Technology GRC

Risk appetite statements for organizations too small to have a risk function

Most small-firm risk appetite statements have never stopped anyone doing anything. What makes one operable — position, boundary, consequence — with a worked one-page example.

Here is a sentence that appears in a great many risk appetite statements:

“The firm has a low appetite for operational risk.”

Ask what it means. Specifically: name one decision the firm made differently because of it. Name one occasion when someone said “we can’t do that, it’s outside appetite.” Usually there isn’t one, because that sentence cannot produce a decision. It has no threshold, no owner and no consequence. It is a feeling with a font.

That’s the state of most risk appetite statements at firms below a few hundred people, and it’s not because the people who wrote them were careless. It’s because the only available models are bank models — twelve risk categories, a taxonomy, a quantitative overlay, an entire second-line function assumed — and a forty-person firm sensibly declines to build that, then produces a one-page version of it that inherits the vocabulary without the machinery.

I spent years owning the technology risk appetite statement and key risk indicator suite for one of Canada’s five largest banks, including the annual refresh, the threshold negotiations, and the reporting that went to executive and board risk committees. What follows is what survives when you strip that discipline down to a scale a small firm can actually operate — and a worked example, because almost nobody publishes one.

What a risk appetite statement is actually for

Not compliance. Not the board pack. Those are consequences.

A risk appetite statement exists to make a decision easier to make later, by making it once, in advance, when nobody is under pressure.

That’s the whole mechanism. Someone will eventually propose a deal, a system, a client, or a shortcut that carries more risk than the firm should take. In the moment, that proposal will have a champion, a revenue number and a deadline. The appetite statement is the thing that lets a reasonable person say “this is outside what we agreed” without having to relitigate the firm’s entire risk philosophy in a Tuesday meeting under time pressure.

If your statement can’t do that, it isn’t one. It’s a description.

Three things that turn a description into a statement

Every workable appetite position has three parts. Most small-firm statements have only the first.

A qualitative position. What you will and won’t accept, in your own business’s language. Not “low appetite” — what, specifically.

A boundary you can measure. A number, a threshold, a count, a duration. It doesn’t have to be sophisticated. It has to be checkable by someone who isn’t you.

A defined consequence. What happens when the boundary is crossed: who is told, in what timeframe, and what they’re expected to do. Without this, a breached threshold produces a shrug.

The third part is the one firms skip, and it’s the one that determines whether anything changes. A threshold with no consequence teaches everyone that thresholds don’t matter, which is worse than having no threshold — you’ve now trained your team to ignore the instrument.

Proportionality, stated honestly

At a bank, the appetite statement sits on top of a risk taxonomy with dozens of categories, feeds a KRI suite with hundreds of indicators, and is refreshed annually through a process involving several functions.

At a firm of sixty, proportionate looks like this: four to six risk areas, one page, eight to twelve indicators total, one named owner, and a quarterly look. That is not a diluted version of the bank approach. It’s the same discipline sized to the number of things your leadership team can genuinely hold in mind at once — and on that measure, a bank’s version is oversized for a bank too.

Pick your four to six areas from where your actual exposure lives, not from a taxonomy. For most financial services firms of this size, they land close to: technology resilience, information security and data, third-party dependency, change, regulatory and client obligations, and — increasingly — AI and automated decisioning.

A worked example

Here is what four positions look like when they’re written to be operable. This is a composite for a hypothetical sixty-person firm providing services to regulated financial institutions. Your numbers will differ; the shape shouldn’t.

Technology resilience

Position: We accept brief, infrequent disruption to internal tools. We do not accept client-facing service disruption that goes unexplained or recurs.

Indicator
Unplanned client-facing downtime, rolling 90 days.
Boundary
4 hours.
If breached
The Head of Operations presents cause and remediation at the next leadership meeting, within 10 business days. A second breach in two consecutive quarters goes to the board with a remediation plan.

Third-party dependency

Position: We accept reliance on third parties for non-core capability. We do not accept dependency on a supplier we could not replace, or exit, within a defined period.

Indicator
Number of critical suppliers without a documented exit plan and an identified alternative.
Boundary
Zero.
If breached
No new critical dependency is contracted until the gap is closed. The COO owns closure within one quarter.

Change

Position: We accept that changes sometimes fail. We do not accept changes reaching production without review, or a pattern of failures that suggests the process isn’t working.

Indicator
Percentage of production changes that are unreviewed or emergency-classified, monthly.
Boundary
5%.
If breached
The CTO reports the cause at the next leadership meeting. Sustained breach over two months triggers a review of the change process itself, not just the individual changes.

