Updated for the 2026-2027 CFA® Level I curriculum.
Every organization that takes financial risk needs someone to decide how much risk is acceptable and someone to enforce that decision daily. That is risk governance. Once the acceptable level of risk is set, it has to be turned into specific limits for specific activities. That is risk budgeting.
Level I questions test whether you can tell the difference between a governance decision and its operational result, and whether you can spot when either one breaks down.
Quick Answer
Risk governance is the set of policies, oversight roles, and accountability rules that determine how much risk an organization takes and who is responsible for managing it. Risk budgeting operationalizes that decision by allocating a defined amount of risk capacity across business activities, strategies, or portfolio positions.
On the CFA Level I exam, you need to recognize governance responsibilities, tell board-level decisions apart from management-level ones, and apply a risk budget to a simple allocation problem.
Key Takeaways About Risk Governance and Risk Budgeting
Risk governance defines who decides, who approves, and who enforces risk policy inside an organization.
The board sets risk appetite and tolerance; management implements it through policies and daily oversight.
A risk budget converts risk tolerance into measurable limits for each activity, strategy, or desk.
Risk budgets allocate risk capacity, not cash. They use risk measures such as value at risk or volatility contribution, not dollar spending limits.
Monitoring compares actual risk usage against budgeted limits and triggers action when a limit is breached.
CFA Level I questions often test whether a scenario shows sound governance or a governance failure.
What You Need to Know for CFA Level I
Identify which body, board or management, holds a specific risk governance responsibility.
Recognize that risk policies must assign clear, individual accountability, not shared or vague ownership.
Know that a risk budget expresses risk tolerance in measurable terms, not spending limits.
Be able to allocate a risk budget across multiple activities using simple risk contribution data.
Understand that monitoring is ongoing. Limits get revisited, not treated as fixed forever.
Distinguish risk budgeting, a specific allocation tool, from the broader risk management framework.
What Is Risk Governance?
Risk governance is the structure of policies, oversight, and accountability that determines how an organization identifies, approves, and monitors risk-taking. It sits inside the broader risk management framework, but it focuses on who decides and who answers for outcomes, not on the technical process of measuring risk.
For the full framework context, see Risk Management and the Risk Management Framework.
Risk Governance Responsibilities
A sound risk governance structure covers four core responsibilities:
Setting the organization's overall risk appetite and tolerance
Approving formal risk policies
Assigning clear accountability for specific risk decisions
Ensuring risk reporting reaches the people who need to act on it
Each responsibility needs an owner. Governance fails when responsibilities exist on paper but no one is accountable in practice.
Board and Management Oversight
The board and senior management play different roles. Level I questions test this distinction directly.
Responsibility | Board of Directors | Senior Management |
|---|---|---|
Set risk appetite | Approves overall tolerance | Recommends based on strategy |
Approve policy | Approves formal risk policies | Drafts and proposes policies |
Daily oversight | Reviews periodic reports | Monitors risk exposures continuously |
Enforce limits | Holds management accountable | Enforces limits and escalates breaches |
The board sets direction and holds people accountable. Management runs the process day to day. A common trap is assuming one group performs both roles.
Risk Policies and Accountability
A risk policy documents the limits, escalation procedures, and accountability rules that put governance into action. A usable policy names who monitors each limit, who gets notified on a breach, and what happens next. A policy that only states a general risk philosophy without assigning ownership is not enforceable, and it will not hold up under a Level I scenario that tests accountability.
Risk Budgeting: From Policy to Practice
Once governance sets the acceptable level of risk, someone has to divide that risk across specific activities. That division is the risk budget.
What a Risk Budget Is (and Isn't)
A risk budget allocates an organization's total risk capacity across portfolios, strategies, or business units. It is expressed in risk terms, such as value at risk, volatility contribution, or tracking error, rather than as an amount of money available to spend.
The total allocated risk should not exceed the overall risk budget:
where:
= total risk budget approved by governance
= risk budget allocated to activity
= number of activities receiving a risk allocation
Actual risk usage for each activity is then monitored against its allocated risk budget:
where:
= actual risk used by activity
= risk budget allocated to activity
If approaches or exceeds , the organization may need to reduce the exposure, reallocate the risk budget, or review the position under its risk governance process.
