ETRM interview questions
5,470 questions. The ones that actually get asked.
Front Office, Middle Office and Back Office, organised by theme: trade capture and product modelling, curves and valuation, position and P&L, risk and limits, settlement, accounting, integration architecture and the scenario questions that separate an architect from an implementer.
5,470 questions · 15 groups · 275 sections
Answer the why, not the what
Most of these questions have an obvious surface answer and a real one underneath. An interviewer asking how you model a physical and a financial trade is not testing whether you know the difference; they are testing whether you understand why one position model has to serve both. Prepare the reasoning, not the definition.
Every question below is free to read. If you want the underlying material rather than a list, the ETRM Pro Bundle is where it is taught.
5,470 questions across 15 groups
Front Office13 sections · 180 questions
1. Front Office and Trading Process10
- Explain the complete Front Office trade lifecycle from deal negotiation through trade capture, validation, position update and downstream processing.A trade begins with negotiation and execution, followed by capture in ETRM. ETRM validates economic terms, counterparty eligibility, limits and reference data. Once validated, it updates positions, exposure and P&L, then generates events for confirmation, scheduling, settlement, accounting and regulatory reporting.
- How does ETRM distinguish between a trade, transaction, instrument, leg, profile and cash flow?A trade is the overall commercial agreement, while a transaction is its system representation. The instrument defines product behaviour and valuation. Legs represent distinct payment or delivery components. Profiles distribute quantities or prices across periods, and cash flows represent the resulting financial payment obligations.
- How would you model physical and financial commodity trades within the same trading portfolio?I would use appropriate physical and financial instruments while aligning commodity, index, currency, unit, delivery period, location, portfolio and strategy dimensions. This enables consolidated exposure and P&L while preserving physical scheduling, nomination and settlement requirements that do not apply to financial derivatives.
- What information must be captured at trade entry to support accurate valuation, position and P&L?Required data includes instrument, buy or sell direction, quantity, unit, price formula, index, currency, delivery profile, pricing dates, payment terms, location, counterparty, portfolio and trader. Missing conversion factors, calendars, curves, fixings or settlement conventions can materially distort valuation, exposure and P&L.
- How do trade date, delivery date, pricing date, fixing date, settlement date and payment date differ?Trade date records execution. Delivery dates define when the commodity is supplied. Pricing dates specify the quotation period, while fixing dates determine when floating prices become known. Settlement date establishes the payable amount, and payment date identifies when cash is contractually transferred between counterparties.
- What are the respective responsibilities of traders, originators, schedulers, risk controllers and product control?Traders execute and manage market exposure. Originators develop structured commercial opportunities. Schedulers manage physical movements, nominations and actuals. Risk monitors limits and independent exposure measures. Product Control validates prices, explains P&L and supports valuation control. Clear segregation prevents traders from independently approving their results.
- How would you design Front Office workflows for high-volume versus structured transactions?High-volume trades require standard templates, automated ingestion, straight-through validation and exception-based processing. Structured trades need richer capture, specialist review, model approval and enhanced controls. Both should share governed reference data, auditability and downstream interfaces without forcing complex transactions through unsuitable standard workflows.
- What are the differences between exchange-traded, OTC-cleared and bilateral OTC transactions?Exchange-traded products use standard contracts and centralised execution and clearing. OTC-cleared trades are negotiated bilaterally but submitted to a clearing house. Bilateral OTC trades remain directly between counterparties, creating customised terms and greater counterparty, collateral, confirmation, valuation and settlement-management requirements.
- How do physical delivery obligations affect the Front Office trade model?Physical trades require delivery locations, quantity profiles, units, quality specifications, tolerances, transportation terms and operational dates. The model must connect commercial economics with nominations, scheduling and actual quantities. Operational changes may alter exposure, valuation, inventory, settlement and imbalance charges throughout the trade lifecycle.
- What controls should prevent incomplete or economically incorrect trades from reaching downstream systems?Controls should validate mandatory fields, product eligibility, trader mandates, counterparty status, credit availability, price reasonableness, units, currencies, calendars, delivery profiles and settlement instructions. Material exceptions should block validation; lower-risk exceptions may generate warnings, approvals or workflow tasks supported by a complete audit trail.
2. ETRM Trade Capture Architecture15
- Explain ETRM's instrument-builder architecture.ETRM's instrument architecture defines how a transaction captures economic terms, generates payment or delivery events, obtains market data and performs valuation. Standard instruments combine configurable parameters, profiles, formulas and event logic, allowing multiple products to be supported without creating separate custom code for every trade type.
- When should an existing instrument be configured instead of creating a custom instrument?Use an existing instrument when it can represent the contractual economics, cash flows, physical obligations and valuation correctly through supported configuration. Custom development is justified only when material requirements cannot be modelled reliably, because custom instruments increase testing, operational support, performance and upgrade risks.
- How do transaction and parameter structures influence valuation and reporting?The transaction stores contractual and organisational attributes, while parameters represent individual economic components such as fixed, floating or physical legs. Their profiles, indexes, dates and formulas drive cash-flow generation and valuation. Reporting depends on correctly aggregating these structures into positions, sensitivities, P&L and settlement events.
- Explain the purpose of deal templates and trade defaults.Deal templates prepopulate approved economic and operational attributes for recurring products. Defaults reduce manual entry, accelerate booking and promote consistent data. Templates should remain controlled by product, desk and legal entity, while users must verify transaction-specific terms rather than treating defaults as confirmed contractual information.
- How would you design trade templates for different desks, commodities and legal entities?I would establish reusable base templates by instrument and commodity, then apply controlled desk, portfolio, legal-entity, location and settlement defaults. The design should minimise duplication, restrict inappropriate products and maintain clear ownership, versioning, testing and approval for every template change introduced into production.
- How are portfolios, books, strategies and organisational units represented in ETRM?ETRM portfolios commonly represent controlled collections of transactions assigned to trading or operational responsibilities. Business units define organisational ownership, while strategies provide analytical classification. The exact hierarchy must support trader mandates, access control, risk aggregation, accounting treatment, reporting and organisational changes without duplicating transactions.
- How would you implement trader mandates and book-level product restrictions?I would combine user roles, personnel assignments, portfolio permissions, instrument eligibility, transaction limits and workflow validation. Controls should restrict who can view, enter, amend or validate trades and which products each book may hold. Exceptions require authorised approval and must remain visible in the audit trail.
- What is the difference between trade entry validation and workflow validation?Trade-entry validation checks field completeness, formats, reference data and basic economic consistency while the user captures a transaction. Workflow validation applies broader business controls before status progression, including credit, mandate, price reasonableness and approvals. Separating them supports usability without weakening governance.
- How would you introduce a new product without disrupting existing transactions?I would perform product analysis, reuse proven instruments, isolate configuration changes and test valuation, events, position, P&L, accounting and settlement. Regression testing would protect existing products. Deployment would use controlled migration, production-readiness approval, monitoring and a rollback plan covering configuration and custom components.
- What ETRM configuration objects would you assess before enabling a product for production?The assessment should cover instruments, transaction templates, portfolios, reference data, indexes, curves, calendars, units, currencies, settlement instructions, accounting rules, workflows, permissions, simulations, reports and interfaces. Every dependency must have an owner, test evidence, migration method, reconciliation control and production-support procedure.
- How would you manage amendments, cancellations, novations, terminations and partial unwinds?I would use supported lifecycle actions that preserve the original transaction's history and establish explicit relationships between affected deals. Each action must correctly reverse or transfer remaining economics, regenerate events, recalculate exposure and P&L, trigger confirmation and settlement changes, and retain authorised audit evidence.
- How do you preserve the economic and operational history of an amended trade?Trade changes should use controlled amendment workflows, transaction versions and audit logs rather than direct database updates. The system must retain previous economics, timestamps, user identity, approval and reason. Historical valuation should reproduce results using the trade version and market data valid at that time.
- How would you identify duplicate trades received from an external execution platform?I would enforce idempotency using a stable source-system identifier, execution identifier and version number. Additional matching could compare counterparty, product, direction, quantity, price and timestamp. Suspected duplicates should enter an exception queue instead of being silently rejected or creating additional ETRM transactions.
- What design decisions are required for block trades and trade allocations?The design must define whether the block or allocated child trades are authoritative, when allocation occurs, and how quantities, prices, fees and identifiers propagate. It must also address partial allocation, rounding, amendments, cancellations, confirmations, credit usage, position reporting, settlement and reconciliation with the execution venue.
- How would you model inter-book and intercompany transactions?Inter-book transfers should create balanced internal transactions that move exposure and P&L without creating external obligations. Intercompany trades require separate legal entities, agreements, transfer pricing, confirmations, accounting and settlement. Both designs need linked identifiers, symmetrical lifecycle processing and controls preventing unbalanced amendments or cancellations.
3. Commodity Product Modelling15
- How would you model a fixed-price physical crude-oil purchase?I would capture the crude grade, quantity, unit, fixed price, currency, delivery period, location, Incoterm, quality terms, tolerance and payment conditions. The transaction must generate physical delivery, scheduling and settlement events while exposing price, volume, location, currency and counterparty risks correctly.
- How would you represent a crude trade priced against monthly Brent plus a differential?I would model a floating-price physical trade referencing the appropriate Brent index, quotation period and averaging convention, then add the contractual differential. The configuration must include pricing-event dates, publication calendar, currency, unit conversions, provisional pricing and rules for unavailable or subsequently corrected index observations.
- How would you model provisional pricing followed by final invoice pricing?The transaction would initially calculate an invoice using an estimated or provisional index value. After all contractual fixings become available, ETRM would calculate the final price and generate an adjustment invoice. The design must preserve both calculations and prevent provisional amounts from being mistaken for final revenue.
- How would you represent pricing based on an average of multiple published index observations?I would configure a quotation-period price using the contractually specified observations, publication calendar and arithmetic or weighted-average method. The model must address excluded days, missing publications, pricing lags, corrections and rounding. Each fixing should remain traceable from the final price to its original market-data source.
- How would you model a pricing formula containing quotation periods, lags, premiums and FX conversion?I would decompose the formula into independently testable components: commodity index, quotation-period rules, publication lag, premium or discount, unit conversion and FX conversion. ETRM should evaluate these in contractual order, use governed market-data sources and retain enough detail to explain the resulting invoice price.
- How would you handle different units of measure between trading, delivery, risk and settlement?I would maintain a canonical quantity with governed conversions among commercial, physical, risk and invoicing units. Conversions may depend on density, calorific value, temperature or contractual factors. The original quantity and every conversion basis must remain visible, reproducible and consistently applied across valuation, scheduling and settlement.
- How do density, temperature and volume-conversion rules affect oil transactions?Oil volumes vary with temperature, while mass-to-volume conversion depends on density. ETRM must therefore apply contractual reference temperatures, density sources and conversion standards. Incorrect assumptions can create differences between traded quantity, delivered quantity, exposure and invoice quantity, producing unexplained position and settlement discrepancies.
- How would you model a natural-gas trade with daily delivery profiles?I would capture the delivery point, contract period, daily quantities, gas day, timezone, unit, price formula and nomination rules. The profile should support planned, nominated and actual volumes while valuation and position reporting aggregate daily exposure correctly across weekends, holidays and daylight-saving transitions.
- How would you represent take-or-pay, swing or tolerance provisions?I would separate base delivery obligations from contractual flexibility. Minimum, maximum, cumulative and daily constraints would govern permitted nominations, while shortfall, excess and make-up provisions generate appropriate valuation or settlement consequences. Material optionality requires a suitable valuation model rather than only operational validation rules.
- How would you model an LNG cargo containing multiple pricing components and delivery conditions?I would represent cargo quantity, loading and discharge windows, locations, boil-off assumptions, index-linked commodity pricing, slope, constant, FX, freight and operational costs. Components should remain separately explainable while supporting provisional pricing, quantity adjustments, diversions, delays and final settlement using actual delivered energy.
- How would you represent power trades with hourly, peak and off-peak delivery profiles?I would model delivery using timezone-aware hourly profiles and the market's official peak definitions, holiday calendar and settlement periods. Quantities and prices must map to each interval, enabling correct valuation and position aggregation while preserving distinctions among baseload, peak-load, off-peak and shaped products.
- How would you handle daylight-saving-time days containing 23 or 25 delivery hours?I would use the market's local timezone, official delivery calendar and uniquely identified settlement intervals. On clock-change days, the missing or repeated hour must be represented explicitly. Using simple hour numbers without timezone offsets can misstate volume, exposure, pricing, scheduling and settlement.
- How would you model renewable certificates or emissions allowances?I would capture certificate type, registry, jurisdiction, vintage, compliance period, quantity, delivery terms and price. The model must distinguish trading from surrender, retirement or cancellation and maintain registry identifiers where required. Position reporting should separate available, committed, delivered and retired environmental instruments.
- How would you represent freight as part of commodity economics?Freight can be captured as a separate charter transaction, a transportation component or a cost allocation linked to the commodity trade. The approach must support route, vessel, quantity, rate, demurrage, currency and timing while allowing landed-cost, exposure, P&L and settlement analysis.
- When should freight be embedded in the commodity trade, and when should it be captured separately?Embed freight when it is an inseparable pricing component and does not require independent lifecycle management. Capture it separately when the organisation contracts transportation independently, manages freight exposure, schedules vessels or settles freight-specific charges. Linked transactions can preserve combined cargo economics without obscuring operational ownership.
4. Market Data and Curves15
- Describe ETRM's market-data architecture from data acquisition through curve construction and valuation.ETRM receives prices, fixings, rates and reference data from approved sources. Data is validated and stored before curve-building processes transform market quotes into valuation curves. Pricing models consume those curves within controlled market-data scenarios to calculate valuations, sensitivities, positions and P&L.
- What is the difference between raw market data, reference data, derived data and a valuation curve?Raw market data includes vendor prices, rates and fixings. Reference data defines instruments, indexes, currencies, units and calendars. Derived data results from calculations or transformations. Valuation curves are constructed term structures used by pricing models to estimate future prices, discount cash flows and calculate risk.
- How would you design forward curves for crude oil, natural gas, LNG or power?I would define the curve's purpose, commodity, location, quality, currency, unit and granularity. Liquid market quotes would anchor observable periods, with governed interpolation and extrapolation elsewhere. The design must reflect seasonality, transport relationships, contract specifications, liquidity and independent validation requirements.
- How are spot prices, futures, swaps, forwards and seasonal instruments combined into a curve?Each instrument contributes information for specific points or periods along the curve. The construction process normalises units, currencies, locations and delivery periods, then resolves overlapping quotes using approved priorities. Bootstrapping and interpolation produce a continuous curve while retaining traceability to underlying market observations.
- Explain bootstrapping, interpolation and extrapolation.Bootstrapping derives successive curve points from quoted instruments. Interpolation estimates values between observable points using an approved mathematical method. Extrapolation estimates values beyond the liquid market horizon. Each introduces modelling assumptions that must reflect commodity behaviour and remain independently reviewed and documented.
- How would you determine the appropriate interpolation method for a particular commodity curve?I would evaluate instrument liquidity, delivery granularity, seasonality, storage economics and desired curve smoothness. Linear methods may suit simple products, while shaped commodities may require seasonality-aware approaches. Selection should be validated through back-testing, stability analysis and assessment of resulting valuation and sensitivity behaviour.
- What is the relationship between index definitions, reference sources, fixing data and forward curves?The index defines the contractual market reference and publication rules. The reference source supplies observations, while fixings store published historical values. Forward curves estimate unfixed future observations. Correct mapping ensures a floating trade transitions consistently from forecast valuation to realised contractual pricing as fixings become available.
- How would you handle multiple curve sets for trading, risk, accounting and independent price verification?I would create governed market-data scenarios for trading, risk, accounting and independent price verification, with explicit ownership and usage rules. Shared observable inputs should be reused where appropriate, while permitted adjustments remain transparent. Reports must identify the scenario and curve version behind every valuation.
- What is a market-data scenario, and how should scenarios be governed?A market-data scenario is a controlled collection of curves, prices, rates, fixings and modelling assumptions used for valuation. Scenarios support official close, intraday, stress and historical calculations. They require effective dates, versioning, approval, access controls and reproducibility to prevent inconsistent results across functions.
- How would you support intraday valuation without compromising official end-of-day results?I would maintain a clearly labelled intraday scenario refreshed from validated market feeds while preserving the official end-of-day scenario unchanged. Traders receive timely indicative P&L and exposure, whereas accounting and control processes use approved snapshots. Data timestamps and freshness indicators should remain visible.
- What happens to valuation when a required fixing is missing?The pricing formula cannot complete the contractual calculation reliably. ETRM may use an approved estimate or fallback for provisional valuation, but the missing fixing should generate an exception. The result must remain distinguishable from a final price and be recalculated when the observation becomes available.
- How would you design fallback rules without hiding market-data-quality problems?Fallbacks should follow contractual or governance-approved hierarchies, such as alternate sources, prior observations or authorised estimates. Every substitution must be flagged, time-limited and auditable. Controls should escalate material missing data and prevent fallback values from silently becoming official or permanent market observations.
- How would you investigate a large valuation change caused by a curve update?I would compare current and previous curve versions, underlying quotes, construction logs and validation exceptions. Next, I would isolate changed tenors and revalue affected cash flows. Sensitivity analysis helps determine whether the movement reflects legitimate markets, erroneous inputs, altered configuration or model behaviour.
- How would you implement historical market-data corrections while preserving reproducibility?I would preserve the original official snapshot and introduce the correction as a separately versioned market-data set. Any rerun should state its purpose and use the corrected version explicitly. Results must distinguish originally reported values from restated values and retain approvals, reasons and reconciliation evidence.
- How do you prevent future-dated data from leaking into an historical as-of valuation?Every valuation should enforce an as-of timestamp across trades, fixings, curves, reference data and configuration. Only information available by that timestamp may be selected. Versioned snapshots, effective dating and automated controls should reject later observations, backfilled records or subsequently corrected data unless explicitly authorised.
5. Valuation and Pricing15
- Explain the ETRM valuation pipeline for a newly captured trade.ETRM validates the trade economics, resolves the instrument and pricing configuration, generates projected cash flows, retrieves market data and applies the valuation model. Simulations then calculate present value, P&L and sensitivities, storing or displaying results according to the selected scenario and reporting definition.
- How does ETRM determine which pricing model and market data to use?The instrument, parameters, deal attributes and valuation configuration determine the pricing model. Index definitions and market-data mappings identify required curves, fixings, FX rates and discount factors. The selected simulation scenario and valuation date determine which approved versions are applied to the calculation.
- What is the difference between trade price, market price, model price and settlement price?Trade price is the contractually agreed price. Market price represents the observable current market level. Model price is calculated using curves and valuation assumptions, particularly when no direct quote exists. Settlement price is the contractually or externally determined value used to calculate the final payable amount.
- Explain discounting and the construction of discounted cash flows.Projected contractual cash flows are calculated from quantities, prices, fixings and payment terms. Each future cash flow is multiplied by a discount factor derived from the relevant currency curve. Summing discounted cash flows produces present value, reflecting both expected economics and the time value of money.
- How would you validate the valuation of a commodity swap independently?I would reconstruct each settlement period using contractual quantities, fixed prices, forward-index values, payment dates and discount factors. The independent result would be compared with ETRM at cash-flow level. Differences would then be traced to curves, calendars, units, fixings, rounding or discounting conventions.
- How are fixings incorporated into partially priced transactions?Published observations replace forward estimates for completed pricing dates, while remaining observations continue using the forward curve. The valuation therefore combines known and forecast index values. Each fixing must follow the contractual calendar and averaging rule, with missing or corrected observations managed through controlled exceptions.
- What happens to exposure as a floating-price trade progressively fixes?As observations fix, the trade's price uncertainty and sensitivity to the forward curve decline. Forecast exposure converts into known settlement value, although currency, volume, discounting and counterparty risks may remain. P&L reflects differences between earlier forward assumptions and subsequently published contractual fixing values.
- How would you value a trade containing multiple currencies?I would project cash flows in their contractual currencies, discount them using the corresponding currency curves and translate the resulting present values into the reporting currency using appropriate FX rates. The valuation should separately expose commodity, interest-rate and FX sensitivities and respect contractual conversion dates.
- How do discount curves, FX curves and commodity curves interact?Commodity curves forecast floating commodity prices, FX curves or rates convert cash flows across currencies, and discount curves translate future payments into present value. Their interaction depends on pricing currency, payment currency, reporting currency and payment timing, requiring consistent valuation dates and market-data conventions.
- How would you approach the valuation of optionality embedded in a physical contract?I would identify the exercise rights, operational constraints, nomination windows, volume limits and economic penalties. Material optionality may require simulation, optimisation or option-pricing techniques using appropriate volatility and correlation assumptions. The model must reflect feasible physical operations, not merely theoretical financial exercise behaviour.
- What are the risks of approximating a structured deal with several standard instruments?A replication may simplify implementation but can misrepresent optionality, dependencies, lifecycle events, settlement terms or physical constraints. It may also create fragmented positions, misleading sensitivities and difficult amendments. The approximation is acceptable only when differences are quantified, immaterial, documented and independently approved.
- When would a custom pricing model be justified?A custom model is justified when supported standard models cannot materially reproduce the contract's economics, optionality or risk profile. The expected benefit must exceed development, validation, performance, support and upgrade costs. Customisation should not compensate for misunderstood requirements, poor configuration or unnecessary product complexity.
- What governance should surround a custom valuation model?Governance should include documented methodology, assumptions, limitations, data requirements, independent model validation, benchmark testing, approval and version control. Production implementation also requires performance testing, access controls, monitoring, change management, fallback procedures and periodic review against observed behaviour and evolving market conditions.
- How would you reconcile ETRM valuation with a trader spreadsheet?I would first align trade version, valuation date, market-data timestamp, curves, fixings, calendars, units and discounting conventions. Next, I would compare projected cash flows and valuation components individually. The spreadsheet is diagnostic evidence, not automatically authoritative, and its formulas must also be validated.
- How would you distinguish model error from market-data error, trade-data error and configuration error?I would reproduce the valuation with controlled inputs, then test one layer at a time: contractual fields, market-data observations, curve construction, instrument configuration and pricing logic. Cash-flow comparison and sensitivity analysis reveal where results diverge, allowing evidence-based classification instead of attributing every difference to the model.
6. Positions, Exposure and P&L15
- Explain the difference between contractual position, scheduled position, nominated position and actual position.Contractual position reflects legally agreed quantities. Scheduled position represents planned physical movements. Nominated position records quantities submitted to pipelines, grids or operators. Actual position uses measured delivery or consumption. Each state should remain separately traceable because operational changes can affect exposure, settlement and P&L.
- How would you calculate the position of a physical commodity desk?I would aggregate validated purchases, sales, inventory, transport commitments and eligible operational movements by commodity, location, delivery period and unit. The report should distinguish contractual, scheduled, nominated and actual quantities while converting them through governed factors and preventing duplication between trades and movements.
- What are the appropriate position measures for oil, gas, LNG and power?Oil requires mass or volume by grade, location and period. Gas requires volume and energy by gas day and hub. LNG needs tonnes, cubic metres and energy by cargo. Power requires MW and MWh by delivery interval, zone and peak classification.
- How should position aggregation handle different units of measure?Positions should retain original contractual quantities while converting them into approved reporting units through governed, effective-dated conversion rules. Context-dependent factors such as density, temperature or calorific value must remain explicit. Aggregation should stop or flag exceptions when a reliable conversion is unavailable.
- How do pricing exposure and physical delivery exposure differ?Pricing exposure measures sensitivity to unfixed market prices and determines how valuation changes when curves move. Physical delivery exposure represents the quantity that must be supplied, received, transported or stored. A fully fixed transaction may have no price exposure while retaining substantial delivery obligations.
- What happens to delta exposure as pricing observations become fixed?Each published fixing replaces a forecast curve observation, reducing the transaction's sensitivity to that market factor. Delta normally declines progressively until pricing is fully fixed. Residual exposure may remain from quantity uncertainty, currency conversion, discounting, basis differences or operational adjustments.
- How would you design trader position screens for prompt and forward exposure?I would provide prompt and forward positions by commodity, book, location, delivery period, index and unit, with drill-down to trades and profiles. Screens should separate physical, financial, fixed and floating exposure, display data freshness and exceptions, and support approved aggregation without hiding basis risk.
- Explain realised, unrealised, settled and total P&L.Realised P&L arises when pricing or disposal economics become fixed. Unrealised P&L reflects changes in the value of open or unfixed positions. Settled P&L relates to completed cash settlements. Total economic P&L combines relevant realised and unrealised components without double counting settlement.
- Explain daily P&L attribution.Daily P&L attribution decomposes the movement from prior close to current valuation into identifiable drivers, including new trades, market movements, fixings, time passage, amendments, cancellations, FX and model changes. Remaining unexplained P&L must be investigated rather than automatically assigned to a balancing category.
- How would you separate new-deal, market-movement, time-decay, fixing and amendment P&L?I would preserve prior-day trades and market data, then revalue through controlled sequential states. Introducing current trades isolates new-deal P&L; updating market data captures market movement; advancing time captures carry; applying published observations captures fixing effects; and applying changed trade versions isolates amendment P&L.
- What is the difference between accounting P&L and risk or economic P&L?Economic P&L reflects current valuation and trading performance using approved risk curves and models. Accounting P&L follows recognition, classification and measurement rules under the applicable accounting standard. Timing, accruals, reserves, hedge accounting and valuation adjustments can therefore produce legitimate differences between them.
- How would you investigate a material unexplained P&L amount?I would confirm trade population, versions, valuation date, market-data snapshots, fixings and calculation status. Then I would compare cash flows and sensitivities across sequential P&L states. Remaining differences would be traced to mappings, lifecycle events, units, curves, model changes or incomplete processing.
- Why might trader P&L differ from Product Control P&L?The trader may use intraday prices, indicative curves, local adjustments or different portfolio filters, while Product Control uses independently approved end-of-day data, reserves and accounting adjustments. Differences can also arise from cut-offs, late trades, FX rates, valuation models, hierarchy mappings or failed calculations.
- How should prior-day curves and prior-day trade states be preserved?Official close processing should retain immutable, versioned snapshots of trades, reference data, fixings, curves, models and configuration with a common as-of timestamp. Reproducing prior-day P&L requires selecting that complete information set, not merely restoring yesterday's prices against today's amended transactions.
- How would you prevent double counting between physical trades and associated hedges?I would retain physical and hedge transactions separately but connect them through strategy or hedge relationships. Reports should aggregate signed exposure by common risk factors while preserving basis differences. Controls must prevent operational movements, internal transfers or derivative equivalents from being counted as additional external positions.
7. Front Office Workflows and Controls15
- Design a workflow from draft trade through trader validation, confirmation and operational processing.A trader creates a draft using approved templates and reference data. Automated checks validate economics, mandate, counterparty, credit and price reasonableness. Authorised approval moves the trade to validated status, triggering positions, confirmations and operational events. Exceptions enter controlled queues with ownership and ageing.
- Which trade checks should be blocked, and which should generate warnings?Failures affecting legal validity, valuation, settlement, credit, trader authority or mandatory economics should block progression. Lower-risk anomalies may generate warnings when an authorised user can assess them. Classification should reflect materiality, compensating controls and downstream consequences rather than user convenience.
- How would you implement approval thresholds based on notional, tenor, product and trader mandate?I would define configurable approval rules using notional, quantity, tenor, product complexity, off-market amount, portfolio and trader mandate. Transactions exceeding thresholds would require independent approval before validation. Rules need named owners, effective dates, version control, exception handling and evidence of approval.
- How would you enforce counterparty, credit and market-risk controls before trade validation?ETRM should calculate incremental counterparty exposure, market-risk usage and applicable limit consumption before validation. Approved rules would block or route breaches for authorised approval. Controls must use current agreements, collateral, hierarchy and market data while preserving the decision, values, timestamp and approver.
- What should happen when credit capacity is unavailable?The trade should remain unvalidated or enter a controlled pending-credit status. Credit Risk may reject it, reduce its size, obtain collateral or approve a documented temporary excess within authority. The system should not silently book the transaction or treat unavailable exposure data as zero.
- How would you support emergency trade capture while retaining governance?I would provide a restricted emergency workflow with named authorised users, mandatory justification, limited products and thresholds, enhanced logging and automatic expiry. Trades would undergo retrospective independent review within a defined period. Emergency access must not become a permanent shortcut around standard controls.
- How would you control backdated and future-dated trades?Date tolerances should vary by product, portfolio and user role. Transactions outside approved ranges should be blocked or require independent approval and justification. Controls must evaluate impacts on historical positions, P&L, confirmations, settlements, accounting and regulatory reporting, triggering restatement where necessary.
- How would you control manual price overrides?Overrides should require a reason, approved source, user authority and independent review above materiality thresholds. ETRM must retain original and overridden values, timestamps and approvals. Reports should identify active overrides, their valuation impact, age and expiry, preventing them from becoming permanent undocumented prices.
- How should off-market transactions be detected and approved?The trade price should be compared with an independent market or model value using product-specific tolerances. Material deviations require documented commercial rationale and approval independent of the trader. The control should consider bid-offer, liquidity, optionality and legitimate structured economics before classifying a breach.
- How would you govern changes to portfolios, strategies and trader assignments?Creation and modification should follow controlled requests with business-owner, Risk, Finance and security approval where relevant. Changes need effective dates, impact analysis, testing and audit history. Historical reporting must preserve prior assignments rather than automatically rewriting earlier positions and P&L under current structures.
- What information should be retained in the trade audit trail?The audit trail should record original and changed values, transaction version, user or service identity, timestamp, action, reason, workflow status and approval. It should also preserve source identifiers and distinguish manual, interface-generated and system-derived changes while remaining tamper-resistant and searchable.
- How should workflow design separate economic validation from operational completeness?Economic validation confirms product, price, quantity, dates, counterparty, portfolio and valuation terms are sufficient for risk recognition. Operational validation confirms settlement instructions, delivery details, confirmation data and documentation. A trade may enter risk promptly while remaining in a controlled operational-exception workflow.
- How would you prevent a failed downstream event from blocking trader activity unnecessarily?Trade validation should commit the authoritative transaction and publish durable downstream work asynchronously. Failed confirmations, reports or interfaces should enter retryable exception queues rather than reversing valid trades. Idempotency, monitoring and reconciliation must ensure failures are recovered without loss or duplicate processing.
- What is your approach to workflow retry, exception handling and operational ownership?I would classify errors as transient, data-related or permanent. Transient failures receive limited automated retries with back-off; data errors enter owned work queues; permanent failures require technical resolution. Every exception needs correlation identifiers, ageing, escalation, controlled replay and proof of successful completion.
- How would you demonstrate that Front Office controls remain effective after an ETRM upgrade?I would execute traceable positive and negative regression tests covering permissions, mandates, limits, approvals, overrides, audit history and exception handling. Results would be compared with the approved baseline, while changed behaviour receives impact assessment, business-control-owner approval and post-production monitoring.
8. Integration Architecture15
- How would you integrate an exchange, broker or execution-management system with ETRM?
- When would you use real-time messaging, APIs, database staging or batch-file integration?
- What are the risks of directly integrating external systems with ETRM database tables?
- How would you design idempotent trade ingestion?
- How would you manage source-system identifiers and ETRM deal numbers?
- How would you handle partial integration failure after a deal has already been created?
- What acknowledgment and reconciliation controls should surround inbound trades?
- How would you publish Front Office positions and P&L to an enterprise data platform?
- How would you ensure that downstream consumers receive amendments in the correct order?
- How would you manage schema evolution for trade events?
- How would Kafka fit alongside ETRM's native integration mechanisms?
- Which data should be distributed as events, and which should be obtained through queries?
- How would you prevent a reporting platform from placing excessive load on ETRM?
- How would you design integrations for low-latency intraday risk?
- How would you reconcile externally executed trades against ETRM?
9. Performance and Batch Architecture10
- A trader's position screen takes five minutes to load. How would you diagnose it?
- What commonly causes slow ETRM simulations?
- How would you separate database, configuration, script and valuation-model performance problems?
- How would you optimize a large portfolio simulation?
- What are the risks of adding excessive result measures to every simulation?
- How would you design intraday simulations differently from official end-of-day runs?
- How would you manage concurrent trader and batch workloads?
- How do grid computing and distributed valuation affect the solution design?
- How would you investigate a simulation that returns different results across environments?
- Which non-functional requirements should be agreed before designing a Front Office solution?
10. Architecture and Design Governance15
- What artifacts should an ETRM Solution Architect produce before implementation?
