Back to blog
GRC Fundamentals

Risk appetite vs risk tolerance: making the difference useful

Appetite is how much risk you are willing to seek; tolerance is how far you will let a specific risk drift before acting. How to write both so they change decisions rather than decorating a policy.
GRC Copilot Team
Risk appetite vs risk tolerance: making the difference useful

Risk appetite is a strategic statement of how much risk you are willing to take in pursuit of objectives. Risk tolerance is the operational boundary on a specific risk before someone must act. Appetite guides direction; tolerance triggers behaviour. Most organisations write the first and skip the second, which is why their appetite statement changes nothing.

The distinction in practice

  • Appetite - "We accept moderate risk in product experimentation, and minimal risk in the handling of customer data."
  • Tolerance - "No critical vulnerability on an internet-facing system remains unremediated beyond 7 days. Beyond 14 days, it escalates to the executive committee."

Notice what the tolerance statement does that the appetite statement cannot: it tells a specific person, on a specific day, what to do. That is the whole point.

Why appetite statements usually fail

  • They are unfalsifiable. "We have a low appetite for cyber risk" cannot be tested, and therefore cannot be breached, and therefore never triggers anything.
  • They are uniform. A single appetite across the whole organisation ignores that you should tolerate more risk in an internal prototype than in a payment flow.
  • They are disconnected from the register. If nothing in the risk register references appetite, it is not being used.
  • Nobody owns breaching them. If exceeding appetite has no consequence, it is aspiration.
The test of a working appetite statement: can you point to a decision in the last quarter that went differently because of it? If not, it is decoration.

Connect appetite to your actual risk register

GRC Copilot scores risks against your defined thresholds, flags anything outside appetite, and tracks who accepted what - so the statement drives behaviour.

Writing appetite by risk category

Differentiate rather than issuing one blanket statement. A workable structure:

  • Customer data confidentiality - averse. We do not accept residual risk above [score] without executive approval.
  • Service availability - low. We accept planned degradation but not unplanned outage of critical services beyond [RTO].
  • Regulatory compliance - averse. We do not knowingly operate outside applicable regulation.
  • Product innovation - open. We accept elevated risk in pre-release environments handling no production data.
  • Third-party dependency - cautious. We accept concentration risk only with a documented exit plan.

The differentiation is what makes it credible. An organisation claiming to be risk-averse about everything is either not innovating or not being honest.

Turning tolerance into triggers

Tolerance is only useful when it is numeric and attached to an action:

  • Score thresholds - "Residual risk of 15 or above requires a treatment plan and executive acceptance."
  • Time thresholds - remediation SLAs by severity, with escalation on breach.
  • Volume thresholds - "More than five overdue high-risk items triggers a review at the risk committee."
  • Trend thresholds - "Any risk increasing for two consecutive reporting periods is escalated."

That last one is underused and catches slow deterioration that snapshot thresholds miss.

How it connects to risk acceptance

Appetite and tolerance define who can accept a risk and for how long. A clean model:

  • Within tolerance - the risk owner manages it, no escalation.
  • Outside tolerance but within appetite - requires documented acceptance by a defined authority, time-bound, with review.
  • Outside appetite - requires treatment. Acceptance needs board-level authority and an expiry date.

Time-bounding acceptance is the discipline that prevents a temporary exception becoming permanent - and permanent undocumented exceptions are exactly what auditors find.

What frameworks expect

ISO 27001 requires risk acceptance criteria as part of your risk assessment methodology - which is appetite and tolerance in substance. SAMA CSF and the NCA ECC expect defined risk management with governance oversight. DORA and NIS2 place risk approval on management bodies, which only works if there are thresholds to approve against.

Frequently asked questions

Who sets risk appetite?

The board or executive leadership - it is a strategic statement about the organisation's posture, not a security team decision.

How often should it be reviewed?

Annually, and on significant change - a new market, a major incident, an acquisition, or a shift in regulatory exposure.

Can appetite differ across the business?

It should. Uniform appetite across all categories is usually a sign the statement was written to exist rather than to be used.

What if we are constantly outside appetite?

Either the appetite is unrealistic or the risk profile genuinely needs investment. Both are useful findings - persistent breach without either response means the thresholds are being ignored.

Key takeaways

  • Appetite is strategic direction; tolerance is an operational trigger.
  • If nothing escalates, the statement is decoration.
  • Differentiate appetite by risk category - uniform aversion is not credible.
  • Time-bound every risk acceptance, or exceptions become permanent.
#risk-appetite #risk-tolerance #governance #risk-acceptance #thresholds