FRM Part 2 – Market Risk · FRM

The usual summary of what happened to Value at Risk after 2008 is that regulators lost faith in it and replaced it with expected shortfall. That is roughly the destination and almost none of the journey, and the journey is what an FRM candidate is examined on.
VaR was not abandoned. It was demoted, patched, partially replaced for capital purposes, and retained for the one job expected shortfall cannot do. Understanding which of those happened, and why each one happened when it did, is the difference between reciting a conclusion and being able to defend it.
The 1996 Market Risk Amendment to Basel I is where this begins. It allowed banks to use their own internal models to set market risk capital, subject to a specified shape: a 99% one tailed confidence level, a ten day holding period, at least one year of historical data, and a multiplication factor of at least three applied to the model output.
That multiplier of three is the part worth pausing on. Regulators were prepared to let banks compute their own capital requirement and then immediately tripled the answer. The framework never claimed the model was accurate. It treated the model as a ranking device and used the multiplier to buy a margin of safety on top.
What went wrong was not that banks used a model regulators distrusted. It was that a number designed as a ranking device was progressively used as something else: a limit for traders, a headline disclosure for investors, an input to performance measurement, and in many institutions the single figure that senior management looked at. A measure calibrated to describe ordinary days became the institution’s answer to the question of how much it could lose.
Four distinct failures showed up between 2007 and 2009, and they are worth separating because the regulatory response addressed them in a specific order.
The lookback made the number procyclical. A VaR estimated from one year of recent data is low when the recent year was calm. Low VaR means low capital, which supports more leverage, which raises the risk actually being carried at exactly the moment the measure reports that risk is falling. When volatility returned, the same mechanism reversed and capital requirements rose into a market where raising capital was hardest. The measure amplified the cycle it was supposed to monitor.
The measure said nothing about the tail. VaR at 99% is a threshold. It states a loss level that should be exceeded on about one day in a hundred, and it is entirely silent on how far beyond that level the loss goes when it does. Two portfolios with identical VaR can have completely different losses in the one percent of days that matter. In 2008 the difference between those portfolios was the difference between a difficult year and insolvency.
VaR is not subadditive. Under the standard axioms of a coherent risk measure, combining two portfolios should never produce more risk than the sum of their separate risks, because diversification cannot be penalised. VaR can violate this, particularly with discontinuous payoffs of the kind that fill a credit portfolio. Aggregating desk level VaR to a firm level number was therefore not guaranteed to be conservative, and a bank could reduce measured risk by splitting a book rather than by reducing exposure.
The ten day horizon assumed a liquidity that vanished. A ten day holding period embeds the assumption that a position can be exited or hedged within ten days. For structured credit in 2008 there was no bid at any horizon. The horizon was not conservative, it was fictional, and a single horizon applied to every asset class was the mechanism by which the least liquid positions were treated as though they were the most liquid.
Only one of these four is a criticism of VaR as a statistic. Non subadditivity is a genuine mathematical defect. The other three are failures of calibration and use: a short lookback, a single liquidity horizon, and an institution treating a threshold as though it were a worst case. This distinction is why the regulatory response fixed the calibration first and changed the measure second.
The Basel Committee published its revisions to the market risk framework in July 2009, with implementation by the end of 2011. This package is usually called Basel 2.5, and it is best understood as a repair to the calibration rather than a replacement of the measure.
Its central instrument was stressed VaR: the same model, run on a continuous twelve month period of significant stress relevant to the bank’s portfolio, rather than on the most recent year. The capital charge became the sum of two terms, each taking the higher of the latest observation and a multiple of a sixty day average.
Capital charge = max(VaRt-1, mc × VaRavg 60) + max(sVaRt-1, ms × sVaRavg 60)
where mc and ms are at least 3, raised by a backtesting add on of up to 1
Adding stressed VaR removed the procyclicality directly. A stress period fixed by reference to a historical window of turmoil does not fall when markets are calm, so the capital requirement stops declining simply because nothing has gone wrong recently. Because the two terms are added rather than averaged, market risk capital rose substantially for trading heavy banks, which was the intended outcome. The Incremental Risk Charge, covering default and migration risk in the trading book, arrived in the same package.
What Basel 2.5 did not do was change the measure. VaR remained a threshold, still silent about the tail beyond it and still not subadditive. The Committee had bought time and fixed the most urgent defect, which was that the number fell when it should have risen.
The Fundamental Review of the Trading Book is the structural answer. First published as a standard in January 2016 and substantially revised in January 2019, it rebuilds the market risk framework rather than adjusting it.
Four changes matter for this discussion. Expected shortfall at 97.5% replaces VaR at 99% as the internal models measure, so the capital number now reflects the average loss in the tail rather than the point at which the tail begins. The measure is calibrated to a period of stress, carrying the Basel 2.5 insight forward permanently. The single ten day horizon is replaced by liquidity horizons of 10, 20, 40, 60 and 120 days assigned by risk factor, so that a position in an illiquid credit spread is no longer capitalised as though it could be sold in a fortnight. And model approval moves to the trading desk level, with each desk required to pass a profit and loss attribution test and backtesting to keep its approval, rather than a single firm wide permission.
| Feature | Pre 2008 (1996 Amendment) | Basel 2.5 (2009) | FRTB (2016 and 2019) |
|---|---|---|---|
| Measure | VaR at 99% | VaR plus stressed VaR, both at 99% | Expected shortfall at 97.5% |
| Calibration period | Recent history, minimum one year | Recent history plus a 12 month stress window | Stress period, permanently |
| Horizon | 10 days for everything | 10 days for everything | 10 to 120 days by risk factor liquidity |
| Model approval | Firm wide | Firm wide | Desk by desk, with attribution tests |
| Tail beyond the threshold | Not measured | Not measured | Measured |
The obvious question is why the confidence level fell from 99% to 97.5% at the same moment the framework was supposed to become more conservative. Lowering a confidence level looks like a weakening, and it is not one.
