Risicomanagement

Risk appetite

Risk appetite is the level of risk an organisation is willing to accept in pursuit of its objectives. In risk-based auditing, board-approved risk appetite serves as a reference point for risk assessment and prioritisation of audit subjects.

Source: COSO ERM 2017

Risk appetite is the level of risk an organisation is deliberately willing to accept in pursuit of its objectives. It is a board-approved reference point that indicates how much uncertainty is acceptable while pursuing the strategy. In risk-based auditing, risk appetite serves as a reference point for risk assessment and for prioritising audit subjects.

For the board, the supervisory board, and the audit committee, risk appetite matters because it makes decision-making verifiable. An explicitly defined risk appetite gives the board a compass for choices and enables the supervisory board and the audit committee to assess whether the organisation is operating within its limits. Without that reference point, risk management remains a matter of instinct, and it becomes difficult to establish afterwards whether a risk taken fitted the agreed course.

In practice, risk appetite is captured in an appetite statement and translated into concrete limits per objective or risk type, often supported by management information. It is important to distinguish risk appetite (the desired level) from risk tolerance (the acceptable deviation from it on a specific objective or process). Frameworks such as COSO ERM 2017 explicitly link risk appetite to strategy and performance, so that it does not stand alone but forms part of management and accountability.

At ONE Risk Advisory, we help organisations articulate their risk appetite and translate it into concrete limits and management information. An explicitly defined risk appetite gives the board a compass for decision-making and makes risk management verifiable. This makes visible which risks are deliberately accepted and which must be controlled.

Last updated:

Related service Risk Management

Frequently asked questions

What is the difference between risk appetite and risk tolerance?

Risk appetite is the level of risk an organisation is willing to accept to achieve its objectives; risk tolerance is the acceptable deviation from it on a specific objective or process. Risk appetite is the guideline at organisational level, while tolerance is the operational range around it.

Why must the board set the risk appetite?

Because risk appetite touches on strategic choices and on how much uncertainty is acceptable, setting it belongs with the board, with oversight by the supervisory board and the audit committee. This anchors risk management in governance rather than in individual judgement.

How does internal audit use risk appetite?

In risk-based auditing, the board-approved risk appetite serves as a reference point for assessing risks and prioritising audit subjects. Audit can thus test whether the organisation operates within the agreed limits and whether breaches are flagged in time.

How do you translate risk appetite into practice?

Risk appetite is captured in an appetite statement and translated into concrete limits per objective or risk type, supported by management information. This turns an abstract reference point into something usable for day-to-day decision-making and periodic accountability.

← All terms