// BLOG
Risk Appetite, Tolerance and Capacity Getting the Terms Straight
Published 30 July 2026
Risk Appetite, Tolerance and Capacity: Getting the Terms Straight
Illustration for: Risk Appetite, Tolerance and Capacity: Getting the Terms Straight
Ask five risk professionals to distinguish appetite from tolerance and you will get seven answers. The confusion is not academic: when a board signs an appetite statement that operations cannot translate into thresholds, the statement decorates the governance pack and changes nothing. This post pins down the three terms and shows how to cascade them into numbers people can actually work to.
The three terms, defined
- Risk capacity is the maximum risk the organisation can absorb and survive. It is a fact about the balance sheet, regulatory position and operational resilience, not a preference. A firm with £2 million in free reserves cannot “decide” to have capacity for a £10 million loss.
- Risk appetite is the amount and type of risk the organisation wants to take in pursuit of its objectives. It is a choice, set by the board, and it must sit inside capacity with room to spare.
- Risk tolerance is the acceptable variation around the appetite for a specific risk or activity, expressed as measurable thresholds. Tolerances are operational; appetite is strategic.
An analogy that survives contact with executives: capacity is the edge of the cliff, appetite is how close to the edge you choose to build the path, and tolerances are the fences and warning markers that tell you when someone has strayed off the path, well before the edge.
Clifftop illustration showing capacity as the edge, appetite as the path and tolerances as warning signs
The clifftop in one picture. The edge is a fact, the path is a choice, and the signs fire before anyone reaches the edge.
ISO 31000 and the Institute of Risk Management use broadly these distinctions, though vocabulary varies between publications. Do not fight over the dictionary; agree definitions in your own framework document and use them consistently. Inconsistency inside one organisation does far more damage than divergence from any standard.
How boards actually set appetite
The failure mode here is the aspiration statement: “we have a low appetite for cyber risk”. Every board in Britain has low appetite for cyber risk, in the same way everyone has low appetite for rain. It costs nothing to say and guides nothing.
Useful appetite statements have three properties:
- They differentiate. Appetite is not uniform: high for product innovation, moderate for supplier concentration, minimal for safety and regulatory breach. A single organisation-wide appetite level is a sign nobody thought hard.
- They accept something. A statement that accepts no risk anywhere is not an appetite, it is a wish. “We accept up to £250,000 aggregate annual fraud loss as a cost of frictionless customer onboarding” is a real decision with a real trade-off attached.
- They are anchored in capacity. The board should see the capacity analysis (what loss would breach covenants, regulatory minima, or survival) before choosing appetite, so the choice is informed rather than performed.
In practice the risk function drafts, the executive stress-tests against real recent decisions (“would this statement have permitted last year’s warehouse system deferral?”), and the board challenges and owns the result. A statement the board merely noted is not owned. Revisit annually and after any material strategy change, acquisition, or near-miss.
Cascading appetite into tolerances and thresholds
This is where most frameworks stall. The bridge is translation: each appetite statement spawns a small set of measurable tolerances, each tolerance gets a metric, a threshold, an owner and an escalation route.
A workable cascade for a cyber-related appetite statement:
- Appetite (board): “We have minimal appetite for risks that could interrupt customer-facing services for more than 24 hours.”
- Tolerance (executive): recovery time for tier 1 services must not exceed 8 hours; no more than two tier 1 incidents per quarter.
- Thresholds (operational): amber when a DR test misses the 8-hour target or a second tier 1 incident occurs in a quarter; red when a live recovery exceeds 8 hours or a third incident occurs. Amber goes to the CIO within a week; red goes to the risk committee at its next sitting, with a paper.
Cascade flowchart from board appetite through executive tolerance to amber and red thresholds
One board appetite statement cascading into executive tolerances and measurable thresholds, with the escalation route running back up.
Three or four metrics per appetite statement is plenty. I have seen cascades with 40 key risk indicators per statement; nobody looked at any of them. Choose metrics you already collect or can collect cheaply, and accept imperfect proxies over perfect metrics that never get measured.
A worked example: mid-size UK organisation
Take a fictional 800-person UK insurance services firm, £90 million turnover, FCA-regulated, £6 million free capital.
- Capacity: finance modelling shows a single loss above £4 million would breach regulatory capital comfort levels. That is the cliff edge, and it is not negotiable at board level.
- Appetite: the board sets a maximum tolerable single-event loss of £1.5 million, differentiated by category: open to risk in new product lines (accepting up to £500,000 a year in aggregate losses from pricing experiments), cautious on technology change, minimal on conduct and data protection.
- Tolerances, data protection: no more than two reportable personal data breaches a year; 100% of critical suppliers holding customer data assessed annually; encryption exceptions require sign-off at CISO level, capped at ten live exceptions.
- Tolerances, technology change: no more than 4 hours unplanned downtime per quarter on the policy administration platform; change failure rate below 10%.
- Thresholds and escalation: each tolerance is green, amber or red on a monthly dashboard. Amber requires the metric owner to present a recovery plan to the executive risk committee. Red, or amber for two consecutive quarters, goes to the board risk committee. Breach of any tolerance connected to the conduct appetite triggers review within five working days regardless of meeting cycles.
Mock monthly tolerance dashboard with five metrics, owners, thresholds and green, amber and red statuses
A monthly tolerance dashboard for the fictional firm; the red row goes to the board risk committee.
The value shows up in decisions. When the operations director wants to defer the supplier assessment programme to fund a warehouse move, the framework converts a vague argument into a specific one: the deferral will breach a stated tolerance, so it needs a documented, time-limited acceptance at board risk committee level. The framework does not prevent the decision. It makes the decision visible, owned and reversible, which is the entire point.
Common failure modes
- Appetite statements written by the risk team and “noted” by the board. Ownership by signature, not by understanding.
- Tolerances with no escalation route, so breaches are recorded but never discussed.
- Metrics chosen because they are easy rather than meaningful (training completion percentage as the sole proxy for people risk).
- No review loop: appetite set in 2021 still governing a business that has doubled since.
- Treating capacity as a preference. It is arithmetic, and pretending otherwise is how firms discover their real capacity during an incident.
Where to start
Write down your organisation’s capacity first, with finance in the room: the loss sizes that would breach covenants, regulatory thresholds or customer commitments. Then take one risk category that matters, draft a single appetite statement that genuinely accepts something, and derive three measurable tolerances with named owners and an escalation route. Run that one cascade for two quarters before scaling to other categories. A single working thread from board statement to monthly threshold teaches you more about your governance than a complete framework written in one heroic offsite, and it gives the board something concrete to challenge, which is what appetite setting is for.
Run your GRC programme in your own network.
RaptorGRC Community Edition is free — every module, offline licence activation, nothing phones home.
Register / Download Contact us