After a risk tolerance review, test the assumptions each tolerance threshold rests on before cascading the limits into KRIs and delegated authorities. A board-approved threshold looks like a decision, but it is closer to a forecast. In 2012, one bank brought a breached limit back into line without reducing its exposure.

A risk tolerance review is a periodic reassessment of the thresholds an organisation sets for acceptable variation around its objectives, usually approved by the board and cascaded into limits.

The standard next step after a risk tolerance review

Once the board approves the revised thresholds, the work turns to cascading them. The Financial Stability Board's 2013 Principles for an Effective Risk Appetite Framework set the pattern most regulated firms follow: the board approves the framework, and management translates it into risk limits for business lines and legal entities. Outside banking, COSO's 2017 update to its ERM framework treats tolerance as the range of acceptable variation in performance around a business objective.

In practice the sequence is familiar. Each tolerance becomes a set of limits. Each limit gets one or more key risk indicators, coloured green, amber and red. Amber prompts a conversation with the risk function; red triggers escalation to an executive committee or the board. Delegated authorities are rewritten so that managers can commit the organisation up to a stated threshold without referral.

What to do after a risk tolerance review: test the assumptions behind each threshold before cascading it into limits
Tolerance thresholds cascade into limits and KRIs, while the assumptions beneath them stay unexamined.Click to expand

The dashboards follow. Monthly risk reports show each KRI against its limit, with trend arrows and a commentary line for anything outside green, often sitting beside the risk register. Internal audit adds the framework to its plan and tests whether breaches were escalated as policy requires. By the end of the cycle, every tolerance has an owner, a metric and a reporting line.

ISO 31000 takes a plainer route. It asks for risk criteria set against the organisation's objectives and context, and does not build the standard around appetite or tolerance at all. The working group that drafted it, which included me, made that choice deliberately, for reasons set out in the case against appetite statements. Most organisations still run the tolerance cascade, because regulators and rating agencies expect to see it.

What that step adds

The cascade does real work. A board cannot supervise thousands of individual commitments, and it should not try. Translating tolerance into limits lets the board say, in advance, which decisions it wants to see and which it is content to leave with management. Delegation without a stated boundary is abdication; a limit at least makes the boundary visible.

KRIs add early warning. A limit breached at month end is old news. An indicator drifting toward amber over three reporting periods gives someone the chance to ask why before the breach arrives. Escalation triggers also remove a familiar excuse. When a red threshold is written down, nobody can later claim they did not know the matter needed to go up the line.

The review itself has value too. Revisiting thresholds forces a conversation about what has changed since last year: new products, new markets, a different funding position. Consider three thresholds of the kind a tolerance review typically approves.

$50m
Daily trading Value-at-Risk limit
Assumes: the model producing the figure captures how the positions behave under stress
15%
Maximum exposure to one counterparty, as a share of capital
Assumes: that counterparty's obligations are not correlated with the rest of the book
3 days
Maximum tolerated outage for a critical customer system
Assumes: the recovery plan has been exercised under the conditions that would cause the outage

Each figure is precise, auditable and easy to report, which is exactly why boards like them. What the review rarely records is what each figure assumes, and whether anyone has checked.

Pick the tolerance threshold your limits cascade from and write down what has to stay true for that number to hold. Start the Walk →

Where the standard playbook breaks down

A tolerance threshold is a number sitting on top of assumptions: about how exposures behave, how they correlate, how quickly they can be unwound, and whether the measurement is sound. The cascade transmits the number. It does not transmit the assumptions. A tolerance statement is a set of untested assumptions dressed as a threshold, and it cannot say whether a specific decision is sound.

JPMorgan Chase showed what that looks like at scale. In 2012 the Synthetic Credit Portfolio, run by the bank's Chief Investment Office, lost at least $6.2 billion on the trades later known as the London Whale. The US Senate Permanent Subcommittee on Investigations report of March 2013 found that the office's risk limits and advisories were breached more than 330 times in the first four months of that year.

The most revealing breach came in January 2012. The Chief Investment Office was over its own Value-at-Risk limit and was contributing to a breach of the bank-wide limit. Rather than reduce the positions, the office hurriedly adopted a new VaR model. According to the Senate report, the new model immediately lowered the portfolio's reported VaR by 50%. The breach ended. The positions did not.

The limit had been respected on paper while the exposure it was meant to constrain kept growing. The bank's own Management Task Force report of January 2013 later found the new model had been poorly implemented, relying on manual spreadsheet inputs and containing calculation errors. The limit assumed the model measured the portfolio accurately. Nobody adequately tested that assumption when the number suddenly improved.

The machinery worked as designed. Limits existed, a breach was detected, and a model change resolved it through the bank's internal approval process. Every control in the cascade was checking the number; none was checking what the number rested on. It is the same failure found in risk evaluation criteria that nobody revisits: the verdict inherits every flaw in the yardstick.

The problem is not confined to banks or to VaR. A complaints KRI assumes complaints are recorded the same way across channels. An outage tolerance assumes the recovery plan works. A counterparty limit assumes correlations seen in calm markets hold in stressed ones. Each is a claim about the world, and that is where the uncertainty lives. A green dashboard only says the numbers are inside their bands. It says nothing about whether the bands are drawn around the right things.

The step to take first

Before cascading revised tolerances into KRIs and delegated authorities, name the assumptions each threshold rests on and test the ones that matter. That is a smaller job than it sounds. Most tolerance statements carry a limited set of thresholds, and only a few of them govern commitments large enough to hurt.

The five-step method in Deciding (Frame, Tentative Elements, Assumptions, Sufficient Certainty, Implement and Monitor) puts this work in the right place. It starts from a specific decision, not a portfolio-wide threshold. The third step asks what must be true for the chosen course to succeed. The fourth asks whether enough is known about those assumptions to proceed, not whether a limit has been observed.

What the tolerance review producedWhat it assumedGap to test
Trading VaR limit of $50mThe VaR model reflects how the positions behave in stressWhether a model change that lowers reported VaR reflects lower exposure or only a different measurement
Amber KRI at 120 complaints a monthComplaints are captured the same way in every channelWhether digital and outsourced channels feed the same count
Delegated authority to approve credit up to $10mLoans below the threshold do not share exposures that add up above itWhether approvals made within authority are concentrated in one sector or borrower group

For each threshold that will govern a real commitment, ask three questions. What does this number assume about how the exposure behaves? What evidence would show that assumption is false? What signal would show it failing before the limit does? A change that improves the reported figure without any change in the underlying positions should trigger a review, not relief.

Then connect each tolerance to the decisions it is meant to govern. A limit is only useful if someone deciding a trade, a loan or a launch can ask how much downside that commitment can carry and get an answer grounded in named assumptions. The same pattern runs through any risk assessment program and the wider governance machinery around risk. The goal is not tighter tolerances. It is sufficient certainty that the assumptions behind each one still hold.

You could cascade the approved tolerance into limits and KRIs and still leave the assumptions behind the number untested.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.