---
title: "Bank Quant"
book: "The Industry: Firms, Roles and Careers"
subject: quant
language: en
chapter: 18
exercises: 8
source: https://one-course.com/books/quant/17/en/chapter/18-bank-quant
---

# Chapter 18 — Bank Quant

On 4 April 2011 the Federal Reserve and the Office of the Comptroller of the Currency told US banks that “validation should be done by people who are not responsible for development or use and do not have a stake in whether a model is determined to be valid”. The United Kingdom’s regulator wrote the same principle into its own statement, in force from 17 May 2024, and the European Central Bank’s guide to internal models grades how far apart the two groups must sit. On 17 April 2026 the US agencies replaced their 2011 guidance with a shorter, risk-based text that keeps the idea. Every model a bank uses now has an owner, a developer and a validator, and a bank quant’s job title usually says which of the three the quant is. This chapter describes the four bank-quant jobs and the valuation-adjustment quant who sits between them, checks a reporting line against the supervisors’ tests, and estimates how many validators a bank’s model inventory employs.

| **Role cards: the four bank quants** |
| --- |
|  | [desk strategist](#def-in-bank-quant-strat) | [library quant](#def-in-bank-quant-library) | [risk quant](#def-in-bank-quant-risk) | [model validator](#def-in-bank-quant-validator) |
| sits with | a trading desk | a central analytics group | the risk function | model risk management |
| ships | pricing and risk tools for the desk | the pricing library | risk and capital models | validation reports and findings |
| P&L | supports the desk’s | none | none | none |
| reports to | head of the desk | head of analytics | chief risk officer | head of model risk |
| codes in filings | 13-2099.01, 15-2041 | 13-2099.01, 15-1252 | 13-2054, 13-2099.01 | 13-2054, 13-2099.01, 15-2041 |
| taught in | Book 5, ch. 27; Book 9, ch. 24, 28 | Book 5, ch. 28; Book 6, ch. 29 | Book 6, ch. 21, 23 | Book 6, ch. 26; Book 12, ch. 21 |

## 18.1 Desk strategist

**Definition 18.1 (Desk strategist).**

A *desk strategist* is a quantitative analyst who sits with one of a bank’s trading desks and builds the models, analytics and tools that the desk’s traders and salespeople use to price, hedge and manage their positions and to answer clients.

Banks name the job differently. Goldman Sachs calls its quantitative staff strats and describes them in a job posting: “quantitative strategists are the cutting edge of our businesses, solving real-world problems through a variety of analytical methods”; “Desk strats sit on trading floors and provide value for both internal & external clients through cutting-edge models, predictive analytics, and high-quality trading tools.” Other banks say desk quant, front-office quant or quantitative analyst on the desk; the work is the same.

What the work consists of depends on the desk.

- **On an options or structured-products desk** (Book 5, chapter 27; Book 9, chapter 28) the strategist prices new payoffs, explains the desk’s risk to the traders, and finds where the desk’s model misses a risk the book carries.
- **On a flow desk** (Book 9, chapter 24) the strategist builds the quoting and hedging tools of electronic market making: pricers that answer client requests in milliseconds, inventory skews, hedging rules.
- **On a central risk book** (Book 9, chapter 25) the strategist nets the flows of several desks and decides what to internalise and what to hedge outside.

A [desk strategist](#def-in-bank-quant-strat) does not own the desk’s profit and loss, but works close to it: a mispriced trade or a missing hedge shows up in the next day’s profit and loss explain (Book 6, chapter 27). The role’s feedback is fast, and its pay tends to follow the desk’s year (chapter 13).

## 18.2 Library quant

**Definition 18.2 (Library quant).**

A *library quant* is a quantitative analyst who builds and maintains a bank’s shared pricing and risk library: the numerical methods, models and interfaces that front-office tools, risk systems and valuation controls call, released under version control and tested against independent benchmarks.

