Quantitative Finance · Book 16 · The firm

The Desk and the Firm

The Desk and the Firm · The firm

12The Risk-Management Function

The examiner appointed in the bankruptcy of Lehman Brothers reported in March 2010 that between December 2006 and December 2007 the firm raised its firm-wide risk appetite limit three times, from $2.3 billion to $4.0 billion. The last increase was approved in January 2008 and backdated to December 2007, which removed the excesses of the intervening weeks from the record; the examiner’s advisers calculated that the method used the year before would have given a limit of about $2.5 billion. The firm’s stress tests left out its commercial real estate and private equity investments and, for a time, its leveraged loans. The numbers were there. What failed was a function that could not make them count.

12.1 Independence: where the risk function reports

A trading firm’s risk function measures the risks its businesses take, sets and polices the limits of chapter 7, and objects when the two disagree. It is the second of Book 6’s three lines of defence: the businesses own their risks, the risk function challenges them, and internal audit checks both. Its value lies entirely in the objection, and an objection is only as strong as the reporting line behind it.

Definition 12.1 (Chief risk officer, risk committee)

The chief risk officer is the executive responsible for the firm’s risk function: for setting the risk limits across the firm and monitoring compliance with them, for the policies and controls that implement the risk appetite, and for reporting breaches, deficiencies and emerging risks. The risk committee is the body, of the board or of senior management, that approves the risk policies and limits, receives the chief risk officer’s reports, and decides on the exceptions and increases the policies reserve to it.

Three things make the chief risk officer independent in practice: a reporting line that does not run through the businesses whose risk is measured, pay that does not depend on their revenue, and a direct line to the risk committee that no one in between can filter. The first is visible on an organisation chart (Figure 12.1); the others are not, and matter as much. The examiner’s report cites press reports, published before the bankruptcy, that the firm had removed its chief risk officer in 2007 because of opposition to its growing accumulation of illiquid investments; the chief risk officer had also argued for a lower limit increase at the end of 2006 than the one adopted.

An independent risk function on an organisation chart: the chief risk officer reports to both the risk committee and the chief executive (thick lines), not to the head of the businesses whose risk is measured, and challenges them from the side. Schematic.
Figure 12.1. An independent risk function on an organisation chart: the chief risk officer reports to both the risk committee and the chief executive (thick lines), not to the head of the businesses whose risk is measured, and challenges them from the side. Schematic.

As of September 2026 — The chief risk officer in US bank rules

Under the Federal Reserve’s Regulation YY (12 CFR 252.33), a US bank holding company with average total consolidated assets of $100 billion or more must maintain a risk committee of its board: an independent committee with a written charter, chaired by an independent director, meeting at least quarterly and documenting its decisions. It must appoint a chief risk officer experienced in the risks of large, complex financial firms, responsible for establishing enterprise-wide risk limits and monitoring compliance with them, whose pay must be consistent with an objective assessment of the risks taken, and who reports directly to both the risk committee and the chief executive officer. Other jurisdictions and smaller firms set their own rules; a proprietary trading firm may have no regulatory requirement at all.

Supervisors who compared major firms after the first months of the 2007 turmoil found the difference was not independence alone. The Senior Supervisors Group reported in March 2008 that at firms which avoided significant losses the risk function had independence and authority but also considerable direct interaction with senior business managers; that some firms escalated concerns about emerging risks as early as the summer of 2006, gaining up to a year; and that in others hierarchical structures filtered what reached senior management. A risk function that is independent and remote sees the numbers late and is heard little.

12.2 Committees and the risk officer’s tools

The risk function’s tools are few and blunt. It proposes the risk appetite (chapter 6) and the limit framework (chapter 7); it measures value at risk and runs stress tests (Book 6); its model validation team approves the models that produce those numbers; it signs off new products and new strategies; and it decides, or recommends, what happens when a limit is breached. Each tool works only if a trade cannot happen without it.

Definition 12.2 (Four-eyes principle)

The four-eyes principle requires that a decision or action of a defined kind (a limit increase, a model change, a new product, a payment) be approved by a second person, independent of the one who proposes or executes it, before it takes effect.

The principle is the operational form of segregation of duties (Book 6): the trader who wants a larger limit does not grant it, and the quant who changes a risk model does not validate the change. It fails when the second pair of eyes belongs to someone whose interests are the first person’s: a head of desk who approves increases for their own desk applies four eyes on paper and two in fact.

