Risk Management Engines: The Gauge the Driver Isn't Supposed to Touch
Surya · 6 min read
A fuel gauge only means something if the driver isn't allowed to recalibrate it every time the needle gets uncomfortably close to empty. The entire point of the gauge is that it tells the driver something they might not want to hear, on a schedule they don't control. The moment the person being warned is also the person who sets what counts as a warning, the gauge stops measuring the tank and starts measuring how the driver feels about running out of gas.
Banks run a version of that exact gauge on their own trading books, and in 2012, one of the largest banks in the world got caught adjusting the dial itself.
What a risk engine actually measures, and what it isn't
Counterparty credit risk asks whether the party on the other side of a trade will still be there to pay up. A market risk engine asks the completely different question sitting underneath every position a firm holds on its own book: if the market itself moves against me, how much could I actually lose? The standard answer is Value at Risk (VaR) — a statistical estimate, recalculated daily, of the maximum loss a portfolio could reasonably expect over a set period at a given confidence level. VaR's companion is stress testing: running the same portfolio through a scenario deliberately worse than anything the statistical model assumes, because VaR is only ever as good as the historical data it was trained on, and markets occasionally do things history never did.
Both tools only work if the model producing the number is trustworthy in a very specific way: nobody whose bonus, reputation, or job depends on that number staying low should be the one deciding how it's calculated.
Example 1: the gauge JPMorgan recalibrated itself
In 2012, JPMorgan's Chief Investment Office built a massive, increasingly volatile position known as the Synthetic Credit Portfolio — the trades that became infamous as the "London Whale." As that portfolio's real risk grew through the first quarter of 2012, it began breaching multiple market-risk limits the bank itself had set specifically to prevent large trading losses. Rather than shrink the position, the CIO changed the VaR model measuring it. The US Senate's Permanent Subcommittee on Investigations later found that regulators at the Office of the Comptroller of the Currency were told in advance the model change was projected to drop the CIO's reported VaR by 44% — a number the Subcommittee itself called suspicious on its face — and the OCC raised no real objection at the time. The Subcommittee's investigation went further than the headline number: the replacement model itself turned out to contain an operator error inside its own spreadsheet, a formula that divided by the sum of two numbers instead of their average, which on its own cut the model's reported volatility roughly in half — a mechanical accident that happened to point in exactly the direction the desk needed it to. The position went on to lose the bank roughly $6.2 billion. The Subcommittee's own conclusion was blunt: this wasn't rogue trading hidden from the bank's systems. It was the bank's own risk-measurement system being deliberately retuned by the desk it was supposed to be watching, then quietly undershooting the truth again for a reason nobody had even chosen on purpose.
Example 2: India just finished building the standardized version of the fix
RBI issued its final Basel III Market Risk Capital Directions on September 21, 2026 — four days before this was written — adopting the Simplified Standardised Approach, the calibrated version of the Basel Committee's post-crisis Fundamental Review of the Trading Book framework, for how Indian banks must calculate capital against market risk, after draft guidelines first circulated in February 2023 and intermediate transition scalars that have already been phasing banks toward the new numbers since April 2024. The full framework becomes mandatory on April 1, 2027.
The design choice underneath that timeline is the same one RBI already made for counterparty exposure limits: a prescribed, standardized calculation instead of letting each bank's own internal model set the number. That's not a coincidence of drafting style. It's a direct structural answer to exactly the gap JPMorgan exposed — a bank's own model, run by the same organization whose trading revenue benefits from that model reporting less risk, is the wrong place to leave the final say on how dangerous a position actually is.
Reality check: this is a different failure than Credit Suisse's
It's worth being precise about what kind of failure this is, because it isn't the one Archegos exposed at Credit Suisse. Credit Suisse's risk function measured Archegos's exposure correctly, flagged it a year in advance, and the number was simply never acted on — an enforcement failure. JPMorgan's CIO didn't ignore a correct number. It changed the number itself, so there was never an accurate figure left for anyone to act on in the first place — a measurement failure. Both are real, and they need different fixes: an enforcement failure needs an escalation path with a consequence that fires automatically; a measurement failure needs the model itself to be governed by someone with no stake in what it reports. A risk system that only solves one of these problems has solved half of what actually went wrong across these two cases.
Why this matters for a Business Analyst
Back to the fuel gauge
A requirement that says "build a risk dashboard" is unfinished until it answers a question neither Archegos nor the London Whale needed to ask out loud: who is allowed to change how the model calculates its own number, and does that person have anything to gain from the number coming out lower? JPMorgan's CIO could request a VaR model change and get it through with essentially no independent challenge. A properly scoped system separates the desk generating the risk from whoever governs how that risk gets measured, with model changes routed through a party who never benefits from the answer looking better than reality. A dashboard that reports whatever number the desk being measured is comfortable with has technically satisfied "build a risk dashboard" while missing the entire point of building one.
Lighthouse Insight
The fuel gauge only protects the driver from running out of gas if the driver never gets to hold the calibration screwdriver. JPMorgan held it, turned it, and a $6.2 billion loss followed a 44% drop in a number that was never actually true. Four days before this was written, India's central bank finished building its own version of the fix — not a rule that trusts a bank's model less out of suspicion, but one built on the plain fact that nobody should be allowed to grade their own risk.
Reference anchors
- US Senate Permanent Subcommittee on Investigations: JPMorgan Chase Whale Trades — A Case History of Derivatives Risks and Abuses (2013)
- RBI: Reserve Bank of India (Commercial Banks — Minimum Capital Requirements for Market Risk) Directions, 2026
- KPMG India: Fundamental Review of the Trading Book — An Overview
Continue the system
A curated path through the next concept, so one essay becomes a map.