Skip to content

FRM Exam Part I · Calculating and Applying VaR

VaR Limitations, Backtesting and Basel Traffic Light Zones

Updated 11 October 2026 · Fact-checked

Backtesting compares daily VaR with actual profit and loss. A day when the loss exceeds VaR is an exception. At 99% VaR over 250 days you expect 2.5 exceptions. Basel's traffic light puts 0-4 exceptions in green, 5-9 in yellow, and 10 or more in red, with higher capital multipliers.

Understand VaR Limitations, Backtesting and Applications

Value at Risk (VaR) gives a loss level that should be exceeded only with a small probability over a set horizon. It is useful, but it has weaknesses. It says nothing about how large losses are beyond the VaR level. It is not always subadditive, so the VaR of a combined portfolio can exceed the sum of the parts. It depends on the model, the data window and the distribution assumed. Normal assumptions understate fat tails. Historical windows can miss new regimes. VaR can also be gamed, for example by taking positions whose losses sit just beyond the confidence level.

Backtesting checks whether a VaR model works. Each day you compare the reported VaR with the actual or hypothetical P&L. If the loss is larger than VaR, that day is an exception (also called a violation or breach). If the model is correct, the number of exceptions in n days is binomial, with probability p = 1 − confidence level on each day.

For 99% VaR, p = 1%. Over 250 days you expect 2.5 exceptions. Too many exceptions mean the model understates risk. Too few mean it is too conservative and ties up capital. A statistical test rejects the model when the count is too far from expectation. There is a trade-off between two errors: rejecting a good model (Type I) and accepting a bad one (Type II).

The Basel traffic light approach turns the count of exceptions into capital consequences. It uses 99% one-day VaR and the last 250 trading days. Green zone is 0 to 4 exceptions, yellow is 5 to 9, and red is 10 or more. In green the multiplier on the capital charge stays at its base level of 3. In yellow, a plus factor is added, rising with the count. In red, the model is presumed flawed and the plus factor is at its maximum. The add-on is a regulatory scale, so you only need the pattern: more exceptions, higher multiplier.

Beyond testing, banks use VaR to set trading limits by desk, to allocate economic capital, and to compute regulatory capital for market risk. Good practice adds stress tests and expected shortfall, because VaR alone is not enough.

Key formulas to remember

Exception probability
p = 1 − confidence level
For 99% VaR, p = 0.01. For 95% VaR, p = 0.05.
Expected number of exceptions
E(X) = n × p
250 days at 99% gives 2.5 exceptions.
Binomial probability of x exceptions
P(X = x) = C(n, x) × p^x × (1 − p)^(n − x)
Assumes exceptions are independent with constant probability.
Standard deviation of exceptions
σ = √(n × p × (1 − p))
Used in the normal approximation to the binomial.
Z-score for exception count
z = (x − n × p) ÷ √(n × p × (1 − p))
Compare with the critical value, such as 1.96 for a two-sided 5% test.
Basel traffic light zones
Green: 0-4; Yellow: 5-9; Red: 10 or more exceptions (99% VaR, 250 days)
Capital multiplier increases from green to yellow to red.
Kupiec unconditional coverage idea
Reject the model if the exception count is too high or too low
Tests whether the exception frequency equals p. It does not test whether exceptions cluster.

How to solve VaR Limitations, Backtesting and Applications questions

Use this routine for most backtesting questions.

  1. 1Identify the VaR confidence level and set p = 1 − confidence.
  2. 2Note the number of observations n and the number of exceptions x.
  3. 3Compute the expected exceptions n × p and compare with x.
  4. 4If asked for a test, compute the standard deviation √(n × p × (1 − p)) and the z-score, then compare with the critical value.
  5. 5If asked about Basel, check that the test uses 99% VaR over 250 days, then map x to green, yellow or red.
  6. 6State the conclusion: too many exceptions means risk is understated; too few means the model is too conservative.
  7. 7For limitation questions, match the weakness to its cause: tail blindness, non-subadditivity, model dependence or data window.

