KITE 2025 New Product Award — Local IT | SACEEC

What Is a Risk Appetite Statement? Appetite, Tolerance & Capacity Explained

A risk appetite statement tells the organization how much risk it is willing to take to pursue its objectives. Here is how to build one that actually guides decisions.

Free PDF GuideDownload this guide as a PDF

Every strategic objective involves taking on risk. The question every board should be able to answer is how much risk it is willing to take to achieve that objective. A risk appetite statement answers exactly that. It is the bridge between strategy and day-to-day risk decisions, translating the board's tolerance for uncertainty into language that managers can act on. This guide explains what a risk appetite statement is, how appetite differs from tolerance and capacity, and how to build one that cascades into real limits and indicators.

Watch: What is a risk appetite statement and how to write one Watch: What is a risk appetite statement (short tutorial)
i

What You'll Learn

By the end of this guide you will understand the difference between risk appetite, tolerance, and capacity; the qualitative and quantitative components of an appetite statement; concrete examples for each risk category; how the board sets appetite; and how appetite cascades into limits and key risk indicators.

What Is a Risk Appetite Statement?

A risk appetite statement is a board-approved articulation of the amount and type of risk an organization is willing to accept in pursuit of its strategic objectives. It sets the boundaries within which the organization is prepared to operate.

The statement matters because, without it, "how much risk is acceptable?" gets answered differently by every manager, every day. A sales team chasing growth and a compliance team avoiding fines will draw the line in very different places. The appetite statement gives them a shared reference point set at the top.

It is referenced by the risk management policy and operationalized through every risk assessment. Once you have scored a risk, the appetite is what tells you whether that score is acceptable or whether the risk must be treated.

Appetite vs. Tolerance vs. Capacity

These three terms are frequently confused, but they describe different things. Getting them straight is essential to writing a coherent statement.

Term Definition Set By
Capacity The maximum risk the organization could absorb before its viability is threatened. A hard ceiling. Determined by financial and operational reality
Appetite The amount of risk the organization chooses to take to pursue objectives. A target level, set below capacity. The board
Tolerance The acceptable variation around appetite for a specific risk or limit, meaning how far you will let things drift before acting Management, within appetite

An analogy helps. Think of driving on a highway. Your capacity is the maximum speed the car can physically reach. Your appetite is the speed you choose to drive, comfortably below the maximum and within the law. Your tolerance is how far above that chosen speed you will let yourself drift before easing off, say five kilometers per hour. Appetite is a deliberate choice, tolerance is the wiggle room, and capacity is the hard limit you never want to test.

Example

Capacity, Appetite, and Tolerance in Practice

A bank determines it could absorb up to R500 million in annual credit losses before breaching capital requirements. That is its capacity. The board sets an appetite of R200 million in expected annual credit losses, well within capacity, to leave a buffer. Management then sets a tolerance band: if losses are tracking 10% above the R200 million target by mid-year, lending criteria are tightened. The appetite is the target, the tolerance is the trigger, and the capacity is the wall.

Want the full framework with worked examples?

Qualitative and Quantitative Components

A strong appetite statement combines two kinds of language: qualitative statements that express attitude and direction, and quantitative measures that make the appetite testable.

Qualitative Components

Qualitative statements describe the organization's posture toward each type of risk. They are written in plain language and set the tone.

  • Directional words: "We have no appetite for breaches of safety regulations" versus "We have a moderate appetite for risk in pursuit of new market growth."
  • Context: Why the organization is willing, or unwilling, to take risk in a given area, linked to strategy.

Quantitative Components

Quantitative measures turn the posture into something measurable. Without them, an appetite statement is just sentiment.

  • Limits: Maximum acceptable exposure, e.g. "single-counterparty exposure not to exceed 10% of capital."
  • Thresholds: Levels that trigger action, e.g. "system downtime not to exceed 0.1% per quarter."
  • Targets and ranges: e.g. "maintain a liquidity coverage ratio above 120%."
i

Pro Tip

Pair every qualitative statement with at least one quantitative measure. "We have low appetite for cyber risk" is unfalsifiable. "We have low appetite for cyber risk; we target zero critical vulnerabilities unpatched beyond 30 days and no more than two reportable incidents per year" can actually be monitored and reported against.

Examples by Risk Category

Appetite varies by risk category. An organization can be hungry for strategic risk while having zero appetite for compliance breaches. The table below shows how a statement might read across categories.

Risk Category Appetite Level Example Statement
Strategic Moderate to High We will accept significant strategic risk to enter new African markets, provided downside is capped at 5% of group revenue per initiative.
Financial Moderate We accept measured financial risk but will maintain a liquidity buffer above 120% at all times.
Operational Low We have low appetite for operational disruption; critical systems must maintain 99.9% availability.
Compliance / Legal Zero / None We have no appetite for breaches of laws, regulations, or our code of conduct.
Reputational Low We have low appetite for actions that could damage stakeholder trust or brand reputation.
Cyber / Technology Low We have low appetite for cyber risk; no critical vulnerability may remain unpatched beyond 30 days.

Notice that "zero appetite" is reserved for areas where any failure is unacceptable, such as safety, legal compliance, and ethics. Declaring zero appetite everywhere is a red flag. It usually means the statement has not been thought through, because an organization that takes no risk anywhere cannot pursue any objective.

How the Board Sets Appetite

Setting risk appetite is one of the board's core governance duties. It is not delegated to the risk function, though the risk function facilitates the process. A typical process looks like this:

  1. Start from strategy. Appetite only makes sense in the context of objectives. The board reviews the strategic plan and asks what risks pursuing it implies.
  2. Assess capacity. Management quantifies how much risk the organization could absorb (capital, liquidity, operational resilience) so appetite can be set safely below it.
  3. Debate appetite by category. The board works through each risk category and agrees a posture, balancing growth ambitions against resilience.
  4. Quantify where possible. Qualitative postures are paired with measurable limits and thresholds.
  5. Approve and document. The board approves the statement, which is then referenced by the risk management policy.
  6. Review periodically. Appetite is revisited at least annually and whenever strategy shifts materially.
!

