Risk Appetite Framework Design for Financial Institutions Training Course

5 days Risk Management Certificate on completion
Course codeSD-RM-025
Duration5 days
LevelIntermediate
CategoryRisk Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Financial institutions often have risk appetite statements that satisfy a policy requirement but fail as management instruments. Limits may be disconnected from strategy and capital plans, metrics may be too broad to trigger action, and breach escalation may be inconsistently applied across credit, market, liquidity, operational, conduct and non-financial risk. This creates a practical governance problem: executives cannot distinguish normal volatility from an emerging threat that requires intervention, while risk teams struggle to evidence that appetite has been embedded in business decisions.

This course teaches a structured method for designing, calibrating and operating a Risk Appetite Framework (RAF) for banks, insurers, asset managers and other regulated financial institutions. Participants translate board-approved risk appetite into measurable appetite statements, key risk indicators, limits, triggers, tolerances and escalation protocols. They learn to connect risk appetite to strategic planning, ICAAP/ILAAP, recovery planning, stress testing, product approval, risk-adjusted performance management and management reporting. Practical attention is given to risk taxonomy, metric selection, data lineage, aggregation, threshold calibration and challenge by senior governance committees.

Delivered over five instructor-led days, the programme combines technical instruction with a running financial-institution case. Participants work in groups to diagnose weaknesses in an existing RAF, define a risk appetite hierarchy, build metric specifications, set threshold logic and design breach reporting. They leave with a reusable Risk Appetite Framework design pack containing an appetite statement structure, metric inventory, limit and trigger matrix, breach escalation workflow, governance map and 90-day implementation plan.

The course is particularly valuable for risk, finance, treasury, compliance and internal audit professionals who must make risk appetite operational rather than merely documented. Managers gain staff who can challenge vague risk statements, improve reporting quality and establish clear management actions when risk positions move outside agreed boundaries.

Course objectives

By the end of this course, participants will be able to:

  • Diagnose gaps in an existing Risk Appetite Framework using a governance, metric and escalation assessment checklist
  • Draft board-level qualitative and quantitative risk appetite statements linked to strategic objectives and risk capacity
  • Construct a risk appetite hierarchy from enterprise appetite through legal-entity, business-line and portfolio limits
  • Specify key risk indicators with definitions, owners, data sources, reporting frequency and data-quality controls
  • Calibrate appetite, tolerance, trigger and limit thresholds using historical performance, stress scenarios and management capacity
  • Design a breach classification, escalation and remediation workflow with accountable decision rights
  • Map risk appetite metrics to ICAAP, ILAAP, recovery planning, stress testing and risk-adjusted performance processes
  • Produce a Risk Appetite Framework design pack and 90-day implementation roadmap for a financial institution

Benefits of attending

For you

  • Gain a repeatable method for converting high-level risk statements into measurable limits, triggers and management actions
  • Build credibility in board, risk committee and executive discussions by explaining threshold rationale and breach implications
  • Develop practical capability to challenge poorly defined KRIs, disconnected limits and weak escalation arrangements
  • Create evidence of RAF design competence through a completed framework pack and implementation roadmap
  • Prepare for broader enterprise risk, risk governance, treasury risk or second-line leadership responsibilities

For your organisation

  • Establish clearer links between strategic ambition, capital and liquidity capacity, and approved risk-taking boundaries
  • Improve the consistency of risk limits and indicators across legal entities, business lines and risk types
  • Reduce delayed management response through defined trigger levels, breach ownership and escalation routes
  • Strengthen evidence for supervisory review, internal audit testing and board risk committee oversight
  • Equip staff to produce decision-focused risk appetite reporting rather than static policy documentation

Target competencies

Risk appetite calibrationKRI specificationThreshold designBreach governanceStress-test integrationBoard risk reporting

Who should attend

  • Enterprise Risk Managers — who design or maintain group-wide risk appetite and escalation arrangements
  • Chief Risk Office Analysts — who translate board risk direction into measurable indicators and reporting
  • Risk Governance Managers — who prepare committee materials and coordinate risk limit approvals
  • Treasury and Liquidity Risk Managers — who manage liquidity, funding and capital appetite metrics
  • Financial Planning and Analysis Managers — who link strategic plans, capital forecasts and risk capacity
  • Internal Audit and Compliance Professionals — who assess whether risk appetite is embedded and evidenced in decisions

Requirements and prerequisites

Participants should have working experience in a financial institution’s risk, finance, treasury, compliance, audit or business-control function. The course assumes familiarity with core risk categories such as credit, market, liquidity, operational and conduct risk, and a basic understanding of board and committee governance. Participants should be comfortable reading management information, ratios, limit reports and simple Excel tables. Experience of ICAAP, ILAAP, stress testing or regulatory risk reporting is useful but not essential. No statistical modelling, programming, specialist GRC platform expertise or prior responsibility for a Risk Appetite Framework is required.

Training methodology

The programme uses short instructor-led modules to introduce RAF design decisions, followed by worked examples from banking and insurance environments. Teams use a running case to build an appetite hierarchy, select metrics, define red-amber-green thresholds and test escalation decisions under stress. Facilitated peer challenge simulates the scrutiny of a risk committee. Participants work with Excel-based metric templates and reporting examples, then complete an end-of-course application plan that identifies their institution’s priority gaps, stakeholders, data dependencies and first 90 days of action.

