Risk Modelling Tutorial
Risk Modelling Tutorial
COMPREHENSIVE TUTORIAL
Theory · Methods · Real-Life Examples · Advantages & Disadvantages
1. Introduction to Risk and Risk Modelling 2. Taxonomy of Risk — Types and Categories
5. Value at Risk (VaR) — Theory and Practice 6. Monte Carlo Simulation in Risk Modelling
11. Qualitative Risk Modelling Methods 12. Risk Model Validation and Backtesting
13. Emerging Approaches — AI/ML in Risk 14. Advantages and Disadvantages — Master
Modelling Summary
SECTION 1
Introduction to Risk and Risk Modelling
Understanding what risk is and why modelling it is a strategic imperative
Risk is the possibility that outcomes will differ from expectations — that actual results will deviate,
positively or negatively, from what was planned or predicted. Every organisation — whether a bank,
hospital, technology firm, pension fund, or government agency — faces risks that, if not managed, can
lead to financial loss, regulatory sanction, reputational damage, or even existential failure.
Risk modelling is the disciplined, quantitative (and sometimes qualitative) process of identifying,
measuring, analysing, and communicating the nature and magnitude of risks an organisation faces. It
provides the analytical backbone of Enterprise Risk Management (ERM), enabling leaders to make
better-informed decisions under uncertainty.
This simple relationship underlies all risk scoring, heat maps, capital adequacy frameworks, and
insurance pricing models used globally.
Regulatory Basel III, Solvency II, NAICOM, PenCom Banks must compute Minimum Capital
Compliance regulations require formal risk models Requirement using VaR models
Capital Allocation Determine how much capital to hold as a Stanbic IBTC Pension allocating reserves
buffer against adverse events against investment loss scenarios
Pricing Decisions Charge premiums or interest rates that Insurance premium = E(Loss) + Risk
reflect actual risk exposure Loading + Expenses
Strategic Planning Stress-test business plans against What happens to revenue if oil prices drop
adverse economic scenarios 50%?
Investor Demonstrate sound risk governance to A bank with robust credit risk models attracts
Confidence shareholders and rating agencies lower-cost funding
Loss Avoidance Identify and mitigate risks before they IT infrastructure risk modelling prevents
materialise costly outages
SECTION 2
Taxonomy of Risk — Types and Categories
A structured classification of the risks organisations encounter
Risk does not come in a single form. A comprehensive risk taxonomy — a structured classification
system — is the starting point for any risk modelling programme. The major risk categories recognised
by international frameworks (Basel III, ISO 31000, COSO ERM) are:
MARKET RISK
The risk of loss from adverse movements in market prices — interest rates, foreign exchange, equity
prices, and commodity prices.
– Interest Rate Risk: A rise in rates reduces the value of fixed-income bond portfolios
– FX Risk: A Nigerian importer paying USD faces losses if the Naira depreciates
– Equity Risk: A pension fund holding equities loses value in a stock market crash
– Commodity Risk: An airline's fuel costs soar when crude oil prices spike
CREDIT RISK
The risk that a counterparty will fail to meet its contractual financial obligations — default risk, downgrade
risk, and concentration risk.
– Default Risk: A bank's borrower fails to repay a loan
– Counterparty Risk: An OTC derivative counterparty fails before settlement
– Concentration Risk: A bank has 60% of its loan book in one sector (e.g., oil & gas)
– Downgrade Risk: A bond issuer's credit rating is cut, reducing its market value
OPERATIONAL RISK
The risk of loss from inadequate or failed internal processes, people, systems, or from external events
(Basel III definition).
– Process Failures: Errors in payment processing, trade booking, or reporting
– IT/Cyber Risk: A ransomware attack cripples a bank's core banking system
– People Risk: Fraud by an employee, key-person dependency
– Legal/Compliance Risk: Regulatory fines for AML/KYC violations
LIQUIDITY RISK
The risk that an entity cannot meet short-term obligations without incurring unacceptable costs — either
funding liquidity or market liquidity.
– Funding Liquidity: Bank unable to roll over its short-term borrowings in a crisis
– Market Liquidity: Asset cannot be sold quickly at fair value (e.g., real estate)
– Example: Northern Rock (UK) bank run in 2007 — a textbook funding liquidity failure
STRATEGIC RISK
The risk of loss from poor business decisions, failure to adapt to market changes, or adverse industry
dynamics.
– Kodak's failure to pivot to digital photography despite inventing the technology
– Nokia's loss of mobile market share to smartphone makers
– A pension fund maintaining an excessively conservative investment mandate
Beyond these core categories, organisations also face reputational risk (loss of stakeholder trust),
country/political risk (sovereign defaults, policy changes), model risk (models that are wrong or
misused), and increasingly, climate/ESG risk (physical and transition risks from climate change).
