Banking
Risk appetite frameworks: building blocks for banks
A risk appetite framework fixes, in advance and in writing, how much risk a bank will take, turning risk appetite into a board-owned input to strategy rather than a rationalisation written after the decisions are already made.
A new lending product is in front of the risk committee, and someone asks the question that ought to be easy: does this fit our risk appetite? In too many institutions the honest answer is that nobody can say, because the risk appetite statement was approved a year ago, filed, and never consulted between board meetings.
A risk appetite framework (RAF) is the structured way a bank sets how much risk it is willing to take in pursuit of its strategy, turns that into measurable limits, and assigns the people responsible for keeping risk-taking inside those limits. It is not a single document. It is the architecture that connects a board’s stated tolerance to the daily decisions of the businesses underneath it.
For a UK bank, one thing matters before anything else: the Prudential Regulation Authority (PRA) does not treat that architecture as a single prescribed supervisory artefact. Euro-area supervision names the RAF explicitly; the UK embeds the same substance across its expectations on board responsibilities, the internal capital assessment, operational resilience, and senior manager accountability. The terminology is less standardised, but the expectation is no softer. Get the building blocks wrong, or leave them disconnected, and every downstream limit, capital plan, and stress test inherits the flaw.
Why appetite went in writing
Before the 2008 crisis, most banks had a sense of how much risk they were willing to run, but few had written it down as a binding input to strategy. The Financial Stability Board (FSB) reported in October 2011 that risk appetite frameworks “actionable and measurable by both firms and supervisors have not yet been widely adopted”, and its February 2013 thematic review on risk governance took the point further.1 Where appetite was written down at all, it often followed the strategy rather than shaping it, which made it a description of what the bank was doing rather than a constraint on what it should do.
The FSB consolidated the response in 2013 with its principles for an effective risk appetite framework, which fixed the term as “the aggregate level and types of risk a financial institution is willing to assume within its risk capacity to achieve its strategic objectives and business plan”.2 That turned risk appetite from good practice into a supervisory expectation.
The FSB is a G20 body hosted at the Bank for International Settlements, and, like the Basel Committee it sits alongside, its principles are international standards that national supervisors choose to implement rather than directly binding rules.
Those principles are the conceptual ancestor of everything that followed. The European Central Bank (ECB) built them into an explicit supervisory statement;3 the UK produced no single equivalent document, but the PRA’s expectations on board responsibility, capital assessment, and governance carry the same requirements. The common thread is that risk appetite must be explicit, board-owned, and set before the strategy it is meant to constrain, not after it.
What do capacity, appetite, profile and limits mean?
If the framework exists to make appetite explicit, the first task is to be precise about what the words mean. The FSB’s lasting contribution was a shared vocabulary of four terms, which the standards that followed, UK expectations included, adopted with little change:
- Risk capacity: the maximum risk a bank could take before it breaches a hard constraint on capital, liquidity, operations, or conduct. It is a ceiling set by what the bank can survive, not by what it wants.
- Risk appetite: the level and types of risk the bank is willing to take, within that capacity, to pursue its strategy. Appetite sits below capacity, and the gap between them is the bank’s margin for error.
- Risk profile: the bank’s actual risk at a point in time, measured across each category. It is where the bank is, set against where it has said it wants to be.
- Risk limits: the quantitative allocations that carve the aggregate appetite into operational constraints for business lines, legal entities, and individual risk types.
The distinction between capacity and appetite is the one practitioners most often blur, and the one that matters most. Capacity is a survival constraint; appetite is a choice made inside it. A bank that sets its appetite equal to its capacity has left itself no room to absorb a surprise, which is the opposite of what the framework is for. The FSB deliberately set aside the older term "risk tolerance", still common in non-banking frameworks, precisely to stop appetite and capacity collapsing into a single idea.
The statement at the centre
Capacity, appetite, profile and limits come together in one written document, the risk appetite statement (RAS), at the heart of the framework. It sets out, in quantitative and qualitative terms, the aggregate risk the bank is prepared to take, under both normal and stressed conditions, and it extends to the exposures that resist easy measurement, among them reputational, conduct, and money-laundering risk.
A risk appetite statement that cannot be disaggregated into the limits businesses actually face is a statement of intent, not a constraint.
