← University
Risk Appetite and Tolerance: Setting the Parameters
0 of 4

A mid-sized construction company headquartered in Calgary has grown substantially over the past 8 years, expanding from a regional residential contractor with annual revenues of approximately $12 million into a diversified firm now undertaking commercial, institutional, and infrastructure projects across 4 provinces. Current annual revenues exceed $85 million, the workforce has grown from 45 employees to more than 320, and the firm now maintains bonding capacity of $40 million for individual projects and $120 million aggregate. The company's board of directors, expanded 3 years ago to include 2 independent members with experience in construction finance and corporate governance, has begun asking pointed questions about whether the organization's risk management framework has kept pace with its operational growth.

The firm's existing risk documentation consists of a 2-page risk policy adopted 6 years ago when the company first sought expanded bonding capacity. That document contains general language about maintaining financial stability and avoiding speculative ventures but provides no quantified parameters, no distinction between different risk categories, and no guidance on how much variability in project outcomes or cash flow the organization can absorb. The board's independent members have noted that recent strategic decisions—including entry into a new geographic market, acceptance of a fixed-price contract representing 18 percent of annual revenue, and an equipment financing arrangement that significantly increased debt load—were made without reference to any articulated risk parameters. Each decision was discussed at the executive level and approved by the board, but the discussions proceeded without a shared vocabulary for evaluating whether the risks being assumed aligned with the organization's capacity to absorb adverse outcomes.

The chief financial officer, who joined the company 14 months ago from a larger publicly traded contractor, has been tasked with leading an effort to develop a comprehensive risk appetite framework. The board has requested a draft risk appetite statement within 90 days, along with a proposal for how the statement will connect to operational decision-making, capital allocation, and project selection. The chief financial officer must also recommend a process for monitoring whether actual risk exposure remains within stated parameters and a protocol for escalation when divergence occurs. The executive team holds varying views on how prescriptive the framework should be, with some members concerned that overly rigid parameters will constrain the entrepreneurial decision-making that drove the company's growth, while others argue that the current approach exposes the organization to risks it has never consciously agreed to accept.

When Appetite and Reality Diverge: Recognizing and Responding to Appetite Breaches

Every organization, whether consciously or not, operates within boundaries that define how much uncertainty it is willing to accept in pursuit of its objectives. These boundaries, expressed through risk appetite and tolerance statements, represent deliberate choices about the nature and extent of risks the organization will embrace, accept, or avoid. Yet the reality of organizational life is that circumstances shift, markets evolve, personnel change, and external pressures mount in ways that can push an organization beyond its stated parameters. When this divergence occurs, when the risks an organization is actually taking exceed or fundamentally differ from the risks it has agreed to accept, a breach has occurred. Understanding how to recognize these breaches, respond to them appropriately, and use them as opportunities for organizational learning represents one of the most practical and consequential skills in enterprise risk management.

The concept of an appetite breach rests on the premise that risk appetite and tolerance statements are not merely aspirational documents but operational commitments. When a board or senior leadership team establishes that the organization will not accept more than a certain level of credit exposure, or that operational downtime must not exceed a specified threshold, or that reputational risks above a defined severity will trigger immediate escalation, these statements create a framework against which actual risk-taking can be measured. A breach occurs when monitoring reveals that current or anticipated risk levels have exceeded these established parameters. This might happen suddenly, as when a single event pushes an organization past its limits, or gradually, as when incremental decisions accumulate into a risk position that was never explicitly authorized. Both situations require recognition and response, though the nature of that response may differ considerably.

Canadian standards provide guidance on how organizations should approach the monitoring and escalation processes that enable breach detection. The International Organization for Standardization's standard on risk management, commonly referenced as ISO 31000, emphasizes that risk management should be dynamic, iterative, and responsive to change, which necessarily implies ongoing comparison between actual risk positions and established appetites. As of the date of authorship, this standard remains the primary international framework adopted across Canadian industries, with sector-specific adaptations in areas such as financial services, healthcare, and critical infrastructure. The Office of the Superintendent of Financial Institutions, which regulates federally incorporated financial institutions, has articulated expectations that these entities maintain clear escalation procedures when risk limits are approached or exceeded. While these regulatory expectations apply directly only to federally regulated entities, they reflect broader principles that prudent organizations across all sectors would be wise to consider.