A bank that prices the same swap in its trading system, its risk engine and its month-end valuation wants one implementation of the swap, not three that disagree. The library is that implementation: curve construction, the option models, Monte Carlo and lattice engines, calibration routines, and the data structures that describe trades (Book 5, chapter 28, builds a small one; Book 6, chapter 29, runs a risk engine on it). QuantLib, “A free/open-source library for quantitative finance”, shows the shape of such a library in public; a bank’s own library is private and much larger.

The [library quant](#def-in-bank-quant-library)’s product is software, and the role sits between the [desk strategist](#def-in-bank-quant-strat) and the quantitative developer of chapter 19: the quant chooses the mathematics and writes much of the numerical code; developers build the systems around it. What the [library quant](#def-in-bank-quant-library) ships reaches every desk at once, so the work runs on releases, regression tests and benchmark comparisons rather than on a trader’s request of the morning; and each change to a model the bank uses goes to the validators before it is released.

## 18.3 Risk quant

**Definition 18.3 (Risk quant).**

A *risk quant* is a quantitative analyst in a bank’s risk function who builds the models that measure the bank’s risk and its capital: value at risk and expected shortfall, stress scenarios, counterparty exposure, credit-risk parameters, and the models of the internal models approach.

The [risk quant](#def-in-bank-quant-risk) works for the chief risk officer, not for a desk, and the models serve limits, capital and the board’s view of risk rather than prices. The work is taught across Book 6: market-risk measures (chapter 21), stress testing (chapter 22), capital for trading books under the internal models approach (chapter 23), counterparty exposure (chapter 17) and margin models (chapter 25). Two features separate it from the [desk strategist](#def-in-bank-quant-strat)’s. First, many of its models need a supervisor’s approval, and changing one is a regulatory event, not a release. Second, its consumers are risk managers, finance and supervisors, so the model must be explained as much as run. A bank that uses the internal models approach needs its risk models to pass the backtesting and profit-and-loss attribution tests of Book 6, chapter 23, desk by desk, and the [risk quant](#def-in-bank-quant-risk) is the person who answers when a desk fails them.

## 18.4 Model validator

**Definition 18.4 (Model validator).**

A *model validator* is a quantitative analyst in a bank’s model risk management function who reviews models built by others, independently of their developers and owners: conceptual soundness, implementation, data, performance and limitations, and who records findings that the developers must resolve before or after the model is approved for use.

Model validation, model risk management, the model inventory, model tiering and effective challenge are defined in Book 6, chapter 26, and the model owner in Book 12, chapter 21. This section is about the person. The validator’s work is to re-derive, re-implement and break other people’s models: to build an independent benchmark of a pricer and compare it over a grid of inputs, to test a risk model’s outcomes against realised losses, to read the documentation and find what it does not say. Its product is a validation report, a tier assessment and a list of findings with deadlines. Some banks recruit both tracks through one graduate programme; one describes its quantitative finance programmes this way: “You’ll help develop or validate mathematical models, methodologies, and tools used throughout the firm.”

What makes the validator’s position unusual is that the supervisors specify where it sits.

- **US, 2011–2026.** The 2011 guidance required that validators “not have a stake in whether a model is determined to be valid”, added that “While independence may be supported by separation of reporting lines, it should be judged by actions and outcomes”, and asked banks to review each model “at least annually”.
- **US, since 17 April 2026.** The revised guidance asks for effective challenge by people with “sufficient independence to maintain objectivity, as well as the organizational standing and influence to effect any change”, names the “misalignment of incentives between different reporting lines, such as model development and validation groups” as a conflict to manage, and lets the timing and frequency of validation vary with the model.
- **UK, since 17 May 2024.** Firms with internal-model approval are “expected to demonstrate independence through separate reporting lines for [model validators](#def-in-bank-quant-validator) and model developers and owners”.
- **Euro area.** The ECB’s guide lists three arrangements, from most to least robust, and expects large and complex institutions to use the first ( [Figure 18.1](#fig-in-bank-quant-org) ).

**Definition 18.5 (Independence arrangement).**

For a validator and a developer, the arrangements of the ECB guide are: (a) two units reporting to different members of senior management; (b) two units reporting to the same member of senior management; (c) separate staff within one unit. A validator who reports, directly or through a manager, to the model’s developer or owner is not independent at all.

