). A USD 10 million fixed-rate bond with modified duration 4.5 has approximately −4.5 × 10m × 0.0001 = −USD 4,500 per bp. A +20-basis-point parallel yield move implies about −USD 90,000 value change, ignoring convexity and other factors. Some desks report positive DV01 as a loss magnitude instead; a report must identify which convention it uses.
A receive-fixed swap commonly has negative signed rate sensitivity under this convention; a pay-fixed swap commonly has positive sensitivity. Projection, discount and basis curves need separate bumps where material. A hedge matched on total PV01 can still have opposite concentrations in five-year and thirty-year buckets.
For an illustrative long option, define delta as currency value per one unit of underlying price, gamma as change in that delta per price unit, and vega as currency value per one percentage-point increase in implied volatility. With delta 200, gamma 30, a +2-price-unit move and unchanged volatility/time, the local approximation is 200 × 2 + 0.5 × 30 × 2² = +460 currency units. If vega is 100 per volatility percentage point and volatility rises from 20 to 23 percent, the vega contribution is approximately +300, not +3. Cross terms, theta and large moves need revaluation. Model derivatives taken with volatility expressed as a decimal require conversion before comparing them with per-percentage-point reporting.
4. Trading book and banking book boundary
The trading book and banking book boundary is one of the most important controls in market risk. Trading-book positions are generally held with trading intent, market-making intent, short-term resale intent, intent to benefit from price movements or intent to hedge other trading-book positions. Banking-book positions are generally held for lending, investment, liquidity management, ALM, relationship banking or longer-term balance-sheet management. The exact classification must follow the applicable regulatory framework and the bank’s internal policy.
The Basel market-risk framework strengthened the trading-book and banking-book boundary to reduce regulatory arbitrage and improve consistency. That matters because book classification affects valuation, risk measurement, capital, P&L reporting, limit framework and management oversight. A position should not move between books simply because one treatment is more convenient. Transfers need documented purpose, approval, evidence and audit trail.
The same bond can create different governance outcomes depending on why it is held. A trading desk may hold the bond as market-making inventory. Treasury may hold the bond as high-quality liquid assets. ALM may hold securities for balance-sheet positioning. The market risk can look similar, but the purpose, limit structure, accounting treatment and management discussion differ. A trading book may focus on daily P&L and trading limits. A liquidity portfolio may focus on HQLA eligibility, liquidity monetisation, duration and stress loss.
Banks must also watch for boundary drift. A desk may start with flow trading and gradually build strategic positions. Treasury may reach for yield in a liquidity portfolio. A hedge book may accumulate residual positions that behave like trading inventory. A banking-book position may contain embedded optionality that needs stronger market-risk measurement. Boundary governance prevents the bank from discovering too late that its actual risk is different from its official classification.
For systems, book classification must be controlled master data, not a loose label. It should feed trade capture, valuation, risk engines, capital calculations, finance ledgers, regulatory reports, limits, hierarchy and dashboards. Changes should require approval and effective dates. A wrong book value can produce wrong capital and wrong management action.
Regulatory book and accounting category are separate
The prudential banking/trading-book boundary is not synonymous with amortised cost, fair value through OCI or fair value through profit or loss. Purpose matters, but prescribed assignments and presumptions also apply. Accounting trading status can create a regulatory presumption; other fair-valued positions can remain in the banking book. Forex and commodity exposures can be subject to market-risk capital even when booked outside the trading book. Use Basel RBC25 and the local rule, rather than a desk name, to determine treatment.
Book changes are especially controlled. Basel prohibits switching for regulatory arbitrage, restricts discretionary reassignment to extraordinary circumstances and disallows a capital benefit from switching. System design should preserve accounting classification and regulatory book as separate effective-dated attributes, with approval and reconciliation to capital reporting.
5. FRTB in practical banking language
The Fundamental Review of the Trading Book, usually called FRTB, is the Basel reform package that reshaped market-risk capital after weaknesses seen in earlier frameworks. Its practical message is that market-risk capital should better capture tail risk, market illiquidity, desk-level model quality, default risk, residual risks and the boundary between trading and banking books. The Basel standard is technical, but the bank implementation is a large operating model across front office, risk, finance, data, technology, model validation and regulatory reporting.
Under the revised framework, the standardised approach is designed to be more risk-sensitive and to act as a credible fallback to internal models. The internal models approach uses expected shortfall rather than the old VaR-based approach for capital, and it applies stronger trading-desk approval tests. A bank cannot simply have one global model approval and assume every desk can use it. Desk-level performance, risk-factor eligibility and P&L attribution matter.
A practical bank implementation asks several questions. Which desks are in scope? Which desks are approved for internal models? Which desks must use the standardised approach? Which risk factors are modellable? Which are non-modellable? Which positions create default risk charge? Which instruments create residual risk add-on? How does the risk engine calculate sensitivities? How does the finance P&L compare with risk-theoretical P&L? What happens when a desk fails eligibility tests? Who owns remediation?
For learners, the important point is that FRTB is not only a capital formula. It forces better discipline around desk structure, trade population, pricing models, market data history, risk-factor mapping, P&L explain and governance. A bank that treats FRTB as a regulatory reporting exercise will struggle. A bank that treats it as a control framework will build better risk transparency.
Basel standard versus local implementation
FRTB is a global prudential standard implemented through jurisdictional rules; publication of a Basel text does not itself change every bank’s legal capital requirement. A release needs a jurisdiction and entity matrix separating current capital, future capital, supervisory reporting and disclosure obligations.
For the UK, PRA PS1/26 final rules sets general Basel 3.1 implementation for 1 January 2027 and the market-risk internal model approach for 1 January 2028. These are future dates relative to October 2026; later consultations and final instruments must be checked before implementation.
For the EU, the Commission’s 4 June 2026 announcement describes targeted temporary adjustments, including capital multipliers, intended for three years from 1 January 2027 subject to parliamentary and Council scrutiny. It is not evidence of a blanket three-year postponement of FRTB. Verify the final legal instrument and current supervisory guidance before using a relief measure. Canada’s OSFI CAR 2026 chapter 9 is a separate national implementation, not a template for EU, UK or US compliance.
For the US, the Federal Reserve, FDIC and OCC announcement of 19 March 2026 requested comment on capital proposals, including the final Basel III components. Its market-risk aspect would apply to banks with significant trading activity. This is a proposal-stage source, not an in-force market-risk rule or a confirmed implementation date. A US implementation programme must distinguish the existing applicable rules from proposed changes and check subsequent final agency instruments.
