Market Risk & Regulatory Capital — Insight Series

The Attribution Test

HPL, RTPL, APL and desk-level controls, explained the way a Product Controller actually has to use them — to investigate a break, not just define a term.

VP
16 MIN READ · TECHNICAL DEEP-DIVE · UPDATED AUGUST 2026
250
trading days of daily HPL/RTPL tested each quarter
0.80
Spearman correlation required for green-zone status
2028
earliest the PLA test goes live for UK banks under PRA Basel 3.1

Every quarter, a trading desk's risk model and its front-office pricing system are asked the same question in two different languages, and regulators check whether the answers agree. That check is the P&L Attribution test — one of the two statistical gatekeepers a desk must pass to keep using the Internal Models Approach instead of the punitive Standardised Approach. This guide builds the test from the ground up: the three P&L measures, why they diverge, how the statistics work, what a failure costs, and how to actually remediate one.

01 — Context

Two Cameras, One Match

The Fundamental Review of the Trading Book (FRTB) is the most significant overhaul of market-risk regulation since Value-at-Risk itself. It asks a deceptively simple question: does a bank's internal risk model actually describe the same portfolio the traders are running?

Under FRTB, model approval is granted — and can be withdrawn — at the level of the individual trading desk, not the bank as a whole. That desk-level granularity is the single biggest philosophical shift FRTB introduced. To keep using the Internal Models Approach (IMA), each desk must clear three separate hurdles.

01

Backtesting

The desk's one-day VaR must hold up: the count of loss exceptions over a 250-day window has to stay within regulatory bounds.

02

P&L Attribution (PLA) Test

The desk's risk model must produce a P&L series that tracks the desk's own front-office P&L closely enough, quarter after quarter.

03

Risk Factor Eligibility Test (RFET)

Every risk factor the model relies on must be classified as modellable or non-modellable, based on real observed pricing history.

Backtesting and PLA are complementary, not redundant. Backtesting asks does the model produce enough loss coverage? PLA asks a subtler question: is the risk model even describing the same portfolio the traders are actually running?

Imagine two cameras pointed at the same match. One is the front-office pricing system — high resolution, every player, every blade of grass. The other is the risk model: cheaper, fewer pixels, a simplified set of risk factors. Every day, both cameras produce a recording. The PLA test compares them to see if they tell the same story.
02 — The Three P&L Measures

APL, HPL and RTPL — Three Recordings of the Same Book

Before the test itself makes sense, the three P&L measures FRTB defines need to be clearly separated. All three start from the same end-of-day (T−2) portfolio; what differs is which prices, which models, and whether trading activity is included.

01

Actual P&L (APL)

The desk's real economic P&L: actual end-of-day prices, all trading activity that occurred during the day, fees and commissions stripped out. APL is not used in the PLA test — its home is backtesting, where it's compared against the model's VaR to count exceptions.

02

Hypothetical P&L (HPL)

What the desk's P&L would have been with no trading — the T−2 portfolio revalued at T−1 actual market prices, using the front office's full valuation models and every risk factor it prices. This is the "front-office camera."

03

Risk-Theoretical P&L (RTPL)

The same T−2 portfolio, no trading, but revalued using the risk model's own generated prices — only the risk factors the model includes, and its simplified valuation methods. This is the "risk camera." The PLA test compares RTPL against HPL.

FeatureAPLHPLRTPL
PortfolioT−2 + tradingT−2 onlyT−2 only
PricesActual marketActual marketModel-generated
ValuationFront-office modelsFront-office modelsRisk models
Trading activityIncludedExcludedExcluded
Used forBacktestingBacktesting & PLAPLA
A point of precision

APL's exclusions run slightly wider than just fees and commissions in practice — certain reserves and valuation adjustments that are only updated on a non-daily cycle are typically also carved out, since they'd introduce noise unrelated to the day's market moves.

03 — Divergence

Why HPL and RTPL Pull Apart

The PLA test's central question is whether daily RTPL and daily HPL are sufficiently close. Four structural gaps drive most of the divergence.

  • Risk factor coverage. HPL includes every risk factor the front office prices; RTPL includes only the factors the risk model has classified as modellable. Anything HPL prices that RTPL excludes creates a persistent, structural difference.
  • Valuation model design. Front-office models chase accuracy on every trade; risk models chase speed and focus on the dominant risk drivers, trading full revaluation for sensitivity-based approximation.
  • Market data alignment. Different providers, different granularity, different cut-off times between the two systems.
  • Timing and cut-offs. End-of-day close times, holiday calendars, and calculation windows rarely line up perfectly between front office and risk.