Method 12.3 (Running a risk committee)

  1. Write its charter: members, quorum, what it alone may approve (increases above a threshold, new products, model changes that move a limit measure), and how often it meets.
  2. Give it standing reports from the risk function, not from the businesses: utilisation against limits, breaches and their resolution, stress results, exceptions outstanding.
  3. Record every decision with its reason and its expiry; review expired exceptions at every meeting.
  4. Give the chief risk officer the right to escalate to the board’s committee directly, and use it.

12.3 Escalation: breaches, excesses and exceptions

Chapter 7 defined the limit breach and the difference between hard and soft limits. What happens next is the escalation procedure.

Definition 12.4 (Escalation procedure, risk exception)

An escalation procedure states, for each severity of limit breach or control failure, who must be told, within what time, who may approve a temporary increase or other exception, and what must be done if no approval is given. A risk exception is a documented, approved and time-limited departure from a limit or policy, with an owner and an expiry date.

A breach is graded by size and by duration. The chapter’s rules (Listing 12.1) grade a breach severity 1 if it exceeds the hard limit by at most 5% for at most two days, severity 3 if it exceeds it by more than 20% or lasts more than five days, and severity 2 in between. Severity 1 is reported to the head of desk the same day, severity 2 to the chief risk officer within a day, and severity 3 to the risk committee within two. There are three honest ways out of a breach: cut the position, have a temporary increase approved by someone independent, or show that the risk was mismeasured and have a corrected model validated. The same three are also the dishonest ways out, when the increase is granted to fit the position or the model is changed to fit the limit.

@dataclass(frozen=True)
class Rules:
    minor_excess: float = 0.05      # peak excess over the hard limit, as a fraction of it
    major_excess: float = 0.20
    minor_days: int = 2             # duration in days
    major_days: int = 5
    repeat_window: int = 60
    repeat_count: int = 2
    notify: dict = field(default_factory=lambda: dict(NOTIFY))


DEFAULT = Rules()


def severity(excess, days, rules=None):
    rules = rules or DEFAULT
    if excess > rules.major_excess or days > rules.major_days:
        return 3
    if excess > rules.minor_excess or days > rules.minor_days:
        return 2
    return 1


def notify(sev, rules=None):
    rules = rules or DEFAULT
    return rules.notify[sev]
Listing 12.1. The escalation rules as data: severity by size and duration, and who is told within how many business days. code/firm/escalation/firm_escalation.py
The firm-wide risk appetite limit in the Lehman examiner’s report: $2.3 billion, raised to $3.3 billion for fiscal 2007, to $3.5 billion on 7 September 2007 (the firm was over the new limit on every business day of September but one) and to $4.0 billion by an approval of 14 January 2008 backdated to 3 December 2007; the examiner’s advisers put the 2008 limit on the previous year’s method at about $2.5 billion. Source: the chapter’s ledger.
Figure 12.2. The firm-wide risk appetite limit in the Lehman examiner’s report: $2.3 billion, raised to $3.3 billion for fiscal 2007, to $3.5 billion on 7 September 2007 (the firm was over the new limit on every business day of September but one) and to $4.0 billion by an approval of 14 January 2008 backdated to 3 December 2007; the examiner’s advisers put the 2008 limit on the previous year’s method at about $2.5 billion. Source: the chapter’s ledger.

The public record (Figure 12.2) shows each of the dishonest exits. A limit raised while the firm was over it; an increase backdated so that the breach disappeared from the register; a limit recalculated with new assumptions that produced a larger number; and, before these, a large position left out of the usage calculation from May to August 2007, which kept the usage under the limit until it was included. One Quant Book 6 tells the story of a later case in which a risk model was changed while a limit was being breached. The escalation register must be built so that such patterns are visible: limits and models kept point in time, as they were known each day, and every change recorded with the day it was approved as well as the day it takes effect.

Proposition 12.5 (Waiting for the committee)

If the risk committee meets every mm-th business day and a breach opens on a day uniformly distributed over the cycle, the wait until the next meeting after the opening day is uniform on {1,…,m}\{1,\dots,m\}, with mean (m+1)/2(m+1)/2 business days.

Proof. The next meeting after day tt is day t+1+((−(t+1)) mod m)t+1+((-(t+1))\bmod m); as tt runs over a cycle, the wait 1+((−(t+1)) mod m)1+((-(t+1))\bmod m) takes each value 1,…,m1,\dots,m once. ∎

With weekly meetings the wait is three business days on average. A procedure that makes the desk wait with its breach open lengthens every breach that goes to the committee; one that makes the desk cut while it waits does not.