6. Standardised approach: what it means operationally
The FRTB standardised approach is often described through risk classes, sensitivities, buckets, correlations and capital aggregation. In operational language, it means the bank must identify the risk factors in each instrument, calculate prescribed sensitivities or risk positions, group them according to the framework and aggregate them in a controlled way. It is not a simple notional-based calculation for most trading books.
The main risk classes include general interest rate risk, credit spread risk, equity risk, commodity risk and foreign exchange risk. Some jurisdictions also provide additional treatment for crypto-asset exposures or other specific categories. For each risk class, instruments must be mapped correctly. A corporate bond is not only an interest-rate product. It also has credit spread risk. A securitisation has different treatment from a plain corporate bond. An option has delta, vega and curvature dimensions. A wrong product mapping creates wrong capital.
For BA and technology teams, standardised approach implementation needs clean product taxonomy, risk-factor mapping, sensitivity generation, bucket assignment, maturity assignment, currency assignment, issuer and sector attributes, rating data, securitisation flags, option characteristics and aggregation rules. A capital report can fail because of a missing issuer sector, wrong seniority, wrong currency, wrong tenor bucket or missing sensitivity.
The standardised approach also becomes a benchmark for internal models. Even where a desk uses internal models, regulators and management may compare internal model capital with standardised approach outcomes. This creates a need for reconciliation and explainability. If standardised capital and model capital move differently, the bank must understand why.
7. Internal models approach: desk-level reality
The internal models approach is not just a sophisticated calculation. It is a permission framework. A bank needs supervisory approval, and approval is tied to trading desks and risk factors. A desk must be defined clearly. Its trades, strategy, products, risk factors, P&L and governance must be controlled. Internal model use can be lost or restricted if model performance, P&L attribution or data quality is weak.
Expected shortfall is central to the revised internal models approach. It focuses on the average of losses beyond a confidence threshold, so it is more sensitive to tail losses than VaR. In management language, expected shortfall asks not only where the loss threshold is, but how bad the loss can be after the threshold is crossed. That is closer to the question senior management actually cares about during crisis conditions.
The internal models approach also distinguishes modellable and non-modellable risk factors. A modellable risk factor has enough real price observations and data quality to be included in the expected shortfall model in the approved way. A non-modellable risk factor does not meet the required standards and attracts stressed capital treatment. This is not a minor data issue. It can materially affect capital and desk economics.
A practical implementation requires risk-factor inventory, market data observation capture, data lineage, modellability assessment, model validation, backtesting, P&L attribution, desk-level governance and remediation workflow. If a risk factor loses modellability because market data becomes sparse, the bank must know quickly. If a desk fails P&L attribution, management must understand whether the issue is modelling, data, valuation, booking or business strategy.
8. P&L attribution and backtesting
The regulatory FRTB P&L attribution (PLA) test compares daily risk-theoretical P&L (RTPL) with hypothetical P&L (HPL), not ordinary actual P&L. HPL revalues the previous day’s closing positions using today’s market data, excluding intraday trading and new or modified deals. RTPL uses the desk risk model’s valuation engine and risk factors. The comparison tests whether model simplifications omit material P&L drivers. Basel MAR32, paragraphs 32.20-32.29 specifies definitions, adjustments and timing.
FRTB desk backtesting compares one-day VaR with actual P&L (APL) and HPL using the prescribed definitions. Actual and hypothetical exceptions are counted separately under the framework. It remains a VaR test even though approved model capital uses expected shortfall. Too many exceptions can indicate inadequate risk capture. Backtesting is not perfect because market history is limited, but it is a necessary challenge to model confidence. A model that looks elegant but repeatedly fails outcome checks cannot be treated as reliable without remediation.
P&L attribution failures can come from many sources. Trades may be missing from the risk engine. Product setup may differ between front-office and risk systems. Market data may not align between valuation and risk. Risk-theoretical P&L may omit factors present in HPL. Fees, valuation adjustments and time effects must follow the regulatory definitions; intraday trading belongs in the appropriately defined actual-P&L view, not the static-position HPL. A desk may use a complex strategy that the model simplifies too much. The investigation must be practical, not only statistical.
For BA and testing teams, P&L attribution requirements should include source P&L definitions, trade population timing, valuation timestamp, market data set, explain categories, residual thresholds, failure classification, ownership, remediation status and historical evidence. A dashboard that shows a failed test without explaining the driver is not enough.
Do not substitute the management P&L explain
A trader’s daily P&L explain can include new trade revenue, fees, reserves and actual trading activity. PLA uses controlled regulatory HPL and RTPL series with prescribed exclusions and adjustments. They are related controls but not interchangeable reports. Test the frozen position population, market-data timestamps, treatment of time effects and the version of the pricing model before evaluating statistical results. A trade-feed change can invalidate a comparison even when the dashboard still produces a score.
9. Non-modellable risk factors
A non-modellable risk factor, often called NMRF, is a risk factor that cannot be treated as modellable under the framework because it lacks sufficient eligible real price observations or does not meet required data standards. This is one of the most practical parts of FRTB because it connects market data availability directly to capital and governance.
In a liquid market, a bank may have regular observed prices, executed trades or committed quotes that support modellability. In an illiquid credit, long-dated option, exotic structure or bespoke curve point, observations may be sparse. The position still has risk, but the bank cannot rely on the same modelling treatment. The framework therefore requires separate stressed treatment for non-modellable risk factors.
Operationally, NMRF control requires a market data evidence store. The bank needs to know which observations were used, where they came from, whether they are real, whether they pass quality tests, which risk factor they support and whether the evidence is current. Vendor data may help, but the bank remains responsible for understanding and governing its use. The Federal Reserve’s revised model-risk guidance also makes clear that vendor tools do not remove the bank’s responsibility to understand and validate model use.
NMRF issues can become business issues. A desk may trade a product because it is profitable, but if the risk factors are non-modellable, capital cost may rise. A product approval committee should therefore ask not only whether a product can be priced, but whether its risk factors can be modelled, observed, controlled and capitalised. This is a real banking-world connection between front-office strategy, data quality and regulatory capital.
10. Default risk, jump risk and residual risk
Smooth market moves are not the only source of market loss. Credit trading books can suffer default or migration losses. A bond issuer can default. A credit spread can gap wider. A reference entity in a credit derivative can experience a credit event. A securitisation tranche can behave non-linearly. These risks are not always captured fully by normal spread sensitivities.
