← University
Risk Appetite and Tolerance: Setting the Parameters
0 of 4

A mid-sized construction company headquartered in Calgary has grown substantially over the past 8 years, expanding from a regional residential contractor with annual revenues of approximately $12 million into a diversified firm now undertaking commercial, institutional, and infrastructure projects across 4 provinces. Current annual revenues exceed $85 million, the workforce has grown from 45 employees to more than 320, and the firm now maintains bonding capacity of $40 million for individual projects and $120 million aggregate. The company's board of directors, expanded 3 years ago to include 2 independent members with experience in construction finance and corporate governance, has begun asking pointed questions about whether the organization's risk management framework has kept pace with its operational growth.

The firm's existing risk documentation consists of a 2-page risk policy adopted 6 years ago when the company first sought expanded bonding capacity. That document contains general language about maintaining financial stability and avoiding speculative ventures but provides no quantified parameters, no distinction between different risk categories, and no guidance on how much variability in project outcomes or cash flow the organization can absorb. The board's independent members have noted that recent strategic decisions—including entry into a new geographic market, acceptance of a fixed-price contract representing 18 percent of annual revenue, and an equipment financing arrangement that significantly increased debt load—were made without reference to any articulated risk parameters. Each decision was discussed at the executive level and approved by the board, but the discussions proceeded without a shared vocabulary for evaluating whether the risks being assumed aligned with the organization's capacity to absorb adverse outcomes.

The chief financial officer, who joined the company 14 months ago from a larger publicly traded contractor, has been tasked with leading an effort to develop a comprehensive risk appetite framework. The board has requested a draft risk appetite statement within 90 days, along with a proposal for how the statement will connect to operational decision-making, capital allocation, and project selection. The chief financial officer must also recommend a process for monitoring whether actual risk exposure remains within stated parameters and a protocol for escalation when divergence occurs. The executive team holds varying views on how prescriptive the framework should be, with some members concerned that overly rigid parameters will constrain the entrepreneurial decision-making that drove the company's growth, while others argue that the current approach exposes the organization to risks it has never consciously agreed to accept.

When Appetite and Reality Diverge: Recognizing and Responding to Appetite Breaches

Every organization, whether consciously or not, operates within boundaries that define how much uncertainty it is willing to accept in pursuit of its objectives. These boundaries, expressed through risk appetite and tolerance statements, represent deliberate choices about the nature and extent of risks the organization will embrace, accept, or avoid. Yet the reality of organizational life is that circumstances shift, markets evolve, personnel change, and external pressures mount in ways that can push an organization beyond its stated parameters. When this divergence occurs, when the risks an organization is actually taking exceed or fundamentally differ from the risks it has agreed to accept, a breach has occurred. Understanding how to recognize these breaches, respond to them appropriately, and use them as opportunities for organizational learning represents one of the most practical and consequential skills in enterprise risk management.

The concept of an appetite breach rests on the premise that risk appetite and tolerance statements are not merely aspirational documents but operational commitments. When a board or senior leadership team establishes that the organization will not accept more than a certain level of credit exposure, or that operational downtime must not exceed a specified threshold, or that reputational risks above a defined severity will trigger immediate escalation, these statements create a framework against which actual risk-taking can be measured. A breach occurs when monitoring reveals that current or anticipated risk levels have exceeded these established parameters. This might happen suddenly, as when a single event pushes an organization past its limits, or gradually, as when incremental decisions accumulate into a risk position that was never explicitly authorized. Both situations require recognition and response, though the nature of that response may differ considerably.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.