FRM Exam Part II · Governance
Credit Risk Governance Framework: Board, Management and Risk Appetite
Updated 11 October 2026 · Fact-checked
A credit risk governance framework sets who decides, who executes and who checks credit risk in a bank. The board approves risk appetite and policies. Senior management turns them into limits and processes. Risk committees and independent risk and audit functions monitor and challenge. To solve questions, match each duty to the right body.
Understand Credit Risk Governance Framework
Credit risk governance is the system of roles, policies and reporting lines that keeps a bank's lending within the risk it is willing and able to take. It does not measure risk itself. It decides who owns decisions about risk and who holds them to account.
The board has ultimate responsibility. It approves the credit risk appetite statement (RAS), the credit risk strategy and the main credit policies, and it reviews them regularly. It sets the tone through risk culture and compensation. The board does not approve every loan. It sets the boundaries and checks that they are respected.
Senior management (the CEO, CRO and heads of business) carries out the board's strategy. It turns appetite into specific limits (by borrower, sector, country, rating grade and product), underwriting standards, approval authorities and monitoring processes. It must report to the board accurately and in good time.
The board risk committee, usually made up of non-executive and often independent directors, gives the board detailed oversight. Management-level committees, such as a credit committee or credit policy committee, approve large exposures, exceptions and watch-list actions. Under the three lines of defense model, business units own risk (first line), the independent risk function and the CRO oversee and challenge it (second line), and internal audit gives independent assurance to the board (third line).
A risk appetite statement has two parts: qualitative statements (what business the bank will and will not do) and quantitative measures such as maximum non-performing loan ratio, concentration limits, expected loss or capital usage. Appetite sits above risk tolerance and limits. Appetite is the broad level of risk, tolerance is the allowed deviation, and limits are the operating controls.
Key formulas to remember
- Hierarchy of risk control
- Risk capacity ≥ Risk appetite ≥ Risk tolerance ≥ Limits
- Capacity is the maximum risk the bank can bear. Appetite is set below it. Limits are set so that breaches are caught before tolerance is exceeded.
- Allocation of duties
- Board: approves and oversees | Management: implements | Risk function: monitors and challenges | Audit: assures
- Use this as a quick sort for any question asking who is responsible for what.
- Three lines of defense
- 1st line: business owns risk | 2nd line: risk and compliance oversee | 3rd line: internal audit assures
- The CRO belongs to the second line and needs independence and direct access to the board.
- Limit utilisation
- Utilisation = Current exposure ÷ Approved limit
- A ratio above 100% is a limit breach and must be escalated under policy.
How to solve Credit Risk Governance Framework questions
Governance questions test whether you assign the right duty to the right body and spot weak structures. Use the same method each time.
- 1Read the scenario and list the parties involved: board, board risk committee, senior management, CRO, business line, internal audit.
- 2Identify the task in question: setting appetite, setting limits, approving a loan, monitoring, reporting or independent assurance.
- 3Match the task to the level: strategy and appetite to the board, implementation and limits to management, monitoring and challenge to the second line, assurance to audit.
- 4Check independence: does the CRO report independently, or does a business head control risk decisions? Flag any conflict of interest.
- 5Check consistency: do limits and compensation align with the stated appetite, and is the appetite within capital and capacity?
- 6Check information flow: is reporting to the board timely, accurate and covering breaches and exceptions?
- 7Eliminate options that put the board in day-to-day lending, let the first line self-police, or let audit take management decisions.
- 8Choose the option that best preserves independence and clear accountability.
Quickest way: Who does what in 20 seconds
When to use it: Use when the question is a short MCQ asking which body is responsible for a specific credit governance task.
- Underline the verb: approve, set, implement, monitor, challenge, assure.
- Approve or set appetite and policy points to the board.
- Implement or set limits points to senior management.
- Monitor or challenge independently points to the CRO and risk function.
- Assure or test controls independently points to internal audit.
- If an option breaks independence, drop it first.
Common mistakes in Credit Risk Governance Framework
Saying the board approves individual loans.
Students confuse ultimate responsibility with daily decisions.
Fix: The board sets appetite and policy and oversees. Management and credit committees approve transactions within delegated authority.
Treating risk appetite and limits as the same thing.
Both are numerical and both restrict risk.
