Skip to content

FRM Exam Part I · Enterprise Risk Management and Future Trends

Risk Appetite and Risk Governance Structure for FRM Part I

Updated 11 October 2026 · Fact-checked

Risk appetite is the amount and type of risk a firm is willing to take to pursue its strategy. The board approves it, management turns it into tolerances and limits, and committees and the CRO oversee it. To answer questions, identify who owns each task and how the levels cascade.

Understand Risk Appetite and Risk Governance Structure

Risk appetite is the aggregate level and type of risk a firm is willing to accept to achieve its objectives. It is a top-down statement set by the board. It links strategy, capital and risk taking. A firm cannot choose a growth target without also choosing how much risk it will bear to reach it.

Risk tolerance is narrower. It is the acceptable variation around a target, or the maximum deviation the firm will accept for a specific risk or objective. Appetite is the broad stance, for example 'we accept moderate credit risk but low market risk'. Tolerance puts a boundary on it, for example 'earnings volatility must not exceed a stated amount'. Be careful: some sources use the two words loosely, so read what the question asks you to separate.

Risk limits are the day-to-day controls. They are set by management for business lines, desks, products or counterparties. Examples are a VaR limit, a notional limit, a single-name concentration limit or a stop-loss. Limits must be consistent with tolerance, and tolerance with appetite. Many firms add early-warning triggers below a hard limit, so management can act before a breach.

A good risk appetite statement (RAS) is written, approved by the board, and covers quantitative measures (capital ratios, loss budgets, liquidity metrics, VaR) and qualitative statements (reputation, conduct, compliance). It is linked to strategy and business planning, communicated down the firm, monitored and reviewed regularly.

Risk governance assigns responsibility. The board has ultimate accountability. It approves the strategy, appetite and the framework, and it challenges management. A board risk committee, usually mostly independent directors, does the detailed work. It reviews risk reports, advises on appetite, oversees the CRO and checks that limits are respected. Senior management, led by the CEO, implements the framework. The CRO runs an independent risk function. Under the three lines of defense model, business units own and manage risk (first line), risk management and compliance oversee it (second line), and internal audit gives independent assurance (third line).

Key formulas to remember

Cascade of risk control
Risk appetite (board) → Risk tolerance → Risk limits (management) → Desk and trader limits
Each lower level must be consistent with and no looser than the level above it.
Three lines of defense
1st line: business units own risk | 2nd line: risk management and compliance oversee | 3rd line: internal audit gives independent assurance
Audit must stay independent of both the business and the risk function.
Limit utilization
Utilization = Current exposure ÷ Limit × 100%
Over 100% is a breach. Early-warning triggers usually sit below 100%.
Capital buffer headroom
Headroom = Actual capital ratio − Board-set minimum ratio
Appetite statements often set a target above the regulatory minimum.

How to solve Risk Appetite and Risk Governance Structure questions

Most questions on this topic are conceptual. Use the same sequence each time to avoid being drawn to a plausible but wrong option.

  1. 1Identify what the question is really testing: definition, who is responsible, or consistency between levels.
  2. 2If it is a definition, place the item on the cascade: appetite (broad, board), tolerance (acceptable deviation), limit (operational control).
  3. 3If it is about responsibility, assign the task: the board approves and challenges, the board risk committee reviews in detail, management implements, the CRO is independent, audit assures.
  4. 4Check independence: the CRO should not report only to the business heads, and audit should not run risk limits.
  5. 5For numbers, compute utilization or headroom and compare with the limit or trigger.
  6. 6Eliminate options that make the board run daily trading or let traders set their own limits.
  7. 7Pick the option that links risk taking to strategy, capital and regular review.

Quickest way: Who sets it, who runs it, who checks it

When to use it: Use for any multiple-choice question about roles, definitions or the structure of risk governance.

  1. Ask: is this setting direction, running the process, or checking it?
  2. Direction (appetite, strategy, framework approval) goes to the board.
  3. Running (limits, reporting, implementation) goes to management and the first line.
  4. Independent oversight goes to the CRO and second line; assurance goes to internal audit.
  5. Remove options that mix these roles or break independence.