- How would you document current-state and target-state ETRM architecture?
- What belongs in a solution-design document for a new trading product?
- How do you decide between configuration, scripting, custom code and external services?
- How do you prevent excessive ETRM customisation?
- What makes an ETRM solution upgrade-safe?
- How would you organise reusable components across multiple commodity desks?
- How would you conduct an architectural design review?
- How do you trace business requirements to configuration, code and tests?
- What design decisions should be recorded in an architecture decision register?
- How would you manage ETRM configuration across development, testing and production?
- How do you handle environment-specific identifiers and reference data?
- How would you assess the impact of an ETRM version upgrade on the Front Office?
- What should be included in a Front Office production-readiness review?
- How would you balance trader usability, control, performance and maintainability?
11. Scenario-Based Architect Questions15
- A trader says the position is correct but P&L is wrong. Describe your investigation.
- ETRM and the exchange show different positions. How do you determine the authoritative state?
- A newly entered deal values correctly but does not appear in the trader's position report. What do you check?
- A curve was corrected after end-of-day. How would you rerun valuation without destroying the original official result?
- A physical crude deal is economically correct but produces incorrect invoices. Is this a Front Office or settlement-design issue?
- A structured LNG contract takes 20 seconds to value individually but causes the portfolio simulation to exceed its SLA. What would you change?
- Traders want a spreadsheet upload that bypasses normal trade validation. How would you respond?
- The business wants one global deal template despite regional differences. What risks would you raise?
- A desk wants real-time P&L, but official market data updates only periodically. How would you define the result?
- A trade amendment changes historical P&L. How would you determine whether this is expected?
- ETRM contains thousands of nearly identical trade templates. How would you rationalise them?
- A new product can be represented using a generic instrument, but users find the trade-entry screen confusing. How would you decide whether to customize it?
- A trader books the same economics across several instruments to obtain the required valuation. What long-term risks does this create?
- A production issue can be fixed through either a script change or reference-data correction. How would you choose?
- The Front Office requests unrestricted manual curve overrides. Design a controlled alternative.
12. Solution-Architect Leadership Questions15
- How do you challenge a requirement that reproduces an inefficient legacy process?
- How do you resolve disagreements between traders, risk, operations and technology?
- How do you estimate an ETRM product-onboarding initiative?
- How do you identify architecture dependencies before committing delivery dates?
- How would you divide responsibilities among functional consultants, developers, quants, data engineers and infrastructure teams?
- How do you review the quality of ETRM scripts and configurations?
- How would you govern design decisions delivered by multiple implementation partners?
- Describe a major ETRM production problem you diagnosed and the evidence that identified its root cause.
- Describe a design you rejected even though the business initially preferred it.
- How do you explain a complex valuation or architecture decision to senior non-technical stakeholders?
- How do you ensure operational support teams can manage the implemented solution?
- What metrics would show whether a Front Office implementation has succeeded?
- How would you plan parallel run and migration for an existing trading desk?
- What would make you stop a production release?
- What distinguishes an ETRM Solution Architect from a senior ETRM developer or functional consultant?
Essential Whiteboard Exercises10
- End-to-end OTC commodity trade flow from execution to P&L and settlement.
- Physical crude trade priced at monthly Brent average plus differential.
- Gas delivery profile with nominations, actuals, imbalance and settlement.
- Intraday and end-of-day curve architecture.
- Real-time trade ingestion with idempotency, retry and reconciliation.
- Front Office position and P&L reporting architecture.
- New-product onboarding process with governance and testing.
- High-availability design for business-critical trading operations.
- Historical as-of valuation and reproducible P&L architecture.
- ETRM-to-enterprise-data-platform integration using events and controlled extracts.
Middle Office12 sections · 170 questions
1. Middle Office Operating Model10
- What does a Middle Office function do within an ETRM-based trading organisation?
- How do Front Office, Middle Office, Product Control, Credit Risk and Back Office responsibilities differ?
- Explain the trade lifecycle from Middle Office validation through risk reporting and control.
- Which trade attributes are most important for Middle Office control?
- How would you design segregation of duties between traders and control functions?
- Which controls should operate pre-trade, at trade validation and post-trade?
- How should the Middle Office manage late, backdated and amended trades?
- What is the difference between preventive, detective and corrective controls?
- How would you establish an exception-based Middle Office operating model?
- What evidence should ETRM retain for audit and regulatory review?
2. Trade Validation and Control15
- How would you design a Middle Office trade-validation workflow in ETRM?
- Which validations should block a trade from progressing?
- How would you identify off-market transactions?
- How would you control manual price overrides?
- How would you detect trades booked in incorrect portfolios?
- How should trader mandates and product permissions be enforced?
- How would you control transactions exceeding tenor or quantity thresholds?
- How would you identify duplicate or missing trades?
- How should cancelled, terminated, novated and partially unwound trades be controlled?
- How would you validate complex pricing formulas independently?
- How would you control internal, inter-book and intercompany trades?
- How should exceptions be prioritised, assigned, aged and escalated?
- How would you handle trades entered after an official valuation cut-off?
- What controls should apply to spreadsheet and bulk-uploaded transactions?
- How would you prove that all executed trades were captured in ETRM?
3. Position and Exposure Management15
- Explain contractual, pricing, delivery, nominated and actual positions.
- How would you design a consolidated commodity position report?
- How should ETRM aggregate positions across units, currencies and locations?
- What is the difference between physical and financial exposure?
- How should fixed and floating legs appear in position reporting?
- How does exposure change as index observations become fixed?
- How would you represent basis and location risk?
- How would you measure shape risk in gas or power portfolios?
- How would you identify unintended residual positions?
- How should options and nonlinear instruments appear in position reports?
- How would you reconcile ETRM positions with exchanges and brokers?
- How would you reconcile physical positions with scheduling systems?
- What can cause a trade to value correctly but appear incorrectly in positions?
- How would you control unit-of-measure conversions?
- How should historical as-of positions be reproduced?
4. P&L and Product Control15
- Explain realised, unrealised, settled and total P&L.
- How would you design daily P&L reporting in ETRM?
- What is P&L attribution or explain?
- How would you separate new-deal, market-movement, fixing, time and amendment P&L?
- What causes unexplained P&L?
- How would you investigate a large day-on-day P&L movement?
- Why might trader P&L differ from Product Control P&L?
- How do intraday and official end-of-day P&L differ?
- How should fees, premiums, transportation and storage costs affect P&L?
- How would you handle provisional and final pricing in P&L?
- How do nominations and actual quantities affect physical-trade P&L?
- How should FX effects be separated from commodity-price effects?
- How would you design P&L sign-off and adjustment workflows?
- How should prior-period corrections and restatements be governed?
- How would you reconcile ETRM P&L with the general ledger?
5. Market Data and Independent Price Verification15
- What is the Middle Office role in market-data governance?
- How would you distinguish trader, risk, accounting and IPV curves?
- What controls should validate incoming market prices?
- How would you identify stale, missing or anomalous market data?
- How should price-source hierarchies and fallback rules be governed?
- How would you design independent price verification in ETRM?
- How do bid-offer reserves affect fair-value reporting?
- How would you value illiquid or unobservable curve tenors?
- How should valuation adjustments be calculated and approved?
- How would you control manual curve adjustments?
- What is prudent valuation, and how does it differ from economic valuation?
- How would you investigate a curve change causing a material P&L movement?
- How should corrected market data be applied after end-of-day?
- How would you prevent future information from entering historical valuations?
- What evidence should support an official market-data snapshot?
6. Market Risk and Sensitivities15
- Which market-risk measures should ETRM calculate for commodity portfolios?
- Explain delta, gamma, vega and theta in commodity trading.
- How would you calculate basis, location and spread sensitivities?
- What risk factors should be mapped for a physical crude-oil portfolio?
- How would you represent gas or power shape risk?
- How do cross-currency trades create combined commodity and FX exposure?
- How should risk-factor mappings be governed?
- What happens when a trade cannot be mapped to an approved risk factor?
- How would you validate ETRM sensitivities independently?
- What can cause unstable or counterintuitive Greeks?
- How would you design risk aggregation by desk, book and legal entity?
- How should nonlinear and optional products be included in risk reporting?
- How would you distinguish gross, net and hedged exposure?
- How should liquidity risk complement conventional market-risk measures?
- How would you investigate inconsistent risk across two simulations?
7. Value at Risk17
- Explain parametric, historical and Monte Carlo VaR.
- Which VaR method is most appropriate for a commodity portfolio?
- How would you design an ETRM VaR implementation?
- What are risk factors, returns, covariance matrices and confidence levels?
- How should missing historical data be handled?
- How would you map new or illiquid products to proxy risk factors?
- What is the difference between full revaluation and sensitivity-based VaR?
- How do holding period and confidence level affect VaR?
- How should options and nonlinear products be treated?
- How would you validate VaR results?
- What is VaR backtesting?
- How should backtesting exceptions be investigated?
- What is model drift, and how would you detect it?
- How would you prevent incorrect aggregation of commodity-level VaR?
- Why can portfolio VaR differ from the sum of individual VaRs?
- How would you investigate an unexpectedly large VaR result?
- What limitations of VaR must be communicated to management?
8. Stress Testing and Scenario Analysis15
- How does stress testing differ from VaR?
- How would you design historical and hypothetical stress scenarios?
- What constitutes a shocked-revaluation stress test?
- Why is multiplying delta by a price shock insufficient for some products?
- How would you stress commodity, basis, FX and volatility risks together?
- How should correlations behave under stressed conditions?
- How would you model negative commodity prices?
- How would you stress illiquid forward-curve tenors?
- How should physical constraints be represented in stress testing?
- How would you stress an LNG portfolio for cargo delay or diversion?
- How would you model gas-storage or power-shape stress?
- How should stress losses be aggregated and reported?
- How would you govern scenario creation, approval and retirement?
- How should stress-test results influence limits and management actions?
- How would you demonstrate that a scenario is severe but plausible?
9. Credit Risk and Limits15
- How does commodity counterparty credit risk differ from market risk?
- Explain current, future and settlement exposure.
- How would you calculate counterparty exposure in ETRM?
- What is potential future exposure?
- How do netting and collateral agreements reduce exposure?
- How would you model parent, subsidiary and credit-group structures?
- How should guarantees and letters of credit affect available credit?
- How would you implement credit limits by counterparty, product and tenor?
- What should happen when a proposed trade breaches a limit?
- How should temporary limit increases be governed?
- How do wrong-way risk and concentration risk arise?
- How would you represent sovereign, country and industry limits?
- How would you reconcile ETRM credit exposure with a central credit platform?
- How should disputed settlements affect credit exposure?
- How would you investigate an unexpected credit-limit breach?
10. Risk Limits and Mandates13
- What types of market-risk limits should be configured?
- How would you distinguish hard and soft limits?
- How should limit utilisation be calculated and aggregated?
- How would you define limits for delta, VaR, stress and position?
- How should desk, book and trader mandates interact?
- What workflow should follow a limit breach?
- How would you handle a breach caused by market movements rather than new trading?
- How should intraday and end-of-day limit monitoring differ?
- How would you prevent users from bypassing limits through portfolio transfers?
- How should temporary exceptions and limit extensions expire?
- What evidence should support limit approval and changes?
- How would you prevent double counting across hierarchical limits?
- How should limit consumption be reconciled with reported risk?
11. Simulations, Reporting and Performance15
- Explain the purpose of ETRM simulations and result measures.
- How would you design separate intraday and end-of-day simulations?
- What result measures are required for Middle Office reporting?
- How would you preserve reproducible official risk results?
- What commonly causes slow ETRM risk simulations?
- How would you optimize a large portfolio simulation?
- How should simulation dependencies and execution order be managed?
- How would you prevent reporting workloads from affecting traders?
- What controls should verify that all portfolios were processed?
- How would you manage failed or partially completed risk runs?
- How should corrected trades or market data trigger recalculation?
- How would you publish ETRM risk results to an enterprise platform?
- How would you reconcile published results with ETRM?
- How should report definitions, filters and calculations be versioned?
- What service-level objectives should apply to risk reporting?
12. Architecture and Scenario Questions10
- A trader's P&L is correct, but VaR is materially overstated. How would you investigate?
- ETRM and the exchange report different positions. Which checks would you perform?
- A new trade is visible in P&L but missing from risk. What could cause this?
- A corrected curve changes yesterday's official P&L. How should it be handled?
- A portfolio has zero net delta but significant basis risk. Explain the situation.
- A VaR result rises tenfold overnight without major market movement. How would you isolate the cause?
- Traders request permission to override risk-factor mappings. How would you respond?
- A physical contract values correctly but its delivery exposure is wrong. Where would you investigate?
- Risk results differ between test and production using the same trades. What should be compared?
- What distinguishes an ETRM Middle Office Solution Architect from a risk analyst, functional consultant or developer?
Back Office12 sections · 190 questions
1. Back Office Operating Model10
- What does the Back Office function do in an ETRM-based trading organisation?
- How do Front Office, Middle Office, Operations, Back Office and Finance responsibilities differ?
- Explain the transaction lifecycle after Front Office validation.
- Which ETRM trade attributes are critical for downstream processing?
- How would you design segregation of duties between trade entry, confirmation, settlement and payment?
- What are the differences between economic, operational, settlement and accounting events?
- How would you design an exception-based Back Office operating model?
- Which controls should be preventive, detective or corrective?
- How should Back Office manage late and backdated transactions?
- What operational evidence must ETRM retain for audit purposes?
2. ETRM Event and Lifecycle Architecture15
- Explain ETRM's event-driven processing architecture.
- How do instruments generate lifecycle and settlement events?
- What is the relationship among transactions, parameters, profiles, cash flows and events?
- How do event dates differ from payment and settlement dates?
- How would you identify missing or incorrectly generated events?
- What happens to events when a transaction is amended?
- How should cancelled, terminated and partially unwound transactions affect existing events?
- How would you prevent duplicate lifecycle events?
- When should an event be regenerated rather than manually corrected?
- How would you manage event dependencies and processing order?
- What controls should prevent incomplete trades from generating downstream events?
- How should historical events be preserved after transaction changes?
- How would you manage manually entered Back Office events?
- What configuration changes can unintentionally alter event generation?
- How would you test event generation for a newly introduced product?
3. Confirmations and Contract Documentation15
- Explain the confirmation lifecycle in ETRM.
- What determines whether a transaction requires confirmation?
- How would you select the correct confirmation template?
- Which trade and reference-data fields commonly populate confirmations?
- How would you support confirmations across products, languages and legal entities?
- What is the difference between paper, email and electronic confirmation?
- How would you integrate ETRM with an electronic confirmation platform?
- How should matching statuses and discrepancies be managed?
- What controls should identify unconfirmed or aged transactions?
- How would you handle disputed economic terms?
- How should trade amendments affect previously issued confirmations?
- How would you manage transaction cancellations and confirmation withdrawals?
- What should happen when confirmation generation fails?
- How would you prevent duplicate confirmations?
- How would you prove that all eligible transactions were confirmed?
4. Settlement Instructions and Static Data15
- What are standard settlement instructions?
- How should settlement instructions be assigned to a transaction?
- How would you model instructions by counterparty, legal entity, currency and product?
- How would you control changes to bank-account details?
- Why should settlement instructions not be maintained directly on every trade?
- How should effective dating work for settlement instructions?
- What happens when settlement instructions are missing or ambiguous?
- How would you prevent payments to unauthorised bank accounts?
- What maker-checker controls should govern sensitive static data?
- How would you handle one-off settlement instructions?
- How should beneficiary, intermediary and correspondent banks be represented?
- How would you manage settlement instructions for internal counterparties?
- What reference data is necessary for physical commodity settlement?
- How would you migrate settlement instructions from a legacy platform?
- How would you test static-data changes without creating real payments?
5. Settlement and Netting20
- Explain the ETRM settlement lifecycle.
- How are settlement amounts generated from transaction economics?
- What is the difference between contractual cash flow and settlement events?
- How would you validate settlement amounts independently?
- How should fixed and floating transactions progress toward settlement?
- How are provisional and final settlements managed?
- How do payment terms, business-day rules and calendars affect settlement dates?
- How would you configure bilateral settlement netting?
- What legal prerequisites must exist before cash flows can be netted?
- How should netting by currency, agreement and settlement date work?
- How would you prevent inappropriate netting across legal entities?
- What is payment netting versus close-out netting?
- How would you manage gross-settlement exceptions?
- How should disputed cash flows be excluded from payment?
- How would you control manual settlement adjustments?
- What happens when a settled transaction is amended?
- How would you reconcile expected and completed settlements?
- How should settlement failures be tracked and escalated?
- How would you manage partial settlement?
- How would you demonstrate settlement completeness at end-of-day?
6. Invoicing20
- Explain the invoice lifecycle for a physical commodity transaction.
- What is the difference between payable, receivable and self-billing invoices?
- How does ETRM group settlement events into invoices?
- Which attributes should determine invoice grouping?
- How would you configure invoice templates for different legal entities?
- How are taxes, fees and additional charges included?
- How would you manage provisional and final invoices?
- How should quantity and price adjustments affect invoices?
- How would you handle credit notes and debit notes?
- What happens when an invoiced transaction is amended?
- How would you prevent duplicate invoicing?
- How should invoice numbering be controlled?
- How would you manage disputed invoices?
- What controls should identify uninvoiced eligible events?
- How would you reconcile invoices with supporting trades and deliveries?
- How should rounding differences be managed?
- How would you integrate ETRM with an external invoicing platform?
- How would you support electronic invoicing requirements?
- How should invoice approval and release be segregated?
- What evidence should support invoice cancellation and reissuance?
7. Physical Commodity Operations15
- How do scheduled, nominated, confirmed and actual quantities differ?
- How should actual quantities update settlement?
- How would you model quantity tolerances?
- How should under-delivery and over-delivery be processed?
- How would you handle natural-gas imbalance charges?
- How should oil quantity and quality adjustments affect invoicing?
- How would you represent losses, gains and shrinkage?
- How should delivery locations and movement identifiers be controlled?
- How would you integrate ETRM with a scheduling or logistics platform?
- What happens when operational actuals arrive after invoicing?
- How would you reconcile contractual quantities with physical movements?
- How should inventory transfers affect settlement and accounting?
- How would you process freight, demurrage and ancillary charges?
- How should LNG boil-off or delivered-energy adjustments be handled?
- How would you preserve traceability from a physical movement to its financial settlement?
8. Payments and Treasury Integration15
- Explain the process from approved settlement to payment instruction.
- How would you integrate ETRM with a treasury-management or payment platform?
- What payment statuses should return to ETRM?
- How would you generate and control payment files?
- What controls should prevent duplicate payments?
- How would you support payment cancellation and recall?
- How should rejected bank payments be handled?
- How would you manage payment cut-off times?
- How should value dates and payment dates differ?
- How would you manage multicurrency settlement?
- How should bank charges be recorded?
- What is payment-on-behalf-of, and what controls does it require?
- How would you manage urgent manual payments?
- How would you reconcile payment acknowledgements and bank statements?
- How should unapplied cash be investigated?
9. Accounting Architecture20
- Explain how ETRM generates accounting entries from transactions and events.
- What is the relationship between business events and accounting events?
- How would you design accounting rules for a new commodity product?
- How should realised and unrealised P&L be accounted for?
- How would you handle accruals and reversals?
- How should invoices, settlements and payments affect accounting?
- How would you account for provisional and final pricing?
- How should fees, premiums and transportation costs be treated?
- How would you handle inventory accounting?
- How should intercompany transactions be accounted for?
- How would you support multiple accounting standards or ledgers?
- How should account mappings be governed?
- What dimensions should accompany general-ledger postings?
- How would you prevent unbalanced accounting entries?
- How should accounting periods and cut-offs be controlled?
- How would you handle postings after period close?
- How should accounting corrections be implemented?
- How would you reconcile ETRM's subledger with the general ledger?
- What controls identify unposted or rejected accounting events?
- How would you test accounting changes for existing products?
10. Collateral and Margin Operations10
- How do variation margin and initial margin differ?
- How should collateral calls be calculated and processed?
- How would you represent collateral agreements and thresholds?
- How do minimum transfer amounts and independent amounts affect calls?
- How should collateral disputes be managed?
- How would you integrate ETRM with clearing brokers or collateral platforms?
- How should cash and non-cash collateral be represented?
- How would you manage collateral interest?
- What controls prevent duplicate or incorrect margin payments?
- How would you reconcile ETRM collateral balances with external statements?
11. Reconciliation, Interfaces and Batch Processing15
- Which Back Office reconciliations should be performed daily?
- How would you reconcile trades, events, invoices, payments and accounting entries?
- How would you design idempotent outbound interfaces?
- How should failed interface messages be retried?
- How would you prevent events from being delivered out of sequence?
- How should source and target identifiers be maintained?
- What should a Back Office control dashboard contain?
- How would you design completeness and control-total checks?
- What commonly causes ETRM end-of-day processing failures?
- How would you restart a failed batch without duplicating output?
- How should business cut-offs and time zones be managed?
- How would you preserve reproducible end-of-day results?
- How should archived settlement and accounting data remain accessible?
- How would you design operational monitoring and alerting?
- Which service levels should apply to confirmations, invoices, payments and accounting?
12. Solution Architecture Scenarios20
- A trade values correctly but generates no settlement event. How would you investigate?
- ETRM produces the wrong payment date despite correct contractual terms. What would you check?
- An amendment creates both the original and revised invoice amounts. How would you resolve it?
- A counterparty receives two confirmations for one transaction. Where could duplication occur?
- ETRM nets payments that the legal agreement requires to settle gross. How would you respond?
- A bank rejects a payment file generated by ETRM. How would you isolate the cause?
- A physical trade settles using scheduled rather than actual quantity. What should be examined?
- ETRM and the general ledger disagree after month-end. How would you reconcile them?
- Accounting entries are correct individually but unbalanced by legal entity. What could cause this?
- An invoice was issued before a corrected fixing arrived. How should the lifecycle continue?
- A settled transaction is cancelled retrospectively. What controls and events are required?
- Operations requests direct database correction of a failed event. How would you respond?
- ETRM and the treasury platform show different payment statuses. Which system is authoritative?
- An interface replay creates duplicate accounting postings. How should the architecture prevent this?
- A Back Office batch misses its cut-off. How would you prioritise recovery?
- A new product values correctly but fails confirmation and accounting tests. Is it production-ready?
- How would you migrate unsettled trades without duplicating invoices or payments?
- How would you prove that every eligible settlement event reached the payment platform?
- What would make you stop a Back Office production release?
- What distinguishes an ETRM Back Office Solution Architect from a functional consultant or developer?
Technical and Platform Architecture17 sections · 320 questions
1. ETRM Platform Architecture15
- Describe the logical architecture of an enterprise ETRM implementation.
- What are the principal ETRM platform components and their responsibilities?
- How do ETRM clients, application services, engines and database components interact?
- How does ETRM's architecture support Front, Middle and Back Office processes?
- Which processing should remain inside ETRM, and which should be externalised?
- How would you identify architectural boundaries between ETRM and surrounding platforms?
- What are the major stateful and stateless components?
- How does ETRM support interactive, scheduled and event-driven processing?
- How would you map ETRM components to business capabilities?
- Which architectural dependencies create the greatest operational risk?
- What information would you collect before designing an ETRM target architecture?
- How would you document the current-state platform?
- How would you identify obsolete, duplicate or unsupported components?
- How should architecture differ for a single-desk and global multi-commodity implementation?
- What distinguishes a platform architecture decision from a functional configuration decision?
2. ETRM Services and Processing Components15
- What categories of ETRM services and engines are commonly deployed?
- How should services be separated by workload and business criticality?
- Which services require continuous availability?
- How do interactive and background processing workloads differ?
- How would you prevent one resource-intensive process from affecting other users?
- How should service instances be distributed across hosts?
- When should multiple service instances be deployed?
- How would you determine appropriate concurrency levels?
- What causes service contention or processing bottlenecks?
- How should service dependencies and startup order be managed?
- What health checks should be implemented for ETRM services?
- How would you detect a service that is running but not processing correctly?
- How should failed jobs be recovered safely?
- How would you prevent duplicate execution following service restart?
- What operational metadata should every service execution produce?
3. Transaction and Reference-Data Architecture15
- How are transactions represented within ETRM?
- What is the architectural relationship among instruments, transactions, parameters and profiles?
- How do transaction statuses affect downstream processing?
- How would you design organisational structures, portfolios and books?
- How should legal entities, business units and counterparties be represented?
- Which reference-data domains are foundational to ETRM?
- How would you establish authoritative sources for reference data?
- What are the risks of duplicating enterprise reference data inside ETRM?
- How should effective-dated reference data be managed?
- How would you control changes to indexes, units, currencies and calendars?
- How should reference-data dependencies be migrated between environments?
- How would you identify transactions affected by a reference-data change?
- What controls should govern bulk reference-data updates?
- How would you reconcile ETRM reference data with enterprise master-data platforms?
- How should historical transactions remain reproducible after reference-data changes?
4. Database and Persistence Architecture15
- What role does the relational database play within ETRM?
- Why should external applications avoid direct writes to ETRM tables?
- When, if ever, are direct database reads acceptable?
- What risks arise from tightly coupling reporting to the ETRM schema?
- How would you identify expensive database queries?
- What causes database blocking and contention in ETRM?
- How should indexes and statistics be managed?
- How would you diagnose rapid database growth?
- Which data-retention and archival requirements should be defined?
- How would you design database backup and recovery?
- How would you verify that a backup is operationally recoverable?
- What consistency risks arise when restoring the database independently of other components?
- How should database credentials and privileged access be controlled?
- How would you separate transactional and analytical workloads?
- How should database changes be governed during an legacy-to-modern ETRM upgrade?
5. Extensibility with Custom Code20
- What is the platform scripting language, and where is it commonly used?
- When should the platform scripting language be used instead of standard configuration?
- When is a Java extension preferable to an the platform scripting language script?
- What are the risks of excessive scripting?
- How would you structure reusable script libraries?
- How should scripts handle transactions, errors and resource cleanup?
- How would you prevent memory leaks in long-running processes?
- How should logging be implemented within custom components?
- How would you manage script dependencies?
- How should configuration values be externalised from code?
- How would you prevent environment-specific identifiers from being hard-coded?
- What standards should apply to code reviews?
- How would you unit-test an the platform scripting language or Java component?
- How should integration and regression testing be organised?
- What makes a customisation upgrade-safe?
- How would you identify unused or duplicate custom code?
- How should custom components be versioned and deployed?
- How would you diagnose intermittent script failures?
- What controls should prevent unauthorised script execution?
- When should custom logic be moved outside ETRM?
6. APIs and Integration Architecture25
- What integration mechanisms are available around ETRM?
- How would you select among APIs, messaging, files and database extracts?
- What is OpenComponents, and when would you use it?
- How would you design synchronous trade-entry integration?
- When is asynchronous processing preferable?
- How would you implement idempotent trade ingestion?
- How should source-system and ETRM identifiers be mapped?
- How would you handle amendments arriving out of sequence?
- How should integration acknowledgements be designed?
- What retry strategy would you use for transient failures?
- How would you distinguish retryable and non-retryable errors?
- How should failed messages be quarantined and reprocessed?
- How would you prevent message replay from creating duplicate transactions?
- How should schemas and interface contracts be versioned?
- How would you maintain backward compatibility?
- What validation should occur before an inbound trade reaches ETRM?
- How would you publish transaction and lifecycle changes?
- Should ETRM expose business events or database-level changes?
- How would Kafka fit into an ETRM integration architecture?
- How would you trace a transaction across multiple systems?
- What reconciliation controls should accompany every material interface?
- How would you secure service-to-service communication?
- How should API throttling and workload protection be implemented?
- How would you test recovery after partial integration failure?
- What makes an interface operationally supportable?
7. Workflow and Process Orchestration15
- How are business workflows represented around ETRM?
- What is the distinction between workflow orchestration and business-rule execution?
- Which processes should be synchronous and which should be queued?
- How would you design an approval workflow?
- How should workflow state be persisted?
- How would you avoid tightly coupling unrelated business processes?
- What is the role of Transaction Processing Manager or equivalent orchestration capabilities?
- How would you design restartable workflow steps?
- How should timeouts and abandoned workflow instances be managed?
- How would you prevent the same event from triggering a process twice?
- How should manual exceptions rejoin automated processing?
- How would you monitor workflow throughput and ageing?
- What audit information should be retained for each transition?
- How should workflow configuration be tested?
- When should orchestration be implemented outside ETRM?
8. Batch, Scheduling and Grid Computing20
- How would you design the ETRM end-of-day architecture?
- What are the major dependencies within an end-of-day schedule?
- How should business dates and processing dates be controlled?
- How would you construct a restartable batch process?
- What checkpoints should exist within a long-running batch?
- How would you prevent duplicate output after a restart?
- What is the role of grid or distributed processing in ETRM?
- Which workloads are suitable for grid execution?
- How should portfolios and simulations be partitioned?
- What can cause uneven workload distribution?
- How would you determine the appropriate number of workers?
- Why might adding more workers fail to improve performance?
- How should compute capacity be allocated between intraday and end-of-day workloads?
- How would you manage dependencies among market data, valuation and reporting jobs?
- What should happen when only part of a risk run fails?
- How would you prove that all expected portfolios were processed?
- How should batch service-level objectives be monitored?
- How would you accommodate different regional cut-offs?
- How should daylight-saving changes be tested?
- What recovery strategy would you use after an extended infrastructure outage?
9. Reporting and Enterprise Data Architecture20
- What reporting workloads should remain within ETRM?
- When should data be extracted to an enterprise data platform?
- How would you protect ETRM from resource-intensive reporting?
- What is the difference between operational and analytical reporting?
- How would you design incremental data extraction?
- How should transaction amendments and deletions be represented downstream?
- How would you preserve historical trade states?
- How should valuation results be versioned?
- How would you model as-of and knowledge-time reporting?
- How would you reconcile a data lake or warehouse with ETRM?
- What control totals should accompany extracted datasets?
- How would you manage schema evolution?
- How should data lineage be captured?
- How would you protect sensitive trading and counterparty data?
- How would you prevent downstream reports from becoming unofficial books of record?
- What should happen when downstream data arrives late?
- How would you publish near-real-time positions?
- Which data is better distributed as events than snapshots?
- How should corrected historical data be communicated to consumers?
- How would you define ownership for ETRM-derived data products?
10. Performance and Capacity Engineering20
- How would you establish a performance baseline?
- Which metrics indicate ETRM platform health?
- How would you investigate slow client response?
- How would you distinguish client, network, service, database and script latency?
- What commonly causes slow simulations?
- How would you identify an inefficient custom script?
- How can excessive result measures affect performance?
- How would you analyse memory growth in a long-running process?
- What causes excessive database round trips?
- How should large datasets be processed efficiently?
- How would you conduct volume and stress testing?
- What transaction, market-data and result-volume assumptions are required?
- How would you model future capacity requirements?
- What are the risks of optimising without representative production data?
- How would you validate that an optimisation has not changed results?
- How should performance regressions be detected before release?
- How would you protect critical workloads during peak processing?
- What operational thresholds should generate alerts?
- How would you address gradually degrading performance?
- When is infrastructure scaling insufficient to solve a performance problem?
11. Security, Entitlements and Audit20
- How would you design role-based access in ETRM?
- How should permissions align with business responsibilities?
- How would you enforce segregation of duties?
- How should privileged administrative access be controlled?
- How would you manage service accounts?
- What is the appropriate approach to credential and secret management?
- How should portfolio and transaction visibility be restricted?
- How would you control access to custom scripts and reports?
- How should sensitive static-data changes be approved?
- What audit trail should exist for transaction amendments?
- How would you identify excessive or conflicting permissions?
- How should joiner, mover and leaver processes affect ETRM access?
- How would you conduct periodic access recertification?
- How should production support access be governed?
- What controls should apply to non-production copies of production data?
- How would you integrate ETRM with enterprise identity management?
- How should authentication failures and suspicious activity be monitored?
- How would you demonstrate compliance to an auditor?
- Which security controls belong inside ETRM and which belong in infrastructure?
- How should emergency-access activity be reviewed?
12. Infrastructure, High Availability and Disaster Recovery20
- How would you design a highly available ETRM environment?
- Which ETRM components require active-active or active-passive resilience?
- How should single points of failure be identified?
- What recovery-time and recovery-point objectives are appropriate?
- How should application and database recovery remain consistent?
- How would you design service failover?
- How should queued or in-flight work be handled during failover?
- How would you prevent duplicate processing after recovery?
