Skip to main content
Category: Enterprise Risk Management

Risk Appetite Statement

Also known as: RAS, Risk appetite declaration
Simply put

A Risk Appetite Statement is a formal document in which an organization sets out the amount and type of risk it is willing to accept as it pursues its objectives. It gives decision-makers a shared reference point for judging whether a given risk falls within what the organization has chosen to take on. In many organizations it is approved at a senior governance level, such as the board.

Formal definition

A Risk Appetite Statement is a formal, typically board- or senior-governance-approved declaration articulating the types and broad amount of risk an organization is willing to accept in pursuit of its strategic objectives and value creation. It operationalizes the concept of risk appetite, defined in NIST's glossary as the types and amount of risk an organization is willing to accept in its pursuit of value, and by the IRM as the amount and type of risk an organization is willing to take to meet its strategic objectives, into a governance artifact that guides risk-taking decisions and informs the setting of more granular thresholds. The statement should be distinguished from risk tolerance, which expresses the acceptable variation or specific limits around particular objectives or risk categories; the Risk Appetite Statement generally expresses appetite at a broad, aggregate level, while tolerances translate that appetite into measurable boundaries. This entry addresses the concept and purpose of the statement rather than drafting methodology, quantification techniques, or sector-specific regulatory requirements, which vary by jurisdiction, industry, and organization; for example, in banking such statements may be subject to particular supervisory expectations that do not apply uniformly to other sectors.

Why it matters

A Risk Appetite Statement gives an organization a shared reference point for deciding whether a given risk falls within the bounds it has consciously chosen to accept. Without such a statement, risk-taking decisions can become inconsistent across functions and business units, with individuals applying their own implicit judgments about how much risk is acceptable. By articulating the types and broad amount of risk the organization is willing to accept in pursuit of its objectives, the statement helps align risk-taking with strategy and supports more defensible, consistent decision-making at the points where risks are actually taken on.

Because the statement is typically approved at a senior governance level, such as the board, it also connects strategic direction to operational risk management. It provides the anchor from which more granular thresholds and tolerances can be derived, translating a broad appetite into measurable boundaries around particular objectives or risk categories. This linkage matters for governance accountability: it signals that the organization's leadership has taken an explicit position on the risks it is prepared to bear, rather than leaving that determination implicit or unexamined.

The significance of a Risk Appetite Statement varies by context. In some sectors, notably banking, such statements may be subject to particular supervisory expectations that do not apply uniformly to other sectors. Organizations should therefore treat the statement as a governance artifact whose form, formality, and regulatory weight depend on jurisdiction, industry, and organizational circumstances, rather than assuming a single universal standard applies.

Who it's relevant to

Boards and senior governance bodies
Because the statement is commonly approved at a senior governance level, such as the board, these bodies own the explicit position it expresses on the types and amount of risk the organization is willing to accept. It gives them a formal instrument for aligning risk-taking with strategic objectives and for demonstrating that leadership has taken a deliberate position on the risks the organization is prepared to bear.
Risk managers
Risk management professionals typically use the Risk Appetite Statement as the anchor from which more granular thresholds and tolerances are derived. It provides the broad, aggregate expression of appetite that they translate into the measurable boundaries used to assess whether specific risks fall within acceptable bounds.
Decision-makers across business functions
Those making day-to-day decisions that involve taking on risk benefit from a shared reference point for judging whether a given risk falls within what the organization has chosen to accept. This supports greater consistency in risk-taking decisions across the organization.
Compliance and governance professionals in regulated sectors
In some sectors, notably banking, Risk Appetite Statements may be subject to particular supervisory expectations that do not apply uniformly elsewhere. Professionals in such contexts need to be attentive to how sector-specific regulatory requirements, which vary by jurisdiction and industry, shape the form and content of the statement.

Inside RAS

Purpose and scope statement
An articulation of why the risk appetite statement exists and the organizational boundaries it applies to, typically linking appetite to the entity's strategy and objectives. Scope may vary by jurisdiction, sector, and organizational size.
Qualitative appetite statements
Narrative expressions of the types and levels of risk the organization is willing to accept in pursuit of its objectives, often expressed by risk category (for example, strategic, financial, operational, compliance, or reputational).
Quantitative measures and thresholds
Where feasible, metrics, limits, or ranges that give effect to the qualitative appetite. These commonly connect to risk tolerance levels, though appetite and tolerance are distinct concepts and should be distinguished within the document.
Distinction between appetite and tolerance
A clear delineation that risk appetite is the broad amount of risk an organization is willing to take, while risk tolerance is the acceptable variation around specific objectives or limits. Blurring the two is a common source of confusion.
Governance and ownership
Identification of the bodies and roles responsible for setting, approving, and overseeing the statement, typically involving the board or a delegated committee, with management responsible for operating within it. This reflects governance decision rights rather than day-to-day risk treatment.
Review and revision provisions
Provisions describing how frequently the statement is reviewed and under what circumstances it is revisited, such as material changes in strategy, environment, or objectives.