Course outline

Day 1: Risk appetite architecture and governance

  • Risk appetite, risk capacity and risk tolerance distinctions
  • Regulatory expectations for financial-institution risk appetite frameworks
  • Board, executive committee and risk committee decision rights
  • Risk taxonomy design across financial and non-financial risk
  • Risk appetite statement structure and statement-writing rules
  • Risk appetite hierarchy from group to business-line level
  • RAF maturity assessment and common implementation failure modes

Workshop: Participants assess a case-study institution’s current RAF and produce a prioritised gap register covering governance, metrics and escalation.

Day 2: Metrics, indicators and threshold design

  • Selection criteria for risk appetite metrics and key risk indicators
  • Leading, lagging and capacity-based indicator design
  • Metric specification sheets and minimum data-definition fields
  • Appetite, tolerance, trigger and hard-limit threshold logic
  • Red-amber-green status design and threshold overlap controls
  • Risk metric ownership, source systems and reporting frequency
  • Data lineage, aggregation and BCBS 239 data-quality considerations

Workshop: Participants create metric specification sheets and a limit-and-trigger matrix for credit, liquidity and operational risk.

Day 3: Calibration through strategy, capital and stress testing

  • Linking risk appetite to strategic planning and business plans
  • Risk capacity assessment using capital, liquidity and earnings resilience
  • Historical trend analysis for initial threshold calibration
  • Scenario analysis and reverse stress testing for appetite validation
  • Integrating ICAAP and ILAAP assumptions into RAF metrics
  • Legal-entity and portfolio-level limit allocation methods
  • Resolving trade-offs between growth targets and risk constraints

Workshop: Teams calibrate proposed thresholds from historical data and stress scenarios, then defend their rationale in a simulated executive review.

Day 4: Breach management, reporting and challenge

  • Breach typology for triggers, tolerances, limits and data exceptions
  • Breach notification timelines and accountable action owners
  • Root-cause analysis and remediation-plan requirements
  • Temporary limit waivers and delegated approval authorities
  • Risk appetite dashboard design for executive and board audiences
  • Trend, concentration and forward-looking reporting techniques
  • Effective challenge questions for risk committee review

Workshop: Participants run a breach-management workshop and produce an escalation workflow, remediation template and board dashboard storyboard.

Day 5: Embedding and implementing the framework

  • Embedding RAF into product approval and new-business governance
  • Using appetite metrics in risk-adjusted performance management
  • Connections with recovery planning and contingency funding plans
  • RAF testing, annual review and change-control procedures
  • Three-lines-of-defence roles in framework operation and assurance
  • Implementation sequencing, stakeholder mapping and change adoption
  • Framework documentation standards and supervisory evidence packs

Workshop: Participants assemble their Risk Appetite Framework design pack and present a 90-day implementation plan for peer and instructor challenge.

Tools & standards covered

Microsoft Excel, Microsoft Power BI, BCBS 239 Principles for effective risk data aggregation and risk reporting, ISO 31000:2018 Risk management guidelines

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. You need practical familiarity with risk reporting or financial-institution governance, but prior RAF ownership is not required. The course starts with the architecture and governance decisions before moving into metric calibration and operating processes.

A laptop is recommended for the Excel-based metric, threshold and implementation templates used during workshops. No specialist GRC system, coding environment or quantitative modelling software is required.

No. The method applies to banks, insurers, asset managers, payment firms and other regulated financial institutions. Cases focus on prudential risk concepts, while exercises can be adapted to the participant's sector and risk profile.

This course concentrates on the operating mechanics of risk appetite: statements, indicators, thresholds, limits, breaches, governance and reporting. It does not survey all ERM disciplines; participants build the specific artefacts needed to make a RAF usable in management decisions.

Participants can use the framework assessment checklist to identify weaknesses in their current arrangement, then apply the metric specification and breach workflow templates to a priority risk area. The 90-day plan provides a practical sequence for engaging risk owners, finance, treasury and governance committees.

You leave with a Risk Appetite Framework design pack developed through the case exercises. It includes an appetite hierarchy, metric inventory, threshold matrix, escalation workflow, governance map, reporting storyboard and implementation roadmap that can be adapted for your institution.

Upcoming sessions

  • 21 – 25 Sep 2026
    Nairobi · USD 3,000
    Book
  • 21 – 25 Sep 2026
    Kigali · USD 3,500
    Book
  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 05 – 09 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Mombasa · USD 3,200
    Book
  • 19 – 23 Oct 2026
    Nairobi · USD 3,000
    Book
  • 19 – 23 Oct 2026
    Live Online · USD 1,500
    Book
  • 02 – 06 Nov 2026
    Dubai · USD 4,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Risk Management

5 Days Certificate

Financial Risk Management Fundamentals for Finance Professionals Training Course

Finance professionals are routinely asked to explain how interest-rate movements, foreign-exchange exposure, borrower default, liquidity pre…

5 Days Certificate

IFRS 9 Expected Credit Loss Risk Modelling Training Course

IFRS 9 expected credit loss (ECL) models must do more than produce an impairment number. Finance, risk and credit teams need to demonstrate …

5 Days Certificate

Moody's Analytics RiskCalc Credit Risk Assessment Training Course

Private-company credit decisions often rely on incomplete financial statements, borrower-supplied forecasts and qualitative judgement. Risk …

5 Days Certificate

Palisade @RISK Monte Carlo Simulation for Financial Risk Training Course

Financial forecasts, valuations, capital proposals and budget models often present a single “base case” result while the underlying inputs—s…