Risk Management

Risk Management Essentials: Drawdowns, Value at Risk, and the Limits of Both

Jeevan B A10 min readUpdated

Risk management is the practice of deciding, in advance, how much you are prepared to lose and structuring positions so that outcome holds. It is not about avoiding losses. It is about ensuring no single loss is large enough to end the exercise.

That distinction matters because of an arithmetic fact most people know and few act on: losses and gains are not symmetric. Recovering from a loss requires a larger gain than the loss itself, and the gap widens fast.

The arithmetic that makes drawdowns expensive

Lose 20 percent and you need 25 percent to get back. Lose 50 percent and you need 100 percent. Lose 70 percent and you need 233 percent, which for most portfolios means it is not coming back at all.

The gain required to recover from a given loss, rising non-linearly. A 20 percent loss needs a 25 percent gain, a 50 percent loss needs 100 percent, and a 70 percent loss needs 233 percent. 0 100% 200% 300% 400% 20% 40% 60% 80% loss taken 25% 100% 233% gain required to get back to even
The curve is simply the loss divided by what remains after it. It is flat and forgiving while losses are small, then turns almost vertical. That shape is the entire argument for capping losses early rather than hoping for a recovery: past roughly 40 percent you are no longer managing a portfolio, you are waiting for an unlikely event.

This is why professional risk limits are set well below the level that feels dangerous. By the time a drawdown feels alarming, the recovery required has already become implausible.

Position sizing decides your drawdowns

Sizing is the lever that actually controls risk. Everything else measures it.

Method The idea Where it falls short
Fixed fractional Risk a set percentage of equity per position Ignores that a volatile asset and a quiet one at the same rupee size carry very different risk
Volatility targeting Scale size by target volatility divided by asset volatility Needs a volatility estimate that is not already stale when you use it
Kelly fraction Size by edge divided by variance Growth-optimal only if you know your edge exactly, which you do not
Risk parity Equalise each holding’s contribution to portfolio risk Requires a covariance matrix that is itself an estimate

Volatility targeting is the most useful default for most people, because it addresses the failure mode that catches everyone: sizing by rupees rather than by risk. Two positions of a lakh each are not the same trade if one moves twice as much as the other.

On Kelly, the practical note is that almost nobody runs full Kelly. Half or quarter Kelly is normal, and the reason is that the formula assumes your edge estimate is correct. It comes from a finite historical sample and is probably optimistic, and Kelly is punishing about overestimated edges.

Estimating the inputs, which is where most of the error lives

Every measure above depends on an estimate of volatility, and that estimate is usually the weakest part of the whole apparatus.

The simplest approach takes the standard deviation of the last twenty or sixty days of returns. It is easy, and it has a specific defect: it treats a return from sixty days ago as exactly as informative as yesterday’s, then drops it entirely on day sixty-one. When a large move rolls out of the window, your measured risk falls sharply even though nothing about the market changed. Positions sized on that number get larger for no reason.

An exponentially weighted estimate fixes the worst of this by decaying the weight on older observations smoothly, so recent behaviour counts for more and nothing falls off a cliff. GARCH models go further by explicitly modelling volatility clustering, the well-documented tendency of turbulent days to follow turbulent days.

The practical point is not which model wins. It is that volatility estimates are always backward-looking, and volatility changes faster than any estimate of it. A position sized on last month’s volatility during a regime change is sized for a market that no longer exists. This is the mechanism behind a common and painful sequence: a quiet period produces low measured volatility, low measured volatility permits larger positions, and the larger positions are in place exactly when volatility returns.

Building a margin of safety into position sizes is not conservatism. It is an acknowledgement that the input is uncertain.

Value at Risk, and what it does not say

Value at Risk answers one question: over a given horizon, at a given confidence level, what loss will not be exceeded? A one-day 95 percent VaR of two lakh means you expect to lose more than two lakh on about five days in a hundred.

Three ways to compute it, with different failure modes:

Method How Weakness
Parametric Assume normally distributed returns, scale by volatility Normal tails badly understate extreme moves
Historical Re-sample actual past returns Assumes the future resembles the sampled past
Monte Carlo Simulate from a chosen distribution Only as good as the distribution you chose

The parametric version is the one most often implemented and the one most often wrong, for the reason covered in quantitative analysis: real return distributions have far more weight in the tails than a normal curve allows. A VaR built on a normality assumption is not a conservative estimate. It is an optimistic one.

The deeper limitation is structural. VaR tells you a threshold, not what lies beyond it. Two portfolios can have identical 95 percent VaR while one loses slightly more than that on a bad day and the other loses everything. VaR cannot distinguish them, and the difference is the only thing that matters.

