Risicomanagement

Risk appetite

Risk appetite is the level of risk an organization is willing to accept in pursuit of its objectives. In risk-based auditing, board-approved risk appetite serves as a reference point for risk assessment and prioritization of audit subjects.

Source: COSO ERM 2017

Risk appetite is the level of risk an organization is deliberately willing to accept in pursuit of its objectives. It is a board-approved reference point that indicates how much uncertainty is acceptable while pursuing the strategy. In risk-based auditing, risk appetite serves as a reference point for risk assessment and for prioritizing audit subjects.

For the board, the supervisory board, and the audit committee, risk appetite matters because it makes decision-making verifiable. An explicitly defined risk appetite gives the board a compass for choices and enables the supervisory board and the audit committee to assess whether the organization is operating within its limits. Without that reference point, risk management remains a matter of instinct, and it becomes difficult to establish afterward whether a risk taken fitted the agreed course.

In practice, risk appetite is captured in an appetite statement and translated into concrete limits per objective or risk type, often supported by steering information. It is important to distinguish risk appetite (the desired level) from risk tolerance (the acceptable deviation from it on a specific objective or process). Frameworks such as COSO ERM 2017 explicitly link risk appetite to strategy and performance, so that it does not stand alone but forms part of steering and accountability.

At ONE Risk Advisory, we help organizations articulate their risk appetite and translate it into concrete limits and steering information. An explicitly defined risk appetite gives the board a compass for decision-making and makes risk management verifiable. This makes visible which risks are deliberately accepted and which must be controlled.

Last updated:

Related service Risk Management

Frequently asked questions

What is the difference between risk appetite and risk tolerance?

Risk appetite is the level of risk an organization is willing to accept to achieve its objectives; risk tolerance is the acceptable deviation from it on a specific objective or process. Risk appetite is the guideline at organizational level, while tolerance is the operational bandwidth around it.

Why must the board set the risk appetite?

Because risk appetite touches on strategic choices and on how much uncertainty is acceptable, setting it belongs with the board, with oversight by the supervisory board and the audit committee. This anchors risk management in governance rather than in individual judgment.

How does internal audit use risk appetite?

In risk-based auditing, the board-approved risk appetite serves as a reference point for assessing risks and prioritizing audit subjects. Audit can thus test whether the organization operates within the agreed limits and whether breaches are flagged in time.

How do you translate risk appetite into practice?

Risk appetite is captured in an appetite statement and translated into concrete limits per objective or risk type, supported by steering information. This turns an abstract reference point into something usable for day-to-day decision-making and periodic accountability.

← All terms