Defining a Risk Management Policy: A Beginner’s Guide for Funds

By Mike North Jul 9, 2026

Somewhere in the last few weeks, an LP asked you for your risk management policy. You said you’d send it across. You do not have one.

That’s the usual way this starts, and if it’s how you got here you’re in reasonable company. Most funds below a few hundred million don’t have a written risk policy until somebody outside the firm asks for it.

The request nearly always turns up during operational due diligence, and it’s usually not personal. Institutional allocators ask this of everyone, and questionnaires modelled on ILPA’s due diligence framework have been steadily expanding what they expect a fund to be able to show.

So. What you need to produce is shorter and less frightening than you’re imagining. The template you’ll find by searching, on the other hand, is going to actively mislead you, and that’s the more annoying problem. It’s most of the reason this guide exists.

What a risk policy actually is

Strip out the framework language and the document answers four questions.

What could go wrong here. Which of those things we’re willing to live with. Who decides, and who acts. And what happens when one of them actually happens.

That’s it. Eight to fifteen pages in most cases. If yours is heading past thirty, you’ve probably confused it with something else.

Three things it isn’t, since the confusion comes up a lot.

It isn’t a risk register. The register is a living list of specific exposures with owners and statuses attached. The policy is the set of rules governing how that register works. You’ll want both eventually, and you want the policy first.

It isn’t a compliance manual. Compliance concerns rules imposed on you from outside. Risk management concerns exposures you’ve chosen to take on. Different problem, different shape.

And it isn’t a document written to impress anyone. I’d underline that if I could. The best risk policies I’ve read are dull, specific and slightly awkward in places, because somebody was trying to describe what the firm would actually do rather than what would sound defensible in a meeting.

Why you’re writing it, which matters more than it sounds

Worth pausing on the trigger, because it shapes what ends up in the document.

Four ways funds tend to arrive here. An LP asked during ODD, which is far and away the most common. A bank or fund administrator wants to see one before proceeding. A regulator, if you happen to sit inside a perimeter — most VC and crypto funds don’t, and I’ll come back to that. Or something went wrong, and now there’s a policy.

That last one is the worst reason and, unfortunately, not a rare one. Policies written in the aftermath of an incident are almost always over-fitted to the thing that just happened and blind to the thing that hasn’t. If you’re writing this after a bad quarter, the useful discipline is to spend deliberately more time on the risks that didn’t materialise than on the one that did.

The problem with every template you’ll find

Here’s the part that will save you a fortnight.

Search for a risk management policy template and you’ll turn up a great many of them. ISO 31000. COSO. Whatever your preferred GRC vendor is giving away this month. In fairness they’re decent documents, and the people who wrote them knew what they were doing.

They also all rest on the same assumption, and the assumption doesn’t hold for you.

They assume your risk lives inside your own organisation.

Which is entirely sensible, because they were written for corporations. A manufacturer’s risk is its supply chain, its plant, its staff, its data. Things it owns and directs. The frameworks slice that into operational, financial, strategic, compliance and reputational, and for a company with three thousand employees that’s a perfectly reasonable carve-up.

Now look at your firm.

Say you’re eleven people. You’ve deployed two hundred million across thirty-eight portfolio companies. Your internal operational risk is real but modest — a small team, a few systems, some wire transfers, a handful of conflicts to manage.

Your actual exposure is sitting inside thirty-eight companies you don’t control, can’t direct, and in most cases can’t see into without asking someone.

Fill in a standard template and you will produce a careful, well-structured document describing maybe fifteen percent of your risk. And it will look complete, which is the dangerous bit.

Inside the firmOutside the firm
ExamplesCyber. Key person. Valuation error. Wire fraud. Staff conduct. Conflicts.Portfolio company failure. Founder misconduct. Sanctions exposure. Counterparty collapse. Impersonation. Regulatory reclassification.
Who controls itYou do.You don’t.
Typical policy coverageThorough.Almost none.
Share of real exposureSmall.Most of it.

Writing the internal half

Right. The unglamorous part, and you do have to do it. This section is what an LP will read most carefully, so it earns the effort.

Key person. What happens if a GP leaves, dies, or is removed. Allocators ask about this constantly and almost nobody has written it down. Two paragraphs will do: who steps in, what constitutes a key person event under the LPA, and what the fund does in the interim.

Wire fraud and payment controls. This gets considerably more space than the rest, because by some distance it is the most likely way a fund your size actually loses money.

The attack is boring and it works. Someone compromises or spoofs an email account — a founder’s, a lawyer’s, occasionally yours — and sends revised wire instructions for a transfer that was already expected. The instructions look right. The context is correct. The timing is plausible, because the attacker has been reading the thread. The money leaves, and it leaves quickly.

Business email compromise sits consistently among the largest categories of reported loss in the FBI’s annual internet crime figures, and the typical victim isn’t a bank. It’s an organisation roughly your size, with roughly your controls, on a Friday afternoon.

Your policy needs three things here and they cost nothing. Dual authorisation above a threshold you pick. Out-of-band verification for any change to wire instructions, meaning you ring a number you already had rather than the one in the email. And a written rule that urgency is never grounds for skipping either.

That third one matters more than the other two, because urgency is the entire attack.

Cyber and data. Proportionate to your size. An eleven-person fund does not need a bank’s information security policy, and writing one produces a document nobody follows. MFA everywhere, endpoint protection, a password manager, and a stated position on where fund data lives and who can reach it.

Valuation. Who marks positions, on what basis, and who reviews the marks. If you’re early-stage and holding at last round, say so plainly rather than dressing it up.

