The forty-page paper is a symptom.
We see it often: a well-drafted risk appetite framework of 35 to 50 pages, full of references to COSO ERM, ISO 31000, the Three Lines Model. Substantively correct. Operationally unusable, because no one opens it during a board meeting. The board discussion turns on a single question: “Should we make this acquisition?” The paper offers no answer.
Two A4 is the working maximum.
Page one, qualitative. Per risk category (strategic, operational, financial, compliance, IT-cyber, ESG) one sentence that expresses tolerance: “We accept X to achieve Y, but not if Z.” No jargon, no percentages. A statement that the Chief Financial Officer (CFO) and the Chief Operating Officer (COO) understand.
Page two, quantitative. Per category, at most two measurable limits: a hard limit (exceeded → board escalation within 24 hours) and a soft limit (exceeded → reported in the next RM cycle). With the measurement source attached, from which system, at which frequency.
What we leave out.
- The definition of risk appetite. Anyone reading it knows what it is.
- Methodology justification. Belongs in an annex or in the Risk Charter.
- Document governance. Reference the Risk Management Charter; do not repeat it.
- Long case-study examples. The example comes verbally in the RM meeting.
The acid test.
A good risk appetite is directly decision-supporting. Our test: can a member of management, without further context, judge within five minutes whether a proposed initiative falls within or outside appetite based on these two pages alone? If not, there is still too much noise on it.