What this is
What is a risk appetite statement?
What is a risk appetite statement?
It is a written position, set by senior management, on how much risk the organisation will accept in each domain — financial, safety, environmental, reputational — before that risk needs escalating or treating further. It exists so that risk acceptance decisions are made against a stated position rather than an individual's private judgement on the day.
How is risk appetite different from risk tolerance?
Appetite is the strategic position — how much risk the organisation wants to carry in pursuit of its objectives. Tolerance is the operational boundary around a specific risk or metric, expressed as a threshold that triggers action. Appetite sets the direction; tolerance sets the trip wire. A statement that only states appetite in general terms, without tolerance thresholds beneath it, cannot be applied to a real decision.
Why does appetite need to be quantified rather than just described in words?
A qualitative appetite statement — 'we are cautious on safety risk' — cannot be tested against a real decision because two people can read it differently. Quantified thresholds, even approximate ones, let a manager check a specific risk against a number rather than a feeling, and let an auditor check whether the organisation actually behaved the way the statement says it would.
Scope
When is a risk appetite statement required?
This template sets the criteria other risk records are judged against. Using it to record an individual decision, or to hold the risks themselves, produces a document that can't do either job properly.
Use this template when
- Setting or refreshing the organisation's risk position, typically annually or after a material change in strategy
- A senior leadership or board cycle requires a documented statement of risk appetite before other risk governance work can proceed
- An acceptance or investment decision needs a stated appetite to test against, and none currently exists or the existing one is out of date
- A new domain of risk (a new site, a new product line, a new regulatory exposure) needs its own appetite position added
- The statement is being checked against recent decisions as part of a scheduled review
Do not use it for
- Enterprise Risk Register, which holds the risks themselves, above the level of individual task risk — the appetite statement sets the criteria the register is judged against, it doesn't list the risks.
- Risk Acceptance Record, which documents one specific decision to accept a named risk — the appetite statement is the standing position that decision gets tested against, not the decision itself.
- Bow Tie Analysis Record, which maps a single major hazard's threats, consequences and barriers — a hazard-level control review, not an organisation-wide risk position.
- Site- or task-level risk assessments, which sit far below the strategic level this statement is written at
- A values or mission statement — appetite is operational and testable, not aspirational language about being 'safety first'
Compliance mapping
Which ISO 31000 cl.5.4 requirements does this satisfy?
ISO 31000 cl.5.4 sits inside the framework clause, not the process clause — it's about designing risk management into how the organisation runs, which is why appetite has to reach into ownership, decision-making and review, not just sit as a policy paragraph.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 31000 cl.5.2 | Leadership demonstrably owns the appetite position, not just signs it | Header |
| ISO 31000 cl.6.3 | Appetite is stated per domain in usable, wherever possible quantified terms | Content |
| ISO 31000 cl.5.4 | Zero-tolerance areas, escalation triggers and authority levels are named so the statement operates without further interpretation | Content |
| ISO 31000 cl.5.3 | The statement is actually used in risk acceptance and investment decisions, not filed separately from them | Application |
| ISO 31000 cl.5.6 | Appetite is tested against recent real decisions, not just re-read at renewal | Application |
| ISO 31000 cl.6.5 | The linked enterprise risk register shows the appetite statement actually governing treatment and acceptance calls | Related records |
| ISO 31000 cl.5.7 | The statement is kept current, consistently applied and feeds into management review | Outcome |
What it does not cover
- Zero Tolerance Areas Named, which if left blank or marked partial means there's no hard boundary in the statement, so no acceptance decision can ever be shown to have crossed one.
- Tolerance Thresholds Quantified Where Possible, which without a number reduces the whole domain to a matter of opinion the day a real decision needs testing.
- Escalation Triggers Defined, which if absent means a risk approaching the edge of appetite has nowhere defined to go before it's already been accepted.
- Tested Against Recent Decisions, which if marked 'No' means the statement has never been checked against how the organisation actually behaves, so its currency is unverified.
- Consistent With Actual Behaviour, which if marked 'No' or 'Partly' is the single clearest sign the statement is aspirational rather than operative.
Global
Risk Appetite Statement requirements by country
ISO 31000 itself is voluntary guidance with no certification body behind it, so the statement's practical weight comes from where it intersects mandatory disclosure or duty-of-care obligations.
UK Corporate Governance Code, Provision 28
Listed companies must describe their principal risks and how the board has assessed the company's risk appetite as part of the annual report.
For a UK listed entity, the appetite statement isn't just internal governance hygiene — it's the evidence base for a public disclosure the board is accountable for.
