Risk Appetite and Risk Limits in Treasury
Risk appetite is how much financial risk a company chooses to bear; risk limits are the measurable guardrails that enforce it. Why both matter, and how they connect.
Risk appetite is how much of each financial risk a company deliberately chooses to bear; risk limits are the measurable guardrails that hold it to that choice. Appetite is the intent, set at the top — how much foreign exchange, interest rate, counterparty and liquidity risk the business is willing to carry to pursue its goals. Limits are the concrete numbers that turn that intent into something a treasurer can actually check a decision against. Get the pair right and you have the foundation of a workable treasury risk management policy; get either wrong and the whole thing floats.
(This is a plain explanation of governance concepts, not investment or hedging advice for any particular situation.)
Appetite is a choice, not a default
In eighteen years across SAP FI/TRM and treasury desks, the thing I've most often seen skipped is the deliberate part. A company will hedge, set exposure caps, run reports — and never actually decide how much risk it wants to carry. The appetite ends up being whatever the accumulated habits of the desk happen to produce.
Risk appetite is the opposite of that: the explicit statement that says, for each financial risk, we are willing to bear this much of it to pursue our objectives. Not zero — the point of the identify-measure-manage-monitor discipline is to keep risk within appetite, not to chase an impossible and expensive zero. A business that hedges everything has spent real money to forgo every favourable move as well as every unfavourable one. So appetite is a genuine choice with a cost on both sides, and that's why it belongs at board or treasury-committee level rather than on the desk. The people taking the risk should not be the ones deciding how much of it is acceptable.
That's the governance line that matters: appetite is set above the desk; the desk operates within it. Keep that separation and risk-taking stays deliberate. Blur it and appetite becomes a description of whatever treasury already does — which is not a control, it's a rationalisation.
Limits are appetite made measurable
An appetite statement on its own is untestable. "We are conservative about currency risk" tells a treasurer nothing they can act on at 4pm with a live exposure in front of them. Limits are what fix that — the concrete, measurable boundaries that operationalise the appetite:
- Hedge-ratio ranges — hedge between X and Y percent of a given exposure, so the desk has a band to work within rather than a single brittle target.
- VaR or CFaR limits — a cap on modelled loss, using value-at-risk for market positions or cash-flow-at-risk for exposures measured against cash flows.
- Counterparty exposure limits — a maximum amount placed with any single bank or trading partner, plus minimum credit standards, so counterparty and credit risk stays diversified.
- Maturity and tenor limits — bounds on how far out positions or investments can run, so the book doesn't quietly extend its own risk horizon.
- Minimum liquidity buffers — a floor of available cash or committed facilities below which the company won't let itself drop.
The relationship is direct: appetite is the intent, limits are the guardrails. Each limit should be traceable back to a line in the appetite — if you can't say which piece of appetite a given limit enforces, either the limit is arbitrary or the appetite is too vague to have produced it. That traceability is the test of whether the two are actually connected or just filed in the same binder.
Appetite without limits is a slogan — it can't stop or approve anything. Limits without appetite are arbitrary numbers nobody can defend when they bite. The work is in the arrow between them: making the limits genuinely follow from the appetite.
How appetite and limits reach the policy
Appetite and limits don't stand on their own — they feed something. The chain runs appetite → limits → policy, and then monitoring closes the loop. The treasury risk management policy is where appetite and limits get codified with authority: written down, approved, made to apply regardless of who's on the desk that day. That's why this article builds toward the policy rather than duplicating it — the policy is where these choices become enforceable rules alongside permitted instruments, approvals and segregation of duties.
Then the loop closes with monitoring and breach escalation. A limit is only real if something checks it and something happens when it's crossed. Monitoring compares live exposures against the limits; a breach triggers a defined escalation path — reported, explained, either brought back inside the limit or formally accepted as an exception at the right level. Without that closing step, a limit is just a suggestion.
So the ownership map is clean: the board sets appetite, treasury operates within limits, and breaches escalate back up to the level that owns the appetite. Everyone knows which decisions are theirs.
Docs versus reality
Here's where the gap between the framework and the filing cabinet usually opens.
The first failure mode is the appetite statement nobody translated into limits. It reads well in the board pack — measured, prudent, appropriately serious — and it changes nothing, because no treasurer can act on "we are prudent about FX." It's decoration. I've reviewed appetite statements that were genuinely thoughtful and completely inert, because the arrow to hard limits was never drawn.
The second is worse: limits nobody monitors. An unmonitored limit is more dangerous than no limit at all, because it manufactures false comfort. The board believes risk is bounded; the reports say a limit exists; and meanwhile the book has drifted past it with nothing watching. No limit at least keeps everyone honest that the exposure is unmanaged.
And the most common failure of all, the quiet one: limits set once and never revisited. The business grows, enters new currencies, takes on new debt, changes its whole risk profile — and the limits still reflect the company as it was three years ago. They're not wrong on the day they're written; they rot. The review cycle keeps appetite and limits aligned with the business they govern, and it's the step that gets dropped first because nothing appears to break when you skip it — until it does.
Getting it right
Decide the appetite deliberately, at the level that owns the business, for each financial risk. Translate it into limits you can measure and a treasurer can test a decision against — and make each limit traceable back to the appetite it enforces. Codify both in the treasury risk management policy so they bind regardless of who's deciding. Then monitor, and escalate breaches, so the numbers stay real. Do that and you have deliberate, bounded, controlled risk-taking. Skip any link and you have a document that describes control without providing it.
Part of the Treasury Risk Management guide. See also the treasury risk management policy and counterparty and credit risk in treasury. The newsletter sends one finance-systems pattern every two weeks.