**As of September 2026 — Model risk rules that shape the validator’s job.**

United States: SR 11-7 (4 April 2011) and OCC Bulletin 2011-12 were superseded on 17 April 2026 by the Federal Reserve, OCC and FDIC’s revised guidance on model risk management (SR 26-2; OCC Bulletin 2026-13), “expected to be most relevant to banking organizations with over $30 billion in total assets”; it sets no “enforceable standards or prescriptive requirements” and leaves generative and agentic AI models outside its scope. United Kingdom: PRA SS1/23, in force from 17 May 2024, for banks and investment firms with internal-model approval; tiering by materiality and complexity; separate reporting lines for validators. Euro area: ECB guide to internal models, release 4.1 of 26 June 2026 (release 4.0 of 28 July 2025): an initial and then an annual internal validation of every internal model; arrangements (a), (b) and (c).

![An illustrative bank organisation and four validator–developer pairs (dashed), graded by firm.roles.independence: (a) different members of senior management; (b) different units under one senior manager; (c) separate staff in one unit; “fail”: the validator reports to the owner of the model it reviews. Senior management here is the chief risk officer and the head of markets. Data: in_bankquant.org_cases.](https://one-course.com/images/onecourse/chapters/quant-17/in-bank-quant/fig-51d59abe05cf.svg)

***Figure 18.1.** An illustrative bank organisation and four validator–developer pairs (dashed), graded by `firm.roles.independence`: (a) different members of senior management; (b) different units under one senior manager; (c) separate staff in one unit; “fail”: the validator reports to the owner of the model it reviews. Senior management here is the chief risk officer and the head of markets. Data: `in_bankquant.org_cases`.*

## 18.5 Valuation-adjustment quant

The desk that manages a bank’s credit, funding and capital valuation adjustments (Book 6, chapter 20) needs quants of its own, and they do not fit the four cards neatly. They build exposure simulations over the whole portfolio, like a [risk quant](#def-in-bank-quant-risk); they price the adjustments that are charged to trading desks, like a [desk strategist](#def-in-bank-quant-strat); their numbers go into the bank’s accounts, so product control (Book 6, chapter 27) and the validators review them. The job needs the broadest modelling of the bank quants (every asset class’s dynamics in one simulation) and the most computing, and it is where a [risk quant](#def-in-bank-quant-risk) most often moves to the front office, or the reverse (chapter 28).

## 18.6 Who they answer to and what they ship

The four cards differ most in whom the quant answers to, and that decides what counts as good work.

| role | judged on | what goes wrong |
| --- | --- | --- |
| [desk strategist](#def-in-bank-quant-strat) | the desk’s use of the tools; pricing and hedging that hold up | a model that suits the desk better than the risk |
| [library quant](#def-in-bank-quant-library) | correctness, speed, stability across releases | a change that moves every desk’s numbers at once |
| [risk quant](#def-in-bank-quant-risk) | capital, limits and supervisory tests passed | a model tuned to the test rather than the risk |
| [model validator](#def-in-bank-quant-validator) | findings that matter, raised in time | a review that affirms what it was shown |
| XVA quant | adjustments that match the market’s and the accounts’ | an exposure model too slow to run daily |

The validators’ number is a design choice for the bank, and a large one. It follows from the inventory of models, their tiers and the review cycle the bank’s policy sets for each tier.

**Method 18.6 (Validation workload).**

Let the inventory hold $n_t$ models of tier $t$; a full validation of a tier-$t$ model take $F_t$ hours and a periodic review $R_t$ hours; tier $t$ be fully revalidated every $k_t$ years and reviewed in the other years; and a share $c$ of all models change materially each year and be fully validated again. The hours a year are

$$
H=\sum_t n_t\left(\frac{F_t}{k_t}+R_t\Bigl(1-\frac{1}{k_t}\Bigr)+c\,F_t\right),
$$

and the validators needed are $H/h$ for $h$ productive hours a validator a year.

