A statement governs decisions it will never attend, and it does so through the cascade. How appetite is translated into business-line limits and desk mandates, why the arithmetic rarely adds up on the first attempt, and what to do when it does not.
In short
- The cascade is the mechanism by which a board statement governs decisions taken by people who will never read it — which makes it the part of an appetite framework that determines whether the rest is doing anything.
- Cascading is a translation, not a division. Appetite is expressed in outcomes the board cares about; a desk mandate has to be expressed in things a desk can control before the close of business.
- The sum of the distributed limits will normally exceed the appetite they express, because not every unit reaches its limit at once. The excess has to be a stated assumption about diversification, not an accident nobody has measured.
- Where cascades fail is between the second and third level: group and division are usually connected, division and desk usually are not, and that is where risk is actually taken.
- The test is to pick one desk, ask which limit expresses appetite, and follow it upward. Whether the answer arrives in one conversation is the measure of the cascade.
On this page
A risk appetite statement has to govern decisions it will never attend. Cascading is how that happens: the translation of a board-level statement into the limits, thresholds and mandates that reach the people who take risk daily.
Why the cascade is the load-bearing part#
Everything else in an appetite framework can be sound and produce no effect if the cascade is missing. The statement can be measure-based, the thresholds derived from capacity, the ownership named — and if the translation to desk level was never made, the framework governs a quarterly report rather than a decision.
This is also the part most often deferred, because it is the only part that requires agreement from the businesses rather than approval from a committee.
Translation, not division#
The instinct is to treat cascading as arithmetic — take the group number, split it by business, split again by desk. That produces limits nobody can act on, because appetite and mandates are expressed in different units.
Appetite is stated in outcomes the board cares about: earnings volatility, capital consumption, a ratio holding under stress, a concentration staying below a share of capital. A desk mandate has to be stated in things a desk can control before the close of business: a notional, a tenor, a counterparty grade, an exposure to a single name, a permitted instrument list.
The cascade is the chain of reasoning that connects the two, and it has to be written down. An institution that can state why a desk’s single-name limit is the number it is, in terms that end at the group’s concentration appetite, has a cascade. One that cannot has two sets of numbers in the same document.
The four steps#
- **Decompose the appetite measure into its drivers.** A group appetite for credit loss decomposes into portfolio size, expected loss rate, concentration and correlation. Each driver belongs to someone; the measure itself belongs to nobody below the executive.
- **Assign each driver to the level that controls it.** Portfolio size is a business-line decision, concentration is set where origination happens, correlation is managed at portfolio level. A driver assigned to a level that cannot move it produces a limit that will be breached by events rather than by choices.
- **Express the assigned driver in the unit that level works in**, and state the conversion. This is where a proportion of capital becomes a currency amount, and where an annual figure becomes a position limit.
- **Reconcile upward.** Sum the distributed limits and compare the total against the appetite they express, then state the assumption that explains the difference.
The arithmetic will not add up, and that is expected#
The sum of the distributed limits will normally exceed the appetite they are meant to express, and this is not automatically an error. Limits are set so that each unit has room to operate, and not every unit reaches its limit at the same moment.
The difference is therefore an assumption about diversification, and the requirement is that it be a stated assumption rather than an accident. An institution that knows its limits sum to a stated multiple of appetite, and has said why that multiple is acceptable, is managing an over-allocation. One that has never added them up has an unmeasured one.
The difference between the two is an assumption about diversification, and the requirement is that somebody has stated it.
Where it goes wrong#
Cascades fail in a consistent place: between the second and third level. Group and division are usually connected, because both are managed by people who attend the same committees. Division and desk usually are not.
- **The desk limits were already there.** They predate the appetite statement, they work, and nobody wanted to renegotiate them — so the cascade was drawn on paper down to division and stopped.
- **The conversion was never written down.** Someone made it once, correctly, and left. The numbers remain and their derivation does not, so the next balance-sheet change cannot be pushed through the cascade.
- **A driver was assigned to a level that cannot move it.** A desk given a limit on a measure driven by portfolio correlation will breach it without having done anything, which teaches the desk that breaches are noise.