12.4 Tutorial: a year of breaches

Goal. Run the escalation rules over a year of limit utilisation for twenty desks, measure how breaches are resolved and how long they last, and flag the pattern of the public record. End state: a table and two charts of how breaches end (Table 12.1, Figure 12.3 and Figure 12.4).

  1. The year. fm_risk.simulate(regime) draws each desk’s value at risk against a hard limit of 100 (a persistent random walk around 75% utilisation). When a hard breach opens the desk asks for a temporary increase (probability 0.45), changes its risk model (0.08; the measured risk falls by a fifth) or cuts its position.
  2. Three regimes. The head of desk approves increases the next day; or the risk committee, meeting every fifth day, approves them with probability 0.6 and validates model changes at the meeting; or the same committee, with the desk required to cut while it waits.
  3. The register. firm.escalation.register finds every breach, grades it, classifies how it closed and flags limits raised or models changed during a breach and repeated increases (Listing 12.2).
  4. The comparison. fm_risk.compare() pools ten simulated years for each regime.
def register(expo, hard, model_days=(), rules=None):
    rules = rules or DEFAULT
    expo, hard = np.asarray(expo, float), np.asarray(hard, float)
    n_desks, n_days = expo.shape
    models = set(model_days)
    out = []
    for d in range(n_desks):
        over = expo[d] > hard[d]
        t = 0
        while t < n_days:
            if not over[t]:
                t += 1
                continue
            s = t
            while t < n_days and over[t]:
                t += 1
            peak = float(np.max(expo[d, s:t] / hard[d, s:t]) - 1)
            if t == n_days:
                how = "open"
            elif hard[d, t] > hard[d, t - 1]:
                how = "limit increase"
            elif (d, t) in models or (d, t - 1) in models:
                how = "model change"
            else:
                how = "position cut"
            b = Breach(d, s, t, peak, how, severity(peak, t - s, rules))
            if any(hard[d, k] > hard[d, k - 1] for k in range(max(s, 1), min(t + 1, n_days))):
                b.flags.append("limit raised during breach")
            if any((d, k) in models for k in range(s, min(t + 1, n_days))):
                b.flags.append("model changed during breach")
            ups = [k for k in range(1, n_days) if hard[d, k] > hard[d, k - 1] and s - rules.repeat_window <= k <= t]
            if len(ups) >= rules.repeat_count:
                b.flags.append("repeated increases")
            out.append(b)
    return out
Listing 12.2. The breach register: every run of days above the hard limit, graded, classified by how it closed and checked for red flags. code/firm/escalation/firm_escalation.py
head of deskrisk committeecommittee,
approvesapprovescut while waiting
breaches a year (20 desks)27.826.427.8
closed by a position cut (%)50.078.487.4
closed by a limit increase (%)45.314.45.4
closed by a model change (%)3.26.16.5
mean duration (days)1.151.641.25
breach-days a year31.843.534.6
severity 2 or 3 (ten years)325725
desk-days above the original limit (%)2.441.330.74
breaches flagged (%)54.723.111.9
Table 12.1. Ten simulated years of breaches on twenty desks under three approval regimes (0.7–1.4% of breaches are still open at a year end). Data: fm_risk.compare.

Most breaches are small and short: the median lasts one day in every regime, since utilisation that drifts over a limit often drifts back. The regimes differ in how the rest end (Table 12.1). When the head of desk approves increases, 45% of breaches are closed by raising the limit; breaches are the shortest, and the desks spend 2.44% of their days above the limit they started the year with. Requiring the committee’s approval cuts increases to 14% and time above the original limit to 1.33%, but breaches last longer while desks wait for a meeting (Proposition 12.5): 43.5 breach-days a year against 31.8, and more of them reach severity 2 or 3. Making desks cut while they wait keeps the committee’s control and removes the delay: 5% of breaches end with an increase, the mean duration is 1.25 days, and the desks spend 0.74% of their days above their original limits.

