Methods and procedures for assessing the risk appetite of a credit institution. On the approach to assessing a company's risk appetite based on a formalized assessment of its financial condition. Determining and monitoring risk appetite

As an organization matures, the likelihood of new risks increases. How much risk is acceptable for the company in this case? The answer to this question lies in the concept of "risk appetite".

risk appetite determines the level of risk an entity can accept to retain in order to achieve its operational and financial objectives. Risk appetite depends on external and internal factors. TO external factors include market conditions, the macroeconomic state of the economy, government regulation requirements, ongoing changes in the industry. Internal factors are the financial capabilities of the organization, the current stage of its life cycle, the opinions of the main stakeholders (shareholders, bondholders, analysts). Also, an important factor is the expectation regarding the development of the company in the medium term: the forecast of profit, revenue, market share, etc.

Risk capacity defines the maximum risk limit an organization can accept. In other words, this indicator corresponds to the maximum level of losses at which the organization will not be declared insolvent (bankrupt).

It is obvious that the risk appetite should not go beyond the limits of the risk capacity, therefore, first, as a rule, the risk capacity is determined, and then the level of risk appetite.

The value of the risk appetite is set by the company's management with the obligatory justification of the compliance of the risk appetite level with the strategic objectives of the organization. When formalizing the risk appetite, its value is fixed in the internal documents of the organization, which determine the internal risk management policy. For example, the risk appetite can be established in the Regulations on risk management of the organization, which also sets out the goals, principles and approaches in the field of risk management. The organization should clearly define who is responsible for monitoring and adhering to the risk appetite.

Having a set value for risk appetite simplifies the organization's risk management process. In this case, it comes down to controlling that the current risk value does not exceed the entered risk-annetite level. If the current risk value exceeds the risk appetite, the organization takes measures to manage the risk in order to reduce it to the risk appetite level. If such an excess occurs, the organization takes the necessary measures to reduce the risk to the level of risk appetite.

When deciding on the management of a specific risk, the ratio between the cost of risk management measures and the risk assessment is taken into account. In exceptional cases, the organization's current level of risk may exceed the value of risk appetite if the cost of risk reduction measures exceeds the risk value.

Thus, the risk appetite allows: 1) to determine what risks the organization can accept; 2) formulate a clear management position regarding risks; 3) simplify the risk management process; 4) to avoid cases when the amount of loss from the occurrence of risk can lead the organization to bankruptcy.

The scheme of using the concept of risk appetite is shown in fig. 2.10.

Rice. 2.10.

The function of the risk appetite in risk management becomes easier to understand if we consider an axis where two opposite ends characterize the two extremes in risk taking (Figure 2.11). On the left side, the extreme point shows a conservative strategy, when the organization is completely risk averse. The right side of the axis, on the contrary, corresponds to the maximum risk strategy. The role of risk appetite is to determine which point on this axis corresponds to the organization's strategy.

On fig. 2.12 shows a risk map. On one axis, the probability of the occurrence of risk is plotted, on the other, the size of the loss from the occurrence of the risk. The straight line, corresponding to the risk appetite, divides the matrix area into two parts: all projects (tasks) of the organization that lie below the direct risk appetite are acceptable, and vice versa, all projects above the risk appetite straight line have an unacceptable level of risk. This figure shows low-risk and high-risk organizations. For each company, the project marked with a dot in the figure 1, is valid, and the project 3 both organizations must reject due to an unacceptable level of risk. However, the project 2 for an organization with a low level of risk is unacceptable, while for another organization it is acceptable.

Rice. 2.11.

Rice. 2.12.

Risk appetite can be defined in quantitative and qualitative terms. In the first case, the absolute value of the possible risk or its relative value is set (for example, the permissible deviation of the indicator from the planned one). At the same time, the risk appetite is determined depending on the goals of the organization. These goals may be to achieve financial targets, meet financial regulations and other performance indicators of the company. They may consist in compliance with financial standards, in achieving the established financial and other performance indicators of the company. A qualitative expression of risk appetite is used when risk cannot be quantified. In this case, the risk appetite is established in a descriptive way.

Examples of quantitative risk appetite.

