Risk Appetite, Tolerance and Limits in Banks Explained

Learn the difference between risk capacity, appetite, tolerance and limits in banks and credit unions, and how to test whether an appetite statement works.

9 min read · From the course Enterprise Risk Management in US Banks and Credit Unions with Python

Risk capacity is the most risk an institution could absorb before it fails. Risk appetite is the amount of risk it chooses to carry, tolerance is how far it will let things drift from that choice before it acts, and a limit is the number that stops a specific transaction. One question tells a working framework apart from a decorative one: could this be breached? If nobody could ever look at a number on some ordinary day, say the institution is outside appetite, and then change something, the institution does not have a risk appetite. It has a statement of hope.

Four words that mean different things

In everyday speech these words get used interchangeably. In enterprise risk management they mean quite different things, and the clearest way to keep them apart is to ask who decides each one.

  • Capacity is the most risk the institution could absorb before it fails. It is set by capital, by earnings, by liquidity and by what the regulator will permit. Capacity is a fact about the institution. Nobody votes on it. You can measure it, and you can be wrong about it, but you cannot choose it.
  • Appetite is the amount of risk the institution chooses to carry in pursuit of its strategy. It is a decision, made by the board, and it could have been made differently.
  • Tolerance is the variation around that choice that the institution will accept before it acts. Appetite says where we intend to be. Tolerance says how far we can drift above or below that before somebody has to do something. It is decided at the same time as appetite but answers a different question.
  • A limit is the number that actually stops a specific transaction. This is where the framework stops being a document and becomes a lending officer being told no. Some limits are approved by the board itself. Many are set further down, in credit policy. It is the only one of the four a lending officer ever meets.

How they fit together

Appetite sits inside capacity, and it must sit strictly inside. An institution that chooses to carry exactly as much risk as it could survive has left itself no buffer and no margin for being wrong about its own capacity. Being wrong about capacity is the ordinary condition in banking. The gap between capacity and appetite is where being wrong is allowed to happen.

Limits, in turn, sit inside appetite. That is how a board's decision reaches a random afternoon.

The breach test: could this statement ever be false?

Most banks and credit unions of any size have a risk appetite statement, and a great many of them are useless. Not badly intentioned or badly written, just incapable of doing their job. Consider sentences of the kind that fill real appetite statements:

  • We have a conservative risk culture.
  • We seek to minimize operational losses.
  • We have no appetite for reputational damage.
  • Risk is managed within prudent bounds.

On what day would any of these be false? What measurement, taken on what date, would tell the board that one had been breached? There is none. Minimize is not a threshold. Conservative is not a number. These sentences cannot be wrong, which is exactly why they are worthless. A statement that cannot be wrong carries no information.

The third sentence deserves special attention because it sounds the most responsible and is the most hollow. Nobody has an appetite for reputational damage. Saying so commits the institution to nothing.

A usable appetite statement needs four things:

  1. A named measure, which means you have decided how the thing is counted.
  2. A threshold on that measure.
  3. A frequency at which it is checked, because a threshold nobody looks at is not a control.
  4. A named person who has to do something when it is crossed.

The uncomfortable consequence is that a usable appetite statement is sometimes untrue. It has to be capable of being false, or it is not saying anything.

A quick diagnostic for any institution: ask how many appetite breaches were reported to the board last year. If the answer is none, and has been none for several years, the likeliest explanation is not exceptional discipline. It is that the thresholds have been set where nothing ever reaches them.

Risk appetite is a shape, not a level

A common mistake is to picture appetite as a single dial running from cautious to reckless, with the board picking a setting. A sensible institution says something more like this: we will take more credit risk and less operational risk, because credit risk is what we are paid for and operational risk is not. We will accept concentration in commercial lending and fund ourselves conservatively to compensate. We intend to grow this segment and shrink that one.

Each of those is a trade-off, and every real decision an institution makes is a trade-off of that kind. A single overall level cannot express any of them, so it cannot inform any decision.

Stating appetite by category requires categories in the first place. That is what a risk taxonomy is for: not filing, but giving the institution a vocabulary to say it wants this much of one risk and less of another. An institution with a vague taxonomy cannot state a shaped appetite. Taxonomy supplies the categories, governance supplies someone to approve the shape and someone to report against it, appetite supplies the shape, and limits make it bite.