**Example 18.7 (An inventory of 1 000 models).**

Score each model 1 to 3 for materiality, complexity and uncertainty, each score drawn with probabilities 0.5, 0.3 and 0.2, and tier it with Book 6’s rule (twice the materiality score plus the other two: tier 1 at 10 or more, tier 2 from 7, tier 3 below), which sets revalidation every one, two and three years. The expected inventory is 102 tier-one, 403 tier-two and 495 tier-three models. With the illustrative hours $F=(400,160,60)$, $R=(40,16,8)$, $c=0.10$ and $h=1\,600$, the inventory needs 102 302 hours a year, or 63.9 validators. Tier-one models are 10.2% of the inventory and take 43.9% of the hours.

| tier | models | hours a year | share of hours |
| --- | --- | --- | --- |
| 1 | 102 | 44 880 | 43.9% |
| 2 | 403 | 41 912 | 41.0% |
| 3 | 495 | 15 510 | 15.2% |

![Validators needed for an inventory of 1 000 models as the tier-one share rises (tier-three models become tier-one), with the example’s hours and cycles. The hours are illustrative; the slope, about 2.6 validators for each percentage point of tier-one models, is what the tiering decision costs. Data: in_bankquant.curve.](https://one-course.com/images/onecourse/chapters/quant-17/in-bank-quant/fig-af0b2ce9f14f.svg)

***Figure 18.2.** Validators needed for an inventory of 1 000 models as the tier-one share rises (tier-three models become tier-one), with the example’s hours and cycles. The hours are illustrative; the slope, about 2.6 validators for each percentage point of tier-one models, is what the tiering decision costs. Data: `in_bankquant.curve`.*

Two conclusions survive any reasonable choice of hours. The tiering rule sets the size of the validation function: moving one model from tier three to tier one adds 409 hours a year, a quarter of a validator. And the revised US guidance, which lets the frequency of validation vary with the model, moves effort from the many small models to the few large ones; the euro-area rule of an annual validation for every internal model does the opposite for capital models.

## 18.7 Pay: what the filings show for bank quants

The labour condition applications of chapter 14 do not split bank quants into the four families: job titles vary too much between banks, and the family “[quantitative researcher](https://one-course.com/books/quant/17/en/chapter/17-quantitative-researcher#def-in-quant-researcher-def) or analyst” at banks gathers most of them, with a separate family for risk titles. The occupational survey adds the financial risk specialists (13-2054) by industry.

**As of September 2025 — What bank quants are paid: the public evidence.**

US labour condition applications of the nine sourced bank employers, offered base: “[quantitative researcher](https://one-course.com/books/quant/17/en/chapter/17-quantitative-researcher#def-in-quant-researcher-def) or analyst” family, median $128 300 in fiscal 2021 (895 applications) and $158 100 in fiscal 2025 (825); by [wage level](https://one-course.com/books/quant/17/en/chapter/14-pay-levels-by-role-firm-type-and-seniority#def-in-pay-levels-by-role-firm-type-and-seniority-soc) in fiscal 2025 $88 300 (I), $145 300 (II), $179 335 (III), $200 000 (IV). Risk titles, fiscal 2025: median $136 776 (380 applications, 5 employers). Occupational survey, May 2025, financial risk specialists: banks (credit intermediation) median $108 170, 10th–90th percentile $62 620–187 490 (17 810 employed); securities industry median $133 070, $83 230–219 990 (9 840). [Base salary](https://one-course.com/books/quant/17/en/chapter/13-how-pay-works#def-in-how-pay-works-base) only.

![Bank quants’ base pay in two sources: offered base in fiscal 2025 labour condition applications (“filings”) and the May 2025 occupational survey (“survey”): 10th to 90th percentile (thin), interquartile range (thick), median (mark). The survey’s occupation 13-2099 is broader than the quantitative analysts it contains. Data: data/industry/lca_ranges.csv and oews_roles.csv, through in_bankquant.](https://one-course.com/images/onecourse/chapters/quant-17/in-bank-quant/fig-4dd0d3c7d53f.svg)

***Figure 18.3.** Bank quants’ base pay in two sources: offered base in fiscal 2025 labour condition applications (“filings”) and the May 2025 occupational survey (“survey”): 10th to 90th percentile (thin), interquartile range (thick), median (mark). The survey’s occupation 13-2099 is broader than the quantitative analysts it contains. Data: `data/industry/lca_ranges.csv` and `oews_roles.csv`, through `in_bankquant`.*

