Short answer
These risk appetite statement examples show how a board states the amount and type of risk it will accept to meet its objectives. A good statement names the risk category, gives an appetite level such as averse, cautious or open, and adds measurable tolerances, for example no more than two high-severity audit findings open beyond 90 days.
Key takeaways
- Appetite is the overall level of risk accepted; tolerance is the measurable limit around it.
- Write one statement per risk category, not one for the whole organisation.
- Each statement needs at least one metric someone can report against.
- In ISO 31000 terms, appetite feeds the risk criteria set in clause 6.3.4.
Appetite, tolerance and criteria
COSO's 2017 ERM framework describes risk appetite as the types and amount of risk, on a broad level, an organisation is willing to accept in pursuit of value. Tolerance is the acceptable variation around a specific objective, expressed as a number. ISO 31000:2018 does not lean on the term appetite; it asks organisations to set risk criteria (clause 6.3.4) that reflect the amount and type of risk they may or may not take. An appetite statement is the board-level source of those criteria.
The UK government's Orange Book and its Risk Appetite Guidance Note use a five-level scale that many organisations borrow: averse, minimal, cautious, open and eager.
Examples by risk category
| Category | Appetite | Statement | Tolerance metrics |
|---|---|---|---|
| Cybersecurity | Averse | We do not accept risks that could lead to a material breach of customer data. | Critical vulnerabilities patched within 14 days; zero unencrypted customer data stores |
| Regulatory compliance | Minimal | We comply with all applicable laws and accept no known, unremediated breach of regulation. | No high-severity audit finding open beyond 90 days; regulator notifications on time 100% |
| Third parties | Cautious | We use suppliers to scale, provided critical suppliers meet our security and continuity standards. | 100% of critical suppliers assessed yearly; exit plans for every critical supplier |
| Operational resilience | Cautious | We accept short disruption to non-critical services but not to payments or customer access. | Critical services restored within 4 hours; two tested failovers per year |
| Innovation and product | Open | We accept higher delivery risk to launch new products, within our compliance limits. | New products pass security review before launch; pilot losses within budget |
| Financial | Cautious | We protect liquidity and accept moderate risk to grow revenue. | Cash runway above 18 months; no single customer above 15% of revenue |
These are examples to adapt. Your levels and numbers should come from your own objectives, regulators and board discussion.
How to write your own
Checklist
Risk appetite statement checklist
0 of 7 done
Put this into practice on QULDEX
Frequently asked questions
What is the difference between risk appetite and risk tolerance?
Risk appetite is the broad amount and type of risk an organisation accepts to meet its objectives. Risk tolerance is the measurable limit around a specific objective, such as a maximum number of days a critical vulnerability may stay open.
Does ISO 31000 require a risk appetite statement?
Not by name. ISO 31000:2018 asks for risk criteria that reflect the amount and type of risk the organisation may take (clause 6.3.4). A board-approved appetite statement is the usual way to set them.
Who approves the risk appetite statement?
The board or its risk committee, usually on a proposal from the chief risk officer or equivalent, and it should be reviewed at least once a year.