In practice, Canadian organizations encounter appetite breaches through several common pathways. The most straightforward involves quantitative triggers, where a key risk indicator exceeds a predetermined threshold. A manufacturing company might establish that workplace safety incidents resulting in lost time must not exceed a certain number per quarter, and when that number is reached or surpassed, a breach has occurred regardless of the circumstances surrounding individual incidents. Similarly, a non-profit organization might establish that its operating reserve must not fall below a specified number of months of expenses, with any decline past that point constituting a breach of its financial risk tolerance. These quantitative breaches are relatively easy to detect provided the organization has implemented adequate monitoring systems and the relevant metrics are being tracked consistently.

More challenging are qualitative breaches, where the nature of risks being taken has diverged from stated appetite even if specific numerical thresholds have not been crossed. An organization might have articulated a conservative approach to innovation risk, preferring to adopt proven technologies rather than experimental ones, yet find itself implementing a new enterprise system that is considerably more novel and unproven than its stated appetite would suggest. No specific number has been exceeded, but the character of the risk differs from what was authorized. These qualitative divergences require judgment to identify and often prompt debate about whether a genuine breach has occurred. Organizations that rely solely on quantitative monitoring may miss these divergences entirely, operating outside their stated appetite without recognizing they are doing so.

A third pathway involves what might be termed emergent breaches, where changes in the external environment transform a risk position that was once within appetite into one that exceeds it, without any action by the organization itself. Consider an organization operating in a Canadian border community whose supply chain depends heavily on cross-border logistics. Changes in trade policy, border processing times, or international relations could transform a supply chain risk that was previously within tolerance into one that materially exceeds it. The organization took no new risks, yet its risk position relative to its stated appetite has fundamentally changed. Recognizing these emergent breaches requires ongoing environmental scanning and periodic reassessment of whether existing risk exposures remain within established parameters given current conditions.

To illustrate how these dynamics play out in practice, consider a situation involving a regional construction firm headquartered in Calgary with projects across Alberta and into Saskatchewan. This firm had developed a reasonably sophisticated risk management framework following a period of rapid growth that had exposed some weaknesses in its approach to project selection and financial management. As part of this framework, the leadership team had articulated a risk appetite statement that included specific tolerances around project concentration, bonding capacity, and geographic diversification. The appetite statement specified that no single project should represent more than twenty percent of annual revenue, that bonding capacity utilization should remain below seventy percent to preserve flexibility for new opportunities, and that work outside Alberta should not exceed thirty percent of total backlog without explicit board approval.

For several years, this framework served the company well. Project managers understood the boundaries within which they operated, and the executive team had developed a rhythm of quarterly risk reviews that compared actual positions against stated appetites. However, during one particular period, several dynamics converged that would ultimately produce a significant breach. A major infrastructure project in Saskatoon, initially estimated at a value representing approximately fifteen percent of annual revenue, experienced scope growth as the client added requirements and the project timeline extended. Simultaneously, several smaller Alberta projects concluded, shifting the overall portfolio balance. Market conditions in Alberta had softened somewhat, making new project wins more competitive and less frequent than historical norms.

By the time the quarterly risk review occurred, the Saskatoon project had grown to represent twenty-eight percent of projected annual revenue, bonding capacity utilization had crept to seventy-four percent due to the project's increased value, and out-of-province work had risen to thirty-seven percent of backlog. On three distinct metrics, the organization had exceeded its stated risk tolerances. Yet this situation had not arrived through any single dramatic decision. Each scope change had been reviewed and approved through normal project management processes. Each increment had seemed reasonable in isolation. The breach had emerged through accumulation rather than through any conscious choice to exceed established limits.

