What is a risk appetite?
In its June 2026 Op Risk Benchmarking study of 61 banks, Risk.net found that 55% had breached their formal risk thresholds for at least one of their top five risks in the past year.
These were large institutions with board-approved appetite statements and mature risk functions, and the limits are still being crossed. When breaches are that common, it usually points to the same root cause: an appetite that was never defined tightly enough to hold in practice.
For lenders, digital banks, marketplaces, onboarding, and anti-money laundering (AML) teams, the pressure is only growing. AI document generators, template farms, and the sale of fully onboarded accounts mean more attempts, in more variations, hitting your controls every day.
But what really is a risk appetite? Why is it important? And how does it make sense for your business?
In this blog, we'll break down what risk appetite is, how it works, and how to define one that protects your institution without grinding to a halt.
Let’s get started.
What is a risk appetite?
Risk appetite is the amount and type of risk your business is willing to accept in pursuit of its goals.
For this blog we’ll focus on the fraud and financial crime context: the level of fraud loss, financial crime exposure, and customer friction you are prepared to live with in order to keep growing.
The risk appetite is usually written down as a “risk appetite statement,” a broad, strategic statement of the specific and measurable limit you set around it, such as an acceptable fraud rate on a given product or a maximum value you will approve without extra checks.
This is a short, board-level document that also sets out which risks the business will accept, which it will avoid, and where the hard limits sit. It gives your fraud, credit, and anti-money laundering teams a shared reference point when they make day-to-day decisions.
Even if a company doesn’t operate with a formal risk appetite statement, they’ll still let their appetite live implicitly in pricing decisions, product policies, and the instincts of a few senior people, that’s why we say everyone has one (even if they haven’t written it down).
5 steps to set up a risk appetite
Regulators expect your risk appetite to connect to a risk-based approach, where you identify and assess your money laundering, terrorist financing, and fraud risks, then apply controls that are proportionate to them.
It works as a cycle that connects your strategy to the decisions your systems and teams make every day.
It usually flows through five steps:
- Assess the risk. Start with a business-wide risk assessment that looks at your products, customers, channels, and geographies, and where each one exposes you to fraud and financial crime.
- Set the appetite and tolerances. Leadership agrees how much risk the business is willing to take, turning it into measurable limits like: acceptable fraud rate, false positive targets, or a value threshold that triggers extra review.
- Translate it into controls. Those limits become the rules, thresholds, and checks in your onboarding, transaction monitoring, and document verification workflows.
- Apply it in decisions. When a customer signs up or a transaction fires, adaptive decisioning approves, declines, or escalates the case based on where it sits against your appetite.
- Monitor and adjust. Track outcomes against your limits, breaches of the risk appetite, and test whether the controls are working, feeding what you learn back into the assessment.
Real world example: A digital lender might decide it will accept a slightly higher rate of first-party fraud on small, short-term loans because the margins and speed justify it, while applying much stricter checks on large or unusual applications.
Why is risk appetite important?
Risk appetite is the setting that everything else runs on. What specifically? Risk appetite impacts all of these processes directly:
- Control thresholds and rule sensitivity. Where you set fraud rules, transaction monitoring thresholds, and screening match tolerances (how aggressive vs. permissive).
- Alert and case volumes. How many alerts you generate and therefore how much investigation and staffing you need downstream.
- Model and score cutoffs. The decision points where a risk score triggers block, review, step-up, or approve.
- Onboarding and KYC/KYB friction. How much KYC/KYB verification, documentation, and step-up you impose on new customers, and where you let genuine users through.
- Auto-decision vs. manual review boundaries. What gets approved or declined automatically versus escalated to a human.
- Product and segment decisions. Which customers, geographies, and products you'll serve or avoid, and the limits you place on them.
- False positive vs. false negative trade-off. How much legitimate-customer friction and lost business you'll tolerate to catch more fraud, and vice versa.
- Escalation and exception handling. When something breaches, how fast it has to be actioned and who signs off.