Allocating Risk Across Activities
Management divides the total risk budget among activities based on factors such as expected return per unit of risk, diversification benefits, and strategic priority. This step is where the abstract idea of risk tolerance becomes a working number that a portfolio manager or trading desk can act on.
Monitoring Against Risk Tolerance
A risk budget only works if someone checks actual risk usage against the allocated limit on an ongoing basis. Monitoring triggers three possible actions when a desk approaches or breaches its limit: reduce exposure, request a temporary increase through the escalation process, or revisit the budget at the next governance review. Monitoring is continuous. It is not a one-time check when the budget is set.
The diagram below shows how a governance decision becomes a working risk budget.

Worked Example
Scenario: Meridian Investment Fund's board approves an annual risk tolerance of $60 million value at risk (VaR), measured at 95% confidence over a one-year horizon. Management allocates this total across three desks based on expected risk-adjusted return.
Desk | Risk Budget (VaR) | Actual Risk Used | Status |
|---|---|---|---|
Equity | $30M | $32M | Over budget |
Fixed Income | $20M | $15M | Under budget |
Alternatives | $10M | $9M | Within budget |
Step 1. Confirm the sum of desk allocations matches the board-approved total. $30M + $20M + $10M = $60M. The allocation is consistent with governance.
Step 2. Compare each desk's actual risk usage to its allocated budget.
Step 3. Identify the breach. Equity used $32M against a $30M budget, a $2M overage.
Step 4. Apply the risk policy. The policy requires escalation to the risk committee once a desk exceeds its budget by more than 5%. Equity's overage is roughly 6.7%, so escalation is required.
The board did not measure risk day to day. It set the overall tolerance and delegated allocation and monitoring to management. When the Equity desk breached its limit, the policy's escalation procedure activated automatically. That is risk governance and risk budgeting working together: clear roles, defined limits, and a monitored outcome, not an ad hoc decision by one portfolio manager.
Common Exam Traps
Confusing a risk budget with an expense budget
A risk budget limits risk exposure, such as VaR or volatility contribution. It does not limit spending or cash outflows.
Assigning all governance to one risk function
The board holds ultimate accountability for risk appetite. A risk management department implements and monitors, but it does not replace board oversight.
Setting a budget without first defining risk tolerance
A risk budget with no tolerance behind it has no reference point. Tolerance comes first; the budget operationalizes it.
Treating limits as permanent and unmonitored
Budgets get reviewed and adjusted as strategy, market conditions, or capital changes. A limit set once and never revisited is a governance gap, not a completed process.
Practice Question
An investment committee approves an annual risk budget expressed in tracking-error basis points and allocates it across two portfolio managers. One manager exceeds the allocated tracking-error limit for two consecutive quarters, but no corrective action occurs. Which statement best describes this situation?
Effective risk budgeting, because the manager generated excess return above the benchmark
A risk governance failure, because the monitoring and escalation process was not enforced
An appropriate risk allocation, because tracking-error limits apply only to a single quarter
Correct Answer: B
Risk budgeting only works when breaches trigger the policy's monitoring and escalation steps. A limit that is exceeded for two consecutive quarters without action shows the governance process failed, regardless of the return the manager produced.
Option A: Confuses investment performance with risk process. Even strong returns above the benchmark do not offset a breach of the risk limit that goes unaddressed.
Option C: Misreads how tracking-error limits function. These limits apply on an ongoing basis, not a single quarter, and repeated breaches require review under the policy.
Continue Your CFA Level I Prep With KeyPoint
Use structured lessons, practice questions, mock exams, and progress tracking to focus on the time you have left
FAQs About Risk Governance and Risk Budgeting
What is the risk governance definition used in CFA Level I?
Risk governance is the structure of policies, oversight roles, and accountability that determines how much risk an organization takes and who manages it. It includes both board-level decisions and management-level implementation.
How is risk budgeting different from a regular risk management budget in the accounting sense?
A risk management budget in this context is not a spending plan. It allocates risk capacity, measured in terms like VaR or volatility contribution, across activities. It does not set dollar spending limits.
Who sets a firm's risk budget?
The board approves the overall risk tolerance. Senior management translates that tolerance into a specific risk budget and allocates it across business activities or portfolios.