Risk Appetite: What It Is and How to Define It for Your Organization
How much risk is your organization willing to take to achieve its goals? The question sounds simple, but in practice the answer often gets stuck in vague terms like "we're risk-averse" or "it depends." That's a shame, because a clearly defined risk appetite is the foundation of every solid risk management process. In this blog, we explain what risk appetite is, why it matters so much, and how to define it in five practical steps.
What is risk appetite?
Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of its strategic objectives. The term comes straight from ISO 31000, the international standard for risk management, where it serves as one of the core principles.
Here's the important part: risk appetite is not about avoiding risk. Every organization that wants to achieve something takes risks. A water authority reinforcing a levee, a construction company taking on a complex infrastructure project, a municipality developing a new neighborhood: they all knowingly accept uncertainty. The question is not whether you take risk, but how much and in which areas.
Risk appetite vs. risk tolerance
The terms risk appetite and risk tolerance are often used interchangeably, but they don't mean the same thing:
- Risk appetite is the strategic choice: how much risk do we want to take as an organization? This is set at the executive or board level.
- Risk tolerance is the operational translation: how much deviation do we accept per objective or project? Think of concrete limits such as "a maximum budget overrun of 5%" or "zero safety incidents involving lost time."
Put simply: risk appetite is the compass, risk tolerances are the guardrails.
Why is risk appetite so important?
Without a clearly defined risk appetite, there is no shared frame of reference. And you'll notice that right away in day-to-day practice:
Everyone applies their own standard. One project manager escalates every single risk, while another handles everything on their own. Without agreed boundaries, there's no consistency in how your organization deals with uncertainty.
Discussions revolve around numbers instead of substance. A risk scores "red" in the matrix, but what does that actually mean? Is red unacceptable, or just something to keep an eye on? Risk appetite gives meaning to your risk scores.
Opportunities go untapped. Organizations without a clear risk appetite are often unintentionally overcautious. They miss opportunities because nobody knows which risks are actually perfectly acceptable.
Compliance requirements demand it. Regulations such as NIS2 and CER, and frameworks like ISO 31000 and COSO, expect organizations to make their risk appetite explicit and be able to justify it.
How to define your organization's risk appetite in 5 steps
You don't write a risk appetite statement alone at your desk. This is exactly where the golden rule applies: risk management is a dialogue, not a box-checking exercise. These five steps will get you started.
Step 1: Start with what you want to protect
Before you can decide how much risk you're willing to take, you need to know what's at stake. Which interests does your organization want to protect? Think of financial continuity, the safety of employees and surroundings, reputation, continuity of service, or public responsibilities. These interests worth protecting are the starting point of any meaningful discussion about risk appetite.
Step 2: Have the conversation with the right people
Risk appetite is a strategic choice and therefore belongs at the executive and board level. But don't limit the conversation to the boardroom. Project managers, team leads, and colleagues in the field know better than anyone which risks actually occur in practice. The broader and more diverse the group, the more realistic and widely supported your risk appetite becomes. An interactive session where participants vote and discuss together delivers far more than a document sent around by email.
Step 3: Differentiate by risk category
A single risk appetite for the entire organization rarely works. Most organizations are willing to take more risk in some areas than in others. A typical picture:
- Safety: very low risk appetite, incidents involving injury are never acceptable
- Finance: moderate risk appetite within defined bandwidths
- Innovation: high risk appetite, experimentation is encouraged and failure is part of the process
- Reputation and compliance: low risk appetite, legal violations are off the table
By making a statement per category, your risk appetite becomes concrete and usable in everyday decision-making.
Step 4: Make it measurable with risk tolerances
Translate the strategic statements into operational limits. "We have a low risk appetite in financial matters" then becomes, for example: "Project risks with an expected impact greater than 10% of the project budget require executive approval." That way, everyone in the organization knows when a risk is acceptable, when mitigation is needed, and when to escalate.
Step 5: Keep it alive
A risk appetite statement is not a document for the drawer. At every risk session, check whether the identified risks fall within the agreed appetite. Discuss deviations explicitly. And evaluate annually whether your risk appetite still fits your strategy, your environment, and the lessons you've learned. Especially in sectors like infrastructure, water management, and construction, circumstances change fast.
Risk appetite in practice: from paper to dialogue
This is where many organizations go wrong. The risk appetite is neatly written down in a policy document, but hardly anyone looks at it in actual projects. Risks get scored in a spreadsheet, the color codes get reported, and that's the end of it.
The solution is not more documents, but better conversations. When a project team identifies and quantifies risks together, for example in an interactive brainstorming session where everyone can join via a QR code, the discussion naturally turns to the question: do we find this risk acceptable? That exact conversation is what brings your risk appetite to life.
Visualization helps enormously here. A dashboard that shows at a glance which risks fall outside the agreed tolerances makes the conversation with executives and the board far more concrete. And because everyone works with the same up-to-date information, the endless debates about outdated Excel versions disappear.
Frequently asked questions about risk appetite
Who sets the risk appetite?The executive team or the board, often in alignment with the supervisory board or audit committee. Ideally, the input comes from across the entire organization.
How often should you review your risk appetite?At least once a year, and additionally after major changes such as a new strategy, a merger, new legislation, or a significant incident.
Is risk appetite mandatory under ISO 31000?ISO 31000 is a guideline, not a certifiable requirement. But the standard does consider making your risk criteria explicit, including your risk appetite, an essential part of professional risk management.
What is a risk appetite statement?A short document in which the organization describes, per risk category, how much risk it is willing to take, including the corresponding tolerances and escalation agreements.
Getting started with risk appetite in your organization
A clear risk appetite gives direction to every risk discussion in your organization. Defining it doesn't have to be a months-long project: with the right people at the table and a structured approach, you can build a solid foundation in just a few sessions.
Want to see how you can bring risk appetite, risk sessions, and dashboards together in one platform? Schedule a personal demo or start a free 30-day trial today. Prefer to talk things through with an ISO 31000 certified consultant first about drafting your risk appetite statement? That's an option too, just get in touch.
Do you have any questions about this article?
Feel free to contact us via live chat or via
support@riskchallenger.nl






