Small Group Tutorials

Here to help students catch up, keep up, and move ahead. Book a consultation here.

How FRTB Internal-Models Algorithms Turn Trading Risk into Capital: Expected Shortfall, Liquidity Horizons, Modellability, NMRFs, Backtesting and P&L Attribution

Reader question: A bank may have sophisticated internal models for its trading desks, but regulators cannot simply accept any model that produces a small risk number. How does the FRTB Internal Models Approach decide which desks and risk factors may be modelled, how expected shortfall is scaled for liquidity, and when a desk is forced back to the standardised approach?

The Basel Fundamental Review of the Trading Book (FRTB) answers this with a layered algorithm rather than one formula. A bank must first obtain supervisory approval for the Internal Models Approach (IMA). Individual trading desks must then pass ongoing backtesting and profit-and-loss attribution tests. Individual market risk factors must pass a risk-factor eligibility test to be treated as modellable. Modellable risks enter a stressed, liquidity-horizon-adjusted 97.5% expected shortfall measure. Non-modellable risk factors receive separate stressed scenario capital. Default risk is captured separately. Desks that fail eligibility tests can be pushed back to the standardised approach.

The architecture is deliberately difficult to game: a sophisticated model is useful only if its risk factors are supported by observable market prices and its modelled profit-and-loss behaviour remains close to the desk’s actual pricing behaviour.

What this page owns — and what it does not

This article owns:

IMA desk approval → backtesting and P&L attribution → risk-factor modellability → expected shortfall with liquidity horizons and stress calibration → NMRF stressed charges → default-risk component → aggregate capital and fallback to standardised capital where required.

It does not replace the FRTB sensitivities-based standardised approach or the standardised default-risk charge. It also does not replace general volatility forecasting or independent price verification.

This is public regulatory mathematics, not a calculation of any bank’s capital requirement and not investment advice.

Why FRTB moved beyond ordinary VaR

Traditional market-risk capital relied heavily on Value at Risk (VaR), which asks for a percentile loss threshold.

If one-day 99% VaR is $10 million, the model says roughly that only 1% of modelled days should lose more than $10 million under its assumptions.

But VaR does not tell us how severe losses are beyond the percentile threshold.

Expected shortfall instead asks:

What is the average loss in the worst tail beyond the chosen confidence level?

FRTB therefore uses 97.5% expected shortfall for the core IMA market-risk measure while retaining VaR for backtesting diagnostics.

Expected shortfall in a simple discrete example

Suppose a simulation produces 1,000 equally weighted portfolio-loss observations ordered from smallest to largest.

At 97.5% confidence, the worst 2.5% corresponds to the worst 25 observations.

A simple empirical expected shortfall is:

ES97.5% = average of the 25 worst losses.

If the 97.5% VaR loss is $20 million but the average of the tail losses is $31 million, expected shortfall captures tail severity that VaR hides.

Step 1: supervisory approval applies at bank and trading-desk levels

Basel MAR30 states that use of internal models for market-risk capital is conditional on explicit supervisory approval.

The bank must demonstrate:

  • sound risk-management systems;
  • skilled staff;
  • independent risk control;
  • model validation;
  • stress testing;
  • integrity of data and implementation.

Importantly, the bank does not receive one blanket permission that automatically covers every trading desk forever.

Trading desks are nominated and individually assessed for IMA eligibility.

Why desk-level eligibility matters

A bank can have a strong rates model and a weak exotic-credit model.

FRTB allows supervisors to distinguish them.

One desk can remain on IMA while another is required to calculate capital under the standardised approach.

This reduces the possibility that a strong model in one area masks model weakness elsewhere.

Step 2: backtesting asks whether losses exceed model forecasts too often

FRTB backtesting compares one-day 99% VaR measures with both:

  • actual P&L (APL);
  • hypothetical P&L (HPL).

An exception occurs when the observed loss exceeds the relevant VaR threshold.

Over a sufficiently long sample, too many exceptions indicate that the model may be understating risk.

Basel retains a traffic-light style approach in which exception counts can increase the capital multiplier and, at the desk level, affect model eligibility.

Why backtesting uses VaR when capital uses expected shortfall

This seems contradictory at first.

Expected shortfall is harder to backtest directly with the same simple frequency logic because it is an average tail measure rather than a single quantile threshold.

VaR provides a clean observable event:

Did today’s loss exceed yesterday’s predicted 99% quantile?

FRTB therefore uses VaR as a diagnostic test even though expected shortfall is the primary capital measure.

Step 3: P&L attribution tests whether the risk model explains the desk

Backtesting asks whether the model captures loss magnitude often enough.

The P&L Attribution Test (PLAT) asks a different question:

Does the risk model explain the same profit-and-loss behaviour as the front-office pricing system?