Two properties make a RAS usable rather than ornamental. It must be clear enough for the people bound by it to understand, and it must connect upward to the strategy and capital plan and downward to business-line and legal-entity limits. This is why supervisors, wherever they sit, read it first.
The UK’s direct statement on the subject is PRA Supervisory Statement SS5/16 on board responsibilities. Paragraph 4.1 asks that the business strategy be “supported by a well-articulated and measurable statement of risk appetite… which is clearly owned by the board, integral to the strategy the board has signed off and actively used by them to monitor and control actual and prospective risks and to inform key business decisions”.4 The ECB reads it the same way, as primary evidence of whether a board governs risk or merely receives reports about it. The test is not the elegance of the wording; it is whether the statement is wired into the decisions the bank makes.
Where a limit earns its name
A risk appetite statement constrains behaviour only once it becomes limits that bite. Risk limits are where the framework meets the desk: they translate the aggregate appetite into constraints at business-line, legal-entity, and risk-category level, and the Basel Committee’s corporate governance principles are specific that these limits must be forward-looking and sensitive to the bank’s own portfolio, not borrowed from peer benchmarks or set at the regulatory floor.5
A limit copied from a competitor, or set at the minimum the rules allow, measures someone else’s appetite, not the bank’s.
EBA
EBA/GL/2021/05: Guidelines on internal governance under the Capital Requirements Directive
View source ↗What turns a limit from a number into a control is the predefined escalation path behind it: who is told, who decides, and how quickly. SS5/16 is direct about where that path starts. The risk control framework should flow from the board’s risk appetite, and the PRA expects evidence of active board oversight against it. The Senior Managers Regime sharpens the point, because adherence is not only the firm’s collective duty; it sits within the accountabilities of named individuals, so a breach that goes nowhere is a question someone specific has to answer. The EBA’s internal governance guidelines ask the same of EU banks.6
A limit that is breached without consequence, or revised upward when it bites, is not a limit. The framework demands discipline: a breach must trigger a defined response, not a renegotiation.
Where appetite meets capital
Appetite that stops at the internal limit framework stays internal. It becomes a regulatory artefact at the point it meets capital. The PRA’s expectations sit in PRA Supervisory Statement SS31/15, updated in December 2025: through its Internal Capital Adequacy Assessment Process (ICAAP), a bank must assess all its material risks and hold capital against them under both normal and stressed conditions, projecting, in SS31/15’s words, “capital resources and capital requirements over a three to five year horizon, taking account of its business plan and the impact of relevant adverse scenarios”.7 The ICAAP is the primary input the regulator uses to set firm-specific capital, so an appetite that is not reflected in it is one the bank has not, in capital terms, committed to.
Stress testing closes the loop back to appetite. Reverse stress testing fixes the bank’s failure as the endpoint and works backward to the events that would cause it.8 It is part of the same process, and the PRA expects the board to engage with what it reveals rather than delegate it. The value is not the scenario itself. It is that confronting the path to failure tells a board whether the appetite it has set leaves enough distance from the edge. Capacity is defined in the abstract in the risk appetite statement; reverse stress testing makes it concrete, because it is the wall the stress test walks the bank towards.
What is an impact tolerance?
PRA
SS1/21: Operational resilience: Impact tolerances for important business services, Paragraphs 3.1 and 4.14
View source ↗Capital is not the only place where the UK gives appetite a hard edge. For operational risk it has produced the most concrete limit in the whole framework: the impact tolerance. The PRA Rulebook’s Operational Resilience Parts require a firm to identify its important business services and to set an impact tolerance for each, defined as “the maximum tolerable level of disruption to an important business service as measured by a length of time in addition to any other relevant metrics”. SS1/21 sets out how the PRA expects that to be done, and gave firms until “no later than Monday 31 March 2025” to be able to remain within those tolerances.9
An impact tolerance is a risk appetite for disruption: a number the board must stand behind before the outage rather than explain after it.
The UK got there first, requiring tolerances to be set from March 2022, where the EU’s comparable obligations under the Digital Operational Resilience Act (DORA) applied from January 2025. The two are not the same shape, though. SS1/21 sets a tolerance per important business service, while DORA is a broader ICT and third-party risk regime.
