Skip to content

FRM Exam Part II · Integrated Risk Management

Risk Appetite and Risk Governance for FRM Part II

Updated 11 October 2026 · Fact-checked

Risk appetite is the amount and type of risk a firm is willing to take to meet its strategy. The board approves it, sets tolerances and limits below it, and assigns duties across three lines of defense. To solve questions, identify who owns what and whether the item is appetite, tolerance or limit.

Understand Risk Appetite and Risk Governance

Risk appetite is the aggregate level and type of risk a firm is willing to accept to pursue its objectives. It is a top-down choice made by the board with senior management. It is written in a risk appetite statement (RAS), which mixes qualitative statements (for example, no tolerance for regulatory breaches) with quantitative metrics (capital ratio, earnings volatility, liquidity coverage).

Appetite is then cut into smaller pieces. Risk tolerance is the acceptable variation around a target or the maximum deviation allowed for a given risk type. Risk limits are the operational controls set for business lines, desks or portfolios, such as a VaR limit, a single-name concentration limit or a stop-loss. Limits are set tighter than tolerance, and tolerance sits inside appetite. This gives early warning before the firm reaches its outer boundary. Many firms use a risk capacity concept too: the maximum risk the firm could bear before breaching capital, liquidity or regulatory constraints. Appetite must always sit below capacity.

Governance assigns who does what. The board approves the RAS, strategy and risk framework, and challenges management. A board risk committee usually does the detailed oversight. The CEO is accountable for implementing the framework. The Chief Risk Officer (CRO) leads the independent risk function, reports to the board risk committee, and should have enough stature and direct access to the board. The CRO should not be pressured by revenue-producing units.

The three lines of defense model separates roles. The first line, the business units, owns and manages risk day to day. The second line, risk management and compliance, sets policy, monitors, and challenges independently. The third line, internal audit, gives independent assurance to the board on whether the first two lines work. Good governance also needs a sound risk culture and pay that does not reward excess risk-taking. Breaches of limits need clear escalation and reporting to the right level.

Key formulas to remember

Hierarchy of risk boundaries
Limits < Risk tolerance < Risk appetite < Risk capacity
Each level is nested inside the next. Limits trigger early action; capacity is the hard ceiling.
Line of defense roles
1st line = owns and manages risk; 2nd line = oversees and challenges; 3rd line = independent assurance
Internal audit is third line and reports to the board, usually via the audit committee.
Risk appetite statement content
RAS = qualitative statements + quantitative metrics + limits and escalation process + roles
A good RAS links to strategy, capital and liquidity plans and is reviewed regularly.
Limit utilization
Utilization = Current exposure ÷ Limit
Above 100% is a breach. Many firms also set early warning triggers below 100%, such as 80%.

How to solve Risk Appetite and Risk Governance questions

Governance questions test classification and ownership. Use the same sequence each time.

  1. 1Read the scenario and note the entity: board, CEO, CRO, business unit, audit.
  2. 2Decide what the item is: appetite, tolerance, limit, capacity, or a policy.
  3. 3Check the hierarchy: is the proposed limit inside tolerance, and tolerance inside appetite and capacity?
  4. 4Assign the owner by line of defense: doing risk is first line, challenge is second, assurance is third.
  5. 5Check independence and reporting: does the CRO or audit have a conflict, or lack board access?
  6. 6Look for culture or incentive problems such as pay tied only to revenue.
  7. 7Match the answer to the best practice that fixes the weakness, and eliminate options that blur lines.

Quickest way: Role and level test

When to use it: Use when the question asks who is responsible or which term fits, and time is short.

  1. Ask: who owns it? Doing equals first line, challenging equals second, assuring equals third.
  2. Ask: who approves it? Appetite and strategy go to the board.
  3. Ask: is it a number for a desk? That is a limit, not appetite.
  4. Reject any option that makes the same unit both take and independently control the risk.

Common mistakes in Risk Appetite and Risk Governance

  • Treating risk appetite and risk limits as the same thing.

    Both are described with numbers and both constrain risk-taking.

    Fix: Appetite is firm-wide and board-level. Limits are operational and set for units within tolerance.

  • Placing risk management in the first line.

    Risk managers sit close to the business and attend its meetings.

    Fix: Independent risk and compliance are second line. Only units that take risk and own it are first line.

  • Saying internal audit sets limits or monitors daily risk.

    Audit reviews risk controls, so it seems involved in them.

    Fix: Audit gives independent assurance to the board. It does not own or manage risks.

  • Thinking the CRO reports mainly to the head of trading or CFO.

    Reporting lines in some firms look like this in practice.

    Fix: Best practice gives the CRO independence and direct access to the board risk committee.

  • Setting a limit above risk tolerance or capacity.

    Students focus on the business need and ignore the nesting.

    Fix: Limits must sit inside tolerance, which sits inside appetite, which sits below capacity.

Worked examples

Example 1

A bank's board approves a risk appetite that Tier 1 capital ratio will not fall below 12%. The regulatory minimum plus buffers is 10.5%. The trading head sets a desk VaR limit of USD 40 million. Which statement is correct?

Show the solution
  1. The 12% floor is firm-wide and board-approved, so it is a risk appetite (or tolerance) metric.
  2. The 10.5% requirement is a regulatory constraint close to risk capacity.
  3. 12% is above 10.5%, so appetite sits inside capacity, which is consistent.
  4. The USD 40 million desk VaR is an operational limit, which should be set so aggregate desk risk stays consistent with the 12% floor under stress.
  5. Limits do not define appetite and the trading head cannot override board appetite.

Answer: The 12% floor is board-level appetite, 10.5% is close to capacity, and the desk VaR is a limit that must be consistent with appetite.

Example 2

A bank's credit officers in the lending business approve loans and monitor them. A separate risk team sets credit policy and independently reviews large exposures. Internal audit reviews whether both functions follow policy and reports to the audit committee. Classify each group and identify one weakness if the CRO reports to the head of lending.

Show the solution
  1. Credit officers originate and manage the risk, so they are first line.
  2. The risk team sets policy and challenges the business, so it is second line.
  3. Internal audit gives independent assurance, so it is third line.
  4. If the CRO reports to the head of lending, the second line is under the influence of the unit it should challenge.
  5. This weakens independence. The CRO should report to the CEO and have direct access to the board risk committee.

Answer: Lending is first line, risk is second line, audit is third line. The weakness is the CRO's lack of independence, fixed by direct board access.

Exam tips

  • Memorize the nesting: limits inside tolerance, tolerance inside appetite, appetite below capacity.
  • In line-of-defense questions, ask who takes the risk and who challenges it. If the same group does both, it is a weakness.
  • Look for hints of weak culture: pay tied only to revenue, ignored limit breaches, CRO without board access.
  • Wrong options often give the board an operational role or give audit a management role. Remove them first.

Practice questions from Integrated Risk Management

Risk Appetite and Risk Governance in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Appetite and Risk Governance: frequently asked questions

What is the difference between risk appetite and risk tolerance?

Risk appetite is the overall amount and type of risk a firm is willing to accept to meet its strategy. Risk tolerance is the acceptable deviation or maximum level for a specific risk type, set within appetite.

Who approves the risk appetite statement?

The board approves it, usually after work by the board risk committee and senior management. Management then turns it into tolerances and limits.

What does each line of defense do?

The first line owns and manages risk in the business. The second line, risk management and compliance, sets policy and independently monitors. The third line, internal audit, provides independent assurance to the board.

Why must the CRO be independent?

The CRO must be able to challenge business decisions and escalate concerns without pressure from revenue-producing units. Direct access to the board and a senior standing in the firm support this.