Skip to main content
All articles

Risk Management

Risk Appetite vs. Risk Tolerance: Practical Examples for Business Leaders

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

Risk Appetite vs. Risk Tolerance: Practical Examples for Business Leaders: original RiskSensai editorial cover

Make the distinction useful to a decision

“We have a low appetite for risk” gives a manager little help deciding whether to launch a new service, tolerate an outage or approve a supplier exception. The statement needs an objective, a risk category and an explanation of the trade-off leadership is willing to make.

NIST's current enterprise-risk guidance distinguishes broad appetite set by leadership from more specific tolerance used to apply that direction.1 This terminology is useful when it helps people make decisions. Do not spend weeks debating vocabulary while leaving important exposure without an owner.

The examples below are original fictional management statements. Their numbers illustrate how a limit can work; they are not benchmarks, legal thresholds or suggested targets for every business.

Appetite, tolerance, target and capacity

TermPractical meaningExample question
AppetiteBroad direction about risk taken to pursue objectivesWhat trade-off are we willing to make?
ToleranceSpecific acceptable variation or operating boundaryAt what point must the owner act?
TargetDesired performance within the boundaryWhat result are we aiming for?
CapacityWhat the organization can actually absorbCould we survive the downside even if we accept it?

A company may be willing to take commercial risk but lack cash to absorb a large loss. A target can be stricter than a tolerance. A requirement imposed by law or contract cannot simply be overridden by an internal appetite statement.

State which definition your organization uses and apply it consistently. Different frameworks use terms differently; unexplained terminology can make a leadership report look precise while hiding incompatible assumptions.

Original decision-statement template

Write the appetite and its operating translation together:

To pursue [objective], we are willing to take [type of risk] within [conditions], while avoiding [unacceptable consequences]. [Accountable owner] will monitor [indicator] for [scope and period]. [Specific limit] triggers [action and escalation]. Exceptions require [authority], [evidence], [expiry] and [review conditions].

Add the source of the data and limitations. A threshold cannot support action if nobody can measure it reliably. Also record who may revise the limit and which changes require leadership approval.

For a first draft, choose one risk relevant to a live decision. Make it understandable to the people who will use it. A twenty-category appetite document may be less useful than a reviewed statement that changes a real approval process.

Worked example: service availability

Fictional scenario: A business depends on an online order service. Leadership wants growth but has little appetite for interruptions that prevent existing customers placing orders.

The appetite statement reads: “We will expand ordering features while protecting reliable access to the core order service. Material unresolved recovery gaps require executive review before a high-impact change.”

The operating tolerance identifies the critical service, a defined disruption limit and the owner who escalates approaching or exceeded limits. It also defines a leading indicator: a failed recovery exercise triggers review even if the live site has not yet had an outage.

The team might choose a two-hour internal escalation boundary for this example, but it must distinguish that management limit from any customer promise. A dashboard showing two hours of downtime does not prove all contract or recovery objectives were met. The continuity and recovery guide explains how technical recovery targets connect to business impact.2

Worked example: supplier concentration

A second fictional company relies on one supplier for a critical component. Leadership accepts some concentration to keep the product economical, provided the team can sustain defined essential deliveries during a disruption.

The tolerance could require review when the alternate supply arrangement expires, when available stock falls below a reviewed operational buffer or when demand materially exceeds the plan's assumptions. These are original example decision conditions, not a universal industry ratio.

The useful question is not whether the register rates the supplier “medium.” It is what the business will do when the dependency moves outside its reviewed boundary. Options might include reducing commitments, improving contingency arrangements or obtaining explicit time-limited acceptance from the authorized decision-maker.

Avoid “zero tolerance” without an operating meaning

Leadership may have no appetite for unlawful conduct or harm to people. That principle does not mean the probability of every incident is zero, or that staff can hide near misses to maintain a green report.

Separate prohibited behavior from risk exposure and response. A policy can prohibit sharing credentials while the organization still plans how to detect and handle accidental exposure. If a risk cannot be eliminated, document safeguards, reporting and remaining uncertainty honestly.

The GAO Green Book discusses risk assessment and preventive controls while recognizing that control systems have limitations.3 It is a federal framework, not a requirement that private businesses adopt a particular appetite structure.

Choose indicators that can drive action

A helpful indicator has a defined population, unit, period, data source, owner and escalation. “Number of open findings” may be useful, but it can also reward closing easy items while serious issues age.

Consider indicators such as overdue high-priority corrective actions, unreviewed supplier changes, unresolved recovery-test failures or exceptions beyond approved expiry. Tailor them to the decision. These are potential management measures, not claims that any software monitors them automatically.

Use both present exposure and warning signals when appropriate. An expired review does not prove a supplier is unsafe, but it can indicate missing evidence needed for continued acceptance. State that distinction in reporting.

Original leadership review checklist

Before approving an appetite/tolerance record, ask:

  1. Does the statement name the business objective and risk category?
  2. Are unacceptable consequences clear and consistent with obligations?
  3. Is the operating boundary specific enough for an owner to use?
  4. Can the indicator be measured with available evidence?
  5. Does the measure hide important subsets or aggregated exposure?
  6. Is there an action before or when the limit is crossed?
  7. Can the decision-maker accept exceptions within their authority?
  8. Do exceptions expire and retain their reason and safeguards?
  9. Are targets, contractual promises and internal tolerances distinguished?
  10. Is there a trigger for review after changed assumptions or incidents?

Record disagreements and uncertainties. A management statement is more credible when it explains a trade-off than when it removes every qualification.

Put the statement into everyday work

Connect the record to supplier approvals, change decisions and remediation escalation. When a finding exceeds tolerance, document the response and authority rather than silently changing its rating.

Review statements when the business model, scale, financial capacity or external obligations change. A limit appropriate for a pilot may become unacceptable after the service supports many more customers. Conversely, new evidence or stronger controls can justify a reviewed change.

Questions about risk limits

Is tolerance always a number?

No. A clear condition or qualitative boundary can work if people know how to assess it and what action follows. Numbers without reliable context create false precision.

Can a manager change the limit to close a finding?

Only through the appropriate authority and reviewed rationale. Preserve the original issue and decision history; do not relabel exposure to conceal a missed commitment.

Where should we begin?

Choose one pending decision, use the template and test whether the operating owner can apply it. The readiness assessment may help identify discussion areas, but leadership must establish and approve its own risk direction.

Sources and references

  1. NIST. IR 8286A Rev. 1: Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management (2025-12-18). Current revision distinguishes broad leadership appetite and more specific operational tolerance. ↩

  2. NIST. SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems, updated November 2010 (2010-11-11). Federal-system guidance used here as a planning reference, not a private-business mandate. ↩

  3. U.S. Government Accountability Office. Standards for Internal Control in the Federal Government: 2025 Green Book (2025-05-15). Federal-agency framework, effective FY2026; voluntary reference here for private-business control design. ↩

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • Risk Appetite
  • Risk Tolerance
  • Leadership
Connecting to your conversation workspace…