All of this comes back to the way you set these requirements. Set it too tight and the cost is quiet but real. You decline good customers, add friction to onboarding, and pour resources into chasing false positives, leading to lost revenue, slower growth, and, at the extreme, whole customer groups pushed out of your business.
Set it too loose and the cost is louder. You absorb fraud losses, take on customers you should have screened out (putting your whole customer base at risk), and flirt with regulatory breaches, fines, and reputational damage that far outweigh the revenue you were chasing.
A clear risk appetite also gives you three things that are hard to get any other way:
- Consistency. Your fraud, credit, and anti-money laundering teams make decisions against the same reference point, so similar cases get treated in similar ways.
- Defensibility. When a regulator asks why you approved or declined a customer, you can point to a documented appetite and a proportionate, risk-based control that follows from it.
- Focus. You spend your time and money on the risks that actually threaten the business, instead of trying to eliminate every risk at once.
With these three key factors in mind, risk appetite becomes one of the most important processes to define for your business.
You cannot stop every bad actor, and trying would break your finances. So institutions must decide what they’re willing to accept and build controls that match.
You can't stop everyone, and you don't want to either
The instinct in fraud and financial crime is to aim for zero. Zero fraud, zero misses, zero risk. It feels like the responsible goal. But that’s not really achievable.
Start with the first half: you can't stop everyone. The Financial Action Task Force (FATF) is explicit that a risk-based approach is not a zero failure approach, and that a firm can take all reasonable steps and still occasionally be targeted or misused.
But you probably don't want to catch all the fraud either. Chasing zero is expensive. Overly tight controls decline good customers, add friction to onboarding, and bury your team in false positives.
For example, say a bank experiences an international laundering scheme and sets its appetite for money service businesses to near zero. Instead of judging each one, it closes accounts across the whole category.
Most of those businesses were legitimate remittance firms serving migrant communities, and once they lost banking access, the bank had pushed out an entire customer group that was mostly honest and profitable.
As we put it in our joint white paper with Fintrail “Unmasking Fraud,”
“There is no silver bullet or bolt-on fraud control that will solve all your fraud issues.”
So perfection is doing what is best for your business while keeping up with regulations and covering your bases. In practice that means three things: calibrate your appetite, be proportionate to your tiers and evidence-backed, and use signals as evidence, not immediate red flags.
It’s also important to acknowledge that appetite is not always set on risk grounds alone. Some customer segments and payment flows are simply profitable, and revenue has a quiet gravity that can pull an appetite higher than a purely risk-based view would set it.
Sure, no one writes that down, but it is a pressure every institution feels, and pretending otherwise is how blind spots form. Risk doesn’t shrink just because the revenue is good. It accumulates in exactly the flows you have decided not to look at too closely.
Then it appears as an unmeasured and unowned fraud loss, a regulatory finding, or an enforcement action that costs far more than the business ever earned.
Risk appetite practical tips
We already went over the steps of defining a risk appetite above. Now we’d like to explore each stage individually, providing advice at each layer to help you navigate the process.
.png?width=1024&height=1536&name=5%20steps%20of%20a%20risk%20appetite%20(1).png)
Step 1: Perform a risk assessment
A risk assessment is the structured exercise of identifying, understanding, and scoring the financial crime risk your business actually faces, before you decide how much of it you are willing to accept.
The Financial Conduct Authority (FCA) is explicit that risk appetite should flow from it. Its 2025 multi-firm review found that the strongest firms could show how risk appetite, the business-wide risk assessment (BWRA), and the customer risk assessment (CRA) work together, while weaker firms set an appetite with no clear line back to assessed risk.
- BWRA. The firm-level view of your exposure across money laundering, sanctions, bribery and corruption, proliferation financing, terrorist financing, and fraud.
- CRA. The customer-level view that scores individual relationships and feeds directly into your due diligence and monitoring.
Some of the FCA's recommendations on how to run one:
- Use quantitative and qualitative data.
- Score inherent risk, control effectiveness, and residual risk in that order.
- Weight the assessment around your specific products, customers, channels, and jurisdictions using sub-factors.
- Cover all financial crime risk, not just fraud.
- Evidence your conclusions.