Fix: Appetite is the board-level amount and type of risk the bank accepts. Limits are the operational tools that keep activity inside it.
Placing internal audit in the second line.
Audit and risk both look like control functions.
Fix: Audit is the third line. It gives independent assurance on the first two lines and does not manage risk.
Letting the CRO report to the head of lending.
It seems efficient for the risk function to sit close to the business.
Fix: The CRO needs independence, seniority and direct access to the board or its risk committee.
Ignoring compensation in governance questions.
Pay feels like an HR topic, not a credit one.
Fix: Incentives that reward volume without regard to risk undermine appetite. Good governance links pay to risk-adjusted results.
Thinking appetite can exceed risk capacity.
Students see appetite as purely a strategy choice.
Fix: Appetite must be set within capacity, which is limited by capital, liquidity and regulatory constraints.
Worked examples
Example 1
A bank's board wants to stop concentration in one sector. Which action best reflects the board's role? A) Approving each large loan to the sector B) Setting a sector concentration measure in the risk appetite statement and requiring regular reporting against it C) Having internal audit set sector limits D) Letting business heads decide the sector mix
Show the solution
- The task is to control concentration, which is an appetite and policy matter.
- Appetite and policy belong to the board, with regular reporting for oversight.
- Option A puts the board in transaction approval, which is management's role.
- Option C gives audit a management function and breaks its independence.
- Option D leaves the first line to police itself without board boundaries.
Answer: B. The board sets a quantitative concentration measure in the risk appetite statement and oversees it through reporting.
Example 2
A bank has an approved limit of $200 million to a corporate group. Current exposure is $230 million after a drawdown. Management did not report this to the board risk committee. Identify the governance failures and the right response.
Show the solution
- Utilisation = 230 ÷ 200 = 115%, so the limit is breached by $30 million.
- First failure: the limit was exceeded, so first-line controls on drawdowns did not work.
- Second failure: the breach was not escalated, so the information flow to the board risk committee failed.
- Right response: report the breach promptly to the committee, and have the appropriate credit authority approve a temporary exception or require the exposure to be reduced.
- The second line (risk function) should review the cause, and internal audit should test whether limit monitoring controls are adequate.
Answer: Utilisation is 115%, a $30 million breach. The failures are weak limit control and missing escalation. The breach should be escalated to the board risk committee and then either approved as a documented exception or reduced, with a review of controls.
Exam tips
- Most questions are role-allocation. Sort the duty by level before reading the options.
- Watch for options that break independence, such as business heads controlling the risk function. These are usually wrong.
- Know the difference between risk capacity, appetite, tolerance and limits, as questions test the order.
- Expect case-style questions about weak governance in a failed bank. Look for missing escalation, poor incentives and an overpowered business line.
- Use precise words: board oversight, management implementation, independent challenge, independent assurance.
Practice questions from Governance
- A bank has Tier 1 capital of USD 2,000 million. Its policy caps exposure to any single counterparty at 10% of Tier 1 capital, and exposures …
- A bank's credit risk appetite statement is being redesigned. Which approach is most consistent with sound governance practice for translatin…
- During a benign credit cycle, a bank's loan officers are under pressure to meet growth targets and begin approving loans with weaker debt-se…
- During a review, internal audit at a bank finds that the credit risk team has been helping relationship managers redesign the loan approval …
- A bank pays loan originators a bonus based solely on the volume of loans booked in the year, paid in full in cash immediately. Which governa…
Credit Risk Governance Framework in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Credit Risk Governance Framework: frequently asked questions
What is the role of the board in credit risk governance?
The board approves the credit risk appetite, strategy and key policies, and oversees management's performance against them. It sets risk culture and reviews reporting on exposures and breaches. It does not approve each loan.
What is a credit risk appetite statement?
It is a board-approved statement of the amount and type of credit risk the bank will accept to meet its strategy. It combines qualitative principles with quantitative measures such as concentration, loss and capital limits.
How does the board oversee credit risk in practice?
It uses a board risk committee, regular management reports, escalation of limit breaches and independent views from the CRO and internal audit. It also reviews policies and incentives.
What is the difference between risk appetite and risk limits?
Appetite is the broad level of risk the board accepts. Limits are specific operational controls, by borrower, sector or product, that keep activity within appetite.