Guide

How to set risk appetite and tolerance

By the Rukn ERM team · August 2026 · 6 min read

"Be careful with cyber" isn't a risk appetite. Here's how to turn intent into measurable boundaries your team can actually act on.

Risk appetite is one of the most talked-about and least well-defined ideas in risk management. Boards approve statements full of words like "prudent" and "measured" that nobody can act on. The fix is to make appetite measurable — and to connect it to your day-to-day data. Here's how.

Appetite vs tolerance: know the difference

The two terms are often confused. Appetite is how much risk you're willing to take in a category to pursue your objectives — a statement of intent. Tolerance is the acceptable range of variation around that intent — the measurable line. Appetite says "we have minimal appetite for cyber risk"; tolerance says "no critical vulnerability stays open beyond 30 days". You need both.

1. Start from your objectives

Appetite only means something relative to what you're trying to achieve. A company pursuing aggressive growth will have a different appetite for strategic risk than one protecting a stable franchise. Anchor every appetite statement to a business objective; otherwise it's just a mood.

2. Choose an appetite level per category

Work category by category and pick a level on a simple scale — for example: Averse → Minimal → Cautious → Open → Hungry. Most organisations are averse to compliance risk, minimal on cyber, cautious on financial, and open on well-understood strategic bets. Writing one clear sentence per category forces useful conversations about where the real limits are.

3. Make it measurable with thresholds

For each category, attach a tolerance threshold you can actually check: "FX exposure within ±5% of budget", "critical service uptime ≥ 99.5%", "zero material compliance breaches". A boundary you can't measure can't be breached — which means it can't protect you.

4. Attach a metric and an escalation trigger

Tie each threshold to a key risk indicator and define what happens when it's crossed: who is told, and what decision is required. This is the difference between appetite as a document and appetite as a control. If nothing happens when a limit is breached, the limit isn't real.

5. Get it approved — then keep it live

Appetite should be owned and approved at board or risk-committee level, and reviewed at least annually. But the bigger challenge is keeping it connected to reality between reviews. In a spreadsheet, checking risks against appetite is manual and quickly abandoned. In Rukn ERM, appetite and tolerance are set per category and breaches surface automatically as residual risk moves — no one has to remember to check.

A worked example

For operational risk: appetite level Cautious; statement "we accept some operational disruption but protect critical services"; threshold "critical service uptime ≥ 99.5%"; metric "uptime, monitored daily"; escalation "any Sev-1 incident goes to the COO". That's an appetite you can run a business on.

Free risk appetite statement template

Appetite levels, tolerance thresholds, metrics and escalation triggers per category — in Excel, no sign-up.

Get the template See appetite live in Rukn