SECTION 3
Risk Modelling Frameworks and Standards
The international guidelines and regulations that govern how risk models are built and used
Risk modelling does not occur in a vacuum. Organisations operate within regulatory and professional
frameworks that define minimum standards for risk identification, measurement, and reporting.
ISO 31000:2018 Universal Risk Principles, framework, and process for enterprise-wide risk
Management management. Applicable to any organisation regardless of
sector.
Basel III / IV Banking Sector International capital adequacy rules for banks. Requires
VaR/Expected Shortfall models for market risk, IRB models for
credit risk, and AMA/SMA for operational risk.
Solvency II Insurance Sector Requires insurers to hold capital covering a 1-in-200-year loss
(EU) event (99.5% VaR over 1 year) — the Solvency Capital
Requirement.
IFRS 9 Financial Reporting Requires banks to recognise Expected Credit Losses (ECL) on
all financial instruments from day one — driving credit risk
model adoption.
PenCom Guidelines Nigerian Pension Pension Commission Nigeria's investment and risk guidelines
Sector for Pension Fund Administrators — requiring formal risk
frameworks.
SECTION 4
Quantitative Risk Models — Overview
The mathematical and statistical toolkit for measuring and quantifying risk
Quantitative risk modelling uses mathematics, statistics, and computational methods to express risk
numerically. This allows risk to be compared, aggregated, priced, and communicated in precise terms
— turning the vague concept of 'uncertainty' into measurable quantities that support decision-making.
Value at Risk (VaR) Maximum loss at a confidence level over Market risk, trading books
a time horizon
Expected Shortfall Average loss in the worst (1-alpha)% of Tail risk, Basel IV standard
(CVaR) scenarios
Monte Carlo Simulation Simulate thousands of random scenarios Complex portfolios, derivatives
Probability of Default (PD) Probability a borrower will default in 12 Credit risk, IFRS 9 ECL
months
Loss Given Default (LGD) Percentage of exposure lost upon default Credit risk, loan pricing
Exposure at Default Total amount at risk at time of default Credit risk capital
(EAD)
Extreme Value Theory Model behaviour in the extreme tail of Catastrophe risk, insurance
(EVT) distributions
• Step 1: Risk Identification: List all material risk factors the model must capture. Example: Credit losses,
FX moves, system downtime
• Step 2: Data Collection: Gather historical data, market data, loss databases. Example: Loan default
history, daily P&L;, incident logs
• Step 3: Model Selection: Choose appropriate statistical distribution and model type. Example: Normal for
returns; Log-Normal for loss sizes
• Step 4: Parameter Estimation: Estimate model parameters from data. Example: Maximum Likelihood
Estimation (MLE)
• Step 5: Risk Measurement: Compute risk metrics (VaR, PD, ECL, etc.). Example: VaR = mu + z * sigma *
sqrt(t)
• Step 6: Validation: Back-test model against actual outcomes. Example: Kupiec test, traffic-light
backtesting
• Step 7: Reporting: Communicate results to decision-makers. Example: Risk dashboards, regulatory
reports
SECTION 5
Value at Risk (VaR)
The most widely used risk metric in financial risk management
Value at Risk (VaR) is defined as the maximum loss that a portfolio or position is expected to
experience over a specified time horizon, at a given confidence level, under normal market conditions.
The loss level x such that losses exceed x with probability (1 - alpha) over horizon T
In plain language: a 1-day 99% VaR of N5 million means there is a 1% probability that the portfolio will
lose more than N5 million in a single trading day.
Assumes returns are normally distributed. Computes VaR analytically from the mean and standard
deviation of the portfolio return distribution.
Advantages:
– Fast computation — closed-form analytical solution
– Easy to understand and explain to stakeholders
– Works well for simple, liquid portfolios
Limitations:
– Assumes normality — underestimates tail risk (fat tails in real markets)
– Breaks down for non-linear instruments (options, structured products)
– Poor performance during market stress when correlations change
Uses actual historical return data. Replays the past N days of market moves on the current portfolio and
takes the (1-alpha) percentile of the resulting P&L; distribution.
Advantages:
– No normality assumption — actual fat tails captured
– Transparent and intuitive: 'What would today's portfolio have lost in past market events?'
– Widely accepted by regulators
Limitations:
– Assumes history repeats — cannot capture truly unprecedented events
– Highly sensitive to the chosen look-back window length
– Slow to adapt to changing volatility regimes
Simulates thousands of random market scenarios using specified statistical models, revalues the portfolio
under each scenario, and derives VaR from the simulated P&L; distribution.
