Risk Appetite
What is Risk Appetite?
The amount and type of risk an organisation is willing to accept in pursuit of its objectives. Set by the board and communicated throughout the organisation.
Terms that appear alongside risk appetite
Each of these is named in at least one of the same controls as risk appetite. The number is how many controls name both.
- governance 32 shared controls
- risk appetite statement 22 shared controls
- information security 19 shared controls
- compliance 18 shared controls
- audit 17 shared controls
- risk management framework 14 shared controls
- risk governance 11 shared controls
- risk tolerance 10 shared controls
Frameworks that govern risk appetite
What the standards actually require on risk appetite
Requirements naming risk appetite across 6 standards, quoted from the control text.
The institution must maintain an appropriate, clear and concise risk appetite statement addressing its material risks, with the Board responsible for setting risk appetite and required to approve the statement.
CPS220-06 · Risk Appetite Statement →Maintain Risk Appetite Statement + Risk Limits + Concentration Risk Management + Limit Breach Protocols per 12 CFR Part 30 Appendix D Sections II.E + II.F + II.G + II.H + II.I + II.K.
OCCHS-3 · Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols →The RSE licensee must maintain an up to date risk appetite statement covering its business operations and each category of material risk, approved by the Board.
SPS220-19 · Risk Appetite Statement →Leadership (business owner or executive management) establishes risk appetite and strategy, approves the content of the six foundational components, and oversees the function to confirm it operates as designed.
ADMF-1.5 · Executive direction and risk appetite →Risk appetite and tolerance for IT risk. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.
FFIEC-03 · Risk appetite and tolerance for IT risk →The IRM Risk Architecture + Strategy + Protocols (RASP) framework defines the governance + structural + behavioural enabling elements of effective enterprise risk management.
IRM-Architecture-Strategy-Protocols-Appetite-Culture-Board-Audit-Committee-CRO-Three-Lines · IRM RASP - Risk Architecture + Strategy + Protocols + Risk Appetite Statement + Risk Culture + Board + Audit Committee + Chief Risk Officer + Three Lines of Defence + Tone at the Top →Questions people ask about risk appetite
What is Risk Appetite?
Why is Risk Appetite important for compliance?
Which compliance frameworks address Risk Appetite?
Where can I learn more about Risk Appetite?
See how Risk Appetite applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.