Risk management

Risk appetite: how to set it and why it matters

A loss boundary agreed in advance. Why the wording has to be measurable, who approves it and how to get a working formulation in a single meeting.

Updated: 17 August 2026 · Author: Evgeny Telenkov · ≈ 4 min read

Risk appetite is the amount of loss a company agrees in advance to accept on a given risk over a period without changing its strategy. The key word is amount — a number or a clear boundary, not a statement of intent.

Why the wording has to be measurable

"We accept a moderate level of operational risk" is useless: any decision and any outcome fits under it. Compliance with such an appetite cannot be tested, so it changes nothing.

A working formulation reads differently. Total losses from outages stay below a stated annual figure. Loss of client transaction data is unacceptable under any circumstance. For internal management reporting, up to one day of data loss is acceptable. Recovery targets follow directly from those boundaries — see business impact analysis.

Who approves it and what happens next

The board or the owner approves appetite, because it is a decision about what the company is prepared to risk in pursuit of return. Management executes it but does not set it for itself.

Appetite is then cascaded into limits for units. If breaching a limit obliges nobody to do anything, the company has no appetite — it has a document.

How to set it in one meeting

FAQ

How is appetite different from risk tolerance? Appetite is the level of risk a company deliberately accepts. Tolerance is the maximum deviation from it before action is required. Appetite sets the course, tolerance sets the width of the corridor.

Can we manage without numbers? For prohibitions, yes — "unacceptable" works. Everywhere else a number is needed, otherwise compliance cannot be tested.

How often should it be revisited? Annually with the strategy, and out of cycle after a major incident, a market shift or new regulatory requirements.

Section 03 · Risk management Risk management system → · All guides in this section