  • 1. The organization must not lose more than 10% of annual income. If the potential losses exceed this value, it is necessary to refuse to accept the risk.
  • 2. The size of the organization's capital must be sufficient to cover five losses of a certain level in a specified period of time. If there is not enough capital, the risk cannot be accepted.
  • 3. The ratio of the financial debt of the organization to the value EBITDA at the 3:2 level.

Examples of qualitative risk appetite.

  • 1. The organization should not operate in countries with increased currency risks.
  • 2. The organization should not work with partners whose financial strength rating is below a certain level.

Each organization has its own way of defining risk appetite. Only the overall level of risk appetite can be set. In this case, the value of the current risk of the organization (taking into account the acceptance of new risks) is compared with the value of the overall risk appetite. With another approach, in addition to the general risk appetite, the maximum value of losses for each type of risk is set. In this case, along with the control of the overall risk of the organization, control is also carried out for each type of risk.

There are different methods in determining risk appetite. Let's consider some of them.

Method, based on the cost of risk management activities. In this method, the only criterion for assessing risk appetite is the ratio between the cost of risk management measures and the amount of risk in a certain period of time. The risk is accepted by the organization in any case, if the potential losses from the occurrence of the risk do not exceed the cost of risk management measures. The level of risk appetite in this case corresponds to the cost of risk management measures.

Method, using the organization's current level of risk. With this method, the overall risk appetite of the company is summarized from the individual components. For this, indicators are calculated, with the help of which the maximum allowable losses of the organization for each type of risk are determined. Such indicators may include the company's total debt portfolio, the company's market value, the company's equity, the amount of liabilities in foreign currencies, counterparty credit ratings for existing financial transactions, and other risk indicators.

The overall risk appetite of an organization in a certain period of time is calculated as the sum of possible losses for each type of risk:

where lj- assessment of losses associated with the onset of risk (1 - credit risk, 2 - liquidity risk, 3 - currency risk, 4 - interest rate risk, 5 - stock risk), taking into account the probability of risk occurrence.

The overall level of risk appetite can be expressed both in absolute terms and in relative terms. For example, risk appetite is set as a certain percentage of an organization's equity capital or its market value. Further redistribution of risk appetite for each risk is carried out taking into account the weight of each risk calculated by the formula

where lj- assessment of losses associated with the occurrence of the i-th risk in a certain period of time, taking into account the probability of the occurrence of the risk; R- the overall risk appetite of the organization in a certain period of time.

A method that uses the organization's historical level of risk. In this method, as in the previous one, the risk appetite is calculated as the sum of possible losses for each type of risk. The difference is that in this case, the historical dynamics of the risk indicators of the organization is considered.

For each type of risk, a period is selected in which the organization assumed an increased risk. This may be, for example, a crisis year with unfavorable market conditions or any other period at the discretion of the company's management. Periods when the onset of risk led to serious consequences for the organization, requiring a radical revision of the chosen development strategy, should not be considered.

The absolute value of risk appetite is calculated as the sum of possible losses for each type of risk in different periods of time:

where Lj(tj)- assessment of losses associated with the occurrence of the i-th risk at time f, taking into account the probability of the occurrence of the risk, i- 1, 2..., 5.

Method based on data from similar organizations. With this approach to determining risk appetite, statistics are used for similar organizations. The criteria by which comparable organizations are selected are established by methodological documents and may include such indicators as the territory of the company, its market value, the amount of revenue, the ratio of own and borrowed funds, etc.

In this case, risk appetite is defined as the overall risk level of an organization that does not lead to a deterioration in the organization's performance, but compared with the average of peers.

Method, based on stress testing. To use this method, the factors that have a significant impact on the organization's activities are first selected. Both internal indicators of the organization and external ones are considered as factors. External factors may include interest rates, macroeconomic indicators, commodity prices, government regulation requirements, etc.

Then a model of the organization's behavior is built depending on different scenarios of the dynamics of the selected factors. After that, a combination of factors leading to the worst acceptable state of the organization is established. Based on these factor values, the level of risk appetite is determined.