Advantages:
– Captures non-linear payoffs (options, structured products)
– Can model complex correlation structures
– Most flexible — adaptable to any distribution assumption
Limitations:
– Computationally intensive — requires significant processing power
– Results depend on model assumptions (GIGO: garbage in, garbage out)
– Model risk: wrong distributional assumptions give misleading VaR figures
Expected Shortfall (ES), also called Conditional VaR (CVaR) or Tail VaR, addresses VaR's biggest
weakness: VaR tells you the loss threshold but says nothing about how bad losses are beyond that
threshold. ES measures the average loss in the worst (1-alpha)% of scenarios.
ES is always >= VaR. Basel IV replaced VaR with ES(97.5%) as the primary market risk metric.
1-Day 99% VaR = mu - z * sigma = 50,000 - 2.326 * 300,000 = 50,000 - 697,800 = -N647,800
Interpretation: There is a 1% chance of losing more than N647,800 in a single trading day.
The risk management committee requires the desk to hold capital equal to 3 × VaR = N1,943,400
(the Basel multiplier of 3 is applied to account for model uncertainty).
+ Provides a single, comparable risk number across – Only measures 'normal market' risk — fails during
asset classes crises (underestimates tail risk)
+ Regulatory standard (Basel III/IV) — widely – VaR is not sub-additive — portfolio VaR can exceed
understood by regulators and investors sum of individual VaRs
+ Enables risk limits and position management (e.g., – Gives no information about magnitude of losses
VaR limits by desk) beyond the threshold
+ Facilitates risk aggregation across business units – Parametric VaR assumes normal distribution — real
returns are fat-tailed
SECTION 6
Monte Carlo Simulation in Risk Modelling
Harnessing computational power to simulate uncertainty across thousands of scenarios
Monte Carlo Simulation (MCS) is named after the famous casino in Monaco, reflecting its reliance on
randomness and probability. In risk modelling, MCS generates a large number of plausible future
scenarios by randomly sampling from probability distributions specified for each risk factor. The
distribution of outcomes across all simulations reveals the full risk profile of the portfolio or system.
• Step 1: Define Risk Factors — Identify all variables that drive the outcome of interest (e.g., interest rates,
default rates, prices)
• Step 2: Specify Distributions — Choose a probability distribution for each risk factor (Normal,
Log-Normal, Poisson, etc.)
• Step 3: Generate Correlations — Model the correlation structure between risk factors using a correlation
matrix or copula
• Step 4: Simulate Scenarios — Draw N random samples (typically 10,000–100,000) from the joint
distribution of risk factors
• Step 5: Value Under Each Scenario — Recompute portfolio value or loss under each simulated scenario
• Step 6: Analyse Results — Compute statistics: VaR, ES, mean loss, standard deviation, and construct
loss distribution
• Step 7: Report and Decide — Present findings to risk committees; set limits, hedges, and capital buffers
accordingly
For a portfolio P with value V dependent on risk factors X = (X■, X■, ..., X■):
Risk factor realisations X_i(k) are drawn from their specified joint probability distribution
REAL-WORLD EXAMPLE — Monte Carlo for Pension Fund Asset Liability Modelling
A pension fund wants to assess the probability that its assets will be insufficient to cover liabilities
over the next 30 years. Monte Carlo simulation is the industry standard approach.
Process: Run 50,000 simulations over 30 years. In each simulation, track assets vs liabilities.
Result: 'Funding ratio < 100% (deficit) in 12% of simulations by Year 20.'
Decision: Increase contribution rates by 2% and shift 5% of equities to inflation-linked bonds
— reducing the deficit probability from 12% to 4% at acceptable cost to members.
Risk Factors:
– Server failure rate: Poisson(lambda=0.5 failures/month)
– Recovery time per failure: Log-Normal(mu=1.5hrs, sigma=0.5hrs)
– Network outage frequency: Poisson(lambda=0.2 events/month)
– Network outage duration: Exponential(mean=2hrs)
Process: Simulate 12,000 months of operation (1,000 years). Track cumulative downtime per year.
Result: 'SLA breach (>4hrs annual downtime) occurs in 8.3% of simulated years.'
Decision: Add a redundant server (halving failure rate) — reducing SLA breach probability to 1.9%.
Cost-benefit: Redundant server costs N2.5M/year. Average cost of SLA penalty = N15M * 8.3% =
N1.25M/year.
After redundancy: N15M * 1.9% = N285,000/year savings. ROI calculation justifies the investment.