The implications of this situation extended well beyond the abstract concern that stated limits had been exceeded. The concentration in a single project meant that adverse developments on that project, whether relating to client payment, design issues, weather delays, or labour availability, would have outsized impact on overall company performance. The elevated bonding utilization constrained the company's ability to pursue other opportunities that might arise and created refinancing risk if the bonding company became concerned about exposure levels. The geographic shift meant that management attention and supervision resources were stretched across a wider territory than the organization had indicated it was comfortable managing.

When the breach was identified during the quarterly review, the leadership team faced several immediate questions. First, they needed to understand how the breach had occurred despite having monitoring systems in place. Investigation revealed that while individual project changes had been tracked, no mechanism existed to aggregate these changes and compare them against portfolio-level appetite thresholds until the formal quarterly review. The monitoring system was oriented toward individual project metrics rather than enterprise-level risk positions. Second, they needed to determine what response was appropriate given that the breach had already occurred and could not easily be reversed. Declining the scope additions after they had been accepted would damage the client relationship and likely trigger contractual complications. Rapidly pursuing new Alberta work to rebalance the portfolio might lead to accepting projects that did not meet quality standards. Third, they needed to assess whether the current risk position, though exceeding stated appetite, was actually manageable given current circumstances, or whether more dramatic action was required.

The response ultimately adopted combined several elements. Senior leadership, including the board, were formally notified of the breach through a documented escalation process. This notification was not merely a formality but served to ensure that those with governance responsibility were aware of and had accepted the current risk position, even though it exceeded previously stated limits. The executive team implemented enhanced monitoring for the Saskatoon project, including more frequent progress reviews and earlier warning indicators for potential problems. They developed a portfolio rebalancing plan that identified upcoming bid opportunities in Alberta and established criteria for prioritizing these opportunities that would support the return to target ranges. They also initiated a review of the appetite statement itself, questioning whether the original parameters remained appropriate given the company's evolved capabilities and market conditions, or whether the breach actually revealed that the original limits had been set too conservatively.

This response illustrates several principles that apply broadly to breach situations. The first principle involves escalation and transparency. When a breach occurs, those with governance authority need to know about it. This is not about assigning blame but about ensuring that the people accountable for organizational outcomes are aware of current risk positions. In the construction company example, the board had established the appetite parameters, and they needed to know those parameters had been exceeded. Depending on the organization's governance structure, escalation might flow to a risk committee, an executive team, a board of directors, or in smaller organizations, simply to the owner or principal who holds ultimate responsibility. The key is that breaches not be concealed or minimized but rather surfaced for appropriate attention.

The second principle involves analysis before action. The instinct when discovering a breach may be to take immediate corrective action, but precipitous responses can sometimes create more harm than the breach itself. In the construction example, hasty efforts to reduce the Saskatoon project exposure might have damaged a valuable client relationship without materially reducing risk. Understanding how the breach occurred, what factors contributed, and what the actual risk implications are should precede decisions about remediation. This analysis might reveal that the breach, while technically exceeding stated limits, poses manageable risks that can be monitored rather than immediately corrected. Alternatively, it might reveal that the situation is more serious than initially apparent and requires urgent intervention.

The third principle involves documentation throughout the process. From initial breach detection through escalation, analysis, decision-making, and implementation of responses, creating a clear record serves multiple purposes. It demonstrates that the organization recognized and responded to the breach, which may be relevant if the risk materializes and questions arise about organizational conduct. It creates institutional memory that can inform future appetite-setting and monitoring design. It provides evidence of appropriate governance functioning, which may be relevant for regulatory relationships, insurance coverage, or stakeholder confidence. Organizations operating under Quebec's civil law framework may find documentation particularly important given that province's distinct approaches to organizational liability and director responsibility, though the principle applies broadly across Canadian jurisdictions.

