Risk statistics are genuinely useful and routinely misused. This module teaches the four you will actually encounter, what each one is really measuring, and — the part usually left out — the specific conditions under which each one fails.
Standard deviation (σ) measures dispersion: how far returns typically land from their own average. High σ means a wide spread of outcomes; low σ means a narrow one. It is the industry’s default definition of risk because it is computable, comparable and additive in convenient ways.
Returns are usually measured daily or monthly, but quoted annually, so you need the scaling rule. Volatility scales with the square root of time:
252 is the approximate number of trading days in a year. So a stock with 1.2% daily volatility has annualised volatility of 1.2 × 15.87 ≈ 19%. Rough reference points: a broad equity index typically sits somewhere around 15–20% annualised, an individual large-cap stock 25–35%, a speculative small-cap 50%+, investment-grade bonds well under 10%.
If returns were normally distributed — they are not, see below — then roughly two-thirds of annual outcomes would fall within one σ of the mean and about 95% within two. For a portfolio expected to return 8% with 16% volatility, that would put the typical year between −8% and +24%, and two-thirds of the range still leaves a one-in-three chance of landing outside it. Even taken at face value, σ describes a very wide fan of outcomes.
Every use of standard deviation as a probability statement smuggles in an assumption: that returns follow a normal distribution. They do not. Real market returns have fat tails — extreme moves happen far more often than a bell curve allows — and they are negatively skewed, meaning the extreme moves are disproportionately downward.
The scale of the discrepancy is hard to overstate. Under a normal distribution, a daily move of five standard deviations should occur roughly once every several thousand years. Equity markets produce them every few years. October 1987’s one-day decline was, on the volatility of the time, in the region of twenty standard deviations — an event with a normal-distribution probability so small the number is meaningless. It happened anyway.
Beta measures how much an asset has moved in response to the market. A beta of 1.0 means it has historically moved with the index; 1.3 means it has amplified index moves by about 30%; 0.6 means it has damped them.
Beta splits total risk into two parts. The portion explained by the market is systematic risk, which diversification cannot remove because it is the market. The remainder is idiosyncratic risk, specific to that company, which diversification can remove. That distinction is the whole basis of Module 4.
Four things beta does not tell you, each of which regularly catches people out:
Return without risk context is meaningless — 20% earned with 60% volatility is not obviously better than 9% earned with 10%. The Sharpe ratio puts them on comparable footing by measuring excess return per unit of volatility:
A portfolio returning 11% with 15% volatility while T-bills pay 3% has a Sharpe of (11 − 3) ÷ 15 = 0.53. As a very rough guide, sustained Sharpe ratios below 0.5 are unremarkable, around 1.0 is good, and anything advertised above 2.0 over a long period deserves suspicion rather than admiration.
Sharpe has an obvious flaw: it penalises upside volatility exactly as much as downside. A fund that occasionally leaps 20% in a month is punished for it. The Sortino ratio fixes this by dividing by downside deviation — the dispersion of negative returns only:
For an investor who cares about losses rather than movement, Sortino is the more honest number. Where the two disagree sharply, the portfolio’s volatility is lopsided, and it is worth finding out in which direction.
Value at Risk (VaR) answers: over some horizon, at some confidence level, what is the most I expect to lose? “One-day 95% VaR of $50,000” means that on 95% of days losses should be under $50,000.
The flaw is in the sentence itself. VaR tells you the threshold and says nothing whatsoever about what happens beyond it. On the other 5% of days, the loss could be $51,000 or $5,000,000 — the measure is silent. Institutions optimised against VaR for years by pushing risk out past the confidence level, where the number could not see it, which is a significant part of why 2008 was so much worse than the models permitted.
The repair is conditional VaR (also called expected shortfall): the average loss given that you are in the bad tail. It answers the question that matters — how bad is bad — and it is much harder to game. For a private investor the takeaway is simpler: any risk number stated with a confidence level is a statement about the ordinary days, and you should ask separately what happens on the other ones.
| Your question | Use | Watch out for |
|---|---|---|
| How bumpy is this ride? | Standard deviation | Assumes a bell curve; understates extremes |
| How much of my risk is just “the market”? | Beta | Backward-looking; rises in crises |
| Am I being paid for the risk I take? | Sharpe / Sortino | Gameable by hidden tail risk |
| What is the worst I have had to sit through? | Maximum drawdown | One historical sample, not a bound |
| How bad is bad? | Conditional VaR | Needs more data; still model-dependent |
| Can I be forced to sell? | Cash runway, leverage ratio | Not a market statistic at all — and often the one that matters most |
The last row is the one to sit with. Every measure above summarises the past and presents it as a description of the future. They are worth computing and worth reading. But the questions that actually determine whether you survive a bad decade — how concentrated am I, how much debt is involved, can anything force my hand — are answered by looking at your own balance sheet, not at a statistic derived from a price series.
Educational purposes only; not financial advice. Historical figures are illustrative and past drawdowns are not a forecast of future ones. Always do your own research and consult a licensed advisor.