- What infrastructure dependencies must be included in disaster recovery?
- How should DNS, certificates, secrets and external endpoints be recovered?
- How would you test disaster recovery without affecting production?
- What constitutes successful business-level recovery?
- How should storage performance and resilience be designed?
- How would you monitor infrastructure capacity?
- How should operating-system and middleware patching be managed?
- How would you minimise downtime during infrastructure maintenance?
- What additional considerations apply to virtualised infrastructure?
- How would network latency affect architecture choices?
- How should time synchronisation be controlled across components?
- What evidence should be retained from resilience testing?
13. Cloud and Deployment Architecture20
- What factors determine whether ETRM workloads are suitable for cloud hosting?
- How would you translate an on-premises ETRM architecture to cloud infrastructure?
- Which components can scale horizontally?
- Which components remain constrained by state or database dependencies?
- How would you design cloud network segmentation?
- How should private connectivity to exchanges, banks and market-data vendors be provided?
- How would you manage cloud identities and secrets?
- How should backups be protected across accounts or regions?
- What are the risks of treating ETRM as a cloud-native application?
- Where can containers be useful around ETRM?
- Why may containerising every ETRM component be inappropriate?
- How would you integrate ETRM with cloud-native messaging and analytics services?
- How should cloud consumption costs be controlled?
- How would you design non-production environments economically?
- How should production data be masked before cloud-based testing?
- What observability capabilities should be cloud-native?
- How would you manage availability-zone or regional failure?
- How would you validate vendor support for the proposed architecture?
- What architecture decisions would require a proof of concept?
- How would you avoid cloud-provider lock-in where it matters?
14. Environment and Configuration Management20
- What ETRM environments should an enterprise maintain?
- How should configuration move from development to production?
- How would you identify dependencies within a deployment package?
- How should database, configuration and code changes be coordinated?
- How would you prevent environment-specific values from entering shared packages?
- What version-control strategy should apply to scripts and configuration?
- How would you detect configuration drift?
- How should emergency production fixes be brought back into development?
- What evidence should accompany a release?
- How would you design automated deployment validation?
- Which ETRM changes require regression testing?
- How should reference data be promoted safely?
- How would you roll back a configuration deployment?
- What if rollback would invalidate newly created transactions?
- How should multiple project teams share an ETRM release train?
- How would you resolve conflicting configuration changes?
- What should a production-readiness review include?
- How should release cut-over and verification be organised?
- What post-deployment monitoring is required?
- When should a release be stopped?
15. Upgrade and Migration Architecture20
- How would you assess an ETRM version upgrade?
- Which customisations create the greatest upgrade risk?
- How would you establish an inventory of configuration and code?
- How should deprecated functions and APIs be identified?
- What regression scope is required for an upgrade?
- How would you compare valuations before and after an upgrade?
- Which differences may be legitimate?
- How would you validate event, settlement and accounting behaviour?
- How should performance be compared across versions?
- What is the role of parallel testing?
- How would you migrate active and historical transactions?
- How would you preserve transaction lineage and identifiers?
- How should open lifecycle events be migrated?
- How would you prevent duplicate confirmations, invoices or payments?
- What reconciliation controls should govern migration?
- How would you manage a phased desk migration?
- What determines whether coexistence is practical?
- How would you plan cut-over and rollback?
- How should business users participate in acceptance?
- What conditions should prevent go-live?
16. Monitoring and Production Support20
- What should an ETRM observability framework cover?
- Which application, service, database and business metrics should be monitored?
- How would you correlate logs across distributed components?
- How should correlation identifiers be propagated?
- What alerts require immediate escalation?
- How would you reduce false-positive alerts?
- How should incidents be classified by business impact?
- How would you diagnose an intermittent production issue?
- What evidence should be captured before restarting a failed service?
- When is a restart an unacceptable substitute for root-cause analysis?
- How would you manage recurring batch failures?
- How should known errors and operational workarounds be documented?
- What should a production-support runbook contain?
- How would you define Level 1, Level 2 and Level 3 support responsibilities?
- How should vendors be engaged during critical incidents?
- How would you perform root-cause analysis?
- How should corrective actions be tracked?
- What production metrics indicate architectural debt?
- How would you transition a new solution into support?
- How would you measure platform reliability?
17. Solution Architecture Scenarios20
- ETRM clients are slow, but database utilisation is normal. How would you investigate?
- A simulation succeeds for small portfolios but fails for the full desk. What would you examine?
- Increasing grid workers makes end-of-day slower. Why might this happen?
- An interface retries after timeout and creates duplicate trades. How would you redesign it?
- Trade updates arrive in the wrong order. How should ordering be enforced?
- A report directly querying ETRM causes production degradation. What should replace it?
- A service is running but has stopped consuming work. How should monitoring detect this?
- Test and production produce different valuations from identical trades. What should be compared?
- A reference-data change alters historical results. How would you restore reproducibility?
- A custom script consumes increasing memory throughout the day. How would you diagnose it?
- An end-of-day job fails after producing partial downstream output. How should I restart work?
- Disaster recovery restores the database but loses queued messages. What inconsistency can result?
- A cloud design assumes every ETRM component can autoscale. How would you challenge it?
- A team proposes direct database writes because the supported interface is slower. How would you respond?
- An upgrade breaks several undocumented scripts. What governance failure allowed this?
- Two projects require conflicting changes to the same configuration. How would you resolve them?
- A deployment succeeds technically but produces incorrect settlement events. What was missing?
- Production support frequently performs manual database corrections. What architectural action is required?
- Business users request zero downtime without funding resilience. How would you frame the decision?
- What distinguishes an ETRM Technical Solution Architect from an infrastructure engineer, developer or functional architect?
Data Model and Reference Data17 sections · 315 questions
1. ETRM Data-Model Fundamentals15
- How would you explain ETRM's logical data model to a non-technical stakeholder?
- What are the principal business-data domains within ETRM?
- How do transactional, reference, market and calculated data differ?
- What is the relationship between an instrument and a transaction?
- How do transactions, parameters, legs and profiles relate?
- How are financial cash flows and physical deliveries represented conceptually?
- How do lifecycle events relate to the originating transaction?
- What is the difference between stored, derived and simulation-result data?
- Which data should be treated as authoritative inside ETRM?
- Which data should remain mastered outside ETRM?
- How would you document ETRM entities and relationships?
- How would you trace a business field from the user interface to downstream output?
- Why is direct knowledge of physical database tables insufficient for solution architecture?
- What risks arise when external systems depend on ETRM's internal schema?
- How should business definitions be separated from physical implementation details?
2. Transaction Data Structure20
- What information is stored at the transaction level?
- What information belongs at the parameter or leg level?
- How are repeating delivery or pricing periods represented?
- How do header-level attributes differ from leg-level attributes?
- How would you model a transaction containing multiple commodities or currencies?
- How are buy/sell direction and payer/receiver direction represented?
- How does transaction status affect downstream processing?
- How are trade date, start date, maturity date and payment dates related?
- How should external execution identifiers be stored?
- How would you establish parent-child relationships among transactions?
- How should block trades and allocated transactions be linked?
- How would you represent amendments and transaction versions?
- How should cancellations and terminations remain historically traceable?
- How would you model novations and partial unwinds?
- What data is required to reproduce a transaction as of an earlier date?
- How would you identify economically equivalent but technically different transactions?
- What causes duplicate transactions, and how should they be prevented?
- How should transaction-level custom attributes be governed?
- When should information be represented as reference data rather than a transaction field?
- How would you avoid overloading generic fields with unrelated business meanings?
3. Instruments and Product Definitions15
- What does an ETRM instrument definition control?
- How do instrument definitions influence data capture and event generation?
- How would you determine whether an existing instrument supports a new product?
- What data-model risks arise from using the wrong instrument?
- How should product taxonomy differ from technical instrument taxonomy?
- How would you model physical and financial variants of the same commodity?
- How should fixed, floating and optional components be represented?
- How would you model a structured transaction containing multiple legs?
- What determines whether components belong in one transaction or linked transactions?
- How should product definitions be aligned with accounting treatment?
- How do product definitions affect risk-factor mapping?
- How should products be restricted by portfolio or business unit?
- How would you maintain product-definition ownership?
- What regression testing is required after changing an instrument configuration?
- How would you retire an obsolete product without affecting historical trades?
4. Parties, Legal Entities and Business Units20
- How does ETRM distinguish legal entities, counterparties and internal business units?
- What is the difference between a counterparty and a settlement entity?
- How should parent, subsidiary and credit-group relationships be represented?
- How would you model branches and booking entities?
- How should internal and external parties be distinguished?
- Which attributes are required to onboard a counterparty?
- How should counterparty status and eligibility be governed?
- How would you represent multiple trading agreements for one counterparty?
- How should agreement applicability be determined?
- How would you model guarantors and guarantee beneficiaries?
- How should credit-rating and classification data be maintained?
- How would you represent regulatory classifications?
- How should tax identifiers and jurisdictions be managed?
- What happens when two records represent the same legal entity?
- How would you identify and resolve duplicate counterparties?
- What controls should govern counterparty mergers or legal-name changes?
- How should historical transactions behave after a party hierarchy changes?
- How would you integrate ETRM with an enterprise party master?
- Which party attributes should ETRM consume, enrich or own?
- How would you reconcile party data across ETRM, CRM, credit and payment systems?
5. Organisational, Portfolio and Strategy Data20
- What is the purpose of an ETRM portfolio?
- How do portfolios, books, desks and strategies differ?
- How should portfolios align with legal ownership?
- How would you design a portfolio hierarchy for a global commodity business?
- How should trader and portfolio assignments be maintained?
- How do portfolio structures affect risk aggregation?
- How do they affect accounting and reporting?
- How should internal portfolios be distinguished from external-facing books?
- How would you represent hedging and commercial portfolios?
- How should dormant portfolios be retired?
- What risks arise from moving trades between portfolios?
- How should historical reporting treat portfolio transfers?
- How would you control the creation of new portfolios?
- How should organisational restructures be reflected?
- What data should drive desk and business-unit reporting?
- How would you avoid using free-text strategies as uncontrolled classifications?
- How should strategy hierarchies be versioned?
- How would you manage shared portfolios across regions?
- What controls prevent bookings into unauthorised portfolios?
- How would you reconcile ETRM's organisation hierarchy with enterprise finance hierarchies?
6. Commodity, Location and Product Reference Data20
- How would you design a commodity hierarchy?
- How should commodity, grade, quality and specification differ?
- How would you represent crude-oil grades?
- How should natural-gas hubs and delivery points be modelled?
- How would you represent power zones, nodes and interconnectors?
- How should LNG loading and discharge locations be maintained?
- How would you model emissions products by scheme and vintage?
- How should renewable certificates be classified?
- How would you represent metal brands, grades and warehouses?
- How should agricultural origin and quality attributes be modelled?
- What is the difference between a physical location and a pricing location?
- How should location hierarchies support aggregation?
- How would you represent transportation routes?
- How should storage facilities and inventory locations be maintained?
- What happens when a market location is renamed or retired?
- How should quality adjustments reference master data?
- How would you prevent commodity classifications from diverging across systems?
- Which attributes should form a commodity master record?
- How should new commodity products be approved?
- How would you migrate commodity and location data from a legacy ETRM?
7. Units of Measure and Conversions20
- Why are units of measure architecturally important in ETRM?
- How should volume, mass, energy and currency units be distinguished?
- What is the difference between static and context-dependent conversion?
- How would you convert barrels to metric tonnes?
- Why can density make oil conversions transaction-specific?
- How would you convert gas volume into energy?
- How do calorific value and standard conditions affect gas conversion?
- How should power quantities and rates be represented?
- How would you manage currency-per-unit price conventions?
- What is the difference between quantity, price and exposure units?
- How should trading, scheduling, risk and settlement units coexist?
- How would you avoid repeated or inconsistent conversions?
- How should conversion-factor sources be governed?
- How should effective dates apply to conversion factors?
- What rounding conventions should be controlled?
- How would you identify a unit mismatch causing incorrect valuation?
- How should converted values remain traceable to original quantities?
- How would you test unit conversions across products?
- What controls prevent users from selecting incompatible units?
- How should unit mappings be reconciled with external systems?
8. Calendars, Dates and Time Zones20
- What types of calendars are required in ETRM?
- How do trading, publication, delivery and payment calendars differ?
- How should business-day conventions be maintained?
- What is the difference between following, modified-following and preceding conventions?
- How should holidays affect pricing observations?
- How should holidays affect settlement dates?
- How would you manage regional calendar differences?
- What risks arise from changing an existing holiday calendar?
- How should calendar versions and effective dates be governed?
- How would you model gas days crossing calendar dates?
- How should power delivery intervals be represented?
- How would you handle 23-hour and 25-hour daylight-saving days?
- Why should timestamps include timezone context?
- How would you standardise timestamps across integrated platforms?
- How should publication time and fixing date differ?
- How would you represent valuation cut-off timestamps?
- What can cause apparent one-day differences across systems?
- How would you test leap years and month-end boundaries?
- How should historical results behave after a calendar correction?
- What controls should govern emergency calendar changes?
9. Market and Index Reference Data20
- What is an index definition in ETRM?
- Which attributes should an index contain?
- How do price source, index, fixing and curve differ?
- How would you represent exchange contracts and contract months?
- How should quotation units and currencies be maintained?
- How would you model index publication calendars?
- How should preliminary and final index values be distinguished?
- How would you handle corrected historical fixings?
- What is the relationship between an index and a forward curve?
- How should multiple vendors supplying the same index be represented?
- How would you design source-priority and fallback rules?
- How should proprietary and composite indexes be governed?
- How would you model an index formula using several components?
- How should discontinued indexes be replaced?
- What happens to historical transactions after an index is retired?
- How would you identify trades affected by an incorrect fixing?
- How should market-data identifiers map across vendors?
- What controls prevent values from being loaded against the wrong index?
- How would you manage timezone and publication-time differences?
- How should index-reference changes be regression-tested?
10. Settlement, Payment and Agreement Data20
- Which reference data drives settlement processing?
- How should standard settlement instructions be represented?
- How should instructions vary by legal entity, counterparty, currency and product?
- Why must bank-account data have stronger controls?
- How should settlement instructions be effective-dated?
- How would you manage temporary or one-time instructions?
- What should happen when multiple instructions are eligible?
- How should payment methods and message formats be maintained?
- How would you represent intermediary and correspondent banks?
- How should settlement netting agreements be modelled?
- What determines whether two cash flows can be netted?
- How should tax and invoice classifications be maintained?
- How would you model confirmation and invoice-document templates?
- How should collateral agreements connect to counterparties?
- How would you represent thresholds and minimum transfer amounts?
- How should agreement amendments affect existing transactions?
- How would you reconcile agreement data with legal-document systems?
- What controls prevent expired agreements from being applied?
- How would you test settlement-data changes safely?
- How should sensitive payment data be masked outside production?
11. Accounting Reference Data15
- Which reference-data domains drive accounting?
- How should account mappings be designed?
- How do product, portfolio, legal entity and event type influence accounting?
- How should accounting-event definitions be governed?
- How would you represent cost centres, profit centres and business dimensions?
- How should multiple ledgers or accounting standards be supported?
- How would you maintain effective-dated general-ledger mappings?
- What happens when an account mapping changes retrospectively?
- How should intercompany mappings be managed?
- How would you prevent incomplete accounting dimensions?
- How should accounting rules reference transaction attributes?
- What are the risks of embedding account numbers in custom scripts?
- How would you reconcile ETRM dimensions with the enterprise chart of accounts?
- How should new products be assessed for accounting-data requirements?
- How would you test that reference-data changes produce balanced postings?
12. User-Defined Fields and Extensibility15
- When should a user-defined field be introduced?
- What alternatives should be considered before creating one?
- How should field names and business definitions be governed?
- Which data type and validation rules should be selected?
- How should mandatory fields vary by product or lifecycle status?
- What risks arise from excessive custom fields?
- How would you prevent several fields representing the same concept?
- How should custom fields be exposed to integrations?
- How should they be included in reporting and lineage?
- How would you backfill a new field for existing transactions?
- How should field defaults be controlled?
- What happens when the meaning of a field changes?
- How would you retire an unused custom field?
- How should sensitive custom attributes be protected?
- What documentation and ownership should every custom field have?
13. Data Quality and Governance20
- What constitutes high-quality ETRM reference data?
- Which dimensions of data quality are most important?
- How would you define critical data elements?
- Who should own counterparty, commodity and market reference data?
- How do data owner and data steward responsibilities differ?
- How should data-quality rules be implemented?
- Which rules should block processing?
- How should non-blocking exceptions be managed?
- How would you establish data-quality thresholds?
- What should a reference-data control dashboard display?
- How should duplicate records be detected?
- How would you manage data-quality issue remediation?
- How should root causes be separated from symptoms?
- How would you measure the downstream impact of poor reference data?
- What is the role of data lineage in ETRM governance?
- How should business definitions be maintained?
- How would you manage conflicting definitions across functions?
- How should emergency data corrections be governed?
- What evidence should support periodic control review?
- How would you demonstrate regulatory compliance for critical data?
14. Integration and Synchronisation20
- How should reference data enter ETRM?
- When should synchronisation be real-time or batch-based?
- How would you implement idempotent reference-data ingestion?
- How should enterprise and ETRM identifiers be mapped?
- What happens when dependent records arrive out of sequence?
- How would you manage partial synchronisation failure?
- How should records rejected by ETRM be handled?
- What reconciliation controls should accompany reference-data interfaces?
- How would you distribute ETRM-owned data downstream?
- How should change events differ from full snapshots?
- How would you handle deleted, merged or retired records?
- How should effective dates be preserved across systems?
- How would you prevent update loops between two authoritative systems?
- What should happen when source and target disagree?
- How should interface schemas be versioned?
- How would you protect personally identifiable and payment information?
- How should data lineage span integration boundaries?
- How would you monitor synchronisation latency?
- How should reference-data cutovers be coordinated?
- What makes a reference-data interface operationally supportable?
15. Migration and Reconciliation20
- How would you profile legacy data before an ETRM migration?
- How should source-to-target mappings be documented?
- How would you identify missing reference-data dependencies?
- What is the difference between cleansing, standardisation and enrichment?
- How should duplicate parties and products be resolved?
- How would you preserve legacy identifiers?
- How should historical and active transactions be treated differently?
- How would you sequence reference and transaction-data migration?
- What happens when source values have no valid ETRM equivalent?
- How should default values be governed?
- How would you validate migrated transaction economics?
- What control totals should be reconciled?
- How would you compare positions, cash flows, P&L and events?
- How should rejected records be tracked and resolved?
- How would you perform iterative migration rehearsals?
- What determines whether a migration defect blocks go-live?
- How should delta migration be managed near cut-over?
- How would you prevent duplicate downstream events after migration?
- What evidence should support migration sign-off?
- How should legacy data remain accessible after decommissioning?
16. Performance, Retention and Archiving15
- How can poor data modelling affect ETRM performance?
- What risks arise from uncontrolled transaction-level attributes?
- How can large profiles affect valuation and reporting?
- How would you identify rapidly growing data domains?
- Which data should be retained online?
- How should archival requirements be defined?
- How would you archive data without breaking auditability?
- How should archived transactions remain searchable?
- What legal or regulatory requirements affect retention?
- How should simulation results be retained?
- When should results be recalculated rather than stored?
- How would you prevent analytical workloads from overloading ETRM?
- What role should an enterprise data platform play?
- How should deletion and anonymisation requirements be handled?
- How would you test data archival and restoration?
17. Architecture Scenarios20
- A trade values correctly but appears under the wrong desk. What would you inspect?
- Two counterparties represent the same legal entity. How would you remediate them?
- A unit conversion causes a thousandfold exposure difference. How would you isolate it?
- A calendar change alters historical settlement dates. How should it be handled?
- A transaction uses a retired index. What remediation options exist?
- A portfolio restructure changes historical P&L reporting. How would you preserve both views?
- A settlement instruction is valid but selects the wrong bank account. What could cause this?
- An upstream party master merges counterparties that ETRM must keep distinct. How would you respond?
- A new custom field duplicates an existing reference-data concept. Would you approve it?
- An integration sends reference data after dependent transactions. How should processing recover?
- Test and production contain different reference-data identifiers. How would you manage deployment?
- A fixing was loaded against the wrong index and used for invoicing. What remediation is required?
- Historical valuation changes after a unit-conversion update. What design weakness does this expose?
- Direct database reporting breaks after an upgrade. What architectural mistake was made?
- Several systems claim ownership of commodity reference data. How would you establish authority?
- A transaction migration balances by count but not by exposure. What should be reconciled next?
- A user requests direct database correction of a counterparty record. How would you respond?
- Data-quality controls generate thousands of unresolved warnings. How would you redesign them?
- A physical location and pricing location were treated as the same concept. What problems can result?
- What distinguishes an ETRM data architect from a database administrator or data modeller?
Integration Architecture and APIs17 sections · 340 questions
1. Integration Architecture Fundamentals20
- What are the major integration patterns used around ETRM?
- How would you define ETRM's integration boundaries?
- Which capabilities should remain inside ETRM?
- Which capabilities should be provided by external platforms?
- How do synchronous, asynchronous, batch and streaming integrations differ?
- When is request-response integration appropriate?
- When should a durable queue be preferred?
- When is file-based integration still appropriate?
- Why should direct database integration generally be avoided?
- How would you assess an existing ETRM integration landscape?
- What belongs in an integration architecture document?
- How would you create a system-context diagram?
- What makes an integration business-critical?
- How should integration ownership be divided between teams?
- How would you prevent point-to-point integration sprawl?
- What factors determine an interface's delivery pattern?
- How should business and technical contracts be separated?
- What non-functional requirements should be agreed before design?
- How would you calculate interface capacity requirements?
- What distinguishes connectivity from complete business integration?
2. ETRM Integration Mechanisms20
- What supported integration mechanisms are available for ETRM?
- What is OpenComponents, and where is it appropriate?
- How does an API-based integration differ from an the platform scripting language process?
- When should ETRM scripting participate in integration?
- When should integration logic remain in middleware?
- What are the risks of embedding orchestration in scripts?
- When can controlled file exchange be preferable to an API?
- How should ETRM-generated reports participate in outbound interfaces?
- What is the role of workflow or transaction-processing capabilities?
- How would you evaluate a vendor-supplied connector?
- How do ETRM-version dependencies affect API consumers?
- How would you avoid coupling consumers to ETRM's internal objects?
- How should supported and unsupported interfaces be distinguished?
- What governance is required before introducing a new connector?
- How would you select the correct mechanism for high-volume trade ingestion?
- Which mechanism would you choose for low-latency position retrieval?
- How would you publish settlement events reliably?
- How should bulk reference-data loads be handled?
- When is database extraction acceptable for analytics?
- How would you prove that an integration is upgrade-safe?
3. API Design25
- How would you design an API for trade creation?
- Which fields should be mandatory in a trade API?
- Should the API expose ETRM's internal transaction structure directly?
- How would you design a canonical trade model?
- How should product-specific fields be represented?
- How would you handle optional and conditionally mandatory fields?
- What is the difference between technical and business validation?
- Which validation belongs at the API gateway?
- Which validation belongs within ETRM?
- How should validation errors be returned?
- How would you design an API for trade amendment?
- Should amendments use complete replacement or patch semantics?
- How should cancellations and terminations be represented?
- How would you retrieve current transaction status?
- How should API pagination be designed?
- How would you support large result sets?
- How should filtering and sorting be constrained?
- How would you prevent APIs from creating expensive database workloads?
- What information should a response envelope contain?
- How should correlation and request identifiers be represented?
- How would you version an API?
- When is a breaking version necessary?
- How should deprecated versions be retired?
- How would you maintain backward compatibility?
- What makes an API operationally supportable?
4. Canonical Data Models and Mapping20
- What is a canonical data model?
- When does a canonical model reduce integration complexity?
- When can it become an unnecessary abstraction?
- How would you map external products to ETRM instruments?
- How should counterparties and legal entities be mapped?
- How would you map books, portfolios, traders and strategies?
- How should units, currencies, indexes and locations be mapped?
- Where should cross-reference mappings be stored?
- How should mappings be effective-dated?
- What happens when one source value maps to several ETRM values?
- How would you manage unmapped values?
- Should interfaces silently apply default values?
- How would you represent multi-leg transactions?
- How should daily or hourly profiles be transmitted?
- How would you represent provisional pricing?
- How should lifecycle relationships be preserved?
- How would you map parent, child and allocation transactions?
- How should source-system identifiers survive migration?
- What controls should validate mapping completeness?
- How would you prevent different interfaces from implementing inconsistent mappings?
5. Synchronous Integration15
- When should an ETRM interface be synchronous?
- What response time should a synchronous trade API provide?
- How should timeouts be selected?
- What does a timeout mean when ETRM may have completed processing?
- How would you resolve an indeterminate transaction outcome?
- Why is blindly retrying a timed-out create request dangerous?
- How should idempotency work for synchronous requests?
- Where should idempotency keys be stored?
- How long should an idempotency record remain valid?
- How would you prevent duplicate execution across service instances?
- What happens when ETRM is temporarily unavailable?
- How should connection pools be configured?
- How would you apply throttling and back-pressure?
- How should synchronous dependencies be limited?
- When should a synchronous request be converted into an asynchronous job?
6. Messaging and Event-Driven Integration25
- When should messaging be used around ETRM?
- What is the difference between a command, event and notification?
- Should a trade-capture message be treated as a command or event?
- How would you design a durable trade-ingestion queue?
- What delivery semantics can messaging platforms provide?
- Why does “exactly once” require business-level design?
- How would you achieve effectively-once processing?
- How should message keys be selected?
- How would you preserve ordering for a transaction?
- Is global message ordering necessary?
- How would you process unrelated transactions concurrently?
- What happens when an amendment arrives before the original trade?
- How should delayed or out-of-order events be managed?
- What is a dead-letter queue?
- What information should a dead-letter record contain?
- How should dead-letter messages be reprocessed?
- How would you prevent replay from creating duplicate actions?
- How should message retention be determined?
- What is consumer lag, and why does it matter?
- How should message schemas evolve?
- How would Kafka fit into an ETRM architecture?
- When might a conventional message queue be preferable to Kafka?
- How would you handle poison messages?
- How should event consumers indicate processing success?
- What reconciliation remains necessary despite reliable messaging?
7. Trade Capture Integration20
- How would you integrate an execution platform with ETRM?
- Which system should assign the authoritative execution identifier?
- How should ETRM deal numbers be returned to the source?
- How would you handle block trades and allocations?
- What happens when allocation arrives after the block?
- How should partial allocations be handled?
- How would you process corrected or busted exchange trades?
- How should execution versions be represented?
- How would you detect duplicate executions?
- Which fields should be compared for duplicate detection?
- How should trade economics be validated before booking?
- How would you manage product mappings?
- What happens when required reference data is unavailable?
- Should invalid trades be rejected or quarantined?
- How should quarantined trades be corrected?
- How would you preserve the original message?
- How should manual intervention be audited?
- How would you prove that every execution reached ETRM?
- How should execution and ETRM status differences be reconciled?
- How would you design cut-off handling for late trades?
8. Market and Reference-Data Integration20
- How would you integrate market-data vendors with ETRM?
- How should real-time and end-of-day data flows differ?
- How would you validate incoming prices and rates?
- How should stale or missing data be detected?
- How would you manage multiple sources for the same index?
- How should source priority and fallback operate?
- How would you ingest corrected fixings?
- How should the original fixing remain traceable?
- What happens when a correction arrives after settlement?
- How would you prevent data being loaded against the wrong index?
- How should price units and currencies be validated?
- How would you integrate an enterprise party master?
- How should merged or retired counterparties be handled?
- How would you synchronise product and location master data?
- What happens when a dependent transaction arrives before reference data?
- How would you avoid update loops between master systems?
- How should effective dates be transmitted?
- How would you reconcile reference data?
- What service levels should apply to critical market data?
- How should licensing restrictions affect data distribution?
9. Outbound Events and Data Distribution20
- Which ETRM changes should generate outbound events?
- Should consumers receive transaction snapshots or change events?
- What are the advantages of a transactional outbox pattern?
- How would you ensure that a committed ETRM change is published?
- What happens if database processing succeeds but event publication fails?
- How should transaction amendments be represented?
- How should cancellations and reversals be published?
- What event should represent a status transition?
- How would you preserve event ordering?
- How should event identifiers be generated?
- How would consumers detect duplicates?
- How should consumers recover missing events?
- When should a complete snapshot be republished?
- How would you support event replay?
- How should replayed events be distinguished from new business activity?
- How would you prevent sensitive fields from leaving ETRM?
- How should consumers be authorised by data domain?
- How would you publish positions and P&L?
- Should calculated results be events, snapshots or query responses?
- How would you communicate corrected historical results?
10. Settlement, Payment and Accounting Interfaces20
- How would you publish settlement instructions from ETRM?
- What controls should surround payment-file generation?
- How would you prevent duplicate payment instructions?
- Which system should own payment status?
- How should bank acknowledgements return to ETRM?
- How would you process rejected payments?
- How should payment cancellation and recall be represented?
- How would you reconcile ETRM with a treasury platform?
- How would invoices be transmitted to an external billing system?
- How should invoice corrections and credit notes be communicated?
- How would you integrate ETRM accounting with a general ledger?
- What information should accompany an accounting posting?
- How should rejected journal entries be handled?
- How would you prevent duplicate general-ledger postings?
- How should accounting periods and cut-offs be aligned?
- How would you reconcile the ETRM subledger with the general ledger?
- What control totals should accompany accounting interfaces?
- How should partial interface completion be handled?
- How would you restart processing without duplicating outputs?
- What evidence is required for financial-control sign-off?
11. File-Based and Batch Integration20
- When is file-based integration appropriate?
- What controls should accompany every file?
- How should file names and business dates be defined?
- How would you detect missing files?
- How should duplicate files be detected?
- What are control totals and hash totals?
- How would you validate file completeness?
- How should partial files be prevented from processing?
- What is an atomic file-delivery pattern?
- How should encryption and signing be applied?
- How would you manage large files?
- What happens when individual records fail?
- Should valid records proceed when some records fail?
- How should rejected records be returned?
- How would you restart a failed batch?
- How should file retention be governed?
- How would you handle reruns for an earlier business date?
- How should time zones and cut-offs be managed?
- How would you reconcile file processing end-to-end?
- When should a file interface be replaced with an API or event stream?
12. Security and API Management20
- How would you authenticate systems calling ETRM APIs?
- How does authentication differ from authorisation?
- When should mutual TLS be used?
- How should service identities be managed?
- Where should API credentials and secrets be stored?
- How should credentials be rotated?
- What data should never appear in logs?
- How would you protect bank-account and counterparty data?
- How should API scopes be designed?
- How would you enforce least privilege?
- What is the role of an API gateway?
- How should rate limits be established?
- How would you protect ETRM from denial-of-service conditions?
- How should inbound payloads be validated?
- How would you prevent injection and deserialisation attacks?
- How should certificates be monitored for expiry?
- How would you audit API access?
- How should non-production interfaces handle production data?
- What controls should apply to privileged support access?
- How would you respond to a compromised service credential?
13. Error Handling, Recovery and Reconciliation20
- What error categories should an interface define?
- How do business, validation, technical and dependency errors differ?
- Which failures are safe to retry?
- How should exponential back-off be applied?
- When should retry attempts stop?
- What is a retry storm?
- How would circuit breakers protect ETRM?
- How should failed requests be quarantined?
- What information is necessary for investigation?
- How should operational users correct errors?
- How would corrected records re-enter processing?
- How should manual changes be audited?
- What is end-to-end reconciliation?
- Why are transport acknowledgements insufficient?
- How would you reconcile counts, quantities, amounts and statuses?
- How should reconciliation breaks be assigned and aged?
- How would you detect silent data loss?
- How should a recovered interface process accumulated backlog?
- How would you prioritise messages after an outage?
- How would you prove that recovery caused no duplication or omission?
14. Performance, Scalability and Availability20
- How would you estimate interface throughput?
- Which volume characteristics matter beyond average transactions per second?
- How would you test peak-volume behaviour?
- How should large profiles and structured trades affect sizing?
- How would you prevent integration workloads from degrading ETRM?
- What is back-pressure?
- How should queues absorb traffic spikes?
- When should consumers scale horizontally?
- What can limit horizontal scaling?
- How would transaction ordering affect concurrency?
- How should connection pooling be configured?
- What causes excessive API latency?
- How would you isolate network, middleware, ETRM and database latency?
- How should service-level indicators be defined?