The fourth principle involves learning and adaptation. A breach is not merely a problem to be solved but an opportunity to strengthen the risk management framework. The construction company's experience revealed gaps in its monitoring systems, specifically the absence of aggregated portfolio-level tracking between formal quarterly reviews. Addressing this gap reduced the likelihood of similar emergent breaches in the future. The experience also prompted reflection on whether the original appetite parameters were appropriately calibrated, a question that might not have received attention absent the breach. Organizations that treat breaches purely as failures to be corrected miss the opportunity to become more resilient through the experience.

Beyond these principles, organizations should consider several practical matters when establishing their approaches to breach recognition and response. Defining what constitutes a breach with sufficient clarity that different people will reach consistent conclusions is essential. Vague appetite statements produce ambiguous breach determinations, which undermine the entire framework. If an organization has stated that it will maintain "adequate" liquidity without specifying what adequate means, different observers may reach different conclusions about whether a breach has occurred. Quantified thresholds, while not appropriate for every dimension of risk appetite, provide clarity that facilitates consistent monitoring and unambiguous breach identification.

Establishing escalation pathways in advance, before a breach occurs, prevents delays and confusion when one is detected. The pathway should specify who receives notification, within what timeframe, with what supporting information, and with what authority to make decisions about response. In federally regulated financial institutions, these pathways are often prescribed by regulatory expectation, but organizations across all sectors benefit from this advance planning. A small non-profit might have a simple pathway specifying that any breach of financial reserves requirements will be reported to the board chair within two business days with a preliminary analysis of causes and options. A larger organization might have differentiated pathways depending on breach severity or risk category.

Distinguishing between approaches for different breach severities enables proportionate responses. A minor technical breach, where a metric has marginally exceeded its threshold and is expected to return to acceptable range through normal operations, may warrant monitoring and documentation but not emergency intervention. A major breach involving substantial exceedance of critical parameters may require immediate senior attention and rapid remediation. Organizations benefit from defining severity levels in advance and associating each level with appropriate response expectations.

Considering the interaction between risk categories when assessing breaches provides a more complete picture of organizational exposure. The construction company scenario involved simultaneous breaches across concentration, capacity, and geographic dimensions. These were not independent concerns but interconnected aspects of a single underlying situation. Analysis that examined each breach in isolation might have missed the systemic nature of the problem. Effective breach response often requires stepping back from individual metrics to assess overall organizational risk position.

Addressing root causes rather than only symptoms produces more durable improvement. If a breach occurred because monitoring systems were inadequate, fixing those systems addresses the root cause. If it occurred because frontline personnel did not understand the appetite parameters within which they should operate, enhanced communication and training addresses that cause. If it occurred because the parameters themselves were unrealistic given market conditions, revising the appetite statement addresses that cause. Surface-level responses that bring metrics back into compliance without addressing underlying factors leave the organization vulnerable to recurrence.

Finally, organizations should recognize that appetite statements themselves may require adjustment in response to breaches. This is not about changing the rules after they have been violated to avoid accountability. Rather, it reflects that appetite statements represent judgments made at a particular point in time based on available information. When actual experience reveals that those judgments were incorrect, revising the statements is appropriate. The construction company might legitimately conclude that its original twenty percent project concentration limit was too conservative given its evolved capabilities and that a twenty-five percent limit better reflects its actual risk management capacity. Such adjustments should be made deliberately, with appropriate governance involvement, and documented to distinguish them from after-the-fact rationalization.

The dialogue between risk appetite and operational reality is ongoing and dynamic. Appetite statements that never require adjustment may indicate that they are set too loosely to be meaningful constraints. Frequent breaches, however, may indicate either that limits are unrealistically tight or that the organization lacks the discipline or capability to operate within chosen boundaries. Neither extreme serves organizational interests. The goal is an appetite framework that provides genuine guidance for decision-making, that can be monitored with reasonable effort, that produces clear signals when boundaries are being approached, and that enables appropriate response when those boundaries are exceeded. When this framework functions well, breaches become not crises but opportunities, moments when the organization's risk management capability is tested and, through thoughtful response, strengthened for challenges yet to come.

Continue with University access

This lesson is part of a $79 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options