Methodology

Risk appetite, tolerance and criteria

Several pages in this Knowledge Base end at the same doorstep: the reporting percentile "is an appetite decision", the remaining risk after treatment must be "within appetite", a matrix band means nothing until someone decides which bands are acceptable. This page is the doorstep. Three defined terms do the work, they are set by different people, and keeping them straight is most of the discipline.

The three definitions

All three come from the risk-management vocabulary standard, ISO 31073:2022:

  • Risk appetite (3.3.27): the "amount and type of risk that an organization is willing to pursue or retain". Both halves matter. Amount and type: appetite is not one number, an organisation can be hungry for product risk and starved of safety risk. Pursue or retain: appetite covers risk you go looking for, not just risk you put up with.
  • Risk tolerance (3.3.28): the "organization's or interested party's readiness to bear the residual risk in order to achieve its objectives", with a note that tolerance "can be influenced by legal or regulatory requirements". Tolerance is about the risk that remains after treatment, and it can be forced on you: a regulator's limit is a tolerance you did not choose.
  • Risk criteria (3.3.6): the "terms of reference against which the significance of risk is evaluated". Criteria are the measuring instrument: the scales, thresholds and rules that let you say whether a particular risk is significant. The companion definition of risk evaluation (3.3.25) closes the circuit: "comparing the results of risk analysis with risk criteria to determine whether the risk is acceptable or tolerable".

The relationship, in one breath: appetite is a policy statement about how much and what kind of risk the organisation wants; criteria translate that policy into something a risk can actually be measured against; tolerance is the bearable envelope around individual residual risks, sometimes set for you by law. ISO 31000:2018 clause 5.2 supplies the causal arrow: among the outcomes top management's leadership is meant to secure is that the organisation "establish the amount and type of risk that may or may not be taken to guide the development of risk criteria". Appetite guides criteria, not the other way around.

Who sets what

ISO 31000:2018 5.2 places accountability at the top: "top management is accountable for managing risk while oversight bodies are accountable for overseeing risk management", and establishing the amount and type of risk to be taken is one of the outcomes the clause says their leadership should deliver. The RMIA's governance domain says the same in competency form: risk appetite approaches and appetite statements are developed for "senior management and Board approval".

The Institute of Operational Risk's sound-practice guidance draws the operational split well. It is honest that "there are no universal definitions of either risk appetite or risk tolerance", then lands the useful distinction: appetite is "a high-level strategic decision" about the balance an organisation is prepared to maintain between the cost of controlling risk and the cost of risk events, and it belongs with the board ("Boards should be more involved in the process of setting risk appetite"). Tolerance, by contrast, is "a specific benchmark for the acceptability of a given… exposure": the green/amber/red thresholds on individual metrics. Business managers "do not, normally, get involved" in setting appetite, but they do help set those per-exposure thresholds, with one rule: tolerances "should not contradict the overarching operational risk appetite".

So the working answer to "who sets what": the board owns appetite, management translates it into criteria and per-exposure tolerances, and the practitioner's job is to make sure the three never contradict each other.

What good criteria look like

Clause 6.3.4 of ISO 31000:2018 is the standard's specification for criteria, and three of its sentences carry most of the weight. The organisation "should specify the amount and type of risk that it may or may not take, relative to objectives". Criteria "should reflect the organization's values, objectives and resources and be consistent with policies and statements about risk management". And criteria "are dynamic and should be continually reviewed and amended, if necessary": a criteria table set in 2019 and never revisited is not conservative, it is stale.

The clause then lists what setting criteria requires you to decide, including "how consequences (both positive and negative) and likelihood will be defined and measured", "how the level of risk is to be determined", and "how combinations and sequences of multiple risks will be taken into account". Notice that this is precisely the content of a risk matrix: the likelihood scale, the consequence scale and the band boundaries are risk criteria made visible. A matrix is not a neutral chart; it is your criteria, drawn.

Where this lands in Monty & Co

  • The matrix: editing the 5×5 scales and band colours in Beau-Tie is criteria-writing. That is why the product insists the shipped matrix is "a starting point, not a recommendation": your criteria should reflect your objectives, not ours.
  • The appetite marker: a bow tie can carry an optional appetite rating alongside residual and target, so the diagram shows not just where the risk is and where treatment should take it, but where the organisation said it was willing to be. The matrix page covers reading the triple.
  • The funded percentile: when PRQ asks which percentile funds the contingency, or Event Risk asks which percentile to report, the tool is asking an appetite question in quantitative clothes. Funding at P50 accepts a coin-flip chance of exceedance; funding at P90 pays for more certainty up front. The right level is whatever your organisation's appetite and any mandated criteria say it is, which is why the Monte Carlo page refuses to name a universally "right" number.

Sources

  • ISO 31073:2022, 3.3.27 (risk appetite), 3.3.28 (risk tolerance), 3.3.6 (risk criteria), 3.3.25 (risk evaluation).
  • AS/NZS ISO 31000:2018, clause 5.2 (leadership, who establishes the amount and type of risk) and 6.3.4 (defining risk criteria). Read in full for this page.
  • Institute of Operational Risk (IRM Group), "Operational Risk Appetite and Tolerance", sound-practice guidance. Its appetite definition differs in wording from ISO 31073's; this page uses ISO's definitions and the IOR's governance split.
  • RMIA Risk Management Body of Knowledge, Domain 6 (Governance), v2.0.