Governance · Enterprise risk · Component

Risk appetite statement

How much risk the organisation is prepared to carry in each category, with the tolerances that trigger escalation to the board.

The deliverable

What it is

Risk appetite is a decision by the owners and the board, not a finding by a risk function. It says, for each kind of risk, whether the organisation seeks it, accepts it within limits or tries to avoid it, and it turns the owners’ mandate into something the risk register can be compared with.

A statement written only in words is hard to apply. The workable ones pair each category with at least one tolerance that can be measured, so the question of whether the organisation is inside its appetite has an answer.

One level in

What it is made of

Each element is a constituent part of the component. Follow one to see the attributes it carries.

  1. Risk categories

    The kinds of risk the organisation distinguishes — strategic, financial, operational, compliance, security and others.

    2 attributes: Category · Category owner

    Learn
  2. Appetite levels

    For each category, whether the organisation seeks the risk, accepts it within limits, or aims to avoid it.

    2 attributes: Appetite · Rationale

    Learn
  3. Tolerances

    Measurable limits for each category, and what happens when a limit is approached or crossed.

    3 attributes: Indicator · Limit · Escalation

    Learn

An appetite with no measurable tolerance cannot be breached, and therefore cannot be enforced either.