COSO Enterprise Risk Management Framework (2017)
COSO treats risk appetite as a named component of ERM and expects it to be articulated, communicated and monitored, though it is not itself a statutory requirement.
US organisations subject to SOX-adjacent governance expectations or investor scrutiny are typically expected to evidence an appetite statement even without a specific statute naming it.
ISO 31000:2018 cl.5.4
A voluntary, non-certifiable framework clause on designing risk management, including establishing risk criteria consistent with objectives.
There is no external auditor who will fail an organisation for a weak appetite statement under ISO 31000 alone — the discipline has to be self-imposed and tested against real decisions.
How to complete it
How to complete a risk appetite statement, step by step
Filling in every field is the easy part. The judgement calls below are what decide whether the finished statement can actually be tested against a real decision six months from now.
A single line covering all safety risk is too coarse to be useful once the organisation has more than one hazard profile across its sites; splitting appetite by domain and, where risk profiles differ materially, by site or activity, is what makes the statement usable rather than decorative.
Quantify wherever a number exists to quantify with — loss values, frequency rates, headcount exposure. Where no number is honest, name a specific, observable boundary condition instead of a general sentiment; a boundary that can't be pointed to in a real case isn't a threshold.
Approval has to sit above the level that benefits from a lenient appetite, and above the level that will be making acceptance decisions against it day to day — otherwise the same manager is effectively setting and applying their own limit.
Pull a sample of recent risk acceptance and investment decisions and check each one against the stated appetite line by line; a statement that passes this test on paper but fails against three of the last five real decisions needs rewriting, not defending.
What auditors find
Most common risk appetite statement findings
These are the gaps that show up most often when an appetite statement is checked against how the organisation actually behaves, not just against the template.
| Finding | Clause | What fixes it |
|---|---|---|
| Appetite is described in general prose with no per-domain breakdown | ISO 31000 cl.6.3 | Rewrite as a short table: domain, stated appetite, quantified threshold where possible, escalation trigger. |
| No zero-tolerance areas are named anywhere in the statement | ISO 31000 cl.5.4 | Name the specific control failures or outcomes the organisation will never accept, regardless of cost or schedule pressure. |
| The statement has not been checked against a real acceptance decision since it was issued | ISO 31000 cl.5.6 | Pull the last three risk acceptance records and test each against the current statement before the next review is signed off. |
| Approval sits at a level that also owns the risk being accepted | ISO 31000 cl.5.4 | Move sign-off to the next level up, and record that independence explicitly on the statement's approval line. |
| Escalation triggers exist for safety domains but not for financial or reputational ones | ISO 31000 cl.5.4 | Add a named trigger and route for every domain the statement covers, not just the highest-profile one. |
| The statement was reviewed on the anniversary date but not after a significant loss event in between | ISO 31000 cl.5.7 | Add an event-triggered review clause alongside the annual cycle, and back-date a review against the event that was missed. |
Case in point
Case in point: an appetite statement that never met a real decision
A distribution business carried a risk appetite statement that had been signed annually for four years, each time with 'Yes' against consistently applied and no supporting evidence attached. When a warehouse manager accepted a fire-loading risk that would have breached the stated financial threshold by a wide margin, nobody had checked the acceptance against the statement — because nobody ever had, on any prior decision.
The statement was accurate on paper and useless in practice. Rewriting it after the event added nothing the organisation didn't already know; what was missing was the habit of testing real decisions against it, which is the only thing that makes an appetite statement worth more than the page it's printed on.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-027
- Archetype
- Plan
- Record ID
- RAS-2026-000
- Scoring
- Statement current
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 31000 cl.5.4
- Links
- Links Enterprise risk, Waivers
- Tags
- Governance, Risk
- Sections
- 5
- Fields
- 37
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 3
Header
11 fieldsStatement ID*
Auto sequence. Format RAS-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Version*
Issue Date*
Next Review Due*
Owner*
Approved By*
Approved At Senior Level*
- Yes3 pts
- No0 pts
Without It Every Acceptance Is A Personal Judgement
When somebody accepts a risk with no stated appetite behind them, they are exposed personally and the decision cannot be defended later.