Conflicts of interest. Personal investments, board seats, allocation between the fund and any co-investment vehicle. Tedious to write, and the section an LP will go through line by line.

Material non-public information. If your team sits on boards, they see things. Say what happens to that information.

Writing the external half, which the templates skip entirely

Now the section that describes most of your actual risk and appears in none of the standard documents.

For each category of external exposure, the policy needs to state four things. What we watch. How often. Who acts. And what triggers an escalation.

Let me be blunt about the second one, because it’s where most of these documents fall over.

Almost every fund risk policy I’ve read contains a phrase like “ongoing monitoring of portfolio companies.” What it means in practice is “we’ll look into it if something comes up.” Everyone in the room knows this. Nobody says it out loud.

If your policy commits you to quarterly review, you have committed to an average detection delay of around forty-five days and a worst case of ninety. A sanctions designation landing in week two of a quarter sits unread for eleven weeks.

That might be a perfectly acceptable risk for your strategy and your portfolio. But it should be a decision rather than an accident. Write the number down. A policy that says “ongoing” and means “occasionally” reads beautifully right up until somebody asks you to demonstrate it.

The categories worth covering, at minimum:

Sanctions and watchlists. Designations hitting portfolio companies, their officers, their counterparties or their jurisdictions. OFAC and its equivalents publish on a rolling basis, not on yours.

Adverse media. Litigation, regulatory action, investigative reporting. Worth remembering that a decent share of what matters here surfaces first in regional press, in languages your team doesn’t read.

Corporate registry changes. Redomiciliation, director changes, share transfers, new subsidiaries. In crypto this is routine rather than exceptional, and a company can look materially different eight months after you wired.

Founder and officer background. New litigation, undisclosed roles, prior ventures resurfacing in ways that reach you.

Counterparty exposure. The exchange, custodian or banking partner your portfolio company depends on. Their failure becomes your problem, and you’ll usually hear about it late.

Impersonation and brand attacks. Fake Telegram channels, cloned social accounts, spoofed support desks. Entirely post-close, invisible to any onboarding process by definition, and common enough now that it belongs in the policy rather than on somebody’s mental list of things to worry about.

We’ve written at length about why this whole half of the risk picture is structurally invisible to onboarding diligence, if you want the long version.

Risk appetite, in language a human can use

This is the concept most beginner guides turn into fog. Let me try to keep it out of the fog.

Risk appetite is just: what would we actually do?

Would we invest in a company whose founder has a prior regulatory action against them? On what conditions, and who signs it off?

Would we hold a position in a company whose primary counterparty gets sanctioned? For how long? What’s the trigger to exit?

How much concentration in a single jurisdiction starts to feel uncomfortable?

Write the answers before you’re in the situation. That’s the entire reason the section exists, and I don’t think most guides say it plainly enough: the answer you’ll give under pressure, with capital already committed and a founder on the phone, is not the answer you’d give calmly on a Tuesday with nothing at stake.

You’re writing this document to constrain your future self, who will be more optimistic than you are now, and considerably more tired.

Escalation and response

Keep this short and specific.

Severity tiers, whatever you want to call them. A named role attached to each rather than “the team.” A response window for each. And a clear statement of what constitutes an escalation to the IC or the partners.

An alert addressed to a group is an alert addressed to nobody, which we’ve written about elsewhere in more detail than anyone strictly needs.

Give the policy its own review date

Annually is the floor. Also after any material incident, and after any material change to strategy or exposure.

There’s a real hazard here worth naming. A risk policy written once and never revisited is arguably worse than no policy at all, because it creates a documented impression of a control that isn’t running.

If an LP or an examiner later asks how you monitor portfolio companies, and your policy says quarterly, and the last review you ran was fourteen months ago, you’re now explaining the gap between your stated process and your actual one. That is a considerably worse conversation than never having written the policy.

So don’t commit to things you don’t intend to do. Write the commitments you’ll actually keep, even if they read as less impressive.

What it looks like when it’s finished

Twelve pages, give or take. Specific. Dull. Nobody will enjoy reading it, and that’s fine.

The test I’d apply: could somebody who joined the firm on Monday open this document and know what to do when a sanctions alert fires on a portfolio company on Thursday?

If yes, it works.

If the honest answer is “they’d go and ask someone,” then what you have is a document about having a policy.

One last thing

Most of writing a risk policy is unglamorous work that no vendor can do for you, and I’d be a little suspicious of anyone claiming otherwise. The internal sections are yours. The appetite statements are yours. The judgment is entirely yours.

But there’s one line in the whole document that determines whether the external half is real or decorative, and it’s the frequency commitment. If the only thing you can honestly write is “quarterly,” then the policy is describing a portfolio you look at four times a year.

That’s the line we exist to let you write differently. Beady AI monitors portfolio companies, founders and counterparties continuously — sanctions, adverse media, corporate registries, impersonation — with every signal traced back to the source it came from. Book a session and we’ll run it against your real holdings, which also happens to be an efficient way of finding out whether the policy you’re about to write is one you can actually keep.

Mike North
Ceo and Cofounder of Company Name

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Mauris tincidunt vulputate efficitur. Pellentesque nec massa sed ante pharetra elementum. Phasellus ac ante vitae quam ultricies tincidunt ac vel odio.

Lorem ipsum dolor sit amet

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Lorem ipsum dolor sit amet

    Lorem ipsum dolor sit amet, consectetur adipiscing elit.

    Ready to get started?

    Helping you go live in days, not weeks.