- What availability level should a critical interface provide?
- How would you design interface failover?
- What happens to in-flight requests during failover?
- How would disaster recovery preserve message consistency?
- How should recovery-point objectives apply to integrations?
- How would you test interface resilience?
15. Monitoring and Observability15
- What should an integration-monitoring dashboard display?
- Which technical and business metrics should be monitored?
- How should correlation identifiers be propagated?
- How would you trace a trade across execution, middleware and ETRM?
- What logs should be generated at each stage?
- How should logs avoid exposing sensitive data?
- What is distributed tracing?
- How could tracing help with ETRM integrations?
- How would you detect a consumer that is alive but not processing?
- What thresholds should trigger alerts?
- How would you reduce false-positive alerts?
- How should business cut-off breaches be detected?
- What data should support service-level reporting?
- How would you distinguish backlog from processing failure?
- How should support teams access replay and reconciliation tools?
16. Testing and Release Management20
- What should an ETRM integration test strategy cover?
- How do unit, component, contract and end-to-end tests differ?
- What is consumer-driven contract testing?
- How would you test API compatibility?
- How should external dependencies be mocked?
- When is a production-like environment necessary?
- How would you create representative test data?
- How would you test duplicates and message reordering?
- How would you test timeouts and indeterminate outcomes?
- How should retry and dead-letter processing be tested?
- How would you test partial batch failure?
- How should failover and disaster recovery be tested?
- How would you conduct volume and soak testing?
- How should reconciliations be tested?
- What evidence is required before production release?
- How should interface configuration move between environments?
- How would you detect configuration drift?
- How should breaking changes be coordinated with consumers?
- What rollback options exist after messages have been processed?
- What conditions should prevent an integration release?
17. Integration Architecture Scenarios20
- An API times out, but ETRM creates the trade. How should the caller recover?
- A retry creates a duplicate transaction. What architectural control was missing?
- Amendments arrive before original trades. How would you redesign processing?
- Kafka reports successful delivery, but ETRM contains no trade. What should be reconciled?
- ETRM commits a transaction but fails to publish its outbound event. How would you recover?
- A reference-data message arrives after the dependent trade. What should happen?
- An upstream system reuses an execution identifier. How would you handle it?
- A queue backlog threatens the trading cut-off. How would you prioritise recovery?
- An interface works in testing but overloads production. What assumptions likely failed?
- A direct database extract breaks after an legacy-to-modern ETRM upgrade. What design flaw does this expose?
- An external system requires ETRM internal field names in its contract. Would you approve this?
- Two consumers require incompatible versions of the same event. How would you support them?
- A payment interface replay creates duplicate bank instructions. How would you prevent this?
- Middleware modifies trade economics without retaining the original message. What risks arise?
- A market-data vendor republishes corrected history. How should corrections enter ETRM?
- Interface counts reconcile, but commodity quantities do not. What should be investigated?
- A service account can create trades in every portfolio. What control weakness exists?
- Operations repeatedly edits failed messages directly in the queue. How would you improve control?
- The business demands exactly-once processing. How would you translate that requirement?
- What distinguishes an ETRM Integration Architect from an API developer or middleware specialist?
Extensibility with Custom Code19 sections · 375 questions
1. Extensibility Strategy20
- When should standard ETRM functionality be used without customisation?
- When is configuration preferable to code?
- When is the platform scripting language appropriate?
- When is Java preferable to the platform scripting language?
- When should functionality be implemented outside ETRM?
- How would you evaluate a custom-development request?
- What questions should be answered before approving an extension?
- How would you calculate the lifecycle cost of customisation?
- What makes an extension upgrade-sensitive?
- How would you prevent ETRM becoming a bespoke application?
- What is the difference between extension and modification?
- Why should supported APIs be preferred?
- How would you identify customisations duplicating standard functionality?
- What architecture principles should govern extensions?
- How would you document an extensibility decision?
- What belongs in an architecture decision record?
- How should business criticality influence implementation choice?
- When is a tactical script acceptable?
- How should tactical components be retired?
- What would make you reject a customisation request?
2. the platform scripting language Fundamentals20
- What is the platform scripting language?
- What types of ETRM processes commonly use the platform scripting language?
- How does an the platform scripting language script execute within the ETRM environment?
- What is the conventional entry point of an the platform scripting language script?
- What role does `com.olf.openjvs` play?
- How are ETRM objects accessed from the platform scripting language?
- How does the platform scripting language differ from general-purpose Java development?
- What limitations should an architect understand?
- How should the platform scripting language scripts be classified by purpose?
- Which scripts should run interactively?
- Which scripts should run as background services?
- Which scripts are suitable for scheduled processing?
- How does execution context affect script behaviour?
- How should user and service-account context be handled?
- How can a script obtain runtime parameters?
- How should a script return execution status?
- What should happen when required parameters are missing?
- How do API-version differences affect scripts?
- How would you assess an unfamiliar the platform scripting language codebase?
- What signs indicate poor the platform scripting language design?
3. the platform scripting language Table Handling20
- What is the platform scripting language `Table` object?
- Why is `Table` central to many the platform scripting language solutions?
- How do ETRM tables differ from Java collections?
- How should columns and rows be defined?
- How would you populate a table efficiently?
- What risks arise from repeated row insertion?
- How would you access values safely?
- How should null, empty and invalid values be distinguished?
- How would you join or aggregate tables?
- When should table operations be performed in memory?
- When should processing be pushed to the database?
- How would you copy or clone a table?
- What risks arise from unintended table references?
- How should temporary tables be managed?
- Why must table objects be destroyed?
- What happens when tables are not destroyed?
- How would you guarantee cleanup after an exception?
- How should very large result sets be processed?
- How would you avoid excessive table copying?
- How would you diagnose table-related memory growth?
4. Transactions and Deal Processing20
- How does the platform scripting language access an ETRM transaction?
- How would you retrieve a transaction safely?
- How should new transactions be created?
- What validation should occur before saving a transaction?
- How would you distinguish business validation from technical validation?
- How should transaction status transitions be controlled?
- What risks arise from scripts changing validated transactions?
- How would you process trade amendments?
- How should cancellations, terminations and novations be handled?
- How would you preserve external identifiers?
- How should duplicate trade creation be prevented?
- How would you design idempotent transaction processing?
- How should parent-child trade relationships be maintained?
- How would you process multi-leg transactions?
- How should transaction profiles be populated?
- How would you manage unit, currency and index mappings?
- What happens when required reference data is unavailable?
- How should partial bulk-processing failure be handled?
- When should one invalid trade prevent the entire batch?
- How would you reconcile script-created trades with source records?
5. Query and Database Access20
- How should the platform scripting language retrieve data from the ETRM database?
- What is the role of supported query APIs?
- Why are direct database writes prohibited?
- What risks arise from direct table updates?
- When can controlled database reads be acceptable?
- How would you parameterise database queries?
- How would you prevent SQL injection?
- Why should dynamic SQL be minimised?
- How would you avoid retrieving unnecessary columns?
- How would you process large database result sets?
- What is the impact of repeated database calls inside loops?
- How would you replace row-by-row queries?
- How should database transactions be handled?
- How would you avoid long-running locks?
- How should user tables be used?
- When is a user table preferable to a configuration file?
- How should user-table schemas be governed?
- How would you migrate user-table changes?
- What risks arise when custom tables imitate core ETRM data?
- How would you diagnose a script causing database contention?
6. Error and Exception Handling20
- What exception types should an the platform scripting language solution anticipate?
- How should `OException` be handled?
- Should scripts catch every exception?
- When should an exception be rethrown?
- How should business exceptions differ from technical failures?
- How would you define recoverable and unrecoverable errors?
- What should a script do after partial processing?
- How would you guarantee resource cleanup?
- How should contextual information be added to errors?
- What information should never appear in error messages?
- How would you prevent exception handling from hiding failures?
- Should a script continue after one record fails?
- How should rejected records be quarantined?
- How would operational users correct and replay failures?
- How should retry logic be designed?
- When can retrying be dangerous?
- How would you prevent retry storms?
- How should fatal errors affect batch status?
- What evidence should be retained after failure?
- How would you test exception paths?
7. Logging and Observability20
- What should an the platform scripting language logging standard contain?
- Which logging levels should be supported?
- What belongs in informational versus debug logging?
- How would you avoid excessive production logging?
- How should correlation identifiers be used?
- How would you trace one trade through several scripts?
- What transaction and batch identifiers should be logged?
- How should sensitive data be masked?
- Why should passwords, tokens and bank details never be logged?
- How would you record processing counts and control totals?
- What execution-duration metrics should be captured?
- How would you identify the slowest processing stage?
- How should script health be monitored?
- How would you detect a script that is running but making no progress?
- What alerts should a business-critical script generate?
- How should log retention be governed?
- How would production support access diagnostic information?
- How should logging differ between development and production?
- How would you correlate application and middleware logs?
- What observability requirements belong in the original design?
8. Java Extensibility20
- When should compiled Java be selected over the platform scripting language?
- What benefits does Java provide for larger components?
- What additional risks accompany compiled extensions?
- How should a Java extension interact with supported ETRM APIs?
- How would you structure a Java codebase?
- How should domain, application and infrastructure logic be separated?
- How would you manage third-party libraries?
- What risks arise from dependency conflicts?
- How should class-loading constraints influence design?
- How would you prevent library-version collisions?
- How should configuration be externalised?
- How would you manage environment-specific values?
- How should thread safety be handled?
- Can every ETRM API object be safely shared across threads?
- What risks arise from unmanaged multithreading?
- How would you manage connection pools?
- How should long-running Java services manage memory?
- How would you diagnose garbage-collection pressure?
- How should Java components expose operational health?
- What makes a Java component supportable by an ETRM operations team?
9. Plug-ins, Hooks and Workflow Extensions20
- What extension points can invoke custom logic?
- When should logic run during trade capture?
- What validation is appropriate before trade save?
- What logic should not run synchronously in the user session?
- How would a slow validation affect trader experience?
- How should post-trade processing be triggered?
- How would you prevent the same event invoking logic twice?
- How should hooks behave when dependent services are unavailable?
- What risks arise from placing external calls inside transaction processing?
- How would you decouple long-running processing?
- How should workflow extensions preserve state?
- How would you design restartable steps?
- How should manual exceptions rejoin automated workflows?
- How would you prevent recursion or repeated event triggering?
- How should workflow timeouts be managed?
- What auditing should surround approval logic?
- How would you test extensions invoked by lifecycle events?
- How should extension execution order be governed?
- How would you identify conflicting hooks?
- When should orchestration be moved to an external workflow platform?
10. Report and Simulation Extensions20
- How would the platform scripting language support custom reporting?
- When should a report use standard result measures?
- When is a custom result calculation justified?
- How should custom results remain reconcilable with ETRM?
- What risks arise from recalculating valuation logic inside reports?
- How would you process simulation results efficiently?
- How should large portfolio results be partitioned?
- How would you avoid loading unnecessary measures?
- How should report filters and parameters be validated?
- How would you preserve valuation scenario and as-of context?
- How should reports handle missing results?
- How would you identify incomplete portfolio processing?
- How should results be published downstream?
- What control totals should accompany extracts?
- How would you prevent reporting from degrading production?
- When should reporting move to an enterprise data platform?
- How would you test custom result calculations?
- How should rounding and aggregation be governed?
- How would you manage report-version changes?
- How should historical report reproducibility be demonstrated?
11. Integration Components20
- How would you implement inbound trade processing using the platform scripting language or Java?
- Should transport logic and trade-booking logic reside in the same component?
- How would you validate inbound messages?
- How should source-system identifiers be stored?
- How would you implement idempotency?
- What happens when ETRM saves the trade but acknowledgement fails?
- How should indeterminate outcomes be resolved?
- How would you process out-of-order amendments?
- How should reference-data dependencies be handled?
- How would you publish outbound events?
- What risks arise from publishing before transaction commit?
- How could an outbox-style pattern improve reliability?
- How should failed messages be quarantined?
- How would you support controlled replay?
- How should interface schemas be versioned?
- How would you protect ETRM from excessive request volume?
- How should connection and API timeouts be configured?
- How would you prevent duplicated payment or accounting output?
- What reconciliation should accompany integration code?
- When should integration be delegated to middleware?
12. Performance Engineering20
- What commonly makes an the platform scripting language script slow?
- How would you establish a performance baseline?
- How would you profile script execution?
- How would you identify expensive database operations?
- Why are database calls inside loops problematic?
- How should batch operations replace row-by-row processing?
- How can excessive table operations affect performance?
- How would you minimise object creation?
- When should processing be partitioned?
- How would you select partition keys?
- What limits safe parallel processing?
- How can parallel scripts create database contention?
- Why might increasing worker count reduce throughput?
- How would you protect interactive users from background workloads?
- How should large transaction profiles be handled?
- How would you test peak-volume behaviour?
- What is soak testing?
- How would you identify gradual memory degradation?
- How should performance regressions be detected?
- How would you verify that optimisation has not changed business results?
13. Secure Coding20
- What secure-coding standards should apply?
- How should scripts authenticate to external services?
- Where should credentials and secrets be stored?
- How should secrets be rotated?
- Why should credentials never be embedded in code?
- How would you validate untrusted input?
- How would you prevent SQL injection?
- How should file paths and file names be validated?
- How would you prevent unauthorised file access?
- How should outbound URLs and endpoints be controlled?
- How would you protect against malicious payloads?
- How should personally identifiable information be handled?
- How would you restrict script execution?
- What permissions should service accounts possess?
- How should privileged actions be audited?
- How would you scan dependencies for vulnerabilities?
- How should third-party libraries be approved?
- How would you respond to a vulnerable dependency?
- What security testing should precede release?
- How should production data be protected in lower environments?
14. Testing Strategy20
- How would you unit-test the platform scripting language code?
- Which logic should be isolated from ETRM APIs?
- How can wrapper or adapter patterns improve testability?
- How would you mock ETRM dependencies?
- What should component testing cover?
- How does integration testing differ from unit testing?
- What belongs in regression testing?
- How would you create representative transaction test cases?
- How should boundary dates and calendars be tested?
- How would you test 23-hour and 25-hour power-delivery days?
- How should negative prices and zero quantities be tested?
- How would you test large profiles?
- How should duplicate and out-of-order messages be tested?
- How would you test partial processing failure?
- How should restart and replay be tested?
- How would you validate memory cleanup?
- How should concurrency problems be tested?
- What results should be reconciled before release?
- How would you automate ETRM regression testing?
- What test evidence is required for production approval?
15. Source Control and Build Management20
- What should be stored in source control?
- How should an the platform scripting language repository be structured?
- How would you version scripts?
- How should branches and releases be managed?
- What coding standards should be enforced automatically?
- How would you introduce static analysis?
- What should a continuous-integration pipeline perform?
- How should compiled Java artifacts be built?
- How should dependencies be pinned?
- How would you ensure reproducible builds?
- How should artifact integrity be verified?
- How should environment-specific configuration be injected?
- How would you package related scripts and user-table changes?
- How should deployment dependencies be declared?
- How would you prevent unreviewed code reaching production?
- What information should a release manifest contain?
- How should database changes accompany code changes?
- How would you handle concurrent changes from multiple teams?
- What is the correct process for an emergency fix?
- How should production fixes return to the main development branch?
16. Deployment and Configuration Management20
- How should the platform scripting language scripts be promoted between environments?
- How should compiled Java components be deployed?
- What pre-deployment checks are required?
- How would you detect missing dependencies?
- How should deployment order be determined?
- What services may require restart?
- How would you minimise deployment downtime?
- How should backward compatibility support rolling deployment?
- What post-deployment smoke tests are required?
- How would you verify the deployed version?
- What operational monitoring should follow deployment?
- How would you roll back a script?
- When is rollback unsafe?
- What if new transactions were processed by the faulty version?
- How should data remediation accompany rollback?
- How would you detect environment drift?
- How should configuration values be compared across environments?
- What evidence should support release sign-off?
- What conditions should stop deployment?
- How should deployment ownership be divided?
17. Upgrade and Technical-Debt Management20
- How would you assess custom code before an legacy-to-modern ETRM upgrade?
- How should API usage be inventoried?
- How would you identify deprecated functions?
- What risks arise from undocumented customisations?
- How should binary and source dependencies be assessed?
- How would you compile and test Java components against the target version?
- Which scripts require full regression testing?
- How would you compare pre-upgrade and post-upgrade results?
- How should legitimate behavioural differences be documented?
- How would you measure customisation-related technical debt?
- Which components should be refactored before upgrading?
- When should a customisation be replaced by new standard functionality?
- How would you retire unused scripts safely?
- How should ownership of legacy code be established?
- How would you manage custom code with no source repository?
- What documentation is required for business-critical extensions?
- How should technical-debt remediation be prioritised?
- How would you prevent new debt during an upgrade?
- What would block upgrade approval?
- How should post-upgrade customisation performance be validated?
18. Code Review Questions15
- What do you examine first in an unfamiliar the platform scripting language script?
- How would you identify resource leaks?
- How would you detect unsafe database access?
- What indicates poor transaction handling?
- How would you identify hidden environment dependencies?
- What signs suggest excessive coupling?
- How would you identify duplicated business logic?
- What makes exception handling inadequate?
- How would you assess logging quality?
- How would you identify scalability risks?
- What indicates that code should be externalised?
- How would you review user-table usage?
- How would you assess thread-safety assumptions?
- What evidence should support a code-review approval?
- How should critical findings be tracked to closure?
19. Architecture Scenarios20
- A script works interactively but fails under a service account. What would you check?
- A long-running the platform scripting language process consumes increasing memory. What is the likely investigation path?
- A bulk trade loader creates duplicates after timeout. How would you redesign it?
- A script performs one database query per transaction. What should replace this pattern?
- A hook calls an external API while saving a trade. What risks does this create?
- A validation script adds several seconds to every trade. How would you improve it?
- An exception is logged, but the batch reports success. What design failure exists?
- A script catches every exception and continues processing. Why is this dangerous?
- A Java extension introduces incompatible library versions. How would you resolve it?
- A production script contains hard-coded portfolio identifiers. What should change?
- A script directly updates core ETRM tables. Would you approve it?
- An upgrade changes API behaviour and custom results differ. How would you isolate the cause?
- A report recalculates P&L differently from ETRM. What architectural problem exists?
- A replay produces duplicate settlement output. Which control is missing?
- Two scripts implement different mappings for the same commodity. How would you rationalise them?
- Operations edits user-table values without approval. What controls are required?
- A component is fast in testing but slow in production. What assumptions should be examined?
- A failed deployment processed some trades before rollback. What recovery is required?
- A business team wants to solve every exception through scripting. How would you challenge this?
- What distinguishes an ETRM extension architect from an the platform scripting language or Java developer?
Reporting, Data Lake and Analytics19 sections · 380 questions
1. Reporting Architecture Fundamentals20
- What reporting capabilities should remain inside ETRM?
- Which workloads should move to an enterprise data platform?
- How do operational, analytical, regulatory and financial reports differ?
- How would you define ETRM's reporting architecture boundaries?
- Why should ETRM not become an enterprise data warehouse?
- What risks arise when every report queries ETRM directly?
- How would you inventory existing ETRM reports?
- How would you identify duplicate or conflicting reports?
- What determines whether a report is business-critical?
- How should official and exploratory reports be distinguished?
- What constitutes an authoritative report?
- How should report ownership be assigned?
- What belongs in a reporting solution design?
- How would you capture functional and non-functional requirements?
- How should data latency requirements influence architecture?
- How would you support intraday and end-of-day reporting?
- How should global and desk-specific reports coexist?
- How would you establish a reporting catalogue?
- Which controls should accompany report publication?
- What distinguishes a reporting solution from a data extract?
2. ETRM Reporting and Simulation Results20
- How do ETRM simulations support reporting?
- What is a result measure?
- How would you select result measures for a report?
- Why should reports avoid requesting unnecessary measures?
- How do transaction, market-data and simulation contexts affect results?
- How should portfolio and transaction filters be defined?
- How would you identify an incomplete simulation result?
- What happens when a trade cannot be valued?
- How should failed transactions appear in reports?
- How would you preserve the market-data scenario used?
- How should valuation and business dates be represented?
- How would you report positions, P&L and sensitivities consistently?
- How should custom result calculations be governed?
- What are the risks of recalculating valuation logic in a report?
- How would you reconcile custom measures with standard results?
- How should report aggregation and rounding be controlled?
- How would you handle multiple currencies and units?
- How should report definitions be versioned?
- How would you reproduce an official ETRM report?
- When should simulation results be stored rather than recalculated?
3. Operational Reporting20
- What constitutes an operational ETRM report?
- Which reports require near-real-time data?
- How would you report failed trade-validation events?
- How should confirmation exceptions be reported?
- How would you identify unsettled or overdue cash flows?
- How should missing settlement instructions be reported?
- How would you report incomplete invoices?
- How should failed accounting postings appear?
- What should an end-of-day control dashboard contain?
- How would you report missing market data?
- How should stale curves and fixings be highlighted?
- How would you report unprocessed portfolios?
- How should exceptions be prioritised?
- How would you represent ownership and ageing?
- What drill-down should an operational report provide?
- How should corrected exceptions disappear from reports?
- How would you prevent duplicate workflow tasks?
- What service levels should operational reports support?
- How should reports distinguish data delay from process failure?
- When is a dashboard insufficient without workflow integration?
4. Position, Exposure and P&L Analytics20
- How would you design an enterprise position model?
- What is the correct grain of a commodity-position dataset?
- How should physical and financial positions coexist?
- How would you represent contractual, scheduled, nominated and actual quantities?
- How should fixed and floating exposures be distinguished?
- How would you model daily and hourly delivery profiles?
- How should unit conversions be applied?
- Which quantity should remain authoritative?
- How would you represent basis and location exposure?
- How should spread exposure be modelled?
- How would you prevent double counting between trades and hedges?
- How should options be represented in exposure analytics?
- How would you model delta-equivalent positions?
- What is the correct grain of a P&L dataset?
- How would you separate realised and unrealised P&L?
- How should P&L explain components be stored?
- How would you represent new-deal and amendment P&L?
- How should currency effects be separated?
- How would you reconcile aggregated analytics with ETRM?
- What controls prevent dashboards from presenting stale positions as current?
5. Market and Credit Risk Analytics20
- How would you model market-risk sensitivities in a data lake?
- What dimensions should accompany a risk measure?
- How should risk-factor mappings be represented?
- How would you store delta, gamma, vega and theta?
- How should VaR results be modelled?
- What metadata must accompany a VaR value?
- How would you represent portfolio diversification?
- Why should commodity VaRs not simply be added?
- How should historical simulation scenarios be stored?
- How would you model stress-test results?
- How should shocked inputs and results remain linked?
- How would you distinguish full-revaluation and approximation results?
- How should limit utilisation be represented?
- How would you report limit breaches and approvals?
- How would you model counterparty exposure?
- How should current, future and settlement exposure differ?
- How would you represent netting and collateral?
- How should credit hierarchies support aggregation?
- How would you preserve risk calculations as of an earlier date?
- How should model and methodology versions accompany risk results?
6. Extraction Architecture20
- What options exist for extracting data from ETRM?
- How would you select between reports, APIs, messaging and database extracts?
- When is a scheduled snapshot appropriate?
- When is change-based extraction preferable?
- How would you design an incremental extract?
- Which field should act as the change watermark?
- What problems arise from relying only on modification timestamps?
- How would you capture late and backdated changes?
- How should transaction cancellations be extracted?
- How would you represent physical deletion or record retirement?
- How should lifecycle-event changes be captured?
- How would you extract large transaction profiles efficiently?
- How should simulation results be exported?
- How would you avoid affecting ETRM's operational performance?
- What control totals should accompany each extract?
- How would you identify missing extraction windows?
- How should extract reruns be handled?
- How would you prevent reruns from duplicating downstream data?
- How should extraction failures be recovered?
- What evidence demonstrates that extraction is complete?
7. Events, CDC and Streaming20
- When should ETRM data be distributed as events?
- What is the difference between event streaming and database change-data capture?
- Why may raw CDC be unsuitable as a business contract?
- What is a business event?
- How should trade-created, amended and cancelled events differ?
- How would you publish events only after successful ETRM processing?
- What is the transactional-outbox pattern?
- How would you preserve event ordering for a transaction?
- How should consumers detect duplicate events?
- How would you support controlled event replay?
- How should event schemas be versioned?
- How would you communicate corrected historical data?
- What happens when a consumer misses events?
- When should a snapshot supplement an event stream?
- How would Kafka support near-real-time analytics?
- How should partitions be selected?
- How would you monitor consumer lag?
- What business reconciliation remains necessary?
- How should sensitive fields be excluded from events?
- When should streaming be rejected in favour of simpler batch extraction?
8. Data Lake and Lakehouse Architecture20
- What is the role of a data lake in an ETRM architecture?
- How does a lakehouse differ from a traditional data lake?
- What should raw, standardised and curated layers contain?
- Should raw ETRM extracts be transformed before retention?
- How would you preserve source-system fidelity?
- What metadata should accompany every ingestion batch?
- How would you partition ETRM datasets?
- What are the risks of excessive partitioning?
- Which file formats are suitable for analytical data?
- How should small-file problems be managed?
- How would you implement ACID processing in a lakehouse?
- How should schema enforcement and evolution be handled?
- How would you manage late-arriving data?
- How should corrected records update curated datasets?
- How would you prevent partial ingestion from becoming visible?
- What quality gates should separate data layers?
- How should failed records be quarantined?
- How would you manage retention and archival?
- How should disaster recovery be designed?
- When is a warehouse preferable to a lakehouse?
9. Analytical Data Modelling20
- How would you model ETRM trades analytically?
- What should be the grain of a trade fact table?
- When should transaction legs form separate facts?
- How should repeating profiles be represented?
- How would you model lifecycle events?
- How should cash flows and settlement events differ?
- How would you model market-data observations?
- How should curves and curve points be represented?
- How would you model simulation results?
- How should portfolio and organisational hierarchies be represented?
- What is a slowly changing dimension?
- Which dimensions require Type 2 history?
- How should counterparty hierarchy changes be handled?
- How would you preserve portfolio history?
- How should effective and ingestion dates differ?
- What is the difference between business time and system time?
- When is a bitemporal model necessary?
- How would you model trade versions?
- How should external and ETRM identifiers coexist?
- How would you prevent model design from losing ETRM business semantics?
10. Historical and As-of Reporting20
- What does “as of” mean in an ETRM report?
- How do valuation time and knowledge time differ?
- What data is required to reproduce an earlier result?
- How would you preserve historical transaction versions?
- How should market-data snapshots be versioned?
- How would you handle corrected historical fixings?
- Should corrected data overwrite original official data?
- How would you distinguish originally reported and restated results?
- How should organisational hierarchy changes affect historical reports?
- How would you report using current and historical hierarchies?
- How should late trades affect prior-day reporting?
- How would you prevent future-data leakage?
- What is an as-of fence?
- How should model versions be incorporated?
- How would you test reproducibility?
- What evidence should support a financial restatement?
- How should historical recalculation be authorised?
- How would downstream users select the correct version?
- How should official snapshots be retained?
- When is exact reproduction impossible, and how should that limitation be disclosed?
11. Data Quality and Reconciliation20
- What data-quality dimensions apply to ETRM analytics?
- How would you define critical data elements?
- Which checks belong at ingestion?
- Which checks belong in curated datasets?
- How would you validate schema and mandatory fields?
- How should referential integrity be tested?
- How would you detect duplicate transactions?
- How should unit and currency validity be checked?
- How would you detect missing transaction profiles?
- How should missing market data be identified?
- What is a control total?
- Which counts and amounts should be reconciled?
- How would you reconcile positions between ETRM and the lakehouse?
- How should P&L reconciliation handle rounding?
- How would you reconcile lifecycle events?
- What should happen when reconciliation fails?
- How should breaks be prioritised and assigned?
- How would you identify the first point of divergence?
- How should corrections be tracked?
- How would you demonstrate data completeness to auditors?
12. Data Lineage, Catalogue and Metadata20
- What lineage is required for an ETRM-derived metric?
- How would you trace a dashboard value back to ETRM?
- What technical and business metadata should be captured?
- How should report definitions be catalogued?
- How would you document transformation logic?
- How should source fields map to business terms?
- What is a data contract?
- How should data-product owners use contracts?
- How would you handle one field having different business meanings?
- How should calculation formulas be versioned?
- What metadata should accompany market-risk results?
- How would you record source-system and processing timestamps?
- How should data-quality results appear in the catalogue?
- What is the role of impact analysis?
- How would lineage support an legacy-to-modern ETRM upgrade?
- How should sensitive data be classified?
- Who owns lineage accuracy?
- How would you prevent documentation becoming stale?
- What metadata should be generated automatically?
- How would you prove lineage for a regulatory report?
13. Security and Data Access20
- How should ETRM data be classified?
- Which datasets contain commercially sensitive information?
- How should counterparty and bank data be protected?
- How would you implement role-based access?
- When is row-level security required?
- When is column-level masking appropriate?
- How should desk and portfolio access be enforced?
- How would you protect data in transit and at rest?
- How should service identities access data?
- How would you manage encryption keys?
- How should production data be protected in development?
- What masking or tokenisation methods could be used?
- How would you audit data access?
- How should bulk downloads be controlled?
- How would you prevent data exfiltration?
- What retention restrictions apply to user activity logs?
- How should external analysts access curated data?
- How would you manage cross-border data restrictions?
- What should happen when a user changes desks?
- How would you conduct periodic access recertification?
14. BI and Semantic-Layer Design20
- What is a semantic layer?
- Why should dashboards not independently redefine business measures?
- How would you define certified position and P&L measures?
- How should reusable dimensions be governed?
- How would you support drill-down from desk to trade?
- What dimensions should support slicing risk results?
- How would you handle unit and currency selection?
- Should currency conversion occur in the dashboard?
- How should aggregation behaviour be defined?
- Which measures are non-additive?
- Why should VaR not be summed indiscriminately?
- How should latest and official snapshots be distinguished?
- How would you communicate data freshness?
- How should incomplete data be displayed?
- How would you optimise dashboard performance?
- When should data be pre-aggregated?
- What caching risks arise for intraday data?
- How would you validate dashboard numbers?
- How should self-service analytics be governed?
- What prevents a dashboard from becoming an uncontrolled spreadsheet replacement?
15. Advanced Analytics and AI20
- Which ETRM datasets are suitable for advanced analytics?
- How could analytics improve trade surveillance?
- How could anomaly detection support P&L control?
- How could machine learning identify market-data anomalies?
- How could settlement failures be predicted?
- How could cash-flow forecasts support treasury?
- How might analytics improve credit-exposure monitoring?
- How would you create features from trade and market data?
- How should point-in-time correctness be maintained?
- What causes training-serving leakage?
- How should model outputs be reconciled with controlled ETRM results?
- Should AI-generated values directly update ETRM?
- What human approval should surround model-driven actions?
- How would you monitor model drift?
- How should model versions and datasets be tracked?
- How would you explain an analytical result to risk controllers?
- What controls apply to generative AI using trade data?
- How would you prevent sensitive information entering external models?
- When is a deterministic rule preferable to machine learning?
- How would you establish that an analytics use case creates measurable value?
16. Performance and Cost Management20
- How would you estimate ETRM data volumes?
- Which datasets typically grow most rapidly?
- How should ingestion frequency affect platform sizing?
- How would you manage hourly or sub-hourly position snapshots?
- When should data be recomputed instead of stored?
- How would you prevent unnecessary full-data reloads?
- What is predicate pushdown?
- How do partition pruning and clustering improve performance?
- How would you handle skewed portfolio data?
- When should datasets be compacted?
- How should compute and storage be separated?
- How would you manage concurrent BI and data-science workloads?
- How should workload isolation be implemented?
- How would you establish cost attribution by data product?
- What metrics indicate inefficient pipelines?
- How would you reduce cloud costs without weakening controls?
- What retention policies should apply to intermediate data?
- How should performance testing use representative volumes?
- How would you detect data-volume assumptions becoming invalid?
- When should architecture be redesigned instead of scaled?
17. DevOps and DataOps20
- How should reporting code be stored and versioned?
- What should a data-pipeline CI/CD process perform?
- How would you test SQL transformations?
- What is data-contract testing?
- How should schema changes be detected?
- How would you test reconciliation automatically?
- How should reference-data mappings be promoted?
- How would you separate code from environment configuration?
- What release evidence should be retained?
- How should failed pipeline deployments be rolled back?
- What if a faulty transformation already published data?
