Risk-Bearing Capacity as a Licence to Act

The Right Risks


The Right Risks: Risk-Bearing Capacity as a Licence to Act Comment

In the first half of 2026, Munich Re did two things that appear contradictory at first sight. In life and health reinsurance, it completed its largest-ever single longevity transaction, covering pension liabilities of around €4 billion. At the same time, in the July property-casualty reinsurance renewals, it reduced business volume by 9.1% after risk-adjusted pricing fell by 5.5%. Management explicitly stated that it would deliberately walk away from business where pricing was not commensurate with risk.

This is close to a textbook illustration of professional risk management: neither taking as much risk as possible nor as little as possible. The company assumes additional risk where the expected risk-return profile is attractive and rejects risk where the compensation does not justify the downside. The skill lies in selecting the right risks.

The financial margin of safety is not a side issue. Munich Re reported a net result of €3.925 billion for the first half of 2026 and a Solvency II ratio of 304%. Its annual report explains that risk tolerances and limits are based on available capital, liquidity and business strategy and are integrated into business planning. Based on its internal model, the Solvency II ratio would have remained above the target level of at least 200% even allowing for major loss events and adverse capital-market effects.

The solvency framework of a reinsurer is not identical to the German corporate-law test of a going-concern threat for an industrial company. Yet the management logic is the same: an attractive opportunity is only the "right" opportunity if the potential downside is understood, quantified, financially absorbable and manageable under adverse scenarios. This is precisely where current practice meets DIIR Revision Standard No. 2.

Successful risk management does not minimise the number of risks. It ensures that the company deliberately takes those risks for which opportunity, compensation and strategic value justify the downside - while preserving sufficient risk-bearing capacity.

Risk has two sides: upside and downside

One of the most important statements in the DIIR standard appears in its definition section. Risk is not merely the possibility of loss. It is defined as the possibility that events or developments affect the achievement of objectives, including positive deviations – opportunities – and negative deviations – threats or risks in the narrower sense (para. 19).

This is a symmetric view of risk. In English-language management terminology, the two sides can be described as upside risk and downside risk. Upside risk means an outcome that is better than expected: a new market grows faster, an acquisition delivers more synergies, or a technology creates more productivity. Downside risk means that the same decision underperforms or produces additional losses, liquidity strain or strategic damage.

The distinction is not semantic. If risk is understood only as danger, the organisation will systematically optimise for caution. Investments become smaller, innovation slower and market entry rarer. That may reduce losses – but it can also reduce enterprise value. If management looks only at opportunity, the company becomes risk-blind. Professional risk management therefore has to model both sides of the same uncertain decision.

This duality is also reflected in the book "Alone on Stormy Seas" (Erben/Romeike 2026). It is no coincidence that the two protagonists are called Captain Sugar and Captain Salt: they symbolize the sweet and the salty side of risk – opportunity and threat. Only by considering both perspectives simultaneously can we understand the full meaning of risk and make balanced decisions under uncertainty.

Why risk management is inherently opportunity management

The DIIR standard draws an important consequence from its symmetric risk concept. Risk management must not be limited to existing risks. Paragraph 20 explicitly includes planned measures and decisions and their potential risks. Paragraph 21 additionally makes clear that enterprise-wide risk management includes risk analysis in corporate decision-making.

This shifts the focus. A traditional risk register asks: What risks do we already have? Decision-oriented risk management additionally asks: What new risks do we want to take, and what do we get in return? That is opportunity management at its core. Most opportunities exist because the company accepts uncertainty: capital is committed, a technology is developed, a market is entered, a product is launched or a competitor is acquired.

Opportunity management should not, however, become a separate optimistic parallel process. Opportunity and risk belong in the same decision paper, the same financial model and the same analysis of total risk. Only then can management distinguish a value-creating option from one that merely appears attractive because the downside has been incompletely represented.

Traditional defensive viewDecision-oriented view
Core questionWhich risks must we avoid or reduce?Which risks should we take, how large should they be and what compensation do we expect?
Risk conceptPredominantly downside/threatUpside and downside as two sides of deviation from objectives
Information baseRisk register, heat map, controlsAlternatives, business case, risk quantification, aggregation, risk-bearing capacity
ObjectiveMinimise risk exposureCreate value at an acceptable level of total risk
Steering logicReduce risksSelect, price, limit, diversify, mitigate or deliberately accept risks
Success criterionFew realised risksAttractive risk-adjusted outcomes without breaching capacity or safety thresholds

Table 01: From risk avoidance to risk selection

The Business Judgement Rule turns decision quality into an audit subject

Version 2.2 of the DIIR standard makes decision orientation particularly visible. The preamble refers to section 93 of the German Stock Corporation Act and the Business Judgement Rule: for entrepreneurial decisions, the governing body is expected to act on the basis of appropriate information. According to the standard, that information should in particular show the opportunities and threats associated with the proposed decision and explain how the company's overall risk exposure would change. The standard therefore dedicates an entire Chapter 7 to decisions under risk.

