Skip to content

FRM Part II · FRM Exam Part II

Validating Bank Holding Companies' Value-at-Risk Models for Market Risk: formula sheet

Full chapter guide

Key formulas

Expected exceptions in a backtest
Expected exceptions = N × (1 − c)
N is the number of observations and c the VaR confidence level. For 250 days at 99%, expect 2.5 exceptions.
Three pillars of validation
Conceptual soundness + ongoing monitoring + outcomes analysis
This is the SR 11-7 style structure. Learn it as the skeleton for any validation question.
Basel backtesting zones (250 days, 99% VaR)
Green: 0–4 exceptions; Yellow: 5–9; Red: 10 or more
Zones drive the capital multiplier add-on in the Basel internal models approach. Red usually means the model is presumed flawed.
Exception probability under a correct model
P(exception on any day) = 1 − c
Exceptions should be independent and occur at this rate. Clustering or a wrong count signals a problem.
Exception probability
p = 1 − confidence level
For 99% VaR, p = 0.01. For 95% VaR, p = 0.05.
Expected number of exceptions
E(N) = T × p
T is the number of days in the backtest window. 250 days at 99% gives 2.5.
Standard deviation of exception count
σ(N) = √(T × p × (1 − p))
Binomial standard deviation. 250 days at 99% gives about 1.57.
Exception rate
x ÷ T
Observed exceptions x divided by days T. Compare it with p.
Z-score (normal approximation)
z = (x − T × p) ÷ √(T × p × (1 − p))
Rough test only. It works poorly for small p and small T. Reject at 5% (two-sided) if |z| > 1.96.
Kupiec unconditional coverage (POF) statistic
LR_uc = −2 ln[(1 − p)^(T − x) × p^x] + 2 ln[(1 − x/T)^(T − x) × (x/T)^x]
Compared with chi-square with 1 degree of freedom. 5% critical value is 3.84. It tests only the frequency of exceptions, not their timing.
Basel traffic light zones (250 days, 99% VaR)
Green: 0 to 4 exceptions. Yellow: 5 to 9. Red: 10 or more.
Multiplier add-on to the capital multiplier rises through the yellow zone. Red zone normally gives the maximum add-on and the model is presumed flawed.
Exception indicator and expected rate
I(t) = 1 if loss(t) > VaR(t), else 0; N = Σ I(t); p = 1 − c; expected exceptions = p × T
T is the number of backtest days, N the observed exceptions. Under a correct model, N is Binomial(T, p).
Kupiec unconditional coverage statistic
LR_uc = −2 ln[(1 − p)^(T − N) × p^N] + 2 ln[(1 − N/T)^(T − N) × (N/T)^N]
Under H0 (exception probability = p), LR_uc follows chi-square with 1 degree of freedom. Critical values: 3.84 at 5% and 6.63 at 1%. Reject H0 if LR_uc is larger.
Transition probabilities
π01 = n01 ÷ (n00 + n01); π11 = n11 ÷ (n10 + n11); π = (n01 + n11) ÷ (n00 + n01 + n10 + n11)
nij = number of days in state j following state i (0 = no exception, 1 = exception). Independence means π01 = π11.
Christoffersen independence statistic
LR_ind = −2 ln[(1 − π)^(n00 + n10) × π^(n01 + n11)] + 2 ln[(1 − π01)^n00 × π01^n01 × (1 − π11)^n10 × π11^n11]
Chi-square with 1 degree of freedom under H0 (independence). Same critical values as Kupiec: 3.84 at 5%.
Conditional coverage statistic
LR_cc = LR_uc + LR_ind
Chi-square with 2 degrees of freedom. Critical values: 5.99 at 5% and 9.21 at 1%.
Parametric VaR (normal)
VaR = z × σ × V × √h
z is the normal quantile (1.645 at 95%, 2.326 at 99%), σ is daily volatility, V is position value, h is horizon in days. Valid under square-root-of-time scaling, which needs i.i.d. returns.
EWMA variance
σ²(t) = λ × σ²(t−1) + (1 − λ) × r²(t−1)
Lower λ reacts faster to new data; higher λ is smoother. λ = 0.94 is the common RiskMetrics daily value.
Portfolio variance (two assets)
σp² = w1²σ1² + w2²σ2² + 2 w1 w2 ρ σ1 σ2
Higher ρ means less diversification and higher VaR. Understated ρ understates VaR.
Historical simulation VaR
VaR at confidence c = loss at the (1 − c) quantile of the sorted scenario P&L
With 500 scenarios at 99%, VaR is roughly the 5th worst loss. Window length drives the result.
Delta-normal option approximation
ΔP ≈ Delta × ΔS
Ignores gamma and vega. Understates risk for large moves in options.
Expected exceptions
Expected exceptions = N × (1 − c)
N = number of days, c = VaR confidence level. 250 days at 99% gives 2.5. Shows why backtesting has low power.
Benchmark gap
Gap % = (VaR model − VaR benchmark) ÷ VaR benchmark × 100
A diagnostic only. A large gap means investigate, not that the model is wrong.
Sensitivity of VaR
Sensitivity = (VaR after change − VaR base) ÷ VaR base
Change one input at a time and keep everything else fixed.
Role of each tool
Backtest = outcomes; Benchmark = comparison; Hypothetical portfolio = known answer; Stress = tail losses; Sensitivity = assumption fragility
Use this to match a tool to the validation question.
Expected exceptions
Expected exceptions = N × (1 − c)
N is the number of days and c the VaR confidence level. At 99% over 250 days, expect 2.5.
Exception rate
Exception rate = x ÷ N
Compare with 1 − c. A rate near the expected value does not prove the model is right, because test power is low.
Type I and Type II errors
Type I = reject a correct model; Type II = accept an incorrect model
Low power at 99% means a high chance of Type II error.
Core limitations
Low power + portfolio change + tail blindness
A memory aid for the three main weaknesses of exceedance-based validation.