+ Captures non-linear payoffs and complex instrument – Computationally intensive — 100,000 simulations
structures may take hours for large portfolios
+ Produces a full distribution of outcomes, not just a – Convergence requires large N — with too few
point estimate simulations, results are noisy
+ Handles path-dependent products (Asian options, – Difficult to audit and explain to non-technical
mortgage prepayments) stakeholders
+ Widely accepted by regulators for internal model – Model risk: wrong distributional assumptions
approval cascade through all results
+ Can incorporate real-world complexity (jumps, – Historical data needed for calibration — sparse data
regime changes) in tails causes estimation error
SECTION 7
Credit Risk Modelling
Quantifying the risk that borrowers or counterparties will fail to meet their obligations
Credit risk is the oldest and largest risk category for most banks and financial institutions. For a typical
commercial bank, credit risk accounts for 70–80% of total risk-weighted assets. Accurate credit risk
modelling is essential for loan pricing, capital allocation, provision setting under IFRS 9, and regulatory
compliance.
The Basel framework decomposes credit risk into three fundamental parameters:
PD — Probability of Default
The probability that a borrower will default within 12 months (or over the lifetime for IFRS 9).
Example: If a N10M loan defaults and N3M is recovered: LGD = (10-3)/10 = 70%
Example: A N5M overdraft with N3M drawn and CCF=75%: EAD = 3M + (2M × 0.75) = N4.5M
IFRS 9 (effective 2018) replaced the 'incurred loss' model with a forward-looking Expected Credit Loss
(ECL) framework, requiring banks and corporates to recognise potential future losses from day one:
For Stage 1 (performing loans): 12-month ECL. For Stage 2/3: Lifetime ECL.
The bank must recognise this N748M as a provision (loan loss reserve) in its financial statements.
– Failure to do so = overstatement of profits = regulatory violation.
– CBN and auditors will review the model assumptions (PD, LGD, EAD) for reasonableness.
– Banks with poor data for PD estimation face supervisory scrutiny and potential overlays.
Credit scoring translates borrower characteristics into a numerical score predicting default probability.
Methods include:
Logistic Regression Statistical model estimating P(default) from Retail banking, SME lending —
financial ratios and borrower attributes. standard scorecard approach
Interpretable and widely used.
Altman Z-Score Linear discriminant model using 5 financial Corporate credit risk, early warning
ratios to predict corporate bankruptcy. systems
Z-Score < 1.81 signals high distress.
Random Forest / Machine learning ensemble methods Fintech lenders, large-scale retail
Gradient Boosting capturing non-linear relationships between credit scoring
borrower features and default.
Neural Networks Deep learning models for complex pattern Advanced credit risk in digital
recognition in credit data — powerful but less lending platforms
interpretable.
Survival Analysis (Cox Models time-to-default rather than just binary Mortgage risk, commercial real
Model) default probability — captures the dynamics of estate lending
default timing.
+ Enables precise loan pricing based on individual – Garbage in, garbage out — models are only as good
borrower risk as the data quality
+ IFRS 9 and Basel compliance requires ECL models – Historical data may not capture future economic
— regulatory necessity regimes (COVID-19, inflation spikes)
+ Reduces subjective judgement in lending decisions – PD models underperform during rapid economic
— consistency and fairness deterioration (pro-cyclicality)
+ Portfolio-level models identify concentrations before – LGD estimation requires long loss history — sparse
they become problems data in good economic periods
+ Early warning models (Watchlist) allow proactive – Regulatory model approval is costly and
management of at-risk borrowers time-consuming
SECTION 8
Operational Risk Modelling
Quantifying losses from processes, people, systems, and external events
Operational risk (OpRisk) is uniquely challenging to model because it encompasses a vast range of
heterogeneous events — from minor processing errors to catastrophic fraud, cyber attacks, or natural
disasters. Unlike market or credit risk, operational risk losses are often rare but extremely severe.
