Skip to content
BIZENIUS

What is a risk appetite statement? Anatomy and the test it has to pass

BIZENIUS Advisory Team · Last updated: 27 August 2026

Written and reviewed by the BIZENIUS advisory practice — senior practitioners from risk, treasury, finance and supervision.

Nearly every institution has one; very few are constrained by one. What a risk appetite statement contains, where its numbers are supposed to come from, and the single question that separates a statement that binds from a statement that describes.

In short

  • A risk appetite statement is a board-approved document setting out the amount and type of risk an institution is willing to accept in pursuit of its strategy, expressed in measures specific enough that a decision can be tested against them.
  • Its purpose is not to describe the institution’s attitude to risk. Its purpose is to make certain answers unavailable — which is why a statement nothing can breach is not a lenient statement but an empty one.
  • The numbers are supposed to come from capacity — what the capital and liquidity position can actually absorb — rather than from where the business already sits or from a peer template.
  • Three failures account for most statements that do not bind: adjectives instead of measures, thresholds set where the business already operates, and a cascade that stops at the first business line.
  • The test is one question: name a decision in the last year that the statement changed. A statement that cannot answer it is a description of the institution, not a constraint on it.
On this page
  1. What a risk appetite statement is
  2. What it is for
  3. The anatomy of a statement
  4. Where the numbers are supposed to come from
  5. Where it goes wrong
  6. What a statement that binds looks like
  7. What to do next

What a risk appetite statement is#

A risk appetite statement is a board-approved document setting out the amount and type of risk an institution is willing to accept in pursuit of its strategy, expressed in measures specific enough that a decision can be tested against them.

The last clause is the whole of it. A document that states a position without giving anyone a way to test a decision against that position is a statement of intent, and intent is not appetite. Appetite is what remains after the intent has been made specific enough to refuse something.

What it is for#

The purpose of the statement is often described as communicating the board’s attitude to risk, and that description is how statements end up written in adjectives. The purpose is narrower and more useful: to make certain answers unavailable in advance, so that when a decision arrives under commercial pressure the boundary has already been agreed by people who were not in the room.

That is why a statement nothing can breach is not a lenient statement. It is an empty one: it has pre-agreed nothing, and it will be silent at the moment it was written for.

The anatomy of a statement#

A statement that can do that work has six components. The proportions vary with the institution; the components do not.

  1. A short qualitative preamble tying appetite to the strategy it serves — the only part where adjectives belong, and only because the measures that follow give them content.
  2. A set of quantitative measures, one family per material risk type, each with a stated basis of measurement.
  3. Thresholds on each measure: the level at which the institution is comfortable, the level at which escalation begins, and the level it will not cross.
  4. Qualitative statements for the risks that resist a single number — conduct, compliance, certain operational exposures — written as what the institution will not do rather than as how much it dislikes doing it.
  5. Named ownership: for each measure, the executive accountable for staying inside it and the forum that reviews it.
  6. The escalation path, stating what happens when a threshold is crossed, who is told, within what period, and who may authorise remaining outside it and for how long.

Components five and six are the ones most often absent, and their absence is what turns the document into a dashboard. A measure without an owner is a fact about the institution rather than an obligation on anyone in it.

Where the numbers are supposed to come from#

Thresholds are not chosen; they are derived. The starting point is capacity — the maximum loss, concentration or outflow the capital and liquidity position could absorb before the institution breached a regulatory minimum or lost the ability to fund itself.

Capacity is arithmetic, and the work that produces it already exists in most institutions inside the capital and liquidity assessment cycle.

Appetite is then set inside capacity, and the distance between the two is the deliberate part — the buffer the board keeps so that being wrong is survivable. Stating that distance and the reasoning behind it is what gives a threshold a defensible origin, and it is the difference between a number the institution can explain and a number it has to defend.

A threshold derived from capacity can be explained to anyone who asks, because the arithmetic behind it is the institution’s own.

Where it goes wrong#

Statements that do not bind fail in a small number of recognisable ways, and the failures are structural rather than a matter of drafting quality.