Quick revision

  • Validation covers model design, inputs, outcomes and ongoing monitoring, not backtesting alone.
  • An exception is a day when the loss exceeds the reported VaR.
  • Expected exceptions = number of observations × (1 − confidence level).
  • Too many exceptions suggest VaR is understated; too few suggest it is overly conservative.
  • Hypothetical P&L isolates model quality by removing intraday trading and fee effects.
  • Coverage tests check exception frequency; independence tests check for clustering.
  • Clustered exceptions suggest the model reacts too slowly to changing volatility.
  • Poor risk factor mapping or proxies can hide risk and distort backtesting results.
  • Benchmarking compares the model with an independent alternative model.
  • Stress testing and sensitivity analysis probe tails and assumptions that VaR misses.
  • VaR gives a loss threshold and says nothing about the size of losses beyond it.
  • A model that passes backtesting can still be weak, because exceptions are rare and tests have low power.

Common mistakes

  • Treating backtesting as the whole of validation Fix: Remember it is only one part of outcomes analysis. Conceptual soundness, data checks, benchmarking and governance are also required.
  • Assuming zero exceptions proves the model is good Fix: Far fewer exceptions than expected can mean the VaR is too conservative and capital is inefficient. The model should be close to the expected rate.
  • Using the wrong p, for example 0.99 instead of 0.01. Fix: Always write p = 1 − confidence level first. The exception probability is the tail.
  • Treating the traffic light zones as applying to any window or any confidence level. Fix: State that these zones are for 250 days of 99% one-day VaR. Other setups need the binomial distribution.
  • Using the 1 df critical value (3.84) for the conditional coverage test. Fix: Conditional coverage adds two components, so it has 2 degrees of freedom. Use 5.99 at 5%.
  • Saying a model that passes Kupiec has independent exceptions. Fix: Kupiec ignores timing. Only the independence or conditional coverage test addresses clustering.
  • Treating a passed backtest as proof that inputs are sound. Fix: Remember that backtests have low power and can hide offsetting errors. Inputs and assumptions need direct review.
  • Saying historical simulation has no assumptions. Fix: It still assumes the past window represents the future, that observations are equally likely, and that the data are reliable.
  • Saying a benchmark gap proves the bank's model is wrong. Fix: A benchmark is another estimate with its own errors. A gap means investigate the cause.
  • Treating stress testing as a way to check VaR's confidence level. Fix: Stress tests look at extreme scenarios beyond the VaR quantile. They complement VaR and do not test its coverage.

Exam tips

  • Questions often ask which component a given activity belongs to. Use the three-pillar triage.
  • Know the Basel zone cut-offs for 250 days at 99% and what each zone implies.
  • Prefer answers that combine several methods and stress independence and documentation.
  • Expect case-style items where one weakness, such as stale data or developer-led review, must be spotted.
  • Convert the confidence level into p first. Many wrong answers come from this one step.
  • Remember the zone boundaries only for 250 days at 99%: green 0 to 4, yellow 5 to 9, red 10 or more.
  • When a question asks which P&L isolates model error, answer clean (hypothetical) P&L.
  • If exception dates are given and they cluster, say the model fails independence even if the count passes.