How breaches end under three approval regimes: ten simulated years of twenty desks each. Moving the approval of increases away from the desk moves breaches from the limit to the position. Data: fm_risk.compare.
Figure 12.3. How breaches end under three approval regimes: ten simulated years of twenty desks each. Moving the approval of increases away from the desk moves breaches from the limit to the position. Data: fm_risk.compare.
One desk around the first breach of the simulated year closed by a model change: a temporary increase to 110, a one-day lapse when it expires and a new increase, then a breach of 7.7% closed two days later by a model change that cuts the measured risk by a fifth with no change in the position. The register flags both the repeated increases and the model change. Data: fm_risk.model_change_window.
Figure 12.4. One desk around the first breach of the simulated year closed by a model change: a temporary increase to 110, a one-day lapse when it expires and a new increase, then a breach of 7.7% closed two days later by a model change that cuts the measured risk by a fifth with no change in the position. The register flags both the repeated increases and the model change. Data: fm_risk.model_change_window.

What to change next. Record each increase with its approval day and check it with firm.escalation.backdated; give the desks a position that is left out of the usage for three months and see which register metric notices it first.

12.5 What the risk officer looks for

A register that only counts breaches misses the failures of the public record, which were patterns rather than events. The risk officer looks for:

  • limits raised, or models changed, while a breach is open, and temporary increases that are renewed rather than allowed to expire;
  • changes that take effect before they were approved;
  • positions outside the measure: exposures left out of the usage calculation or out of the stress tests because they are new, illiquid or hard to model (the examiner found the firm’s stress tests excluded its commercial real estate and private equity investments);
  • limits recalculated with new assumptions that produce a larger number at the moment a larger number is needed;
  • exceptions without an owner or an expiry, and a committee that approves everything it is asked.

Definition 12.6 (Risk culture)

Risk culture is the set of norms, attitudes and behaviours in a firm that decide how risk is taken and controlled in practice: whether limits are treated as binding, whether bad news travels up quickly, and whether those who object are heard.

Culture cannot be read off a register, but its traces can: the share of breaches closed by increases, the share of flagged breaches, the time from a breach to the committee’s hearing of it, the number of exceptions past their expiry. The examiner found that management had treated the firm-wide limit as a “soft” guideline while describing it to its regulator and board as a meaningful constraint. On the question the examiner had to answer, the report found insufficient evidence that the senior officers’ conduct in managing risk fell outside the business judgement rule or was reckless or irrational: decisions that proved unwise were, legally, still decisions management was entitled to make. The lesson for a risk function is that its authority must be written into the procedure, since it cannot rely on the law to supply it after the event.

Remark 12.7 (Chapter 7’s limits and this chapter’s procedure)

Chapter 7 sized limits and priced capital as if every limit held. This chapter’s register is how a firm finds out whether they do: a limit that is raised whenever it binds is not a limit, and the capital it was meant to protect is not protected.

12.6 Build: the escalation register

Purpose. The breach register and escalation workflow as data: grading, notification, resolution tracking, audit metrics and red flags.

Interface. firm.escalation: Rules, severity, notify, hard_path (from a firm.limitalloc node and dated increases), register, stats, flagged, backdated.

Rules. A breach is a run of days above the effective hard limit; it closes by a limit increase, a model change or a position cut, in that order of precedence; flags are recorded, never cleared; limits and models are point in time.

Acceptance tests. code/firm/escalation/tests/: the severity grid; one breach of each resolution type on hand-made data; repeated increases; a backdated change.

Stretch. Notification deadlines checked against a log of who was told when; exceptions with owners and expiry dates; a daily report for the risk committee.

Sources and further reading

  • Report of Anton R. Valukas, Examiner, In re Lehman Brothers Holdings Inc., No. 08-13555 (Bankr. S.D.N.Y.), 11 March 2010, volume 1.
  • 12 CFR 252.31 and 252.33 (Regulation YY).
  • Senior Supervisors Group, Observations on Risk Management Practices during the Recent Market Turbulence, 6 March 2008.

12.7 Exercises

Exercise 12.1 ★

Grade under the chapter’s rules a breach of 3% lasting one day, one of 10% lasting one day and one of 3% lasting six days, and say who is told and by when.

Solution

Solution of Exercise 12.1.

Severity 1 (the head of desk, the same day); severity 2 (the chief risk officer, within a business day); severity 3 (the risk committee, within two business days).

Exercise 12.2 ★

By what percentage did the firm-wide limit of Figure 12.2 rise from November 2006 to December 2007? By how much did the 2008 limit exceed the one the previous year’s method gave?

Solution

Solution of Exercise 12.2.

