Portfolio Construction · Reading 92

Value At Risk

CFA Level I · Portfolio Construction · Reading 92: Introduction to Risk Management · about 32 min

What you'll learn

Module 92.1

Introduction to Risk Management

This reading defines risk management and the features of a risk management framework, and explains risk governance, risk tolerance and risk budgeting. It then classifies financial and non-financial risks and their interactions, and describes how risk exposures are measured (including VaR and CVaR) and modified.

LOS 92.a — What risk management is

Risk management is the process by which an organization, a portfolio manager or an individual (1) identifies its risk tolerance, (2) identifies and measures the risks it faces, and (3) modifies and monitors those risks, so that the bundle of risks it keeps is the one best suited to its goals.

  • The goal is to hold the right risks. It is not to minimize or eliminate risk: returns above the risk-free rate come from bearing risk. An organization may deliberately increase its exposure to risks it is well placed to manage and reduce its exposure (through organizational changes, insurance or hedging) to risks it handles poorly.
  • Managers cannot control the returns of any single period. They can control which risks they take and how much total risk they take. Risk management therefore means choosing the optimal bundle of risks and putting in place the strategies that achieve it.
  • The same logic applies to individuals, who choose the bundle of risks that maximizes their expected utility.

The figure puts the steps in order. Risk governance sets the tolerance; the risks are then identified and measured; exposures are compared with the tolerance and modified when they are out of line; and the results are monitored, communicated and fed into strategic risk analysis.

Flow diagram. Risk governance (senior management) leads to step 1, set risk tolerance, and then to risk budgeting, which allocates the tolerated risk. Next is step 2, identify and measure the risks. A decision box asks whether exposures are within risk tolerance. If no, step 3 modifies the risks by avoiding, preventing, accepting, transferring or shifting them, and then the exposures are monitored. If yes, the process moves on to monitoring. Monitoring exposures over time leads to communicating across the organization and then to strategic risk analysis, which feeds back to the top of the process.
The risk management process as a loop

LOS 92.b — Features of a risk management framework

A comprehensive risk management framework addresses all of the following:

  1. Establishing processes and policies for risk governance.
  2. Determining the organization's risk tolerance.
  3. Identifying and measuring existing risks.
  4. Managing and mitigating risks so that the organization ends up with its optimal bundle of risks.
  5. Monitoring risk exposures over time.
  6. Communicating across the organization.
  7. Performing strategic risk analysis.

Disciplinary action against individual employees (for example, penalizing a trader who breached a limit) is not one of these features.

LOS 92.c — Risk governance

Risk governance is senior management's determination of the organization's risk tolerance, of the elements of its optimal risk exposure strategy, and of the framework for oversight of the risk management function. It is set at the enterprise level and aims to manage risk in a way that supports the organization's overall goals. It gives organization-wide guidance on which risks to pursue efficiently, which to limit, and which to reduce or avoid. A risk management committee gives different parts of the organization a forum to raise issues of risk measurement, integration of risks and mitigation.

TermMeaningRelationship
Risk governanceSenior management's overall oversight of risk managementThe umbrella concept
Risk toleranceHow much overall risk the organization will take, and which risksOne element decided under risk governance
Risk budgetingAllocating the acceptable risk across assets/investmentsOne element carried out within risk governance

LOS 92.d — How risk tolerance affects risk management

Risk tolerance is the overall amount of risk an organization will take in pursuing its goals. Top management sets it by identifying the risks the firm can take effectively and those it should reduce or avoid. The factors that determine it include:

  • expertise in its lines of business;
  • skill at responding to negative outside events;
  • the regulatory environment;
  • financial strength and the ability to withstand losses.

Management must examine risks that arise both inside and outside the organization and weigh each one against the expected benefit of bearing it. A low risk tolerance does not require cutting every identified risk. Some risks are worth keeping because they are consistent with the organization's objectives.

LOS 92.e — Risk budgeting

Risk budgeting allocates the organization's total acceptable risk (its risk tolerance) to assets or investments by considering their risk characteristics and how they combine. The aim is to place that risk where expected returns over time are greatest.

  • The budget can be a single metric: return variance, portfolio beta, portfolio duration or value at risk.
  • It can be split by investment category (e.g., domestic equities, domestic debt, international equities, international debt).
  • It can be built from risk factors (interest rate risk, equity market risk, foreign exchange risk), which are estimated and aggregated to check that the total matches the risk tolerance.

LOS 92.f — Financial and non-financial risks and how they interact

Financial risks arise from exposure to financial markets. Non-financial risks arise from the organization's operations and from sources outside it.

