Risk: From Market Risk to Expected Credit Loss, Part 2. Previously: Value at Risk Explained.
Expected shortfall answers the question VaR refuses to. Where VaR tells you the threshold you should breach once in a hundred days, expected shortfall tells you how bad things get when you breach it. That difference sounds academic until you look at what happened in 2008.

What went wrong
The failure was not that VaR limits were breached. Breaches are expected — that is what a 99% threshold means. The failure was that the breaches, when they came, were enormous and arrived in clusters.
Three mechanisms compounded.
The lookback window was calm. Models calibrated on 2004 to 2006 data saw low volatility and benign correlations. Measured risk was therefore small, position limits were generous, and leverage built up on the strength of a number that was accurate about a world that had stopped existing.
Correlations converged. Diversification assumptions held in normal conditions and dissolved in the crisis. Assets that had moved independently for years began falling together, because the common factor was no longer economic fundamentals but forced selling.
Nobody had a number for the tail. Risk committees knew the 99% threshold. They did not have a figure for the average loss beyond it, because the measure in use does not produce one.
How expected shortfall works
Expected shortfall — also called conditional VaR or tail VaR — is the average of all losses worse than the VaR threshold.
Mechanically, with 1,000 simulated daily outcomes:
- Sort every outcome from worst loss to best gain.
- Identify the threshold: at 99%, the tenth-worst outcome is the VaR.
- Take the ten worst outcomes — everything at or beyond that threshold.
- Average them.
- That average is the expected shortfall.
A concrete case. Two portfolios, both with a 99% VaR of 2.8 billion VND, differing entirely in their worst ten days:
| Portfolio A | Portfolio B | |
|---|---|---|
| 99% VaR | 2.8bn | 2.8bn |
| Worst ten days, range | 2.8bn to 3.4bn | 2.8bn to 41bn |
| Expected shortfall | 3.0bn | 12.6bn |
VaR calls these portfolios identical. Expected shortfall puts a factor of four between them. Portfolio B is the one that sells deep out-of-the-money options — the gaming strategy described in the previous post, now visible in the number.
The mathematical fix
Beyond tail sensitivity, expected shortfall repairs the defect that made VaR theoretically awkward: it is sub-additive. Combining two portfolios can never produce an expected shortfall greater than the sum of the parts.
That matters practically, not just formally. Under VaR, a risk manager could find that splitting a book across two desks reduced measured risk, creating an incentive to fragment reporting rather than manage exposure. Expected shortfall belongs to the family of coherent risk measures, where diversification is always rewarded and never penalised.
What Basel did
The Fundamental Review of the Trading Book, the post-crisis overhaul of market risk capital, made three changes that follow directly from the above.
- Expected shortfall replaces VaR for capital, at 97.5% rather than 99%. The lower confidence level is deliberate: averaged over the tail, 97.5% ES is comparable in severity to 99% VaR for normal distributions, while remaining far more responsive to fat tails.
- Calibration to a stressed period. Rather than a rolling recent window, capital is calibrated against a historical period of significant stress — directly addressing the calm-window problem.
- Varying liquidity horizons. Different risk factors get different assumed holding periods, acknowledging that an illiquid position cannot be exited in ten days just because a liquid one can.
What expected shortfall does not fix
It remains a backward-looking statistic computed from a chosen distribution. If your window excludes a type of event, no amount of tail averaging will conjure it.
It is also harder to backtest. VaR backtesting is a clean counting exercise — did breaches occur at roughly the expected frequency? Expected shortfall concerns the average size of events that, by construction, are rare, so you have very few observations to test against. Basel’s framework works around this by backtesting VaR while capitalising on ES, which is a pragmatic compromise rather than an elegant one.
Most importantly, neither measure tells you what you have not imagined. That gap is what stress testing exists to fill, and it is the subject of the next post.
Frequently asked questions
What is the difference between VaR and expected shortfall?
VaR is the threshold loss at a confidence level. Expected shortfall is the average loss given that the threshold is breached, so it describes the tail rather than just locating it.
Why does Basel use 97.5% for ES but 99% for VaR?
Because averaging across the tail already adds severity. For a normal distribution the two calibrations give similar figures, while ES stays far more responsive when tails are fat.
What does sub-additive mean, and why does it matter?
It means combining portfolios never increases measured risk. Consequently diversification is always rewarded, removing the incentive to fragment reporting that VaR created.
Is expected shortfall harder to backtest?
Yes. Testing an average of rare events gives very few observations, which is why supervisors still backtest VaR while setting capital on ES.
Try it yourself
Extend the VaR spreadsheet from the previous post, in this order:
- Take your sorted portfolio return series.
- Identify the 1% threshold — your existing VaR figure.
- Average every return at or beyond that threshold to get expected shortfall.
- Note the ratio of ES to VaR for your portfolio.
- Add a short position in deep out-of-the-money puts and recompute both.
VaR will barely move. ES will jump. Watching that divergence appear in your own numbers explains the regulatory shift more convincingly than any argument.
Next in this series: stress testing, and how to design scenarios that actually matter.