The framework compares:

  • Hypothetical P&L (HPL) from the desk’s pricing systems under specified assumptions;
  • Risk-Theoretical P&L (RTPL) generated from the risk factors included in the internal risk model.

The current Basel framework uses statistical tests including rank correlation and distribution comparison to classify desks into zones.

Why PLAT is a model-boundary test

Suppose a desk’s front-office P&L moves sharply with volatility skew, but the risk model includes only flat implied volatility.

The model can appear stable while missing an important source of actual P&L.

PLAT exposes that gap because HPL and RTPL will behave differently.

This is not merely “model accuracy”; it tests whether the model’s chosen risk factors span the economics that drive desk P&L.

Step 4: each risk factor must prove that it is modellable

Passing PLAT does not mean every risk factor may automatically enter the expected-shortfall model.

Basel’s Risk Factor Eligibility Test (RFET) requires sufficient representative real price observations.

MAR10 defines real prices to include:

  • actual transactions by the bank;
  • arm’s-length transactions between other parties;
  • firm quotes at which an arm’s-length transaction could occur.

MAR31 sets detailed observation-frequency and representativeness rules.

A risk factor that fails those rules becomes a Non-Modellable Risk Factor (NMRF).

Observed market data and model parameters are not the same thing

Suppose a bank fits a five-parameter volatility function to sparse option quotes.

The five fitted parameters may change smoothly every day.

That does not prove those parameters are directly observable market prices.

Basel therefore requires modellability to be assessed using the market data used to calibrate such parametric curves or surfaces rather than allowing a fitted parameter to become “modellable” merely because software produces it daily.

This is a strong protection against manufactured observability.

Third-party vendor data can count, but only with controls

MAR31 allows real-price observations from third-party vendors if the required conditions are met, including information about observation counts and dates, identifiers that permit mapping to risk factors and auditability of the vendor’s pricing information.

So:

vendor data ≠ automatically valid RFET evidence.

The provenance and representativeness of the data matter.

Step 5: calculate expected shortfall for modellable risk factors

For risk factors that pass RFET, the bank calculates expected shortfall under the approved internal model.

At a high level:

  1. map each position to approved market risk factors;
  2. generate historical or modelled shocks consistent with Basel rules;
  3. revalue or approximate portfolio changes;
  4. construct the loss distribution;
  5. take 97.5% expected shortfall;
  6. adjust for regulatory liquidity horizons;
  7. apply stress-period scaling using the approved reduced set of risk factors.

Liquidity horizons change the holding-period assumption

FRTB recognises that not every market risk can be closed or hedged within ten days.

The framework assigns risk factors to liquidity horizons such as:

  • 10 days;
  • 20 days;
  • 40 days;
  • 60 days;
  • 120 days.

More illiquid risk is therefore capitalised over a longer assumed period.

This is a major conceptual difference from simply calculating one 10-day risk number for every instrument.

A teaching approximation for horizon scaling

If independent daily risk scaled perfectly with square root of time, a 40-day risk could be approximated from 10-day risk as:

Risk40 ≈ Risk10 × √(40/10) = 2 × Risk10.

FRTB’s actual liquidity-horizon expected-shortfall construction is more structured because risk factors are grouped into horizon layers and incremental components are aggregated according to the Basel formula.

The teaching intuition is still useful:

longer assumed liquidation time → larger tail-risk capital, all else equal.

Why horizon layers matter

Suppose a portfolio has:

  • liquid G10 rate risk in a short horizon;
  • less-liquid credit basis risk in a longer horizon.

It would be overly conservative to scale the entire portfolio to the longest horizon, but too optimistic to treat every risk as 10-day.

The FRTB layer construction applies longer-horizon scaling to the risks assigned to those horizons while preserving the portfolio structure.

Step 6: calibrate to a period of stress

Current market volatility is not the only input.

FRTB requires expected shortfall to reflect a historical stress period relevant to the portfolio.

Because a full risk-factor set may not have sufficiently long clean historical data, the framework permits a reduced set of risk factors that must explain a sufficiently large share of the full model’s variation under the rules.

The model then scales current full-set expected shortfall using the relationship between stressed and current expected shortfall for the reduced set.

Why stress scaling exists

Suppose markets have been calm for two years.

A model calibrated only to recent data can produce very small tail losses.

Stress scaling asks:

How large would the modelled risk be if the portfolio were exposed to a historically stressed market environment?

This reduces procyclicality and prevents capital from collapsing merely because recent volatility is quiet.

Step 7: non-modellable risk factors receive separate stressed charges

Risk factors that fail RFET do not simply disappear.

They are capitalised through a stressed expected-shortfall/stress-scenario measure under MAR33.

