Most banks can produce a risk appetite statement on request. Far fewer can explain, in concrete terms, what that statement actually constrains day to day. The gap between the two is usually a questionnaire problem: a risk appetite framework (RAF) is only as useful as the mechanism that turns board-level intent into numbers a risk owner can be held to.
There's a second, quieter failure mode worth naming before going any further: a dashboard where every KRI reads green can be more dangerous than one with an amber or two on it, because it's easy to read as proof that risk is under control rather than as evidence that the thresholds were never tested against reality. All-green is not a static achievement — it's a claim that decays as the portfolio, the environment, and the control maturity underneath each metric keep moving. A KRI calibrated two years ago against a smaller balance sheet, a different threat landscape, or a control environment that has since matured (or quietly eroded) can stay green for the wrong reason: not because the risk is contained, but because the threshold stopped being a meaningful tripwire. Recalibration isn't a housekeeping step at the end of this framework — it's what keeps green from becoming a false sense of security instead of a genuine signal.
This post walks through that mechanism using a working example: a seven-category framework covering credit, operational, technology and cybersecurity, compliance, market, model, and strategic risk, built on two linked questionnaires — 56 appetite-setting questions answered by the board and executive committee, and 56 key risk indicators (KRIs) that monitor actual exposure against the appetite those answers set.
Automate Regulatory Model Risk Governance
Examine models against 32 qualitative criteria and resolve risk Tiers with pre-deployment checklists per OCC 2011-12 guidelines.
Two questionnaires, two different jobs
The framework deliberately separates setting appetite from monitoring it, because the people best placed to do each job are different, and the two questionnaires ask fundamentally different kinds of questions.
The appetite-setting questionnaire is qualitative and forward-looking. Each of the 56 questions is answered on a five-point scale — Averse, Minimal, Cautious, Open, Seeking — and asks some version of "how much of this risk are we willing to carry in pursuit of our objectives?" These are board and ExCo questions because they require a view on strategy, not just risk mechanics: is the bank willing to grow the loan book faster than the market if it means somewhat weaker asset quality? Is it willing to let a new product ship before every control is fully built out?
The KRI register is quantitative and backward-looking (or, at best, near-real-time). Each of the 56 indicators has a defined calculation, a direction — whether a higher or lower reading is worse — and Green and Red thresholds that translate the qualitative appetite into a number a risk owner reports monthly or quarterly. Where the appetite questionnaire asks "how much sector concentration are we willing to accept?", the KRI register asks "what is our largest sector concentration right now, and is it above 20% or above 30%?"
The connection between them is the calibration step: a "Cautious" answer to the credit-growth appetite question should produce a tighter Green/Red band on the loan-growth-variance KRI than an "Open" answer would. The questionnaire sets direction; the KRI register sets the tripwire.
What the 56 appetite questions are really testing
Read across all seven categories, the appetite questions cluster around a handful of recurring tensions rather than being a flat list of unrelated topics.
Growth versus asset quality. Several questions in credit and strategic risk are variations on the same trade-off — faster loan growth, new markets, new products, M&A — each paired with an implicit cost in risk quality or execution certainty. A board that answers these consistently (all Cautious, or all Open) is revealing a coherent growth philosophy; a board that answers inconsistently is signaling a framework that hasn't yet resolved its own priorities.
Concentration, in every form it takes. Single-obligor exposure, sector exposure, geographic exposure, and revenue-line concentration all appear, and they're really the same underlying question asked in four risk categories: how much is the bank willing to depend on any single thing going right? This is one of the clearest places where appetite answers should be internally consistent — a bank averse to sector concentration in its loan book but open to revenue concentration in a single business line has an inconsistency worth surfacing to the board.
Tolerance for moving ahead of full control maturity. This theme shows up as new-product launches ahead of embedded controls (operational), products launched ahead of regulatory clarity (compliance), AI/ML models used in material decisions without full governance (technology and model risk), and cloud migration ahead of proven contingency plans (technology). It's effectively one question restated five times: how much does the bank value speed-to-market over control completeness? Framing it this way across categories makes it easier for the board to set one coherent standard rather than five uncoordinated ones.