AI and automated output

Position: We accept the use of AI tools to support our work. We do not accept AI-assisted output reaching a client, a financial figure, or a regulatory submission without review by a named, competent person who is accountable for it.

Indicator
Instances identified where required review did not occur.
Boundary
Zero tolerance, but measured by whether they are reported, not by whether they occur.
If breached
Reported promptly and reviewed without blame; the response is process change, not discipline, unless the disregard was deliberate or repeated.

Four positions, four indicators, four consequences. It fits on a page, a new joiner can understand it, and — the test that matters — each one is capable of stopping something.

Note what that last position does. It sets an expectation of zero, then deliberately measures reporting rather than occurrence, because at small scale you can have deterrence or you can have visibility and visibility is worth more. Appetite statements can encode that choice. Most don’t.

Setting thresholds when you have no history

The most common blocker: we don’t know what number to put.

Start where you are, not where you’d like to be. Measure current performance for a month or a quarter, set the boundary just above it, and tighten deliberately over time. A threshold set at aspirational performance is breached from day one, everyone learns to ignore it, and the instrument dies in its first quarter.

Two failure modes to avoid in the other direction. A threshold you will never breach tells you nothing and quietly signals you’re not really looking. And a threshold you’re already breaching when you publish it needs to be named as such — with a remediation plan attached — rather than published as though the firm is inside appetite when it isn’t. Boards forgive a known gap with a plan. They do not forgive discovering the statement was aspirational.

What to do about the areas you can’t measure yet

Some things matter and resist measurement — culture, judgment quality, whether people speak up. Don’t force a fake metric onto them. State the qualitative position, say plainly that it isn’t currently measured, and note how it’s overseen instead. An honest “we monitor this through quarterly leadership review, not a metric” is more credible to a reader who knows the discipline than a fabricated indicator, and it costs you nothing.

How to actually build it

Two hours, four people, one session.

Get the people in the room who would have to live with the answers — usually the COO, the CTO or technology lead, whoever owns compliance, and the CEO. Work through three questions per risk area: What would genuinely damage us here? How would we know? Who would act, and what would they do? Write the answers as you go. Do not open a template.

Then someone drafts one page from those answers, circulates it, and it gets approved by whoever has the authority to approve it — with a date. The approval date matters more than firms expect: it’s the first thing a reader checks, and an undated statement reads as one nobody owns.

Set a review date. Annually is fine at this size; more often if you’re growing or your risk profile is moving. Honour it, and record that you did.

What it connects to

A risk appetite statement isn’t a standalone artifact, and its value multiplies where it connects.

To your indicators. The boundaries in the statement are your KRI set. You don’t need a separate exercise — at this scale, eight to twelve indicators drawn straight from the statement is the entire suite.

To your board or advisory reporting. One page, quarterly: each position, current status against the boundary, direction of travel, and anything breached with its remediation. Directors read that. They do not read a twelve-page risk report, and producing one costs you their attention on the things that matter.

To your client questionnaires. Institutional clients ask about risk governance. “Here is our risk appetite statement, approved by our board on this date, with these indicators reported quarterly” is a materially stronger answer than a paragraph of description — and it converts a governance question into a piece of evidence, which is what the reviewer on the other side actually needs.

To saying no. The underrated one. A firm with a written appetite has a shared reference point for declining work, suppliers and shortcuts. Without it, every “no” is a personal opinion, and personal opinions lose to revenue.

Where to start

If you have no statement: book the two hours, pick four risk areas, and write positions with boundaries and consequences. You’ll have a first draft the same day, and it will be more useful than anything you could download.

If you have one that’s never been referenced in a decision: don’t rewrite it. Take one real decision your firm made in the last year that involved accepting risk, and test whether your statement would have shaped it. Wherever it wouldn’t have, you’ve found what to fix — and that’s a considerably shorter list than starting over.

If you’d like the session run by someone who has built and defended these at institutional scale and then sized them honestly for firms that aren’t, that’s precisely the work we do.

Bunmi Makinde · Founder, Hosmak Solutions

FCA (Nigeria) — see designation note · CISA · CRISC · AAIR · CFSA

Twenty-five years in financial services technology risk, including eleven years in Big 4 advisory at PwC and EY and nearly a decade inside one of Canada’s five largest banks, where he owned the technology and operations risk appetite statement and key risk indicator suite and designed the risk reporting that went to executive and board risk committees.

This article is general information, not legal or professional advice. Firms should confirm their specific obligations with their own advisors.

Start with a conversation

Bring the questionnaire, the finding, or the board question. Thirty minutes, no cost, and you’ll leave with a straight view of what answering it would take — whether or not you work with us.

Book a 30-minute consultation

Or email hello@hosmaksolutions.ca