For each NMRF, the stress scenario must be at least as prudent as the 97.5% stressed expected-shortfall calibration, and its liquidity horizon is at least the greater of the assigned regulatory horizon and 20 days.

This creates a deliberate penalty for risk that cannot be supported by sufficient real price observations.

NMRF capital is an observability penalty, not necessarily a volatility penalty

A risk factor can be economically quiet but still non-modellable because there are too few real observations.

Another risk factor can be volatile yet modellable because it trades frequently.

Therefore:

modellability measures evidence quality and market observability, not simply volatility magnitude.

Why this can matter for exotic products

An exotic option may depend on a volatility point that is rarely quoted or traded.

The desk’s pricing model can interpolate that point every day, but the regulatory model may still classify it as non-modellable if real-price evidence is insufficient.

This is one reason exotic portfolios can attract substantial NMRF capital even when headline delta or vega appears modest.

Step 8: model default risk separately

Expected shortfall captures continuous market moves and related trading risks, but jump-to-default risk requires a different horizon and tail treatment.

FRTB IMA therefore includes a separate Default Risk Charge (DRC) model for approved desks with credit/equity default exposure.

The internal-model DRC uses a one-year capital horizon and very high confidence calibration under the Basel rules.

This page keeps DRC as a separate component because default jumps are structurally different from ordinary daily market volatility.

Step 9: aggregate desk and bank-level capital

For model-eligible desks, MAR33 combines:

  • expected shortfall for modellable risk factors;
  • stressed charges for NMRFs;
  • default-risk capital where applicable;
  • capital multipliers and backtesting adjustments.

Desks that are not approved or that lose eligibility are calculated under the standardised approach and added separately.

The bank therefore holds a hybrid market-risk capital state:

IMA capital for eligible desks + standardised capital for ineligible/out-of-scope desks.

The multiplier prevents the model from being taken at face value

MAR33 applies a multiplication factor with a regulatory floor. The base multiplier is 1.5 and supervisors can increase it; backtesting exceptions can also create an add-on.

Conceptually:

Capital is not merely yesterday’s model ES.

The framework uses recent observations, averaging and multipliers to reduce instability and penalise poor model performance.

Failure can push a desk back to the standardised approach

This is one of the most important control loops in FRTB.

A desk that fails required tests does not get to keep using an internal model merely because the bank prefers the lower capital number.

Depending on the failure and the framework’s zone rules, the desk can lose model eligibility and must use the standardised approach.

This gives the tests economic consequences.

Why the standardised approach is also a benchmark

The standardised approach is not only a fallback for small banks.

Under FRTB it also provides:

  • a capital measure for non-IMA desks;
  • a common benchmark against which modelled outcomes can be understood;
  • a floor-like discipline because desks cannot simply disappear from capital when IMA eligibility fails.

This connects directly to the existing FRTB sensitivities-based algorithms page.

Evidence polarity: what supports confidence?

Evidence for a credible IMA implementation includes:

  • supervisory approval for the bank and relevant desks;
  • stable desk definitions;
  • risk factors mapped to representative real price observations;
  • RFET evidence that is auditable and current;
  • HPL and RTPL distributions that pass PLAT;
  • backtesting exception counts consistent with model quality;
  • expected-shortfall calculations reproducible from approved historical data;
  • liquidity-horizon assignments consistent with Basel categories;
  • NMRF capital traceable to explicit non-modellable factors;
  • stress-period and reduced-set selection supported by documented tests.

Evidence against confidence includes:

  • risk factors labelled modellable without representative real prices;
  • HPL and RTPL diverging systematically;
  • large backtesting exception clusters;
  • stress periods chosen only because they minimise capital;
  • long-horizon risks classified into short liquidity horizons without evidence;
  • NMRFs disappearing after a data-source change without documented RFET evidence;
  • desk restructurings timed to avoid model failures.

Counterexample: more data points do not always prove modellability

A vendor can publish an evaluated price every day.

If those values are not representative real price observations under MAR31, daily frequency alone does not satisfy RFET.

Model-generated continuity is not the same as market observability.

Counterexample: a desk can pass backtesting and fail PLAT

A risk model might predict tail loss frequency reasonably well but omit risk factors that drive day-to-day front-office P&L.

VaR exceptions can look acceptable while RTPL poorly explains HPL.

That is precisely why FRTB uses both tests.

Counterexample: a desk can pass PLAT but still have NMRFs

PLAT is a desk-level comparison of risk-theoretical and hypothetical P&L.

RFET is a risk-factor-level evidence test.

A desk can have broadly good model representation while individual sparse factors remain non-modellable and require separate stressed capital.