Under FRTB, the default risk charge targets issuer jump-to-default risk; spread migration and other market movements are addressed through other components of the framework. In practical terms, the bank must identify instruments exposed to issuer default, calculate exposures, apply correct issuer, seniority, maturity, hedging and netting logic and aggregate results. A wrong issuer mapping or wrong seniority can materially distort default risk.
Residual risk add-on captures risks that are not adequately captured by the sensitivities-based components of the standardised approach. Exotic underlyings, path dependency, correlation structures and complex optionality can create residual risk. A product that appears small in delta may still carry meaningful risk because payoff behaviour changes sharply under certain conditions.
For new product approval, default and residual risk questions should be explicit. Does the product create jump risk? Does it reference a basket, index, tranche or exotic underlying? Does the payoff depend on path, barrier, volatility, correlation or future realised value? Can systems calculate the correct capital and limits? Can product control independently value it? Can the desk hedge it in stress? If the answer is weak, the product should not be rushed into production.
11. VaR, expected shortfall and their limits
Value-at-Risk estimates potential loss over a defined time horizon and confidence level. A one-day 99 percent VaR of ten million means the model estimates that losses should exceed ten million on about one percent of days, under the model’s assumptions and data. VaR is useful because it creates a common measure across desks and products. It is also easy to misunderstand. VaR does not tell management how large losses can be beyond the threshold. It can be too dependent on historical data, assumptions and market conditions.
Expected shortfall looks beyond the threshold and averages losses in the tail. This makes it more sensitive to severe loss outcomes. The revised Basel internal models approach moved from VaR toward expected shortfall for market-risk capital because tail risk matters. For management, the lesson is direct: the bank should not be satisfied with a single normal-market risk number. Tail loss, stress loss and liquidity loss matter.
Both VaR and expected shortfall depend on data and assumptions. If historical data does not include the current kind of stress, the model may understate risk. If correlations break down, diversification benefits may disappear. If market liquidity dries up, a calculated loss may not reflect exit cost. If positions are complex, models may simplify behaviour. If risk factors are missing, the number is incomplete.
A mature bank uses VaR or expected shortfall as part of a package. It also uses sensitivities, stress testing, scenario analysis, stop-loss, concentration limits, liquidity measures, valuation uncertainty measures and expert review. A single number should never silence judgement. Risk measures are estimates under explicit assumptions, and their limitations should be visible alongside the result.
A small empirical VaR and expected-shortfall example
Suppose twenty equally weighted illustrative one-day losses, sorted in ascending order in USD millions, are −2, −1, −0.5, 0, 0.2, 0.4, 0.6, 0.8, 1, 1.2, 1.4, 1.6, 1.8, 2, 2.2, 2.4, 2.6, 3, 4, 8. Negative loss means a gain. Use a stated nearest-rank empirical convention at 90 percent confidence solely to make the arithmetic visible. The 18th observation is USD 3 million, so VaR is USD 3 million. The worst 10 percent comprises USD 4 million and USD 8 million; their mean is USD 6 million, the empirical expected shortfall for this example.
Twenty observations and 90 percent confidence are inadequate for a production capital model; this is a quantile teaching example, not FRTB calibration. Quantile interpolation and boundary probability treatment can change a small-sample result. Risk reports need horizon, confidence, currency, position date, observation window and method. A “99 percent VaR” does not guarantee one exception every hundred days, and it is not the largest possible loss. Do not scale one-day risk by the square root of time without examining distribution, independence and liquidity assumptions.
12. Stress testing and scenario design
Stress testing asks what happens if severe but plausible market moves occur. It is the bank’s rehearsal for uncomfortable events. Rate shocks, curve twists, credit spread widening, currency devaluation, volatility spikes, commodity gaps, liquidity evaporation, sovereign stress, basis dislocation and issuer default can all be stress scenarios. A good stress framework is tailored to the bank’s actual exposures.
Historical scenarios replay past events such as the global financial crisis, sovereign debt stress, pandemic market dislocation, sudden rate shocks or currency crises. Hypothetical scenarios design future risks based on current vulnerabilities. Reverse stress testing asks what scenario would break the bank’s appetite or capital. Each method has a role. Historical scenarios provide realism. Hypothetical scenarios provide relevance. Reverse stress exposes hidden dependencies.
Scenario design must include more than one clean market move. Real stress is messy. If rates jump, credit spreads may widen. If a currency devalues, funding markets may tighten. If volatility rises, option hedging may become expensive. If liquidity disappears, exit assumptions become unrealistic. If correlations change, hedges may fail. Stress scenarios should therefore include market moves, liquidity assumptions, basis behaviour, correlation changes and management actions.
Stress testing should lead to decisions. If stress loss exceeds appetite, the bank can reduce risk, hedge, change limits, increase capital, adjust liquidity, change product strategy or accept the exposure with formal approval. A report that shows a large stress loss but produces no action path is not a control. It is decoration.
The same scenario should drive valuation and funding
For a fictional bank, a combined shock produces USD 8 million asset-value loss and USD 6 million hedge-value gain: net economic loss is USD 2 million. A separate scenario can produce a hedge loss and VM outflow while the asset gains economically. Derive both from the same shocked portfolio rather than assuming the hedge must always call for cash when assets lose value. Treasury also needs margin timing, collateral haircuts, unavailable inflows and the cost of hedge rebalancing.
Liquidity is a cash constraint, not another sensitivity that can simply be added to USD 2 million. Maintain a P&L/economic-loss view and a cash requirement view, with a bridge showing which amounts overlap. Stress monetisation may crystallise an existing valuation loss rather than create an additional identical loss. This avoids counting the same loss once in mark-to-market, again in sale proceeds and a third time in cash stress.
13. Limits as behaviour controls
A limit is the bank’s risk appetite translated into daily boundaries. Limits may be set by trader, desk, book, product, currency, tenor, issuer, country, legal entity, risk factor, sensitivity, VaR, expected shortfall, stress loss, stop-loss, inventory age, notional, concentration or settlement exposure. A limit should tell people when risk is acceptable, when attention is needed and when action is required.
Limits are not meant to be impressive in policy documents. They must influence behaviour. If a trader approaches a limit, the desk should know whether to hedge, reduce inventory, request approval or stop taking new risk. If a limit is breached, the bank should know who owns the breach, who can approve excess, how long it can remain, what remediation is required and how it is reported. If none of that is defined, the limit is weak.
