COSO risk appetite is the amount of risk, on a broad level, that an organisation is willing to accept in pursuit of stakeholder value, and COSO’s Enterprise Risk Management framework makes defining it a distinct principle. Many boards approve a risk appetite statement once, file it, and never connect it to targets, so it cannot guide a single decision.
This guide explains what Principle 7 says, how appetite differs from tolerance, how to write a statement people can use, and how to cascade it into measures and escalation. For the whole framework, see our COSO ERM principles guide.
Free gap assessment
Is risk management actually changing decisions?
A maturity assessment against all eight principles, the framework and the process, free. Nobody can certify you to ISO 31000, so this scores distance from good practice instead.
Run the free ISO 31000 maturity assessment → or View premium report sample
What COSO risk appetite means in the ERM framework
COSO’s 2017 framework, Enterprise Risk Management: Integrating with Strategy and Performance, sets out twenty principles in five components. Principle 7 sits in the strategy and objective-setting component and states that the organisation defines risk appetite in the context of creating, preserving and realising value. The placement matters. Appetite is set while strategy is being chosen, so that leaders can test whether a strategy works in tandem with it, and then used to steer performance.
Free enterprise risk assessment
Which of your business risks sit above your appetite?
Set your criteria and appetite, pick from 36 strategic, financial, operational and compliance scenarios, rate them and decide how to treat each. Built to ISO 31000, and free.
Run the free enterprise risk assessment → or View premium report sample
The principles in that component run from analysing business context (6), through defining risk appetite (7) and evaluating alternative strategies (8), to formulating business objectives (9). You cannot compare strategic options sensibly without an appetite to compare them against, which is why the order is what it is. Our COSO framework overview explains how this framework relates to the internal control framework.
COSO risk appetite vs risk tolerance
The two terms are often used as if they meant the same thing. In COSO’s usage they sit at different levels. Appetite is strategic and broad, usually qualitative and approved by the board. Tolerance is operational: the acceptable variation in outcomes related to specific performance measures linked to objectives.
| Concept | Question it answers | Typical form | Owner |
|---|---|---|---|
| Risk appetite | How much risk do we want to take in pursuing value? | Qualitative statements by category | Board approves, executives propose |
| Risk tolerance | How far from the target can a measure move? | Ranges, thresholds, limits | Management, by objective |
A worked illustration from published guidance: a board says the brand is essential, which leads to an objective of maintaining eight products in development. A tolerance then sets the acceptable range as six to ten. If the count falls to five, the breach triggers escalation. The appetite gave direction and the tolerance gave a trigger.
How to write a COSO risk appetite statement
A useful statement is short, specific to categories of risk and written in language that managers can apply. COSO describes three approaches: qualitative, quantitative and hybrid. Most organisations start qualitatively at the top, and add numbers as the statement moves down to measures.
- Start from strategy. List the objectives and the value you are trying to create or protect.
- Group risks by category. Use categories that match how you manage the business, such as strategic, financial, operational, compliance, technology and reputation.
- Set a stance for each category. For example, low appetite for regulatory breaches, moderate for new-market entry, higher for product innovation.
- Explain the reason. Tie each stance to objectives and to what the organisation can bear.
- Test against the plan. Check that the strategy and budget do not contradict the stated appetite.
- Approve and communicate. Have the board approve the statement and make it available to the managers who take decisions.
Avoid words that cannot be measured
Phrases like “we have zero tolerance for risk” or “we accept a prudent level of risk” tell nobody what to do. Zero appetite for a compliance breach may be a fair position for the statement, but it should be paired with a tolerance for the control that supports it, such as a maximum number of overdue mandatory training completions, so managers know what triggers action.
Cascading COSO risk appetite into tolerances and indicators
The link between appetite and daily management is the set of tolerances attached to performance measures. For each objective under a category, choose a measure, a target and a tolerance range, and decide who is told when it is breached. Many organisations use key risk indicators for the early-warning layer. Our guide to KRI thresholds shows how to set the green, amber and red bands.
- Financial. Maximum acceptable variance against budget, or a minimum liquidity ratio.
- Operational. Maximum unplanned downtime for a critical service.