Expected shortfall answers the question VaR ducks

Expected shortfall, also called conditional VaR, asks: given that we have breached VaR, what is the average loss? It looks past the threshold into the tail.

A return distribution with the worst five percent of outcomes shaded. Value at Risk marks the boundary of the shaded region, while expected shortfall is the average of everything inside it. VaR the worst 5% of days expected shortfall is the average loss inside the shaded tail, not its edge
VaR is the dashed line. Expected shortfall is the average of everything to the left of it. This is why regulators moved toward expected shortfall: it is sensitive to how bad the bad case actually is, and it rewards diversification in a way VaR does not.

Expected shortfall is also mathematically better behaved. It is sub-additive, meaning the measured risk of a combined portfolio never exceeds the sum of its parts, which matches the intuition that diversification should help. VaR can violate that, occasionally suggesting that splitting a portfolio increases its risk.

Stress testing, because every model is fitted to a calm past

Both VaR and expected shortfall are estimated from history. A stress test asks a different question: what happens under conditions your sample does not contain?

  • Historical replay. Run the portfolio through a genuine crisis period and see what it does. The 2008 crisis and the March 2020 crash are the obvious candidates for Indian portfolios.
  • Hypothetical shocks. A sharp rate move, a large index fall, a currency spike. Useful because you choose the scenario rather than waiting for history to supply one.
  • Reverse stress testing. The most useful and least practised. Instead of asking what a scenario would cost, ask what combination of moves would produce a loss you could not survive, then judge how implausible that combination really is.

The recurring finding in stress tests is that correlations move. Assets that diversified each other for years converge in a crisis, precisely when the diversification was supposed to help. A portfolio that looks well spread under normal correlations can be one position under stressed ones, which is a core theme of portfolio construction.

Hazards worth checking in your own market

Circuit limits and liquidity gaps. Price bands halt trading in individual stocks after large moves. An exit you assumed was available may not be, and your realised loss can exceed the modelled one because you could not transact at all.

Concentration hiding inside an index. Indian benchmarks carry meaningful sector concentration, especially in financials. A portfolio of index funds and a few large caps can be far less diversified than the number of holdings suggests.

Derivatives margin moving against you. Margin requirements rise with volatility, so the capital demand increases exactly when the position is under stress. See credit spreads and iron condors for how that plays out on a defined-risk structure.

Which number to actually watch

A risk report with fifteen metrics gets ignored. Three, checked consistently, do not.

Current drawdown from peak. The most honest single number, because it is a realised fact rather than an estimate, and because the recovery curve at the top of this article tells you exactly how much trouble a given reading represents. If you track one thing, track this.

Portfolio volatility against your target. This is what tells you whether your sizing is still doing what you intended. Drifting well above target usually means correlations rose rather than that you added risk deliberately, which is precisely the drift worth catching early.

Largest single position as a share of total risk, not of capital. Concentration measured in rupees hides concentration in risk. A position that is 10 percent of capital but twice as volatile as everything else is contributing far more than a tenth of your exposure.

Regulated intermediaries in India operate under prescribed risk and margin frameworks, and the NSE margin documentation and SEBI circulars are worth reading even as an individual, because they show what a regulator considers adequate for the same instruments you are trading. You are not required to meet an institutional standard. It is a useful benchmark for whether your own limits are serious.

Controls that work because they are automatic

The failure mode of every risk framework is the human being who overrides it during the event it was designed for.

Useful controls share one property: they act without requiring a decision at the worst moment. A daily loss limit that halts trading. A position cap enforced at order entry. An alert that fires on a margin threshold rather than on your remembering to check. Pre-committing is the entire point, since judgement under stress is the thing you are protecting against.

The test of a control is whether it can be overridden in the moment. A stop-loss you can cancel while watching the screen is a suggestion. A daily loss limit you can raise once you have hit it is a preference. Controls that survive contact with a bad day are the ones that carry some friction: a rule written down before the position was opened, an order resting at the exchange rather than an intention in your head, or simply a size small enough that the decision never becomes urgent.

That last one deserves emphasis. Most risk problems are sizing problems wearing a disguise, and a position sized correctly rarely needs rescuing.

Where to go next

Sizing and measurement are only half the problem. Combining positions so their risks offset rather than compound is portfolio construction, and testing whether a strategy’s historical risk was real or an artefact of a clean sample is quantitative analysis. For hedging an existing equity book rather than resizing it, see hedging with NIFTY options.

The measure to internalise is the first one. Almost every account that fails does so by taking a loss it mathematically could not recover from, and that outcome is decided by sizing long before it shows up in a risk report.