Where this shows up in practice

Volatility Surface — Equity Derivatives

HPL prices off an implied volatility surface with five tenors and three moneyness levels. RTPL uses a single flat implied volatility. The missing smile is exactly what the PLA test is built to catch.

Curve Granularity — Interest Rate Swaps

HPL revalues daily off the OIS curve and daily 3m LIBOR with full swap valuation. RTPL updates OIS monthly, 3m LIBOR weekly, and approximates with sensitivities rather than full revaluation.

Cut-off Mismatch — A US Bank Holiday

Front office marks off stale data on a US holiday; risk substitutes a proxy or its own stale data. The mismatch shows up as a one-day spike in unexplained P&L, not a structural problem.

04 — Diagnostics

Unexplained P&L: The Diagnostic Bridge

Unexplained P&L  =  RTPL − HPL

This single series is the bridge between the front-office camera and the risk camera. Breaking it down by risk factor reveals exactly which inputs are driving the two P&Ls apart — the starting point of every PLA investigation.

  • Mean Ratio (M₁) — Mean(Unexplained) ÷ Mean(HPL)
  • Variance Ratio (M₂) — Variance(Unexplained) ÷ Variance(HPL)
A point of precision

M₁ and M₂ were the original 2016 PLA metrics. The Basel Committee replaced them in the 2019 final standards with Spearman correlation and the KS test, precisely because mean/variance ratios proved too easy to satisfy without the underlying models actually agreeing. Many desks still track M₁/M₂ internally as a cheap daily early-warning signal — but they are no longer the binding regulatory test. Spearman and KS are.

05 — The Statistics

Spearman Correlation and the Kolmogorov–Smirnov Test

Since the 2019 revision, the official PLA test is calculated quarterly, using the preceding 12 months (250 trading days) of daily HPL and RTPL data — not the monthly windows the original 2016 design used. Many desks monitor the underlying series daily as an internal early-warning practice, but the number a bank actually reports to its regulator is the quarterly, trailing-12-month result.

Spearman Rank Correlation

Do HPL and RTPL move in the same direction, in the same order? A value above 0.80 is green; 0.70–0.80 is amber; below 0.70 is red.

Plain English

When HPL is high, is RTPL also high? When HPL is low, is RTPL also low? Perfect lockstep scores 1.0.

Kolmogorov–Smirnov (KS) Test

Are the two P&L series drawn from similar distributions? The KS statistic is the largest gap between their empirical cumulative distributions. Below 0.09 is green; 0.09–0.12 is amber; above 0.12 is red.

Plain English

Plot both sets of values on the same number line and compare their spread. The KS statistic is the widest gap between them — smaller is more similar.

The two tests are complementary by design: Spearman captures directional alignment, KS captures distributional shape. A desk can pass one and fail the other, and each failure points investigators toward a different kind of problem.

06 — Outcomes

The Traffic Light System

ZoneSpearmanKSIMA Status
Green> 0.80< 0.09IMA eligible
Amber0.70–0.800.09–0.12IMA with capital surcharge
Red< 0.70> 0.12Must use Standardised Approach

A desk's overall zone is set by the worse of the two test results — a desk that is green on Spearman but amber on KS is treated as amber overall, not averaged between the two. Amber desks stay on IMA but absorb a capital add-on scaled to how far their statistics sit from the green threshold. Red desks lose IMA entirely and must capitalise the desk under the Standardised Approach, which is materially more conservative.

To avoid a hard cliff-edge from a single bad quarter, the Committee built in a modified traffic-light mechanism that smooths the transition between zones rather than switching a desk straight from IMA to SA.

Well-hedged portfolios often find PLA harder to pass, not easier. When total P&L is small because the book is delta-neutral, even tiny absolute differences between HPL and RTPL become large relative to the total — the hedge doesn't help the test, it magnifies the noise.

Consequences of a Red Result

  • Capital: mandatory move to the Standardised Approach, materially higher capital for that desk. Industry studies have suggested that a majority of desks fail on first attempt under a strict reading of the thresholds.
  • Operational: loss of IMA eligibility, heightened regulatory scrutiny, and remediation cost.
  • Return to IMA: a desk must demonstrate green-zone PLA results and satisfy backtesting requirements over a full trailing 12-month period before regaining eligibility — there is no shortcut back.
07 — Response

Remediation: From Red to Green

Isolating the actual cause of a PLA failure is rarely straightforward — most banks lack mature infrastructure for risk-factor-level mapping between front office and risk, which is precisely where the answer usually lives.

01

Detection

Monitor PLA results continuously; flag any desk moving to amber or red.