Counterexample: expected shortfall can fall while capital rises

Suppose current modellable-market ES declines, but several previously modellable exotic risk factors fail RFET after market liquidity disappears.

NMRF charges can rise enough that total capital increases.

Therefore:

lower model ES ≠ necessarily lower FRTB IMA capital.

Counterexample: a 10-day model is not enough for every risk

If a portfolio contains a risk assigned a 120-day liquidity horizon, treating it as 10-day because the bank’s internal risk report uses 10-day VaR understates the regulatory assumption.

The liquidity-horizon transformation is a required part of the IMA capital engine.

Weak links in implementation

Desk-boundary drift. Trades move between desks in ways that distort backtesting or PLAT histories.

HPL/RTPL mapping error. Front-office and risk systems use different trade populations or market-data timestamps.

Real-price duplication. The same observation is counted multiple times toward RFET.

Vendor-provenance failure. Third-party observations lack required identifiers or audit support.

Liquidity-horizon misclassification. A risk factor inherits the product label instead of the correct regulatory horizon.

Stress-window cherry-picking. The chosen period minimises capital rather than satisfying the representativeness rules.

Reduced-set weakness. The reduced risk-factor set no longer explains the required share of full-set variation.

NMRF omission. Sparse risk factors are silently interpolated and left inside modellable ES.

Exception-count mismatch. APL and HPL backtesting populations are not aligned with the VaR calculation.

Diagnostics: how to test the engine

  • tail-average test: construct a known loss distribution and reproduce empirical 97.5% expected shortfall.
  • horizon test: move one risk factor from a short to longer liquidity horizon and verify capital responds in the expected direction.
  • RFET sparse-data test: remove representative real-price observations and require the risk factor to become non-modellable under current MAR31 rules.
  • vendor-data test: remove audit/provenance fields and prevent vendor observations from qualifying.
  • PLAT missing-factor test: omit a material skew or basis factor and verify HPL/RTPL statistics deteriorate.
  • backtesting test: inject known VaR exceptions into a 250-day history and reproduce the applicable multiplier treatment.
  • stress-period test: compare current and stressed reduced-set ES and verify the stress-scaling ratio is reproducible.
  • NMRF test: migrate one factor from modellable to non-modellable and verify it exits core ES treatment and receives the separate stressed charge.
  • desk-fallback test: force a desk into a failing test zone and verify standardised capital is substituted according to the framework.
  • full reconciliation test: aggregate IMA-eligible desk capital, NMRF charges, DRC and standardised desks and reconcile to the bank-level market-risk requirement.

What would falsify confidence?

Confidence should be withdrawn if the model cannot reproduce expected shortfall from its saved loss distribution, if risk-factor modellability cannot be supported by auditable real-price evidence, if PLAT and backtesting are run on inconsistent trade populations, if long liquidity horizons are ignored, if NMRF charges are not traceable, or if a desk that fails eligibility continues to receive IMA capital treatment without a documented supervisory basis.

Alternatives and limits

The FRTB standardised approach is the primary alternative regulatory calculation for desks not using IMA. It is more prescriptive and sensitivity-driven.

A bank may also use internal VaR, stress testing, scenario analysis and economic capital models for day-to-day risk management. Those models can be useful without satisfying IMA rules.

IMA approval does not certify that a model forecasts every future crisis. It certifies that the bank meets a regulatory framework of model design, market-data evidence, tail-risk calibration, desk testing and governance.

How this connects to the surrounding knowledge estate

FRTB sensitivities-based algorithms own the standardised method that ineligible desks fall back to. The standardised DRC page provides the parallel rule-based treatment of default risk. Independent price verification connects to market-data quality and pricing control. GARCH/EWMA volatility models illustrate why statistical forecasting and regulatory stressed expected shortfall are related but not identical tasks.

Verification and update triggers

Preserve:

  • Basel Framework version;
  • supervisory approval scope;
  • desk definitions;
  • HPL, APL and RTPL histories;
  • VaR backtesting outputs;
  • real-price observations and vendor provenance;
  • RFET classifications;
  • liquidity-horizon assignments;
  • expected-shortfall loss distributions;
  • stress period and reduced risk-factor set;
  • NMRF stress calculations;
  • DRC outputs;
  • standardised fallback capital.

Revalidate after Basel rule amendments, desk restructurings, material pricing-model changes, vendor-data changes, loss of market liquidity, repeated backtesting exceptions, PLAT deterioration or supervisory findings.

Primary and high-quality references

Educational boundary: This article explains public Basel market-risk algorithms. It does not determine any bank’s regulatory capital, model eligibility or supervisory status, and it does not provide trading or investment advice.

Discover more from Bukit Timah Tutor

Subscribe now to keep reading and get access to the full archive.

Continue reading