Most organisations have already documented their appetite for different common decisions or business objectives. Segregation of duties, financing and deal limits, procurement criteria, investment criteria, zero tolerance to fraud or safety risks – are all examples of how organisations set risk appetites. Appetites or limits for different kinds of decisions and risks has been around for decades. Not all risks, but most of them.
So, what is this recent hype about risk appetite about? Not much really, it’s just another consulting red herring. Contrary to what most modern-day consultants tell us, the authors believe that any attempts in non-financial companies to aggregate risks into a single risk appetite statement is both unnecessary and unrealistic. Even having few separate risk appetite statements is totally missing the point.
After all, risk appetite is just a tool to help management make decisions and be transparent to stakeholders when making these decisions.
Instead of creating separate new risk appetite statements, risk managers should review existing Board level policies and procedures and identify:
We strongly believe that risk appetites should be integrated into existing Board level documents and very rarely, if ever, published as separate risk appetite statements. Also keep in mind, that risk appetite concept non-financial companies have inherited from regulators in banking sector. For banks risk appetite is used a regulator control mechanism. Sometimes we use the analogy of the dog’s leash.
Since most risk managers in non-financial companies are likely to be paid by the CEO and usually work for the management and not the regulator or even the shareholders, risk managers should probably view the concept of risk appetite from a management’s perspective.