Risk appetite
Risk appetite is the aggregate level and type of risk an institution is willing to accept in pursuit of its objectives, formalised through a documented risk appetite framework and statement. The Financial Stability Board’s 2013 principles, the reference standard most large financial institutions build from, explicitly name money laundering as one of the harder-to-quantify risks a risk appetite statement needs to address, alongside reputation and conduct risk.
Key takeaways
- Risk appetite is the aggregate level of risk an institution is willing to accept, formalised through a documented framework and statement.
- The FSB’s 2013 Principles for an Effective Risk Appetite Framework is the reference standard most large financial institutions build from.
- Risk capacity (the hard limit), risk appetite (the strategic choice), and risk tolerance (the operational band) are distinct, linked concepts, not interchangeable terms.
- FSB’s Principles explicitly name money laundering, alongside reputation and conduct risk, as a risk category a risk appetite statement must address.
- A complete framework has four parts: the statement, risk limits, their cascade to business units, and governance roles.
- The board approves the framework with the CEO, CRO, and CFO, and is accountable for enforcing it, including breach escalation.
- Money laundering risk appetite is genuinely harder to quantify than financial risk appetite, so most firms combine qualitative statements with measurable proxy indicators.
On this page
What risk appetite actually meansThe FSB’s Principles: the reference standardRisk appetite vs risk tolerance vs risk capacityWhy FSB explicitly names money laundering in its frameworkWhat a risk appetite statement actually has to includeThe four components of a risk appetite frameworkBoard and senior management’s specific roleHow risk appetite connects to a firm’s AML risk assessmentWhy qualitative risks are harder to appetite-set than financial onesWhat a weak risk appetite statement looks likeMaking risk appetite operationally real, not just a documentFAQsRead more
18 Nov 2013
Date the FSB published its Principles for an Effective Risk Appetite Framework
Source: Financial Stability Board
4
Components of a complete risk appetite framework per FSB guidance: statement, limits, cascade, governance
Source: Financial Stability Board
What risk appetite actually means
Risk appetite is the aggregate level and type of risk an institution is willing to accept, or deliberately avoid, in pursuit of its business objectives. It’s a strategic, board-level articulation, not an operational rule, meant to guide how much risk-taking is acceptable across the organisation before decisions get made at the transaction or relationship level.
In practice, risk appetite gets formalised through a documented framework and a written statement, both of which are meant to translate a strategic-level concept into something concrete enough for a board, senior management, and front-line staff to actually apply consistently.
The FSB’s Principles: the reference standard
The Financial Stability Board’s Principles for an Effective Risk Appetite Framework, published 18 November 2013, is the reference standard most large, internationally active financial institutions build their approach around. The FSB designed the Principles primarily for systemically important financial institutions but stated they’re relevant more broadly, across banks, insurers, securities firms, and other financial institutions.
The Principles set out key elements for four things specifically: an effective risk appetite framework itself, an effective risk appetite statement, risk limits, and the defined roles and responsibilities of the board and senior management in maintaining all of it.
Risk appetite vs risk tolerance vs risk capacity
Risk appetite, risk tolerance, and risk capacity are related but distinct concepts, and conflating them is a common practical mistake. Risk capacity is the outer boundary: the maximum risk an institution can absorb given its actual balance sheet strength, liquidity, and regulatory capital, a hard limit that can’t be chosen, only measured. Risk appetite is a strategic choice within that capacity: how much of the available capacity the institution actually wants to deploy in pursuit of its objectives. Risk tolerance sits below appetite, the acceptable variation around the appetite level for specific risk categories, closer to an operational boundary than a strategic one.
Treated correctly, these form one linked system: capacity sets the ceiling, appetite sets the strategic target within it, and tolerance sets the operational band around that target.
Why FSB explicitly names money laundering in its framework
Here’s a detail that ties this concept directly to AML rather than leaving it as generic corporate governance language: the FSB’s own Principles explicitly state that a risk appetite framework should address more difficult-to-quantify risks, specifically naming reputation and conduct risks as well as money laundering and unethical practices, alongside the more easily quantified financial risk categories.
That’s a deliberate choice by the standard-setting body, not an incidental mention. It means an institution’s risk appetite statement that doesn’t address money laundering risk explicitly is arguably incomplete against the FSB’s own reference standard, not just against sector-specific AML guidance.
What a risk appetite statement actually has to include
A properly constructed risk appetite statement, per FSB guidance, needs to include the key background assumptions that informed the institution’s strategic and business plans, be explicitly linked to short and long-term strategic, capital, and financial plans as well as compensation structures, and establish the actual amount of risk the institution is prepared to accept in pursuit of its objectives, taking customer and other stakeholder interests into account.
A statement that just declares “we have low risk tolerance for financial crime” without connecting that to specific, measurable parameters and linking it to how the business is actually run doesn’t meet this bar. It’s a sentiment, not a functioning risk appetite statement.
The four components of a risk appetite framework
A complete risk appetite framework generally has four working parts: the risk appetite statement itself, defining the aggregate risk position; risk limits, the specific, measurable boundaries derived from the statement for individual risk categories or business lines; the cascade of these limits down to individual business units and legal entities, adjusted proportionately for their size and complexity; and the governance structure, roles and responsibilities, that makes the whole framework operate as a functioning system rather than a static document.
A risk appetite statement without the framework built around it is, in a phrase used by risk practitioners, essentially decoration: it states an intention without the infrastructure to actually implement, monitor, or enforce it.
