Last updated: 6 October 2026
Quick answer: A risk appetite statement is a board-approved document that sets out how much and what types of risk an organisation is willing to accept in pursuit of its objectives. A good one names each risk category, gives a qualitative appetite level and translates it into measurable tolerances, limits and escalation triggers that managers can act on.
Most organisations say they manage risk. Far fewer can show where the line is between acceptable and unacceptable risk, and who decided it. That is the job of a risk appetite statement.
Written well, it turns vague board intent into rules that shape budgets, projects, supplier choices and security priorities. Written badly, it becomes a page of generic phrases that nobody reads after approval.
This guide explains the key terms, what regulators and frameworks expect in the EU, UK and US, and a step-by-step method with a template and worked examples for cyber and privacy risk.
What is a risk appetite statement?
It is the written articulation of the amount and types of risk an organisation is prepared to accept, approved by the board and used to guide decisions.
COSO’s 2017 enterprise risk management framework describes risk appetite as the types and amount of risk, on a broad level, that an organisation is willing to accept in pursuit of value. The Financial Stability Board’s Principles for an Effective Risk Appetite Framework (November 2013) place the statement inside a wider framework that also covers risk capacity, risk limits and risk profile.
A statement typically contains:
- An overall appetite position linked to strategy.
- Appetite levels for each principal risk category.
- Quantitative metrics, tolerances and limits.
- Roles, escalation routes and review frequency.
How do risk appetite, tolerance and capacity differ?
Appetite is what you are willing to accept; tolerance is the acceptable variation around it, expressed as measurable thresholds; capacity is the maximum you could absorb before failing.
| Term | Meaning | Example (cyber) |
|---|---|---|
| Risk capacity | The most risk the organisation can bear before breaching regulatory, financial or operational limits | An outage long enough to trigger licence action or lose key customers |
| Risk appetite | The amount and type of risk the board is willing to pursue or retain | Low appetite for loss of customer data |
| Risk tolerance | The acceptable deviation from appetite, set as measurable thresholds | No more than a set number of critical vulnerabilities open past their patch deadline |
| Risk limit | A hard boundary assigned to a business unit, process or metric | No production system without multi-factor authentication for administrators |
The relationship matters because regulators link them. For example, DORA Article 6(8)(b) requires financial entities’ digital operational resilience strategy to establish the risk tolerance level for ICT risk “in accordance with the risk appetite of the financial entity”.
What do regulators and frameworks expect?
Expectations vary by market and sector, but the common theme is that the board owns risk appetite and that it must drive real decisions.
| Region | Key source | What it expects |
|---|---|---|
| EU | DORA (Regulation (EU) 2022/2554) | Financial entities set ICT risk tolerance in line with their risk appetite, within the ICT risk management framework |
| UK | UK Corporate Governance Code 2024 | Principle O: the board determines the nature and extent of the principal risks it is willing to take to achieve long-term strategic objectives |
| US | NIST Cybersecurity Framework 2.0 | GV.RM-02: risk appetite and risk tolerance statements are established, communicated and maintained |
| Global (financial) | FSB principles (2013) | A risk appetite framework with statement, limits, and clear roles for the board, CEO, CRO and CFO |
In the UK, the 2024 UK Corporate Governance Code has applied since 1 January 2025, and its Provision 29 on the effectiveness of material controls has applied since 1 January 2026. Provision 28 asks boards to carry out a robust assessment of emerging and principal risks and describe them in the annual report. A clear risk appetite statement makes both far easier to evidence.
In the US, NIST CSF 2.0, published in February 2024, places risk appetite in its new Govern function. Its GV.RM category covers priorities, constraints, risk tolerance and appetite statements used to support operational risk decisions. Our NIST Cybersecurity Framework page explains how the Govern function fits with the rest of the framework.
How do you write a risk appetite statement step by step?
Start from strategy, agree a small set of risk categories, set a qualitative level for each, then turn every level into metrics with owners and triggers.
1. Anchor it to strategy
List the three to five strategic objectives for the next period. Appetite only makes sense relative to what you are trying to achieve. A company expanding into new markets needs a different stance on regulatory and supplier risk than one consolidating.
2. Choose risk categories
Use the same categories as your risk register so the statement connects to day-to-day risk management. Common ones are strategic, financial, operational, cyber and information security, data protection and privacy, third-party, legal and regulatory, and reputational.
3. Set a qualitative appetite level
Use a simple scale that the board understands. A five-level scale works for most organisations:
| Level | Description |
|---|---|
| Averse | Avoid the risk wherever possible, even at significant cost |
| Minimal | Accept only very low levels of risk with strong controls |
| Cautious | Prefer safe options; accept some residual risk with clear controls |
| Balanced | Accept moderate risk where benefits are clear and managed |
| Open | Willing to take higher risk for strategic reward, with oversight |
4. Translate levels into metrics
For each category, define key risk indicators with a green, amber and red threshold. Amber means “within tolerance but approaching the limit”; red means “outside appetite, escalate”. Guidance such as NIST IR 8286 on integrating cybersecurity with enterprise risk management is useful for linking technical measures to enterprise-level appetite.