Method of expert opinion of specialists. In this case, the risk appetite is established based on the opinions of the owners of the organization, its management and other experts.

Combined method. This approach combines various methods for determining risk appetite. For example, an organization's overall level of risk appetite is calculated using a peer-to-peer method, and the allocation to each risk is made using weights calculated based on the organization's historical level of risk.

In many companies, risk appetite is the starting point for developing a strategy for its development and capital planning. When determining the risk appetite, management proceeds from the objectives of the organization. For example, a bank aims to achieve a high rating with a low risk appetite or to achieve a high level of income, implying a high level of risk appetite. The entity should consider how the identified risk annetite is acceptable in the current period and how it will be acceptable in the future.

Risk appetite affects the corporate culture and style of the organization. Its use helps to choose the directions for the development of the organization that correspond to the established level of risk appetite.

Many government regulators recommend using the concept of risk appetite in the activities of organizations. In particular, in the banking sector, the Basel Committee on Banking Supervision and Regulation (Basel II) considers the use of risk appetite as one of the main principles of bank risk management.

The disadvantage of using risk appetite in managing a company's financial risks is the presence of subjective assessments in its determination. The absence of the necessary financial components for calculating the risk appetite makes it necessary to rely only on expert opinion.

In addition, there are no precise statistical models for quantitative risk assessment to calculate the current risk level. Therefore, an organization can only establish a risk appetite for certain types of risk, where its value can be calculated with a fairly high degree of accuracy. In addition, the concept of risk appetite requires that the organization's internal business processes be designed in a way that makes it easy to calculate the company's current level of risk at any given time. The management of the company should have timely and sufficient information about the nature and level of risks taken.

Risk manager: in dreams of management

Sometimes it seems that risk management has reached a dead end. Risk managers “measure, record the presence or document risks, assuring everyone around them that risks and their reduction are the main goal of managing an organization”, as Aleksey Sidorenko wrote in his series of articles. The last point, convincing everyone around that risk reduction is the main goal of business management, is very useful from the point of view of self-positioning and self-promotion of risk managers. Global initiatives like Basel I-II-III-etc are the cash cows of consultants (we really love them!).

But risk managers are often just annoying to business leaders. Therefore, business unit leaders often try to ignore risk managers, and sometimes they are simply fooled. At best, they view risk management as an inevitable cost of being in business, and require risk managers simply not to have problems with regulators.

Isolation from the real world where profits are made makes the day-to-day work of risk management dull, pointless, and merciless to the people who do it. And these people are qualified: they are good at building mathematical models, predicting, and identifying patterns. Ignoring this experience, wasting working time by these people is an unaffordable luxury in the era of declining margins, fintech and the growth of objectively existing risks.

So, how do you make risk management business-oriented, but still remain risk management? What are the real problems (beyond regulatory compliance) that business risk management can address? How can risk managers help improve business performance? How to make sure that business units and risk management work in one team? What managerial decisions need to be made to achieve these goals?

One of the answers to all these questions is the Declaration of Appetite for Risk.

Risk appetite declaration: what is it?

The risk appetite declaration is a formal document that lists risks, risk factors, their target values, threshold values, upon reaching which certain decisions are required. This document also formally establishes the target level of economic capital adequacy to cover risks, the volume of the required liquidity buffer, as well as the target return on capital.

This definition is a tribute to dead letters and is capable of destroying any sound idea in the bud. It makes no sense in terms of real business development needs. Everything that is mentioned in this definition is either invented or imagined by risk managers. In order for a risk appetite declaration to be worth more than the paper it is printed on, it needs to be specified.

A list of specific managerial decisions and actions can breathe the breath of life into this document. The main source of management actions is business goals. The risk also does not exist in itself, but represents the failure to achieve these goals. Therefore, the Declaration of Appetite for Risk should contain a list of objectives. The management actions listed in the Declaration are tied to goals, but have different conditions for their application. They also depend on our attitude towards risks.