Limit calibration is a real management decision. Too tight, and the desk cannot serve clients or manage hedges efficiently. Too loose, and the bank accepts risk it may not understand. Calibration should consider business strategy, liquidity, historical usage, stress losses, capital, P&L volatility, trader experience, product complexity and market conditions. Limits should be reviewed periodically and after major market changes.
A good limit framework uses layers. A desk may have DV01 limits, curve bucket limits, VaR limits, stress limits, stop-loss limits, issuer limits, aged inventory limits and product limits. These are not duplicates. They control different behaviours. DV01 controls rate sensitivity. Stress controls severe scenarios. Stop-loss controls realised damage. Issuer limits control concentration. Aged inventory controls positions that are becoming difficult to exit.
14. Intraday limits and fast-moving desks
End-of-day risk is not enough for every desk. FX, rates, futures and options books can change quickly during the day. Client flows may create temporary positions. Market moves may turn a safe opening position into a limit issue by noon. Intraday controls are therefore important where risk changes fast.
Intraday limits may be formal hard limits, warning thresholds or trader dashboards. The exact design depends on the desk. A high-volume FX spot desk may need near-real-time open currency positions. An options desk may need intraday delta and vega. A bond portfolio may rely more on end-of-day plus event-driven monitoring. The control frequency should match the speed of risk.
Intraday reporting creates technology demands. Trade capture must be timely. Market data must update. Risk engines must calculate fast enough. Limit systems must consume intraday measures. Alerts must reach the right people. Manual workarounds can be dangerous if the desk believes it is controlled while the system is stale.
Testing intraday risk requires timestamp discipline. A tester should verify trade booking time, market data time, risk calculation time, limit-check time, alert time and approval time. Without timestamps, an intraday control cannot prove it worked.
15. Stop-loss and loss escalation
Stop-loss limits control actual or mark-to-market losses over a defined period. They are different from sensitivity limits. A desk can be within DV01 and still lose money because the market moved against it. Stop-loss escalation forces management to review whether the strategy remains valid, whether risk should be reduced and whether the desk is trying to recover losses by increasing risk.
Losses are not automatically misconduct. Markets move. A desk can lose money within an approved strategy and still be well controlled. The issue is whether the loss is explainable, within appetite and properly escalated. If loss comes from known risk within approved limits, management may allow the strategy to continue. If loss comes from unauthorised trades, valuation error, model weakness, hidden exposure or unexplained P&L, stronger action is required.
Stop-loss discipline protects culture. Without it, traders may double down, business heads may delay escalation and management may discover losses too late. A clear threshold makes escalation normal rather than personal. It creates a controlled conversation before the loss becomes a crisis.
Systems must define the P&L used for stop-loss. Intraday P&L, end-of-day P&L, realised P&L, unrealised P&L, management P&L and official finance P&L can differ. Fees, reserves, valuation adjustments, funding costs and model changes must be treated consistently. Ambiguity weakens control.
16. Valuation control and independent price verification
Market risk depends on valuation. If a position is priced incorrectly, risk, P&L, capital, collateral and management reporting become unreliable. Product control and independent price verification exist to challenge valuation quality. Front office may mark positions, but independent control functions verify prices, inputs, reserves, model use and P&L explanation.
Independent price verification compares front-office marks with independent sources where possible. Sources may include exchange prices, broker quotes, evaluated prices, consensus data, vendor feeds, observable transactions, model calibration and alternative curves. The method depends on product liquidity and market observability. A liquid government bond is easier to verify than a bespoke long-dated structured product.
Illiquid positions require stronger judgement. A price may be theoretical, stale, vendor-derived or based on limited quotes. The bank may need valuation reserves or prudent valuation adjustments. Prudent valuation is especially important for positions without directly observable prices, concentrated positions, less liquid positions and stale positions. The Basel framework and national implementations include prudent valuation expectations for fair-valued positions.
Valuation control should include price source hierarchy, tolerance checks, stale price checks, independent challenge, manual override control, reserve methodology, approval workflow and audit trail. A manual price override without evidence is a red flag. A repeated tolerance breach without action is a control weakness. A stale price that keeps a report green is worse than no report because it creates false comfort.
Accounting fair value and prudent valuation differ
Independent price verification supports reliable valuation. Accounting fair value, management reserves and prudential adjustments have distinct purposes and rules. Basel CAP50 prudent valuation guidance includes controls and adjustments for valuation uncertainty. A prudential deduction is not automatically an accounting P&L reserve. Finance and capital reporting should maintain a documented bridge, including scope, methodology, input evidence and approval. Illiquidity warrants challenge; it does not authorise replacing an uncertain price with an unreviewed conservative guess.
17. P&L explain and product control
P&L explain connects daily profit and loss to identifiable drivers. A strong P&L explain can show how much came from rates, curve movement, FX, credit spread, volatility, carry, time decay, new trades, fees, reserves, valuation adjustments, model changes and residual unexplained movement. This is one of the most practical controls in a trading bank.
Unexplained P&L matters. It may reveal missing trades, stale data, wrong curve mapping, wrong product setup, unauthorised activity, model limitations or valuation issues. Small residuals may be acceptable within tolerance. Large or repeated residuals require investigation. A desk that makes money but cannot explain the source is not necessarily safe. Profit can hide risk just as loss can reveal it.
P&L explain also supports trader accountability. If a trader says a loss came from a market move, the explain should support or challenge that statement. If the explain shows unexpected volatility loss, basis loss or residual loss, the conversation becomes specific. This improves both risk management and business discipline.
For BA teams, P&L explain needs trade population, official P&L source, risk-theoretical P&L, market data snapshots, explain buckets, tolerance thresholds, residual calculation, sign-off workflow and escalation. Product control, market risk and front office must agree definitions before testing begins.
18. Market data governance
Market data is the raw material of market risk. Prices, curves, spreads, volatilities, correlations, fixings, calendars, ratings, issuer data and reference data all feed valuation and risk. If market data is wrong, the risk result is wrong. A polished dashboard cannot fix weak inputs.
Market data failures are common in real institutions. A price may be stale. A curve point may be missing. A fixing may be corrected after publication. A volatility surface may have gaps. A bond may be mapped to the wrong issuer. A holiday calendar may be wrong. A credit spread may use the wrong seniority. A vendor feed may arrive late. A manual override may be entered without approval. Each issue can affect valuation, sensitivities, P&L explain and limits.
Governance should define source hierarchy, validation rules, tolerance checks, fallback logic, stale data treatment, interpolation rules, curve construction rules, override approval, evidence retention and ownership. During stress, market data often becomes harder to source exactly when management needs more reliable information. Strong governance must exist before stress, not after.
