FX risk limits are the boundaries a firm sets on currency loss, exposure and concentration, and the rule that makes them work is simple: calibrate to stressed outcomes, not just to quiet historic volatility. That means backing limits with Value at Risk, backtesting, and stress tests, then watching exposure intraday so breaches get caught before they become losses.
TL;DR:
- Limits should be calibrated to stressed market scenarios, with regular backtesting and stress testing to ensure they remain effective during volatility spikes.
- Combining multiple risk metrics such as Value at Risk, potential future exposure, and position limits provides a comprehensive view; relying on only one can leave firms vulnerable.
- Monitoring systems must include intraday exposure dashboards and automated alerts to detect breaches early and prevent losses in fast-moving markets.
- Limits require clear governance, fixed review cycles, and documentation connecting them to internal capital processes, with escalation procedures for breaches.
- Automated platforms like CorpHedge facilitate real-time tracking, VaR analysis, and breach alerts, helping firms avoid time-consuming manual processes and stale limit calibrations.
Table of Contents
- What FX risk limits do and why they matter for trading desks
- Common limit metrics and how to choose them
- Calibrating limits: backtesting, stress testing and roll-over risk
- Monitoring, reporting and breach remediation
- Governance: risk appetite, review frequency and documentation
- How practitioner tools implement limits in practice
- Practitioner perspective: three mistakes that keep recurring
- CorpHedge as an option for limit-setting and monitoring
- Key primary sources for formalizing FX limits
- Sources
- FAQ
What FX risk limits do and why they matter for trading desks
Limits come in several forms, and each protects a different part of the business. Loss limits cap how much a desk can lose before a position must be cut, exposure limits cap the size of open currency positions, position limits cap how much a single trader or book can hold, and concentration limits stop too much risk from piling into one currency pair, tenor or counterparty. Stop rules add a hard floor beneath all of them.
Together these controls protect capital, liquidity and counterparty exposure when markets move fast. Regulators treat this as a governance question, not just a trading one: the Prudential Regulation Authority's expectations for FX position capitalization and the European Banking Authority's.pdf) guidance on FX lending both push firms to build limits into their internal capital and risk review processes, not treat them as a trading desk afterthought. For a fuller breakdown of how these thresholds get established, see this overview of corporate FX risk limits.

Common limit metrics and how to choose them
No single metric captures FX risk on its own, so most desks and corporate treasuries run several in parallel.
- Value at Risk (VaR) estimates the maximum expected loss over a set horizon at a chosen confidence level, and it needs regular backtesting against realized P&L to stay credible; a step-by-step backtesting primer is a useful reference for validating the model before relying on it.
- Potential future exposure (PFE) and gross notional or gross market value measures matter most for counterparty credit limits, since they capture how much exposure could grow before a trade settles.
- Net open position limits and per-desk position limits control how much directional currency risk a market-making or proprietary book can carry at any moment.
- Daily P&L limits and per-trade loss limits work best on execution desks, where the goal is catching a bad trade or a bad day quickly rather than modeling tail risk.
Each metric has a blind spot. VaR assumes a return distribution that can break down in a real crisis, PFE can understate risk when currency and credit risk move together, and position limits alone say nothing about how expensive it might be to actually exit a position during a liquidity squeeze. Firms that rely on one number tend to get surprised by the one risk that metric was never built to catch. The BIS guidelines on counterparty credit risk management make the case directly: limit frameworks should combine PFE, gross notional and gross market value with stress-calibrated measures rather than leaning on any single figure.
Calibrating limits: backtesting, stress testing and roll-over risk
Turning a metric into a working limit takes a few concrete steps.
- Backtest VaR against actual outcomes over a meaningful sample period, comparing predicted losses to realized ones at your chosen confidence level and horizon, then adjust the model when breaches cluster beyond what the confidence level implies.
- Design stress scenarios that go beyond recent history, sizing them to firm complexity: a smaller corporate treasury can rely on targeted sensitivity checks, while a large trading operation needs institution-wide, granular stress frameworks, as the Bank of England's stress-testing guidelines recommend.
- Quantify roll-over risk on short-dated hedges. Riksbank research on hedging maturity choice shows that replacing a rolled FX swap during market stress can cost far more than historic averages suggest, so limits should include replacement-cost scenarios at more than one severity level.
- Set concentration thresholds by currency, tenor and counterparty, with materiality triggers that force a review once exposure to any single pair or counterparty crosses a defined share of the book.
Pro Tip: Run your stress scenarios against the same roll dates your hedges actually use, not generic quarter-end dates, since replacement cost spikes tend to cluster around real market stress events rather than calendar convenience.
For readers who want the underlying model mechanics, this FX VaR modeling and backtesting guide walks through the calculation in more detail.
Monitoring, reporting and breach remediation
A limit is only as good as the monitoring behind it. Daily reporting catches yesterday's problem; intraday exposure dashboards catch today's.
- Set graduated thresholds, with soft alerts firing well before a hard limit breach so a desk head can act before the position becomes a compliance issue.
- Build an escalation flow that names who gets notified, how fast, and what the immediate response looks like, whether that is cutting a position, adding a hedge or triggering a collateral call.
- Automate early-warning indicators tied to live market feeds so a currency's volatility spike or a widening swap spread triggers a review without waiting for the next reporting cycle.
The BIS guidance on counterparty credit risk notes that intraday PFE or exposure calculations meaningfully cut detection lag for large, fast-moving positions, and firms with material FX activity should build toward that capability where it is technically feasible.
Pro Tip: Treat a soft-alert breach as a data point, not noise. A pattern of near-misses on the same currency pair usually means the limit was set too loose, not that the desk got unlucky twice.
A practical checklist for building this monitoring layer is covered in proven steps for managing currency risk.
Governance: risk appetite, review frequency and documentation
Limits need an owner. A risk committee or chief risk officer typically sets overall risk appetite and approves the top-level limit structure, while desk heads set and manage operational sub-limits within that envelope. Nobody below that level should have authority to widen a hard limit on their own.
Review frequency should be periodic, at minimum annually, but also event-driven: a currency's sudden devaluation, a new hedging product, or a material shift in the firm's FX exposure should trigger an off-cycle recalibration. Auditors and regulators expect documented rationale for how each limit was calibrated, how it links to internal capital processes such as ICAAP, and a clear record of every breach and remediation step. Without that paper trail, a well-designed limit framework is hard to defend under supervisory review.
How practitioner tools implement limits in practice
A platform like CorpHedge illustrates how policy limits translate into daily operations. Real-time position tracking feeds a live exposure dashboard, VaR calculations run against current positions rather than end-of-day snapshots, and stress-scenario simulation lets a treasury team test how a given limit structure would hold up under a currency shock before it happens. Alerts and workflow tools flag threshold breaches and route them to the right approver automatically.