For Internal Audit, this changes the perspective. The audit is no longer limited to whether risks are inventoried, assessed and reported correctly. It should also assess whether major strategic decisions are prepared in a way that enables the board to make a sound trade-off. This concerns both the management system and individual decision papers.

Chapter 7 requires, among other things, a clear distinction between major entrepreneurial decisions and other decisions, appropriate information gathering, identification of alternatives, a transparent comparison of alternatives and a well-founded decision paper. The effort should be proportionate to the significance, risk content and investment volume of the decision. Crucially, risk management must be able to assess whether the additional risks associated with a decision could critically increase the degree of threat to the company's continued existence (para. 90).

What is the "right" risk?

There is no universal risk category that every company should take. The same risk may be attractive for one company and irresponsible for another. Strategy, capabilities, diversification, financial resources and loss-absorbing capacity all matter. The "right" risk is therefore not simply one with a high expected return. It is a risk whose expected benefit is attractive, whose downside can be understood and managed, and whose assumption does not reduce the company's margin of safety to an inappropriate level.

The Right-Risk Test – a practical synthesis of the DIIR logic

→ Does the decision fit the corporate strategy and the organisation's capabilities?
→ What measurable upside can arise – earnings, cash flow, enterprise value, market position or future growth options?
→ What downside scenarios are realistic, including rare extreme events?
→ How do the new risks change the company's aggregated total risk?
→ How much unused risk-bearing capacity remains after the decision?
→ Does the margin of safety remain adequate under stress?
→ Which alternatives were assessed – including doing nothing, a smaller entry, a partnership or staged investment?
→ Are price, return or strategic benefit commensurate with the risk?
→ Which early-warning indicators, limits and exit options are available?
→ Are the assumed risks transferred into operational risk management after the decision?

Risk strategy: the bridge between ambition and margin of safety

The DIIR standard explicitly requires the risk strategy to be derived from the overall corporate strategy. Under paragraph 49 it includes management's risk appetite, taking the organisation's risk-bearing resources into account, as well as risk-steering objectives and measures. It should be sufficiently concrete to guide operational risk management.

This is central to the idea of the right risks. Corporate strategy says where the company wants to go. Risk strategy says what uncertainty it is willing to accept on the way. A growth-oriented company may deliberately accept more market or innovation risk while maintaining very low tolerance for liquidity, compliance or cyber risk.

The standard therefore calls for risk tolerances or a limit system, a risk-bearing-capacity framework and thresholds that trigger countermeasures. A well-designed risk strategy is not a defensive list of prohibitions. It creates a reliable operating space within which management can seize opportunity quickly without reopening the question of corporate survival every time.
Risk-bearing capacity is not a brake – it is a licence to act

In many companies, risk-bearing capacity is treated primarily as a crisis metric. That is too narrow. From a decision-oriented perspective, unused risk-bearing capacity is a strategic resource. A company with capital, liquidity, credit lines and stable cash generation can invest during a downturn, acquire competitors, gain market share or deliberately assume risks that others cannot carry.

The DIIR standard recommends comparing aggregated total risk with the company's risk-bearing resources. Those resources can be defined both through equity and – often more important for continued payment ability - through liquidity reserves including available and potential additional credit lines. The distinction from simple risk avoidance is fundamental: zero risk is not the objective; an adequate margin of safety is.

The key management measure is therefore not only absolute risk-bearing capacity, but remaining risk-bearing capacity after a decision. A major acquisition may be a deliberate, absorbable risk for a company with high liquidity and stable cash flow; for a highly leveraged company, the same transaction may reduce resilience so much that even moderate economic stress could become existential.

Why risk aggregation determines whether a risk is "right" or "wrong"

No material strategic risk exists in isolation. Expansion may simultaneously create revenue opportunity, start-up losses, foreign-exchange exposure, working-capital requirements, supply-chain risk and additional financing needs. The DIIR standard therefore defines risk aggregation as determining total risk from quantified individual risks while considering combination effects and stochastic dependencies.

For decision orientation, this means that an option is not necessarily acceptable merely because its standalone downside is below a limit. What matters is how it changes the company's overall risk profile. A new business may be valuable even if its standalone risk is material, because it diversifies existing exposures. Conversely, an apparently attractive project may be dangerous if it produces losses in exactly the scenarios in which the core business is also under pressure.

The right question is not: "How risky is this project?" It is: "How does this project change the distribution of our future earnings, cash flows and liquidity, including interactions with the risks we already carry?"

Stress scenarios protect against strategic optimism

Decision papers are naturally vulnerable to optimism. Project teams usually understand expected synergies, market opportunity and strategic benefits very well. Less often are the questions asked with equal discipline that determine risk-bearing capacity: What if market entry is delayed by twelve months? What if prices fall by ten per cent? What if financing costs rise? What if two critical assumptions fail at the same time?