- **The cascade is one-way.** Limits go down and nothing comes back up, so the framework cannot answer whether the distributed permissions still express the appetite after a year of business decisions.
- **Utilisation is not reported alongside the limit.** A limit reported only when breached hides the more useful signal, which is a unit that has been running at the top of its mandate for two quarters.
The last two are the ones that decay quietly. A cascade built correctly and never reconciled upward will drift out of alignment within a year of ordinary business decisions, and nothing in the reporting will say so.
What good looks like#
A working cascade has four properties that can be checked without reading the framework document.
- Anyone taking risk can name the limit that expresses appetite for what they do, and distinguish it from the limits that exist for other reasons.
- The derivation of that limit can be followed upward to a measure in the statement, in writing, in one sitting.
- The upward reconciliation is performed on a stated cycle, and the over-allocation is a number the executive knows.
- Utilisation against limit is reported continuously, not only on breach, so that a unit consistently at the top of its mandate is visible before it exceeds it.
What to do next#
Pick one desk and ask the person running it which of their limits expresses the institution’s risk appetite. Then follow that limit upward until it reaches a measure in the statement.
The answer arrives in one conversation, or it does not arrive. Where the chain breaks is the level at which the cascade actually stops, and it is usually one level higher than the framework document shows.
Frequently asked
What does it mean to cascade risk appetite?
Cascading risk appetite means translating a board-level appetite statement into the limits, thresholds and mandates that reach the people who take risk daily. It is a translation rather than a division: appetite is stated in outcomes the board cares about — earnings volatility, capital consumption, a ratio holding under stress — while a desk mandate has to be stated in things a desk can control before the close of business, such as a notional, a tenor, a counterparty grade or a single-name exposure. The cascade is the written chain of reasoning connecting the two, and it is what allows a statement to govern decisions nobody consults it for.
Should the sum of business-line limits equal the group risk appetite?
Normally it exceeds it, and that is not automatically an error. Limits are set so each unit has room to operate, and not every unit reaches its limit at the same moment, so the total distributed will be larger than the appetite it expresses. What matters is that the difference is a stated assumption about diversification rather than an accident. An institution that knows its limits sum to a particular multiple of appetite, and has said why that multiple is acceptable, is managing an over-allocation deliberately. One that has never added them up has an unmeasured one — and adding them up for a single material risk type is an afternoon of work.
Where do risk appetite cascades usually break down?
Between the second and third level — division and desk. Group and division are usually connected because both are managed by people who attend the same committees, while desk-level limits typically predate the appetite statement, work adequately, and were never renegotiated. Four other failures recur: the conversion from appetite to limit was made once and never written down, so it cannot be redone when the balance sheet changes; a driver was assigned to a level that cannot move it, so breaches happen by event rather than by choice; the cascade runs one way with no upward reconciliation; and utilisation is reported only on breach, hiding the more useful signal of a unit running at the top of its mandate for two quarters.
How can you test whether a risk appetite cascade works?
Pick one desk, ask the person running it which of their limits expresses the institution’s risk appetite, and follow that limit upward until it reaches a measure in the appetite statement. The answer arrives in one conversation or it does not arrive at all, and the point where the chain breaks is the level at which the cascade actually stops — usually one level higher than the framework document shows. A second check is the upward reconciliation: sum the limits distributed for one material risk type and compare the total against the appetite they are supposed to express. Most frameworks have never run either test, and both are cheap.
The programme behind this article
Work through this material with the practitioners who wrote it.
Practical Risk Appetite and Risk Tolerance Masterclass
Risk appetite as a working management tool — frameworks, metrics and trigger levels that turn a board statement into daily decisions across the organisation.
View the programme →A Structured Approach to Building Predictive Key Risk Indicators and Operational Risk Appetite Masterclass
Predictive KRIs that fire before the loss event — bow-tie analysis, horizon scanning and machine learning inside a working operational risk appetite framework.
View the programme →Advanced Enterprise Risk Management (ERM) Masterclass
Enterprise risk management that runs as one discipline across the organisation — framework design, risk appetite, quantitative analysis and the updated COSO ERM model, built for implementation.
View the programme →