Key concept

Financial risksNon-financial risks
Credit risk: the counterparty may not meet its contractual obligationsOperational risk: losses from human error, faulty processes, inadequate security or business interruption (includes cyber risk)
Liquidity risk: having to sell an asset below its fair value because of market conditionsSolvency risk: running out of cash and being unable to continue operating
Market risk: uncertainty about the prices of stocks, commodities and currencies, and about interest ratesRegulatory risk: the regulatory environment changes, adding costs or restricting activities
Governmental or political risk (includes tax risk): political action outside the regulatory framework, such as a tax increase, imposes costs
Legal risk: uncertainty about exposure to future legal action
Model risk: valuations from the organization's models are wrong
Tail risk: extreme outcomes are more likely than the organization's analysis indicates (e.g., from wrongly assuming normality)
Accounting risk: accounting policies or estimates are judged incorrect

Individuals also face mortality risk (dying before providing for dependents, usually addressed with life insurance) and longevity risk (outliving one's assets, which a lifetime annuity reduces), as well as the risk of health care expenses (health insurance). The approach is the same as for an organization: decide which risks to bear (self-insure), which to prevent or avoid, and which to take in order to maximize expected utility.

Interactions. Risks are not independent. Suppose a commodity producer hedges price risk with a swap arranged with a dealer. If commodity prices fall sharply, the dealer owes the producer a large payment under the swap, so the producer's credit risk rises. If the dealer disputes the contract, legal risk appears. Credit and legal losses may force the producer to sell assets in a weak market (liquidity risk), and those losses drain cash (solvency risk). Interactions like these are frequent and matter most in periods of market stress, so risks must be assessed together as well as one at a time.

LOS 92.g — Measuring and modifying risk exposures

Measures

Key concept

MeasureWhat it measures
Standard deviationVolatility of asset prices or interest rates (stand-alone risk); can mislead for non-normal distributions (negative skew, fat tails)
BetaMarket risk of equities/equity portfolios; appropriate for securities held in a well-diversified portfolio
DurationPrice sensitivity of debt securities to interest rate changes
DeltaSensitivity of a derivative's value to the underlying's price
GammaSensitivity of delta to the underlying's price
VegaSensitivity of a derivative's value to the underlying's volatility
RhoSensitivity of a derivative's value to the risk-free rate

Common measures of tail risk (also called downside risk) are:

  • Value at risk (VaR) is the minimum loss over a given period that will occur with a stated probability, so a VaR figure always states an amount, a period and a probability. Equivalently, it is the maximum potential loss at the matching confidence level (95% for a 5% VaR), but larger losses still occur in the tail, so VaR is not the worst possible loss. Results depend heavily on the inputs and the model chosen, so VaR should be used together with other measures. Banks use it widely, including to set minimum capital requirements.
  • Conditional VaR (CVaR) is the expected loss given that the loss exceeds the VaR threshold (the probability-weighted average of those losses). It is similar to the loss given default used for debt securities.

Example. A fund reports a one-week VaR of $600,000 at 5%. In about 5% of weeks the fund should expect to lose at least $600,000. If the losses in those worst weeks average $850,000, the CVaR is $850,000.

Two methods supplement VaR. Stress testing examines the effect of a specific (usually extreme) change in one key variable. Scenario analysis combines changes in several inputs at once. Rare events, operational risks and tax or regulatory changes often need subjective estimates. The market prices of insurance and derivatives also reveal market participants' estimates of expected losses, and operational risk can be estimated from large samples of firms (the overall probability of a large operational loss and the average size of such losses). A subjective estimate of a risk's probability and size is still better than ignoring the risk.

Modifying risk exposures

Key concept

MethodHow it worksExample
Avoid a riskDo not engage in the activityNot investing in a politically unstable country. Usually a top-management decision, made when the risk outweighs the activity's benefits
Prevent a riskTake steps to prevent the loss or make it less likelyStronger data security against breaches, when the benefit exceeds the cost
Accept (bear) a risk / self-insuranceKeep the risk, ideally efficiently (e.g., via diversification or a loss reserve)Reserve account for small claims. Self-insurance only means bearing the losses; it can reflect inaction rather than a deliberate decision
Risk transferAnother party takes on the riskInsurance, surety bonds (pay if a third party fails to perform), fidelity bonds (employee theft or misconduct). Insurers diversify across risks that ideally are not highly correlated, and may buy reinsurance for concentrated risks
Risk shiftingChange the distribution of possible outcomes, mainly with derivativesForwards, futures or swaps to hedge currency risk; buying puts to set a floor; writing calls (gives up upside, and the premium reduces the downside)

The choice is always a cost–benefit comparison, and several methods may be combined for a single risk. An insurance policy with a deductible is an example: the insurer takes on losses above the deductible (risk transfer), while the insured bears the losses up to it (self-insurance). The aim is a risk profile consistent with the organization's risk tolerance.

Common exam traps

  • A what-if run that moves interest rates and oil prices together is scenario analysis. A stress test looks at one key variable.
  • Do not read VaR as the worst possible loss or as the average loss in the tail. The average of the losses beyond VaR is CVaR.
  • Buying puts or writing calls reduces a loss by changing the distribution of outcomes, so it is risk shifting. Risk transfer means another party, such as an insurer, takes the risk on.
  • Beta does not measure interest rate sensitivity. Duration and rho do.
  • Solvency, model, tax and tail risk sound financial, yet they are classified as non-financial risks.