- How would you perform data correction and backfill?
- How should pipeline dependencies be orchestrated?
- How would you make pipelines restartable?
- What checkpoints should long-running jobs maintain?
- How should observability be built into pipelines?
- What service-level objectives apply to data products?
- How should data incidents be managed?
- How would you detect configuration drift?
- What conditions should block a reporting release?
18. Migration and Modernisation20
- How would you migrate legacy ETRM reports?
- Which reports should be retired rather than migrated?
- How would you identify report usage?
- How should business definitions be rationalised?
- How would you compare legacy and target results?
- What differences may be legitimate?
- How should parallel reporting operate?
- How long should parallel validation continue?
- How would you migrate historical snapshots?
- How should historical lineage be preserved?
- How would you handle reports containing undocumented logic?
- How should user-owned spreadsheets be assessed?
- When should a spreadsheet become a governed data product?
- How would you migrate without disrupting daily controls?
- What reconciliation thresholds should apply?
- Who should approve report decommissioning?
- How would you prevent users returning to obsolete reports?
- What training and adoption support is required?
- How should post-migration defects be prioritised?
- What determines successful reporting modernisation?
19. Architecture Scenarios20
- ETRM and a dashboard show different P&L. How would you investigate?
- Trade counts reconcile, but positions do not. What should be compared?
- A cancelled trade remains in the data lake. What extraction weakness might exist?
- Yesterday's official dashboard changes after a fixing correction. What design problem exists?
- Intraday reports are current, but their market data is stale. How should this be shown?
- A data pipeline rerun duplicates simulation results. Which controls are missing?
- A report sums desk-level VaR and overstates enterprise risk. What modelling error occurred?
- Current portfolio hierarchies rewrite historical reporting. How would you correct this?
- A direct database report fails after an legacy-to-modern ETRM upgrade. What architectural decision should change?
- Traders request unrestricted access to raw ETRM data. How would you respond?
- A lakehouse trade model removes leg-level detail. What analytics could become incorrect?
- A dashboard converts all quantities using current conversion factors. What historical problem results?
- An hourly position dataset becomes prohibitively expensive. How would you redesign it?
- A source extract completes successfully but omits one portfolio. How should completeness be detected?
- A late trade must update yesterday's report without overwriting the originally published result. How would you model it?
- Two teams define realised P&L differently. How would you establish an authoritative definition?
- An AI model predicts settlement failures but cannot explain its drivers. Would you operationalise it?
- The data platform contains sensitive counterparty data accessible to every analyst. What controls are required?
- The business requests real-time reporting although ETRM updates only periodically. How would you frame the limitation?
- What distinguishes an ETRM data and analytics architect from a BI developer or data engineer?
Performance, Grid and Batch Architecture19 sections · 410 questions
1. Performance Architecture Fundamentals20
- What does performance mean for an ETRM platform?
- How do latency, throughput, concurrency and capacity differ?
- Which ETRM workloads are latency-sensitive?
- Which workloads are throughput-oriented?
- How should interactive and batch requirements differ?
- What is a performance baseline?
- Which measurements should establish the baseline?
- How would you define a performance service-level objective?
- How do technical and business service levels differ?
- What is a representative workload?
- Why is average response time insufficient?
- How should percentile response times be used?
- What is workload contention?
- How would you identify the platform's bottleneck?
- Why should infrastructure scaling not be the first response?
- What is coordinated omission in performance testing?
- How would you distinguish a symptom from a root cause?
- What architectural decisions most influence ETRM performance?
- How should performance requirements be documented?
- What evidence demonstrates acceptable production performance?
2. Workload Classification and Isolation20
- How would you classify ETRM workloads?
- How do trade capture, valuation, reporting and settlement workloads differ?
- Which processes require immediate execution?
- Which processes can be queued?
- How would you isolate trader-facing workloads?
- How should end-of-day workloads be separated from intraday processing?
- How would you prevent reporting from affecting trade entry?
- Which workloads should run on dedicated services?
- When should dedicated hosts be considered?
- How should critical and non-critical queues be separated?
- What is workload prioritisation?
- How should business cut-offs influence prioritisation?
- How would you control ad hoc user workloads?
- How should large report requests be governed?
- What is admission control?
- How would you prevent one desk monopolising shared capacity?
- When is workload throttling appropriate?
- How should back-pressure be implemented?
- How would you handle unexpected volume spikes?
- What indicates that workload isolation is inadequate?
3. Client and Interactive Performance20
- How would you investigate slow ETRM client response?
- How would you separate client, network, service and database latency?
- What causes slow trade-entry screens?
- How can excessive defaulting logic affect users?
- How can synchronous validations increase latency?
- Which validations must remain synchronous?
- Which validations could run asynchronously?
- How would you diagnose a slow portfolio query?
- How can large result sets affect client performance?
- How should search criteria be constrained?
- How could user layouts or saved queries create performance problems?
- How would you investigate slow login?
- How can entitlement evaluation affect response time?
- How would network latency affect remote users?
- When should regional access architecture be reconsidered?
- How would you monitor user-experienced latency?
- What telemetry is needed for interactive diagnostics?
- How would you reproduce an intermittent client issue?
- Why might only one user experience slowness?
- When should a client-performance incident be treated as a platform issue?
4. Database Performance25
- How does database performance affect ETRM?
- What are the common symptoms of database bottlenecks?
- How would you identify expensive queries?
- What causes blocking and lock contention?
- How can long-running transactions affect other workloads?
- How should query execution plans be analysed?
- What role do indexes play?
- How can inappropriate indexing reduce performance?
- Why are database statistics important?
- How should statistics maintenance be scheduled?
- What causes excessive database round trips?
- Why are row-by-row queries inefficient?
- How would you replace repeated queries with set-based processing?
- How can direct analytical queries affect ETRM?
- How should operational and analytical workloads be separated?
- What causes temporary-space pressure?
- How would you investigate increasing database I/O?
- How does storage latency affect batch performance?
- What causes database connection exhaustion?
- How should connection pools be sized?
- How would you detect connection leaks?
- How should data growth be monitored?
- When should historical data be archived?
- How would you verify that archiving improved performance?
- What controls should govern database tuning changes?
5. the platform scripting language and Java Performance25
- What commonly causes poor the platform scripting language performance?
- How would you profile an the platform scripting language script?
- Why are database calls inside loops problematic?
- How should table operations be optimised?
- How can repeated table copying affect memory and runtime?
- Why must the platform scripting language table objects be destroyed?
- How would you detect table-related memory leaks?
- What risks arise from processing an entire dataset in memory?
- How should large datasets be partitioned?
- How would you choose an appropriate batch size?
- What are the risks of very small batches?
- What are the risks of very large batches?
- How would you reduce unnecessary object creation?
- How should reusable reference data be cached?
- What risks arise from stale caches?
- How would you profile a Java extension?
- What does sustained garbage collection indicate?
- How would you diagnose heap exhaustion?
- How can unmanaged threads affect ETRM?
- When can parallel processing make a script slower?
- How would you ensure thread safety?
- How should external-service calls be timed and monitored?
- What timeout and retry problems can degrade performance?
- How would you detect a performance regression after code deployment?
- How should optimisation preserve functional results?
6. Simulation Architecture25
- What is an ETRM simulation?
- Which inputs determine simulation performance?
- How do transaction volume and product complexity affect runtime?
- How does the number of result measures affect performance?
- Why should simulations request only necessary measures?
- How do market-data scenarios influence processing?
- How would you design an intraday simulation?
- How should official end-of-day simulations differ?
- How would you partition a large simulation?
- Which partition keys are commonly useful?
- What risks arise from partitioning by transaction count alone?
- How should complex transactions influence partitioning?
- How would you address skewed portfolio workloads?
- What is full revaluation?
- When can sensitivity-based calculation reduce runtime?
- What control is required when using approximations?
- How should dependencies between result measures be managed?
- What can cause one transaction to slow an entire simulation?
- How would you identify problematic transactions?
- How should unvalued transactions be handled?
- What constitutes a complete simulation result?
- How would you verify that all expected portfolios were processed?
- How should partial simulation failures be recovered?
- How would you compare simulation results across environments?
- What would justify redesigning a simulation rather than adding capacity?
7. Grid Architecture25
- What is the role of grid computing in ETRM?
- Which workloads benefit from grid execution?
- Which workloads are unsuitable for distribution?
- What are grid coordinators, workers and work units conceptually?
- How should work be divided across workers?
- How would you select the number of workers?
- Why does adding workers not guarantee linear scaling?
- What shared resources can limit grid scalability?
- How can the database become a grid bottleneck?
- How can network latency affect distributed processing?
- What is workload skew?
- How would you detect uneven worker utilisation?
- How should large or complex portfolios be distributed?
- What happens when a worker fails?
- How should failed work units be retried?
- How would you prevent duplicate results after retry?
- How should intermediate results be managed?
- What constitutes successful grid completion?
- How would you detect a worker that is alive but stalled?
- Which worker metrics should be monitored?
- How should worker capacity be reserved for critical workloads?
- How would you support multiple simulations concurrently?
- What causes grid queue congestion?
- How should queue priority be governed?
- How would you test grid failover?
8. Batch Architecture25
- What constitutes an ETRM batch process?
- What makes a batch restartable?
- How should a batch be divided into logical stages?
- What checkpoints should be retained?
- How should dependencies be represented?
- How would you prevent downstream stages running prematurely?
- What is the difference between job completion and business completion?
- How should batch control totals be calculated?
- How would you detect missing portfolios or records?
- What happens when only one stage fails?
- Should the entire batch be rerun?
- How would you design selective restart?
- How should previously completed work be recognised?
- How would you prevent duplicate outputs?
- How should batch parameters be controlled?
- How would you manage business-date parameters?
- What risks arise from defaulting to the current system date?
- How should reruns for historical dates be handled?
- How should batch status be reported?
- What audit evidence should every run retain?
- How should manual intervention be controlled?
- When should operators be prevented from bypassing failed stages?
- How would you manage downstream notification?
- How should batch retention and log archival be governed?
- What makes a batch architecture operationally supportable?
9. End-of-Day Architecture25
- What are the principal stages of an ETRM end-of-day cycle?
- How should trading cut-off be established?
- How would you control late and backdated trades?
- How should official market-data readiness be confirmed?
- What checks should precede valuation?
- How should valuation, risk and P&L jobs be sequenced?
- When can jobs execute in parallel?
- Which dependencies require strict ordering?
- How should settlement and accounting processing fit into end-of-day?
- What is an official result snapshot?
- How should official and rerun results be distinguished?
- How would you preserve the original published result?
- How should corrected trades or market data trigger recalculation?
- Who should authorise a rerun?
- How should downstream systems be notified of restated results?
- How would you coordinate regional close schedules?
- How should overlapping business dates be managed?
- How would you handle daylight-saving transitions?
- What happens when end-of-day misses its SLA?
- How should critical and deferrable stages be classified?
- What is the minimum viable close?
- How should incomplete results be communicated?
- How would you recover after an extended outage?
- What reconciliation proves end-of-day completeness?
- What criteria determine successful business-day closure?
10. Scheduling and Orchestration20
- How should ETRM jobs be scheduled?
- When should enterprise scheduling be used?
- How should ETRM-native and external scheduling coexist?
- How would you model cross-system dependencies?
- What is a job dependency graph?
- How should calendars and regional holidays affect schedules?
- How would you prevent duplicate scheduler execution?
- What happens during scheduler failover?
- How should missed schedules be detected?
- How would you manage ad hoc executions?
- How should job parameters be approved?
- How would you control manual restarts?
- What is a maximum execution window?
- How should long-running jobs be escalated?
- When should a job be terminated?
- What risks arise from automatically killing a slow job?
- How should scheduler time zones be configured?
- How would you coordinate month-end and year-end processing?
- What operational dashboard should orchestration provide?
- How would you test schedule changes?
11. Concurrency and Transaction Management20
- What concurrency risks exist in ETRM processing?
- How can two processes attempt to update the same trade?
- How should conflicting updates be handled?
- What is optimistic versus pessimistic locking?
- How can lock contention affect batch throughput?
- How would you identify a deadlock?
- How should transaction boundaries be selected?
- Why are long database transactions risky?
- How would you process independent records concurrently?
- Which records must remain sequential?
- How should ordering be maintained for trade amendments?
- How would you prevent simultaneous duplicate processing?
- What is idempotent processing?
- How does idempotency support batch restart?
- How should shared reference-data caches be protected?
- What risks arise from parallel writes to output tables?
- How should control totals be calculated across parallel workers?
- How would you test race conditions?
- Why can concurrency defects be difficult to reproduce?
- When should concurrency be reduced deliberately?
12. Memory and Resource Management20
- Which ETRM workloads are memory-intensive?
- How would you establish normal memory usage?
- What is the difference between a memory spike and a leak?
- How would you identify gradual memory growth?
- What causes heap exhaustion?
- How can large transaction profiles increase memory usage?
- How should large result tables be processed?
- Why is resource cleanup essential?
- How would you detect unreleased database connections?
- What causes excessive temporary-file usage?
- How should disk space be monitored?
- What is CPU saturation?
- How would you distinguish useful CPU work from contention?
- What indicates thread-pool exhaustion?
- How should worker thread pools be sized?
- How would you diagnose excessive context switching?
- How can logging degrade performance?
- How should log levels be controlled dynamically?
- What resource limits should trigger alerts?
- When should a process be restarted, and when is restart insufficient?
13. High Availability and Recovery20
- Which performance services require high availability?
- How should active-active and active-passive designs differ?
- What happens to running jobs during failover?
- How should in-flight work be identified?
- How would you prevent duplicate processing after recovery?
- How should checkpoints survive host failure?
- What recovery-point objective applies to batch state?
- What recovery-time objective applies to end-of-day?
- How should database and application recovery remain consistent?
- What happens when grid workers lose coordinator connectivity?
- How should queued work survive service restart?
- How would you recover from database unavailability?
- How should accumulated backlog be prioritised?
- What capacity is required during degraded operation?
- How would you test failover under full workload?
- What constitutes business-level recovery?
- How should disaster-recovery capacity be sized?
- How would you verify historical results after recovery?
- What evidence should resilience testing produce?
- Which recovery assumptions require regular revalidation?
14. Monitoring and Observability20
- What should an ETRM performance dashboard show?
- Which client-performance metrics should be monitored?
- Which service metrics should be monitored?
- Which database metrics should be monitored?
- Which grid metrics should be monitored?
- Which batch metrics should be monitored?
- How would you correlate activity across components?
- What role should correlation identifiers play?
- How would you trace a slow simulation?
- How should queue depth and consumer lag be interpreted?
- How would you identify a stalled worker?
- What is the difference between liveness and progress?
- How should expected completion time be forecast?
- What thresholds should generate warnings?
- What thresholds should generate incidents?
- How would you avoid alert fatigue?
- How should performance trends be retained?
- What data supports capacity planning?
- How would you detect degradation before SLA breach?
- How should business completeness appear alongside technical status?
15. Capacity Planning20
- What inputs are needed for ETRM capacity planning?
- How should trade-volume growth be projected?
- How should product complexity influence estimates?
- How do hourly profiles affect data and compute requirements?
- How should additional result measures influence sizing?
- How would you estimate concurrent-user growth?
- How should intraday valuation frequency affect capacity?
- What headroom should production maintain?
- How would you size for month-end peaks?
- How should failover capacity be considered?
- How would you model compound growth across datasets?
- What does a capacity constraint look like?
- How should capacity forecasts be validated?
- When should capacity be added?
- How would you distinguish vertical and horizontal scaling opportunities?
- Which ETRM workloads scale poorly horizontally?
- How should storage growth be forecast?
- How would archival affect future capacity?
- What cost-performance trade-offs should be presented?
- When does capacity planning require architectural redesign?
16. Performance Testing20
- What should an ETRM performance-test strategy contain?
- How do load, stress, volume, spike and soak tests differ?
- How would you create representative trade populations?
- Why must structured products be included?
- How should market-data volume be represented?
- How would you simulate concurrent users?
- How should end-of-day dependencies be reproduced?
- What baseline environment is required?
- How would you account for smaller non-production infrastructure?
- Which metrics should be captured during testing?
- How would you test grid scalability?
- What does a scalability curve reveal?
- How would you identify the saturation point?
- How should failure and recovery be included?
- How would you test partial worker failure?
- How should test results be compared with SLAs?
- How would you validate result correctness under load?
- What is an acceptable performance variance?
- How should performance regressions block release?
- What evidence should support production-capacity approval?
17. Cloud and Infrastructure Considerations20
- How does cloud infrastructure affect ETRM performance?
- Which workloads benefit from elastic capacity?
- Why may autoscaling be unsuitable for some ETRM components?
- How should compute placement minimise latency?
- How does cross-zone communication affect performance?
- How should database storage be selected?
- What impact can network-attached storage have?
- How would you benchmark cloud instances?
- How should burstable instances be assessed?
- How would you avoid noisy-neighbour effects?
- How should grid workers be scaled in cloud environments?
- What startup time limits elasticity?
- How would you manage capacity for predictable end-of-day peaks?
- How should infrastructure-as-code support repeatability?
- What monitoring should integrate with cloud observability?
- How would you control performance-related cloud costs?
- When is reserved capacity preferable?
- How should disaster-recovery environments be scaled?
- How would you validate vendor support for the infrastructure?
- What cloud assumptions require proof-of-concept testing?
18. Performance Governance20
- Who owns ETRM performance?
- How should application, database and infrastructure responsibilities be divided?
- What performance standards should developers follow?
- How should solution designs include capacity impact?
- When is performance testing mandatory?
- How should performance defects be prioritised?
- What is a performance budget?
- How would you prevent gradual SLA erosion?
- How should architectural exceptions be approved?
- How would you maintain a performance-risk register?
- What evidence should accompany tuning changes?
- How should production changes be benchmarked?
- How would you prevent untested indexes or parameters reaching production?
- When should vendor support be engaged?
- How should recurring incidents inform architectural remediation?
- What metrics indicate accumulated performance debt?
- How should improvement benefits be measured?
- How would you communicate capacity risk to executives?
- What release criteria should include performance?
- What conditions justify stopping production deployment?
19. Architecture Scenarios20
- End-of-day runtime doubles without increased trade volume. How would you investigate?
- Adding grid workers makes simulations slower. What bottlenecks might explain this?
- One portfolio consumes half the risk-run duration. How would you redesign partitioning?
- Trade entry slows only during reporting hours. What does this suggest?
- Database CPU is low, but query latency is high. What else should be examined?
- A batch reports success while one portfolio is missing. What control failed?
- Restarting a failed batch duplicates accounting output. What design is missing?
- A script processes transactions one at a time with repeated queries. How should it change?
- Grid workers are busy but overall throughput is flat. What shared constraint may exist?
- A simulation is fast in testing but slow in production. Which assumptions should be compared?
- A service is running but its queue continues growing. How should monitoring classify it?
- Month-end processing misses its cut-off every quarter. Why is this not merely an operational issue?
- A complex LNG transaction takes minutes to value. How would you isolate the expensive component?
- A report requests every result measure for every trade. What architectural correction is required?
- Memory returns to normal after restart but grows again daily. How should this be treated?
- A database index improves one report but slows trade capture. How would you assess the change?
- A regional close overlaps with another region's intraday run. How would you manage capacity?
- Disaster recovery meets infrastructure RTO but misses the business close. What was defined incorrectly?
- The business asks for a five-minute SLA without providing expected volumes. How would you respond?
- What distinguishes an ETRM performance architect from a database administrator or infrastructure engineer?
Security, Entitlements and Audit20 sections · 400 questions
1. Security Architecture Fundamentals20
- What are the principal security domains in an ETRM implementation?
- How would you define ETRM's security boundary?
- Which controls belong inside ETRM?
- Which controls belong in identity, network, database and infrastructure platforms?
- How do authentication, authorisation and accountability differ?
- What is the principle of least privilege?
- What is defence in depth?
- How would you perform an ETRM security assessment?
- What should an ETRM security architecture document contain?
- How would you identify critical business actions?
- How should business risk determine control strength?
- What is a threat model?
- Which ETRM assets require the strongest protection?
- How would you classify ETRM data?
- How should preventive, detective and corrective controls work together?
- What is a security control objective?
- How would you map controls to risks?
- How should security exceptions be approved?
- How would you prevent security architecture becoming environment-specific?
- What constitutes effective security rather than documented security?
2. Identity and Authentication20
- How should ETRM users be uniquely identified?
- How would you integrate ETRM with enterprise identity management?
- What authentication methods should be considered?
- When should single sign-on be used?
- What risks accompany local ETRM accounts?
- When might a local emergency account be necessary?
- How should emergency credentials be protected?
- What is multifactor authentication?
- Where should MFA be enforced?
- How should service accounts authenticate?
- Why should shared user accounts be prohibited?
- How should authentication failures be monitored?
- What account-lockout policy is appropriate?
- How should inactive accounts be handled?
- How would you manage password requirements where passwords remain necessary?
- How should authentication sessions expire?
- How would you manage users across multiple ETRM environments?
- How should non-production identities differ from production identities?
- What risks arise from copying identity data between environments?
- How would you prove that every action maps to an accountable identity?
3. Role-Based Access Control20
- What is role-based access control?
- How would you design an ETRM role model?
- Should roles mirror job titles?
- What is the difference between business and technical roles?
- How should trader, risk, operations and administrator roles differ?
- How would you avoid one role containing excessive permissions?
- What is role explosion?
- How would you manage regional variations?
- How should temporary responsibilities be granted?
- How would you define role ownership?
- What information should a role catalogue contain?
- How should role changes be approved?
- How would you identify unused roles?
- How should inherited permissions be analysed?
- How would you detect conflicting roles?
- What is attribute-based access control?
- When could attributes complement ETRM roles?
- How would you test a role before production deployment?
- How should roles move between environments?
- How would you demonstrate that a role remains appropriate over time?
4. Organisational, Portfolio and Transaction Entitlements20
- How should access be restricted by business unit?
- How should portfolio-level visibility be implemented?
- How would you restrict a trader to authorised books?
- How should read, create, amend and validate permissions differ?
- How would you prevent unauthorised portfolio transfers?
- How should product eligibility be enforced?
- How would you restrict transaction entry by instrument?
- How should tenor, quantity or notional mandates be controlled?
- How would you restrict access by legal entity?
- How should regional data restrictions be represented?
- Can users with view access see economically sensitive fields?
- How would you limit bulk transaction operations?
- How should historical transaction access be governed?
- How would you prevent users from bypassing controls through templates?
- How should inter-book transactions be authorised?
- How would you control cancellation and termination rights?
- How should amendment permissions vary by transaction status?
- What controls apply after confirmation or settlement?
- How would you test negative-entitlement scenarios?
- How would you detect booking activity outside a user's mandate?
5. Segregation of Duties20
- What is segregation of duties?
- Which ETRM duties should normally be separated?
- Can a trader create and validate the same transaction?
- Should a user maintain and approve settlement instructions?
- Should developers deploy their own production changes?
- Should operations staff amend core trade economics?
- How would you construct a segregation-of-duties matrix?
- What constitutes a toxic access combination?
- How would you detect toxic role combinations?
- How should unavoidable conflicts be managed?
- What is a compensating control?
- When is supervisory review an adequate compensating control?
- How should small teams handle limited staff separation?
- How should emergency-access conflicts be reviewed?
- How would you prevent users from obtaining conflicts through multiple roles?
- How should temporary access affect segregation checks?
- How would you test segregation during user acceptance?
- How should conflicts be reported and escalated?
- Who should accept residual segregation risk?
- How would you prove that segregation controls operated effectively?
6. Privileged Access Management20
- What constitutes privileged access in ETRM?
- Which accounts should be treated as privileged?
- How should administrator access be granted?
- What is just-in-time privileged access?
- How should privileged sessions be approved?
- How would you integrate privileged access management?
- Should administrators use privileged accounts for ordinary work?
- How should database-administrator access be controlled?
- How should operating-system access be governed?
- How would you manage vendor-support access?
- What controls should apply to production support?
- How should privileged credentials be rotated?
- How would you eliminate embedded administrative passwords?
- Should privileged sessions be recorded?
- What privileged activities require real-time alerting?
- How should emergency access be activated?
- How should emergency activity be reviewed?
- What happens when privileged access expires?
- How would you recertify privileged accounts?
- What evidence should a privileged-access review produce?
7. Service Accounts and Machine Identities20
- How do service accounts differ from user accounts?
- Why should every service have a distinct identity?
- How should service-account ownership be assigned?
- What permissions should a trade-ingestion service possess?
- How should batch-service permissions differ?
- How should reporting-service permissions differ?
- Why should service accounts be non-interactive?
- How should secrets be stored?
- How should secrets be rotated without service interruption?
- What is certificate-based authentication?
- When should mutual TLS be used?
- How should certificate expiry be monitored?
- How would you prevent credentials appearing in scripts?
- How should environment-specific secrets be separated?
- How would you identify unused service accounts?
- How should service-account activity be monitored?
- What indicates that a service identity is compromised?
- How should compromised credentials be revoked?
- How would you recover dependent services after rotation?
- How should service identities be included in access recertification?
8. Sensitive Data Protection20
- Which ETRM data should be classified as confidential?
- How should transaction economics be protected?
- How should counterparty information be classified?
- What controls apply to bank-account details?
- How should trader and personnel data be protected?
- How would you enforce field-level restrictions?
- When should data masking be used?
- What is tokenisation?
- How should production data be sanitised for testing?
- Why is simply changing names insufficient anonymisation?
- How should data be encrypted in transit?
- How should data be encrypted at rest?
- Who should control encryption keys?
- How should backups be encrypted?
- What controls should apply to data exports?
- How would you restrict spreadsheet downloads?
- How should reports avoid exposing unnecessary information?
- What controls apply to email-distributed reports?
- How would you manage data residency requirements?
- How should sensitive-data access be audited?
9. Database and Infrastructure Security20
- How should ETRM database access be restricted?
- Why should users not connect directly to production tables?
- How should application database credentials be managed?
- What risks arise from shared database credentials?
- How would you monitor privileged database activity?
- How should database changes be approved?
- What controls prevent direct updates to core tables?
- How should backups and replicas be protected?
- How should operating-system accounts be managed?
- What file-system permissions should ETRM components receive?
- How should network segmentation protect ETRM?
- Which inbound and outbound connections should be allowed?
- How should firewalls implement least connectivity?
- What is the role of a bastion or controlled administration host?
- How should remote administrative access be secured?
- How should vulnerability scanning be performed?
- How should operating-system and database patches be governed?
- How would you manage unsupported platform components?
- What evidence demonstrates secure infrastructure configuration?
- How should disaster-recovery security match production?
10. APIs and Integration Security20
- How should systems authenticate to ETRM-facing APIs?
- How should API authorisation be implemented?
- What is the role of an API gateway?
- How should API scopes be defined?
- How would you restrict an interface to authorised portfolios?
- How should inbound payloads be validated?
- How would you prevent injection attacks?
- How should oversized or malformed requests be handled?
- How would rate limiting protect ETRM?
- What is transport-layer security?
- How should certificates be governed?
- How would you prevent replay attacks?
- How should idempotency keys be protected?
- How should message queues be secured?
- How would you authorise message producers and consumers?
- How should sensitive message fields be encrypted?
- What data should never appear in integration logs?
- How should external vendor connectivity be controlled?
- How would you revoke a compromised integration identity?
- What security testing should every interface undergo?
11. the platform scripting language and Custom-Code Security20
- Who should be permitted to create or modify the platform scripting language scripts?
- Who should be allowed to execute scripts?
- How should scripts be reviewed before deployment?
- Why should credentials never be hard-coded?
- How should external endpoints be restricted?
- How should input validation be implemented?
- How would you prevent SQL injection?
- Why should direct database updates be prohibited?
- How should file-system access be constrained?
- How would you prevent unauthorised command execution?
- How should third-party libraries be approved?
- How should dependency vulnerabilities be monitored?
- What static-analysis controls should be applied?
- How should sensitive information be excluded from logs?
- How would you detect malicious or unauthorised script changes?
- How should code signing or artifact integrity be used?
- How would you separate developer and deployment responsibilities?
- How should emergency code changes be reviewed?
- What evidence should accompany a production script?
- How would you retire insecure legacy customisations?
12. Trade and Market-Control Audit20
- What trade activities must be audited?
- How should original trade capture be recorded?
- What evidence should accompany an amendment?
- How should cancellations and terminations be audited?
- How should manual price overrides be recorded?
- What evidence should support an off-market trade?
- How should portfolio transfers be audited?
- How should user-entered market data be controlled?
- What evidence should accompany curve overrides?
- How should corrected fixings remain traceable?
- How should trader and approver identities be preserved?
- What timestamps are required?
- How should system-generated and manual changes be distinguished?
- How would you report transactions changed after cut-off?
- How should bulk changes remain traceable?
- What controls prevent audit records from being altered?
- How long should trade audit information be retained?
- How would you retrieve evidence for a particular transaction?
- How should historical audit data remain accessible after upgrades?
- How would you prove that audit coverage is complete?
13. Settlement, Payment and Accounting Controls20
- How should settlement-instruction changes be authorised?
- What controls should apply to bank-account changes?
- How would callback or independent verification complement system controls?
- How should one-time settlement instructions be managed?
- Who should be allowed to release payments?
- How would you prevent duplicate payments?
- How should urgent manual payments be controlled?
- What evidence should support payment cancellation or recall?
- How should invoice amendments be audited?
- Who should approve credit and debit notes?
- How should disputed settlements be controlled?
- What controls should govern accounting-rule changes?
- How should manual journals be authorised?
- How would you detect unbalanced postings?
- How should period-close access be restricted?
- What controls apply to backdated accounting changes?
- How should rejected postings be monitored?
- How would you reconcile ETRM with payment and ledger systems?
- What access should auditors receive?
- How would you demonstrate completeness of financial controls?
14. Audit Logging and Evidence20
- What is the difference between application logging and an audit trail?
- Which user activities should generate audit records?
- Which administrative activities should be audited?
- What fields should an audit record contain?
- How should before-and-after values be preserved?
- How should timestamps be standardised?
- Why is reliable time synchronisation important?
- How should correlation identifiers support investigations?
- How would you protect audit logs from alteration?
- Should administrators be able to delete their own audit records?
- How should audit logs be centralised?
- What retention period should apply?
- How would you make archived logs searchable?
- How should log access be restricted?
- What events should trigger real-time alerts?
- How would you detect unusual transaction activity?
- How should failed login attempts be analysed?
- How would you distinguish user and service-account actions?
- What evidence is required to demonstrate control execution?
- How would you test audit logging after an upgrade?
15. Monitoring and Security Analytics20
- Which ETRM security events should be monitored?
- How should ETRM logs integrate with a SIEM?
- What constitutes suspicious access behaviour?
- How would you detect excessive failed logins?
- How would you identify access from unusual locations or hosts?
- How should privilege escalation be detected?
- How would you detect unauthorised portfolio access?
- How should mass trade amendments be monitored?
- How would you identify unusual data exports?
- What alerts should bank-account changes generate?
- How should emergency-access activity be monitored?
- How would you detect service-account misuse?
- What is a security use case?
- How should alert severity be assigned?
- How would you reduce false positives?
- Who should investigate security alerts?
- How should security and operational incidents be correlated?
- What evidence should be retained during investigation?
- How would you measure security-monitoring effectiveness?
- How should lessons from incidents improve controls?
16. Joiner, Mover and Leaver Controls20
- How should new ETRM access be requested?
- Who should approve a new user's roles?
- How should employment status be verified?
- How should access start and expiry dates be controlled?
- How would you manage contractor access?
- What happens when a user changes desks?
- How should obsolete roles be removed?
- How quickly should leaver access be revoked?
- How would you handle immediate termination?
- How should dormant accounts be detected?
- What happens to reports or processes owned by a departing user?
- How should service ownership be reassigned?
- How would you reconcile ETRM users with the identity directory?
- What exceptions should a reconciliation detect?
- How should unresolved identity exceptions be escalated?
- How would you test the leaver process?
- What evidence should demonstrate timely removal?
- How should rehires be handled?
- How would you prevent old entitlements being automatically restored?
- Who owns the complete joiner-mover-leaver control?
17. Access Reviews and Recertification20
- Why is periodic access recertification required?
- Which ETRM access should be reviewed most frequently?
- Who should certify business access?
- Who should certify privileged access?
- What information should reviewers receive?
- How would you make reviews risk-based?
- How should toxic combinations be highlighted?
- How should unused access be identified?
- What constitutes meaningful certification?
