Why does volatility arrive in clusters?
"SPY's volatility is 18%" is a true sentence about an average. Inside the ten years that produced it, one month ran at 4% and another at 88%, and a big day was far more likely the day after a big day than after a quiet one. This lesson measures that dependence, because it is the single most reliable statistical regularity in market data.
Returns do not remember; their size does
Measured on 2026-09-04, on twenty years of SPY.US daily returns: the correlation of today's return with yesterday's is −0.105 — mildly negative, almost entirely a product of the sharp reversals inside 2008 and 2020, and near zero at every longer lag. Whether the market rose yesterday says next to nothing about today's direction.
Now square the returns, so that the sign disappears and only the size remains. The correlation of today's squared return with yesterday's is 0.255; with the squared return five days ago, 0.287; with the one twenty days ago, still 0.139. The absolute returns tell the same story at 0.315, 0.357 and 0.225. The size of a move is predictable from the size of recent moves, and the direction is not. That is volatility clustering, first written down by Mandelbrot in 1963 and the reason the ARCH family of models (Engle, 1982) exists.
Regimes
Take the ten years to 3 September 2026 and compute realised volatility month by month, annualised. The quietest month was February 2017 at 4.4%; the wildest was March 2020 at 87.6%; the median month ran at 12.0%. The "18%" that summarises the decade is an average over a distribution of months that is itself fat-tailed — most months well below it, a handful far above.
This is why a risk number computed from a long window is wrong most of the time in both directions: too high in the calm years that make up most of the sample, far too low in the month that matters. A volatility estimate has a half-life measured in weeks, and the rolling-windows lesson shows the same fact from three window lengths at once.
Why it happens
Nobody fully knows, and the candidate explanations are all partly right. News arrives in clusters — an earnings season, a crisis, a policy cycle. Leverage responds to losses: a fall forces selling, which produces another fall. And traders' own risk models use recent volatility to size positions, so a rise in volatility triggers de-risking that raises it further. The August 2007 quant week in the factor course is that last mechanism in its purest form.
What it changes
Three practical things. Yesterday's volatility is the best forecast of today's, and a long-run average is a worse one: the EWMA and GARCH estimators the derivatives domain uses are this observation turned into a formula. The tails come in clusters, so the 83 days beyond three sigma in the previous lesson are not 83 independent events; they are perhaps a dozen episodes, and the count of episodes is what a sample needs to contain. Position sizing on a fixed volatility target trades more in a crisis, selling into the fall — a design choice with the clustering built into its cost.
In the data
All of it is the same twenty-year /eod/SPY.US pull: returns squared, then correlated with themselves at a lag. For a rolling view, /technical/SPY.US?function=volatility&period=20 returns the provider's rolling estimate, and comparing its level in February 2017 with March 2020 is the regime table in one call.
Try it now
- Here are two three-month windows of
/eod/SPY.US, with every daily return beyond ±3.7% (three sigma of the twenty-year distribution) marked. Computed on adjusted closes on 28 September 2026:
| Window | Daily returns | Days beyond ±3.7% |
|---|---|---|
?from=2020-02-01&to=2020-04-30 |
61 | 16 |
?from=2017-02-01&to=2017-04-30 |
60 | 0 |
The sixteen days of 2020, with their returns: 27 Feb −4.49%, 2 Mar +4.33%, 4 Mar +4.20%, 9 Mar −7.81%, 10 Mar +5.17%, 11 Mar −4.87%, 12 Mar −9.57%, 13 Mar +8.55%, 16 Mar −10.94%, 17 Mar +5.40%, 18 Mar −5.06%, 20 Mar −4.31%, 24 Mar +9.06%, 26 Mar +5.84%, 1 Apr −4.50%, 6 Apr +6.72%. Count the trading days between consecutive hits, and how many hits follow a hit of the opposite sign. Write the two window counts side by side; that is clustering. 2. Both regimes on one chart, where the difference is visible without arithmetic:
Measure February 2017 and then March 2020, and note which one the "18%" is closer to. 3. Explain to a colleague why a 99% value-at-risk figure computed on 1 February 2020 was about to be wrong, and what number computed on 1 March would have done better.