Bottom line

  • Risk management identifies the risk tolerance, identifies and measures the risks faced, and modifies and monitors them, with the aim of holding the optimal bundle of risks rather than minimizing or eliminating risk.
  • Risk governance is senior management's determination of risk tolerance, of the elements of the optimal risk exposure strategy and of the framework for overseeing risk management, set at the enterprise level.
  • Risk tolerance depends on expertise in the lines of business, skill at responding to negative outside events, the regulatory environment and financial strength, and a low risk tolerance does not require cutting every identified risk.
  • Risk budgeting allocates the total acceptable risk to assets or investments, using a single metric such as variance, beta, duration or VaR, a split by investment category, or aggregated risk factors.
  • Financial risks are credit, liquidity and market risk, while operational, solvency, regulatory, political and tax, legal, model, tail and accounting risks are non-financial, and because risks interact, especially in periods of market stress, they must be assessed together as well as one at a time.
  • VaR is the minimum loss over a stated period that will occur with a stated probability, so it is not the worst possible loss, and CVaR is the expected loss given that the loss exceeds the VaR threshold.
  • A stress test examines a specific, usually extreme, change in one key variable, while scenario analysis changes several inputs at once.
  • Risk can be avoided, prevented, accepted through self-insurance, transferred to another party such as an insurer, or shifted by changing the distribution of outcomes with derivatives, the choice being a cost–benefit comparison.

Quick check

Question 1Core

Which of the following is most likely one of the goals of an organization's risk management process?

Show answer and explanation

Correct answer: A

The risk management process identifies the organization's risk tolerance, identifies and measures the risks it faces, and then modifies and monitors those risks. Its aim is the optimal bundle of risks rather than the smallest possible amount of risk.

Why the other options are wrong

  • B. Minimizing risk is not the goal. Returns above the risk-free rate require bearing risk, and an organization may deliberately increase risks it manages well.
  • C. Eliminating all risk would also eliminate the returns that come from bearing it; risk management keeps the risks that fit the organization's tolerance and goals.

Key takeaway Risk management chooses which risks to bear; it does not try to avoid all risk.

Practice Questions

Question 2Core

Which statement about how an organization sets its risk tolerance is most accurate?

Show answer and explanation

Correct answer: A

Financial strength matters since it indicates how large a loss the organization can absorb. Other factors are its expertise in its lines of business, its skill at responding to negative outside events and its regulatory environment.

Why the other options are wrong

  • B. Even with low risk tolerance, an organization may choose to keep some risks that fit its objectives; risk management does not aim to reduce every risk.
  • C. Risk tolerance must reflect risks arising inside the organization as well as those arising outside it.

Key takeaway Risk tolerance depends on expertise, response skill, regulation and financial strength, and covers internal and external risks.

Question 3Core

To protect its equity portfolio, the Ashcombe Teachers' Pension Fund buys over-the-counter put options from a single dealer. Over the next quarter, equity prices fall 25% and the puts move deep in the money. Which risk has most likely increased the most for the fund as a result of this move?

Show answer and explanation

Correct answer: B

Risks interact. The puts reduced the fund's market risk, but after the fall the dealer owes the fund a large payment on them. If the dealer fails to pay, the fund loses the protection it bought just when it needs it, so its credit (counterparty) risk has grown with the value of the puts.

Why the other options are wrong

  • A. The puts were bought to offset losses on the equities, and their gains now cushion the fall. The decline has moved exposure from the market to the dealer.
  • C. Operational risk comes from human error, faulty processes, poor security or business interruptions. Nothing in the market move changes the fund's internal processes.

Key takeaway Hedging market risk with OTC derivatives creates counterparty credit risk, and that credit risk grows as the hedge gains value.

Question 4Core

Westbury College buys a flood insurance policy for its campus buildings. For each flood claim, the college pays the first $400,000 of damage itself, and the insurer pays the rest. Which description of this arrangement is most accurate?

Show answer and explanation

Correct answer: C

Insurance is a form of risk transfer: the insurer takes on the losses it covers in return for premiums. Because the college pays the first $400,000 of every claim, it bears that layer of each loss itself, which is self-insurance. The arrangement therefore combines risk transfer with self-insurance.

Why the other options are wrong

  • A. The deductible means the college still bears every loss up to $400,000, so it keeps part of its flood risk.
  • B. Risk shifting changes the distribution of outcomes mainly through derivative contracts, such as forwards, swaps or options. Buying insurance is classified as risk transfer.

Key takeaway Insurance transfers risk; a deductible is a layer of self-insurance; derivatives used to alter outcomes are risk shifting.

This reading has 20 questions in the full bank. Practice all of them.

Key Takeaways