When the dashboard changes colour

A company can have a risk policy, a monthly dashboard and a control register, yet still struggle the moment a meaningful signal changes.

Suppose its largest enterprise customer starts paying more slowly and receivables become more concentrated. The obvious questions are operational. Can sales continue adding exposure? Does finance tighten terms? At what point does the CFO become involved? Was the credit review completed? If an exception was approved, who approved it and where is the record?

Those questions expose the gap between having risk artefacts and having a working governance system. They also explain why a single generic risk score is a poor substitute for identifying the exposure that matters. Saying that overall risk is 7.2 out of 10 still tells a manager very little about what needs action. Credit risk, liquidity risk and market, foreign-exchange or interest-rate risk travel through different mechanisms, so they need different measures and mitigants.

The rest of the system starts with a much narrower question: what exposure are we carrying now, and what decisions should follow as it moves towards a boundary?

Four boundaries that should not share one label

The Financial Stability Board’s Risk Appetite Framework was developed for financial institutions. Its vocabulary is therefore useful here as a framework, not as a universal regulatory requirement.

It separates four ideas that are often blended together. Risk capacity is the outer amount of risk the organisation can absorb before constraints such as capital, liquidity, regulation or viability become binding. Risk appetite describes the broad type and amount of risk management is willing to accept while pursuing objectives and value. Limits or tolerance make that stance more operational. Risk profile describes the exposure actually being carried at a point in time.

COSO’s risk-appetite guidance also treats appetite as a decision concept tied to pursuing value. That matters because an appetite statement such as “moderate” has little operating value on its own. A manager still needs to know what exposure would be outside the intended range, who needs to see the change and who is allowed to accept or reduce it.

One way to keep the concepts straight is to picture a field of operation. Capacity marks the outer constraint. Appetite describes where management is willing to operate within it. Limits create usable boundaries. The risk profile shows the organisation’s current position.

From appetite to a decision path

COSO links risk appetite with tolerance, measures, indicators and triggers. In practice, the sequence is less about filling in a framework and more about making a policy statement observable.

An organisation first decides why a particular risk is worth taking. It then defines a limit or tolerance that is meaningful for that exposure. Indicators show movement. Thresholds determine when the movement deserves a response.

Closed risk-governance loop from Risk Profile through Risk Appetite, Limits and Tolerance, KRI and KCI, Threshold and Trigger, Escalation and Decision Rights, Controls, and Evidence and Remediation, which feeds the next Risk Profile assessment.

The design breaks down when the order is reversed. If a team starts with a hundred metrics, adds red, amber and green statuses, and only later tries to decide what each colour means, it usually ends up with monitoring that has no owner. The missing information is not another metric. It is the connection from the signal to an authority and a response.

The actual threshold should be company-specific. Capital structure, customer concentration, cash needs, business model and risk-bearing capacity differ too much for another organisation’s percentage to become a ready-made red line.

Escalation is where this becomes a governance design question. The UK’s FRC Corporate Governance Code Guidance is written for UK listed companies, so it should not be treated as universal law. Its operating principle is still transferable: significant risks and issues need clear escalation procedures and agreed triggers.

That means a threshold should come with an owner, a destination for escalation, a defined decision right and a response time that matches the speed of the risk. Crossing a threshold may lead to accepting the exposure, mitigating it, changing commercial terms, restricting an exception or stopping an activity. The useful feature is that the organisation has already decided who can make that call.

Three different objects can appear on the same risk report

The terminology around KRIs, KCIs and controls is especially easy to blur because all three may sit next to each other in a reporting pack.

The US OCC uses KRI and KCI terminology in a banking context, so the labels are not universal. In its Director’s Reference Guide to Board Reports and Information, KRIs help identify changes in risk while KCIs track factors related to the effectiveness of internal controls.

Consider a company worried about customer credit concentration. The largest customer’s share of receivables and the proportion of receivables more than 60 days overdue can serve as KRIs. They describe the exposure. A KCI might track whether high-risk credit reviews are completed on time or whether overrides retain documented approval. Those measures say something about the health of the control process.