The DIIR standard does not prescribe one universal stress-test format. But its requirements for risk quantification, aggregation, risk-bearing capacity, thresholds and the early detection of developments threatening the company's existence logically lead to robust stress analysis. Without analysing adverse combinations of assumptions, management does not know the true margin of safety.

The Munich Re example illustrates this logic particularly clearly. The company does not only report a high current solvency ratio; it also states that its internal model indicates capitalisation would remain above the target level even after major loss events and adverse capital-market effects. That kind of headroom analysis is what separates calculated risk-taking from risk blindness.

Upside should be modelled as professionally as downside

A symmetric risk concept does not mean that opportunity should appear only as an optimistic paragraph in the business case. Upside should be analysed systematically as well. Which assumptions drive the positive deviation? How likely is it? Which investment or risk is required to realise it? Which capacities limit the ability to exploit the opportunity? Can the upside be scaled if the favourable scenario materialises?

This makes opportunity management measurable. A project with limited downside and large optional growth potential may be more attractive than one with a slightly higher expected value but severe tail risks. Decision quality does not arise from the expected value alone; it depends on the shape of the outcome distribution and its fit with the company's risk-bearing capacity.

What Internal Audit should examine

Chapter 7 of the DIIR standard extends the audit universe towards decision quality. Internal Audit should not decide which strategic project the company ought to choose. It should, however, assess whether the process provides the conditions necessary for the governing body to make a sound risk decision.

  • Is it defined which strategic decisions require enhanced risk analysis?
  • Are upside and downside for each major alternative described consistently and, where possible, quantified?
  • Are effects on total risk, risk-bearing capacity and key limits shown?
  • Do decision papers include stress scenarios, combination effects and tail risks?
  • Are genuine alternatives compared, or merely variations of a preferred solution?
  • Is the decision paper free from inappropriate bias and, where necessary, subject to independent quality assurance?
  • Are thresholds, early-warning indicators and escalation paths defined for the post-decision period?
  • Are newly assumed risks transferred into ongoing risk management and reporting after implementation?

The final point is especially important. Paragraph 93 expressly refers to transferring risks identified in the decision paper into operational risk management. A decision is therefore not complete when the board signs it. Only a closed loop of decision, implementation, monitoring and learning turns a one-off business case into effective risk management.

The most dangerous risk culture is not the bold one – it is the inconsistent one

A sound risk culture rewards neither blanket caution nor blanket boldness. It ensures that risks are discussed openly, assumptions are challenged and good opportunities are not blocked merely by fear of personal accountability. Consistency is the key: a company should know which risks it deliberately seeks for strategic reasons and which it avoids because it lacks the capabilities, compensation or risk-bearing capacity to carry them.

This is also a governance issue. If success is measured only by revenue growth or project approvals, managers have a systematic incentive to understate downside. If every negative deviation is punished, the incentive shifts toward excessive risk aversion. Decision-oriented risk management therefore requires a leadership culture that evaluates risk-adjusted success: Was a reasonable decision made on the basis of appropriate information, and was the remaining margin of safety acceptable?

Conclusion: the best companies do not have the fewest risks

Competitive advantage rarely comes from eliminating uncertainty. It comes from understanding risks better, pricing them more precisely, diversifying them more intelligently and carrying them more effectively than competitors. This makes risk management a core capability of value creation.

The DIIR Revision Standard No. 2 supports this change in perspective. The standard connects its symmetric risk concept with risk strategy, risk aggregation, risk-bearing capacity and the explicit audit of entrepreneurial decisions. What appears to be defensive risk management becomes a system for allocating scarce risk capacity more intelligently. The key management question is no longer: "How can we avoid risk?" It becomes: "Which risks should we take, how large should they be – and how do we ensure that we remain capable of acting even when several things go wrong at the same time?" 

Sources:

  • DIIR – German Institute for Internal Auditing: DIIR Revision Standard No. 2, Audit of the Risk Management System by Internal Audit, Version 2.2, August 2026. Particularly relevant: paras. 19-28, 49-50, 59-76 and 82-95.
  • Erben, Roland F. / Romeike, Frank (2026): Allein auf stürmischer See – Risikomanagement für Einsteiger [Alone on a Stormy Sea – Risk Management for Beginners], 4. komplett überarbeitete Auflage, Wiley Verlag, Weinheim 2026.
[ Source of cover photo: Generated with AI ]
Risk Academy

The seminars of the RiskAcademy® focus on methods and instruments for evolutionary and revolutionary ways in risk management.

More Information
Newsletter

The newsletter RiskNEWS informs about developments in risk management, current book publications as well as events.

Register now
Solution provider

Are you looking for a software solution or a service provider in the field of risk management, GRC, ICS or ISMS?

Find a solution provider
Ihre Daten werden selbstverständlich vertraulich behandelt und nicht an Dritte weitergegeben. Weitere Informationen finden Sie in unseren Datenschutzbestimmungen.