Skip to content

Risk Tolerance

What is Risk Tolerance?

The acceptable level of variation an organisation is willing to tolerate around specific risk objectives. Risk tolerance provides specific, measurable thresholds that translate the broader risk appetite into operational guidance.

Risk Management

Each of these is named in at least one of the same controls as risk tolerance. The number is how many controls name both.

What the standards actually require on risk tolerance

Requirements naming risk tolerance across 6 standards, quoted from the control text.

Organizational risk tolerances are determined and documented. Tolerance is written down at a level that lets someone decide whether a measured risk is acceptable, and it is traceable to an authority that can set it.

AIRMF-MP-1.5 · Organizational risk tolerances are determined and documented

Risk appetite and risk tolerance statements are established, communicated, and maintained

NIST-CSF-GV.RM-02 · Risk appetite and risk tolerance statements are established, communicated, and maintained
NIST SP 800-303 controls

Conduct risk assessments at the three tiers defined in NIST SP 800-30 Rev 1 Section 2.3 and aligned with NIST SP 800-39 governance tiers.

NISTSP30-2 · Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)

Vet mobile applications prior to deployment using static and dynamic analysis aligned with enterprise risk tolerance.

800-124r2-3.4 · Mobile Application Vetting
NIST SP 800-1372 controls

Define ISCM metrics per Section 3.2 covering security control effectiveness + system + organizational metrics + leading and lagging indicators + Cyber-Resilience metrics + KPIs (Mean Time to Detect MTTD + Mean Time to Respond MTTR + Mean Time to Remediate MTTR...

NISTSP137-2 · Monitoring Metrics, Measures, and Frequencies
NIST SP 800-392 controls

Execute the Frame step per NIST SP 800-39 Chapter 3 Section 3.1. Framing produces a risk frame that establishes the context within which risk-based decisions are made.

NISTSP39-2 · Risk Framing: Risk Frame Components and Trust

Questions people ask about risk tolerance

What is Risk Tolerance?
The acceptable level of variation an organisation is willing to tolerate around specific risk objectives. Risk tolerance provides specific, measurable thresholds that translate the broader risk appetite into operational guidance.
Why is Risk Tolerance important for compliance?
Risk Tolerance is a key concept in Risk Management. Understanding risk tolerance helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk Tolerance?
Risk Tolerance appears in the requirement text of NIST AI Risk Management Framework (AI RMF 1.0), NIST Cybersecurity Framework 2.0, NIST SP 800-30, NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices, NIST SP 800-137. Across these standards we have identified 15 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Tolerance?
Explore our compliance framework pages to see how risk tolerance applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Tolerance applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.