Zero-tolerance zones versus calibrated zones. Not every question is really asking "how much" — some are structurally closer to yes/no. Material regulatory breaches, confirmed PII data breaches, and unapproved models in production are the kind of risk most boards answer near-Averse regardless of strategy, because the downside is disproportionate and doesn't scale with reward the way credit or market risk does. The questionnaire is useful precisely because it forces the board to say this explicitly rather than leaving it assumed.
People and behavior as a risk category in their own right. Sales incentive design, override rates on model decisions, staff turnover in control functions, and shadow IT all point to the same insight: a meaningful share of operational, compliance, and model risk originates in incentive and behavior design, not systems failure. These questions exist so the appetite statement addresses why control breaks happen, not only how severe they're allowed to be.
What the 56 KRIs are really measuring
The KRI register has its own internal logic, and it's worth naming explicitly because it explains why the register is built the way it is rather than as a simple list of "important numbers."
A mix of leading and lagging indicators, by design. Metrics like patch time for critical vulnerabilities, compliance training completion, and model revalidation status are leading indicators — they describe the health of a control before it fails. NPL ratio, regulatory fines, and confirmed security incidents are lagging indicators — they describe the outcome after something has already gone wrong. A monitoring register built only on lagging indicators tells the board about problems too late to act; one built only on leading indicators misses whether the leading signals actually translate into fewer bad outcomes. The register pairs both deliberately in every category.
Direction isn't uniform, and that matters for how the RAG logic works. Most KRIs are "higher is worse" — loss ratios, breach counts, backlog days. But a meaningful minority are "lower is worse" — system uptime, provision coverage, training completion, model validation coverage. Any scoring logic (including the conditional formatting or formulas in a working version of this register) has to branch on that direction, because a single "value below threshold = red" rule silently mis-scores half the indicators.
Thresholds are expressed as ratios, not absolutes, so they scale with the institution. Single-obligor concentration is a percentage of capital, not a dollar figure; trading VaR is a percentage of eligible capital; fraud losses are measured against budget rather than a fixed number. This is what lets the same framework structure be recalibrated for a different balance sheet size without redesigning the questionnaire itself — only the numbers change, not the logic.
Monitoring cadence tracks how fast each risk can move. Market risk KRIs are largely daily or weekly, because positions can move materially within a trading session. Strategic risk KRIs are largely annual, because market share and peer ROE gaps don't meaningfully shift month to month. Forcing every category onto the same reporting calendar would either drown the board in noise for slow-moving risks or leave it blind to fast-moving ones — the register avoids both by letting cadence follow risk velocity.
Every KRI has a named owner, which is what makes escalation real. A threshold without an accountable owner is a statistic; a threshold with one is a control. The register assigns each indicator to a specific role — Chief Credit Officer, CISO, MLRO, Head of Model Risk — so that an Amber or Red reading has an obvious first call before it ever reaches the board.
Why the two questionnaires have to be read together
Neither questionnaire is meaningful on its own. Fifty-six appetite answers with no KRIs behind them is a values statement the organization has no way of testing itself against. Fifty-six KRIs with no appetite-setting process behind them is a dashboard with arbitrary thresholds nobody can defend when challenged.
Read together, they form a loop: the board sets direction on the qualitative scale, the risk function translates that direction into numeric thresholds, actual performance is measured against those thresholds monthly or quarterly, and breaches flow back to the board as evidence for whether the original appetite answer still holds. The annual refresh of the appetite questionnaire is where that evidence gets used — a KRI that's been sitting in Amber for a year across three review cycles is a strong signal that either the risk environment has changed or the original appetite answer was too aggressive, and either way, it belongs back in front of the board rather than staying quietly logged in a monitoring sheet.
That loop — not the questionnaire itself — is the actual output of a risk appetite framework. The 112 questions are just the instrument for keeping it running.