HPL, RTPL, APL and desk-level controls, explained the way a Product Controller actually has to use them — to investigate a break, not just define a term.
Every quarter, a trading desk's risk model and its front-office pricing system are asked the same question in two different languages, and regulators check whether the answers agree. That check is the P&L Attribution test — one of the two statistical gatekeepers a desk must pass to keep using the Internal Models Approach instead of the punitive Standardised Approach. This guide builds the test from the ground up: the three P&L measures, why they diverge, how the statistics work, what a failure costs, and how to actually remediate one.
The Fundamental Review of the Trading Book (FRTB) is the most significant overhaul of market-risk regulation since Value-at-Risk itself. It asks a deceptively simple question: does a bank's internal risk model actually describe the same portfolio the traders are running?
Under FRTB, model approval is granted — and can be withdrawn — at the level of the individual trading desk, not the bank as a whole. That desk-level granularity is the single biggest philosophical shift FRTB introduced. To keep using the Internal Models Approach (IMA), each desk must clear three separate hurdles.
The desk's one-day VaR must hold up: the count of loss exceptions over a 250-day window has to stay within regulatory bounds.
The desk's risk model must produce a P&L series that tracks the desk's own front-office P&L closely enough, quarter after quarter.
Every risk factor the model relies on must be classified as modellable or non-modellable, based on real observed pricing history.
Backtesting and PLA are complementary, not redundant. Backtesting asks does the model produce enough loss coverage? PLA asks a subtler question: is the risk model even describing the same portfolio the traders are actually running?
Before the test itself makes sense, the three P&L measures FRTB defines need to be clearly separated. All three start from the same end-of-day (T−2) portfolio; what differs is which prices, which models, and whether trading activity is included.
The desk's real economic P&L: actual end-of-day prices, all trading activity that occurred during the day, fees and commissions stripped out. APL is not used in the PLA test — its home is backtesting, where it's compared against the model's VaR to count exceptions.
What the desk's P&L would have been with no trading — the T−2 portfolio revalued at T−1 actual market prices, using the front office's full valuation models and every risk factor it prices. This is the "front-office camera."
The same T−2 portfolio, no trading, but revalued using the risk model's own generated prices — only the risk factors the model includes, and its simplified valuation methods. This is the "risk camera." The PLA test compares RTPL against HPL.
| Feature | APL | HPL | RTPL |
|---|---|---|---|
| Portfolio | T−2 + trading | T−2 only | T−2 only |
| Prices | Actual market | Actual market | Model-generated |
| Valuation | Front-office models | Front-office models | Risk models |
| Trading activity | Included | Excluded | Excluded |
| Used for | Backtesting | Backtesting & PLA | PLA |
APL's exclusions run slightly wider than just fees and commissions in practice — certain reserves and valuation adjustments that are only updated on a non-daily cycle are typically also carved out, since they'd introduce noise unrelated to the day's market moves.
The PLA test's central question is whether daily RTPL and daily HPL are sufficiently close. Four structural gaps drive most of the divergence.
HPL prices off an implied volatility surface with five tenors and three moneyness levels. RTPL uses a single flat implied volatility. The missing smile is exactly what the PLA test is built to catch.
HPL revalues daily off the OIS curve and daily 3m LIBOR with full swap valuation. RTPL updates OIS monthly, 3m LIBOR weekly, and approximates with sensitivities rather than full revaluation.
Front office marks off stale data on a US holiday; risk substitutes a proxy or its own stale data. The mismatch shows up as a one-day spike in unexplained P&L, not a structural problem.
This single series is the bridge between the front-office camera and the risk camera. Breaking it down by risk factor reveals exactly which inputs are driving the two P&Ls apart — the starting point of every PLA investigation.
M₁ and M₂ were the original 2016 PLA metrics. The Basel Committee replaced them in the 2019 final standards with Spearman correlation and the KS test, precisely because mean/variance ratios proved too easy to satisfy without the underlying models actually agreeing. Many desks still track M₁/M₂ internally as a cheap daily early-warning signal — but they are no longer the binding regulatory test. Spearman and KS are.
Since the 2019 revision, the official PLA test is calculated quarterly, using the preceding 12 months (250 trading days) of daily HPL and RTPL data — not the monthly windows the original 2016 design used. Many desks monitor the underlying series daily as an internal early-warning practice, but the number a bank actually reports to its regulator is the quarterly, trailing-12-month result.
Do HPL and RTPL move in the same direction, in the same order? A value above 0.80 is green; 0.70–0.80 is amber; below 0.70 is red.