Market data lineage is essential. A risk manager should know which data source fed a number, when the data was received, whether it passed validation, whether it was overridden, who approved the override and which downstream reports used it. Without lineage, investigation becomes manual and slow.
19. Model risk management
Market-risk measurement relies heavily on models. Valuation models price derivatives and complex products. Curve models build discount and projection curves. VaR and expected shortfall models estimate statistical losses. Stress engines apply scenarios. Sensitivity engines calculate Greeks. XVA models estimate valuation adjustments. Models simplify reality, and simplification creates model risk.
For a US supervisory example, the Federal Reserve’s SR 26-2 of 17 April 2026 superseded SR 11-7 and SR 21-8 and emphasises a risk-based approach tailored to the organisation’s model risk profile, size and complexity. The letter says it is expected to be most relevant to Federal Reserve-regulated banking organisations above USD 30 billion total assets; it is not a global legal threshold. The guidance describes model risk as potential adverse consequences from decisions based on incorrect or misused model output. This is directly relevant to market risk because trading and treasury decisions often rely on modelled valuation, sensitivities, VaR, expected shortfall and stress results.
Model governance should include model inventory, model owner, business purpose, methodology, assumptions, limitations, validation, approval, implementation control, performance monitoring, change control and retirement. Vendor models still need governance. A bank may not see every line of vendor code, but it must understand conceptual soundness, inputs, outputs, limitations and fitness for purpose.
A model can fail in several ways. It may be mathematically wrong. It may be mathematically sound but used for an unapproved product. It may rely on stale calibration. It may ignore a material risk factor. It may be implemented incorrectly in production. It may produce output that users misunderstand. A strong model-risk framework controls all of these possibilities.
20. XVA, CVA and counterparty-linked market risk
Derivatives valuation is not only clean price. Banks often consider valuation adjustments such as CVA, DVA, FVA, ColVA, MVA and other XVA components depending on institution practice, accounting, regulatory context and product scope. CVA, or credit valuation adjustment, reflects counterparty credit risk in derivative valuation. CVA risk can move because counterparty spreads change and because market risk factors drive exposure values.
CVA sits at the boundary of market risk and counterparty credit risk. A rates move can change the exposure profile of a swap. A credit-spread move can change CVA. Collateral terms can change exposure. Netting agreements can reduce exposure. Wrong-way risk can make exposure and counterparty credit quality deteriorate together. This is why derivative control needs market risk, counterparty risk, collateral, legal documentation and valuation teams working together.
From a systems perspective, XVA requires trade population, netting sets, collateral agreements, margin terms, counterparty data, credit spreads, exposure simulation, discount curves and model assumptions. Missing CSA data can materially distort exposure. Wrong netting-set mapping can overstate or understate CVA. Stale counterparty spread data can misstate valuation adjustment.
Learners should not treat XVA as a separate mysterious topic. It is part of the practical reality of derivatives risk. A derivative desk may hedge interest-rate delta but still carry CVA sensitivity. A counterparty downgrade may create valuation movement. A collateral dispute may change exposure. These are real banking events, not academic footnotes.
21. Collateral, repo and securities financing risk
Market risk also appears in collateral and securities financing transactions. Repos, reverse repos, securities lending, collateral swaps and margin lending involve market values, haircuts, collateral eligibility, margin calls and liquidation risk. A repo may look secured, but collateral value can fall, haircuts can widen and liquidity can disappear.
A reverse repo desk holding collateral must monitor market value, issuer concentration, maturity, currency, wrong-way risk and liquidity. If collateral falls in value, margin calls are required. If the counterparty defaults, the bank may need to liquidate collateral in stressed market conditions. The realised value may differ from normal valuation.
Collateral also affects derivatives. Variation margin responds to current mark-to-market exposure; whether it collateralises or legally settles that exposure depends on the contract. Initial margin covers potential exposure over close-out, subject to the model and legal terms. See the derivatives chapter for the separate collateral and settlement accounting examples. Market moves can create collateral calls that affect liquidity. A hedge that reduces economic market risk may still create cash outflows through margin. This is why market risk, liquidity risk and collateral management must connect.
Testing collateral-linked risk requires price movements, haircut changes, margin call generation, dispute workflow, eligibility checks, concentration checks, settlement failure and default scenario handling. A clean valuation without collateral workflow is incomplete for real-bank control.
22. Treasury securities, HQLA and OCI risk
Treasury portfolios are often misunderstood by beginners. A high-quality liquid asset can still lose market value. Government bonds, covered bonds and high-quality securities may be liquid and eligible for liquidity buffers, but they carry duration, curve and sometimes spread risk. When rates rise sharply, the fair value of fixed-rate securities falls.
The accounting treatment matters. Some securities are marked through profit and loss. Some may be fair-valued through other comprehensive income depending on accounting classification and jurisdiction. Some may be held at amortised cost. Economic risk can exist even when accounting P&L is not immediately affected. Management must understand the difference between accounting presentation, regulatory liquidity value, economic value and monetisation value.
HQLA portfolios require market-risk limits. Treasury should monitor duration, key-rate exposure, credit spread sensitivity, issuer concentration, country concentration, haircut assumptions, repo eligibility and stress loss. Liquidity quality does not cancel market risk. A bond can be usable for liquidity but painful for valuation.
ALCO should review treasury portfolio market risk alongside liquidity metrics. If the bank extends duration to earn yield, it should understand economic value sensitivity and potential accounting volatility. If it shortens duration, it may reduce risk but sacrifice income. These are management trade-offs, not purely technical calculations.
23. Banking-book market risk and IRRBB connection
Not all market risk is trading-book risk. Banking-book positions also respond to market rates. Interest-rate risk in the banking book, or IRRBB, covers risk to earnings and economic value from adverse movements in interest rates affecting banking-book positions. Fixed-rate loans, floating-rate loans, deposits, mortgages, savings products, behavioural balances and hedges all matter.
IRRBB is usually managed through ALM rather than trading desk limits, but the market-risk thinking is similar. The bank needs repricing gaps, behavioural assumptions, duration, optionality, NII sensitivity, EVE sensitivity, stress scenarios and governance. Deposit behaviour is especially important because contractual maturity may not reflect real customer behaviour.
The boundary between market risk and ALM should be clear but connected. A trading swap book may be controlled by market risk. A banking-book hedge may be controlled through ALM. A treasury securities portfolio may sit in banking book but need market value stress. A foreign-currency structural position may be managed differently from a trading FX position. Governance must define ownership.