The filings sit above the survey for the same reason as in chapter 14: they cover the employers that file for skilled foreign hires, at the rate they offer, while the survey covers everyone in the occupation. Between fiscal 2021 and 2025 the banks’ median offer for the quantitative family rose 23.2% in dollars and 3.7% after US consumer prices, and the ladder by level steepened ([Figure 18.4](#fig-in-bank-quant-levels)): levels II to IV rose, level I did not.

![Median offered base at banks by wage level: the quantitative family in fiscal 2021 and 2025, and risk titles in fiscal 2025 (the 2021 risk cells are too small at level I). Data: as .](https://one-course.com/images/onecourse/chapters/quant-17/in-bank-quant/fig-ccbfa872adbc.svg)

***Figure 18.4.** Median offered base at banks by [wage level](https://one-course.com/books/quant/17/en/chapter/14-pay-levels-by-role-firm-type-and-seniority#def-in-pay-levels-by-role-firm-type-and-seniority-soc): the quantitative family in fiscal 2021 and 2025, and risk titles in fiscal 2025 (the 2021 risk cells are too small at level I). Data: as [Figure 18.3](#fig-in-bank-quant-pay).*

## 18.8 Tutorial: pay, reporting lines and the validators’ workload

**Goal.** Put the bank quant’s pay evidence beside a check of reporting lines and the size of the validation function. **End state:** Figures [18.1](#fig-in-bank-quant-org), [18.2](#fig-in-bank-quant-headcount), [18.3](#fig-in-bank-quant-pay) and [18.4](#fig-in-bank-quant-levels).

1. **Pay.** `firm.roles.lca_cells(rows, role, fy, level)` for the families `quant researcher` and `risk` , keeping the bank cells; `data/industry/oews_roles.csv` for occupation 13-2054 in industries 5220A1 and 523000 (derived once by `in_oews_roles_derive.py` from the survey’s files).
2. **Reporting lines.** Write the organisation as a map from each person or unit to its manager and mark the members of senior management; `independence` grades each validator–developer pair ([Listing 18.1](#lst-in-bank-quant-independence)). `def independence (boss, senior, validator, developer, owner=None ): """How far a model's validator is from its developer (and owner), as the ECB guide's three arrangements: 'a' different members of senior management; 'b' different units under the same senior manager; 'c' separate staff in one unit; 'fail' if the validator reports, directly or not, to the developer or the owner.""" up = chain(boss, validator) if developer in up or (owner is not None and owner in up): return " fail " def seat (node): path = [node] + chain(boss, node) for i, n in enumerate (path): if n in senior: return n, (path[i - 1 ] if i > 0 else n) return None , path[-1 ] (sv, uv), (sd, ud) = seat(validator), seat(developer) if sv != sd: return " a " return " b " if uv != ud else " c "` **Listing 18.1.** A validator’s independence from a model’s developer and owner, graded as the ECB guide’s arrangements. code/firm/roles/firm_roles.py
3. **Inventory.** Book 6’s `firm.modelval.ModelRecord` tiers each model from its scores and sets its revalidation interval; `in_bankquant.inventory` takes the expected count of each tier.
4. **Workload.** `validation_hours` and `validator_headcount` apply the method ([Listing 18.2](#lst-in-bank-quant-hours)); `in_bankquant.curve` varies the tier-one share. `def validation_hours (counts, full_hours, review_hours, interval_years, change_rate): """Hours a year of independent validation for an inventory of counts[tier] models: a full validation every interval_years[tier], a lighter periodic review in the other years, and a full validation of the share change_rate of models materially changed each year.""" total = 0.0 for t, n in counts.items(): k = interval_years[t] total += n * (full_hours[t] / k + review_hours[t] * (1.0 - 1.0 / k) + change_rate * full_hours[t]) return total def validator_headcount (counts, full_hours, review_hours, interval_years, change_rate, productive_hours): return validation_hours(counts, full_hours, review_hours, interval_years, change_rate) / productive_hours` **Listing 18.2.** Hours of validation a year and the validators they need. code/firm/roles/firm_roles.py

For the example: 63.9 validators; 50.7 at a 5% tier-one share and 140.1 at 40%.