When HPL is high, is RTPL also high? When HPL is low, is RTPL also low? Perfect lockstep scores 1.0.
Are the two P&L series drawn from similar distributions? The KS statistic is the largest gap between their empirical cumulative distributions. Below 0.09 is green; 0.09–0.12 is amber; above 0.12 is red.
Plot both sets of values on the same number line and compare their spread. The KS statistic is the widest gap between them — smaller is more similar.
The two tests are complementary by design: Spearman captures directional alignment, KS captures distributional shape. A desk can pass one and fail the other, and each failure points investigators toward a different kind of problem.
| Zone | Spearman | KS | IMA Status |
|---|---|---|---|
| Green | > 0.80 | < 0.09 | IMA eligible |
| Amber | 0.70–0.80 | 0.09–0.12 | IMA with capital surcharge |
| Red | < 0.70 | > 0.12 | Must use Standardised Approach |
A desk's overall zone is set by the worse of the two test results — a desk that is green on Spearman but amber on KS is treated as amber overall, not averaged between the two. Amber desks stay on IMA but absorb a capital add-on scaled to how far their statistics sit from the green threshold. Red desks lose IMA entirely and must capitalise the desk under the Standardised Approach, which is materially more conservative.
To avoid a hard cliff-edge from a single bad quarter, the Committee built in a modified traffic-light mechanism that smooths the transition between zones rather than switching a desk straight from IMA to SA.
Isolating the actual cause of a PLA failure is rarely straightforward — most banks lack mature infrastructure for risk-factor-level mapping between front office and risk, which is precisely where the answer usually lives.
Monitor PLA results continuously; flag any desk moving to amber or red.
Calculate unexplained P&L, break it down by risk factor, and review the front-office-to-risk mapping.
The usual suspects: missing risk factors, data misalignment, model differences, timing gaps, mapping errors.
Add the missing risk factors, align the data sources, harmonise the models, correct the mapping.
Rerun the test and confirm the desk has moved back into the green zone.
Keep watching and documenting — a fixed desk can drift again as products and models evolve.
| Function | What they own |
|---|---|
| Product Control | Financial accounting, P&L verification, unexplained P&L analysis, PLA reporting, remediation support. |
| Market Risk | Model performance monitoring, PLA test execution, risk factor management, capital calculation. |
| Quants | Model development, PLA methodology, risk factor modelling, validation support. |
Close collaboration across all three is the actual precondition for a successful remediation — PLA failures that get treated as a Product Control problem in isolation tend to stay unresolved.
Situation: an equity derivatives desk fails PLA at Spearman 0.65, KS 0.14. Finding: front office prices off a five-tenor, three-moneyness volatility surface; risk uses a single flat implied vol — the smile is simply missing from the model.
Fix: add the missing volatility risk factors. Result: Spearman recovers to 0.82, KS to 0.08 — green.
Situation: an interest rate desk fails on variance ratio at 25%, with unexplained P&L spiking on specific days. Finding: front office marks off the 4pm New York close; risk uses the 5pm London close, and large intraday moves fall in the gap.
Fix: align cut-off times to a single source of truth. Variance ratio improves to 18%.
Situation: a well-hedged, delta-neutral FX options desk fails on mean ratio at 12% against a 10% threshold. Finding: total P&L is small by design, so even tiny absolute differences read as large relative ones.
Fix: this is a structural issue, not a data bug — improving model accuracy helps at the margin, but the desk's hedging profile itself needs to be documented for regulators as context.
Situation: a credit derivatives desk fails with no obvious pattern in the unexplained P&L. Finding: front office prices off five credit spread tenors; the risk model maps all five onto a single flat spread.
Fix: rebuild the mapping to preserve the term structure. The desk passes on the next quarterly run.
Everything above describes a fully specified, final BCBS standard — but as of mid-2026, the PLA test is not yet a binding requirement in most major jurisdictions. FRTB's market-risk provisions have been repeatedly deferred, largely to preserve a level playing field while the US finalises its own approach.
For a Product Controller, the practical implication isn't that PLA doesn't matter — it's the opposite. Every deferral has been driven by banks demonstrating, in practice, how hard the test is to pass cleanly. The institutions that use this extra runway to actually build the risk-factor mapping, data alignment, and investigation muscle described above will be the ones that clear the bar comfortably once the test goes live.
Spearman and KS are complementary and both must be passed; the traffic-light system determines IMA eligibility and capital treatment; and remediation is fundamentally a mapping and data-alignment discipline, not a modelling exercise alone. Regulators are already discussing further simplification — including dropping the Spearman test and extending the monitoring period — so this is a framework worth watching, not memorising once and filing away.