Skip to content

Risk Appetite

What is Risk Appetite?

The amount and type of risk an organisation is willing to accept in pursuit of its objectives. Set by the board and communicated throughout the organisation.

Risk Management

Each of these is named in at least one of the same controls as risk appetite. The number is how many controls name both.

What the standards actually require on risk appetite

Requirements naming risk appetite across 6 standards, quoted from the control text.

The institution must maintain an appropriate, clear and concise risk appetite statement addressing its material risks, with the Board responsible for setting risk appetite and required to approve the statement.

CPS220-06 · Risk Appetite Statement

Maintain Risk Appetite Statement + Risk Limits + Concentration Risk Management + Limit Breach Protocols per 12 CFR Part 30 Appendix D Sections II.E + II.F + II.G + II.H + II.I + II.K.

OCCHS-3 · Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols

The RSE licensee must maintain an up to date risk appetite statement covering its business operations and each category of material risk, approved by the Board.

SPS220-19 · Risk Appetite Statement

Leadership (business owner or executive management) establishes risk appetite and strategy, approves the content of the six foundational components, and oversees the function to confirm it operates as designed.

ADMF-1.5 · Executive direction and risk appetite

Risk appetite and tolerance for IT risk. Control from FFIEC IT Examination Handbook framework, domain: FFIEC IT Examination Handbook: Information Security Governance.

FFIEC-03 · Risk appetite and tolerance for IT risk

Questions people ask about risk appetite

What is Risk Appetite?
The amount and type of risk an organisation is willing to accept in pursuit of its objectives. Set by the board and communicated throughout the organisation.
Why is Risk Appetite important for compliance?
Risk Appetite is a key concept in Risk Management. Understanding risk appetite helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk Appetite?
Risk Appetite appears in the requirement text of APRA CPS 220 Risk Management, OCC Heightened Standards (12 CFR Part 30, Appendix D), APRA SPS 220 Risk Management (Superannuation), ASEAN Data Management Framework, FFIEC IT Examination Handbook. Across these standards we have identified 27 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Appetite?
Explore our compliance framework pages to see how risk appetite applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Appetite applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.