Common mistakes in Risk Appetite and Risk Governance Structure

  • Treating risk appetite and risk tolerance as identical.

    Everyday language uses both words for 'how much risk we accept'.

    Fix: Appetite is the overall type and amount of risk sought. Tolerance is the acceptable deviation or boundary. Limits are the operating controls.

  • Thinking the board sets individual trading limits.

    Students assume top authority means control of every detail.

    Fix: The board sets appetite and approves the framework. Management sets and monitors limits within it.

  • Placing the CRO under a business head.

    Students focus on reporting convenience rather than independence.

    Fix: The CRO should have independence, direct access to the board or its risk committee, and sufficient seniority.

  • Confusing the second line with internal audit.

    Both seem to 'check' the business.

    Fix: The second line oversees and challenges risk taking continuously. Audit gives independent assurance on the whole control framework, including the second line.

  • Assuming a RAS is only quantitative.

    Exam focus on VaR and capital ratios hides the qualitative side.

    Fix: A strong RAS also covers conduct, reputation and compliance statements, because not all risks can be measured.

  • Treating limits as fixed forever.

    Limits look like static rules.

    Fix: Limits and appetite are reviewed when strategy, markets, capital or the firm's risk profile change.

Worked examples

Example 1

A bank's board sets a rule that the trading book's 1-day 99% VaR must not exceed $50 million. The desk's current VaR is $41 million. The early-warning trigger is 85% of the limit. (a) What is limit utilization? (b) Is the trigger reached?

Show the solution
  1. Utilization = Current exposure ÷ Limit × 100%.
  2. Utilization = 41 ÷ 50 × 100% = 82%.
  3. Trigger level = 0.85 × 50 = $42.5 million.
  4. Current VaR of $41 million is below $42.5 million, so the trigger is not reached.

Answer: Utilization is 82%. The early-warning trigger is not reached, and there is no breach.

Example 2

Which statement about risk governance is most accurate? A) The board approves risk appetite and the CRO sets it independently of the board. B) The board approves risk appetite, management sets limits consistent with it, and the CRO provides independent oversight. C) Internal audit sets limits so they are independent. D) Business units set their own appetite and report it to the CRO for approval.

Show the solution
  1. Appetite is a board responsibility, so A fails because the CRO does not set it independently of the board.
  2. Setting limits is a management task, so C fails and audit must stay independent of this activity.
  3. Business units operate within the appetite and do not set it, so D fails.
  4. B matches the cascade: board approves appetite, management sets limits within it, and the CRO oversees independently.

Answer: B

Exam tips

  • Learn the cascade of appetite, tolerance and limits and match each to its owner.
  • Expect questions on the board risk committee: it reviews and challenges, but management stays responsible for running risk.
  • Watch for independence traps involving the CRO and internal audit.
  • If the stem includes numbers, compute utilization or headroom before reading the options.
  • A good RAS links to strategy, capital and planning, and is reviewed regularly. Pick options that say so.

Practice questions from Enterprise Risk Management and Future Trends

Risk Appetite and Risk Governance Structure in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Appetite and Risk Governance Structure: frequently asked questions

What is the difference between risk appetite and risk tolerance?

Risk appetite is the overall amount and type of risk a firm is willing to take to meet its objectives. Risk tolerance is the acceptable variation or maximum deviation around a specific objective or risk. Limits then turn tolerance into operating controls.

What does a board risk committee do?

It helps the board oversee risk. It reviews the risk appetite and framework, examines risk reports, monitors breaches and oversees the CRO. It does not run daily risk taking, which stays with management.

How do firms set risk limits in ERM?

Management starts from the board's appetite and tolerance, then allocates them to business lines, desks and counterparties. Limits use measures such as VaR, notional, concentration and loss triggers. They are monitored, escalated when breached and reviewed periodically.

What should a risk appetite statement contain?

It should be written and board approved. It should include quantitative measures, such as capital, liquidity and earnings volatility, and qualitative statements on conduct and reputation. It should also be tied to strategy and communicated across the firm.