top of page

Risk Appetite, Capacity and Tolerance: A Practical Guide for Business Owners

Writer: Andrew Roy
Andrew Roy
7 hours ago
5 min read
AI-generated illustration.
AI-generated illustration.

Risk Appetite, Risk Tolerance and Risk Capacity: What’s the Difference?

By Andrew Roy, Founder of Roy Legal


Risk appetite is the risk a business is willing to take to achieve its goals. Risk capacity is what the business can actually support, given its resources and obligations. Risk tolerance sets the acceptable variation from specific business objectives.


For business owners, these distinctions help answer three practical questions: Is this an opportunity we want to pursue? Can we afford the consequences if it goes wrong? What boundaries should guide our decisions?

Concept

What it means

A practical business question

Risk appetite

Willingness to take risk in pursuit of a goal

Are we willing to depend more heavily on one customer to grow?

Risk capacity

Ability to support risk, given resources, capabilities and obligations

Could we cover wages and other commitments if that customer paid late?

Risk tolerance

Acceptable variation from an objective

How much variation in costs, orders or payment timing is acceptable?

These explanations adapt the Financial Stability Board’s definitions of appetite and capacity for financial institutions, together with COSO’s performance-based approach to tolerance. Terminology varies across frameworks, so a business should make clear how it uses these terms. FSB, pages 2–3; COSO, pages 5 and 19


The longer I work with businesses, the more I see how their approach to risk shapes their success. Owners often have sound judgment developed through experience. The difficulty is that their approach may remain largely in their own heads.


As the business grows, other people start making decisions too. A sales manager agrees to longer payment terms. A department hires ahead of demand. An operations manager commits to new equipment. Each decision may look reasonable on its own, while together they leave the business with little room for a setback.


A shared approach to risk helps people understand how their decisions affect the whole business.


Financial institutions provide a useful example of formal risk oversight. For the federally regulated institutions covered by its Corporate Governance Guideline, OSFI sets expectations for a risk appetite framework, board oversight and a chief risk officer or equivalent. It also provides flexibility for smaller, less complex institutions. OSFI’s Corporate Governance Guideline, Part III


An ordinary small business can borrow elements of that discipline and adapt them to its circumstances.


Consider a business planning to open a second location.


Its risk appetite might include accepting lower profits and uncertain returns while establishing the new location. The owners believe the growth opportunity justifies that uncertainty.


Its risk capacity depends on whether it has enough cash, staff and management support to open the location while keeping its existing operations running. Could it support both locations if the new one takes longer than expected to become profitable?


Its risk tolerance sets acceptable variation from the expansion plan. How far can opening costs exceed the budget? How far can sales fall below the forecast? How much later than planned can the location reach break-even?


Management should establish review triggers that leave time to respond before the business exhausts its capacity. Reviewing a slow start while cash is still available is a different conversation from reviewing it when payroll is due and the reserve is gone.

BDC makes a related point in its guidance on financing growth: spending operating cash on expansion can create a cash-flow squeeze if revenue subsequently weakens. BDC on financing growth


A major customer contract shows how the same concepts apply to everyday commercial decisions.


Suppose a business is offered a substantial contract with a new customer. To deliver the work, it would need to expand operations, hire staff and buy equipment.


The contract could significantly increase revenue, but it would also create ongoing costs supported largely by one customer. If that customer pays late or reduces its orders, the business still has wages, rent and equipment payments to cover.


Its risk appetite concerns whether it is willing to accept that dependence and those commitments in pursuit of growth.


Its risk capacity concerns whether it can support the consequences if things do not go as planned. Can it fund the expansion before payments start? Could it cover the additional costs if orders fall short or payments are delayed, while continuing to meet its existing obligations?


BDC recommends incorporating scenarios such as cancelled orders or a major customer’s failure into cash-flow planning. BDC on cash-flow scenarios


Its risk tolerance gives the plan measurable boundaries. Management could identify acceptable variation from the expansion budget, expected order volumes and agreed payment dates.


Review triggers then establish when someone needs to act. A payment delay approaching the business’s tolerance might prompt management to revisit planned hiring, discretionary spending or the assumptions behind further expansion.


The distinction matters: a business may be willing to accept a major customer opportunity but lack the capacity to support it on the proposed terms.


The broader industry also matters. Several customers may provide less diversification than their number suggests if they all depend on the same sector. A downturn could affect them at the same time.


For another business, the main exposure might be dependence on a key employee, a critical supplier or one technology platform. Cash reserves alone will not solve every problem. Risk capacity also includes the people, systems and operating capability needed to respond.


To set useful risk tolerances, start with a specific objective and a way to measure performance against it. Then decide what variation is acceptable and when management should review the situation. Those boundaries should reflect the business’s capacity and leave room to respond.


For a smaller organization, this can begin with a short written record of its main exposures, agreed boundaries, responsible people and review triggers. Bring it into existing management discussions and revisit it when a significant customer, investment or operating condition changes.


That approach reflects ISO’s guidance to tailor risk management to the organization and integrate it into its activities, with clear responsibilities and appropriate resources. ISO’s introduction to risk management


Owners and executives should also make room for people to question the assumptions behind a decision. Someone pursuing an opportunity may see its potential clearly. Someone responsible for cash, delivery or staffing may see a constraint that deserves attention.


A business should be able to explain which risks it has chosen, why they are worth taking and what would cause it to reconsider. That understanding should be shared by the people making its decisions.


Roy Legal advises businesses on commercial contracts, governance and regulatory compliance. If you are considering an expansion, a major customer agreement or another significant commitment, we can help you assess the legal obligations and risks before you commit.


This article provides general information only and is not legal advice. Reading or relying on it does not create a solicitor-client relationship with Andrew Roy or Roy Legal. Laws and their interpretation may change, and their application depends on the circumstances. Obtain legal advice about your specific situation before acting on this information.

© 2026 Andrew Roy. All rights reserved.

 
 
 

Comments


bottom of page