Common questions

Answers to the questions practitioners most commonly ask about RAS.

Is a risk appetite statement the same as a risk tolerance?
No. A risk appetite statement typically expresses, at a broad and strategic level, the amount and type of risk an organization is willing to pursue or accept in pursuit of its objectives. Risk tolerance is generally narrower, describing the acceptable level of variation or deviation around specific objectives, risks, or metrics. In many frameworks, appetite sets the overall direction while tolerance operationalizes it into measurable boundaries. Conflating the two tends to obscure the difference between strategic intent and the specific thresholds used to monitor and control individual risks.
Does having a risk appetite statement mean the organization is trying to eliminate risk?
Not typically. A risk appetite statement is not a declaration that risk should be minimized or avoided. It commonly articulates the risk the organization is willing to take on to achieve its objectives, which may include accepting meaningful risk in some areas while limiting it in others. Treating the statement as a mandate for risk elimination misreads its purpose, which is to guide risk-taking decisions rather than to suppress them.
Who is typically responsible for approving a risk appetite statement?
In many governance structures, the board or an equivalent oversight body approves the risk appetite statement, often on the recommendation of executive management and with input from the risk management function. This reflects the statement's role as a governance instrument that sets direction for management. Practices vary by jurisdiction, sector, and organization size, and specific approval and review arrangements should be confirmed against applicable regulatory expectations and internal governance arrangements.
How is a risk appetite statement connected to day-to-day decision-making?
A risk appetite statement is commonly translated into more specific tolerances, limits, and key risk indicators so that it can inform operational and management decisions. Without this translation, the statement may remain aspirational and difficult to apply in practice. The linkage between the high-level statement and measurable thresholds is what typically allows management to assess whether particular activities or exposures fall within accepted boundaries. This entry does not cover specific tooling or implementation methods.
How often should a risk appetite statement be reviewed?
Review frequency varies by organization, sector, and jurisdiction. Many organizations review the statement periodically, commonly on a defined cycle, and also revisit it when there are significant changes to strategy, the operating environment, the risk profile, or applicable regulatory requirements. The appropriate cadence should be set in line with governance arrangements and any relevant supervisory expectations rather than a fixed universal interval.
How can an organization tell whether it is operating within its stated risk appetite?
Monitoring against appetite generally relies on the tolerances, limits, and indicators derived from the statement, together with reporting that compares actual exposures to those boundaries. Where exposures approach or exceed defined thresholds, escalation and response processes are typically triggered. It is important to distinguish this monitoring, which is a management activity, from independent assurance over the appetite framework, which is commonly performed by functions such as internal audit to preserve objectivity.

Common misconceptions

A risk appetite statement and risk tolerance are the same thing.
They are related but distinct. Appetite typically expresses the broad level and types of risk an organization is willing to take in pursuit of objectives, whereas tolerance commonly refers to the acceptable variation around specific objectives or limits. A statement may reference both, but conflating them undermines its usefulness.
A risk appetite statement is primarily a compliance document.
It is chiefly a governance instrument that expresses board and management direction on risk-taking aligned to strategy. While it may inform compliance activities, its role spans governance and risk management rather than adherence to external law alone.
Setting a risk appetite statement guarantees that the organization will stay within acceptable risk levels.
The statement articulates intended limits and preferences; it does not by itself ensure outcomes. Its effectiveness depends on how it is operationalized through controls, monitoring, and reporting, and on the accuracy of the underlying risk information.

Best practices

Explicitly distinguish risk appetite from risk tolerance within the document to avoid conflation, and define how the two relate to specific objectives and limits.
Align appetite statements with the organization's strategy and objectives so that expressed risk-taking supports, rather than contradicts, stated goals.
Combine qualitative narrative with quantitative thresholds where measurement is feasible, while acknowledging that not all risk categories lend themselves to precise metrics.
Clarify governance roles, specifying which body sets and approves the statement and confirming that management operates within it, keeping oversight distinct from day-to-day risk treatment.
Establish a defined review cadence and triggers for revision, such as material changes in strategy, environment, or objectives.
Tailor the statement to the organization's jurisdiction, sector, and size rather than treating any given formulation as universal.
Promotional banner for the Pentest Readiness checklist download