Attitude to risks is a key moment in building a risk management focused on managerial actions. It is not possible to manage all risks. You don't need to manage all the risks. If we minimized all risks, there would be no sources of profit left. Therefore, you need to decide from the very beginning:

What risks do we accept (and transfer to our shareholders, leaving them to manage these risks);

What risks do we manage, that is, what risks are in the area of ​​our business and our competence;

What risks do we and our shareholders prefer to avoid that our shareholders are not prepared to take under any (reasonable) circumstances.

By classifying risks in this way, we can focus on those that we manage and (to a lesser extent) those that we accept. The cause of any risk is a change in risk factors. Risk factors may have different qualitative characteristics and quantitative measures. Some of these characteristics and measures are tied to probability, some to the impact that the realization of the risk has on the organization. Some risk measures are expressed in units of the financial result (the amount of profit or loss), some are risk-oriented in a narrower sense of the word.

Management actions and decisions depend on the situation. Some of them are simply planned in advance depending on the stage of the portfolio or transaction life cycle. Some should be taken in response to an external event. Actions can be natural in the normal course of business, or they can be extreme anti-crisis. An example of the latter type of action is stop loss selling.

Procedures for regularly monitoring a transaction or portfolio we manage should also be described in the Risk Appetite Statement.

Thus, the Declaration of Appetite for Risk is not only and not so much about risks. It's about business in general. A valid Risk Appetite Declaration is more of an investment declaration created to address all internal management challenges.

Declaration of appetite for risk in bank management

A valid Risk Appetite Declaration permeates the bank management process. It sets the starting point for planning, since it defines the target characteristics of the portfolio that the bank forms.

It also regulates the lending process. The image of the target borrower, lending rules and risk acceptance are an integral part of the Declaration.

It defines the rules and methods of portfolio management. Managing an established portfolio of retail loans is a complex task. This is much more difficult than managing portfolios of securities. Loan conditions are fixed and cannot be changed unilaterally. The secondary market for loans is not liquid. Their sale requires long and scrupulous preparation. Therefore, selling as a portfolio management tool in a crisis situation is practically an inaccessible tool. But sometimes the Declaration of risk appetite in terms of prepayment risk may dictate the need for unilateral easing of loan conditions and set the rules for such easing.

Because the Risk Appetite Statement sets out the objectives of a retail loan portfolio, it can be used to evaluate the performance of that portfolio. Profits and losses of business units, risk-adjusted financial result are calculated based on the assumptions specified in the Declaration. Moreover, if some risks materialize, onlyThe risk appetite declaration distinguishes between bad luck and risk management failure.

Key risk indicators for retail lending

Widely used indicators of the risk of a retail loan portfolio include the average rate of provisions for possible losses in the portfolio, the share of overdue loans, 0 + 3mob (the share of loans falling into arrears during the first three months after issuance), 30 + 6mob (the share of loans whose maturity overdue exceeds 30 days overdue in the first six months after issuance), the volume of loans written off in the portfolio. All these indicators are relatively easy to calculate. However, they all have one drawback: they are not leading, and therefore their use in portfolio management is difficult.

Instead, we recommend using more complex indicators, such as LTS, specific LTS, forecasts of reserves for possible losses, forecasts of delinquency volumes and delinquency frequencies. The computational complexity of these indicators is easily offset by specialized information systems such as . However, in return, the risk manager gets the ability to manage.

For example, as a portfolio matures, the amount of reserves for possible losses increases, and therefore the economic capital available to the bank to cover the risks it takes decreases. At the same time, the generation of young loans brings good returns, which initially cover the costs associated with reserves and capital. The optimal choice of the timing of the sale of loans (securitization) allows you to double the profitability of the bank's capital.

The most important characteristic of a loan portfolio is LTS (loss-to-sale). This value represents the accumulated losses over the generation of loans. LTS grows, maturing throughout the lifetime of a generation and depends on the initial contractual term of loans and the credit quality of borrowers. Specific LTS is a derivative characteristic of the credit quality of borrowers (the effect of the initial contract term of loans has been removed). The concept of specific LTS was originally developed by Vladimir Babikov. In essence, the formation of rules for issuing loans is a procedure for linking the specific LTS to the characteristics of customers (debt-to-income ratio, borrower's region, level of education, industry affiliation, etc.). Therefore, when formulating the Declaration of Appetite for Risk, the risk manager must determine the target level of specific LTS.