Internal Fraud Employee theft, misappropriation, Société Générale: Jerome Kerviel's rogue
unauthorised trading trading — EUR 4.9B loss (2008)
External Fraud Robbery, cyber fraud, phishing, Bank customers defrauded via BVN-linked SIM
identity theft swap fraud in Nigeria
Employment Practices Discrimination claims, health & Workplace injury lawsuits, unfair dismissal
safety violations claims
Damage to Assets Natural disasters, fires, vandalism Flooding of a data centre destroying backup
systems
Business Disruption IT system failures, power outages, Banking app downtime during salary payment
network failures days
Execution/Process Failed trades, settlement errors, SWIFT payment sent to wrong account;
Errors data entry mistakes reconciliation failures
The Loss Distribution Approach (LDA) is the most rigorous quantitative method for operational risk
capital estimation. It models the aggregate annual loss as the compound of:
• Frequency Distribution: How many events occur per year? — typically modelled with Poisson(lambda) or
Negative Binomial
• Severity Distribution: How large is each event? — typically modelled with Log-Normal, Weibull, or
Generalised Pareto (for the tail)
Aggregate loss distribution derived by Monte Carlo convolution of frequency and severity distributions
+ LDA provides a rigorous quantitative basis for – OpRisk data is sparse — rare severe events have
OpRisk capital high estimation uncertainty
+ Separating frequency and severity allows targeted – Loss data is often unreported or under-reported due
risk reduction strategies to reputational concerns
+ Scenario analysis supplements sparse data in the – LDA models are highly sensitive to the choice of
extreme tail severity distribution for the tail
+ Risk Control Self-Assessment (RCSA) captures – Causation is complex — root cause analysis is
forward-looking risks missed in history harder than for market/credit risk
+ Quantification enables cost-benefit analysis of risk – Model validation is difficult when loss history is
mitigation investments limited
SECTION 9
Market Risk Modelling
Measuring exposure to adverse movements in financial market prices
Market risk encompasses the risk of loss from movements in equity prices, interest rates, foreign
exchange rates, and commodity prices. It is the primary risk for banks' trading books, investment funds,
and treasury operations.
A critical insight of market risk modelling is that volatility is not constant. Financial markets exhibit
volatility clustering: periods of high volatility (like the 2008 crisis or COVID-19 crash of 2020) follow
each other, as do periods of calm. The GARCH(1,1) model (Bollerslev, 1986) captures this:
Where omega > 0, alpha >= 0, beta >= 0, and alpha + beta < 1 (for stationarity). The sum (alpha + beta)
measures persistence — how long a volatility shock lingers. Typical values for equity markets: alpha ≈
0.10, beta ≈ 0.85, sum ≈ 0.95 (highly persistent).
On a calm day, sigma_t = 0.012 (1.2% daily volatility): 1-day 99% VaR = 2.326 × 1.2% = 2.79%
On a stress day after a market shock (epsilon_t-1 = -3%), the model predicts:
– sigma_t^2 = 0.00002 + 0.09*(0.03)^2 + 0.88*(0.012)^2 = 0.000020 + 0.000081 + 0.0001267 = 0.000228
– sigma_t = 1.51% => 1-day 99% VaR jumps to 2.326 × 1.51% = 3.51%
This dynamic VaR adjusts capital requirements in real time as market conditions change,
far outperforming static models that assume constant volatility.
For fixed-income portfolios, interest rate risk is typically measured using Duration (first-order price
sensitivity to rates) and Convexity (second-order):
Scenario: Interest rates rise by 100bp (1.0%) across the yield curve
– dP/P = -8.5 × 0.01 + 0.5 × 95 × (0.01)^2 = -0.0850 + 0.00475 = -0.0803
– Capital loss = N100B × 8.03% = N8.03 billion
Scenario: Rates fall by 100bp (bond price rises due to convexity benefit)
– dP/P = -8.5 × (-0.01) + 0.5 × 95 × (0.01)^2 = +0.0850 + 0.00475 = +0.0898
– Capital gain = N100B × 8.98% = N8.98 billion
The asymmetry (loss 8.03% < gain 8.98%) is due to positive convexity — bonds gain more
when rates fall than they lose when rates rise by the same amount.
Risk management decision: Reduce duration from 8.5 to 6.0 years to limit rate sensitivity.
+ GARCH captures real market behaviour — volatility – Models calibrated on calm periods dramatically
clustering and regime changes underestimate crisis-period risk
+ Duration/convexity provides fast, analytical sensitivity – Correlations between assets break down exactly
estimates when diversification is needed most
+ Market risk models are well-developed with decades – Liquidity risk (bid-ask spread widening) is hard to
of academic and regulatory refinement incorporate into standard models
+ Data is abundant — liquid markets provide – Model risk: complexity of models can obscure
continuous high-quality price data fundamental assumptions
+ Regulatory frameworks (FRTB, Basel IV) provide – Jump risk (sudden gap moves like circuit-breaker
clear modelling standards events) is poorly captured by diffusion models
SECTION
10 Stress Testing and Scenario Analysis
Testing how organisations survive extreme but plausible adverse conditions
Stress testing and scenario analysis evaluate the resilience of a business, portfolio, or system under
severe but plausible adverse conditions. Unlike VaR which focuses on the 99th percentile of normal
markets, stress testing deliberately explores extreme scenarios — often in the 99.9th percentile or
beyond — to reveal vulnerabilities that standard models miss.
• Sensitivity Analysis: Change one risk factor at a time (e.g., rates +100bp) to measure isolated impact.