The control itself is different again. Pre-contract credit review, exception authority and an overdue-account review workflow are mechanisms through which the organisation intervenes.

This distinction is consistent with COSO’s Internal Control framework, which describes internal control as a process intended to provide reasonable assurance over objectives related to operations, reporting and compliance. A metric can reveal a condition. A control changes what people are expected to do in response to that condition.

As a result, a worsening KRI does not by itself establish that the control failed. A deteriorating KCI can also appear before the loss outcome changes. That separation becomes important when deciding what to fix.

A customer-concentration case shows why the diagnosis matters

Take a B2B company that depends on a small number of large enterprise customers. It accepts some concentration because those relationships support growth, but it does not want one customer’s receivable balance to threaten near-term obligations.

For illustration, assume the company starts an amber review when its largest customer reaches 20% of total receivables and starts red escalation above 25%. These are teaching assumptions, not market benchmarks. It also monitors receivables more than 60 days overdue. Its KCIs include the completion rate of high-risk credit reviews and whether sales overrides retain documented approval. Controls include pre-contract credit review, approval for excess credit limits, regular overdue-receivables review and a documented override process.

In one month, the largest customer’s share rises from 18% to 22% and payment days lengthen. The KRI moves into amber. The credit reviews have been completed, overrides are documented and overdue-account reviews have occurred. The control process appears to be operating as designed.

The management response should therefore address the changed risk profile. That might mean tightening payment terms, reducing a credit limit, intensifying collections, constraining new exposure or asking the authorised executive to accept the higher concentration explicitly.

Now change the facts. The largest-customer concentration stays at 18% and overdue receivables remain normal, but completion of high-risk credit reviews falls. Sales overrides increase, and some have no retained approval record. The KRIs remain calm while the KCIs deteriorate.

Here the immediate work is different. Management may need to restore review capacity, tighten approval authority, prevent undocumented overrides and examine whether exceptions have become routine. The absence of a loss so far does not establish that the control process is healthy.

If both sets of signals deteriorate together, the exposure is worsening at the same time as the protective mechanism weakens. That combination would normally deserve higher escalation priority than either condition on its own.

What evidence makes a control credible?

Control inventories are useful for design, but they do not establish whether a control operated when it was needed.

The FRC guidance explicitly separates the existence of a risk-management and internal-control framework from its effectiveness. Ongoing operation, monitoring, review and remediation matter. COSO’s internal-control language is also deliberately limited to reasonable assurance. Even well-designed controls manage risk rather than eliminating uncertainty.

For a rule such as “all high-risk customers require credit review before contracting”, the evidence needs to reach beyond the policy sentence. The organisation should be able to show the trigger, owner and exception authority; confirm whether the review occurred when required; retain a review or approval record; and show how delays, bypasses or design weaknesses were corrected.

Three things are therefore weak proxies for effectiveness: a control listed in a matrix, a test that passed last year, and the fact that no loss has occurred yet. Exposure, workflow and staffing can change, while a risk may simply not have materialised.

Significant control problems also remain relevant after remediation. In the FRC governance model, significant issues, corrective action and subsequent review form part of the same oversight process. Surfacing the issue allows management or the board to see where the system failed and whether the remedy actually addressed the weakness.

Remediation feeds the next assessment

A near miss, a repeatedly late review or an undocumented override provides more than a compliance exception. It is evidence about assumptions that may have been wrong in the earlier risk design.

If sales overrides have repeatedly escaped documentation, filling in missing forms addresses the record but not necessarily the cause. Management may need to ask whether the KCI detected the pattern too late, whether approval authority was ambiguous, or whether the frequency of exceptions shows that stated appetite and limits no longer match commercial behaviour.

That is also where control effectiveness reconnects with the risk profile. After the process is repaired, the organisation may need to reassess the exposure itself and decide whether limits, indicators or escalation rules still fit.

A practical test is to pick one material exposure and trace it through the organisation. Can you identify the appetite and boundary, the KRI or KCI used to monitor it, the trigger and owner, the person with the relevant decision right, the control, evidence that the control operated, and what happened after a deficiency was found? If that trail disappears at any point, that is where governance is still relying on improvisation.

References