Analytical procedures (for example, those implemented in the Roll Rate Analytic System®) allow you to model the impact of GDP growth, unemployment and other macroeconomic factors on the level of delinquency, LTS and specific LTS. According to the requirements of the Basel Committee, credit ratings must be assigned to borrowers taking into account possible deterioration in economic conditions or unexpected events (see §§414-416 in International Convergence of Capital Measurement and Capital Standards, paragraph 12.13 of Regulation 483-P of the Bank of Russia). Objective analysis of LTS is a practically efficient way to ensure that this requirement is met.

Issuance of loans

Lending procedures should be based on the Declaration of Appetite for Risk and ensure that the resulting portfolio is consistent with its objectives. The cornerstone of these procedures are scorecards. With their help, the diversity of characteristics of borrowers is converted into an aggregate score. This allows you to form an unambiguous decision whether to issue a loan to this client or not. However, the decision rule should take into account not only the current characteristics of borrowers, but also their possible evolution over time. This is not only a requirement of common sense, but also of regulatory standards. Therefore, the scoring system must link the characteristics of borrowers to the specific LTS of the portfolio that the bank wishes to build.

Moreover, scorecards need to cover more than just credit risk in terms of unit LTS. They must also take into account the behavior of customers, in particular, their early repayment of loans. Why is it very important? If the value added of the loan portfolio is initially 10% of the loan amount, early repayment of 30% of the portfolio per year reduces the value added to negative -40% of the loan amount. In other words, a borrower who repays loans ahead of schedule brings losses to the bank. The experience of our clients shows that taking into account the behavior of clients when building scorecards (along with taking into account their credit quality, of course) allows you to increase profits by five times while reducing the volume of new loans by half (which reduces the bank's costs when attracting resources).

Risk Appetite Declaration: A Working Example

As mentioned above, the Risk Appetite Declaration governs all aspects of banking portfolio management, namely:

Target return on capital and other key portfolio performance indicators;

Risk targets;

Portfolio size and other characteristics;

Indicators that should be constantly monitored, as well as their threshold values, the violation of which entails the adoption of managerial decisions.

These principles are illustrated in the figure.

Forming a Declaration of Appetite for Risk is a difficult task. But it is worth solving. The result of using hidden reserves, which will be released as a result of the correct organization of the business process, justifies all costs. The combination of portfolio objectives and management procedures facilitates the management of the bank. As a result, returns on capital are rising even in an era of increased competition, economic crises, tighter regulations and a resurgence of barriers to entry. High-quality risk management guarantees business owners good nights. True, some amateurs call it luck for some reason.

He who has ears, let him hear! Those who have risk management, let them profit!

Dmitry Nikolaevich Palunin,
Member of the Management Board - Head of the Financial and Economic Center of PJSC Inter RAO

Artem Mikhailovich Kokosh,
Head of the Analysis, Financial Modeling and Insurance Department of PJSC Inter RAO

In the theory and practice of financial management and risk management, it is common to use the concept of risk appetite, which determines the level of uncertainty that an organization is willing to accept in the course of its activities. At the same time, approaches to assessing the value of risk appetite are not strictly formalized. In the absence of a reasonable monetary assessment of the level of risk appetite, in the real life of a corporation, this concept can remain only a theoretical construct. This article proposes an approach to assessing a company's risk appetite based on a credit rating, which is an indicator of assessing the company's financial condition. The results of such an assessment can later be used by the board of directors of the company for a transparent and reasonable distribution of levels of responsibility, setting priorities in risk management, and motivating management.