Simple but ignores interactions. Note: Fastest to compute; limited realism
• Scenario Analysis (Historical): Replay historical stress episodes on the current portfolio. 2008 Financial
Crisis, COVID-19 crash, 1994 Mexican Peso Crisis. Note: Realistic but constrained to past events
• Scenario Analysis (Hypothetical): Design plausible but novel stress scenarios not seen historically.
Global pandemic, cyber attack on financial infrastructure. Note: Forward-looking but requires judgement
• Reverse Stress Testing: Start from a failure outcome (insolvency, rating downgrade) and work
backwards: what scenario causes it? Note: Reveals hidden vulnerabilities; required by UK PRA
• Regulatory Stress Tests: Mandated scenarios from central banks (e.g., CBN, Fed, ECB). Banks must
show capital adequacy under prescribed shocks. Note: DFAST (US), EBA stress tests (EU), CBN ICAAP
Outcome: Board approves contingency capital raise of N30B to build resilience buffer.
+ Reveals tail risks that VaR and standard models – Scenario selection is subjective — key risks may be
completely miss missed if imagination is limited
+ Regulatory requirement — mandatory for systemic – Results are highly sensitive to scenario assumptions
banks globally — small changes can flip outcomes
+ Improves board-level risk dialogue — concrete – Do not produce a probability — cannot quantify 'how
scenarios resonate better than statistics likely is this scenario?'
+ Reverse stress testing identifies specific failure paths – Computational burden — complex portfolios require
proactively significant resources
+ Informs contingency planning, recovery plans, and – Scenarios can become 'check-box' exercises unless
capital buffers embedded in real decision-making
SECTION
11 Qualitative Risk Modelling Methods
Structured approaches for risks that are difficult or impossible to quantify numerically
Not all risks can be reduced to numbers. Emerging risks, reputational risks, strategic risks, and risks
with no historical data require qualitative and semi-quantitative approaches. These methods are
particularly important in operational risk, IT risk, project risk, and strategic planning.
A risk heat map is a 2-dimensional matrix plotting risks by their likelihood and impact. It provides a
simple visual summary enabling prioritisation and resource allocation.
CRITICAL Immediate
HIGH MEDIUM Monitor HIGH Mitigate CRITICAL Urgent Action
Action
MEDIUM LOW Accept MEDIUM Monitor HIGH Mitigate CRITICAL Urgent Action
Risk Heat Map: Risks in the top-right quadrant demand immediate mitigating action.
RCSA is a structured process in which business units identify their material risks and assess the
adequacy of controls. It is a core tool in operational and IT risk frameworks.
Core Banking HIGH LOW HIGH (CR DR site, backup MEDIUM Quarterly DR testing
System Failure ITICAL) systems
Data Breach / HIGH HIGH CRITICAL Firewall, MFA, HIGH Penetration testing
Cyber Attack SIEM annually
+ Accessible to all stakeholders — no statistical – Highly subjective — ratings depend on who conducts
expertise required the assessment
+ Captures forward-looking and emerging risks with no – No probability estimates — cannot aggregate or
historical data compare risks rigorously
+ Heat maps communicate risk visually to boards and – Risk of optimism bias — managers may underrate
executives risks in their own areas
+ RCSA embeds risk ownership in business lines — – Cannot be used directly for capital requirement
not just a risk function exercise calculations (regulatory limitation)
+ Complements quantitative models — addresses risks – Results can be stale — must be refreshed regularly
not amenable to statistical modelling to remain relevant
SECTION
12 Risk Model Validation and Backtesting
Ensuring models are fit for purpose: accurate, robust, and properly used
Model risk — the risk that a model is wrong, misused, or misunderstood — is a significant source of
risk in its own right. All quantitative risk models must undergo rigorous independent validation before
being used for decision-making or regulatory reporting.
Backtesting compares a model's predictions against actual outcomes. For VaR, we count the number of
days when actual losses exceeded the predicted VaR — called 'exceptions' or 'exceedances'.