- Review formally at least annually, with quarterly or event-triggered updates.
Step 2: Set the appetite and tolerance
With the assessment done, you turn it into your appetite and tolerance. Appetite is the level of risk you are willing to run, and tolerance is how far you will let it drift before someone has to act.
- Group the taxonomy into a few tiers. For example, tier one for high-risk products and customers and tier three for low-risk ones, so similar risks get consistent treatment.
- Carry the assessment weightings into the tiers. Take the BWRA and CRA weightings straight into the tiering so the two stay joined up (which the FCA specifically calls good practice).
- State appetite as residual risk. Your appetite is really a statement about the exposure left after controls, so define what good looks like per tier in those terms.
- Turn each target into key risk indicators (KRIs) with hard limits. Good fraud KRIs are forward-looking early warnings with a named owner and a defined breach trigger.
- Put a money figure on it wherever you can. Fraud is one of the few risks you can price in tangible financial terms, which makes fraud appetite unusually quantifiable, so anchor limits in money rather than adjectives.
“Unlike other areas of financial crime, it is easier to put a tangible financial cost against fraud risk. This can help define your risk appetite statement, drive priorities and help manage resource allocation.”
Step 3: Translate each limit into control settings
This is where appetite becomes operational and starts driving the stack.
- Wire limits into onboarding, monitoring, and decisioning. A higher-risk tier moves from standard customer due diligence (CDD) to enhanced due diligence (EDD), monitoring thresholds and rule sensitivity are tuned to the tier, and adaptive decisioning bands set where a case is auto-approved, referred, or declined.
- Name the trade-off you are accepting. Tighten thresholds and suspicious activity report (SAR) volume and false positives climb, loosen them and you accept more residual exposure, so make it a decision rather than an accident.
- Do not let a low appetite collapse into de-risking. The Financial Action Task Force (FATF) is explicit that avoiding risk wholesale, rather than managing it, is not a risk-based approach and does not imply a zero-failure standard.
Step 4: Apply it in decisions
Apply the appetite to see if it holds up against the cases your teams actually see. A couple of habits help here.
- Sanity-check it against known typologies. It is worth walking your appetite through the fraud you will realistically face, such as first-party versus third-party fraud, synthetic identities, money mule networks, and authorized push payment scams. If a plausible typology sails straight through your limits, that is a good sign the appetite needs tightening before it reaches the front line.
- Assume residual risk always remains. No single control covers every typology, so an appetite that quietly assumes full coverage is already wrong.
In practice, that looks different for every business. A digital lender might accept a first-party fraud loss rate up to 2 percent on small short-term loans, where speed and margin justify it, while holding sub-0.5 percent tolerance on large facilities backed by full EDD.
A payments marketplace might express appetite as a merchant chargeback ratio ceiling, tiering sellers and cutting off onboarding above a set threshold. A neobank might tune monitoring to keep false positives under a target rate so analysts are not buried, while accepting that a few lower-value cases are caught after the fact.
Step 5: Document it and get sign-off
An appetite is only real once someone owns it and it keeps up with the threat.
- Write it up as a board-owned risk appetite statement (RAS). The FSB expects the board to approve the framework and genuinely challenge it rather than rubber-stamp management, so record each tier, KRI, and threshold.
- Keep a clear line from assessed risk to live control. The FCA wants to see how your stated appetite connects to the systems and controls you actually run, so the documentation should trace from risk to tier to KRI to control setting.
- Review it continuously. Appetite shifts with the threat, so monitoring should be ongoing and KRIs refreshed on any material change. Fraud does not stand still; neither should your fraud detection.
- Cultural buy in. There is a real cultural issue, firms must commit to managing the defined risks and if they are prepared to fund and invest in the controls
Why AI matters to risk appetite: Adaptive decisioning

A risk appetite is only as good as your ability to hold it in real conditions. That is where AI has become hard to ignore.
AI-generated documents, synthetic identities, and automated attacks arrive in endless small variations, and a fixed rule set either misses the new patterns or blocks half your good customers trying to catch them.