Following the chain: an Acme Bank example

At Acme Bank, a fictional teaching institution, commercial real estate and construction together stand at 186% of total capital. That figure is an observation, a measurement of where the institution stands right now. On its own it says nothing about whether that is acceptable.

  • Appetite is the next question, and it is a question for the board, not for the number. Is this where we intend to be? Did we choose it, or did it pile up while nobody was adding it up? The second possibility is extremely common, and it is the honest reason concentration limits exist.
  • Tolerance comes next. If the board says this is roughly where it means to be, how far may it drift before someone acts? It will drift. Loans repay, new ones are written, and a bad year's losses can shrink the capital under the ratio without anyone lending another dollar.
  • The limit is the operational end: the number that means a particular deal on a particular afternoon is denied.

The chain runs measurement, then intention, then drift, then the thing that stops a transaction. And a limit should never be quoted without its measure and its basis. Otherwise it gets repeated in a paper next quarter, and by then nobody can say what it was measured against.

What a limit needs, including what happens at the edge

A limit has two parts, and the second is the one that gets neglected.

The limit itself

  • A measure that is already produced. If measuring it takes a special exercise, it will be measured late and eventually not at all.
  • A threshold someone can compute today, not after a project.
  • A stated frequency.
  • An accountable owner.
  • A documented basis for the number. Why this level and not a fifth higher? A limit nobody can justify gets moved the first time it is challenged or becomes inconvenient.

The exception process

  • Who is told, and how quickly?
  • Who may approve an exception, and for how long? This must be someone other than the person who wants the exception.
  • What happens if the breach persists? A breach lasting a year is a different animal from one lasting a week.
  • Does new business in that category stop in the meantime?
  • How does the board find out? That is not the same question as whether it finds out eventually.

The exception process is the real design, not an afterthought. Every limit gets breached eventually, and most breaches are not emergencies. A property revaluation can push a ratio through a threshold with nobody having done anything. If there is no orderly way to approve an exception, people face a choice between stopping perfectly good business and quietly not mentioning the number. A rigid framework with no exception path does not produce discipline. It produces concealment, reliably.

Why risk appetite statements fail, and what works instead

Five failure modes

  1. Written to be approved, not used. If the goal is to get through a board meeting without difficulty, you write things nobody can object to, and those commit to nothing.
  2. Aspirations where thresholds should be.
  3. No owner. If nobody is accountable for a measure, nobody is ever wrong when it drifts.
  4. Never revisited when strategy changes. The institution expands into a new business and the statement is reapproved unchanged. Appetite is meant to constrain current strategy and be decided alongside it.
  5. No connection between the appetite statement and the operating limits. The board approves a framework while credit policy and treasury set their own limits, each through its own history and committee. Neither refers to the other, and the limits are the ones that bind. What the board approved is not what the institution does. This is the most common failure and the most damaging.

Five features of a working framework

  1. Stated by category, using the institution's own taxonomy, so appetite and risk reporting share a vocabulary.
  2. Every statement has a measure, a threshold and an owner. Two out of three does not work: a measure and threshold with no owner drifts, and a measure and owner with no threshold cannot be breached.
  3. Limits are derived from the appetite and say so explicitly. The document setting a limit references the appetite statement it comes from.
  4. Breaches are reported, including ones that turned out to be fine. If reporting a breach is punished, breaches stop being reported long before they stop happening.
  5. It is reviewed when strategy changes, not only on an annual cycle.

The practical tell

Pick a lending officer's approval authority and trace it upward, asking why that number? at every step. Where the framework works, the trail runs from that authority to a portfolio limit, to a category appetite, to a sentence the board approved, and everyone along the way knows the next step up. Where it does not, the trail stops after one step, at a number someone set years ago for a reason nobody remembers.

Key takeaways

  • Nobody decides capacity. It is measured, and you can only be wrong about it.
  • The board decides appetite and must leave a gap below capacity, because that gap is where being wrong is allowed to happen.
  • Tolerance answers how far you can drift before someone has to act. A limit is where the chain reaches the business.
  • Appetite is a shape, not a level, because every real decision is a trade-off between risk categories.
  • A statement that cannot be false says nothing. Every appetite measure needs a measure, a threshold, a checking frequency and an owner.
  • A framework that has never reported a breach usually has thresholds set out of reach.
  • A limit without an exception process does not produce discipline. It produces concealment.
  • Test any framework by tracing a lending officer's authority back up to a sentence the board approved.

More from Enterprise Risk Management

Educational content only, not legal, accounting or investment advice.