← University
Risk Appetite and Tolerance: Setting the Parameters
0 of 4

A mid-sized construction company headquartered in Calgary has grown substantially over the past 8 years, expanding from a regional residential contractor with annual revenues of approximately $12 million into a diversified firm now undertaking commercial, institutional, and infrastructure projects across 4 provinces. Current annual revenues exceed $85 million, the workforce has grown from 45 employees to more than 320, and the firm now maintains bonding capacity of $40 million for individual projects and $120 million aggregate. The company's board of directors, expanded 3 years ago to include 2 independent members with experience in construction finance and corporate governance, has begun asking pointed questions about whether the organization's risk management framework has kept pace with its operational growth.

The firm's existing risk documentation consists of a 2-page risk policy adopted 6 years ago when the company first sought expanded bonding capacity. That document contains general language about maintaining financial stability and avoiding speculative ventures but provides no quantified parameters, no distinction between different risk categories, and no guidance on how much variability in project outcomes or cash flow the organization can absorb. The board's independent members have noted that recent strategic decisions—including entry into a new geographic market, acceptance of a fixed-price contract representing 18 percent of annual revenue, and an equipment financing arrangement that significantly increased debt load—were made without reference to any articulated risk parameters. Each decision was discussed at the executive level and approved by the board, but the discussions proceeded without a shared vocabulary for evaluating whether the risks being assumed aligned with the organization's capacity to absorb adverse outcomes.

The chief financial officer, who joined the company 14 months ago from a larger publicly traded contractor, has been tasked with leading an effort to develop a comprehensive risk appetite framework. The board has requested a draft risk appetite statement within 90 days, along with a proposal for how the statement will connect to operational decision-making, capital allocation, and project selection. The chief financial officer must also recommend a process for monitoring whether actual risk exposure remains within stated parameters and a protocol for escalation when divergence occurs. The executive team holds varying views on how prescriptive the framework should be, with some members concerned that overly rigid parameters will constrain the entrepreneurial decision-making that drove the company's growth, while others argue that the current approach exposes the organization to risks it has never consciously agreed to accept.

Developing a Risk Appetite Statement That Actually Guides Decisions

Every organization, whether it realizes it or not, operates according to some set of assumptions about which risks it will accept and which it will avoid. The question is whether those assumptions remain unexamined and inconsistent, leading to reactive decision-making and missed opportunities, or whether they are deliberately articulated in a way that provides genuine guidance when difficult choices arise. A risk appetite statement represents the deliberate path, serving as a formal expression of the amount and type of risk an organization is willing to pursue or retain in order to achieve its objectives. When crafted properly, this statement becomes a living document that shapes capital allocation, strategic planning, operational decisions, and governance oversight. When crafted poorly, it becomes another compliance artifact that gathers dust in a policy binder while actual decisions continue to be made on an ad hoc basis.

The concept of risk appetite has its foundations in both financial theory and organizational governance practice. The International Organization for Standardization's ISO 31000 standard, which provides principles and guidelines for risk management and is widely adopted across Canadian industries, defines risk appetite as the amount and type of risk that an organization is prepared to pursue, retain, or take. As of the date of authorship, the 2018 version of ISO 31000 remains the current iteration, and it emphasizes that risk appetite should be considered throughout the risk management process rather than treated as a standalone determination. In Canada, various sector-specific regulators have incorporated risk appetite requirements into their oversight frameworks. The Office of the Superintendent of Financial Institutions, for instance, expects federally regulated financial institutions to establish and communicate risk appetite as part of their enterprise risk management approach. Provincial securities regulators operating through the Canadian Securities Administrators have similarly emphasized the importance of risk governance disclosure for public companies. Beyond regulated industries, the adoption of formal risk appetite frameworks has spread to healthcare organizations, municipalities, educational institutions, non-profits, and small and medium-sized businesses seeking to professionalize their risk management practices.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.