Risk appetite is the amount of loss a company agrees in advance to accept on a given risk over a period without changing its strategy. The key word is amount — a number or a clear boundary, not a statement of intent.
Why the wording has to be measurable
"We accept a moderate level of operational risk" is useless: any decision and any outcome fits under it. Compliance with such an appetite cannot be tested, so it changes nothing.
A working formulation reads differently. Total losses from outages stay below a stated annual figure. Loss of client transaction data is unacceptable under any circumstance. For internal management reporting, up to one day of data loss is acceptable. Recovery targets follow directly from those boundaries — see business impact analysis.
Who approves it and what happens next
The board or the owner approves appetite, because it is a decision about what the company is prepared to risk in pursuit of return. Management executes it but does not set it for itself.
Appetite is then cascaded into limits for units. If breaching a limit obliges nobody to do anything, the company has no appetite — it has a document.
How to set it in one meeting
- Take three to five risk types, not the whole register. Usually disruption of operations, data loss, loss of a key supplier, sanctions exposure.
- Give each a number or a prohibition. An annual figure, or an unqualified "unacceptable".
- Test it against history. Take your largest incident of the past three years and check whether it fits inside the stated boundary.
- Name the escalation addressee. Who learns that the boundary is close and what they must do — see three lines of defence.
FAQ
How is appetite different from risk tolerance? Appetite is the level of risk a company deliberately accepts. Tolerance is the maximum deviation from it before action is required. Appetite sets the course, tolerance sets the width of the corridor.
Can we manage without numbers? For prohibitions, yes — "unacceptable" works. Everywhere else a number is needed, otherwise compliance cannot be tested.
How often should it be revisited? Annually with the strategy, and out of cycle after a major incident, a market shift or new regulatory requirements.