5. Assign owners and escalation
Every metric needs an owner, a reporting frequency and a named escalation route. Decide what happens when a threshold is breached: who is told, how quickly, and who can approve a temporary exception.
6. Approve, communicate and review
The board approves the statement, management communicates it in plain language, and the statement is reviewed at least annually or when strategy or the risk environment changes.
Common mistake: writing appetite for “risk” in general. A single statement such as “we have a low appetite for risk” is not usable. Appetite almost always differs by category: you might be open to innovation risk and averse to regulatory breaches at the same time.
What does a risk appetite statement template look like?
A usable template has one row per risk category with the appetite level, a short statement, measurable tolerances and an owner.
| Category | Appetite level | Statement | Tolerance metrics (illustrative) | Owner |
|---|---|---|---|---|
| Cyber and information security | Minimal | We will not accept risks that could lead to material compromise of systems or customer data. | Critical patches applied within the agreed window; MFA on all admin and remote access; tested restore of critical systems each quarter | CISO |
| Data protection and privacy | Averse | We will not knowingly process personal data unlawfully or without appropriate safeguards. | All high-risk processing covered by a DPIA; data subject requests closed within the legal deadline; breaches assessed for notification within 72 hours | DPO |
| Third-party risk | Cautious | We will use suppliers that meet our security and privacy requirements, with proportionate assurance. | All critical suppliers assessed before contract and at least annually; no critical supplier with overdue high-risk findings | Head of Procurement |
| Regulatory compliance | Averse | We will not accept known non-compliance with laws that apply to us. | No open regulatory findings past agreed remediation date | Head of Compliance |
| Innovation and new products | Open | We will pursue new products and technologies where risks are identified and managed. | New AI or data projects pass a risk review before launch | COO |
Adjust the metrics to your context. The numbers above are illustrative, not benchmarks.
If you want to link each metric directly to live risks, controls and incidents instead of a static document, you can start your 14-day free trial and see how risks, controls and incidents connect in one place.
How do you embed risk appetite in daily decisions?
Connect the statement to the tools people already use: the risk register, project approvals, supplier onboarding and board reporting.
- Risk register: score each risk against the appetite level for its category, so residual risks above appetite are flagged automatically. An enterprise risk management module makes this visible.
- Policies: reflect appetite in policies, for example patch timelines or supplier assurance requirements, and keep them aligned through policy management.
- Suppliers: set assessment depth by appetite. Our post on why vendor risk is now an executive liability covers the supplier side in more depth.
- Financial entities: if DORA applies, link the ICT risk tolerance directly to the statement. See our DORA framework page for the wider requirements.
In practice: report appetite breaches, not just risk scores. A board pack that shows “three metrics in amber, one in red, here is the plan” drives better discussion than a heat map with 60 dots.
Key takeaways
- A risk appetite statement sets how much and what types of risk the board will accept, by category.
- Appetite, tolerance, capacity and limits are different; regulators such as DORA expect tolerance to follow appetite.
- The UK Corporate Governance Code, NIST CSF 2.0 and FSB principles all make the board responsible for defining risk appetite.
- Translate every qualitative level into measurable metrics with owners and escalation triggers.
- Review at least annually and embed the statement in the risk register, policies and supplier decisions.
Frequently asked questions
Who approves the risk appetite statement?
The board, or an equivalent governing body, approves it. Management usually drafts the statement, often led by the chief risk officer or risk function, with input from heads of security, privacy, finance and operations. Frameworks such as the UK Corporate Governance Code and the FSB principles place ultimate responsibility for risk appetite with the board.
How often should a risk appetite statement be reviewed?
Review it at least once a year, and sooner when strategy, regulation or the threat environment changes significantly. Metrics and thresholds may need more frequent tuning than the headline appetite levels. Record each review and approval, because auditors and regulators often ask for evidence that the statement is current and actively used.
What is the difference between risk appetite and risk tolerance?
Risk appetite is the broad level and type of risk the organisation is willing to accept. Risk tolerance is the acceptable variation around that appetite, expressed as measurable thresholds. For example, a minimal appetite for cyber risk could translate into a tolerance of no critical vulnerabilities open beyond the agreed patching window.
Do small organisations need a risk appetite statement?
They benefit from one, even if no law requires it. A one-page statement covering five or six risk categories helps owners make consistent decisions on security spending, suppliers and new projects. It also answers common questions from customers, insurers and auditors about how the organisation decides which risks to accept.
How does a risk appetite statement relate to ISO 27001?
ISO 27001 requires an organisation to define criteria for accepting information security risks and to have risk owners approve residual risks. A risk appetite statement provides the board-level basis for those acceptance criteria, so the ISMS risk assessment and the enterprise view of risk stay consistent.
Making risk appetite usable
A risk appetite statement earns its place only when it changes decisions. Keep it short, set appetite by category, attach real metrics and owners, and connect it to the systems where risks, controls and suppliers are managed. Enactia’s AI-powered GRC platform keeps risks, controls and vendors connected across frameworks.
To talk through your risk appetite framework, contact us or book a demo or start your 14-day free trial.
