Skip to content

FRM Exam Part II · Risk, Regulation and Organizational Structure

Risk Appetite Frameworks and Risk Culture for FRM Part II

Updated 11 October 2026 · Fact-checked

A risk appetite framework (RAF) is the set of policies, limits, roles and controls through which a firm sets, cascades and monitors the aggregate risk it will accept to meet its strategy. Risk culture is the shared norms that shape risk-taking. To answer questions, link appetite to strategy, capacity, limits, monitoring and escalation.

Understand Risk Appetite Frameworks and Risk Culture

Start with risk capacity. This is the maximum risk a firm can bear before it breaches capital, liquidity or regulatory constraints. Risk appetite is the amount of risk the board chooses to accept, in aggregate, to pursue its strategy. It must sit below capacity. Risk profile is the risk actually being run at a point in time. A sound framework keeps profile within appetite and appetite within capacity.

The risk appetite statement (RAS) is the written expression of appetite, approved by the board. Good statements have qualitative parts (for example, no appetite for conduct breaches or for material regulatory violations) and quantitative parts (for example, a minimum CET1 ratio, a maximum stress loss, a minimum LCR, a cap on single-name concentration). Metrics should be forward-looking, linked to strategy and business plan, and tested under stress, not only in normal conditions.

The RAS is then cascaded. The board sets top-level appetite. Senior management translates it into limits by business line, legal entity, risk type and desk. Risk limits are operational controls, such as VaR limits, notional caps, or counterparty exposure limits. They are narrower and more granular than appetite. Appetite says how much risk the firm accepts overall. Limits are the tools that keep day-to-day activity within that amount. Many frameworks also use triggers or early-warning levels below hard limits, so management acts before a breach.

Governance matters as much as the numbers. The board approves and challenges the RAS. The CEO is accountable for implementing it. The CRO owns the framework and independent monitoring and reports to the board. Business lines own the risks they take (first line). Breaches must have defined escalation, approval and remediation processes. Appetite should feed into strategy, budgeting, capital planning, and compensation.

Risk culture is the set of norms, attitudes and behaviours on risk awareness, risk-taking and controls. Supervisors, such as the FSB in its risk culture guidance, look for four indicators: tone from the top, accountability, effective challenge, and incentives. Signs of weak culture include repeated limit breaches that are waived, bonuses driven by revenue with no risk adjustment, silenced risk staff, slow escalation, and a focus on compliance with rules instead of good judgement. Culture is assessed through surveys, breach and escalation data, audit findings, and staff turnover in control functions.

Key formulas to remember

Ordering of risk concepts
Risk profile ≤ Risk appetite ≤ Risk capacity
Appetite must sit inside capacity. Profile is what is actually being run and is managed to stay within appetite.
Capacity headroom
Headroom = Risk capacity − Risk appetite
Gives the buffer between chosen appetite and the point of regulatory or solvency breach.
Capital buffer against a minimum
Buffer = Actual ratio − Minimum ratio
For example, CET1 of 11.5% against an internal appetite floor of 10.0% leaves 1.5 percentage points.
Utilisation of a limit
Utilisation = Current exposure ÷ Limit
Used to compare against early-warning triggers, such as 80% of limit.
Four indicators of risk culture (FSB)
Tone from the top; Accountability; Effective challenge; Incentives
Use these as a checklist when a case asks you to diagnose culture.

How to solve Risk Appetite Frameworks and Risk Culture questions

Use this sequence for any scenario or definition question on risk appetite or risk culture.

  1. 1Identify what the question tests: a definition (capacity, appetite, limit, profile), design of the RAS, cascading and monitoring, governance roles, or culture.
  2. 2Place the figures or facts on the ladder: profile, appetite, capacity. Check the ordering holds.
  3. 3If numbers are given, compute headroom, buffer or utilisation and compare to the appetite level and any trigger.
  4. 4Decide whether the item is a top-level appetite metric (board, aggregate, strategic) or a limit (management, granular, operational).
  5. 5Check governance: who owns it (board, CEO, CRO, business line) and whether escalation of breaches is defined.
  6. 6For culture questions, map each fact to one of tone from the top, accountability, effective challenge, incentives.
  7. 7Pick the option that is forward-looking, linked to strategy, stress-tested and independently monitored. Eliminate answers that rely on past losses only or on business-line self-policing.

Quickest way: Ladder-and-owner check

When to use it: Use when you have about a minute per question and the options are close.

  1. Write profile, appetite, capacity on scratch paper and place the numbers.
  2. Ask: is this broad and board-level (appetite) or narrow and operational (limit)?
  3. Ask: who is accountable? Board approves, CRO monitors independently, business lines own risk.
  4. For culture, tag the symptom as tone, accountability, challenge or incentives.
  5. Choose the answer that includes stress testing, escalation and a link to strategy.

