Risk

Risk tolerance is
not one question.

Most risk tooling answers a single question and treats the answer as a property of the person. It is not, and it moves.

“Risk score” means at least four different things

Walk through a typical advisory technology stack and you will find the phrase used for four unrelated quantities: the result of a behavioural questionnaire, the volatility implied by a model, the risk a portfolio is actually carrying, and the distance between where a portfolio should be and where it is.

All four get called a risk score. All four appear on client-facing documents. And in most firms they are computed by different systems, from different inputs, on different scales, by teams who have never had to reconcile them.

Why that is a compliance problem, not a design problem

It is tempting to treat this as cosmetic — different screens, different numbers, nobody dies. But consider what these documents are.

A proposal states that a client is suitable for a particular allocation. A drift report later states that the portfolio has moved away from target. An investment policy statement records what was agreed. If the risk number underlying those three is not the same number, computed the same way, then the firm has produced three regulatory records that disagree with each other about the same client.

Nobody notices until someone reads them side by side. Historically that someone is an examiner, or a client's attorney.

The test worth running at your own firm: pull one client's proposal, their most recent drift or review report, and their IPS. Do the three risk figures reconcile? Can anyone explain the difference?

The chain that makes it tractable

The confusion clears once you stop treating risk as one number and start treating it as four points on a chain:

PointThe question it answersWhere it comes from
What the client should holdWhat risk is appropriate for this person? Behavioural assessment, capped by capacity
What we assignedWhat did we actually recommend? The model or blend selected
What that impliesWhat risk does the recommendation carry? Derived from the target allocation
What they holdWhat risk are they carrying right now? Computed from actual positions

Every meaningful risk question is a gap between two points on that chain. Suitability is the distance between the first and the last. Drift is the distance between the third and the fourth. Implementation quality is the distance between the second and the third. Stated that way, each question has one answer instead of four.

Four principles that make it hold

  1. One definition. Comparing two points on the chain is only meaningful if both were computed the same way. A questionnaire result and a portfolio measurement expressed on different scales cannot be subtracted, no matter how confidently a report subtracts them.
  2. Computed once, served everywhere. Each figure is produced by the system holding its inputs and distributed. No screen re-derives it locally — that is how three documents come to disagree.
  3. Missing is not zero. "Not yet assessed", "not applicable" and "stale" are three different states, and none of them is a clean zero. A risk assessment that has expired is an outstanding compliance task, and a system that quietly treats it as neutral is hiding work.
  4. Direction is half the information. A portfolio that is under target and one that is over target by the same amount are not the same finding, and a report that shows only magnitude has discarded the part that determines what to do.

Suitability is a record, not a screen

The most useful reframe: a client's suitable risk range is not a display value. It is a regulatory record, set under firm policy with compliance sign-off, carried into the proposal, the plan, the policy statement and the ongoing monitoring — and versioned, so that a change is a dated decision rather than a silent overwrite.

Firms that treat it as a number on a screen end up unable to answer the only question that matters afterwards: what did you believe about this client, when did you believe it, and what did you do about the gap?

What we publish and what we do not

Our platform holds one risk definition across every module — the assessment, the proposal, the plan, the policy statement, the monitoring and the reporting all read the same number from the same source, and the client's suitable range is carried as a versioned record rather than recomputed at each surface.

We are not going to publish the axis, the volatility method, or the policy bands. Those took years and they are the part worth having. What we will do is take one of your live households and show you whether your current stack can pass the three-document test above.

Questions this did not answer? Ask them directly — that is what the twenty minutes is for.

Book 20 minutes with Kyle