For learners, the key is not to force every exposure into one department. The bank should ask who owns the risk, how it is measured, what limits apply, where it is reported and how management acts. That is more important than labels.
24. Concentration and wrong-way risk
A portfolio can look diversified by product but still be concentrated by risk driver. Many different bonds may all be exposed to the same country spread. Several desks may all depend on the same currency funding market. A group of structured products may all be short volatility. A set of counterparties may all depend on the same sector. Concentration risk appears when losses are driven by common factors.
Wrong-way risk appears when exposure increases at the same time as credit quality or market liquidity worsens. In derivatives, a counterparty may become weaker exactly when the bank’s exposure to that counterparty increases. In collateral, the collateral value may fall at the same time as the borrower defaults. In country risk, currency devaluation and sovereign spread widening may happen together.
Concentration controls can include issuer limits, country limits, sector limits, currency limits, tenor limits, product limits, maturity bucket limits and stress concentration reports. The point is to stop the bank from hiding one big risk inside many small-looking positions.
A good risk manager asks: what common factor hurts this portfolio? What hedge stops working in stress? What position cannot be sold when everyone else wants to sell? What exposure grows when the counterparty weakens? Those questions often reveal more than a simple total risk number.
25. Desk mandates and authorised products
A desk mandate defines what a desk is allowed to do. It should specify products, markets, currencies, clients, strategies, risk types, hedging instruments, booking locations, valuation approach, limits and escalation. Without a clear mandate, control becomes reactive and arguments start after risk has already been taken.
Authorised product lists are practical controls. A desk approved for vanilla government bonds should not automatically trade structured credit options. A treasury liquidity desk should not quietly move into illiquid yield products. An FX conversion desk should not warehouse large speculative positions if its mandate is client pass-through conversion. Mandate drift is one of the most common ways risk grows without a formal decision.
New product approval should review product economics, target clients, legal documentation, accounting, taxation if relevant, regulatory reporting, valuation model, market data, risk factors, limits, hedging, settlement, collateral, operations, technology, conduct, client suitability and exit strategy. A product should not go live just because front office can sell it. The bank must be able to value, risk-manage, settle, report, govern and unwind it.
For BA teams, product taxonomy is a control. A product type that is too broad can hide complexity. A swap, cap, floor, swaption, callable note and structured note may all be rates products, but they require different lifecycle events, models, risk measures and controls.
26. Breach management and escalation
A limit breach is not automatically a scandal. It is a control signal requiring classification, ownership and decision. A breach may be caused by a new trade, market movement, data correction, stale data update, model change, hierarchy mapping, limit change, operational timing or unauthorised activity. The response depends on the cause, but the breach must never be ignored.
A strong breach workflow records limit name, threshold, utilisation, excess amount, time of breach, cause, owner, immediate action, approval status, approver, expiry, remediation plan, closure evidence and reporting status. It should distinguish warning thresholds, soft breaches and hard breaches. It should show breach ageing. It should escalate material breaches to senior management or committee.
Temporary excess approvals need discipline. If a desk repeatedly receives temporary approvals for the same issue, the bank must decide whether appetite should formally change or risk should be reduced. Repeated exceptions are often policy drift in disguise.
Testing breach management should include normal utilisation, warning threshold, hard breach, data-error breach, market-move breach, approved excess, expired approval, repeated breach, closure and MI reporting. A limit system that only shows red and green without workflow is incomplete.
A breach should remain open until its exposure is resolved
Suppose a desk’s signed parallel-rate sensitivity limit is ±USD 50,000 per bp and utilisation is +USD 62,000 per bp. The excess is USD 12,000 per bp. Front office identifies a hedge carrying −USD 15,000 per bp; on the same population and bump convention it would reduce utilisation to +USD 47,000 per bp. Independent risk should also test bucket and stress effects before allowing this scalar result to close the breach.
A proposed hedge does not reduce actual exposure. An executed but unbooked hedge may reduce economic risk while leaving the control population incomplete, requiring immediate booking and investigation. A booked trade rejected by the intended clearing service creates another workflow rather than evidence of an accepted cleared hedge. Closure requires confirmed risk recomputation, documented approval and evidence that outstanding operational exceptions remain owned. Cash settlement and collateral readiness are checked separately.
27. Governance and three lines of defence
Front office is the first line. It owns day-to-day risk-taking within mandate and should know positions, P&L, limits, hedges and client obligations. A strong front office does not wait for independent risk to discover problems.
Market risk is second-line independent oversight. It measures, monitors, challenges and reports risk. It designs limit frameworks, reviews utilisation, runs stress tests, investigates breaches and escalates concerns. It must understand the business well enough to challenge intelligently. A risk team that only forwards reports is weak. A risk team that blocks without understanding business purpose is also weak. Effective challenge is informed, firm and evidence-based.
Product control independently verifies valuation and P&L. Model risk validates and governs models. Compliance monitors conduct. Operations confirms and settles trades. Finance owns official books and reporting. Internal audit provides third-line assurance over the design and operating effectiveness of controls. Senior committees approve risk appetite, major limits, model frameworks and material exceptions.
Governance evidence matters. Policies, desk mandates, limit approvals, breach logs, committee minutes, model approvals, P&L explain packs, IPV evidence, market data override logs, issue remediation and audit findings all prove whether the framework is actually operating. In banking, if a control cannot be evidenced, it is difficult to rely on it.
28. Conduct, surveillance and market abuse controls
A desk can be inside market-risk limits and still create serious conduct risk. Market abuse, benchmark manipulation, misuse of client information, inappropriate order handling, spoofing, layering, wash trades, off-market pricing, late booking, suspicious cancellations and unauthorised amendments are not solved by VaR. They need conduct controls and surveillance.
Market-risk data can support surveillance. Unusual P&L, repeated manual price overrides, trades near benchmark windows, large cancellations, backdated trades, unusual amendments, sudden position changes, limit breaches and stale booking patterns can all trigger review. Not every unusual event is misconduct, but patterns deserve attention.
Client fairness matters. If a bank sells a complex product, the customer must receive appropriate disclosure under applicable rules and bank policy. If the product is unsuitable, profitable revenue can become future conduct loss. If a dealer quotes a price, execution and markup should follow policy. If confidential client flow is misused, the damage can be severe.
For BA requirements, surveillance data should include order time, trade time, amendment time, cancellation reason, user, book, client, product, price source, benchmark window, approval, communication reference where available and exception status. Surveillance cannot work with incomplete event data.
