A risk appetite statement is the shortest document in a licence file and the one that gets read first. It tells the supervisor what the board thinks the firm is for, which risks it has decided to run on purpose, and where it has drawn a line it will not cross. Everything else in the pack, the capital plan, the compliance manual, the outsourcing register, is supposed to follow from it. When those documents contradict each other, the risk appetite statement is usually the one that was written last and read least.
The failure mode is easy to describe. A firm writes that it has a low appetite for financial crime risk, then submits a target market covering countries with heavy sanctions exposure and an onboarding flow built on a single automated identity check. Nothing in the file is false. The statement simply does not describe the business the rest of the file describes. A supervisor does not need to find a breach to lose confidence at that point.
Appetite is a set of limits, not a set of adjectives
Words like low, moderate and cautious carry no information on their own. The useful version of the document attaches each category of risk to something the firm can actually measure and to a named person who watches it. Market risk becomes a stated maximum net exposure the dealing desk may carry overnight, with a rule for what happens when it is breached. Client money risk becomes a reconciliation frequency and a tolerance for unexplained differences. Conduct risk becomes complaint volumes and the trigger at which a product is pulled from a market.
The numbers are yours to choose. That is the point of the exercise, and it is why the regulator cares. A supervisor is not looking for a specific figure. They are looking for evidence that the board understood the trade it was making when it picked one, and that the figure connects to a report someone reads on a fixed day of the month rather than to a paragraph nobody opens again after submission.
The sections that carry real weight
Financial crime appetite matters more than founders expect, because it is the section that most directly predicts the firm's future behaviour under commercial pressure. If the target market includes higher risk jurisdictions, saying so plainly and setting out the enhanced due diligence that follows reads far better than a blanket claim of low appetite. Supervisors have seen enough applications to know that a broker chasing volume in a hard market will take the client, and they would rather see the control than the denial.
Capital and liquidity appetite is where the statement meets arithmetic. Regulatory capital requirements scale with the permissions applied for and with the firm's own risk profile, and the statement should describe the buffer the board wants to hold above the minimum and what management action is triggered when the buffer erodes. Our note on capital requirements for brokers covers the mechanics of how those thresholds are built.
Operational and technology appetite covers outages, data loss and third party failure. For a firm running a trading platform, this is a statement about the maximum tolerable downtime during market hours and what the firm does when its liquidity connection drops. Vague language here is unhelpful to the firm as well as to the supervisor, because it means nobody has decided in advance who calls the halt.
This article describes how these documents are read, not what yours should say. Risk appetite sits at board level and the drafting has legal consequences in most regimes. Take your own regulatory and legal advice before filing anything.
Banks and payment partners ask for it too
The document does not stay inside the regulatory file. Correspondent banks, payment service providers and acquirers running know your business checks on a trading firm frequently request the risk appetite statement alongside the AML policy and the ownership chart. They are not supervising the firm. They are deciding whether onboarding it exposes them to a risk category their own compliance committee has already ruled out, and the statement is the fastest way to find out what the firm intends to do.
This is where a carelessly broad target market becomes expensive. A firm that writes it will serve clients worldwide has told every prospective banking partner that it accepts sanctions and jurisdiction risk it has not described how to control. Banks manage that concern through de-risking rather than through conversation, which is the mechanism explored in correspondent banking de-risking. Firms that name their markets, exclude the ones they will not serve and show the screening behind the exclusion get further, faster. The same pattern shows up in the wider question of which licences banks accept, where the licence itself matters less than the coherence of the file around it.
The version that matches reality
A risk appetite statement is a living control document. If the board sets an exposure limit and the dealing desk runs above it for a quarter without a documented decision, the firm now has a written admission of a control failure sitting in its own regulatory file. That is worse than having no limit, and it is the reason the statement should be reviewed on a fixed cycle with the board minutes to show it happened. Supervisory audits and thematic reviews often start by comparing the stated limits against the actual reports, and the gap between the two is the finding.
Practical consequence for anyone building the operating side: the limits you write must be things your systems can produce. If the appetite statement promises daily monitoring of aggregate client exposure by instrument, the platform and CRM have to report that without someone rebuilding a spreadsheet each morning. Firms running the Broker CRM tend to write tighter statements for the simple reason that they know which numbers they can pull on demand. Write a limit you cannot measure and you have written a breach with a delayed start date.
What good looks like on the page
Short. Board approved with a date. Risk categories that match the permissions applied for and no others. A measurable threshold per category, an owner, a monitoring frequency and a stated escalation route. An explicit statement of the activities and markets the firm will not enter. A review cycle, and evidence the last review happened. That is the whole document, and a firm that can produce it honestly has usually thought harder about its business model than one that submitted forty pages.
"If you cannot pull the number your risk appetite statement promises to monitor, you have not written a control, you have written a future finding against yourself."
— Roman Onta, Executive Director, SINGUARD
Key Takeaways
- A risk appetite statement is judged on measurable limits with named owners, not on adjectives like low or moderate.
- Every limit must match a report the firm can actually produce, or it becomes documented evidence of a control gap.
- Banks, PSPs and acquirers request the same document during KYB, so a vague target market costs banking access as well as credibility.
- The statement has to stay consistent with the capital plan, the AML policy and the outsourcing register, because supervisors read them together.
Frequently Asked Questions
Is a risk appetite statement required for every licence application?
It is not universal, but most established regimes expect a board level statement of risk appetite either as a standalone document or inside the business plan and internal governance file. Even where it is not named as a requirement, the underlying question of which risks the firm accepts is asked in some form. Confirm the exact expectation with counsel in your target jurisdiction.
Who is supposed to own the document inside the firm?
The board or governing body owns it, because setting risk appetite is a governance decision rather than a compliance drafting task. The compliance function usually drafts and maintains it, the risk function monitors against it, and the board approves it and reviews it on a fixed cycle with minutes recording the review.
Why do banks and payment providers ask to see it?
They are running their own know your business assessment and need to understand what risk categories the firm intends to take on. The statement is the quickest way to see the target markets, the client types and the financial crime controls the firm has committed to, which feeds directly into whether the partner can onboard the firm within its own risk policy.
About the Author
Roman Onta is an Executive Director at SINGUARD. He builds the Prop Firm CRM, the Broker CRM, Scalegram and CopySignals side by side with his brother Alex Onta, and he helped on the design of eTrader, the division Alex built and leads. His ground is worldwide payment processing, AML compliance and the corporate structures brokers are built on, work the two of them carry together, shaped by executive roles in the UAE and international corporates. He lives and works in Dubai for most of the year. Meet the executive duo leading Singuard's five divisions.