Content
6 fieldsAppetite Stated By Domain*
- Yes3 pts
- Partly1 pt
- No0 pts
Expressed In Usable Terms*
- Yes3 pts
- Partly1 pt
- No0 pts
Zero Tolerance Areas Named*
- Yes3 pts
- Partly1 pt
- No0 pts
Tolerance Thresholds Quantified Where Possible*
- Yes3 pts
- Partly1 pt
- No0 pts
Escalation Triggers Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Authority Levels Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Application
6 fieldsUsed In Risk Acceptance Decisions*
- Yes3 pts
- Partly1 pt
- No0 pts
Used In Investment Decisions*
- Yes3 pts
- Partly1 pt
- No0 pts
Managers Understand It*
- Yes3 pts
- Partly1 pt
- No0 pts
Consistent With Actual Behaviour*
- Yes3 pts
- Partly1 pt
- No0 pts
Tested Against Recent Decisions*
- Yes3 pts
- Partly1 pt
- No0 pts
Reviewed After Significant Events*
- Yes3 pts
- Partly1 pt
- No0 pts
Related records
1 fieldEnterprise Risk Register ID
The register this appetite statement governs.
Links to CMP-026 Register ID
Outcome
13 fieldsStatement Current*
- Yes3 pts
- Overdue0 pts
Consistently Applied*
- Yes3 pts
- Partly1 pt
- No0 pts
Communicated To Managers*
- Yes3 pts
- Partly1 pt
- No0 pts
Feeds Management Review*
- Yes3 pts
- Partly1 pt
- No0 pts
Next Review Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-027 · record IDs look like RAS-2026-000 · Links Enterprise risk, Waivers
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The statement itself is short. What actually takes ongoing effort is checking it against real decisions, routing exceptions to the right level, and catching when it's gone stale.
Holds the appetite statement against the enterprise risk register and acceptance records, and flags when a decision has gone through without being tested against the current position.
Feeds safety-domain incident and near-miss data back into the appetite review, so the safety line of the statement is tested against what's actually happening on site, not just re-signed from memory.
Surfaces environmental exceedances and permit near-misses against the environmental appetite line, so that domain doesn't drift unnoticed between annual reviews.

Coordinates the review across domains, rolls exceptions and overdue tests into one view for the board cycle, and holds every write for approval before it touches the record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Risk Appetite Statement definitions and key terms
- Risk appetite
- The amount and type of risk an organisation is willing to pursue or retain in order to meet its objectives, set at a strategic level by senior management.
- Risk tolerance
- The specific, measurable boundary around a risk or metric that operationalises appetite — the number or condition that triggers escalation or action.
- Risk criteria
- The terms of reference an organisation uses to evaluate the significance of risk, including how likelihood and consequence are scored and combined.
- Escalation trigger
- A defined condition or threshold that, once met, requires a decision to be referred to a higher level of authority than the one that would normally make it.
- Residual risk
- The risk remaining after treatment or controls have been applied, which is what a risk acceptance decision is actually measured against.
FAQ
Frequently asked questions about risk appetite statement
Does every organisation need a formal risk appetite statement?+
Not by law in most sectors, but any organisation making risk acceptance decisions without one is doing so on an ad hoc, undocumented basis. Once decisions start being challenged after the fact — by a regulator, an insurer, or an incident investigation — the absence of a statement becomes the finding.
Can risk appetite differ by site or business unit?+
Yes, and for most organisations it should. A single group-wide appetite statement that ignores real differences in hazard profile, regulatory exposure or maturity between sites ends up too vague to apply anywhere specifically.
What happens if a decision falls outside the stated appetite?+
It should trigger the escalation route named in the statement, going to a decision-maker at or above the level the statement specifies — it should not be quietly approved at the original level with a note that appetite was exceeded.
How often should the statement actually be reviewed?+
At minimum annually, but also immediately after any event that tests it — a significant loss, a near miss, a material change in strategy or regulatory environment. An appetite statement reviewed only on the calendar and never after an event is reviewing the wrong trigger.
Who should sign the appetite statement?+
Senior management, at a level that sits above the day-to-day owners of the risks being governed. A statement signed only by the risk function without line management ownership tends to be ignored the first time it's inconvenient.
Does the statement need to name specific numbers?+
Wherever a defensible number exists, yes. Where it genuinely doesn't, name an observable condition instead — but avoid defaulting to vague language purely because quantifying is harder; that's usually the domain that needs the most discipline.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Management System Governance
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
More in Risk Governance
Enterprise Risk Register
Holds the risks that could stop the organisation meeting its objectives, above the level of individual task risk
Risk Acceptance Record
Records a deliberate decision to accept a risk rather than treat it, with who accepted it and for how long
Bow Tie Analysis Record
Maps threats, the top event, consequences and the barriers on each side for a major hazard
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 31000:2018 cl.5.4 — Design of the framework for managing risk
- ISO 31000:2018 cl.6.3 — Scope, context and criteria
- ISO 31000:2018 cl.5.6 — Evaluation
- UK Corporate Governance Code (2018), Provision 28
- COSO Enterprise Risk Management Framework (2017) — Risk Appetite component
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.