**What to change next.** Give each tier its own share of material changes; add the validation of learned models with Book 12’s checklist (`firm.modelcard.validation_checklist`), whose explanation and stability tests take longer than a pricer’s benchmark; draw the inventory at random rather than taking its expectation.

## 18.9 Build: bank-quant cards, reporting lines and the validation workload

**Purpose.** Add the four bank quants to the role registry, a check of reporting lines, and the model of the validation function’s size.

**Interface.** `firm.roles`: the cards `desk strategist`, `library quant`, `risk quant`, `model validator`; `chain(boss, node)`; `independence(boss, senior, validator, developer, owner)` returning `a`, `b`, `c` or `fail`; `validation_hours(counts, full_hours, review_hours, interval_years, change_rate)`; `validator_headcount(…, productive_hours)`.

**Rules.** A reporting cycle is an error; a validator under the developer or the owner fails whatever the units; hours and cycles are the caller’s, labelled illustrative; tiers come from Book 6’s rule.

**Acceptance tests.** `code/firm/roles/tests/`: the four grades on a small organisation; a cycle raises; one tier with a one-year cycle costs exactly its full validation; a four-year cycle costs a quarter of it plus three quarters of a review.

**Stretch.** Owners and developers as sets (a model with several developers); a matrix organisation with two managers per person; findings and their deadlines as a queue whose backlog the headcount must clear.

Sources and further reading

- Board of Governors of the Federal Reserve System and OCC (2011), SR 11-7, Supervisory guidance on model risk management.
- Federal Reserve, OCC and FDIC (2026), SR 26-2, Revised guidance on model risk management; OCC Bulletin 2026-13.
- Prudential Regulation Authority (2023), SS1/23, Model risk management principles for banks.
- European Central Bank (2026), ECB guide to internal models, release 4.1.
- Goldman Sachs and JPMorganChase careers pages; QuantLib.
- Chapter 14’s tables from the Department of Labor’s LCA files; BLS occupational survey, May 2025.

## 18.10 Exercises

**Exercise 18.1 ★.**

By how much did the banks’ median offer for the quantitative family rise between fiscal 2021 and 2025, in dollars and after US consumer prices (index 114.325 in 2021, 135.8312 in 2025)?

**Solution of Exercise 18.1.**

From $128 300 to $158 100: 23.2% in dollars. Prices rose by $135.8312/114.325=1.188$, so the real rise is $1.232/1.188-1=3.7\%$.

**Exercise 18.2 ★.**

A validator reports to the chief risk officer through the head of model risk; the model’s developer reports to the head of markets through the head of quantitative analytics. Which arrangement is this?

**Solution of Exercise 18.2.**

Arrangement (a): the two units report to different members of senior management (the chief risk officer and the head of markets), and the validator is not under the developer or the owner.

**Exercise 18.3 ★.**

With the example’s parameters, how many hours a year does one tier-one model cost, and one tier-three model?

**Solution of Exercise 18.3.**

Tier one: a full validation every year (400 hours), no separate review, and 10% of 400 for material changes: 440 hours. Tier three: $60/3+8\times\frac23+0.1\times60=31.3$ hours.

**Exercise 18.4 ★★.**

Suppose every tier-two model were a capital model that must be validated in full every year. How many validators does the example’s inventory need?

**Solution of Exercise 18.4.**

With a one-year cycle for tier two, each tier-two model costs $160+16=176$ hours instead of 104: the inventory needs 82.1 validators instead of 63.9.

**Exercise 18.5 ★★.**

A new product programme doubles the share of models changed materially each year, to 20%. How many validators are needed?

**Solution of Exercise 18.5.**

The change term doubles, from 13 498 to 26 996 hours: 72.4 validators.

**Exercise 18.6 ★★.**

Why should the [desk strategist](#def-in-bank-quant-strat) who built a pricer not validate it, even if the strategist is the best-qualified person in the bank?