Quickest way: Count against expectation

When to use it: Use for any question that gives exception counts or asks for a traffic light zone.

  1. Compute n × p in your head. 250 at 1% is 2.5.
  2. Memorise the zone cut-offs 4 and 9 for 250 days.
  3. Place the count in a zone first. Only compute a z-score if the question asks for a test.
  4. Remember that a loss exactly at VaR is not an exception; it must exceed VaR.

Common mistakes in VaR Limitations, Backtesting and Applications

  • Using 95% VaR with the Basel zone table.

    The cut-offs are memorised without their conditions.

    Fix: The zones apply to 99% one-day VaR over 250 days. For other settings, compute n × p yourself.

  • Treating too few exceptions as perfect.

    Fewer breaches look safe.

    Fix: Too few exceptions suggest the model is too conservative, which wastes capital. A good model is close to n × p.

  • Saying VaR is always subadditive.

    Mixing it up with expected shortfall.

    Fix: VaR is not subadditive in general. Expected shortfall is coherent.

  • Using p = 0.99 in the binomial formula.

    Confusing confidence level with exception probability.

    Fix: p is the chance of a breach: 1% for a 99% VaR.

  • Thinking a backtest shows exceptions are independent.

    The count looks fine, so the model seems fine.

    Fix: A correct count can hide clustering of exceptions. Independence needs a separate test.

  • Believing VaR tells you the size of the loss beyond VaR.

    VaR is read as a worst case.

    Fix: VaR is only a threshold. It ignores the size of tail losses.

Worked examples

Example 1

A bank backtests a 99% one-day VaR model over 250 trading days and records 7 exceptions. Find the expected number of exceptions and the Basel zone.

Show the solution
  1. p = 1 − 0.99 = 0.01.
  2. Expected exceptions = 250 × 0.01 = 2.5.
  3. Observed 7 is above 2.5.
  4. Basel zones: green 0-4, yellow 5-9, red 10 or more. 7 falls in 5-9.

Answer: Expected exceptions are 2.5. The model is in the yellow zone, so a higher capital multiplier applies.

Example 2

A 99% VaR model over 500 days produces 11 exceptions. Using the normal approximation, compute the z-score. Should a two-sided test at 5% reject the model (critical value 1.96)?

Show the solution
  1. p = 0.01, n = 500, so n × p = 5.
  2. σ = √(500 × 0.01 × 0.99) = √4.95 ≈ 2.225.
  3. z = (11 − 5) ÷ 2.225 ≈ 2.70.
  4. 2.70 is greater than 1.96.

Answer: z ≈ 2.70, which exceeds 1.96, so the test rejects the model: it understates risk.

Exam tips

  • Memorise the zone cut-offs for 250 days at 99%: 0-4, 5-9, 10 or more.
  • Questions often ask which error is worse: a red-zone model is penalised, but a yellow-zone result needs judgement about the cause.
  • Be ready to list VaR limitations: no tail information, not subadditive, model and window dependence, and sensitivity to distribution assumptions.
  • Compute n × p first. It anchors every backtesting answer.
  • If a question mentions exceptions bunching together, the issue is independence, not the average count.

Practice questions from Calculating and Applying VaR

VaR Limitations, Backtesting and Applications in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

VaR Limitations, Backtesting and Applications: frequently asked questions

How many exceptions are expected in a 99% VaR backtest?

Multiply the number of days by 1%. Over 250 days you expect 2.5 exceptions. Actual counts will vary, so you test whether the difference is statistically significant.

What are the Basel traffic light zones?

With 99% one-day VaR and 250 days, 0 to 4 exceptions is green, 5 to 9 is yellow, and 10 or more is red. Higher zones carry a larger capital multiplier.

Why is VaR criticised?

It gives no information on losses beyond the threshold, it is not always subadditive, and its result depends on model assumptions and the data window. Expected shortfall addresses some of these issues.

What is an exception in VaR backtesting?

An exception is a day when the actual loss is larger than the VaR estimate. It is also called a violation or breach.