02

Initial investigation

Calculate unexplained P&L, break it down by risk factor, and review the front-office-to-risk mapping.

03

Root cause analysis

The usual suspects: missing risk factors, data misalignment, model differences, timing gaps, mapping errors.

04

Fix implementation

Add the missing risk factors, align the data sources, harmonise the models, correct the mapping.

05

Validation

Rerun the test and confirm the desk has moved back into the green zone.

06

Ongoing monitoring

Keep watching and documenting — a fixed desk can drift again as products and models evolve.

Roles and Responsibilities

FunctionWhat they own
Product ControlFinancial accounting, P&L verification, unexplained P&L analysis, PLA reporting, remediation support.
Market RiskModel performance monitoring, PLA test execution, risk factor management, capital calculation.
QuantsModel development, PLA methodology, risk factor modelling, validation support.

Close collaboration across all three is the actual precondition for a successful remediation — PLA failures that get treated as a Product Control problem in isolation tend to stay unresolved.

08 — Field Notes

Four Investigations, Four Different Causes

Missing Risk Factor

Situation: an equity derivatives desk fails PLA at Spearman 0.65, KS 0.14. Finding: front office prices off a five-tenor, three-moneyness volatility surface; risk uses a single flat implied vol — the smile is simply missing from the model.

Fix: add the missing volatility risk factors. Result: Spearman recovers to 0.82, KS to 0.08 — green.

Market Data Misalignment

Situation: an interest rate desk fails on variance ratio at 25%, with unexplained P&L spiking on specific days. Finding: front office marks off the 4pm New York close; risk uses the 5pm London close, and large intraday moves fall in the gap.

Fix: align cut-off times to a single source of truth. Variance ratio improves to 18%.

The Hedged-Portfolio Problem

Situation: a well-hedged, delta-neutral FX options desk fails on mean ratio at 12% against a 10% threshold. Finding: total P&L is small by design, so even tiny absolute differences read as large relative ones.

Fix: this is a structural issue, not a data bug — improving model accuracy helps at the margin, but the desk's hedging profile itself needs to be documented for regulators as context.

Mapping Error

Situation: a credit derivatives desk fails with no obvious pattern in the unexplained P&L. Finding: front office prices off five credit spread tenors; the risk model maps all five onto a single flat spread.

Fix: rebuild the mapping to preserve the term structure. The desk passes on the next quarterly run.

09 — Regulatory Status, 2026

This Framework Is Mature. It Isn't Live Everywhere Yet.

Everything above describes a fully specified, final BCBS standard — but as of mid-2026, the PLA test is not yet a binding requirement in most major jurisdictions. FRTB's market-risk provisions have been repeatedly deferred, largely to preserve a level playing field while the US finalises its own approach.

United Kingdom
2027 / 2028
The PRA's January 2026 policy statement (PS1/26) confirmed a general Basel 3.1 start date of 1 January 2027, with the market-risk internal models approach — and therefore the PLA test — further deferred a year, to 1 January 2028.
European Union
2027
FRTB's application date has been postponed twice, now to 1 January 2027. The Commission has since introduced temporary, targeted amendments running for three years from that date, including provisions to run PLA as a monitoring tool rather than a full binding requirement for some banks.
United States
In Progress
The "Basel III Endgame" proposal was reissued in March 2026 with its consultation period closing in June 2026. US market-risk rules, and therefore the American PLA timeline, remain unsettled.

For a Product Controller, the practical implication isn't that PLA doesn't matter — it's the opposite. Every deferral has been driven by banks demonstrating, in practice, how hard the test is to pass cleanly. The institutions that use this extra runway to actually build the risk-factor mapping, data alignment, and investigation muscle described above will be the ones that clear the bar comfortably once the test goes live.

Final Word

The Test That Catches the Gap

“A desk can pass backtesting with a crude model that happens to be conservative, yet fail PLA because that same crude model is missing risk factors the front office prices every day. PLA is the test that catches the gap between the risk view of the book and the pricing view of the book.”

Spearman and KS are complementary and both must be passed; the traffic-light system determines IMA eligibility and capital treatment; and remediation is fundamentally a mapping and data-alignment discipline, not a modelling exercise alone. Regulators are already discussing further simplification — including dropping the Spearman test and extending the monitoring period — so this is a framework worth watching, not memorising once and filing away.

This guide is for educational purposes only and does not constitute regulatory or legal advice. Banks should consult their own legal and compliance teams for guidance specific to their FRTB implementation.

EDUCATION SERIES · PRODUCT CONTROL · 2026