Skip to content
BIZENIUS

The risk appetite framework review checklist: ten areas it is tested on

BIZENIUS Advisory Team · Last updated: 27 August 2026

Written and reviewed by the BIZENIUS advisory practice — senior practitioners from risk, treasury, finance and supervision.

Ten areas where a risk appetite framework is tested — by the board, by a real decision, and by a supervisor — what a sound answer looks like in each, and the symptom that gives a weak one away.

In short

  • Risk appetite frameworks are rarely found to be wrong in one decisive way. They decay: thresholds stay still while the balance sheet moves, owners leave, the cascade is never reconciled, and the annual refresh updates the figures rather than re-examining the reasoning.
  • The ten areas below are where a framework is most consistently tested. Each is stated as what a sound framework can show, followed by the symptom that gives a weak one away.
  • Use is the single most diagnostic area on the list, and it is the only one that cannot be improved by improving the document.
  • The pattern across all ten is that the defects are found by asking for specifics — a derivation, a name, a date, a decision — rather than by reading the framework.
  • Run the ten against one material risk type before running them across the framework. Most of what is wrong will appear in the first, and it will appear while it is still cheap to fix.
On this page
  1. 1. Capacity
  2. 2. Derivation of thresholds
  3. 3. Measures rather than adjectives
  4. 4. The qualitative risks
  5. 5. Ownership
  6. 6. The cascade
  7. 7. Upward reconciliation
  8. 8. Escalation that has been used
  9. 9. Use
  10. 10. Maintenance
  11. Using the list

Risk appetite frameworks are rarely found to be wrong in one decisive way. They decay. Thresholds stay still while the balance sheet moves, named owners leave, the cascade is built once and never reconciled, and each annual refresh updates the figures rather than re-examining the reasoning that produced them.

The ten areas below are where a framework is most consistently tested — by the board, by a real decision arriving under commercial pressure, and by a supervisor. Each is stated as what a sound framework can show, followed by the symptom that gives a weak one away.

1. Capacity#

**Sound:** capacity is calculated for each material risk type, from the capital and liquidity position, and it is refreshed when either moves. **Symptom:** the word appears in the framework and no number is attached to it, or capacity is quoted as a regulatory minimum rather than as what the institution could absorb before reaching one.

2. Derivation of thresholds#

**Sound:** for any threshold, someone can show the arithmetic connecting it to capacity and state the margin deliberately left between the two. **Symptom:** the derivation is a peer comparison, a round number, or last year’s position rounded outward — and the person who could explain it has left.

3. Measures rather than adjectives#

**Sound:** every material risk type carries at least one measure with a stated basis of measurement, and the qualitative language is confined to the preamble. **Symptom:** the statement can be signed by any institution in the sector without changing a word.

4. The qualitative risks#

**Sound:** conduct, compliance and the operational exposures that resist a single number are expressed as what the institution will not do, with named exception authority and indicators that would show the boundary being approached. **Symptom:** zero appetite is declared, which reads well and gives nobody a way to rank two imperfect options.

5. Ownership#

**Sound:** every measure names one accountable executive, and that person is the one who would have to act rather than the one who compiles the report. **Symptom:** ownership is stated at committee level, which means the measure is owned by a calendar rather than by a person.

6. The cascade#

**Sound:** a person taking risk can name the limit that expresses appetite for what they do, and its derivation can be followed upward to a measure in the statement in one sitting. **Symptom:** the cascade is drawn to divisional level in the framework document and stops there, because desk limits predated the statement and were never renegotiated.

7. Upward reconciliation#

**Sound:** the limits distributed for each material risk type are summed on a stated cycle and compared against the appetite they express, and the over-allocation is a number the executive knows and has justified. **Symptom:** the sum has never been calculated, so the framework cannot say whether the permissions in force still express the appetite approved.

8. Escalation that has been used#

**Sound:** thresholds have been crossed, escalation ran as written, and the record shows who was told, when, and what was decided — including the decision to remain outside appetite for a stated period. **Symptom:** years of green reporting, read as good management. A framework without breaches is a framework without information.

9. Use#

**Sound:** decision papers cite the appetite position, and at least one decision in the last year was changed by it — a concentration declined, a limit not raised, a market entered on smaller terms. **Symptom:** the statement is current, complete, approved, and absent from every board paper that recorded a real choice.

10. Maintenance#

**Sound:** the framework is re-derived when capital, liquidity, strategy or the risk profile changes materially, not only on the annual cycle, and the review record shows reasoning revisited rather than figures updated. **Symptom:** consecutive versions differ only in their numbers.

Using the list#

The pattern across all ten is that the defects are found by asking for specifics — a derivation, a name, a date, a decision — rather than by reading the framework. A document review will pass a framework that fails nine of these.

Run the ten against a single material risk type before running them across the whole framework. Most of what is wrong will appear in the first one, because the same reasoning was applied everywhere, and it will appear while it is still cheap to fix.

BIZENIUS runs this review as a diagnostic with risk and finance teams, and delivers the underlying material as an in-house programme where a team wants to build the capability rather than buy the conclusion. Both are available in English and French; scope and fees are confirmed on enquiry.

Frequently asked

How do you review a risk appetite framework?

By asking for specifics rather than reading the document, because a document review will pass a framework that fails on use. Ten areas carry most of the diagnostic weight: whether capacity is calculated, whether thresholds have a derivation traceable to it, whether measures replace adjectives, how the qualitative risks are handled, whether every measure has one accountable person, whether the cascade reaches the desk, whether limits are reconciled upward against appetite, whether escalation has ever actually run, whether decision papers cite the appetite position, and whether maintenance re-derives the reasoning or only updates the figures. Run all ten against one material risk type first — the same reasoning was usually applied everywhere.

What is the strongest single sign that a risk appetite framework is weak?

No threshold has ever been breached. Years of green reporting are usually read as evidence that the framework is working, and more often they indicate that thresholds were set where the business already sat rather than where capacity runs out. A framework without breaches is a framework without information: it has pre-agreed nothing, so it will be silent at the moment it was written for. The second strongest sign is closely related — the framework is complete, current and approved, and absent from every board paper that recorded a real choice.

How often should a risk appetite statement be reviewed?

On the strategy cycle at minimum, and additionally whenever capital, liquidity, strategy or the risk profile changes materially — because thresholds derived from capacity stop being derived from it the moment capacity moves. The more useful question is what a review consists of. A sound review record shows reasoning revisited: why this measure, why this threshold given current capacity, whether the owner is still the person who would have to act. A weak one shows consecutive versions differing only in their numbers, which is the signature of an annual refresh that updates figures without re-examining what produced them.

Who should carry out the review — the risk function or an independent party?

The risk function can run the whole list, and should, because most of the ten are answered from records it already holds. Two areas benefit from someone outside the process: derivation of thresholds and use. Both require judging work the risk function itself produced, and both are the areas where a confident internal answer is hardest to challenge from inside. A practical arrangement is for the risk function to run the ten and for the two contested areas to be tested by internal audit, a board risk committee member, or an external practitioner reading the last twelve months of decision papers against the statement.

More where this came from

Browse the full resources hub, or subscribe in the footer for occasional substantial pieces.

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.