  • **The statement speaks in adjectives.** Moderate appetite for credit risk, low appetite for operational risk, no appetite for conduct risk. Every institution can sign these and no decision can be tested against them, because two people reading the same word will place the boundary in different places.
  • **The thresholds were set where the business already was.** Taking last year’s positions and rounding outward produces a statement that has never been breached and never will be, which is then reported each quarter as evidence that the framework is working.
  • **The cascade stops at the first business line.** Group-level measures exist, divisional ones are inherited without translation, and at desk level nobody can say which limit expresses appetite and which expresses something else entirely.
  • **The qualitative risks are handled by declaring zero appetite.** Zero appetite for conduct failures reads well and guides nothing, because it offers no way to rank two imperfect options — which is the only situation in which guidance is needed.
  • **Nothing has ever escalated.** Years of green reporting is read as good management. It is more often evidence that the thresholds are not where the risk is.

These failures compound in a particular order. Adjectives make thresholds unnecessary, absent thresholds make a cascade impossible, and an absent cascade means the statement is never consulted where risk is actually taken — at which point the annual refresh becomes a formatting exercise.

What a statement that binds looks like#

A statement that binds is recognisable from the outside by four properties, none of which concerns its prose.

  • Every quantitative measure has a threshold whose derivation from capacity can be shown on request.
  • Every measure has one named owner, and that owner is the person who would have to act rather than the person who compiles the report.
  • Breaches occur, are escalated, and are visible in board reporting as a normal feature rather than an incident — a framework without breaches is a framework without information.
  • The statement is cited in decision papers, which is the property that cannot be manufactured after the fact.

The fourth is the one worth checking first, because it is the only one that cannot be produced by improving the document.

What to do next#

The diagnostic costs an afternoon. Take the statement and the last twelve months of significant risk decisions — a concentration accepted, a market entered, a portfolio bought, a limit raised — and ask, for each, whether the statement was consulted and whether it changed the answer.

If the answer is no for all of them, the problem is rarely the wording. It is somewhere in the chain between the document and the desks: thresholds with no derivation, measures with no owner, or a cascade that was never built. Each of those is fixable, and each is fixed in a different place.

Frequently asked

What is a risk appetite statement?

A risk appetite statement is a board-approved document setting out the amount and type of risk an institution is willing to accept in pursuit of its strategy, expressed in measures specific enough that a decision can be tested against them. It contains a short qualitative preamble tying appetite to strategy, quantitative measures with a stated basis of measurement, thresholds on each measure, qualitative statements for risks that resist a single number, named ownership for every measure, and an escalation path stating what happens when a threshold is crossed. Its purpose is not to describe the institution’s attitude to risk but to make certain answers unavailable in advance, so a boundary agreed in calm conditions governs a decision taken under pressure.

Where do risk appetite thresholds come from?

Thresholds are derived rather than chosen. The starting point is capacity — the maximum loss, concentration or outflow the capital and liquidity position could absorb before the institution breached a regulatory minimum or lost the ability to fund itself. Appetite is then set inside capacity, and the distance between the two is the deliberate buffer the board keeps so that being wrong remains survivable. Stating that distance and its reasoning is what gives a threshold a defensible origin. Thresholds set instead by rounding outward from where the business already sits produce a statement that has never been breached and never will be, which is the most common reason an appetite framework reports green indefinitely.

How do you know whether a risk appetite statement actually works?

Name a decision in the last year that the statement changed. That single question separates a statement that binds from one that describes, and it cannot be answered by improving the document. Take the last twelve months of significant risk decisions — a concentration accepted, a market entered, a portfolio bought, a limit raised — and ask for each whether the statement was consulted and whether it altered the outcome. A supporting check is whether breaches ever occur: a framework in which no threshold has ever been crossed is more often evidence that the thresholds are not where the risk is than evidence of good management.

How should a risk appetite statement handle risks that cannot be quantified?

By stating what the institution will not do, rather than how much it dislikes doing it. Declaring zero appetite for conduct or compliance failures reads well and guides nothing, because it gives nobody a way to rank two imperfect options — which is the only situation in which guidance is needed. A usable qualitative statement names the specific behaviours, products, client types or practices that are out of bounds, names who may authorise an exception and on what evidence, and pairs itself with indicators that would show the boundary being approached. It is written for the person who has to make a judgement call at short notice, not for the reader of the annual report.

More where this came from

Browse the full resources hub, or subscribe in the footer for occasional substantial pieces.

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.