From appetite to operational limits
The phrasing problem
"We have a low appetite for operational risk" enables no decision. Nobody can tell from that sentence whether to accept or refuse a project, a provider or a deadline.
A usable appetite has three components: an accepted annual loss amount, a tolerated number of major incidents, and qualitative limits on what is never acceptable.
The cascade
| Level | Phrasing | Who decides |
|---|---|---|
| Board | Annual operational loss below €Xm; no incident affecting more than Y clients | Board |
| Risk committee | Allocation by business line, alert thresholds at 70% of the limit | Committee |
| Business line | Limits per process, key indicators with green / amber / red thresholds | Line head |
| Frontline | Operational rules: maximum amount without dual approval, maximum handling time | Operational manager |
Without this cascade, the board's statement remains a document and influences no daily decision.
Qualitative limits
Some things cannot be quantified and must nonetheless appear in the statement:
- no activity that would expose the firm to licence withdrawal;
- no processing of sensitive data outside the Union without adequate clauses;
- no critical provider without a documented exit strategy;
- no production release without a verified backup.
These limits are more effective than quantified thresholds, because they are objectively verifiable.
Reporting that produces decisions
A useful operational risk report fits on one page and ends with a decision request. Its structure:
- The period's losses, compared with the limit;
- Indicators at red, with the triggered action;
- Risks whose residual exceeds appetite;
- The decisions requested from the committee — two or three, each stated in one sentence.
Item 4 is what distinguishes reporting from information. A committee receiving forty pages with no decision request takes note, and nothing changes.
Key takeaways
- Appetite is expressed in thresholds, never adjectives
- The cascade links the board statement to frontline limits
- A breach must trigger a named action, not a comment