From $2.3 to $4.0 billion: 74%. The 2008 limit was $1.5 billion, or 60%, above the $2.5 billion of the previous year’s method.

Exercise 12.3 ★

A risk committee meets every fifth business day. How long, on average, does a desk wait for it after a breach opens? And with meetings every tenth day?

Solution

Solution of Exercise 12.3.

(5+1)/2=3(5+1)/2=3 business days; (10+1)/2=5.5(10+1)/2=5.5 with meetings every tenth day.

Exercise 12.4 ★★

Why is a backdated limit increase a red flag even when the increase itself is justified?

Solution

Solution of Exercise 12.4.

It rewrites the record: the breaches between the effective day and the approval day disappear from a register that uses the effective limit, so no one can later see that the firm was over its limit or that the increase was granted to cover a breach. A register must keep limits as known each day, with approval and effective dates.

Exercise 12.5 ★★

In Table 12.1, why do breaches last longer when the committee approves increases, and why does requiring the desk to cut while it waits bring the duration back down?

Solution

Solution of Exercise 12.5.

Desks that ask for an increase wait for the next meeting, three business days on average, with the breach open. When they must cut while they wait, most breaches close before the meeting and the request lapses: the mean duration falls from 1.64 to 1.25 days.

Exercise 12.6 ★★

Explain why a head of desk approving increases for their own desk satisfies the four-eyes principle on paper but not in fact.

Solution

Solution of Exercise 12.6.

Two people are involved, but the approver is not independent: the head of desk is paid on the desk’s results and wants the same outcome as the trader. The second pair of eyes must belong to someone whose interests differ, such as the risk function or the committee.

Exercise 12.7 ★★★

Coding. Run fm_risk.run for the desk regime and list the breaches of desk 19 before its model change. Which are flagged, and why?

Solution

Solution of Exercise 12.7.

Five breaches, at −51-51, −27-27, −9-9, −5-5 and −2-2 business days from the change. The one at −27-27 is flagged for a limit raised during a breach; the one at −5-5, when the first increase expired, for a limit raised and repeated increases; the one at −2-2, closed by the model change, for a model changed during a breach and repeated increases. The other two closed by cuts and are not flagged.

Exercise 12.8 ★★★

Find the flaw. “Our risk function is independent: the chief risk officer reports to the head of trading, who understands the risks better than anyone.”

Solution

Solution of Exercise 12.8.

The head of trading is the head of the businesses whose risks are measured: the objection runs through the person it objects to, whose pay depends on the revenue the limits constrain. Independence needs a reporting line to the risk committee and the chief executive, not expertise in the line manager.

12.8 Problem: Raised to Fit

Problem 12.1

Weekend problem — raised to fit

A new chief risk officer inherits a firm where heads of desk approve their own temporary increases, and must propose a new escalation procedure to the risk committee.

Part I — The function.

  1. Define the chief risk officer and the risk committee.
  2. What three things make the chief risk officer independent in practice?
  3. What did the Senior Supervisors Group find distinguished the firms that avoided significant losses in 2007?
  4. Define the four-eyes principle and give two decisions it should cover.

Part II — The public record.

  1. Give the path of the firm-wide limit in the examiner’s report, with the dates.
  2. What did the backdating of January 2008 do to the record of breaches?
  3. What did the stress tests leave out, and what position was left out of the usage calculation?
  4. What did the examiner conclude on the business judgement rule, and what does that mean for a risk function?

Part III — The register.

  1. Define an escalation procedure and a risk exception.
  2. State the chapter’s severity rules and grade three breaches of your choice.
  3. State and prove Proposition 12.5.
  4. Give the shares of breaches closed by increases under the three regimes.
  5. Give the mean duration, breach-days a year and time above the original limit under each.
  6. What does the register flag, and what share of breaches is flagged under each regime?

Part IV — The proposal.

  1. Why is the median duration the same in every regime, and what statistic shows the difference?
  2. Describe the model-change episode of Figure 12.4.
  3. What point-in-time records must the register keep?
  4. Define risk culture and name three register metrics that trace it.
  5. State the named result: the share of breaches resolved by raising the limit, the median time to resolution, and how both move when increases need the risk committee’s approval.
  6. In two sentences, write the new escalation procedure.
Solution

Solution of Problem 12.1.

