TPRM glossary

Risk appetite, the line that makes a decision automatic

Risk appetite is the amount and type of risk an organisation is willing to accept in pursuit of its objectives, stated deliberately and approved at board level. In third-party risk it converts judgement into policy: which vendors may be onboarded, which findings block a contract, and which exposures require escalation.

Making it usable

Most appetite statements fail the same way: they are written as sentiment. "We have a low appetite for cyber risk" cannot resolve a single decision, because every party to the argument agrees with it and still disagrees about the vendor.

A usable statement is expressed as thresholds that decide things. No critical vendor may be onboarded without a current independent assurance report. High findings on a critical vendor must be remediated within 30 days or escalated to the risk committee. No single provider may support more than a stated share of critical business services. Each of those settles an argument in advance, which is the entire purpose — appetite exists so that the same decision does not get relitigated by whoever is in the room.

Appetite, tolerance and where they bite

Appetite is what you are willing to take on; tolerance is how far you will let things drift beyond it before acting. Both are only real if breaching them triggers something. An appetite statement with no consequence is a mission statement, and the tell is a risk register full of accepted exceptions that nobody remembers approving.

In practice, appetite is enforced at three points: onboarding, where it decides whether a vendor may be used at all; residual risk acceptance, where it decides who may sign; and reporting, where indicators are set against it so a breach is visible without anyone having to raise it.

Common questions

What is the difference between risk appetite and risk tolerance?
Appetite is the level of risk you are willing to accept in pursuit of objectives; tolerance is the acceptable variation around it before action is required. Appetite is set deliberately at board level, tolerance defines the trigger point where drift stops being tolerated.
How do you write a third-party risk appetite statement?
Express it as thresholds that decide something: minimum assurance for each vendor tier, remediation SLAs by finding severity, limits on concentration in a single provider, and the escalation point for exceptions. If a statement cannot resolve a specific onboarding argument, it is sentiment rather than appetite.
Who sets risk appetite?
The board or an equivalent governing body, on advice from risk and the business. It cannot be set by the risk function alone, because appetite is a statement about what the organisation is prepared to trade for commercial benefit — a decision that belongs to the people accountable for that trade.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.