- How would you prevent automatic approval?
- What happens when reviewers do not respond?
- How quickly should rejected access be removed?
- How should remediation be evidenced?
- How would you review service accounts?
- How should emergency accounts be certified?
- How would you measure recertification completeness?
- What sampling should independent control teams perform?
- How should access-review findings influence role redesign?
- How would you demonstrate the control to an auditor?
- What indicates that the certification process is ineffective?
18. Change, Release and Environment Security20
- How should ETRM security configuration move between environments?
- Who should approve entitlement changes?
- How should configuration changes be versioned?
- How would you detect security-configuration drift?
- Who should be able to deploy production changes?
- How should developer access differ across environments?
- Should developers have permanent production access?
- How should emergency deployments be controlled?
- What security testing should precede release?
- How would you test negative permissions?
- How should test accounts be governed?
- How should production data be protected in lower environments?
- What evidence should accompany a release?
- How should deployment artifacts be protected?
- How would you verify artifact integrity?
- What should post-deployment security validation cover?
- How should rollback preserve security?
- What if a release creates excessive permissions?
- Which security findings should block release?
- How should upgrade testing validate existing entitlements and audit trails?
19. Incident Response and Resilience20
- What constitutes an ETRM security incident?
- How should suspected credential compromise be handled?
- What actions should follow unauthorised transaction activity?
- How would you preserve forensic evidence?
- When should an account be disabled immediately?
- How should business continuity be considered during containment?
- How would you rotate compromised service credentials?
- How should dependent integrations be recovered?
- What if audit logging was unavailable during an incident?
- How would you determine the affected period?
- How should sensitive data exposure be assessed?
- Who should participate in incident response?
- How should regulators or clients be informed?
- What should a post-incident review contain?
- How should corrective actions be prioritised?
- How would you test an ETRM security-response plan?
- How should backup credentials be secured?
- How should disaster-recovery access be governed?
- What security controls must remain operational during recovery?
- How would you prove that normal access was restored safely?
20. Architecture Scenarios20
- A trader can book into another desk's portfolio. How would you investigate?
- A user can create and validate the same trade. What control is missing?
- Operations can change bank details and release payment. How should access change?
- A service account has full administrative access. How would you remediate it?
- A terminated employee's account remains active. What controls failed?
- A developer deploys an unreviewed the platform scripting language script directly to production. What weaknesses exist?
- Audit logs show a change but not the previous value. Is the evidence sufficient?
- A shared account was used for a manual curve override. How would you establish accountability?
- A user receives access through several roles that collectively create a conflict. How should it be detected?
- A privileged account is used daily because standard access is inconvenient. How would you respond?
- An API credential appears in application logs. What immediate actions are required?
- A payment file contains unauthorised bank details despite correct ETRM permissions. What else should be examined?
- A production database copy is placed in testing without masking. What risks and actions arise?
- A user exports all counterparty data before leaving the company. Which controls should detect this?
- An emergency fix bypasses normal approval. What retrospective controls are required?
- An upgrade silently resets several entitlements. How should testing and monitoring detect it?
- A vendor requests permanent administrator access for support. Would you approve it?
- Business management repeatedly approves segregation conflicts without remediation. Is the control effective?
- The company has extensive audit logs but never reviews them. What capability is missing?
- What distinguishes an ETRM security architect from an identity administrator or IT auditor?
Infrastructure, Cloud, HA and Disaster Recovery26 sections · 530 questions
1. Infrastructure Architecture Fundamentals20
- Describe the infrastructure layers supporting an enterprise ETRM implementation.
- How would you translate logical architecture into physical deployment architecture?
- Which ETRM components are stateful?
- Which components can be treated as stateless?
- What information is required before designing the infrastructure?
- How should business criticality influence infrastructure design?
- What are the principal ETRM workload categories?
- How do interactive, integration, grid and batch workloads differ?
- How would you identify infrastructure dependencies?
- What constitutes a single point of failure?
- How would you document component-to-host allocation?
- What should an infrastructure architecture document contain?
- How should production and non-production designs differ?
- How would you determine environmental sizing ratios?
- What is infrastructure headroom?
- How much capacity should remain available during normal operation?
- How should failure-mode analysis influence design?
- What is fault isolation?
- How would you avoid one workload affecting the entire platform?
- How would you validate vendor certification and supportability?
2. Compute and Host Architecture20
- How would you size compute for ETRM services?
- Which workload characteristics drive CPU requirements?
- Which workloads are memory-intensive?
- How should interactive services be separated from batch services?
- When should dedicated hosts be used?
- When is shared infrastructure acceptable?
- How would you select virtual-machine sizes?
- What risks arise from heavily oversized virtual machines?
- What risks arise from undersized infrastructure?
- How would you monitor CPU saturation?
- What does sustained high CPU indicate?
- How would you investigate low CPU with poor performance?
- How should memory utilisation be monitored?
- What is the difference between memory pressure and a memory leak?
- How would you detect swapping or paging?
- How can NUMA architecture affect large workloads?
- How should host-level concurrency be controlled?
- How would noisy neighbours affect ETRM?
- How should compute capacity support month-end peaks?
- When should vertical scaling give way to workload redesign?
3. Operating-System Architecture20
- Which operating-system requirements should be validated for ETRM?
- How should supported versions be governed?
- How would you manage operating-system hardening?
- What ETRM-specific exceptions might require approval?
- How should service accounts be configured?
- What file-system permissions should services receive?
- How should process limits be configured?
- How would you manage environment variables and configuration paths?
- How should temporary directories be sized and monitored?
- What risks arise from insufficient temporary space?
- How should system time be synchronised?
- Why is clock drift dangerous for trading systems?
- How should locale and timezone settings be governed?
- How would you manage operating-system patching?
- What testing should precede kernel or system-library changes?
- How should endpoint-protection software be configured?
- Can antivirus scanning affect ETRM performance?
- How should exclusions be controlled and reviewed?
- What operating-system telemetry should be retained?
- How would you detect configuration drift across hosts?
4. Network Architecture25
- What network flows does an ETRM implementation require?
- How would you document connectivity?
- How should network segmentation be designed?
- Which components should reside in separate security zones?
- How would you restrict inbound and outbound connectivity?
- What is the principle of least connectivity?
- How should firewalls be configured?
- How would you manage port and protocol inventories?
- How can network latency affect ETRM clients?
- How does latency affect grid processing?
- How would you measure network latency and packet loss?
- What is connection-state exhaustion?
- How should load balancers be used?
- Which health checks should a load balancer perform?
- What are the risks of relying only on TCP health checks?
- How should DNS support high availability?
- How would DNS caching affect failover?
- How should certificates and TLS be managed?
- How would you connect market-data providers securely?
- How should exchanges, banks and clearing platforms connect?
- What is private connectivity?
- When is public internet connectivity unacceptable?
- How would proxy infrastructure affect integrations?
- How should bandwidth requirements be estimated?
- How would you diagnose intermittent network-related failures?
5. Database Infrastructure25
- How would you design the database platform supporting ETRM?
- Which database capabilities are critical for ETRM?
- How should database compute and memory be sized?
- What storage characteristics influence database performance?
- How should transaction logs be provisioned?
- How would you manage temporary database space?
- What causes database I/O bottlenecks?
- How should indexes and statistics be maintained?
- How would you control database connection counts?
- What happens when connection pools are exhausted?
- How should database credentials be protected?
- Why should direct writes to core ETRM tables be prohibited?
- How should privileged database access be monitored?
- How would you design database high availability?
- What is synchronous versus asynchronous replication?
- What data-loss trade-off accompanies asynchronous replication?
- How can synchronous replication affect transaction latency?
- How should database backups be designed?
- How would you validate point-in-time recovery?
- How should database recovery align with message and file recovery?
- What happens if the database is restored without dependent integration state?
- How should database maintenance be scheduled?
- How would you perform database patching with minimal disruption?
- How should database growth be forecast?
- What evidence demonstrates database recoverability?
6. Storage and File-System Architecture20
- Which ETRM components depend on shared or local storage?
- How would you classify persistent and temporary files?
- When is shared storage necessary?
- What availability risks accompany shared file systems?
- How should storage throughput and latency be measured?
- What is IOPS?
- Which ETRM workloads are sensitive to storage latency?
- How should temporary processing space be sized?
- How would you prevent disk exhaustion?
- What alerts should storage monitoring generate?
- How should file retention be governed?
- How would you protect interface landing zones?
- How should file permissions be configured?
- What controls should prevent partial files from being processed?
- How would you implement atomic file delivery?
- How should backups of file-based state align with database backups?
- How would you replicate shared files to disaster recovery?
- What consistency risk arises from asynchronous file replication?
- How should archived data remain accessible?
- When should object storage be used?
7. Middleware and Integration Infrastructure20
- Which middleware components commonly surround ETRM?
- When should an API gateway be introduced?
- How should message brokers support resilient integration?
- What availability level should a trade-ingestion queue provide?
- How should messages survive broker failure?
- How would you prevent duplicate processing after recovery?
- How should consumer concurrency be configured?
- What is back-pressure?
- How should accumulated messages be managed after an outage?
- How would you prioritise critical message types?
- How should dead-letter queues be protected?
- What monitoring should middleware expose?
- How should schema registries be made highly available?
- How would you manage integration certificates?
- How should secret-management services be made resilient?
- What happens when ETRM is available but middleware is unavailable?
- What happens when middleware is available but ETRM is unavailable?
- How should cross-site message replication be designed?
- How would you test integration failover?
- What reconciliation proves messaging recovery was complete?
8. ETRM Service Deployment20
- How should ETRM services be distributed across hosts?
- Which services should be isolated by workload?
- How would you determine the number of service instances?
- Which services require automatic restart?
- When can automatic restart hide a recurring defect?
- How should service dependencies be represented?
- How should service startup and shutdown be ordered?
- What makes a service health check meaningful?
- How would you detect a service that is running but stalled?
- What is the difference between liveness and readiness?
- How should service configuration be versioned?
- How would you prevent inconsistent configuration across instances?
- How should environment-specific settings be externalised?
- How should service credentials be injected securely?
- How would you manage service log files?
- How should log rotation be configured?
- How would you prevent log volumes exhausting storage?
- What diagnostic information should be captured before restarting?
- How should service restarts be audited?
- What post-restart validation is required?
9. Grid Infrastructure20
- What infrastructure supports ETRM grid computing?
- How should coordinators and workers be deployed?
- Which grid components require high availability?
- How should worker hosts be sized?
- Should all workers use identical configurations?
- How would heterogeneous workers affect workload distribution?
- How should worker concurrency be determined?
- What shared resources can constrain grid scalability?
- How can the database become a grid bottleneck?
- How does network latency affect distributed valuation?
- What happens when a worker host fails?
- How should unfinished work be reassigned?
- How would you prevent duplicate result production?
- What happens when the coordinator fails?
- How should grid queues survive failover?
- How would you detect an unhealthy worker?
- How should worker images or builds be controlled?
- How would you scale grid capacity for end-of-day?
- When is temporary capacity useful?
- How should grid failover be tested under realistic workload?
10. Virtualisation Architecture20
- What benefits does virtualisation provide to ETRM?
- What risks does virtualisation introduce?
- How should CPU overcommitment be assessed?
- Why can CPU ready time matter?
- How can memory ballooning affect performance?
- How should storage contention be monitored?
- What is a noisy-neighbour problem?
- How should affinity and anti-affinity rules be used?
- Which components should not share a failure domain?
- How would live migration affect latency-sensitive services?
- How should hypervisor maintenance be planned?
- What monitoring should include hypervisor-level metrics?
- How would you establish reservation and limit policies?
- Should disaster-recovery capacity share production clusters?
- How would you prevent simultaneous loss of redundant instances?
- How should virtual-machine templates be governed?
- How would you patch base images?
- What tests should follow virtualisation-platform upgrades?
- How should licensing implications be evaluated?
- When is physical infrastructure still justified?
11. Cloud Architecture Fundamentals20
- What factors determine ETRM's suitability for cloud hosting?
- How would you assess vendor-supported cloud configurations?
- What is the shared-responsibility model?
- How would you map ETRM components to cloud services?
- Which managed services could reduce operational burden?
- Which managed services could create supportability risk?
- How should cloud accounts or subscriptions be structured?
- How would you separate production and non-production environments?
- How should cloud network segmentation be designed?
- What is a landing zone?
- How should policies and guardrails be applied?
- How would you prevent uncontrolled public exposure?
- How should private endpoints be used?
- How would you manage cross-region connectivity?
- What latency constraints influence region selection?
- How should data-residency requirements influence placement?
- How would you evaluate cloud concentration risk?
- How should architecture account for provider service limits?
- What assumptions require proof-of-concept testing?
- Why should ETRM not automatically be treated as cloud-native?
12. Cloud Compute, Containers and Orchestration20
- When are cloud virtual machines appropriate?
- Which ETRM workloads can scale horizontally?
- Which workloads remain constrained by state?
- When could autoscaling be useful?
- Why may reactive autoscaling be too slow for end-of-day?
- How should predictable batch peaks be handled?
- Where could containers be useful around ETRM?
- Why may containerising every ETRM component be inappropriate?
- What vendor-support questions apply to containers?
- How should persistent state be separated from containers?
- How would container orchestration manage health and restart?
- What risks arise from aggressive automatic restart?
- How should container images be secured?
- How would you control image provenance?
- How should secrets be supplied to containers?
- How should resource requests and limits be configured?
- What happens when memory limits terminate a process?
- How should logs and metrics be exported?
- How would you manage rolling upgrades?
- When is conventional virtual-machine deployment safer?
13. Cloud Storage, Database and Networking20
- How would you select cloud storage for an ETRM database?
- Which latency and throughput guarantees are required?
- How should managed databases be evaluated?
- What ETRM support limitations might affect selection?
- How should database availability zones be configured?
- What latency can synchronous multi-zone replication introduce?
- How should backups be stored across accounts or regions?
- How would immutable backups improve resilience?
- How should object storage support archives and extracts?
- How would you secure cloud storage buckets?
- How should private connectivity to ETRM be implemented?
- What is a transit network?
- How would you connect corporate data centres?
- How should routing failover be designed?
- How would you resolve cloud DNS during regional failure?
- What happens when identity or key-management services are unavailable?
- How should cloud service quotas be monitored?
- How would you protect against accidental resource deletion?
- How should infrastructure events be correlated with ETRM monitoring?
- What cloud dependencies must be included in disaster-recovery testing?
14. Infrastructure as Code and Configuration Management20
- What is infrastructure as code?
- Which ETRM infrastructure should be codified?
- How would infrastructure code improve disaster recovery?
- How should modules and reusable patterns be structured?
- How would you separate code from environment configuration?
- How should secrets be excluded from source control?
- How would you review infrastructure changes?
- What should a CI/CD pipeline validate?
- How would you detect configuration drift?
- How should emergency manual changes be reconciled?
- What is immutable infrastructure?
- Where is immutability practical around ETRM?
- How should host configuration be automated?
- How would you version firewall and load-balancer rules?
- How should deployment dependencies be represented?
- What evidence should accompany infrastructure release?
- How would you roll back an infrastructure change?
- When could rollback be more dangerous than remediation?
- How should production and disaster-recovery configurations be compared?
- How would you prove that an environment can be rebuilt?
15. High-Availability Fundamentals20
- What is high availability?
- How does high availability differ from disaster recovery?
- What availability target should ETRM provide?
- How would business impact determine availability requirements?
- What is an availability zone or failure domain?
- How should redundant components be separated?
- What is active-active architecture?
- What is active-passive architecture?
- When is active-active unsuitable?
- How would you calculate theoretical availability?
- Why does component redundancy not guarantee service availability?
- How should dependent services affect availability calculations?
- What is graceful degradation?
- Which capabilities could be temporarily degraded?
- How should automated failover be governed?
- When is manual failover safer?
- What split-brain risk exists?
- How should quorum be established?
- What evidence proves that high availability works?
- How frequently should failover be tested?
16. Application and Service High Availability20
- How should redundant ETRM services be deployed?
- How would you handle services that maintain local state?
- How should sessions behave during failover?
- What happens to active user operations?
- How should in-flight batch work be recovered?
- How would you prevent two active instances processing the same job?
- What is leader election?
- How should scheduled jobs avoid duplicate execution?
- How would you manage shared service configuration?
- How should load balancers remove unhealthy instances?
- What constitutes a readiness check?
- How would you test application failover?
- How should business users be notified?
- What information should be captured during failover?
- How would you validate business functionality after recovery?
- What happens if services recover before the database?
- How should dependent integrations reconnect?
- How would queued requests be drained safely?
- What post-failover reconciliation is required?
- When should service failback occur?
17. Database High Availability20
- What database high-availability patterns are available?
- How should primary and standby databases be configured?
- What is automatic database failover?
- What risks accompany automatic failover?
- How should replication lag be monitored?
- When is zero data loss technically achievable?
- What performance cost can synchronous replication introduce?
- How would ETRM connections locate the new primary?
- How should connection pools respond to failover?
- What happens to uncommitted transactions?
- How should partially completed business processes recover?
- How would you prevent writes to both database copies?
- What is a fencing mechanism?
- How should read replicas be used?
- Can reporting safely use a delayed replica?
- How would you validate database failover?
- How should data consistency be checked?
- What application reconciliation is required?
- When should the original primary be reintroduced?
- How should failback be planned?
18. Backup and Restore20
- How do backup and high availability differ?
- What ETRM data and configuration must be backed up?
- How should backup frequency be determined?
- What is a full, differential or incremental backup?
- What is point-in-time recovery?
- How should transaction-log backups support recovery objectives?
- Where should backups be stored?
- Why should backups be isolated from production credentials?
- What is an immutable backup?
- How would immutable backups mitigate ransomware?
- How should backup encryption keys be protected?
- How long should backups be retained?
- How would regulatory retention affect policy?
- How should backup success be monitored?
- Why is backup completion not proof of recoverability?
- How frequently should restore tests occur?
- What should a restore test validate?
- How should database and file backups remain consistent?
- How would you recover accidentally deleted reference data?
- What evidence should backup controls produce?
19. Disaster-Recovery Strategy20
- What constitutes a disaster for an ETRM service?
- How should disaster scenarios be identified?
- What is a business-impact analysis?
- What is recovery time objective?
- What is recovery point objective?
- What is maximum tolerable downtime?
- How should RTO and RPO be agreed?
- Why should every component not receive identical targets?
- How would you select an alternate recovery location?
- How should regional correlation risk be considered?
- What infrastructure must exist at the recovery site?
- What can be provisioned only after disaster declaration?
- How should capacity at disaster recovery be sized?
- Can reduced-capacity recovery be acceptable?
- Which ETRM functions must recover first?
- How should recovery waves be defined?
- How would external dependencies be recovered?
- What happens if a market-data provider cannot serve the recovery site?
- How should users connect after recovery?
- What constitutes business service restoration?
20. Disaster-Recovery Data Consistency20
- How should database replication support disaster recovery?
- How does replication differ from backup?
- What happens when replication transfers corrupted data?
- How should message queues be recovered?
- How would you reconcile database and broker recovery points?
- What happens to files transferred shortly before failure?
- How should in-flight API requests be handled?
- How would you identify transactions with indeterminate outcomes?
- How should external systems resubmit safely?
- What role does idempotency play in disaster recovery?
- How should ETRM-generated outbound events be reconciled?
- How would you prevent duplicate confirmations or payments?
- How should official market-data snapshots be recovered?
- How would you preserve batch checkpoints?
- What happens if reference data and transactions recover to different times?
- How would you establish a common recovery point?
- What reconciliation should precede business reopening?
- How should unrecoverable differences be managed?
- Who should approve resumption of trading?
- What evidence should support recovery sign-off?
21. Disaster-Recovery Execution and Testing20
- Who should declare a disaster?
- What should a disaster-recovery runbook contain?
- How should technical and business responsibilities be divided?
- What is the required component recovery order?
- How should credentials and certificates be activated?
- How would DNS and routing be switched?
- How should integrations be redirected?
- How would users be informed?
- What technical validation should follow recovery?
- What business validation should follow recovery?
- How should positions and P&L be reconciled?
- How should settlements and payments be checked?
- What is a tabletop exercise?
- How does a technical failover test differ from a full business test?
- How often should recovery tests occur?
- Why should tests include realistic transaction volume?
- How would you test an unplanned failover?
- How should findings be recorded?
- Who owns remediation?
- What makes a disaster-recovery test genuinely successful?
22. Cyber Resilience20
- How does cyber recovery differ from conventional disaster recovery?
- Why may immediate failover be unsafe during a cyberattack?
- How would you identify a clean recovery point?
- What is an isolated recovery environment?
- How should privileged credentials be recovered?
- How would you verify that restored systems are uncompromised?
- How should immutable backups support cyber recovery?
- What if both production and replicated data are corrupted?
- How would you rebuild infrastructure from trusted artifacts?
- How should ETRM custom code be integrity-checked?
- How would you validate database content before reopening?
- What security monitoring must operate in recovery?
- How should compromised integrations be isolated?
- How would new credentials be distributed?
- What manual business processes are needed during cyber recovery?
- How should accumulated trades be captured after restoration?
- What reconciliations are required?
- How would you prevent reinfection?
- Who should approve return to normal operation?
- How should cyber-recovery exercises be conducted?
23. Monitoring and Observability20
- What should an ETRM infrastructure dashboard display?
- Which host metrics should be monitored?
- Which database metrics are essential?
- Which network metrics should be retained?
- How should storage latency be monitored?
- How would you monitor ETRM-service health?
- What is synthetic monitoring?
- How could synthetic transactions validate business service?
- How would you detect a service that is alive but unable to process?
- How should correlation identifiers support diagnostics?
- How should infrastructure and application logs be centralised?
- What alert thresholds should reflect business impact?
- How would you prevent alert fatigue?
- What is anomaly-based monitoring?
- How should certificate expiry be monitored?
- How should backup and replication failures be alerted?
- How would you monitor disaster-recovery readiness?
- What data supports capacity planning?
- How long should operational telemetry be retained?
- How would observability shorten recovery time?
24. Maintenance, Patching and Upgrades20
- How should infrastructure maintenance windows be planned?
- How would you patch redundant components without full outage?
- What testing should precede operating-system patching?
- How should database patching be validated?
- How would middleware patches affect ETRM integrations?
- How should certificate changes be tested?
- What is configuration drift after patching?
- How should firmware and hypervisor updates be governed?
- What rollback plan should accompany maintenance?
- When may rollback be impossible?
- How should maintenance interact with end-of-day schedules?
- How would you coordinate global business calendars?
- What pre-maintenance health checks are required?
- What post-maintenance business checks are required?
- How should failed maintenance be escalated?
- What evidence should accompany completion?
- How should vendor support be engaged?
- When should a patch be expedited?
- What conditions should delay maintenance?
- How would you measure patching effectiveness?
25. Capacity and Cost Management20
- How would you forecast infrastructure capacity?
- Which ETRM growth drivers matter?
- How should trade complexity influence sizing?
- How do hourly profiles affect storage and compute?
- How should additional grid workloads be forecast?
- What headroom is required for failure conditions?
- How would you size disaster-recovery capacity?
- How should month-end and year-end peaks be considered?
- When should capacity be added?
- How would you detect capacity-risk trends?
- What is cloud cost allocation?
- How should ETRM costs be attributed?
- How would you optimise cost without compromising resilience?
- When is reserved capacity appropriate?
- When can temporary compute reduce cost?
- How should storage lifecycle policies be used?
- What hidden network costs should be considered?
- How would you compare on-premises and cloud total cost?
- What business assumptions should accompany the comparison?
- When should cost concerns trigger architecture redesign?
26. Architecture Scenarios20
- ETRM is available, but users cannot connect after a load-balancer failover. What would you investigate?
- Database failover succeeds, but services retain stale connections. How should recovery work?
- Both redundant services run the same scheduled batch. What control is missing?
- Grid workers remain healthy, but throughput collapses. Which shared dependencies should be checked?
- A shared file system fails and stops all interfaces. How would you remove the single point of failure?
- Disaster recovery restores the database but loses recent messages. What reconciliation is required?
- The recovery site starts successfully but cannot receive market data. Was the service recovered?
- A backup completes daily but has never been restored. Is the control effective?
- Synchronous cross-region replication causes unacceptable trade-entry latency. How would you frame the trade-off?
- Cloud autoscaling adds workers after end-of-day has already breached its SLA. What should change?
- A security agent consumes significant CPU during valuation runs. How should this be resolved?
- Infrastructure monitoring is green, but ETRM cannot value trades. What monitoring layer is missing?
- The disaster-recovery environment has half production capacity. When could this be acceptable?
- Production and recovery sites share the same identity provider. What dependency risk exists?
- A regional cloud outage also affects the configured backup store. What design principle failed?
- An automated restart repeatedly clears symptoms without preserving diagnostics. How would you correct operations?
- DNS caching delays failover for several hours. What should have been designed and tested?
- Ransomware corruption replicates immediately to disaster recovery. What recovery capability is required?
- The business requests zero downtime and zero data loss across regions. What costs and technical constraints must be challenged?
- What distinguishes an ETRM infrastructure architect from a cloud engineer, database administrator or disaster-recovery manager?
Configuration Management, Testing and CI/CD25 sections · 500 questions
1. Configuration-Management Fundamentals20
- What constitutes configuration in an ETRM implementation?
- How does configuration differ from reference data, code and infrastructure?
- Why should ETRM configuration be treated as a controlled software asset?
- Which configuration domains are business-critical?
- How would you inventory existing ETRM configuration?
- What metadata should accompany each configuration item?
- How should configuration ownership be assigned?
- How would you establish a configuration baseline?
- What is configuration drift?
- How would you detect drift between environments?
- How should configuration dependencies be documented?
- How would you identify orphaned configuration?
- How should duplicate configuration be rationalised?
- What is the difference between global and desk-specific configuration?
- How would you prevent unnecessary configuration variants?
- How should configuration standards be governed?
- What is a configuration-management plan?
- How should emergency configuration changes be handled?
- How would you preserve historical configuration states?
- What evidence demonstrates effective configuration control?
2. Configuration Classification and Ownership20
- How would you classify ETRM configuration by domain?
- Which configuration should business teams own?
- Which configuration should technology own?
- Who should own instruments and deal templates?
- Who should own curves, indexes and market-data mappings?
- Who should own portfolios and organisational structures?
- Who should own settlement and accounting configuration?
- Who should own simulations and reports?
- How should shared configuration be governed?
- What happens when multiple teams claim ownership?
- How should criticality influence approval requirements?
- Which changes require independent review?
- How would you document the authorised use of each item?
- How should configuration naming conventions be designed?
- How would you prevent free-text configuration from becoming uncontrolled?
- How should effective dates be managed?
- How should obsolete items be retired?
- How would you identify configuration still referenced by active trades?
- What is the role of a configuration owner during an upgrade?
- How should ownership transfer when teams reorganise?
3. Source Control20
- Which ETRM artifacts should be stored in source control?
- How should the platform scripting language and Java code be organised?
- How should SQL, report and interface artifacts be stored?
- Can all ETRM configuration be represented as text?
- How would you manage configuration that is difficult to diff?
- How should exported configuration packages be versioned?
- What repository structure would you use?
- How should shared libraries be separated from project code?
- What branching strategy is appropriate?
- How should release branches be managed?
- What is trunk-based development?
- When could short-lived feature branches be preferable?
- How should commit messages support traceability?
- How would you associate changes with requirements and defects?
- How should peer review be enforced?
- Who may approve production-bound changes?
- How would you protect the main branch?
- How should binary artifacts be handled?
- What risks arise from storing credentials in source control?
- How would you recover when production code is absent from the repository?
4. Versioning and Dependency Management20
- How should ETRM custom components be versioned?
- What is semantic versioning?
- When is semantic versioning useful for internal components?
- How should configuration-package versions be assigned?
- How would you identify the exact version running in production?
- What should a release manifest contain?
- How should dependencies among scripts be declared?
- How should dependencies on user tables be managed?
- How should dependencies on ETRM APIs be recorded?
- How would you manage third-party Java libraries?
- What risks arise from unpinned dependency versions?
- How would you prevent conflicting library versions?
- How should external API versions be tracked?
- How would you identify deprecated functions before an upgrade?
- What is a software bill of materials?
- Should custom ETRM components maintain one?
- How should dependency vulnerabilities be monitored?
- How would you verify artifact integrity?
- What is artifact provenance?
- How should dependency changes be regression-tested?
5. Environment Strategy20
- Which ETRM environments should an enterprise maintain?
- What is the purpose of development, test, UAT and production environments?
- When is a dedicated integration-test environment required?
- When is a performance environment necessary?
- Should disaster recovery be treated as a test environment?
- How should environments differ in scale?
- Which characteristics must remain production-like?
- How would you manage environment-specific identifiers?
- How should endpoints and credentials differ?
- How would you prevent production connections from lower environments?
- How should business dates be controlled?
- How should market data be provided to testing?
- What are the risks of copying production data?
- How should copied data be masked?
- How would you manage test-user entitlements?
- How should shared testing environments be scheduled?
- What causes environment contention?
- How would you refresh an environment?
- What controls should surround refresh?
- How would you prove that environments have not drifted?
6. Change-Management Process20
- What should initiate an ETRM change?
- How should requirements be assessed?
- What belongs in an impact assessment?
- How would you identify affected products and processes?
- How should architecture review participate?
- Which changes require formal design approval?
- How should risk and criticality be assessed?
- What is a standard change?
- What is a normal change?
- What is an emergency change?
- How should change categories affect approval?
- What evidence should accompany a change request?
- How should segregation of duties apply?
- Who should approve business-rule changes?
- Who should approve infrastructure changes?
- How should implementation and rollback plans be reviewed?
- What is a change collision?
- How would you identify conflicting releases?
- What should a change advisory board evaluate?
- When should a change be rejected?
7. Requirements Traceability20
- What is requirements traceability?
- How would you link requirements to designs?
- How should designs link to configuration and code?
- How should test cases link back to requirements?
- What is a requirements traceability matrix?
- Which requirements require negative test cases?
- How would you trace regulatory requirements?
- How should non-functional requirements be represented?
- How would you ensure every requirement is tested?
- How should scope changes affect test coverage?
- What happens when code has no corresponding requirement?
- How would you handle undocumented legacy behaviour?
- How should defects link to failed tests?
- How should acceptance criteria be written?
- What makes an acceptance criterion objectively testable?
- How would you trace production verification?
- Who owns traceability completeness?
- How should evidence be retained?
- How would auditors use traceability?
- What indicates that traceability is only administrative rather than effective?
8. Test Strategy and Governance20
- What should an ETRM test strategy contain?
- How should testing reflect business risk?
- What are the principal ETRM testing levels?
- How do unit, component, integration, system and acceptance tests differ?
- What is functional testing?
- What is non-functional testing?
- What is regression testing?
- What is smoke testing?
- What is exploratory testing?
- How should positive and negative testing differ?
- How would you define test entry criteria?
- How would you define exit criteria?
- What is a test oracle?
- How should expected results be established independently?
- Who should approve the test strategy?
- How should test independence be achieved?
- What should determine test depth?
- How should defects be classified?
- When can unresolved defects be accepted?
- What evidence demonstrates release readiness?
9. Unit and Component Testing20
- What ETRM logic can be unit-tested?
- How would you isolate business logic from ETRM APIs?
- How do adapters and wrappers improve testability?
- How would you test the platform scripting language components?
- How would you test Java extensions?
- What dependencies should be mocked?
- What are the limitations of mocking?
- How would you test table-processing logic?
- How should database queries be tested?
- How would you test validation rules?
- How should exception handling be tested?
- How would you test resource cleanup?
- How should logging behaviour be verified?
- What code-coverage target is meaningful?
- Why is high code coverage not proof of quality?
- How should boundary conditions be tested?
- How would you test null and missing values?
- How should repeated execution be tested?
- What makes a unit test deterministic?
- When should a component test require a real ETRM environment?
10. Functional Product Testing20
- How would you test a new ETRM instrument?
- What should a golden transaction contain?
- How should fixed and floating legs be tested?
- How would you test multi-leg structures?
- How should trade amendments be tested?
- How would you test cancellation and termination?
- How should novation and partial unwind be tested?
- How would you test physical delivery profiles?
- How should provisional pricing be tested?
- How would you test corrected fixings?
- How should unit conversions be validated?
- How would you test business-day conventions?
- How should daylight-saving transitions be tested?
- How would you test negative commodity prices?
- How should zero and negative quantities be handled?
- How would you test transaction templates?
- How should product restrictions be tested?