Why culture decides
All of this architecture, the definitions, the statement, the limits, the capital assessment, rests on one question: who owns it, and does anyone act as though they do? The UK’s answer is unambiguous. SS5/16 makes the risk appetite statement the board’s property, developed with challenge from every director before approval; the risk function maintains the framework day to day, but the board remains accountable for it.
Board accountability for the risk appetite statement has statutory teeth. SS5/16 puts it plainly: “Strong and effective governance is an intrinsic element of the Threshold Conditions in Schedule 6 to the Financial Services and Markets Act 2000 and particularly the suitability condition, which requires that an authorised person is fit and proper, having regard to, among other things, the need to ensure that the authorised person’s affairs are conducted soundly and prudently.”4 A firm must keep meeting those conditions to stay authorised.
Ownership on paper is not the same as appetite in practice, and this is where most frameworks succeed or fail. SS5/16 expects the board to articulate and maintain a culture of risk awareness, embedded through incentives, remuneration among them. A bank with immaculate documents and a culture that prizes growth over discipline will produce breaches that are explained away, and the documents will not save it.
Anyone who has sat on a risk committee will recognise the pattern: a breach arrives on the agenda already packaged as a timing issue, the paper recommends a temporary uplift, and the item closes quickly because the growth target is next. One test a board can run on itself: when the last board paper flagged a breach, did the minute record a decision or a discussion?
In practice
The board-approved appetite is not the end of the cascade: domain-specific appetites flow from it, with a climate risk appetite the most prominent example given the PRA’s standing supervisory attention. Any such sub-appetite is only as coherent as the top-level framework it flows from.
For a bank, the building blocks of a risk appetite framework are easy to list and hard to wire together. Capacity, appetite, profile, and limits can be defined in an afternoon; making them constrain a real decision (a new product at the risk committee, a limit breach on a Friday afternoon, a capital plan under stress) is the work of years, and it is the part supervisors actually test. The practical question for a board is not whether it has a risk appetite statement. It is whether, the next time someone asks whether a decision fits the bank’s appetite, the framework can answer before the decision is made rather than after.
A risk appetite framework earns its place only when appetite becomes a constraint the bank feels before it acts, not a statement it cites once the loss has arrived.
Frequently asked questions
What is a risk appetite framework?
A risk appetite framework is the structured way a bank sets how much risk it is willing to take in pursuit of its strategy, turns that into measurable limits, and assigns the people responsible for keeping risk-taking inside those limits. It is not a single document. It is the architecture connecting a board's stated tolerance to the daily decisions of the businesses underneath it.
Is there a single PRA rule on risk appetite frameworks?
No, and this catches firms out. Euro-area supervision names the risk appetite framework explicitly, while the UK embeds the same substance across its expectations on board responsibilities, the internal capital assessment, operational resilience and senior manager accountability. The terminology is less standardised; the expectation is no softer. Get the building blocks wrong or leave them disconnected, and every downstream limit, capital plan and stress test inherits the flaw.
Why did risk appetite have to be written down?
Before 2008 most banks had a sense of how much risk they were willing to run, but few had written it down as a binding input to strategy. The FSB's October 2011 progress report on enhanced supervision found that actionable, measurable risk appetite frameworks had not yet been widely adopted, and its February 2013 thematic review on risk governance pressed the point. Where appetite was written down at all, it often followed the strategy rather than shaping it, which made it a description of what the bank was doing rather than a constraint on what it should do. The Financial Stability Board consolidated the response in 2013 with its principles for an effective risk appetite framework.
What are the four terms in a risk appetite framework?
The FSB's lasting contribution was a shared vocabulary of four terms. Risk capacity is the maximum risk a bank could take before breaching a hard constraint on capital, liquidity, operations or conduct: a ceiling set by what the bank can survive. Risk appetite is the level and types of risk the bank is willing to take within that capacity to pursue its strategy. Risk profile is the bank's actual risk at a point in time, measured across each category. Risk limits are the quantitative allocations that carve the aggregate appetite into operational constraints for business lines, legal entities and individual risk types.
What is the difference between risk capacity and risk appetite?