Our joint white paper with Fintrail “Unmasking Fraud” found AI-generated repeated copy in 0.5 percent of application forms across hundreds of thousands of monthly applicants, a sign of how cheaply fraud now scales. AI detection also went up 90x in 2025 according to our Global Document Fraud Report.
As the same white paper later notes, people alone cannot catch every type of document fraud, especially unstructured ones like utility bills and bank statements, and it only gets harder across multiple jurisdictions and languages.
AI also lets you operate a tiered appetite at scale through adaptive decisioning. Instead of one blunt threshold, adaptive decisioning weighs dozens of signals per case and places it against the right tier in real time, applying EDD where risk is high and straight-through processing where it is low.
The Unmasking Fraud paper’s case study shows how that pays off: one firm layered AI-powered document and behavioral controls to reject around 2 percent of applications for fraud while reducing friction for genuine customers, saving over 1,200 hours of manual review.
AI moves the false positive and false negative rates at the same time. Better detection means you can tighten on genuine risk without dragging good customers into manual review, which is usually the constraint that forces teams to loosen their appetite in the first place.
As our white paper on AI Regulation in the US puts it:
“Implemented properly, AI has led to the identification of more suspicious activity while decreasing the volume of alerts."
But how the model communicates its findings matters as much as how well it detects. Explainability is key.
Why clear explanations are better than risk scoring
Most legacy systems hand you a number. A case comes back as 82 out of 100, or red, amber, green, and you are left to guess what actually drove it.
Clear, reasoned explanations beat an opaque score for four practical reasons:
- They connect to your appetite. Tiering threats and understanding the difference between manipulation vs. generation or theft of documents helps map risk signals directly onto your CDD and those that require EDD.
- They let you use the signal instead of just blocking it. When you can see the specific reason, a suspected fake document can feed the wider decision rather than trigger an automatic decline, so you stay in line with your appetite instead of turning away business by reflex.
- They are defensible. When a regulator asks why you approved or declined a customer, a documented reason ties the outcome back to your risk-based approach. “The model said red” is not an explanation a supervisor or auditor will accept.
- They make tuning possible. Reason codes show you which patterns are driving alerts, so you can adjust thresholds deliberately and see the effect on your KRIs. A bare score gives you nothing to calibrate against except the cutoff itself.
This is also where regulators are heading. The White House Blueprint for an AI Bill of Rights sets a notice and explanation principle, that automated systems should explain outcomes in plain, accessible language.
The Federal Trade Commission expects firms to explain their decisions to customers, including risk scores, so people know what data was used and how.
The NIST AI Risk Management Framework says much the same, listing explainable and interpretable alongside accountable and transparent as properties of trustworthy AI.
The one caveat is that explanation has limits in financial crime, where the Bank Secrecy Act's tipping off rules mean you explain to your analysts, auditors, and governance, not to a suspected launderer.
Conclusion
Risk appetite decides which customers you approve, which transactions you let through, and which documents you choose to trust. That's why your fraud detection capabilities need to be just as advanced.
Resistant Documents vets the documents you trust, Resistant Transactions monitors the payments you clear, and Defense in Depth applies both across onboarding and ongoing monitoring, so your appetite holds at the point of every decision rather than just on paper.
Set your appetite deliberately, define it in terms you can measure, and back it with detection built to the same standard.
Scroll down to book a demo.
Any document. Anywhere
Fraud awareness, examples, and lessons
Learn more about fraud in specific industries, best practices, and targeted documents.
View all
PRAGUE – 22 July 2026 – Resistant AI, a leading provider of document fraud detection solutions, today announced ...
In our last article, we teased that Fakedocshop, a popular document template farm running on subscriptions, has ...
Fake New York business licenses are risky in 2026. Whether it’s to provide jurisdictional privileges, or renew the ...
When we think about APP fraud, our hearts go out to the victims. But in 2026, banks in the UK are shouldering a ...
If you've seen as many template farm websites as we have, things start to blur. Hundreds of sites are selling ...
Keep yourself informed. Subscribe to our newsletter.
Be the first to know about releases and industry news and insights.