Governance · Enterprise risk · Component
Risk appetite statement
How much risk the organisation is prepared to carry in each category, with the tolerances that trigger escalation to the board.
The deliverable
What it is
Risk appetite is a decision by the owners and the board, not a finding by a risk function. It says, for each kind of risk, whether the organisation seeks it, accepts it within limits or tries to avoid it, and it turns the owners’ mandate into something the risk register can be compared with.
A statement written only in words is hard to apply. The workable ones pair each category with at least one tolerance that can be measured, so the question of whether the organisation is inside its appetite has an answer.
One level in
What it is made of
Each element is a constituent part of the component. Follow one to see the attributes it carries.
Risk categories
The kinds of risk the organisation distinguishes — strategic, financial, operational, compliance, security and others.
2 attributes: Category · Category owner
LearnAppetite levels
For each category, whether the organisation seeks the risk, accepts it within limits, or aims to avoid it.
2 attributes: Appetite · Rationale
LearnTolerances
Measurable limits for each category, and what happens when a limit is approached or crossed.
3 attributes: Indicator · Limit · Escalation
Learn
An appetite with no measurable tolerance cannot be breached, and therefore cannot be enforced either.
The other components in enterprise risk
Enterprise risk register
The principal risks across the whole organisation, drawn from every function, assessed on one scale and each with a named owner.
LearnAssurance map
For each principal risk, who manages it, who oversees it and who checks it independently — and when each last did so.
Learn