Important

Appetite set in a vacuum, disconnected from strategy and capacity, becomes a shelf document. If the board approves an appetite statement once and never references it in real decisions, it provides no governance value. Appetite should be cited when major investments, new products, and large risks are debated. That is the test of whether it is real.

Cascading Appetite into Limits and KRIs

An appetite statement is only useful if it reaches the people making daily decisions. This happens through a cascade: the board-level appetite is translated into specific limits and then monitored with key risk indicators.

From Appetite to Limits

High-level appetite is broken down into operational limits that managers can apply. "Moderate appetite for credit risk" becomes "no single counterparty exposure above 10% of capital" and "minimum average portfolio credit rating of BBB."

From Limits to KRIs

Each limit is paired with a key risk indicator (KRI), a measurable metric that signals when exposure is approaching the limit. KRIs are typically given green, amber, and red bands so that breaches are visible early.

Appetite (Board) Limit (Management) KRI (Monitored)
Low appetite for operational disruption Critical systems must maintain 99.9% availability Monthly system uptime % (amber below 99.95%, red below 99.9%)
Low appetite for cyber risk No critical vulnerability unpatched beyond 30 days Count of critical vulnerabilities aged over 30 days
Moderate financial risk Liquidity coverage ratio above 120% Daily LCR (amber below 125%, red below 120%)

This cascade closes the loop. When a KRI breaches its threshold, it signals that the organization is approaching or exceeding its stated appetite, triggering escalation under the risk policy. The relationship between appetite, limits, and KRIs is also what makes ongoing monitoring meaningful, because you are measuring against a target the board actually set. For more on tracking these over time, see how to monitor risks over time.

Common Mistakes to Avoid

1. All Qualitative, No Numbers

A statement made entirely of "we have low appetite for X" cannot be monitored. Without quantitative limits, you can never tell whether you are within appetite.

2. Zero Appetite Everywhere

Declaring no appetite for every risk is both unrealistic and useless. It signals the board has not genuinely engaged with the trade-offs.

3. No Link to Strategy

Appetite divorced from strategic objectives is arbitrary. The whole point is to define how much risk you will take to achieve specific goals.

4. Set and Never Used

An appetite statement that is approved and filed away changes nothing. It must be referenced when real decisions and risk assessments are made.

5. No Cascade

If board-level appetite never becomes operational limits and KRIs, frontline managers have nothing to act on. The cascade is what makes appetite live.

Key Takeaways

Summary

  • A risk appetite statement defines how much and what type of risk an organization will take to pursue its objectives
  • Capacity is the maximum you could absorb, appetite is what you choose to take, and tolerance is the acceptable variation around it
  • Combine qualitative postures with quantitative limits so the statement is measurable
  • Appetite varies by category, often high for strategic growth and zero for compliance and safety
  • The board sets appetite from strategy, and it cascades into limits and KRIs that drive daily decisions

Frequently Asked Questions

What is the difference between risk appetite and risk tolerance?

Risk appetite is the amount of risk you choose to take overall to pursue your objectives, a high-level target set by the board. Risk tolerance is the acceptable variation around a specific limit, meaning how far you will let a particular metric drift before acting. Appetite is the strategic posture; tolerance is the operational wiggle room within it.

Who sets the risk appetite statement?

The board sets and approves the risk appetite statement, because deciding how much risk to take is a fundamental governance choice tied to strategy. The risk function and executive team facilitate the process by gathering data, drafting language, and quantifying limits, but the board owns the final decision and references the statement in the risk management policy.

Can risk appetite be different for different risk types?

Yes, and it usually should be. A healthy appetite statement is differentiated by category. An organization might have a high appetite for strategic risk to grow, a moderate appetite for financial risk, and zero appetite for compliance, safety, or ethics breaches. A single blanket appetite across all risk types is a sign the statement has not been thought through.

How does appetite connect to a risk assessment?

Appetite is the benchmark you evaluate against. Once a risk assessment has scored a risk, usually as a residual likelihood and impact, you compare that score to your appetite. If the residual risk sits within appetite, you can accept and monitor it. If it exceeds appetite, the risk must be treated or escalated. Without an appetite, there is no objective basis for deciding which risks are too high.

What are KRIs and how do they relate to appetite?

Key risk indicators (KRIs) are measurable metrics that signal when exposure is approaching a limit. They are the monitoring layer of the appetite cascade: the board sets appetite, management translates it into limits, and KRIs track how close you are to breaching those limits, usually with green-amber-red bands. When a KRI hits red, it tells you appetite is about to be exceeded and escalation is needed.

How often should the appetite statement be reviewed?

At least annually, and whenever strategy changes materially, such as entering a new market, launching a new product line, a major acquisition, or a significant shift in the operating environment. Because appetite is tightly coupled to strategy, it should be revisited whenever strategy is revisited, which is one reason it is often kept as a separate document from the risk policy.

Save this guide for later

Download the PDF version to read offline or share with your team.

Co-Founder & ERM Practitioner

An enterprise risk management practitioner with experience across healthcare, public sector, and regulated environments. Phumi focuses on translating ERM frameworks into practical, decision-relevant processes.

Co-Founder & ERM Practitioner

Specialises in enterprise risk management through risk assessments, data analysis, and mitigation planning. Contributes to compliance oversight, risk reporting, and monitoring of key risk indicators.