Board and senior management’s specific role
The FSB’s Principles are specific about board and senior management responsibilities. The board approves the risk appetite framework, developed in collaboration with the CEO, CRO, and CFO, and has to ensure it stays consistent with the firm’s strategic and business plans, capital position, and compensation structure. The board holds the CEO and senior management accountable for the framework’s integrity, including timely escalation of any breaches. Annual business plans need to align with the approved appetite, and compensation programmes need incentives that actually support adherence to it, not incentives that quietly reward exceeding it.
This governance structure is exactly what turns risk appetite from an abstract concept into something an institution can actually be held accountable for maintaining.
How risk appetite connects to a firm’s AML risk assessment
Risk appetite and a firm’s AML risk assessment connect directly: the risk assessment identifies and measures the actual money laundering and terrorist financing risk the business faces, while the risk appetite statement sets the boundary for how much of that risk the institution is willing to accept before it has to change its business model, exit a customer segment, or invest further in controls.
A firm that discovers, through its risk assessment, that it’s carrying more AML risk than its own stated appetite permits has a governance gap, not just a compliance one. That mismatch is precisely the kind of finding a board is supposed to catch and act on under a properly functioning framework.
Why qualitative risks are harder to appetite-set than financial ones
Setting appetite for financial risks, credit losses, market exposure, is comparatively straightforward because the underlying metrics already exist in a quantified, historically tracked form. Setting appetite for money laundering risk, reputational risk, and conduct risk is genuinely harder, because there’s no single, agreed number for “acceptable AML risk” the way there’s a defined number for acceptable credit loss.
Most institutions address this by combining qualitative risk appetite statements, describing the types of customers, products, or jurisdictions the firm won’t engage with at all, with measurable proxy indicators: SAR filing volumes and trends, regulatory findings, control testing results, that give the board something concrete to monitor even without a single unifying financial metric.
What a weak risk appetite statement looks like
A weak risk appetite statement tends to share recognisable features: vague language (“we take AML seriously”) without specific, measurable parameters; no clear connection to the firm’s actual business plans or compensation structure; financial risk categories addressed in detail while reputational, conduct, and money laundering risk get a single generic sentence; and no defined limits or escalation triggers that would actually catch a breach before it became a crisis.
These gaps tend to surface exactly when they matter most, during a regulatory examination or after a control failure, when a board is asked to demonstrate that its stated risk appetite actually governed real decisions rather than sitting unused in a policy binder.
Making risk appetite operationally real, not just a document
Making risk appetite operationally real means building the full framework, not just publishing a statement: defined, measurable risk limits cascaded to the business lines that actually take on risk; genuine board-level accountability with named escalation triggers for breaches; and a direct, documented link between the risk assessment’s findings and the appetite statement’s boundaries, so that a change in the firm’s actual risk profile visibly connects to a decision about whether that risk still fits within what the board has said it’s willing to accept.
Turn risk appetite into a documented AML policy
Generate a policy draft that connects your risk assessment findings to a defined risk appetite.
Frequently asked questions
What is risk appetite?
Risk appetite is the aggregate level and type of risk an institution is willing to accept in pursuit of its business objectives, formalised through a documented risk appetite framework and statement.
What is the FSB’s Principles for an Effective Risk Appetite Framework?
Published 18 November 2013, it’s the reference standard most large financial institutions build their risk appetite approach around, setting out key elements for the framework, the statement, risk limits, and board/management responsibilities.
What is the difference between risk appetite, risk tolerance, and risk capacity?
Risk capacity is the maximum risk an institution can absorb, a hard measured limit. Risk appetite is the strategic choice of how much of that capacity to actually deploy. Risk tolerance is the acceptable variation around the appetite level for specific risk categories.
Does risk appetite specifically address money laundering risk?
Yes. The FSB’s own Principles explicitly state that a risk appetite framework should address harder-to-quantify risks, specifically naming money laundering and unethical practices alongside reputation and conduct risk.
What are the four components of a risk appetite framework?
The risk appetite statement itself, risk limits derived from it, the cascade of limits to business units and legal entities, and the governance roles and responsibilities that operate the framework.
Who is responsible for approving a firm’s risk appetite framework?
The board approves it, developed in collaboration with the CEO, CRO, and CFO, and holds senior management accountable for its integrity, including timely escalation of breaches.
How does risk appetite connect to a firm’s AML risk assessment?
The risk assessment measures the actual money laundering risk the business faces; the risk appetite statement sets the boundary for how much of that risk the institution is willing to accept before it must change its business or controls.
Why is setting risk appetite for money laundering harder than for financial risks?
There’s no single, agreed quantitative metric for acceptable AML risk the way there is for acceptable credit loss, so most institutions combine qualitative statements with measurable proxy indicators instead.
What does a weak risk appetite statement look like?
Vague language without measurable parameters, no link to business plans or compensation, financial risks covered in detail while reputational and money laundering risk get only a generic mention, and no defined escalation triggers.
Read more: our ultimate guides, whitepapers and templates
Related guides and resources to help you act on what you just read.
Last reviewed July 19, 2026 · 10 min read · Written for compliance and risk professionals · By the WhoWiki editorial team
Key takeaway: Risk appetite is the aggregate level and type of risk an institution is willing to accept in pursuit of its objectives, formalised through a documented risk appetite framework and statement. The Financial Stability Board’s 2013 principles, the reference standard most large financial institutions build from, explicitly name money laundering as one of the harder-to-quantify risks a risk appetite statement needs to address, alongside reputation and conduct risk.