For 99% VaR over 250 days: expected exceptions = 1% × 250 = 2.5 exceptions
The Basel Traffic Light Approach classifies VaR models by exception count over the most recent 250
trading days:
Kupiec POF Test Tests whether the observed exception frequency Chi-squared test on exception
equals the expected frequency under the null count
hypothesis
Christoffersen Tests whether exceptions are independent (not Examines sequential exception
Independence Test clustered) — clustered exceptions signal volatility patterns
model failure
Berkowitz Test Tests the entire distribution of PnL predictions, More powerful than
not just the tail exception-based tests
Model Benchmarking Compare model output against simpler Identifies if complexity adds value
benchmark models or industry peers
P&L; Attribution Decompose actual P&L; into risk-factor Required for FRTB internal model
components; compare to model predictions approval
Sensitivity Analysis Change model inputs systematically; verify Validates model logic and
outputs respond plausibly parameter sensitivity
+ Backtesting catches model failures before they – Backtesting requires long P&L; history — less
cause material losses reliable for newer models or instruments
+ Regulatory requirement — Basel III requires annual – Statistical tests have limited power — may accept
backtesting of market risk models flawed models in short samples
+ Model documentation creates institutional knowledge – Model validation requires specialised expertise —
and auditability expensive and resource-intensive
+ Continuous monitoring catches model drift as market – Models can be 'gamed' — developers optimise to
conditions evolve pass backtests without improving true accuracy
SECTION
13 Emerging Approaches — AI/ML in Risk Modelling
How artificial intelligence and machine learning are transforming risk management
Artificial Intelligence and Machine Learning are reshaping risk modelling across all dimensions. While
traditional statistical models rely on explicit assumptions (linearity, normality, stationarity), ML models
learn complex patterns directly from data — offering superior predictive performance in many risk
contexts.
Credit Scoring Gradient Boosting, Capture non-linear relationships in Major African fincechs,
Random Forest, borrower data; outperform logistic Kuda Bank, Fairmoney
Neural Networks regression on complex datasets
Fraud Detection Isolation Forest, Detect anomalous transaction Card fraud detection at
Autoencoders, LSTM patterns in real time; self-adapting to Nigerian banks
Networks evolving fraud techniques
Market Risk LSTM for return Capture non-stationarity in returns; Hedge funds, quantitative
forecasting, adaptive hedging strategies trading desks
Reinforcement
Learning for hedging
Operational NLP for incident Extract risk signals from unstructured SIEM systems, compliance
Risk classification, text (emails, incident reports) monitoring
Anomaly detection
for cyber threats
Regulatory NLP for regulatory Automatically map regulatory RegTech firms, large bank
Compliance text analysis, requirements to internal policies compliance teams
Knowledge Graphs
Stress Testing Deep Neural Capture complex interdependencies Advanced banks' ICAAP
Networks for between macro scenarios and models
non-linear scenario portfolio losses
impact modelling
+ Superior predictive accuracy for high-dimensional, – Black-box models — hard to explain to regulators,
non-linear problems boards, and customers
+ Automatic feature selection — identifies relevant risk – Requires large, high-quality training datasets — poor
drivers from thousands of variables data = poor model
+ Continuous learning — models update as new data – Risk of spurious correlations — models may identify
arrives patterns that do not generalise
+ Natural language processing enables risk mining – Adversarial risk — fraudsters can probe and 'trick'
from unstructured text data ML models once they understand them
+ Anomaly detection in real time — millisecond fraud – Model drift — performance degrades as the
detection at transaction scale environment changes without retraining
+ Ensemble methods are robust to outliers and – Regulatory uncertainty — explainability requirements
overfitting (SR 11-7, Basel model risk guidance) constrain ML
adoption
SECTION
14 Advantages and Disadvantages — Master Summary
A consolidated reference comparing the strengths and limitations of all major risk modelling approaches
+ Converts vague uncertainty into measurable, – All models are simplifications — no model perfectly
comparable, and communicable numbers captures reality
+ Enables rational capital allocation based on actual – Model risk: wrong assumptions can lead to
risk magnitude dangerously false confidence
+ Supports regulatory compliance (Basel III, Solvency – Data dependency — requires historical data that may
II, IFRS 9, PenCom) not represent future
+ Facilitates risk-adjusted performance measurement – Pro-cyclicality: models may reduce estimated risk in
(RAROC, Sharpe Ratio) good times, amplifying cycles
+ Allows comparison and aggregation of different risk – Can create a false sense of precision — '99.7% VaR'
types across an organisation implies accuracy that may not exist
+ Creates institutional risk memory and learning from – Regulatory compliance can become tick-box
loss history exercise rather than genuine risk management
+ Supports proactive risk management — identify and – Expensive — requires data infrastructure, expert
address risks before they materialise staff, and governance frameworks
+ Well-understood theoretical properties — – Parameters estimated from historical data may not
interpretable parameters hold in future regimes