Integrations with bank feeds, market data providers and platforms like Corpay close the manual gaps that usually cause reporting lag between a trade happening and a limit breach getting noticed. None of this replaces governance, though: a platform can enforce and monitor the limits a risk committee sets, but the risk appetite, approval authority and escalation ownership still sit with people, not software.
Practitioner perspective: three mistakes that keep recurring
Most limit failures trace back to the same three habits: calibrating against calm markets instead of stressed ones, ignoring the replacement cost of rolling short-dated hedges, and escalating breaches too slowly because nobody automated the early warning.
— Bartas
CorpHedge as an option for limit-setting and monitoring
Building this framework from scratch, with spreadsheets and manual bank reconciliations, is where most treasury teams lose time and where limits quietly go stale. CorpHedge's platform brings real-time exposure tracking, VaR-based hedging analysis and automated alerts into one view, so a limit breach shows up the moment it happens rather than at month-end close.

CorpHedge offers real-time exposure and VaR tools to finance teams in various markets. If your current limit structure exists mostly in a spreadsheet, check the hedging based on Value at Risk page or explore the FX hedging course to build the calibration skills behind it.
Key primary sources for formalizing FX limits
Start with the BIS guidance on liquidity stress testing, which treats FX funding as a distinct stress category, and the Bank of England's stress-testing framework for proportionality guidance across firm sizes.
Sources
- Guidelines on counterparty credit risk management (BIS)
- Hedging against exchange rate risk — maturity choice and roll-over risk (Riksbank)
- Guidelines of institutions' stress testing (Bank of England)
FAQ
Is risking 2% per trade too much?
There is no universal answer since it depends on account size, stop placement and how correlated your open positions are.
What is the 3-5-7 rule in trading?
It is not a regulatory standard, and institutional desks generally rely on VaR and exposure limits instead.
What is the 2% rule in forex?
It is a common retail heuristic rather than a fixed regulatory requirement, and firms with formal risk frameworks typically size limits against VaR and stress outcomes instead.
What is the 90% rule in forex?
Leveraged retail products carry standardized risk warnings and margin close-out protections under measures like those adopted by ESMA, reflecting how much capital retail traders can lose on these products.
How often should FX risk limits be reviewed?
Limits should be reviewed on a set periodic schedule, at least annually, alongside event-driven recalibration whenever market conditions or exposure profiles shift materially. The Bank of England's stress-testing guidance recommends that stress-test outputs directly inform when and how limits get adjusted.