  1. See Definition 12.1.
  2. A reporting line outside the businesses, pay independent of their revenue, and direct access to the risk committee.
  3. Independence and authority combined with direct interaction with business managers, early escalation (some from the summer of 2006), and information not filtered by hierarchy.
  4. See Definition 12.2; limit increases and changes to risk models.
  5. $2.3 billion; $3.3 billion for fiscal 2007 (end of 2006); $3.5 billion on 7 September 2007; $4.0 billion approved on 14 January 2008, effective 3 December 2007.
  6. It removed from the record the excesses over the $3.5 billion limit between 3 December and the approval.
  7. Commercial real estate, private equity and, for a time, leveraged loans; a $2.3 billion bridge equity position, from May to August 2007.
  8. Insufficient evidence that conduct was outside the business judgement rule or reckless: unwise decisions were still management’s to make. The risk function’s authority must be written into procedure beforehand.
  9. See Definition 12.4.
  10. Severity 1 up to 5% and two days, 3 above 20% or five days, 2 between; for example 3%/1 day, 10%/1 day and 3%/6 days give 1, 2 and 3.
  11. See Proposition 12.5.
  12. 45.3%, 14.4% and 5.4%.
  13. 1.15, 1.64 and 1.25 days; 31.8, 43.5 and 34.6 breach-days a year; 2.44%, 1.33% and 0.74% of desk-days.
  14. Limits raised or models changed during a breach, and repeated increases; 54.7%, 23.1% and 11.9%.
  15. Most breaches are one-day drifts that reverse whatever the regime; the mean duration, the breach-days and the severity counts show the difference.
  16. A temporary increase that expires and is renewed at once, then a breach of 7.7% closed by a model change that lowers the measured risk by a fifth without any change in the position.
  17. Limits and models as known each day, with approval and effective dates for every change, and every flag, never cleared.
  18. See Definition 12.6; the share of breaches closed by increases, the flagged share, exceptions past their expiry.
  19. Head of desk approving: 45.3% of breaches closed by raising the limit, median one day (mean 1.15). Committee approving: 14.4%, median one day but mean 1.64 and more breach-days; with cutting while waiting, 5.4% and a mean of 1.25.
  20. Increases and model changes need the risk committee’s approval, with the desk cutting towards its limit while it waits; every change is recorded with its approval date, and repeated increases and changes during a breach go to the committee as red flags.

12.9 Interview questions

Interview question 12.1 ★ risk

To whom should a chief risk officer report, and why?

Solution

Solution of Interview question 12.1.

To the risk committee of the board and to the chief executive, not to the head of the businesses whose risk it measures, so that objections cannot be filtered or overruled by those they concern.

What the interviewer is looking for: independence of the reporting line and direct access to the board.

Interview question 12.2 ★ trader, risk

Your desk breaches its VaR limit by 3% at the close. What happens next?

Solution

Solution of Interview question 12.2.

It is logged and graded; the head of desk is told the same day; the desk cuts or asks for a temporary increase approved independently, with an expiry; if it persists, it is escalated to the chief risk officer.

What the interviewer is looking for: the procedure, not only the cut.

Interview question 12.3 ★★ risk

A desk asks for its third temporary increase in two months. What do you do?

Solution

Solution of Interview question 12.3.

Refuse to renew by default and take it to the committee: either the limit is wrong and should be reset through the annual process, or the desk is using increases to carry more risk than it was given.

What the interviewer is looking for: repeated increases as a red flag.

Interview question 12.4 ★★ risk, researcher

A desk proposes a new VaR model that lowers its measured risk by 20% while it is in breach. How do you handle it?

Solution

Solution of Interview question 12.4.

The breach stands under the old model until the new one is independently validated; validation checks the model on its merits, not on its effect, and the change is recorded with its date and flagged.

What the interviewer is looking for: validation independent of the breach.

Interview question 12.5 ★★ risk

What would you look for in a firm’s breach register to judge its risk culture?

Solution

Solution of Interview question 12.5.

The share of breaches closed by increases, changes made during breaches, backdated changes, exceptions past expiry, and the time for bad news to reach the committee.

What the interviewer is looking for: patterns, not counts.

Interview question 12.6 ★★★ risk, developer

Design the data model of a breach register that cannot be rewritten after the fact.

Solution

Solution of Interview question 12.6.

Append-only tables of limits, model versions and exposures, each with effective and recorded timestamps; breaches derived from them as of each day; approvals as separate signed records; flags stored and never deleted.

What the interviewer is looking for: bitemporal records and append-only storage.

Terms defined in this chapter

See all 2333 terms in the glossary