Skip to content

CFA Level I Exam · Introduction to Risk Management

Risk Governance and Risk Tolerance for CFA Level I

Updated 7 October 2026 · Fact-checked

Risk governance is the top-level structure of oversight, accountability and decision rights for risk in an organization. It sets the risk tolerance, and enterprise risk management (ERM) applies it across the firm. To solve questions, identify who sets, who executes and who monitors, then match the term to its role.

Understand Risk Governance and Risk Tolerance

Start with a simple split. Risk governance is about who is in charge of risk and how decisions are made. Risk management is the day-to-day work of identifying, measuring and treating risks. Governance sets the rules and direction. Management carries them out.

The board of directors has ultimate oversight. It approves the risk framework, sets or approves the firm's risk tolerance, and checks that management follows it. Senior management, often led by a chief risk officer (CRO), builds and runs the systems, reports on exposures and keeps risk within limits. Many firms use a risk committee of the board to give risk focused attention.

Enterprise risk management (ERM) is a firm-wide approach. It looks at all risks together, not in silos, so that interactions and concentrations show up. A good ERM framework covers risk governance, risk identification and measurement, risk infrastructure, policies and processes, risk mitigation and management, communication, and strategic risk analysis. The benefit is a consistent, whole-firm view of risk against reward.

Risk tolerance is the amount of risk, and potential loss, an organization is willing and able to accept. It depends on both willingness and capacity to bear loss. It should be set before choosing strategies, because it defines the boundary for everything else.

Risk budgeting turns tolerance into practice. The total acceptable risk is allocated across units, strategies or portfolios, usually measured in a common metric such as value at risk or tracking risk. Each unit then gets a share of the risk budget, and the aim is to use risk where it is expected to be best rewarded.

Key formulas to remember

Risk tolerance
Risk tolerance = willingness to take risk + ability (capacity) to bear loss
Set by the board and management before strategy. The more restrictive of the two usually binds.
Risk budget
Total risk budget = Σ risk allocated to each unit or strategy
Allocations are in a common risk measure. Because of diversification, standalone risks usually do not add up to total risk.
Governance vs management
Governance = set direction and oversee; Management = identify, measure, treat and report
Use this split to answer who-does-what questions.

How to solve Risk Governance and Risk Tolerance questions

Questions on this topic are mostly conceptual. Use this routine to separate similar terms.

  1. 1Read the stem and mark the key verb: set, approve, oversee, implement, monitor, allocate.
  2. 2Decide the level: board (oversight and tolerance), senior management or CRO (execution), or business unit (risk ownership).
  3. 3Decide the scope: one risk in one unit points to risk management; a firm-wide, combined view points to ERM.
  4. 4Check whether the stem is about how much risk is acceptable (risk tolerance) or how that amount is divided up (risk budgeting).
  5. 5Eliminate any option that gives the board a day-to-day task or gives units the job of setting firm-wide tolerance.
  6. 6Choose the option that matches the role and scope, then reread the stem for a trap word.

Quickest way: Who, what, how much

When to use it: Use it for any definition or role question when you have under a minute.

  1. Who? Board oversees, management implements.
  2. What? Governance sets framework, ERM applies it firm-wide.
  3. How much? Tolerance is the limit, budget is the split.
  4. Cross out the two options that swap these roles.

Common mistakes in Risk Governance and Risk Tolerance

  • Treating risk governance and risk management as the same thing.

    Both words sound alike and appear together in the curriculum.

    Fix: Governance is oversight and structure. Management is the process of handling risks inside that structure.

  • Saying risk management should eliminate risk.

    Risk sounds like something to avoid.

    Fix: The goal is to take the right amount of risk for the expected reward and within tolerance, not to remove all risk.

  • Confusing risk tolerance with risk budgeting.

    Both involve setting limits.

    Fix: Tolerance is the overall amount of acceptable risk. Budgeting divides that amount among units or strategies.

  • Defining ERM as managing each risk in its own unit.

    Candidates picture traditional silo risk management.

    Fix: ERM is firm-wide and integrated, so it captures interactions and concentrations across risks.

  • Assuming tolerance depends only on how comfortable managers feel.

    Willingness is easier to picture than capacity.

    Fix: Include ability to bear loss, such as capital, liquidity and obligations. Both matter.

Worked examples

Example 1

A firm's board approves a framework stating the maximum loss the firm will accept in a year, and then asks management to report against it quarterly. Which concept does the board's action best describe? A. Risk budgeting. B. Setting risk tolerance as part of risk governance. C. Hedging a specific exposure.

Show the solution
  1. The board is approving a firm-wide maximum acceptable loss. That is the amount of risk the firm will accept.
  2. This is oversight and direction, which is governance, not day-to-day treatment of a risk.
  3. Option A would require dividing the limit among units, which the stem does not say.
  4. Option C is a specific risk treatment, not a board framework.

Answer: B

Example 2

A CRO splits the firm's total risk limit across the equity, credit and trading desks using one common risk measure, then tracks each desk's use of its share. This process is best described as: A. Risk governance. B. Risk tolerance. C. Risk budgeting.

Show the solution
  1. The firm already has a total risk limit, so tolerance is set.
  2. The CRO is dividing that total among desks in a common measure.
  3. Dividing the acceptable total across units and monitoring use is risk budgeting.
  4. Governance would describe board oversight structure, and tolerance would describe the total limit itself.

Answer: C

Exam tips

  • Look for the actor in the stem. Board points to oversight and tolerance; CRO or management points to implementation.
  • Watch for the words firm-wide or integrated. They signal ERM.
  • Remember tolerance is a ceiling set first, and budgeting follows it.
  • With three options, eliminate any that give a role to the wrong level, then pick between the remaining two on scope.
  • Expect definitions and role matching rather than calculations.

Practice questions from Introduction to Risk Management

Risk Governance and Risk Tolerance in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Governance and Risk Tolerance: frequently asked questions

What is the difference between risk governance and risk management?

Risk governance is the structure of oversight, accountability and decision rights, led by the board. Risk management is the process of identifying, measuring and treating risks within that structure.

What is risk budgeting in CFA Level I?

Risk budgeting allocates the total acceptable risk across units, strategies or portfolios using a common risk measure. It aims to place risk where the expected reward is best.

What is enterprise risk management?

ERM is a firm-wide, integrated approach to managing all of an organization's risks together. It captures interactions and concentrations that separate silos can miss.

Who sets risk tolerance?

The board, with senior management, sets or approves risk tolerance. It reflects both the willingness and the ability of the organization to bear losses.