How VaR is calculated
Three main methods are used. Historical simulation: apply the past N days of actual market returns to the current portfolio and rank the resulting P&L. The 99th percentile loss is the 1% VaR. Advantage: no distributional assumptions. Disadvantage: backward-looking — if the historical window excludes a 2008-type scenario, it underestimates crisis risk. Variance-covariance (parametric) VaR: assume returns are normally distributed, estimate portfolio volatility using covariance matrices of all positions, and apply the normal distribution to find the 99th percentile loss. Fast and analytically tractable but entirely dependent on the normality assumption — which financial returns violate, particularly in the tails. Monte Carlo simulation: generate thousands of random scenarios for all risk factors, reprice the portfolio under each scenario, and take the 99th percentile. Most flexible but computationally intensive.
Why VaR failed in 2008
The 2008 crisis exposed VaR’s critical limitations comprehensively. VaR models calibrated to 2003–2007 data systematically underestimated risk because: (1) that period was unusually calm — low volatility and low correlations gave unrealistically benign VaR estimates; (2) historical simulation ignored crisis scenarios; (3) credit and structured product risks were not captured by market-price VaR; (4) VaR is measured at the portfolio level but not at the system level — individual banks showed acceptable VaR while collective positions in the same instruments created systemic risk invisible to any single firm’s model. Regulators have since mandated stress testing (which uses severe but plausible scenarios rather than statistical inference) alongside VaR, recognising that no single model is adequate.
“VaR is like a speedometer that works perfectly below 60mph and breaks down exactly when you need it most — in the crashes.” — Nassim Taleb, paraphrased
What this means for you
VaR remains the industry standard for day-to-day risk management despite its flaws — because it provides a consistent, comparable, and computationally tractable measure. The critical discipline is using it alongside complementary tools: Expected Shortfall for tail quantification; stress testing for specific scenarios; and qualitative judgment about risks that no model captures. For non-practitioners, the lesson from VaR’s 2008 failure is the most important: quantitative risk models are calibrated on past data, and past calm periods systematically underestimate the risk of future crises. Any reported VaR figure should be understood as a minimum likely loss in extreme conditions, not a maximum.