**Solution of Exercise 18.6.**

The strategist has a stake in the model being approved, knows what it was built to do rather than what it fails to do, and would review assumptions he chose. Every rule of the chapter (the 2011 US guidance’s “stake”, the UK statement’s separate reporting lines, the ECB’s arrangements) excludes it; the strategist’s knowledge enters as documentation and tests that the validator reviews.

**Exercise 18.7 ★★★.**

*Coding.* Draw the 1 000 models’ scores at random 2 000 times (seed 18) instead of taking the expected tier counts. What is the mean and the 5th–95th percentile range of the validators needed?

**Solution of Exercise 18.7.**

Each draw tiers 1 000 random score triples and applies the method: the mean is 64.0 validators and the 5th–95th percentile range 60.1–67.9. The randomness of the inventory moves the answer by about three validators either way; the choice of hours moves it far more.

**Exercise 18.8 ★★★.**

*Find the flaw.* “Our validators sit in their own team under the head of quantitative analytics, whose library they review, and he reports to the head of markets; they are a separate unit, so this is arrangement (b).”

**Solution of Exercise 18.8.**

The validators report to the head of quantitative analytics, who owns the library they review: they are under the developer, so `independence` returns `fail`, whatever the team’s name. Arrangement (b) requires two units that meet only at a member of senior management.

## 18.11 Problem: Who Validates the Validators?

**Problem 18.1.**

Weekend problem — who validates the validators?

A bank’s new head of model risk must propose a budget for validation and defend the reporting line of her team.

**Part I — The roles.**

1. Define the [desk strategist](#def-in-bank-quant-strat) , the [library quant](#def-in-bank-quant-library) , the [risk quant](#def-in-bank-quant-risk) and the [model validator](#def-in-bank-quant-validator) .
2. How does one bank describe its desk strats?
3. Why does a bank want one pricing library rather than one per system?
4. What makes a [risk quant](#def-in-bank-quant-risk) ’s model change a regulatory event?
5. Where does the valuation-adjustment quant sit, and why does the job fit no single card?

**Part II — The rules.**

6. What did the 2011 US guidance say about who should validate, and about reporting lines?
7. What replaced it in 2026, and what changed about the frequency of validation?
8. What does the UK statement expect of firms with internal-model approval?
9. State the ECB’s three arrangements.
10. Who, under the revised US guidance, checks the model risk function itself, and what does it not do?

**Part III — The workload.**

11. State the validation-workload method.
12. How does Book 6’s tiering rule turn scores into tiers and cycles?
13. Give the expected tier counts for 1 000 models with the example’s score probabilities.
14. What share of the hours do tier-one models take, and why?
15. How many validators does an annual full validation of tier-two models add?

**Part IV — The verdict.**

16. State the *named result* : the validators needed for 1 000 models at the example’s tier split, and the change for each percentage point of tier-one share.
17. Which of the example’s parameters are illustrative, and which come from rules?
18. Grade her proposed line: her team reports to the chief risk officer, developers to the head of markets.
19. Who validates the validators?
20. In two sentences, give her budget case.