- How would you verify audit history?
- Which lifecycle stages must a new product traverse?
- What proves that a product is operationally complete?
11. Valuation and Risk Testing20
- How would you validate ETRM valuation independently?
- What constitutes a valuation benchmark?
- How should cash flows be compared?
- How would you validate discounting?
- How should forward-curve use be tested?
- How would you test partially fixed transactions?
- How should multicurrency valuation be tested?
- How would you validate option models?
- How should Greeks be tested?
- What is sensitivity bump testing?
- How would you test position aggregation?
- How should basis and location risk be validated?
- How would you test P&L attribution?
- How should VaR results be regression-tested?
- How would you test stress scenarios?
- What tolerances are acceptable?
- How should numerical tolerances be justified?
- What happens when a model upgrade legitimately changes values?
- How should model-version differences be documented?
- What evidence should model validators approve?
12. Middle- and Back-Office Testing20
- How would you test trade-validation workflows?
- How should maker-checker controls be tested?
- How would you test confirmation generation?
- How should electronic matching be tested?
- How would you validate settlement events?
- How should netting rules be tested?
- How would you test provisional and final invoices?
- How should credit and debit notes be tested?
- How would you validate payment instructions?
- How should duplicate-payment prevention be tested?
- How would you test accounting-event generation?
- How should balanced postings be verified?
- How would you test rejected accounting entries?
- How should physical actuals affect invoicing?
- How would you test collateral or margin processing?
- How should business cut-offs be tested?
- How would you validate end-of-day completeness?
- How should failed events be recovered?
- What reconciliations must pass?
- Who should provide business acceptance?
13. Integration and Contract Testing20
- How would you test an inbound trade interface?
- What is API contract testing?
- What is consumer-driven contract testing?
- How should message schemas be validated?
- How would you test backward compatibility?
- How should mandatory and optional fields be tested?
- How would you test duplicate messages?
- How should out-of-order amendments be tested?
- How would you test timeouts with indeterminate outcomes?
- How should retry behaviour be verified?
- How would you test dead-letter processing?
- How should controlled replay be tested?
- How would you verify idempotency?
- How should partial batch failures be tested?
- How would you test missing reference data?
- How should external systems be simulated?
- When is a real external dependency necessary?
- How would you test reconciliation?
- How should interface-volume testing be conducted?
- What proves end-to-end delivery?
14. Data and Migration Testing20
- How would you test ETRM data migration?
- How should source-to-target mappings be validated?
- What is data profiling?
- How would you identify source-data anomalies?
- How should defaulted values be tested?
- How would you validate reference-data dependencies?
- How should duplicate records be detected?
- What control totals should be compared?
- How would you reconcile transaction counts?
- Why are record counts alone insufficient?
- How should quantities, cash flows and positions be reconciled?
- How would you compare valuation and P&L?
- How should open lifecycle events be tested?
- How would you prevent duplicate downstream processing?
- How should rejected records be tracked?
- What is a migration reconciliation dashboard?
- How would you perform repeatable migration rehearsals?
- How should migration defects be prioritised?
- What criteria should block cut-over?
- What evidence supports migration sign-off?
15. Regression Testing20
- What should an ETRM regression suite cover?
- How would you select representative products?
- What are golden trades?
- How should golden portfolios be maintained?
- How would you include unusual lifecycle states?
- How should historical production defects enter regression?
- How would you test unchanged functionality?
- How should reference-data changes affect scope?
- How should an legacy-to-modern ETRM upgrade affect regression depth?
- How would you compare large result datasets?
- What is tolerance-based comparison?
- How should expected legitimate differences be handled?
- How would you detect unintended differences?
- How should regression failures be triaged?
- Which tests should execute on every build?
- Which tests may run nightly?
- Which tests should run before release?
- How would you keep regression runtime manageable?
- Who owns regression-suite maintenance?
- What indicates that a regression suite has become ineffective?
16. Test Data Management20
- What makes ETRM test data representative?
- How would you create a controlled trade library?
- Which commodity products must be represented?
- How should lifecycle states be covered?
- How would you include complex and high-volume profiles?
- How should market-data scenarios be prepared?
- How would you create deterministic fixings and curves?
- Why should tests avoid uncontrolled live market data?
- How should counterparty and settlement data be anonymised?
- What production information must never enter testing?
- How would you generate synthetic transactions?
- How should test-data versions align with test cases?
- How would you reset test data between runs?
- What is test-data pollution?
- How should parallel testers avoid collisions?
- How would you manage business dates?
- How should expired or effective-dated data be tested?
- Who owns the test-data catalogue?
- How should test data be retained?
- What controls prove compliance with privacy requirements?
17. Performance, Resilience and Security Testing20
- How do load, stress, volume, spike and soak tests differ?
- How would you test end-of-day performance?
- How should grid scalability be tested?
- How would you establish representative transaction volume?
- How should concurrent users be simulated?
- How would you validate performance after configuration changes?
- What is failure-injection testing?
- How would you test service failover?
- How should database failover be tested?
- How would you test batch restart?
- How should disaster-recovery testing integrate with release assurance?
- What security testing should custom code undergo?
- How would you test negative entitlements?
- How should segregation of duties be verified?
- How would you test API authentication and authorisation?
- What vulnerability testing applies to third-party libraries?
- How should sensitive information in logs be tested?
- What performance or security findings must block release?
- How should non-functional evidence be retained?
- Who accepts residual non-functional risk?
18. Test Automation20
- Which ETRM tests are suitable for automation?
- Which tests should remain manual?
- How would you prioritise automation?
- What is the automation pyramid?
- Why should end-to-end UI tests not dominate?
- How would you automate API tests?
- How should database-result comparisons be automated?
- How would you automate valuation reconciliation?
- How should large tables be compared efficiently?
- How would you automate lifecycle processing?
- How should business dates be controlled?
- How would you automate negative test cases?
- What makes automated tests repeatable?
- How should test failures retain evidence?
- How would you prevent flaky tests?
- What causes ETRM test automation to become brittle?
- How should reusable test libraries be designed?
- How should automated-test code be reviewed?
- How would you measure automation effectiveness?
- When should an automated test be retired?
19. CI Pipeline Design20
- What should continuous integration mean for ETRM development?
- What should trigger a CI pipeline?
- Which validations should run on every commit?
- How should compilation and syntax checking work?
- How would you introduce code formatting and linting?
- What static analysis should be applied?
- How should unit tests execute?
- How should dependency vulnerabilities be scanned?
- How would you scan for embedded secrets?
- What is a quality gate?
- Which failures should block merging?
- How should build artifacts be produced?
- Why should artifacts be built once and promoted?
- How would you create reproducible builds?
- How should artifacts be signed or checksummed?
- Where should artifacts be stored?
- What retention should apply?
- How should pipeline permissions be controlled?
- How would you protect CI credentials?
- What evidence should a successful build produce?
20. Continuous Delivery and Deployment20
- How does continuous delivery differ from continuous deployment?
- Is fully automatic production deployment appropriate for ETRM?
- Which deployment stages can be automated safely?
- How should approvals be inserted into pipelines?
- How would you package scripts, configuration and database changes?
- How should deployment order be determined?
- How would you validate dependencies before deployment?
- How should environment-specific values be injected?
- What is a deployment manifest?
- How should pre-deployment checks work?
- How would you detect conflicting changes?
- How should services be stopped or drained?
- Which components require restart?
- How should database changes be deployed?
- How would you automate post-deployment smoke tests?
- How should deployment status be communicated?
- What telemetry should be monitored after release?
- When should automatic rollback occur?
- When is automatic rollback unsafe?
- What makes an ETRM deployment production-safe?
21. Release and Deployment Strategies20
- What is a big-bang deployment?
- When could phased deployment be used?
- What is blue-green deployment?
- Where might blue-green be difficult for ETRM?
- What is canary deployment?
- Which ETRM components could support canary techniques?
- How would database compatibility constrain deployment?
- What is backward-compatible configuration?
- How should interface schema changes be staged?
- How would consumers migrate between API versions?
- How should parallel processing be reconciled?
- What is a dark launch?
- How could feature flags be used?
- What risks arise from long-lived feature flags?
- How should cut-over activities be sequenced?
- What is a deployment freeze?
- How should global business calendars affect releases?
- How would you avoid end-of-day disruption?
- What post-release observation period is appropriate?
- When should a release be backed out?
22. Rollback, Recovery and Remediation20
- What should an ETRM rollback plan contain?
- Which changes are easily reversible?
- Which changes are difficult to reverse?
- Why may database rollback be dangerous?
- What happens when new trades use changed configuration?
- How should processed lifecycle events affect rollback?
- How would you handle faulty accounting output?
- How should erroneous payment messages be contained?
- What is forward remediation?
- When is forward remediation safer than rollback?
- How would you identify transactions affected by a defective release?
- How should impacted data be corrected?
- Who should approve remediation?
- How should correction scripts be controlled?
- What testing should correction scripts undergo?
- How would you prevent correction from creating new errors?
- What reconciliations should follow recovery?
- How should stakeholders be informed?
- What audit evidence should be retained?
- How should lessons influence future deployment design?
23. Release Governance20
- What should a production-readiness review cover?
- Who should participate?
- What functional evidence is required?
- What non-functional evidence is required?
- How should open defects be presented?
- Who may accept residual risk?
- What is a release go/no-go decision?
- Which conditions should automatically produce no-go?
- How should vendor dependencies be assessed?
- What operational documentation must exist?
- How should support teams demonstrate readiness?
- What monitoring and alerts must be operational?
- How should rollback feasibility be confirmed?
- What business approvals are required?
- How should release communications be managed?
- What is an early-life-support period?
- How should incidents during early life be handled?
- When should a release be declared stable?
- What metrics should assess release quality?
- How should failed releases improve governance?
24. Audit, Compliance and Evidence20
- What CI/CD activities should be auditable?
- How should code-review evidence be retained?
- How should approvals be linked to artifacts?
- How would you prove that the tested artifact reached production?
- What is artifact provenance?
- How should deployment identities be controlled?
- How would you prevent manual unrecorded deployment?
- How should emergency changes be evidenced?
- What records should demonstrate segregation of duties?
- How should automated test results be retained?
- How should failed quality gates be recorded?
- What evidence supports configuration reconciliation?
- How would you demonstrate environment integrity?
- How should privileged deployment activity be monitored?
- What retention period should apply to release evidence?
- How should auditors retrieve evidence?
- How would you test the effectiveness of deployment controls?
- What indicates that controls are ceremonial?
- How should recurring audit findings be remediated?
- Who owns the end-to-end change-control framework?
25. Architecture Scenarios20
- Test and production contain different portfolio identifiers. How would you design deployment?
- A developer changes production configuration manually and forgets lower environments. What failed?
- An automated deployment succeeds technically but generates incorrect settlement events. What was missing?
- A test suite passes, but it uses only simple financial trades. Is release evidence sufficient?
- A faulty instrument change affects existing trades. How would you identify and remediate them?
- Rollback restores code but cannot reverse generated payments. What recovery approach is required?
- Every release requires several undocumented manual steps. What architectural risk exists?
- Regression testing takes five days and blocks frequent releases. How would you optimise it?
- Automated tests fail intermittently without product defects. How should flaky tests be handled?
- A migration reconciles record counts but not valuation. Should go-live proceed?
- An emergency production fix has no peer review. What controls are required?
- A pipeline rebuilds an artifact separately for each environment. What integrity risk does this create?
- A database script has no rollback because it transforms existing records. What should the release plan contain?
- An upgrade changes valuation legitimately, but the regression suite flags every trade. How should differences be classified?
- Configuration exports cannot be meaningfully compared. How would you establish control?
- Developers have no representative test environment. What delivery risks arise?
- A deployment works in UAT but fails under production volume. Which testing layer was inadequate?
- Business users approve screens but do not test accounting or settlement. Is the product production-ready?
- Management demands fully automatic ETRM production deployment. What limitations and safeguards would you raise?
- What distinguishes an ETRM DevOps architect from a release manager, tester or automation engineer?
Upgrade, Migration and Production Support27 sections · 540 questions
1. Upgrade Strategy and Objectives20
- Why do organisations upgrade ETRM?
- How would you distinguish mandatory and discretionary upgrade drivers?
- What business outcomes should an upgrade deliver?
- How would you assess the risks of remaining on an older version?
- What should an legacy-to-modern ETRM upgrade strategy contain?
- How would you define upgrade scope?
- Should an upgrade include business transformation?
- What risks arise from combining upgrade and major redesign?
- When is a technical upgrade preferable?
- When should remediation be completed before upgrading?
- How would you assess vendor support timelines?
- What external platform dependencies influence version selection?
- How should regulatory deadlines influence the plan?
- What is an upgrade-readiness assessment?
- Who should participate in upgrade governance?
- What architecture decisions must be made early?
- How would you establish success criteria?
- What would justify delaying an upgrade?
- What conditions should prevent starting implementation?
- How would you communicate upgrade value to executives?
2. Current-State Discovery20
- How would you inventory the existing ETRM estate?
- Which platform components should be documented?
- How would you identify every custom script?
- How should Java extensions and third-party libraries be inventoried?
- How would you catalogue interfaces?
- How should reports and simulations be assessed?
- How would you inventory user tables and custom schemas?
- How should instrument and workflow customisations be identified?
- How would you discover undocumented scheduled jobs?
- How should environment-specific configuration be captured?
- How would you identify obsolete components?
- How would you identify duplicate functionality?
- What production statistics should support discovery?
- How should user and service-account usage be assessed?
- How would you identify unsupported technical components?
- What is the role of dependency mapping?
- How would you validate the inventory's completeness?
- What if source code cannot be located?
- How should unknown ownership be resolved?
- What output should a current-state assessment produce?
3. Compatibility and Impact Assessment20
- How would you assess target-version compatibility?
- Which release documentation should be reviewed?
- How would you identify deprecated or removed APIs?
- How should changed standard behaviour be analysed?
- Which customisations create the greatest upgrade risk?
- How would you assess database compatibility?
- How should operating-system compatibility be validated?
- How should Java-runtime compatibility be checked?
- How would you assess browser or desktop-client compatibility?
- How should integration middleware be assessed?
- What risks arise from third-party library changes?
- How would you evaluate authentication compatibility?
- How should reporting tools be assessed?
- How would you identify changed valuation behaviour?
- How should lifecycle-event changes be analysed?
- How would you assess configuration-conversion requirements?
- What is a compatibility matrix?
- How should severity and remediation priority be assigned?
- Which findings require proof-of-concept testing?
- What should the final impact assessment contain?
4. Customisation Rationalisation20
- Why should customisations be reviewed before an upgrade?
- How would you classify custom components?
- Which customisations should be retained?
- Which should be replaced by standard functionality?
- Which should be redesigned externally?
- Which should be retired?
- How would you establish whether a script is still used?
- What risks arise from unused custom code?
- How would you identify duplicated business logic?
- How should tactical solutions be handled?
- What makes a customisation upgrade-safe?
- How would you reduce dependency on internal schemas?
- How should direct database integrations be remediated?
- When should the platform scripting language be replaced by compiled Java?
- When should custom logic move to middleware?
- How would you quantify technical debt?
- How should business owners approve retirement?
- How would you test that removed functionality is genuinely unused?
- How should rationalisation benefits be measured?
- What would prevent rationalisation during an upgrade?
5. Upgrade Environment Strategy20
- Which environments are required for an legacy-to-modern ETRM upgrade?
- What is the purpose of an upgrade sandbox?
- When is a dedicated remediation environment required?
- How should development and system-test environments differ?
- Why is a production-like performance environment necessary?
- How should UAT be structured?
- What environment should support migration rehearsals?
- How should disaster recovery be upgraded and tested?
- How would you sequence environment upgrades?
- How should environment refreshes be controlled?
- What production data may be copied?
- How should copied data be masked?
- How would you preserve repeatable test conditions?
- How should market-data snapshots be prepared?
- How should business dates be controlled?
- How would you detect environment drift?
- What infrastructure differences must be documented?
- How should environment access be restricted?
- How would you manage concurrent business projects?
- What makes an upgrade environment fit for purpose?
6. Technical Upgrade Execution20
- What are the major stages of a technical legacy-to-modern ETRM upgrade?
- How should installation prerequisites be validated?
- How would you manage database-conversion steps?
- What backups are required before conversion?
- How should conversion logs be reviewed?
- How would you identify partially converted components?
- What should happen when a conversion step fails?
- How should repeated upgrade rehearsals be automated?
- How would you measure conversion duration?
- How should configuration transformations be managed?
- How would you deploy recompiled custom components?
- How should third-party libraries be upgraded?
- How would you validate service startup?
- What technical smoke tests are required?
- How should application and database versions be confirmed?
- How would you verify installed patches?
- What should an upgrade execution runbook contain?
- How should manual steps be reduced?
- What evidence should each execution stage retain?
- How would you determine technical upgrade completion?
7. Functional Regression Testing20
- What should an legacy-to-modern ETRM upgrade regression suite cover?
- How would you select representative golden trades?
- Which Front Office functions must be tested?
- Which Middle Office controls must be tested?
- Which Back Office processes must be tested?
- How should trade amendments be tested?
- How would you test cancellations and terminations?
- How should confirmations be validated?
- How would you test settlements and invoices?
- How should payment instructions be tested?
- How would you test accounting entries?
- How should collateral and margin processes be tested?
- How would you validate market-data loading?
- How should curves and fixings be tested?
- How would you test reports and simulations?
- How should user entitlements be verified?
- What negative testing is required?
- How should historical production defects be included?
- How would regression failures be triaged?
- What evidence supports functional acceptance?
8. Valuation and Risk Regression20
- How would you compare pre-upgrade and post-upgrade valuation?
- Which market-data snapshot should be used?
- How should trade populations be selected?
- Why should cash flows be compared before present value?
- How would you compare positions?
- How should P&L be reconciled?
- How would you validate Greeks?
- How should VaR and stress results be compared?
- What numerical tolerance is acceptable?
- How should tolerances be justified?
- What can create legitimate valuation differences?
- How would you distinguish intended model change from defect?
- How should rounding differences be handled?
- How would you isolate instrument-specific differences?
- How should unvalued trades be investigated?
- What is a valuation-difference waterfall?
- Who should approve expected differences?
- How should differences be documented?
- Which differences must block production?
- How would you demonstrate overall valuation equivalence?
9. Non-Functional Upgrade Testing20
- What non-functional testing does an upgrade require?
- How would you establish the current performance baseline?
- Which interactive processes should be measured?
- How should end-of-day runtime be compared?
- How would you test grid scalability?
- How should interface throughput be tested?
- What is soak testing?
- How would you identify memory degradation?
- How should database-performance changes be analysed?
- How would you test concurrent workloads?
- What availability and failover testing is required?
- How should disaster recovery be tested?
- How would you validate security hardening?
- How should vulnerability findings be handled?
- How would you verify authentication and entitlements?
- What accessibility or usability changes require testing?
- How should infrastructure sizing be reassessed?
- What degradation should block go-live?
- Who accepts residual non-functional risk?
- What evidence supports non-functional readiness?
10. Data-Migration Strategy20
- When does an ETRM initiative require data migration?
- How does upgrade conversion differ from business-data migration?
- What should a migration strategy contain?
- How would you define migration scope?
- Which data should be migrated?
- Which historical data may remain archived?
- How should active and matured trades be treated differently?
- What is the source of truth during migration?
- How would you establish source-to-target mappings?
- How should transformation rules be documented?
- How would you manage data cleansing?
- What is data enrichment?
- How should default values be governed?
- How would you preserve legacy identifiers?
- How should transaction lineage be retained?
- What is a migration wave?
- When is phased migration appropriate?
- When is big-bang migration preferable?
- What dependencies determine migration sequence?
- What would make a migration strategy unacceptable?
11. Reference-Data Migration20
- Why must reference data precede transactions?
- Which reference-data domains must be migrated?
- How would you map legal entities and counterparties?
- How should duplicate counterparties be resolved?
- How would you migrate portfolios and organisational structures?
- How should products and instruments be mapped?
- How would you migrate commodities and locations?
- How should units and conversion factors be handled?
- How would you migrate indexes and calendars?
- How should settlement instructions be migrated securely?
- How would you migrate accounting mappings?
- How should effective dates be preserved?
- What happens when source values have no target equivalent?
- How should retired records be represented?
- How would you validate reference-data completeness?
- What should block transaction loading?
- How should reference-data ownership support sign-off?
- How would you reconcile reference data?
- What security controls apply to sensitive migrations?
- What evidence supports reference-data approval?
12. Transaction and Lifecycle Migration20
- How would you migrate active transactions?
- Should trades be recreated or transformed directly?
- Why should supported loading mechanisms be used?
- How would you preserve transaction economics?
- How should multi-leg structures be migrated?
- How would you migrate daily and hourly profiles?
- How should partially fixed transactions be handled?
- How would you migrate amended transactions?
- How should cancellations and terminations be represented?
- How would you preserve parent-child relationships?
- How should novations and partial unwinds be migrated?
- How would you migrate accrued and settled cash flows?
- How should open confirmations be handled?
- How would you migrate uninvoiced settlement events?
- How should unpaid invoices be migrated?
- How would you prevent duplicate payments?
- How should open accounting events be treated?
- How would you prevent duplicate downstream output?
- What transactions require manual review?
- What proves transaction migration completeness?
13. Historical-Data Migration20
- How much historical data should move into ETRM?
- What business requirements determine history?
- How should regulatory retention influence scope?
- When should history move to a separate archive?
- How would users access archived history?
- How should historical transactions remain traceable?
- How would you preserve historical market data?
- Should all simulation results be migrated?
- How should official historical P&L be retained?
- How would you preserve audit trails?
- What happens when legacy history lacks required target fields?
- How should data-quality limitations be disclosed?
- How would you handle obsolete products?
- How should historical identifiers remain searchable?
- How would you prevent future-data leakage into historical reporting?
- How should archived data be secured?
- How would you test archive retrieval?
- What service levels should apply to archived data?
- Who approves historical-data disposition?
- What evidence demonstrates compliant retention?
14. Migration Tooling and Automation20
- What capabilities should migration tooling provide?
- How should extraction be automated?
- How would you create repeatable transformation pipelines?
- How should mapping rules be versioned?
- How would you validate data before loading?
- How should rejected records be quarantined?
- How would you support controlled replay?
- How should migration batches be identified?
- How would you make loads idempotent?
- How should checkpoints support restart?
- What control totals should every stage produce?
- How would you prevent parallel-load conflicts?
- How should database and application load be monitored?
- How would you estimate migration duration?
- How should sensitive data be protected?
- What logging should migration tools provide?
- How should technical and business errors differ?
- How would you prove the deployed migration version?
- How should migration code pass CI/CD controls?
- When would manual migration be unacceptable?
15. Migration Reconciliation20
- What is migration reconciliation?
- Why are transaction counts insufficient?
- Which quantitative control totals should be compared?
- How would you reconcile quantities?
- How should notional and cash flows be compared?
- How would you reconcile present value and P&L?
- How should positions be compared?
- How would you reconcile open lifecycle events?
- How should settlement and invoice status be validated?
- How would you reconcile accounting balances?
- How should reference-data mappings be checked?
- What is record-level reconciliation?
- What is aggregate reconciliation?
- How should tolerances be established?
- How would exceptions be classified?
- How should breaks be assigned and aged?
- Who should approve unresolved differences?
- Which differences must block cutover?
- How should reconciliation evidence be retained?
- What constitutes migration sign-off?
16. Migration Rehearsals20
- Why are migration rehearsals necessary?
- How many rehearsals should be planned?
- What should each rehearsal validate?
- How would you establish consistent source snapshots?
- How should environments be reset between rehearsals?
- How would you measure extraction, transformation and load duration?
- How should reconciliation duration be measured?
- How would you identify manual bottlenecks?
- What is a dress rehearsal?
- How closely should it reproduce cutover?
- How should production-like volume be represented?
- How would you test restart after partial failure?
- How should late source changes be simulated?
- How would you test rollback?
- How should downstream integrations participate?
- How would business users validate migrated transactions?
- What findings should enter the cutover plan?
- How should rehearsal defects be tracked?
- What exit criteria should the final rehearsal satisfy?
- When should a failed rehearsal delay go-live?
17. Cutover Planning20
- What should an ETRM cutover plan contain?
- How should cutover ownership be assigned?
- What is the required activity sequence?
- How should trading freeze be managed?
- How would you control late transactions?
- How should final source extraction be authorised?
- What pre-cutover backups are required?
- How should migration checkpoints be defined?
- What are go/no-go decision points?
- How should elapsed time be monitored?
- What happens when an activity exceeds its window?
- How should cross-system dependencies be coordinated?
- How would you validate market data?
- How should users and entitlements be activated?
- What technical smoke tests are required?
- What business validation is required?
- How should interfaces be released?
- How should downstream outputs be controlled?
- Who authorises reopening for trading?
- What evidence should cutover retain?
18. Rollback and Contingency20
- What should a rollback plan contain?
- At what point does rollback become impractical?
- What is the rollback decision deadline?
- Who may invoke rollback?
- How would you return users to the legacy platform?
- How should trades entered after go-live be handled?
- What happens to messages already processed?
- How would you prevent duplicate transactions after rollback?
- How should generated confirmations be handled?
- What happens to invoices and payments?
- How should accounting outputs be contained?
- How would you restore database and file-system consistency?
- How should source systems be redirected?
- What reconciliation follows rollback?
- How would you communicate business limitations?
- What alternative exists when rollback is unsafe?
- What is forward remediation?
- How should contingency capacity be planned?
- How would you test rollback in rehearsal?
- What makes a rollback plan credible?
19. Go-Live and Hypercare20
- What is hypercare?
- How long should hypercare continue?
- What support coverage is required?
- How should business and technical teams be organised?
- What command-centre structure is appropriate?
- Which metrics should be monitored?
- How should defects be prioritised?
- What constitutes a critical defect?
- How should workarounds be approved?
- What changes should be permitted during hypercare?
- How should emergency fixes be tested?
- How would you prevent uncontrolled production correction?
- How should user issues be distinguished from defects?
- What daily reconciliations are required?
- How should unresolved migration breaks be tracked?
- When should vendor support be engaged?
- What is the exit criterion for hypercare?
- How should operational ownership be transferred?
- What lessons-learned review is required?
- How would you measure go-live stability?
20. Production-Support Operating Model20
- How would you design ETRM production support?
- What responsibilities belong to Level 1 support?
- What responsibilities belong to Level 2?
- What responsibilities belong to Level 3?
- When should a vendor receive an escalation?
- How should functional and technical support collaborate?
- What coverage hours are required?
- How should global handovers operate?
- What support skills are critical?
- How should ownership by service and component be documented?
- What is a RACI matrix?
- How should support queues be structured?
- How would you prevent ticket reassignment loops?
- What should an operational knowledge base contain?
- How should known errors be documented?
- What training should support teams receive?
- How should new releases transition into support?
- What production access should support personnel receive?
- How would you measure support effectiveness?
- What indicates that the support model is under-resourced?
21. Incident Management20
- What constitutes an ETRM production incident?
- How should incident severity be determined?
- How should business impact influence priority?
- What information should the first incident record contain?
- Who should lead a major incident?
- How should technical workstreams be coordinated?
- What communication cadence is appropriate?
- How would you prevent premature assumptions?
- What diagnostic evidence should be collected?
- When is service restart appropriate?
- When can restart destroy valuable evidence?
- How should workarounds be assessed?
- How should failed trades or jobs be contained?
- How would you manage downstream impacts?
- When should disaster recovery be considered?
- How should vendor support be engaged?
- What constitutes service restoration?
- What validation should follow restoration?
- How should outstanding data corrections be tracked?
- When can an incident be closed?
22. Problem and Root-Cause Management20
- How does problem management differ from incident management?
- What is root-cause analysis?
- Which methods can support root-cause analysis?
- Why is “human error” rarely a sufficient root cause?
- How would you construct an incident timeline?
- What evidence should support causal conclusions?
- How should contributing factors be identified?
- What is a known error?
- How should temporary and permanent fixes differ?
- How would you prevent recurring incidents?
- How should corrective actions be prioritised?
- Who should own each action?
- How would you track actions to completion?
- What validation proves remediation effective?
- How should root causes influence architecture standards?
- When should technical debt be formally recorded?
- How should recurring incidents influence investment?
- What should a post-incident report contain?
- Who should review major-problem reports?
- What indicates ineffective problem management?
23. Monitoring and Observability20
- What should ETRM production monitoring cover?
- How do infrastructure, application and business monitoring differ?
- Which service-health metrics are essential?
- How would you detect a process that is alive but stalled?
- What queue metrics should be monitored?
- How should database health be observed?
- How would you monitor grid workers?
- What batch metrics should be captured?
- How should interface completeness be monitored?
- What business controls should appear on dashboards?
- How would you monitor unvalued transactions?
- How should missing market data be alerted?
- How would you detect settlement or accounting failures?
- What is synthetic monitoring?
- How should correlation identifiers support diagnosis?
- How would you reduce alert fatigue?
- What service-level indicators should be retained?
- How should trends support capacity planning?
- How would you detect degradation before failure?
- What makes monitoring actionable?
24. Batch and End-of-Day Support20
- How should support monitor ETRM end-of-day?
- What constitutes technical batch completion?
- What constitutes business completion?
- How would you detect a missing portfolio?
- How should failed work units be recovered?
- When should a complete job be rerun?
- How would you prevent duplicate output?
- How should late market data be managed?
- What happens when end-of-day misses its cut-off?
- Which stages may be deferred?
- How should corrected input trigger recalculation?
- Who should approve an official rerun?
- How should restated results be labelled?
- How would you preserve the original result?
- How should regional processing dependencies be managed?
- What should a batch runbook contain?
- How should manual intervention be recorded?
- What reconciliation closes the business day?
- How would recurring batch failures be remediated?
- What metrics demonstrate end-of-day stability?
25. Production Data Correction20
- When is production data correction justified?
- Why should direct database correction be avoided?
- What supported alternatives should be considered?
- How should affected records be identified?
- What impact analysis is required?
- How should correction logic be independently reviewed?
- How would you test a correction script?
- What backup or recovery point is required?
- Who should approve execution?
- How should segregation of duties apply?
- How would you prevent correcting unintended records?
- What control totals should be captured before correction?
- What verification should follow execution?
- How should downstream effects be remediated?
- What happens if confirmations or payments were already generated?
- How should correction evidence be retained?
- How would you reverse an incorrect correction?
- When should vendor guidance be required?
- How should recurring corrections trigger architectural remediation?
- What makes a production correction auditable?
26. Service-Level and Capacity Management20
- Which ETRM services require formal service levels?
- How should availability be measured?
- How should transaction-processing latency be measured?
- What service level should apply to end-of-day?
- How should interface timeliness be measured?
- What is an operational-level agreement?
- How should third-party commitments support ETRM SLAs?
- How would you measure SLA breaches?
- How should planned maintenance be treated?
- What error budgets may be appropriate?
- How should capacity trends be monitored?
- What growth factors should be forecast?
- How should peak loads influence planning?
- What headroom is required?
- How should disaster-recovery capacity be considered?
- When should infrastructure be scaled?
- When should workload design be changed?
- How would recurring SLA breaches be escalated?
- What service-review metrics should management receive?
- How would you demonstrate continual improvement?
27. Upgrade, Migration and Support Scenarios20
- Post-upgrade valuations differ for only one instrument family. How would you investigate?
- An upgrade succeeds technically, but settlement events differ. Should go-live proceed?
- Several scripts compile but fail at runtime. What assessment was incomplete?
- End-of-day is 40% slower on the target version. How would you isolate the cause?
- A direct database interface breaks after upgrade. What architectural weakness does this expose?
- Migration counts reconcile, but commodity positions do not. What should be compared next?
- An amended legacy trade loses its historical relationship after migration. What was missing?
- A migrated trade generates a duplicate invoice. Which cutover control failed?
- A fixing correction arrives during migration freeze. How should it be managed?
- The final migration rehearsal exceeds the cutover window. Should go-live continue?
- Users enter trades after the rollback deadline. What contingency is required?
- Hypercare teams repeatedly correct data manually. What systemic action is needed?
- A production service restarts successfully, but its queue does not move. Is service restored?
- Support closes incidents after restart without root-cause analysis. What risk accumulates?
- Monitoring is green, but one portfolio is missing from risk reports. Which monitoring layer failed?
- A critical vendor defect has no immediate patch. How would you design containment?
- Disaster recovery restores the platform but not the latest outbound events. What must be reconciled?
