"Be careful with cyber" isn't a risk appetite. Here's how to turn intent into measurable boundaries your team can actually act on.
Risk appetite is one of the most talked-about and least well-defined ideas in risk management. Boards approve statements full of words like "prudent" and "measured" that nobody can act on. The fix is to make appetite measurable — and to connect it to your day-to-day data. Here's how.
The two terms are often confused. Appetite is how much risk you're willing to take in a category to pursue your objectives — a statement of intent. Tolerance is the acceptable range of variation around that intent — the measurable line. Appetite says "we have minimal appetite for cyber risk"; tolerance says "no critical vulnerability stays open beyond 30 days". You need both.
Appetite only means something relative to what you're trying to achieve. A company pursuing aggressive growth will have a different appetite for strategic risk than one protecting a stable franchise. Anchor every appetite statement to a business objective; otherwise it's just a mood.
Work category by category and pick a level on a simple scale — for example: Averse → Minimal → Cautious → Open → Hungry. Most organisations are averse to compliance risk, minimal on cyber, cautious on financial, and open on well-understood strategic bets. Writing one clear sentence per category forces useful conversations about where the real limits are.
For each category, attach a tolerance threshold you can actually check: "FX exposure within ±5% of budget", "critical service uptime ≥ 99.5%", "zero material compliance breaches". A boundary you can't measure can't be breached — which means it can't protect you.
Tie each threshold to a key risk indicator and define what happens when it's crossed: who is told, and what decision is required. This is the difference between appetite as a document and appetite as a control. If nothing happens when a limit is breached, the limit isn't real.
Appetite should be owned and approved at board or risk-committee level, and reviewed at least annually. But the bigger challenge is keeping it connected to reality between reviews. In a spreadsheet, checking risks against appetite is manual and quickly abandoned. In Rukn ERM, appetite and tolerance are set per category and breaches surface automatically as residual risk moves — no one has to remember to check.
For operational risk: appetite level Cautious; statement "we accept some operational disruption but protect critical services"; threshold "critical service uptime ≥ 99.5%"; metric "uptime, monitored daily"; escalation "any Sev-1 incident goes to the COO". That's an appetite you can run a business on.
Appetite levels, tolerance thresholds, metrics and escalation triggers per category — in Excel, no sign-up.
Get the template See appetite live in Rukn