**Solution of Problem 18.1.**

1. As in the chapter’s four definitions: the desk’s model and tool builder; the builder of the shared pricing library; the builder of risk and capital models; the independent reviewer of others’ models.
2. Goldman Sachs: desk strats “sit on trading floors and provide value for both internal & external clients through cutting-edge models, predictive analytics, and high-quality trading tools”.
3. So that the same trade has one price in the trading system, the risk engine and the accounts.
4. Many risk and capital models need a supervisor’s approval; a material change needs it again.
5. Between the desk and risk: it simulates exposures like a [risk quant](#def-in-bank-quant-risk) , prices charges like a strategist, and its numbers go into the accounts.
6. Validators should have no stake in the result; reporting lines may support independence, but it is judged by actions and outcomes; each model reviewed at least annually.
7. The 2026 revised interagency guidance (SR 26-2; OCC Bulletin 2026-13): risk-based, with the timing and frequency of validation varying with the model.
8. Separate reporting lines for validators and for developers and owners, and tiering by materiality and complexity.
9. (a) Different members of senior management; (b) the same member, different units; (c) separate staff in one unit.
10. Internal audit evaluates whether model risk management is rigorous and effective; it does not duplicate development or validation.
11. $H=\sum_t n_t(F_t/k_t+R_t(1-1/k_t)+cF_t)$ hours; $H/h$ validators.
12. Twice the materiality score plus complexity and uncertainty: 10 or more is tier one (yearly), 7 to 9 tier two (every two years), less tier three (every three years).
13. 102, 403 and 495.
14. 43.9%, for 10.2% of the models: they are revalidated in full every year at the highest hours.
15. 18.1 validators (82.1 against 63.9).
16. 63.9 validators; about 2.6 more for each percentage point of tier-one share.
17. Illustrative: the score probabilities, the hours, the change rate and the productive hours. From rules: annual review in the 2011 US guidance, annual validation of internal models in the ECB guide, tiering in the UK statement; the cycles by tier are Book 6’s illustrative policy.
18. Arrangement (a), the most robust.
19. Internal audit, which checks that the function works; and the supervisors, who review the bank’s framework.
20. At the bank’s current tiering the inventory needs about 64 validators, and each percentage point of models moved into tier one adds about three more. The team reports to the chief risk officer, separately from the developers and owners, which meets every rule the chapter cites.

## 18.12 Interview questions

**Interview question 18.1 ★ bank, risk.**

How would you test a new Black–Scholes pricer that the desk has written?

**Solution of Interview question 18.1.**

Compare with an independent implementation over a grid (strikes, maturities, volatilities, rates), check limits (zero volatility, zero maturity, deep in and out of the money), put–call parity, Greeks against finite differences, and behaviour at extreme inputs.

*What the interviewer is looking for: an independent benchmark, limits and identities, not one test price.*

**Interview question 18.2 ★ bank, trader.**

A trader says your pricer’s price for a barrier option is wrong because a competitor quotes differently. What do you do?

**Solution of Interview question 18.2.**

Find out why before changing anything: the same inputs (volatility surface, barrier monitoring, rebate, dividends)? The model (local or stochastic volatility, which price barriers differently)? A difference in the market’s price is evidence about the model to be understood, not a price to be copied.

*What the interviewer is looking for: separating inputs from model risk.*

**Interview question 18.3 ★★ risk.**

Your desk’s value at risk had 7 exceptions in 250 days at 99%. Is the model wrong?

**Solution of Interview question 18.3.**

Two and a half are expected; seven or more has probability 1.4% under a correct model, so it is evidence against it, and it falls in the Basel yellow zone (five to nine). Check first for data and position errors and for clustering in a stress period, then the model.

*What the interviewer is looking for: a binomial test and a look at the causes.*

**Interview question 18.4 ★★ bank, developer.**

A library release changes a curve interpolation and moves every desk’s valuation by a few basis points. How do you release it?

**Solution of Interview question 18.4.**

Measure the change on every desk’s positions before release, explain it, have it validated as a model change, agree a date with the desks and product control, and release with the old version available for comparison.

*What the interviewer is looking for: impact analysis and change control.*

**Interview question 18.5 ★★ bank, risk.**

What would you look for first in the documentation of a model you have never seen?

**Solution of Interview question 18.5.**

Its intended use and the decisions it feeds; its limitations as stated by the developer; the data and assumptions; and what testing was done against what benchmark. A document that does not say what the model must not be used for is a finding.

*What the interviewer is looking for: use, limitations and evidence.*

**Interview question 18.6 ★★★ bank, researcher.**

Two local-volatility calibrations fit today’s surface equally well and price a cliquet differently by 3%. Which do you use, and what do you tell the validators?

**Solution of Interview question 18.6.**

The difference is model risk that today’s surface cannot resolve, because a cliquet depends on forward volatility. Price with one, reserve or report the difference as model uncertainty, try a model with stochastic volatility, and give the validators both calibrations and the difference.

*What the interviewer is looking for: forward-volatility dependence and a model reserve.*