- Management asks to combine an upgrade, cloud migration and product rollout in one cutover. How would you challenge it?
- The target version provides standard capability replacing custom code, but the business wants to retain both. What risks arise?
- What distinguishes an legacy-to-modern ETRM upgrade and support architect from a project manager or production-support lead?
Commodity-Specific Case Studies10 sections · 380 questions
A. Crude Oil and Refined Products50
- How would you model the transaction in ETRM?
- How would you represent the pricing window relative to the bill-of-lading date?
- How should provisional and final prices be calculated?
- What events should be generated?
- How would quantity tolerance be handled?
- How should missing or corrected assessments be controlled?
- Which positions and sensitivities should the trader see?
- How would you test final invoice adjustment?
- Which accounting entries are required?
- What integrations are needed?
- Which attributes belong on the trade?
- Which values belong in reference data?
- How would laboratory results enter ETRM?
- How should quality adjustments affect settlement?
- Should they change valuation before delivery?
- How would provisional quality assumptions be managed?
- How should actual quantity replace scheduled quantity?
- What audit trail is required?
- How would incorrect laboratory data be corrected?
- How would you reconcile the final invoice?
- How would you model the physical and financial transactions?
- How should they be linked analytically?
- Which risk factors are required?
- What basis risks remain after hedging?
- How would you avoid double counting?
- How should futures settlements affect P&L?
- How would you attribute hedge and physical P&L?
- How should exchange positions be reconciled?
- What happens when the cargo pricing period changes?
- How would you measure hedge effectiveness?
- How would trades and inventory movements be separated?
- What is the authoritative inventory quantity?
- How should tank locations be represented?
- How would temperature conversion be governed?
- How should operational losses be processed?
- How would inventory valuation be calculated?
- How should transfers between tanks be represented?
- How would negative inventory be detected?
- How should trades reconcile with inventory movements?
- Which accounting events should be produced?
- How would port, vessel and delivery data be represented?
- How should port-specific indexes be mapped?
- How would multiple deliveries under one contract be handled?
- How should delivery-document quantities update settlement?
- How would quality claims be processed?
- What credit exposure exists before delivery?
- How should invoices group deliveries?
- What taxes and fees might require configuration?
- How would an external marine-fuel platform integrate?
- What controls prevent duplicate delivery invoicing?
B. Natural Gas50
- How would the daily delivery profile be modelled?
- How should gas-day boundaries and time zones be handled?
- How would daily fixings enter the price?
- How should unfixed exposure be reported?
- How would monthly invoicing be generated?
- What happens when one fixing is missing?
- How should weekends and holidays be handled?
- Which market-data curves are required?
- How would the deal appear in daily positions?
- How would you validate the monthly invoice?
- How would you represent minimum and maximum quantities?
- Does the flexibility create embedded optionality?
- How should optionality be valued?
- How would nominations update expected delivery?
- How should cumulative constraints be monitored?
- How would make-up rights be represented?
- How should penalties be generated?
- What is the correct position view?
- How would you test operational constraint breaches?
- When would external optimisation be required?
- How would commodity and transportation contracts be modelled?
- How should entry and exit locations be represented?
- Which basis exposure remains?
- How should pipeline capacity be monitored?
- How would fuel-gas losses affect quantity?
- How should nominations and allocations enter ETRM?
- How would imbalance charges be calculated?
- Should transport costs be embedded or separate?
- How would landed margin be reported?
- What reconciliations are required?
- How should storage capacity be represented?
- How would injection and withdrawal rights be modelled?
- How should ratchets affect available capacity?
- What embedded optionality exists?
- How should storage valuation be calculated?
- How would optimisation results become operational nominations?
- How should inventory be reconciled?
- What stress scenarios are required?
- How would model assumptions be governed?
- Which capabilities should remain outside ETRM?
- How would the pricing formula be decomposed?
- How should lagged oil observations be represented?
- How would take-or-pay exposure be measured?
- How should annual contract quantities be tracked?
- How would a price-review clause affect valuation?
- How should forecast and fixed prices coexist?
- What curve and FX dependencies exist?
- How would the contract be stress-tested?
- How should accounting estimates be produced?
- What requires custom modelling?
C. LNG40
- How would the pricing slope and constant be represented?
- How should crude-price averaging be configured?
- How would tonnes, cubic metres and MMBtu be reconciled?
- Which quantity should drive settlement?
- How should boil-off losses be treated?
- What events occur at loading and discharge?
- How would provisional settlement operate?
- Which FX and discount curves are required?
- How should cargo P&L be reported?
- What data must come from external systems?
- Should the original transaction be amended or supplemented?
- How should the destination change be audited?
- Which market exposures change?
- How should additional freight be represented?
- How would changed boil-off affect delivered quantity?
- What happens to the original hedge?
- How should incremental diversion value be measured?
- What new settlement events are needed?
- How should confirmations be updated?
- How would you preserve original and revised economics?
- Which data is required for destination netback?
- Which calculations belong inside ETRM?
- Which belong in an external optimisation platform?
- How should freight curves be represented?
- How would boil-off be calculated?
- How should port and canal charges be maintained?
- How would FX affect comparison?
- How should counterparty credit influence decisions?
- How would scenario assumptions be governed?
- How would selected economics become a booked transaction?
- How would commercial trades and physical movements be separated?
- How should inventory ownership be represented?
- How would title-transfer points be captured?
- How should transshipment losses be treated?
- How would multiple vessel movements be integrated?
- What quantity should settle each contract?
- How should inventory reconcile after reload?
- What operational events require audit?
- How would demurrage be handled?
- What end-to-end controls are required?
D. Power and Renewables50
- How should hourly delivery profiles be modelled?
- How should peak and off-peak definitions be governed?
- How would holidays affect peak delivery?
- How should daylight-saving days be represented?
- How would zonal basis risk be measured?
- How should shaped exposure be aggregated?
- What curves are required?
- How would position reports prevent hourly detail from being lost?
- How should exchange hedges be reconciled?
- What performance considerations arise from hourly profiles?
- How would expected generation be represented?
- How should forecast and actual generation differ?
- How would inflation escalation be modelled?
- What optionality is created by the floor?
- How should negative-price provisions be represented?
- Which market-data curves are required?
- How would weather-driven volume risk be handled?
- How should imbalance costs affect value?
- What is the appropriate valuation methodology?
- Which assumptions require model governance?
- Should power and certificates be separate transactions?
- How should the transactions be linked?
- How would certificate vintage be represented?
- How should metered generation determine certificate quantity?
- What happens when production is below forecast?
- How should certificate delivery be tracked?
- How would registry identifiers be maintained?
- What exposures should be reported?
- How should retirement or cancellation be represented?
- How would power and certificate revenue be reconciled?
- How should physical battery constraints be represented?
- What optionality does the battery provide?
- How should charging and discharging be modelled?
- How would efficiency losses affect quantity?
- How should state of charge be tracked?
- What optimisation capability is required?
- How should dispatch instructions integrate with ETRM?
- How would revenues from multiple markets be attributed?
- What stress scenarios should be applied?
- Which functions should sit outside ETRM?
- How would forecast customer load be represented?
- How should actual metered consumption update positions?
- How would load-shape risk be measured?
- How should fixed-tariff revenue be modelled?
- What wholesale hedges are required?
- How would weather scenarios affect risk?
- How should imbalance exposure be represented?
- What volume should be settled?
- How would customer systems integrate?
- What controls prevent forecast data being treated as actual?
E. Emissions and Environmental Products30
- How should allowance instruments be represented?
- How should compliance year and vintage differ?
- How would forecast emissions be modelled?
- How should purchased, delivered and surrendered allowances differ?
- How would registry movements enter ETRM?
- What position indicates compliance shortfall?
- How should allowance valuation be performed?
- What accounting treatment requires consideration?
- How would surrender be controlled?
- How would ETRM reconcile with the external registry?
- How would the carbon-credit taxonomy be designed?
- Which attributes are economically material?
- How would unique registry serial numbers be handled?
- How should issuance, transfer and retirement differ?
- How would quality differences affect valuation?
- What market-data limitations exist?
- How should invalidated credits be handled?
- How would concentration risk be reported?
- Which provenance evidence must be retained?
- What prevents double counting or double retirement?
- How would the two instruments be represented?
- Which currency exposure arises?
- How should spread risk be reported?
- What correlation assumptions affect VaR?
- How would liquidity differences be handled?
- How should exchange positions reconcile?
- What stress scenarios are appropriate?
- How should margin cash flows be represented?
- How would P&L attribution separate outright and spread moves?
- What regulatory classifications must be maintained?
F. Metals30
- How would LME pricing be represented?
- How should quotation periods and averaging work?
- How would the regional premium be modelled?
- How should warehouse and metal-grade data be maintained?
- What physical and financial exposures exist?
- How would warrants or warehouse receipts be represented?
- How should exchange hedges be linked analytically?
- What basis risk remains?
- How would inventory and title be reconciled?
- How should the final invoice be validated?
- How would assay results be incorporated?
- How should provisional and final assays differ?
- How would payable metal be calculated?
- How should treatment and refining charges be represented?
- How would impurity penalties affect settlement?
- Which quantity should drive market exposure?
- How should provisional invoices be adjusted?
- What audit evidence is required?
- How would the valuation be independently reconstructed?
- When is custom settlement logic justified?
- How would principal metal quantity be represented?
- How should lease interest be calculated?
- What commodity and credit exposures arise?
- How should physical return differ from cash settlement?
- How would collateral be represented?
- Which market and discount curves are required?
- How should inventory ownership be tracked?
- What events occur at maturity?
- How would default be modelled operationally?
- What accounting considerations apply?
G. Agriculture and Soft Commodities30
- How would futures reference and differential be represented?
- How should origin, grade and crop year be modelled?
- How would actual quality change settlement?
- How should bag, kilogram and tonne conversions be controlled?
- How would shipment periods be represented?
- What basis risks remain after futures hedging?
- How should actual quantity update exposure?
- How would warehouse receipts be handled?
- How should provisional and final invoices work?
- What controls prevent incorrect crop-year mapping?
- What optionality does the seller hold?
- How should approved origins be represented?
- How would expected origin be valued before declaration?
- What happens when origin is nominated?
- How should freight exposure be represented?
- How would quality specifications affect settlement?
- What position should be shown before nomination?
- How should stress testing cover origin selection?
- How would confirmations represent optional terms?
- What requires custom modelling?
- How should input and output commodities be related?
- How would conversion yields be represented?
- How should processing losses be handled?
- Which curves are required?
- How would futures hedges be mapped?
- How should crush-margin P&L be calculated?
- What operational actuals should update the model?
- How would yield variance be reported?
- How should inventory be reconciled?
- What belongs in ETRM versus the manufacturing system?
H. Freight and Shipping30
- Should freight be a separate transaction?
- How would vessel, route and voyage be represented?
- How should estimated and actual costs differ?
- How would laytime be captured?
- How should demurrage be calculated?
- How would freight affect cargo netback?
- What currency exposures arise?
- How should invoices be reconciled?
- Which operational systems must integrate?
- How would voyage profitability be reported?
- How would the charter commitment be represented?
- How should daily hire charges accrue?
- How would costs be allocated across voyages?
- How should idle days be treated?
- How would bunker exposure be represented?
- How should off-hire periods affect settlement?
- How would vessel utilisation be reported?
- What accounting treatment requires consideration?
- Which data belongs in a voyage-management system?
- How would ETRM receive actual operating costs?
- How would physical and financial freight be modelled?
- How should route and vessel class be represented?
- Which fixing and forward curves are required?
- How would basis risk be measured?
- How should settlement against the index operate?
- What happens when the physical shipment date changes?
- How would hedge P&L be attributed?
- How should broker trades be reconciled?
- What liquidity risks remain?
- How would the combined freight position be reported?
I. Cross-Commodity and Structured Cases40
- How should crude inputs and product outputs be represented?
- How would yield assumptions be maintained?
- Which price curves are required?
- How should location and quality basis be captured?
- How would crack-spread sensitivities be reported?
- How should futures and swap hedges be mapped?
- What operational actuals should replace forecasts?
- How would production variance affect P&L?
- Which calculations belong outside ETRM?
- How would the complete margin be reconciled?
- How would power, gas and emissions positions be connected?
- What is the clean spark spread?
- How should heat-rate assumptions be represented?
- How would plant availability affect expected generation?
- What optionality does dispatch provide?
- How should start-up costs be treated?
- What optimisation capability is required?
- How would cross-commodity stress testing work?
- How should actual fuel burn update settlement?
- What should remain in the plant-management system?
- How should physical fuel and environmental attributes be separated?
- How would the composite price formula be represented?
- How should sustainability certification be maintained?
- How would volume commitments be monitored?
- What happens when certified supply is unavailable?
- How should conventional-jet and renewable-premium risks be reported?
- How would certificates or credits be retired?
- What accounting and disclosure requirements arise?
- How should supplier evidence be integrated?
- What controls prevent environmental double counting?
- Should the agreement be one trade or linked transactions?
- How should common contractual identifiers be maintained?
- How would cross-commodity pricing be represented?
- What embedded optionality exists?
- How should credit exposure be aggregated?
- How would confirmations be generated?
- How should invoices be consolidated?
- What happens when only one commodity component is amended?
- How would risk be reported by commodity and contract?
- Which parts require custom architecture?
J. End-to-End Architecture Challenges30
- How would you assess product scope?
- What gap analysis would you perform?
- How would you decide between configuration and customisation?
- Which reference data must be established?
- What integrations are required?
- How would you create the product-control framework?
- What test strategy is necessary?
- How would you migrate open trades?
- What determines production readiness?
- How would you phase delivery?
- How would you assess the source portfolio?
- Which trades should be migrated?
- How would reference-data mappings be governed?
- How should historical identifiers be preserved?
- How would open events be migrated?
- How would you prevent duplicate confirmations and payments?
- Which positions and values must reconcile?
- How would cutover be rehearsed?
- What rollback limitations exist?
- What should block go-live?
- How should market-data exceptions be governed?
- How would stale or unavailable prices be handled?
- Which stress scenarios should run?
- How should nonlinear transactions be revalued?
- How would liquidity risk be reported?
- How should margin cash-flow forecasts be produced?
- How would credit-limit utilisation change?
- What operational processes require prioritisation?
- How should official and indicative results differ?
- Which architecture bottlenecks might appear?
Architect Leadership and Stakeholder Management22 sections · 440 questions
1. Solution Architect Role and Accountability20
- What is the role of an ETRM Solution Architect?
- How does it differ from a functional consultant?
- How does it differ from a technical architect?
- How does it differ from a senior developer?
- How does it differ from a programme manager?
- Which decisions should the Solution Architect own?
- Which decisions should the business own?
- Which decisions require collective governance?
- How should the architect remain accountable without controlling every delivery activity?
- What artifacts should the architect produce?
- How should the architect measure solution quality?
- What does end-to-end ownership mean?
- How should an architect balance strategic and tactical work?
- When should an architect become directly involved in implementation?
- How would you prevent becoming a delivery bottleneck?
- How should architecture responsibilities change after go-live?
- What makes an architect credible with traders?
- What makes an architect credible with engineers?
- What makes an architect credible with control functions?
- How would you demonstrate that architecture created business value?
2. Stakeholder Identification and Analysis20
- Who are the principal stakeholders in an ETRM programme?
- How would you identify hidden stakeholders?
- How do traders, risk, operations and Finance priorities differ?
- What concerns would Product Control raise?
- What concerns would Credit Risk raise?
- What concerns would Treasury raise?
- What concerns would Compliance and Internal Audit raise?
- What concerns would infrastructure and production support raise?
- How would you analyse stakeholder influence and interest?
- What is a stakeholder map?
- How would you identify decision-makers?
- How would you identify subject-matter experts?
- How would you distinguish approvers from contributors?
- How should external vendors be represented?
- How would you engage stakeholders who are affected but unavailable?
- What happens when the nominal owner lacks decision authority?
- How would you identify conflicting incentives?
- How should stakeholder engagement vary by project stage?
- How would you maintain a stakeholder register?
- What indicates that stakeholder analysis is incomplete?
3. Business Understanding and Discovery20
- How would you learn a new trading desk's business?
- What questions would you ask traders?
- What would you ask risk controllers?
- What would you ask schedulers and operations?
- What would you ask settlements and Finance?
- How would you separate contractual requirements from user preferences?
- How would you identify undocumented processes?
- What can production incidents reveal about the operating model?
- How would you analyse spreadsheets and manual workarounds?
- How would you identify the actual system of record?
- How would you validate business terminology?
- How should process walkthroughs be conducted?
- What is a current-state process map?
- How would you identify control gaps?
- How would you identify duplicate data entry?
- How would you quantify operational pain?
- How would you challenge “ETRM cannot do this”?
- How would you validate vendor claims?
- What discovery evidence is sufficient to begin design?
- When should discovery be extended?
4. Requirements Leadership20
- How would you distinguish business, functional and technical requirements?
- What makes a requirement testable?
- How would you identify non-functional requirements?
- How should regulatory requirements be captured?
- How would you prioritise requirements?
- What is MoSCoW prioritisation?
- What are its limitations?
- How would you distinguish need from solution preference?
- How would you challenge a requirement that copies a legacy system?
- How should conflicting requirements be resolved?
- What happens when traders and Product Control disagree?
- How would you handle requirements that arrive after design approval?
- What is requirements traceability?
- Who should own acceptance criteria?
- How would you prevent requirements from remaining ambiguous?
- How should assumptions be documented?
- How should constraints differ from assumptions?
- What is an open question register?
- When should unresolved requirements block design?
- How would you obtain meaningful requirements sign-off?
5. Architecture Vision and Target State20
- How would you develop an ETRM target-state vision?
- How should business strategy influence architecture?
- What principles would guide the target state?
- How would you define ETRM's functional boundaries?
- How would you decide which capabilities remain outside ETRM?
- How would you explain target architecture to executives?
- How should current-state constraints influence sequencing?
- How would you distinguish target state from an idealised diagram?
- What transition architectures may be required?
- How should technical debt be represented?
- How would you identify architectural runway?
- How should scalability and resilience enter the vision?
- How would you incorporate data and integration strategy?
- How should security and controls be embedded?
- How would you align the target state with enterprise architecture?
- What happens when enterprise standards conflict with ETRM supportability?
- How would you manage exceptions?
- How should the target state be reviewed?
- What evidence demonstrates stakeholder alignment?
- When should the target architecture be revised?
6. Decision-Making and Trade-offs20
- How do you make an architecture decision with incomplete information?
- What is an architecture decision record?
- Which decisions require formal records?
- How should options be compared?
- What evaluation criteria would you use?
- How should cost, time, risk and maintainability be balanced?
- How would you evaluate configuration versus customisation?
- How would you compare ETRM and external-service implementation?
- How should vendor supportability influence decisions?
- How would you quantify technical debt?
- How should reversible and irreversible decisions differ?
- What is a time-boxed proof of concept?
- When is a proof of concept necessary?
- When can it become a delaying tactic?
- How would you prevent analysis paralysis?
- Who should accept residual risk?
- How would you communicate an unpopular decision?
- How should a rejected option remain documented?
- When should an earlier decision be reopened?
- How would you assess whether a decision produced the expected outcome?
7. Challenging Stakeholders Constructively20
- How would you challenge a senior trader's proposed design?
- How would you respond when urgency is used to bypass controls?
- What if the business insists on direct database updates?
- How would you challenge unrestricted manual market-data overrides?
- What if users want every legacy screen reproduced?
- How would you respond to an unnecessary custom instrument request?
- What if Finance requires a process that damages Front Office performance?
- How would you challenge an unrealistic delivery date?
- What evidence makes a challenge credible?
- How would you avoid turning a technical disagreement into a personal conflict?
- When should you propose a controlled tactical solution?
- How should tactical debt be time-bounded?
- What if the stakeholder refuses all alternatives?
- When should disagreement be escalated?
- How would you record accepted risk?
- What if an executive verbally approves an unsupported design?
- How would you respond if a vendor promises an unverified capability?
- When should an architect refuse approval?
- How would you preserve working relationships after disagreement?
- What distinguishes constructive challenge from obstruction?
8. Communication and Executive Influence20
- How would you explain ETRM architecture to executives?
- How would you explain valuation risk without mathematical detail?
- How would you present a production-readiness concern?
- What should an executive architecture summary contain?
- How would you communicate uncertainty?
- How would you explain technical debt in business terms?
- How should options and recommendations be presented?
- What is the role of visual architecture diagrams?
- How would you avoid overwhelming stakeholders with detail?
- How should communication differ for traders and engineers?
- How would you communicate a missed milestone?
- How should bad news be escalated?
- What should a steering-committee update contain?
- How would you distinguish fact, assumption and forecast?
- How should decisions and actions be recorded?
- How would you handle hostile questioning?
- How would you explain why a technically successful release is not business-ready?
- How should architecture metrics be presented?
- How would you build executive sponsorship?
- What indicates that communication was ineffective?
9. Workshop and Facilitation Skills20
- How would you plan a product-design workshop?
- Who should attend?
- What pre-reading should be supplied?
- How would you define workshop outcomes?
- How should competing perspectives be managed?
- How would you ensure quieter participants contribute?
- What happens when one stakeholder dominates?
- How would you separate requirements from solution design?
- How would you resolve terminology differences?
- What should be captured in real time?
- How would you manage unresolved questions?
- When should a workshop be stopped?
- How should decisions be confirmed afterward?
- What is a playback session?
- How would you prevent workshop fatigue?
- How should remote workshops be structured?
- How would you facilitate a failure-mode review?
- How would you run a production-readiness workshop?
- What evidence demonstrates workshop success?
- When is a workshop inappropriate?
10. Architecture Governance20
- What is architecture governance?
- Which ETRM decisions require governance?
- How would you establish an architecture-review board?
- Who should participate?
- What should a design review evaluate?
- What evidence should accompany a review?
- How would you prevent governance becoming bureaucratic?
- How should low-risk changes be handled?
- How should architecture exceptions be approved?
- What is an exception-expiry date?
- How would you monitor compliance with decisions?
- How should implementation deviations be managed?
- What is design assurance?
- How does design assurance continue during delivery?
- How should reusable patterns be governed?
- How would you prevent multiple teams solving the same problem differently?
- How should vendor designs be reviewed?
- What happens when delivery begins before architecture approval?
- How should recurring exceptions influence standards?
- What makes governance effective?
11. Design Reviews and Quality Assurance20
- How would you conduct an ETRM solution-design review?
- What functional areas must be represented?
- How should trade-lifecycle completeness be assessed?
- How would you evaluate data-model impact?
- How should integration reliability be reviewed?
- How would you assess performance impact?
- How should security and entitlement design be evaluated?
- How would you review operational supportability?
- What upgrade risks should be considered?
- How would you identify hidden dependencies?
- What questions expose incomplete designs?
- How should assumptions be validated?
- How would you classify review findings?
- What constitutes a blocking finding?
- How should findings be tracked?
- Who confirms closure?
- How would you manage conditional approval?
- What if the implementation differs from the approved design?
- How should post-implementation architecture validation work?
- How would you measure design-review effectiveness?
12. Delivery Planning and Estimation20
- How would you estimate a new ETRM product implementation?
- What factors drive complexity?
- How should uncertainty affect estimates?
- What is a discovery estimate?
- How does it differ from a delivery commitment?
- How would you identify dependencies?
- What is the critical path?
- How should vendor lead times be incorporated?
- How would you estimate testing effort?
- How should migration and reconciliation be estimated?
- How would you account for business availability?
- What contingency is appropriate?
- How should assumptions accompany estimates?
- How would you challenge politically imposed dates?
- What could be phased to meet a fixed deadline?
- What cannot safely be compressed?
- How would you communicate confidence ranges?
- What early warning signs indicate schedule risk?
- How should architecture support incremental delivery?
- What makes an estimate credible?
13. Programme and Portfolio Alignment20
- How should an ETRM solution align with the wider programme?
- How would you identify cross-project dependencies?
- What happens when several projects change the same configuration?
- How should shared environments be governed?
- How would you manage competing release priorities?
- What is a release train?
- How should architecture work align with delivery increments?
- How would you prevent local optimisation?
- What is portfolio-level technical debt?
- How should enterprise data and integration initiatives be coordinated?
- How would you align an legacy-to-modern ETRM upgrade with product onboarding?
- When should initiatives be separated?
- How should resource conflicts be escalated?
- What should a programme architecture forum achieve?
- How would you avoid duplicated platform capabilities?
- How should roadmaps reflect architectural dependencies?
- How would you communicate cumulative risk?
- What metrics should programme governance review?
- When should architecture recommend resequencing?
- What demonstrates successful programme alignment?
14. Team Leadership and Collaboration20
- How would you structure an ETRM delivery team?
- What responsibilities belong to functional consultants?
- What responsibilities belong to developers?
- What responsibilities belong to quantitative analysts?
- What responsibilities belong to data and integration engineers?
- What responsibilities belong to testers?
- How should infrastructure and security teams participate?
- How would you clarify accountability?
- What is a RACI matrix?
- What are the limitations of RACI?
- How would you delegate architecture work?
- How should delegated designs be reviewed?
- How would you mentor developing architects?
- How should technical disagreement within the team be resolved?
- What if the strongest technical contributor communicates poorly?
- How would you handle consistently weak delivery?
- How would you create psychological safety while maintaining standards?
- How should knowledge be shared?
- How would you reduce dependence on individual specialists?
- What indicates a high-performing architecture team?
15. Vendor and Systems-Integrator Management20
- How would you evaluate an ETRM implementation partner?
- What evidence should support vendor capability claims?
- How should vendor responsibilities be defined?
- How would you prevent knowledge remaining exclusively with the vendor?
- What design artifacts must vendors deliver?
- How should vendor estimates be challenged?
- How would you review vendor-created customisations?
- What if the vendor recommends a highly customised solution?
- How should vendor accelerators be evaluated?
- Who owns intellectual property and source code?
- How should product defects differ from implementation defects?
- When should an issue be escalated to the software vendor?
- What information should accompany a vendor support case?
- How would you manage conflicting vendor recommendations?
- How should commercial incentives be considered?
- What acceptance criteria should apply to vendor deliverables?
- How should knowledge transfer be tested?
- What happens when a vendor misses quality thresholds?
- How would you transition away from a partner?
- What makes a vendor relationship effective without becoming dependent?
16. Risk, Issue and Dependency Management20
- How do risks, issues, assumptions and dependencies differ?
- What belongs in an architecture-risk register?
- How should risk probability and impact be assessed?
- How would you identify architectural risks early?
- Who should own mitigation?
- What is residual risk?
- Who may accept residual risk?
- How should risk triggers be defined?
- How would you monitor risk exposure?
- What makes a mitigation credible?
- How should technical debt appear as risk?
- How would you escalate a dependency outside your control?
- What happens when a critical assumption becomes invalid?
- How should issues be connected to decisions?
- How would you avoid risk registers becoming passive documents?
- What risks should be discussed at steering committee?
- How should vendor risks be represented?
- How should cumulative delivery risk be assessed?
- What evidence demonstrates active risk management?
- When should risk require a no-go recommendation?
17. Conflict and Escalation Management20
- How would you resolve conflict between Trading and Risk?
- What if Front Office speed conflicts with control requirements?
- How would you resolve disagreement between architecture and delivery?
- What if two architects recommend incompatible designs?
- How would you distinguish factual and value-based disagreement?
- What evidence should be collected?
- How should decision authority be identified?
- When is compromise appropriate?
- When is compromise unsafe?
- How would you escalate without undermining colleagues?
- What should an escalation contain?
- How would you avoid escalating every disagreement?
- What if senior management overrides your recommendation?
- How should accepted risk be documented?
- How would you respond when an overridden risk materialises?
- What if stakeholders withhold necessary decisions?
- How should unresolved decisions affect delivery?
- How would you facilitate reconciliation after conflict?
- What lessons should be captured?
- What distinguishes principled leadership from inflexibility?
18. Control, Compliance and Audit Stakeholders20
- How would you engage Compliance early?
- How should Internal Audit participate without designing controls?
- How would you translate regulatory obligations into system requirements?
- Who should own control design?
- How would you validate that a control is operationally practical?
- What is control evidence?
- How should manual and automated controls differ?
- How would you assess compensating controls?
- What if business users consider controls burdensome?
- How should audit findings influence architecture?
- How would you challenge an ineffective remediation?
- What if the proposed control produces excessive false positives?
- How should model-risk stakeholders be engaged?
- How would you obtain security approval?
- What should a regulatory traceability matrix contain?
- How should control ownership continue after go-live?
- How would you demonstrate control effectiveness?
- What if a critical control cannot be automated?
- When should compliance risk stop a release?
- How would you explain residual control risk to executives?
19. Production Readiness and Operational Leadership20
- What does production readiness mean?
- Who should participate in readiness review?
- What functional evidence is required?
- What non-functional evidence is required?
- How should unresolved defects be assessed?
- What operational documentation must exist?
- How should support teams demonstrate readiness?
- What monitoring must be operational?
- How should data reconciliation be validated?
- What rollback capability is required?
- Who should make the final go/no-go decision?
- What conditions should automatically stop release?
- How would you resist schedule pressure?
- What is an early-life-support model?
- How should hypercare be governed?
- How should production issues be prioritised?
- When should vendor support be present?
- How is ownership transferred to operations?
- When is a release considered stable?
- How should lessons improve future delivery?
20. Transformation and Change Adoption20
- Why can a technically correct ETRM solution fail?
- How would you assess organisational readiness?
- How should operating-model changes be identified?
- What training do traders and operations require?
- How would you manage resistance to standardisation?
- How should spreadsheet-dependent processes be transitioned?
- What is a super-user network?
- How can super-users support adoption?
- How should communications prepare users for change?
- What should business process documentation contain?
- How would you measure adoption?
- What behaviour indicates users are bypassing the solution?
- How would you respond to shadow systems?
- How should feedback be collected?
- When should feedback change the design?
- How should post-go-live improvements be prioritised?
- What ownership sustains the new process?
- How would you prevent regression to legacy practices?
- What metrics demonstrate transformation success?
- What is the architect's role in change adoption?
21. Behavioural and Experience Questions20
- Describe an ETRM design you rejected and why.
- Describe a time you changed your architecture recommendation.
- Describe a serious requirement ambiguity you resolved.
- Describe a conflict between Trading and a control function.
- Describe a production issue caused by an architectural decision.
- Describe a difficult stakeholder you influenced.
- Describe an unrealistic commitment you challenged.
- Describe a tactical solution you approved.
- How did you ensure that the tactical solution was later removed?
- Describe a vendor recommendation you challenged.
- Describe a design review that uncovered a critical issue.
- Describe a release you recommended stopping.
- Describe an architecture risk management accepted.
- Describe a time your recommendation was overruled.
- What happened, and what did you learn?
- Describe how you developed a junior architect.
- Describe how you recovered a failing workstream.
- Describe how you simplified an overly complex solution.
- Describe an architectural mistake you made.
- How did you correct it?
22. Leadership Scenarios20
- Traders demand same-day deployment of a new pricing rule. How would you respond?
- Risk refuses go-live because one stress scenario is incomplete. What would you do?
- Finance wants direct ETRM database access for month-end reporting. How would you challenge it?
- A senior executive has promised an impossible delivery date. How would you reframe the plan?
- The vendor says custom code is the only option, but no gap analysis exists. What would you require?
- Two implementation partners blame each other for an interface failure. How would you establish accountability?
- Developers say architecture governance is slowing delivery. How would you assess the claim?
- An architect approves designs but does not follow implementation. What risk results?
- A technically superior design exceeds budget. How would you structure the decision?
- A cheaper design creates long-term operational dependence on one consultant. Would you approve it?
- The business wants one global process despite legal regional differences. How would you resolve this?
- Product Control and traders use different P&L definitions. How would you establish authority?
- A production-readiness review finds missing support documentation. Should release proceed?
- A critical defect has a manual workaround. What determines go-live eligibility?
- The programme hides technical debt to preserve a green status. How would you respond?
- A security control blocks an essential overnight process. How would you manage the conflict?
- An offshore team lacks commodity-domain knowledge but owns critical configuration. What should change?
- The business refuses to fund disaster recovery while demanding high availability. How would you frame the risk?
- A migration rehearsal fails, but management wants to continue. What evidence should drive the decision?
- What distinguishes an ETRM architecture leader from a technically strong individual contributor?
Reading the questions is not the same as being able to answer them
The ETRM Pro Bundle covers the material these questions are drawn from: trade capture and product modelling, curves and valuation, position and P&L, risk, settlement and integration architecture.