The Committee chose 97.5% because, under a normal distribution, expected shortfall at that level produces almost exactly the same number as VaR at 99%. The calibration was deliberately set so that the switch would not by itself change capital requirements for a bank whose losses really were normally distributed. Everything the change does, it does through the fat tail.
A trading book of $500 million has a daily volatility of 1.2%, so one standard deviation of daily profit and loss is $6 million. Compare the two measures under a normal distribution and under a fat tailed one.
Answer: the switch to expected shortfall is calibrated to be neutral when the tail is well behaved and to bite when it is not. That is precisely the property the pre 2008 framework lacked, because VaR at 99% returns a threshold whether the tail beyond it is thin or catastrophic.
Expected shortfall also satisfies subadditivity, so aggregating desk level numbers to a firm level figure can no longer produce the perverse result that combining two books reduces measured risk. That closes the one genuine mathematical defect from the list in Section 2.
VaR did not disappear, and candidates lose marks by writing as though it did.
The most important survival is in backtesting. Expected shortfall is difficult to backtest directly, because it is a conditional average rather than a quantile and there is no simple count of observations that either did or did not breach it. VaR has exactly that property: you count exceptions and compare the count with what the confidence level predicted. So under FRTB the capital number is expected shortfall while the validation of the model is still performed on VaR, at desk level, at 97.5% and 99%.
The Basel traffic light approach that governs this is unchanged in structure. Over 250 trading days at 99% confidence, the expected number of exceptions is 2.5.
| Zone | Exceptions | Multiplier | Consequence |
|---|---|---|---|
| Green | 0 to 4 | 3.00 | Model accepted |
| Yellow | 5 to 9 | 3.40 to 3.85 | Scaled add on, supervisory scrutiny |
| Red | 10 or more | 4.00 | Model presumed deficient |
VaR also survives everywhere outside regulatory capital. It remains the common language of trading limits, internal risk reporting and disclosure, because a single threshold number is easier to set a limit against and easier to explain than a conditional average. What changed is its status. Before 2008 VaR was the answer. Now it is one input, sitting alongside stress testing and scenario analysis, which the crisis promoted from a supplementary exercise to a central one precisely because they do not depend on the historical distribution being a good guide to the next event.
The framework is settled on paper and still arriving in practice. FRTB has been repeatedly delayed across major jurisdictions, largely because no supervisor wants its banks to carry the higher trading book capital before competitors in other markets do.
The European Commission adopted targeted amendments in June 2026 setting implementation from 1 January 2027, together with a temporary multiplier running through 2029 to soften the capital impact while other jurisdictions catch up. The stated reason is the international level playing field rather than any doubt about the measure itself, which is a useful thing for a candidate to notice: the disagreement is about timing and competitiveness, not about whether expected shortfall is the better measure.
Questions on this material almost never ask what changed. They ask why. Be able to say that stressed VaR fixed procyclicality without changing the measure, that expected shortfall fixed tail blindness and non subadditivity, that liquidity horizons fixed the fictional ten day exit, and that VaR was retained for backtesting because expected shortfall cannot be backtested by counting exceptions. Four failures, four specific fixes, and one deliberate retention.
The larger lesson is the one worth carrying past the exam. VaR did not fail because the mathematics was wrong. It failed because a number that described ordinary days was asked to describe an extraordinary one, and because an institution that reports a single figure will eventually manage to that figure. Expected shortfall is a better measure. It is not a measure that would have prevented 2008 on its own, and no framework built on historical distributions ever will be. That is what stress testing is for.
It proved that VaR was being asked the wrong question. Three of its four failures in 2008 were failures of calibration and use rather than of the statistic: a one year lookback that fell when markets were calm, a single ten day horizon that assumed liquidity, and institutions treating a threshold as a worst case. Only non subadditivity is a genuine mathematical defect, and that is the one expected shortfall fixes.
Stressed VaR is the same model run on a continuous twelve month period of significant financial stress relevant to the bank’s portfolio, rather than on recent history. Basel 2.5 introduced it in 2009 to remove procyclicality. A stress window fixed in the past does not fall when current markets are calm, so the capital requirement stops declining simply because nothing has gone wrong recently.
Because the two measures are different objects. Under a normal distribution, expected shortfall at 97.5% is about 2.338 standard deviations and VaR at 99% is about 2.326, so the switch is deliberately close to capital neutral for a well behaved distribution. The extra conservatism appears only where the tail is fat, which is exactly where the old framework was blind.
Yes, in two places. Under FRTB it is still the backtesting instrument at desk level, because expected shortfall cannot be validated by simply counting exceptions the way a quantile can. Outside regulatory capital it remains the working language of trading limits and internal reporting, since a single threshold is easier to set a limit against than a conditional average.
FRTB replaces the single ten day holding period with horizons of 10, 20, 40, 60 and 120 days assigned according to how liquid each risk factor is. The pre crisis framework capitalised an illiquid structured credit position as though it could be exited in a fortnight, which was the mechanism by which the least liquid exposures were treated as the most liquid.
Not uniformly. Implementation has slipped repeatedly across major jurisdictions, with each supervisor reluctant to impose higher trading book capital ahead of others. The European Commission adopted amendments in June 2026 setting an implementation date of 1 January 2027 with a temporary multiplier running through 2029. The delays concern competitive timing rather than any dispute about the measure.
Loading comments...
Add your Thoughts: