Lesson13 min

From appetite to operational limits

The phrasing problem

"We have a low appetite for operational risk" enables no decision. Nobody can tell from that sentence whether to accept or refuse a project, a provider or a deadline.

A usable appetite has three components: an accepted annual loss amount, a tolerated number of major incidents, and qualitative limits on what is never acceptable.

The cascade

LevelPhrasingWho decides
BoardAnnual operational loss below €Xm; no incident affecting more than Y clientsBoard
Risk committeeAllocation by business line, alert thresholds at 70% of the limitCommittee
Business lineLimits per process, key indicators with green / amber / red thresholdsLine head
FrontlineOperational rules: maximum amount without dual approval, maximum handling timeOperational manager

Without this cascade, the board's statement remains a document and influences no daily decision.

Qualitative limits

Some things cannot be quantified and must nonetheless appear in the statement:

  • no activity that would expose the firm to licence withdrawal;
  • no processing of sensitive data outside the Union without adequate clauses;
  • no critical provider without a documented exit strategy;
  • no production release without a verified backup.

These limits are more effective than quantified thresholds, because they are objectively verifiable.

Reporting that produces decisions

A useful operational risk report fits on one page and ends with a decision request. Its structure:

  1. The period's losses, compared with the limit;
  2. Indicators at red, with the triggered action;
  3. Risks whose residual exceeds appetite;
  4. The decisions requested from the committee — two or three, each stated in one sentence.

Item 4 is what distinguishes reporting from information. A committee receiving forty pages with no decision request takes note, and nothing changes.

Key takeaways

  • Appetite is expressed in thresholds, never adjectives
  • The cascade links the board statement to frontline limits
  • A breach must trigger a named action, not a comment