Capacity is a survival constraint; appetite is a choice made inside it. This is the distinction practitioners most often blur and the one that matters most, because the gap between the two is the bank's margin for error. A bank that sets its appetite equal to its capacity has left itself no room to absorb a surprise, which is the opposite of what the framework is for. The FSB deliberately set aside the older term "risk tolerance", still common in non-banking frameworks, precisely to stop appetite and capacity collapsing into one idea.
What makes a risk appetite statement usable rather than ornamental?
Two properties. It must be clear enough for the people bound by it to understand, and it must connect upward to the strategy and capital plan and downward to business-line and legal-entity limits. A statement that cannot be disaggregated into the limits businesses actually face is a statement of intent, not a constraint. PRA Supervisory Statement SS5/16 on board responsibilities looks for a well-articulated and measurable statement, owned by the board, integral to the strategy the board has signed off, and actively used to monitor risk and inform key business decisions.
What should a risk appetite statement cover?
It sets out, in quantitative and qualitative terms, the aggregate risk the bank is prepared to take under both normal and stressed conditions. It also has to reach the exposures that resist easy measurement, among them reputational risk, conduct risk, which our guide to conduct risk frameworks under Consumer Duty covers, and money-laundering risk.10 Confining the statement to the risks that quantify neatly leaves the framework silent on the ones most likely to arrive as a surprise.
When does a risk limit become a control?
When a predefined escalation path sits behind it: who is told, who decides, and how quickly. Limits themselves must be forward-looking and sensitive to the bank's own portfolio rather than borrowed from peer benchmarks or set at the regulatory floor. A limit breached without consequence, or revised upward when it starts to bite, is not a limit. Under the Senior Managers Regime adherence is not only the firm's collective duty, so a breach that goes nowhere is a question a named individual has to answer.
How does risk appetite connect to capital?
Appetite that stops at the internal limit framework stays internal. It becomes a regulatory artefact where it meets capital, through the Internal Capital Adequacy Assessment Process. PRA Supervisory Statement SS31/15, updated in December 2025, requires a bank to assess all its material risks and hold capital against them under both normal and stressed conditions, over stress scenarios spanning at least three years. The ICAAP is the primary input the regulator uses to set firm-specific capital, so an appetite not reflected in it is one the bank has not committed to in capital terms.
How does reverse stress testing test a bank's appetite?
Reverse stress testing fixes the bank's failure as the endpoint and works backwards to the events that would cause it, and the PRA expects the board to engage with what it reveals rather than delegate it. Its value is not the scenario. Confronting the path to failure is what tells a board whether the appetite it has set leaves enough distance from the edge. Capacity is defined in the abstract in the statement; the stress test is where it becomes concrete.
Who owns the risk appetite framework?
The board. SS5/16 makes the risk appetite statement the board's property, developed with challenge from every director before approval. The risk function maintains the framework day to day, but accountability stays with the board. Ownership on paper is not the same as appetite in practice, which is where most frameworks succeed or fail.
Why does culture decide whether the framework works?
Because a bank with immaculate documents and a culture that prizes growth over discipline will produce breaches that get explained away, and the documents will not save it. SS5/16 expects the board to articulate and maintain a culture of risk awareness, embedded through incentives including remuneration. One test a board can run on itself: when the last board paper flagged a breach, did the minute record a decision or a discussion?
Sources
- 1 FSB. Thematic Review on Risk Governance View source ↗
- 2 FSB. Principles for an Effective Risk Appetite Framework View source ↗
- 3 ECB Banking Supervision. SSM supervisory statement on governance and risk appetite View source ↗
- 4 PRA. SS5/16: Corporate governance: Board responsibilities, Paragraphs 1.3 and 4.1 View source ↗
- 5 BCBS. Corporate governance principles for banks (d328) View source ↗
- 6 EBA. EBA/GL/2021/05: Guidelines on internal governance under the Capital Requirements Directive View source ↗
- 7 PRA. SS31/15: The ICAAP and the SREP, Paragraphs 3.9 and 3.23 View source ↗
- 8 Gini. Reverse stress testing explained View source ↗
- 9 PRA. SS1/21: Operational resilience: Impact tolerances for important business services, Paragraphs 3.1 and 4.14 View source ↗
- 10 Gini. Conduct risk frameworks under FCA Consumer Duty View source ↗