- Compliance. Number of overdue regulatory actions, with zero as the target and a low ceiling before escalation.
- Technology. Time to patch critical vulnerabilities, or the share of privileged accounts without multi-factor authentication.
- Reputation. Complaint volumes or service-level breaches for key customers.
Using COSO risk appetite in decisions
The statement earns its keep in three places. In strategy reviews it acts as a test: does the option under discussion fit our appetite, and if not, what has to change? In project approvals it sets the bar for how much residual risk a sponsor can accept without escalation. In performance reviews it turns risk reports into decisions, because a tolerance breach demands a response rather than a comment. If none of these routines refer to the statement, it is a document and not a tool.
Governance and reporting for COSO risk appetite
The board owns the statement, and a risk committee usually reviews performance against it. Executives own the categories and the tolerances beneath them, and the risk function coordinates the data and challenges the numbers. Report to the board on a fixed cycle: the current position against each appetite category, tolerance breaches since the last meeting, the actions taken, and any strategic decision that came close to the limits. Keep the report to a page or two, with trend lines and plain wording, so directors can see at a glance where the organisation sits relative to what it said it would accept.
Appetite, capacity and culture
Appetite should sit inside the organisation’s capacity, which is the maximum risk it can bear without threatening its survival, given its capital, liquidity, licences and obligations. An appetite that exceeds capacity is a hope, not a policy. Culture matters as well: if managers are rewarded for hitting targets regardless of the risk taken, a cautious statement will not change behaviour. Align incentives, escalation norms and the tone from senior leaders with the appetite you have approved, so the words and the conduct point in the same direction.
A hypothetical example
A regional lender approves an appetite statement with low appetite for credit losses outside its core segments, moderate appetite for digital product change, and no appetite for deliberate compliance breaches. Management converts the credit stance into a tolerance: non-performing loans in new segments must stay within a set percentage of the portfolio, with escalation to the risk committee at a lower trigger. The digital stance becomes a limit on the number of major releases in one quarter without a rollback plan. When a proposed expansion into a new segment would breach the credit tolerance on the base-case forecast, the committee sends it back for redesign. The example is illustrative only.
Reviewing and updating COSO risk appetite
Appetite is not permanent. Review it whenever strategy shifts, after a major incident or near miss, when regulators change expectations, and at least once a year. In each review, ask three questions. Did any strategic decision push against the limits, and was that a deliberate call? Did the tolerances give early warning before losses appeared? And do the categories still describe how the business really runs? Record the answers and any change to the statement, with the date and the approver. A short change log lets a new director see how the organisation’s thinking has evolved, and it gives auditors evidence that the framework is applied, not just written.
Common mistakes with COSO risk appetite
- One statement, no measures. The board approves words, and management never receives a number.
- Appetite set after strategy. The statement rationalises the plan instead of testing it.
- Appetite and tolerance mixed up. One list serves both purposes and neither works.
- Not reviewed. The statement is unchanged while the business, markets and threats have moved.
- Not communicated. Managers who take the decisions have never seen it.
- No escalation path. A breach is reported, but no one has to respond.
Tools and next steps
Practical documents include a risk appetite statement template, a category-to-tolerance table, an escalation protocol, a board reporting pack and a review calendar. The COSO Toolkit includes templates for ERM and internal control, which you can adapt to your own categories and measures. Compare the appetite approach with ISO 31000 in our ISO 31000 vs COSO ERM guide. For the primary source, see the COSO ERM executive summary.
COSO risk appetite FAQ
Which COSO ERM principle covers risk appetite?
Principle 7, in the strategy and objective-setting component, says the organisation defines risk appetite in the context of creating, preserving and realising value.
What is the difference between risk appetite and risk tolerance?
Appetite is the broad amount of risk an organisation will accept in pursuit of value. Tolerance is the acceptable variation in outcomes for specific performance measures linked to objectives.
Who approves the risk appetite statement?
The board normally approves it, on a proposal from executive management, and reviews it as strategy changes.
How often should it be reviewed?
At least annually, and whenever strategy, the operating environment or the organisation’s capacity to absorb loss changes materially.