Raymond Cheung
Chartered Actuary · CRO · Board Adviser · Singapore
Risk appetite statements are everywhere. Frameworks that genuinely influence how an organisation makes choices are far rarer. The difference is not technical — it is about whether leadership is willing to be constrained by it.
I have read hundreds of risk appetite statements. Most of them are well-constructed, clearly articulated, and entirely disconnected from how the organisation actually makes decisions. That is not a documentation problem. It is a leadership problem.
Risk appetite — the amount and type of risk an organisation is willing to accept in pursuit of its objectives — should be the anchor for strategic decisions. It should be the framework that a CFO invokes when evaluating a capital allocation, that an underwriter references when pricing a risk, that a board director reaches for when a management proposal tests the boundaries of what the organisation has said it stands for. In practice, most risk appetite frameworks sit behind the enterprise risk policy and are referenced at half-yearly risk committee meetings.
Why frameworks fail
In my years as a statutory CRO, I saw this pattern consistently. A risk appetite framework gets developed — usually with significant effort from the risk function, real engagement from the CFO, genuine sign-off from the board. It is well-designed. It identifies the right categories of risk. It sets sensible thresholds. And then nothing changes.
The failure is almost never in the framework itself. It is in three things: the framework is not embedded in decision-making processes; management is not held to account when risk appetite boundaries are approached or breached; and the board is not asking the right questions in the right forums.
“A risk appetite statement that does not constrain a single decision in the year it was approved has no appetite in it at all.”
What embedding actually looks like
Embedding risk appetite is not about putting it in a dashboard. It is about connecting it to the moments where decisions are actually made — capital committee papers, product approval processes, M&A due diligence, strategic planning cycles.
At AIG Asia Pacific, we worked hard to move risk appetite from a document that informed the annual report to a framework that shaped how businesses submitted capital requests. That required two things: a clear articulation of appetite in terms that business units could actually use, and consistent challenge from the risk function when proposals pushed against the stated boundaries. The second part is the harder one — it requires the CRO to be willing to slow things down, and it requires the CEO and board to support that when it happens.
The board's role
Boards set risk appetite. But in my experience, too few boards follow up on whether that appetite is actually operating as intended. The question to ask is not 'Are we within appetite?' — management will almost always say yes. The question is: 'Show me a decision made in the last six months where the risk appetite framework caused us to do something differently than we otherwise would have.'
If the answer is silence, the framework is decorative. A functioning risk appetite framework should be producing real friction — decisions slowed down, proposals modified, strategies adjusted because the organisation has made a commitment to itself about the kind of risk it is willing to carry.
A practical starting point
- Translate your risk appetite into decision-relevant language for each business function — not just risk categories, but thresholds they can actually apply
- Connect it explicitly to your capital allocation, underwriting guidelines and product development process
- Build a reporting cadence that shows the board where the organisation is sitting relative to appetite — not just whether it is within limits, but how the trend is moving
- Require management to cite risk appetite in board papers where it is relevant, and challenge when it is absent
Risk appetite is not a compliance exercise. When it works, it is the mechanism by which a board's risk judgement travels through the organisation and shapes the decisions being made three layers down. That is worth building properly.
About the author
Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.