+ Regulatory acceptance and decades of industry – Correlations assumed constant — break down in
validation crises exactly when needed
+ Decomposable — can isolate contributions of – Poor performance for non-linear instruments and
individual risk factors structured products
+ Full distribution of outcomes — captures tail risks – Computationally intensive — large run times for
and non-linearities high-accuracy simulations
+ Flexible — any distribution, any correlation structure, – Entirely model-dependent — GIGO (Garbage In,
any payoff function Garbage Out)
+ Industry standard for complex portfolios and – Convergence requires large N — sampling error
scenario-based capital planning remains for small N
+ Reveals tail and cliff-edge risks invisible to standard – Scenario selection is inherently subjective — key
statistical models risks may be omitted
+ Board-friendly — concrete narratives resonate better – No probability attached — cannot determine how
than abstract statistics likely a scenario is
+ Forward-looking — can incorporate risks with no – Results highly sensitive to scenario design — easily
historical precedent gamed or optimised
+ Regulatory requirement — mandatory for systemic – May not capture interaction effects between
institutions globally simultaneously stressed risk factors
+ Enables risk-based loan pricing — better borrowers – PD models are pro-cyclical — underestimate risk in
pay less good times, overestimate in busts
+ IFRS 9 and Basel III compliance requires rigorous – LGD estimation requires long recovery history —
credit risk quantification sparse for new products
+ Reduces lending decision subjectivity — consistency – Model performance deteriorates rapidly in economic
and fairness regime changes
+ Portfolio-level view identifies sector concentrations – Regulatory validation and approval is costly and
proactively time-intensive
+ Embeds risk culture in business lines — not just a – Optimism bias — managers systematically underrate
risk function activity risks in their own area
+ Complements quantitative models — addresses risks – Results can become stale unless refreshed regularly
not amenable to statistics with disciplined governance
AI / ML RISK MODELS
+ Real-time fraud detection and anomaly identification – Model drift — accuracy degrades as economic
at transaction scale environment changes
+ Handles alternative data sources — mobile data, – Adversarial risk — sophisticated fraudsters can learn
social signals, text to defeat ML detectors
SECTION
CONCLUSI
ON
Risk Modelling — Key Takeaways
• No single model is sufficient: Every risk modelling programme should combine quantitative models
(VaR, ECL, GARCH) with qualitative methods (RCSA, scenario analysis) and emerging techniques (ML).
Each approach has blind spots that others compensate for.
• Model risk is a real risk: The greatest danger in risk modelling is not having too few models — it is placing
too much confidence in the ones you have. All models are wrong; the question is how wrong, and whether
that wrongness matters for your specific decisions.
• Data quality determines model quality: Garbage in, garbage out. Investment in risk data infrastructure —
clean, consistent, granular loss data — is the single highest-return investment in any risk modelling
programme.
• Risk modelling must serve decisions: A technically perfect model that sits in a spreadsheet and never
influences a lending decision, capital allocation, or business strategy has zero value. Model outputs must
be embedded in governance, limits, pricing, and strategic planning.
• Stress testing reveals what models cannot: Standard models quantify risk within the normal range.
Stress tests and scenarios reveal what happens beyond it. Both are essential — for normal times and for
crises.
• Regulatory frameworks are the floor, not the ceiling: Basel III, IFRS 9, and ISO 31000 set minimum
standards. Institutions that treat regulatory compliance as the end goal of risk modelling will always be
behind — best-in-class firms use these frameworks as a starting point for genuine risk insight.
• AI/ML enhances but does not replace judgement: Machine learning models can predict better than
traditional models in many contexts. But they cannot replace domain expertise, regulatory knowledge, and
ethical judgement — especially for risks at the frontier of human experience.
In an uncertain world, the ability to measure, understand, and manage risk intelligently
is not just a compliance requirement — it is a fundamental source of organisational resilience
and competitive advantage.
• Basel Committee on Banking Supervision (2019). Minimum Capital Requirements for Market Risk. Bank for
International Settlements.
• Basel Committee on Banking Supervision (2017). Basel III: Finalising Post-Crisis Reforms. BIS, Basel.
• IFRS Foundation (2014). IFRS 9 Financial Instruments. International Accounting Standards Board.
• ISO (2018). ISO 31000:2018 — Risk Management: Guidelines. International Organisation for
Standardisation.
• Hull, J.C. (2018). Risk Management and Financial Institutions, 5th Ed. Wiley Finance.
• McNeil, A.J., Frey, R. & Embrechts, P. (2015). Quantitative Risk Management: Concepts, Tools,
Techniques, 2nd Ed. Princeton University Press.
• Jorion, P. (2007). Value at Risk: The New Benchmark for Managing Financial Risk, 3rd Ed. McGraw-Hill.
• COSO (2017). Enterprise Risk Management — Integrating with Strategy and Performance. Committee of
Sponsoring Organisations.
• CBN (2022). Risk-Based Capital Adequacy Framework for Nigerian Banks. Central Bank of Nigeria.
• PenCom (2021). Investment Regulation for Licensed Pension Fund Operators. National Pension
Commission Nigeria.