Keywords: risk management, credit rating, risk appetite, critical risks, risk map, tolerance curve

In theory and practice of financial management and risk management it’s widely spread to use the concept of risk appetite, which determines the level of uncertainty the company is willing to accept within its operations. At the same time in the international practice approaches for the estimation of risk appetite level are not strictly formalized. One can see that when there is no pecuniary justified valuation of risk appetite, it could remain only a theoretical concept with no use in the real life of the corporation. In current article it’s proposed to evaluate pecuniary the risk appetite based on the credit rating of the company, composed of its key financial indicators. The Board of Directors could use the results of this evaluation for transparent and justified allocation of the responsibilities for risk management, for the prioritization of risks, for the motivation of top management.

key words: risk management, credit rating, risk appetite, critical risks, risk map, tolerance curve

Best international practice recognizes that the definition of risk appetite in the corporate risk management system helps protect the company from pursuing too unrealistic or extremely conservative goals, that is, it allows you to optimize the level of risk that is accepted in achieving corporate goals (Fox, 2012). Thus, assessing the level of risk appetite, as the level of uncertainty that an organization is willing to accept in the course of its activities, is a key attribute of an effective corporate risk management system.

Risk appetite reflects the amount and types of risk (uncertainty) that an organization is willing to accept in order to achieve its goals. (Basel Committee on Banking Supervision, BCBS, 2011). The International Standard indicates that different goals imply different levels of risk - thus, each organization must formulate for itself how much and what types of risks it is ready to accept in the course of its activities (“risk appetite statement”). (Committee of Sponsoring Organizations, COSO, 2012). At the same time, international standards do not formalize the methodology for determining risk appetite, but only offer a number of approaches by which the Board of Directors or shareholders can formulate the level of acceptable and unacceptable risk. As a result, for many executives and board members, risk appetite remains only a theoretical construct that cannot be expressed in numbers and is difficult to apply in practice (Jim DeLoach, 2014). In this situation, some authors offer a list of questions for board members that can help formulate what the organization's risk appetite is (Purvis Mike, 2013). Other authors (Lamanda, et al., 2012) offer a number of approaches to determine risk appetite as a share of profit before tax or capital (top-down approach), or based on a historical analysis of losses as a result of risk realization (approach "upwards").

This article will propose an approach to the numerical assessment of the organization's risk appetite, based on a formalized assessment of its financial condition. To do this, we will use the following definition - the value of risk appetite is defined as the maximum risk level of the company, accepting which the company does not violate the established restrictions and obligations to creditors, regulators, shareholders, consumers and other interested parties. (Financial Stability Board, FSB, 2013). One of the most convenient indicators that reflects the existing limitations of the organization and its obligations to counterparties can be the company's international credit rating. A specific threshold value of the international rating can be specified in the company's loan agreements, in the motivation system (KPI) of the management and in other documents of the organization.

Thus, in this case, the risk appetite can be formulated as the level of losses, the realization of which will lead to the prospect of lowering the international credit rating of the organization by a set number of intermediate steps - as a rule, these are 1-2 intermediate steps (notch), less often 3 intermediate steps.

To assess the impact on the international rating of an organization of a particular level of losses, you can use the internal credit rating methodology proposed in the article by D.N. Palunin (2015). The advantage of the internal credit rating - on the one hand, in a fairly accurate approximation of the international credit rating, and, on the other hand, a completely transparent methodology for its calculation. These properties of an internal credit rating make it possible to use it to assess the level of risk tolerance and determine the risk appetite of an organization.

To formulate the level of risk tolerance, we formulate two concepts that will be used in what follows. Pain threshold (PT, Pain Threshold) - the level of risk (in financial terms), the excess of which, if implemented, is unacceptable. Risk appetite (RA) is the degree of total risk that the company as a whole considers acceptable for itself in the process of creating value, achieving its goals. In terms of the internal credit rating, the pain threshold can be respectively expressed as the level of losses for the planned period, the implementation of which will lead to the prospect of lowering the international credit rating of the organization by 2 intermediate steps.

Risk appetite in terms of the internal credit rating is the level of losses over the planned period, the implementation of which raises the prospect of lowering the international credit rating by less than 1 intermediate step. Tier levels are given as an example and may be changed by the Board of Directors or shareholders depending on the financial condition of the company and the risk appetite of shareholders.

