CFA Level II Exam · Measuring and Managing Market Risk
Market Risk Management Overview for CFA Level II
Updated 7 October 2026 · Fact-checked
Market risk is the chance of loss from changes in market prices such as interest rates, equity prices, exchange rates and commodity prices. Organizations measure it to set limits, allocate capital and meet governance duties. To solve questions, identify the risk factor, the owner of the decision, and the control that fits.
Understand Market Risk Management Overview
Market risk is the risk that the value of a position or portfolio falls because market prices or rates move. The main sources, called risk factors, are interest rates, equity prices, exchange rates and commodity prices. Volatility and correlations also matter, because they drive how large the moves can be and how risks combine.
Organizations measure market risk for several reasons. They need to know how much they could lose, whether that loss is acceptable, and how much capital to hold against it. They also use measurement to compare risk across desks, to price risk into products, and to satisfy regulators, boards and clients. Measurement alone is not enough. It must feed decisions, which is why management and governance matter.
Risk governance is the top-down framework that sets how an organization defines, accepts, monitors and controls risk. It sets the risk tolerance, which is the level and type of risk the organization is willing to take. It defines who has authority, how limits are set, how breaches are escalated, and how risk reporting reaches the board. Good governance keeps risk-taking aligned with the organization's objectives and its capacity to absorb losses.
Risk management is the process of identifying, measuring, and then modifying risk to fit that tolerance. Modifying risk can mean avoiding it, reducing it, transferring it (for example with derivatives or insurance), or accepting it. A risk manager typically provides independent measurement, monitoring and reporting. A portfolio manager takes risk in pursuit of return, within the limits set. Keeping these roles distinct supports objectivity and reduces conflicts of interest.
On the exam, expect vignettes that describe a firm, its exposures and its risk framework. You are asked to classify the risk, judge whether governance is sound, or say who should act. Focus on the logic: identify the exposure, link it to tolerance and limits, then pick the response.
How to solve Market Risk Management Overview questions
Use this method for any conceptual or applied question on market risk management and governance.
- 1Read the vignette and underline the exposures: bonds, equities, foreign currency assets, commodity positions.
- 2Classify each exposure by risk factor: interest rate, equity price, currency or commodity price.
- 3Find the stated risk tolerance, limits or objectives. These define what is acceptable.
- 4Identify who is acting: board, risk manager or portfolio manager, and check that the action fits that role.
- 5Decide the response: avoid, reduce, transfer or accept the risk, and see which one fits the tolerance.
- 6Check the measurement and reporting: is it independent, timely and escalated to the right level?
- 7Eliminate options that mix up roles, ignore tolerance, or treat measurement as a replacement for judgement.
Quickest way: Factor, tolerance, owner
When to use it: Use when a question gives a short description of a firm's risks or governance and asks what is correct or what should be done.
- Name the risk factor in one word.
- Compare the exposure with the stated tolerance or limit.
- Ask who owns the decision: the board sets tolerance, the portfolio manager takes risk within limits, the risk manager measures and monitors independently.
- Pick the option that keeps risk-taking inside limits and keeps oversight independent.
Common mistakes in Market Risk Management Overview
Treating market risk as only equity price risk.
Equity examples are the most familiar.
Fix: List all four main factors: interest rate, equity, currency and commodity. Bond portfolios and foreign assets carry market risk too.
Saying the risk manager's job is to eliminate risk.
The word management suggests removal.
Fix: The goal is to keep risk consistent with tolerance and objectives. Taking risk is how returns are earned.
Giving the portfolio manager the job of independent risk oversight.
Both roles deal with risk, so they seem interchangeable.
Fix: Portfolio managers take risk within limits. Independent risk staff measure and monitor it, which avoids conflicts of interest.
Confusing risk tolerance with risk measurement.
Both involve numbers and limits.
Fix: Tolerance is the acceptable level of risk set by governance. Measurement tells you the current level. You compare the two.
Assuming a good risk measure makes governance unnecessary.
Quantitative tools feel objective and complete.
Fix: Models have limits. Governance adds oversight, escalation, limits and judgement on top of any measure.
Worked examples
Example 1
Vignette: A global asset manager holds a portfolio of euro-denominated government bonds for a US-dollar-based client. It also holds a small position in oil futures. The board has set a tolerance that limits overall portfolio loss in a bad month. Q1: Which market risk factors does the portfolio face? Q2: Who should set the loss tolerance?
Show the solution
- Euro government bonds are exposed to interest rate changes, so interest rate risk applies.
- The client is USD-based and the bonds are in euros, so exchange rate risk applies.
- Oil futures expose the portfolio to commodity price risk.
- The vignette says the board set the tolerance. Governance assigns tolerance setting to the board or its risk committee, not to the trader.
Answer: Q1: Interest rate, currency and commodity price risk. Q2: The board (through its governance framework) sets the loss tolerance.
Example 2
Vignette: At a fund firm, the head of the equity desk also reviews the desk's daily risk reports and decides whether limit breaches need escalation. The desk has exceeded its position limit twice this quarter. Q1: What is the governance weakness? Q2: What is the best improvement?
Show the solution
- The person taking risk (desk head, acting as portfolio manager) also monitors and reports on it.
- This removes independence, because the person with a return incentive controls the escalation.
- The fix is to separate the functions. An independent risk manager should measure, monitor and report limit breaches to senior management or the risk committee.
- Escalation of the breaches should then follow the defined governance process.
Answer: Q1: Risk-taking and risk oversight are combined, so there is no independent monitoring. Q2: Move monitoring and breach reporting to an independent risk function that reports to senior management or the board risk committee.
Exam tips
- Read the vignette for who is acting. Many questions test roles, not calculations.
- Memorize the four risk factors and match each exposure to one or more of them, including currency risk on foreign assets.
- Look for words like tolerance, limit and independent. They signal the governance point being tested.
- Prefer answers that align risk with objectives over answers that remove all risk.
- There is no penalty for wrong answers, so answer every question.
Market Risk Management Overview in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Market Risk Management Overview: frequently asked questions
What is market risk in CFA Level II?
It is the risk of loss from changes in market prices and rates, mainly interest rates, equity prices, exchange rates and commodity prices. It is measured and managed against a stated risk tolerance.
What is the difference between risk governance and risk management?
Governance is the framework of policies, authority and oversight that sets tolerance and accountability. Risk management is the process of identifying, measuring and modifying risk within that framework.
How do risk managers and portfolio managers differ?
Portfolio managers take risk to earn return within set limits. Risk managers provide independent measurement, monitoring and reporting. Keeping them separate protects objectivity.
Does this topic need calculations?
This overview is mainly conceptual. The calculations come in related topics such as Value at Risk and sensitivity measures, so study them together.