29. Reporting and senior management information
A market-risk report should answer five questions: what risk exists, what changed, why it changed, whether it is within appetite and what action is required. Reports should show sensitivities, VaR, expected shortfall, stress losses, limit utilisation, breaches, concentrations, P&L explain, valuation issues, market data issues, model issues and commentary.
Senior management does not need trader-level detail in every pack, but it needs drivers. If VaR increased, was it new trades, higher volatility, changed correlations, model change or market data correction? If stress loss increased, which scenario and desk drove it? If P&L loss occurred, was it rates, spread, FX, volatility, carry or unexplained? If a breach occurred, is it temporary, approved, reducing or unresolved?
Reports should show data freshness and quality. A green limit based on stale data is not green. A stress report missing a product feed is not reliable. A P&L explain with a large residual should not be hidden behind a polished summary. Uncertainty must be visible.
Lineage is essential. A user should trace from report to desk, desk to book, book to trade, trade to valuation, valuation to market data and market data to source. Without lineage, management questions become slow manual investigations.
30. Data architecture for market risk
Market-risk architecture begins with trade capture. Trades flow from front-office systems into risk engines. Market data feeds curves, prices, vol surfaces, spreads and fixings. Models calculate valuation and sensitivities. Aggregation engines combine risk by hierarchy. Limit systems compare exposure against appetite. P&L explain links valuation changes to risk drivers. Reporting layers present results. Workflow tools manage breaches and exceptions.
Important data fields include trade ID, external ID, version, book, desk, trader, legal entity, product type, strategy, counterparty, notional, currency, maturity, coupon, index, strike, option type, settlement date, collateral terms, valuation model, market data set, sensitivity, P&L, limit, breach status, hierarchy and timestamp. Missing or wrong fields can change risk materially.
Data pipelines need reconciliation. Trade count from front office should match risk population. Valuation should reconcile with product control where expected. P&L explain should reconcile with finance P&L. Limit utilisation should reconcile with risk measures. Capital inputs should reconcile with trade and sensitivity sources. Exceptions should be visible and aged.
Architecture should support the right frequency. Some desks need near-real-time risk. Others can operate with end-of-day. The control frequency should match the speed and materiality of the risk. A high-volume FX options desk cannot rely only on yesterday’s risk. A small banking-book investment portfolio may not need tick-by-tick monitoring.
From transaction truth to a defensible risk decision
This illustrative architecture uses versioned trade, market-data and model snapshots. A calculation is published with its run status and coverage, not only its number. A missing feed should create an incomplete result and an exception. Approved manual estimates can support temporary decisions, but the report needs their scope and uncertainty. A threshold engine routes warnings and breaches to authorised owners; execution and recalculation prove remediation.
Market-risk measurement does not settle the underlying transaction. A securities fail can leave the booked market exposure plus an unsettled receivable or payable; a swap still needs confirmed coupons, cash settlement and collateral reconciliation. Operations’ settlement and lifecycle statuses therefore feed risk completeness checks, while official cash and securities balances reconcile through their own ledgers. Capital reporting consumes correctly scoped positions and measures; it must retain the applicable rule version rather than reuse an unlabelled management sensitivity.
31. Operational controls around market risk
Market risk depends on operational processes. Trade booking, confirmation, amendment, cancellation, lifecycle processing, settlement, collateral, market data loading, model runs, batch schedules, report publication and sign-offs all affect risk. Operational failure can create market-risk misstatement or real loss.
Late booking is a common issue. If a trade is executed but not booked, the desk may carry unreported risk. If a trade is booked to the wrong book, risk goes to the wrong limit. If a cancellation is not reflected in the risk engine, exposure is overstated. If a lifecycle event such as option exercise, coupon reset, corporate action or early termination is missed, valuation and risk can be wrong.
Batch control matters. Risk engines often run overnight. If a feed fails, the system should alert users and mark reports as incomplete. Silent fallback is dangerous. If yesterday’s data is reused, the report must say so. If a manual upload is used, approval and evidence are needed.
Operations, technology and risk should agree incident procedures. When a risk report is wrong, who is notified? Is trading restricted? Is a manual estimate produced? Is the report republished? Is the regulator notified if required? Is the issue logged and remediated? Market-risk control needs incident discipline.
32. Audit, evidence and control testing
Internal audit does not only ask whether a policy exists. It asks whether the policy is designed properly and whether it operates effectively. For market risk, audit may review desk mandates, limit approvals, breach management, market data controls, valuation controls, model governance, risk reporting, system access, change management and issue remediation.
Evidence is the practical language of audit. A limit approval should show who approved it and why. A breach should show cause, owner, approval and closure. A model should show validation and approval. A manual price override should show evidence and approver. A market data exception should show resolution. A report should show data completeness status.
Control testing should cover design effectiveness and operating effectiveness. Design effectiveness asks whether the control would work if performed. Operating effectiveness asks whether it was actually performed. A good breach workflow design is not enough if breaches are closed without evidence. A market data policy is not enough if stale prices are ignored.
A mature bank treats audit findings as control improvement, not only criticism. Repeated findings in market risk usually indicate weak ownership, weak data, weak workflow or unclear accountability. The remediation should fix root cause, not only the immediate symptom.
33. BA and testing scenarios
A practical market-risk test pack should start with trade completeness. Book a simple bond, feed it to risk, verify valuation, DV01, desk aggregation, limit utilisation and report output. Amend the maturity and verify risk changes. Cancel the trade and verify removal. Break the trade feed and confirm alert. This proves population control.
Test market data. Feed a valid curve and calculate sensitivity. Shift the curve one basis point and verify DV01 direction. Feed a stale price and confirm stale flag. Feed missing volatility and confirm exception. Override a price and verify approval. Correct a fixing and verify downstream recalculation. Market data tests are core because market data drives valuation.
Test limits. Create utilisation below warning. Then cross warning threshold. Then breach hard limit. Verify notification, owner, approval, expiry, remediation and closure. Test a breach caused by market move, a breach caused by new trade, a breach caused by data correction and a false breach caused by bad data. Each should follow defined workflow.
Test P&L explain. Move rates and verify rates P&L. Move FX and verify FX P&L. Move credit spreads and verify spread P&L. Add new trade and verify new-trade effect. Introduce unexplained P&L and verify escalation. Test product-control sign-off and finance reconciliation.
Test model governance. Use an approved model and verify output. Change model version and verify approval workflow. Use a product not approved for the model and trigger exception. Run stress scenario and store assumptions. Re-run scenario and verify reproducibility. A model-control test should leave evidence.
