Risk appetite is one of three terms that get used as though they were synonyms — appetite, tolerance and capacity — and the confusion is expensive, because each one answers a different question and only one of them is a hard limit. Worth knowing before you start: ISO 31000 itself does not use the term.
This guide separates the three, shows what a usable appetite statement looks like, and covers where these statements stop working.

Three terms, three questions
| Term | Question it answers | Who sets it |
|---|---|---|
| Capacity | How much loss could we absorb before we fail? | Arithmetic — balance sheet, liquidity, regulation |
| Appetite | How much risk do we choose to take in pursuit of objectives? | The board |
| Tolerance | How much variation around that is acceptable in practice? | Management, within the board’s appetite |
Capacity is a fact you discover. Risk appetite is a decision you make, and it should sit below capacity with room to spare. Tolerance is the operating band around a specific objective — the point at which management escalates rather than absorbs.
The ISO 31000 wrinkle
ISO 31000 does not require a risk appetite statement, and does not use the phrase in its requirements. What it requires is risk criteria: the terms of reference against which the significance of risk is evaluated, defined when the process is designed and reviewed as things change. Risk appetite, as most organizations use it, is the board-level expression of those criteria, and the vocabulary came into general use mainly through enterprise risk management frameworks rather than through ISO.
That matters practically. If you are being audited against ISO 31000 or a management system standard, the auditable artifact is the criteria — the scales, the thresholds, the escalation rules. An appetite statement with no criteria beneath it satisfies nobody.
What a usable risk appetite statement looks like
The failure mode is universal and recognisable: “We have a low appetite for operational risk and a moderate appetite for strategic risk.” Nobody has ever made a decision with that sentence. A statement earns its place when it does four things:
- Splits by risk category, not by the whole organization. Appetite for safety risk and appetite for market risk have nothing to do with each other, and an average of the two is meaningless.
- Attaches a measure. A number, a rating, a time limit — anything an operational decision can be tested against. “No unplanned downtime above four hours for tier 1 services” is usable; “low appetite for outages” is not.
- Says what happens at the boundary. Who is told, how fast, and who can authorise an exception. An appetite with no escalation rule is advice.
- Distinguishes appetite from zero. Very few organizations genuinely have zero appetite for anything except regulatory breach and harm to people. Declaring zero appetite everywhere means the statement will be ignored the first time reality intrudes.
Connecting it to the risk register
The link is the scoring scale. If risks are scored on a five-by-five matrix, the risk appetite has to be expressed in the same units, so that “above appetite” is a fact about the register rather than a judgement call. Without that, every escalation becomes a negotiation. Our guide to the cybersecurity risk register covers the register side of the same join.
Where risk appetite statements stop working
Written once, for the board pack. An appetite statement that is not revisited when strategy changes describes a company that no longer exists.
No connection to authority. If exceeding appetite does not change who may approve a decision, the statement has no teeth. The mechanism is delegated authority: within appetite, the manager decides; above it, somebody more senior does.
Aggregation ignored. Ten individually acceptable risks can breach appetite collectively. Portfolio-level review is the only place that shows up.
Appetite set by the risk function. Risk teams draft; boards own. An appetite the board did not genuinely debate will not survive the first time it is inconvenient.
Frequently asked questions
What is risk appetite?
The amount and type of risk an organization is willing to pursue or retain in pursuit of its objectives — a board-level choice, sitting below the organization’s capacity to bear loss.
How is it different from risk tolerance?
Appetite is the overall willingness; tolerance is the acceptable variation around a specific objective, set by management within appetite and usually expressed as a threshold that triggers escalation.
Does ISO 31000 require a risk appetite statement?
No. ISO 31000 requires risk criteria. Most organizations express the board’s position as an appetite statement and derive the criteria from it, which satisfies both.
Who approves it?
The board or equivalent governing body, on advice. Delegating approval to a risk committee is common; delegating it to the risk function is not.
How often should it be reviewed?
At least annually and whenever the strategy, business model or external environment changes materially — the same trigger that should prompt a review of the criteria beneath it.
Where this leaves you
Work out capacity first, because it bounds everything else. Set risk appetite per category with a measure attached, tie it to the same scale your risk register uses, and write the escalation rule that says what happens when a risk sits above it. Then push it into delegated authority — an appetite that changes who can approve what is a control, and one that lives only in a board paper is a paragraph.
References
- ISO 31000:2018 — risk management principles and guidelines, including risk criteria.
- COSO Enterprise Risk Management — the framework where appetite and tolerance vocabulary is most developed.
More on risk management
- Risk appetite — you are here
- ISO 31000 and its three components
- Setting risk criteria
- The cybersecurity risk register
Appetite statements, criteria scales and the register template are in the ISO 31000 Risk Management Toolkit, or start with the free ISO templates.