In most organizations without professional risk managers, the amount of risk individuals are allowed to take is set informally and evaluated by tradition. This can work reasonably well if the right mix of aggressive risk-takers and cautious risk-avoiders are present, and if the traditional rules encourage optimal organizational behavior and evolution.