Test FRTB-specific flows where applicable. Verify desk mapping, standardised approach risk class mapping, sensitivities, bucket assignment, modellability data capture, NMRF classification, P&L attribution results, backtesting exceptions, default risk charge inputs and residual risk flags. Regulatory capital implementation fails most often through data and mapping weakness, not through lack of mathematical ambition.
34. Practitioner casebook
Case 1: DV01 is green but stress is red
A rates desk is within daily DV01 limit. The desk argues that the position is controlled. Stress testing shows a major loss under curve steepening because the desk is long five-year risk and short thirty-year risk. The lesson is that one sensitivity cannot represent the whole risk profile. Management should review curve bucket limits and stress appetite.
Case 2: P&L loss is not explained
A desk reports a material daily loss. P&L explain attributes only part of the loss to known market moves. Product control and risk investigate and find a trade mapped to the wrong curve and a stale volatility input. The lesson is that unexplained P&L is a control alarm, not a rounding issue.
Case 3: Market move creates a breach
A credit desk breaches spread sensitivity after market spreads widen sharply. No new trade caused the breach. The desk is not automatically at fault, but the bank is now above appetite. Management approves a short temporary excess while the desk reduces risk. The lesson is that breach cause affects response, but breach governance is still required.
Case 4: Treasury HQLA loses value
Treasury holds high-quality bonds for liquidity. Rates rise sharply and fair value falls. The bonds remain liquid, but the portfolio creates economic and accounting pressure. ALCO reviews duration appetite and hedge strategy. The lesson is that HQLA quality does not remove market risk.
Case 5: Delta hedge misses vega
An FX options desk is delta hedged. Spot movement is controlled, but volatility rises and the desk loses money. The report had focused too much on delta and too little on vega and stress. The lesson is that option books need full Greek and scenario controls.
Case 6: New product without risk readiness
A structured rates product is approved commercially, but limit systems cannot capture optionality and valuation requires manual workarounds. Risk blocks further booking until model approval, market data, P&L explain and limits are implemented. The lesson is that new product approval must include control readiness.
Case 7: Stale data hides a breach
A market data feed fails and the system carries yesterday’s price. The limit report stays green. After correction, the desk is above limit. The issue is data governance. The lesson is that stale data should create warning, not false comfort.
Case 8: Temporary excess becomes normal
A desk receives repeated temporary limit approvals over several weeks. Audit asks whether this is still temporary. Risk escalates to committee. Either appetite must formally change or exposure must reduce. The lesson is that repeated exceptions can become hidden policy drift.
Case 9: FRTB modellability changes desk economics
A desk trades a bespoke long-dated product with attractive margin. Later, key risk factors fail modellability assessment because eligible price observations are too sparse. Capital cost rises. The product remains profitable on a gross basis but unattractive after capital. The lesson is that data observability affects business strategy.
Case 10: Vendor model is treated as a black box
A bank uses a vendor model for complex valuation. The desk trusts the output, but validation evidence is weak and limitations are not understood. A market dislocation exposes model behaviour that users did not anticipate. The lesson is that vendor models still need model-risk governance.
Case 11: Collateral call creates liquidity pressure
A hedge reduces economic rate risk but moves deeply out of the money after rates move. The bank must post variation margin. Market risk shows the hedge worked economically, while liquidity risk shows cash pressure. The lesson is that hedging can transform market risk into collateral liquidity demand.
Case 12: Conduct issue hides inside normal risk numbers
A trader remains within VaR and sensitivity limits, but surveillance detects repeated trades near benchmark windows and unusual cancellations. Compliance investigates. The lesson is that market-risk limits do not replace conduct controls.
35. Source references used for this chapter
- BIS Basel Committee - Minimum capital requirements for market risk - Primary Basel source for the revised market-risk capital framework, trading-book and banking-book boundary, standardised approach, internal models approach, expected shortfall, risk factors, default risk and residual risk.
- BIS FSI - Revised market risk framework executive summary - BIS summary explaining the revised market-risk framework, expected shortfall, standardised approach, internal models, liquidity horizons and market illiquidity.
- BIS Basel Committee - Fundamental review of the trading book - Basel consultative source explaining the reform agenda behind the trading-book review, including trading-book boundary reform and movement from VaR toward expected shortfall.
- BIS Basel Framework - Core principles, market risk references - Basel supervisory principles covering market-risk governance, systems, controls, model use, limits, valuation and trading-book allocation.
- BIS Basel Framework - Market risk disclosure chapter - Basel disclosure material covering qualitative and quantitative information around market-risk models, expected shortfall, default risk and non-modellable risk factors.
- European Banking Authority - Market, counterparty and CVA risk - EBA regulatory page describing market risk, counterparty credit risk, CVA risk and EU implementation work around FRTB.
- Federal Reserve - Revised Guidance on Model Risk Management SR 26-2 - 2026 Federal Reserve supervisory letter replacing earlier SR 11-7 guidance and emphasising risk-based model risk management.
- Federal Reserve - Supervisory Guidance on Model Risk Management - Federal Reserve guidance page describing model risk, vendor model considerations, validation, ongoing monitoring and outcome analysis.
- Federal Reserve - Market Risk Management supervisory topics - Federal Reserve page linking supervisory material for market risk management, investment securities, counterparty risk and interest-rate risk management.
- OSFI CAR 2026 Chapter 9 - Market Risk - National implementation example for market-risk capital, prudent valuation and standardised approach structure.
Final takeaways
Market Risk, Limits & Controls is the bank’s discipline for turning uncertain market movement into governed decisions. It is not only VaR, expected shortfall or a daily report. It is the combined framework of desk mandate, product approval, trade capture, market data, valuation, sensitivities, P&L explain, stress testing, limits, model governance, breach escalation, surveillance, reporting, audit evidence and senior management action.
A learner should leave this chapter with a practical banking instinct. When you see a position, ask what market factor can hurt it. Ask how sensitive it is. Ask whether valuation is independent and reliable. Ask whether the trade is in the right book. Ask which limit controls it. Ask what stress scenario exposes it. Ask whether P&L is explainable. Ask whether the model is approved. Ask whether market data is fresh. Ask who owns the breach. Ask whether management has a decision to make.
That is how market risk works in the practical banking world. The bank is not trying to predict every market move perfectly. It is trying to make sure risk is known before loss, explainable after movement, controlled through appetite and escalated before small exceptions become large failures.