The Treasury Risk Management Policy
A treasury risk management policy is the governing document that turns risk appetite into enforceable rules — which risks are managed, permitted instruments, limits, approvals and reporting. It's the control that keeps hedging from drifting into speculation.
A treasury risk management policy is the governing document that turns risk appetite into enforceable rules — which risks are managed and how, the permitted instruments, the limits, the approval authorities, and the reporting. It's what makes risk management consistent and bounded rather than dependent on whoever happens to be deciding, and it's the single most important control keeping hedging from drifting into speculation. Every article in this pillar — FX, interest rate, counterparty, hedging — ultimately lives or dies by the policy that governs it. Without one, "manage risk sensibly" means whatever today's decision-maker thinks it means.
What it is
The policy is where the company writes down, in advance and with authority, how it handles financial risk — so the answer to "can we do this?" is a document, not an argument. It's the constitution of treasury risk: the rules that apply to everyone, every time, regardless of the individual or the temptation of the moment.
Why it matters
Without a policy, risk management is just a series of individual judgements — and the day a judgement is wrong, or a hedge is really a bet, there's nothing that was supposed to stop it. The policy is that something.
Three things a policy does that judgement alone can't:
- Encodes appetite. It fixes how much risk is acceptable, so it doesn't drift with whoever's deciding.
- Ensures consistency. The same rules apply across time, people and situations.
- Prevents speculation. By requiring an underlying exposure and permitting only certain instruments, it keeps treasury from running a trading book.
It's also what the board and auditors rely on to know financial risk is actually controlled.
What it covers
A complete policy typically addresses:
- Scope of risks — which risks it governs (FX, interest rate, liquidity, counterparty, commodity).
- Risk appetite and limits — how much of each risk is acceptable, in concrete numbers.
- Permitted instruments — which instruments are allowed (and, by exclusion, which are prohibited — exotic structures usually among them).
- Counterparty limits & credit standards — caps per institution and minimum quality.
- Approval authorities — who can approve what, at what size.
- Segregation of duties — the separation of dealing, confirming and settling.
- Measurement — how each exposure is quantified.
- Reporting & monitoring — what's reported, to whom, how often.
- Exceptions — how a breach or an exception is handled and escalated.
Risk appetite at its heart
Everything else flows from risk appetite — the deliberate statement of how much risk the company is willing to bear. Get that right and the limits, permitted instruments and approvals all follow logically. Get it vague ("we're prudent") and the whole policy floats, because there's no anchor to test any decision against. The appetite is the policy's foundation, not a preamble.
Approval and segregation of duties
A policy without teeth is decoration. It must define who approves what and enforce segregation of duties — the same money-moving controls as the rest of treasury: the person who strikes a deal can't be the one who confirms and settles it. This is what stops a rogue position or an error from passing unchecked, and it's why a risk policy is as much about control as about strategy.
Review and governance
A risk policy should be approved at board or senior level — giving it the authority to actually bind — and reviewed on a regular cycle, because the business, its exposures and the market change. A policy written five years ago and never revisited may permit what's now imprudent or forbid what's now needed. Governance keeps it a living control, not a forgotten document.
What usually goes wrong
- No policy. Risk run on judgement and habit, with no agreed appetite or rules.
- A policy that's ignored. It exists on paper but isn't enforced, so it controls nothing.
- Too vague. "Be prudent" with no concrete limits or appetite — nothing to actually test decisions against.
- Never reviewed. Set once and left, drifting out of line with the business it governs.
- No teeth. No defined approvals, segregation or consequences for a breach, so it can't actually stop anything.
Anchor the policy on a clear risk appetite, translate it into concrete limits and permitted instruments, enforce it with approvals and segregation of duties, and keep it reviewed and board-owned — and it becomes the framework that makes all of treasury's risk-taking deliberate, consistent and controlled. It's the document that turns the whole identify-measure-manage-monitor discipline from principle into practice.
Part of the Treasury Risk Management guide. See also what is treasury risk management and counterparty and credit risk. The newsletter sends one finance-systems pattern every two weeks.