Common mistakes in Risk Appetite Frameworks and Risk Culture

  • Treating risk appetite and risk limits as the same thing.

    Both are expressed as numbers and both constrain risk-taking.

    Fix: Appetite is the aggregate, board-approved level of risk accepted for strategy. Limits are granular controls set by management to keep activity within appetite.

  • Confusing risk appetite with risk capacity.

    Both describe how much risk a firm can take.

    Fix: Capacity is the maximum the firm can bear. Appetite is what the board chooses to accept and must be below capacity.

  • Assuming the CRO sets the appetite.

    The CRO runs the framework day to day.

    Fix: The board approves appetite. The CRO designs, monitors and reports independently. The CEO is accountable for implementation.

  • Using only backward-looking, normal-time metrics in the RAS.

    Historical VaR and loss data are easy to measure.

    Fix: Good RAS metrics are forward-looking and tested under stress, with capital, liquidity, earnings and qualitative conduct measures.

  • Treating a breach as acceptable if the business is profitable.

    Revenue pressure weakens challenge.

    Fix: Breaches need defined escalation, approval and remediation. Repeated waivers signal weak risk culture.

  • Thinking culture is only about written policies.

    Policies are visible and auditable.

    Fix: Culture is behaviour: tone from the top, accountability, effective challenge, and incentives. Look at actions and pay, not just documents.

Worked examples

Example 1

A bank has a CET1 ratio of 12.0%. Its regulatory minimum plus buffers is 9.0%. The board's risk appetite floor is 10.5%. Under the severe stress scenario, CET1 falls by 2.0 percentage points. Does the bank stay within appetite and capacity under stress?

Show the solution
  1. Stressed CET1 = 12.0% − 2.0% = 10.0%.
  2. Compare with the appetite floor of 10.5%: 10.0% is below it, by 0.5 percentage points.
  3. Compare with capacity, here the regulatory minimum plus buffers of 9.0%: 10.0% is above it, by 1.0 percentage point.
  4. So stress takes the profile below appetite but not through capacity.

Answer: The bank breaches its appetite floor under stress (10.0% vs 10.5%) but stays above its regulatory capacity level of 9.0%. Management should escalate to the board and plan actions such as reducing risk-weighted assets or raising capital.

Example 2

A trading desk has a VaR limit of $20 million. An early-warning trigger is set at 80% of the limit. Current VaR is $17 million. The head of the desk asks to keep adding positions because the limit is not breached. What is the utilisation, and what is the correct response?

Show the solution
  1. Utilisation = 17 ÷ 20 = 85%.
  2. The trigger is 80% × $20 million = $16 million.
  3. Current VaR of $17 million exceeds the trigger, but is below the hard limit.
  4. A trigger exists so management acts before a breach: escalate to the CRO function, review the drivers and agree actions before more risk is added.

Answer: Utilisation is 85%, above the 80% trigger but below the limit. No hard breach has occurred, but the trigger requires escalation and review before adding risk. Adding positions simply because the limit is not breached defeats the purpose of early warning.

Exam tips

  • Expect definition-based items that separate appetite, capacity, profile and limits. Learn the ordering profile ≤ appetite ≤ capacity.
  • When a case lists symptoms like waived breaches or revenue-only bonuses, name the culture indicator involved: tone, accountability, challenge or incentives.
  • The best RAS answer is usually the one that is board-approved, linked to strategy, forward-looking, stress-tested and cascaded to limits.
  • Be precise on roles: board approves, CEO is accountable, CRO monitors independently, business lines own risk.
  • Do the small arithmetic carefully: stressed ratio, headroom and utilisation. Compare each to the correct reference level.

Practice questions from Risk, Regulation and Organizational Structure

Risk Appetite Frameworks and Risk Culture in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Risk Appetite Frameworks and Risk Culture: frequently asked questions

What is the difference between risk limits and risk appetite?

Risk appetite is the aggregate level and type of risk the board accepts to pursue strategy. Limits are specific, operational controls, such as VaR or notional caps by desk, that keep activity within that appetite. Appetite is set at the top and limits are derived from it.

How do you set a risk appetite statement?

Start from strategy and risk capacity, including capital and liquidity constraints. Define qualitative statements and quantitative metrics, test them under stress, and have the board approve them. Then cascade to business lines as limits and set monitoring and escalation procedures.

What are the indicators of a sound risk culture in financial institutions?

Supervisory guidance points to tone from the top, accountability, effective challenge and incentives. Sound cultures show leaders who model good behaviour, clear ownership of risk, open challenge from risk staff, and pay that rewards risk-adjusted results.

Who is responsible for risk appetite in a bank?

The board approves the risk appetite statement and oversees it. The CEO is accountable for implementation, and the CRO leads the framework and independent monitoring. Business lines own the risks they take within the limits.