Risk appetite, the line that makes a decision automatic
Risk appetite is the amount and type of risk an organisation is willing to accept in pursuit of its objectives, stated deliberately and approved at board level. In third-party risk it converts judgement into policy: which vendors may be onboarded, which findings block a contract, and which exposures require escalation.
Making it usable
Most appetite statements fail the same way: they are written as sentiment. "We have a low appetite for cyber risk" cannot resolve a single decision, because every party to the argument agrees with it and still disagrees about the vendor.
A usable statement is expressed as thresholds that decide things. No critical vendor may be onboarded without a current independent assurance report. High findings on a critical vendor must be remediated within 30 days or escalated to the risk committee. No single provider may support more than a stated share of critical business services. Each of those settles an argument in advance, which is the entire purpose — appetite exists so that the same decision does not get relitigated by whoever is in the room.
Appetite, tolerance and where they bite
Appetite is what you are willing to take on; tolerance is how far you will let things drift beyond it before acting. Both are only real if breaching them triggers something. An appetite statement with no consequence is a mission statement, and the tell is a risk register full of accepted exceptions that nobody remembers approving.
In practice, appetite is enforced at three points: onboarding, where it decides whether a vendor may be used at all; residual risk acceptance, where it decides who may sign; and reporting, where indicators are set against it so a breach is visible without anyone having to raise it.
Common questions
What is the difference between risk appetite and risk tolerance?
How do you write a third-party risk appetite statement?
Who sets risk appetite?
Related terms and pages
Definitions are the easy part. Evidence is not.
See what your vendors actually expose — scored, monitored and evidenced in one place.