For the purposes of searching for the absolute values ​​of risk appetite and pain threshold, the simulation method can be applied, within which a random value of the annual net profit for the reporting period is modeled. For each value of the simulated net profit, the values ​​of dependent indicators included in the calculation of the internal credit rating are calculated: EBITDA, cash flows from operating activities, financial debt and other indicators that affect the internal credit rating. The basis for calculating indicators can be a company's business plan and an internal model that describes the dependence of key indicators on changes in the organization's net profit. The result of the calculation is the amount of loss, expressed in rubles, upon the occurrence of which the forecast international credit rating of the company is reduced by a given number of steps. The estimated loss is the organization's risk appetite and pain threshold.

One of the directions for using the result of the pain threshold and risk appetite assessment for the Group's companies is risk ranking, that is, the division of risks into acceptable and critical ones. Next, we propose an approach to ranking risks based on the utility function. The utility function allows you to move from comparing risks that have 2 parameters (probability of occurrence and expected damage) to comparing one value of the utility function, which uniquely determines the level of criticality (significance) of the risk. To construct a utility function, it is possible to use the Cobb-Douglas utility function of the following form:

- the amount of damage in thousands of rubles,
- the likelihood of damage,
– a parameter that takes values ​​from 0 to 1, which determines the preferences between damage and probability.

The indifference curves of the utility function (that is, the set of points that have the same utility) have the form of a family of hyperbolas:

- probability of damage,
- amount of damage
- parameter,
is a constant.

To construct an indifference curve, it is necessary to determine the probability with which the company can allow the realization of losses corresponding to the value of risk appetite and pain threshold. We define these probabilities as 50% for risk appetite, and 1% for pain threshold. Next, we construct an indifference curve on which there are two points - risk appetite (RA) with a probability of 50% and pain threshold (PT) with a probability of 1%. By means of mathematical transformations, the parameter of the utility function is uniquely determined.

is responsible for the preference between the probability and the level of damage. Thus, the shape of the indifference curve is completely determined by the simulated loss levels RA and PT:

The indifference curve of the utility function passing through the points on the risk map corresponding to the risk appetite and pain threshold can be called the tolerance curve. On the risk map, the horizontal axis (abscissa) is the amount of damage, the vertical axis (ordinate) is the probability of damage. The tolerance curve is unique for each company, and, given the approach to determining the pain threshold and risk appetite, the tolerance curve changes, depending on the current financial condition of the company.

Let's represent the tolerance curve in the coordinates of the probability P and the amount of losses L, by transforming the utility curve:



Already at this level, it is possible to cut off some of the risks as critical according to the following condition:

- the likelihood of a particular risk,
– the magnitude of the specific risk.

In addition, the maximum number of risks can be additionally cut off, the total equivalent level of tolerance of which does not exceed the level of tolerance of the company. The risks included in the cut-off risks are considered the risks of an acceptable level, all remaining risks are critical risks.

Any of the risks located on the risk map lies on its own indifference curve corresponding to the above utility function.

For example, from the above risk map it follows that:

We will also give a practical example of ranking risks on a risk map.

The tools of risk tolerance, pain threshold and risk appetite also make it possible to visually decompose risk tolerance into the level of the company's functional areas. Building a tolerance curve separately for each functional area allows you to classify the risks of each area into acceptable and critical ones, as well as rank the risks to determine the priority order for responding to risks in functional areas. Risk appetite indicators are calculated for each functional area

And pain threshold


- risk appetite

– pain threshold for the entire Society,

N - the number of functional areas of the Company. Further, similarly, a tolerance curve is constructed for each functional area separately.

with a constant

And the parameter .

All risks of the functional area are ordered in ascending order of the indicator. The higher the value of this indicator for the risk, the more significant this risk is for the Company. A risk with characteristics is critical within a given functional area if it satisfies the condition

Where: - the number of the functional area,
a is the risk number in this functional area.

In conclusion, it should be noted that the proposed approach for assessing risk tolerance indicators based on an internal credit rating makes it possible to make the assessment more reasonable and understandable at all levels of organization management. Such a formalized indicator as an internal credit rating makes it possible to clearly show how much loss will lead to a significant deterioration in the company's financial condition. As a result, the risk appetite can become not just a theoretical construct that came from international standards, but a practical tool for the board of directors to separate the organization's important risks from minor risks, determine risk management priorities, and reasonably and reasonably allocate levels of responsibility for managing specific company risks.

