Knowella

Risk Appetite Statement

States how much risk the organisation is prepared to accept in each domain, so decisions are consistent. Written once and reviewed yearly. Owned by senior management. Without it, every risk acceptance is an individual judgement nobody can defend.

KnowComplyPlanCMP-027Pinned in navigation
Completed by
Owned by senior management
Raised
When the thing being planned is created, and again at the

Summary

In short

  • A risk appetite statement is a plan used in KnowComply that states how much risk the organisation is prepared to accept in each domain, so decisions are consistent. It is built against ISO 31000 cl.5.4 and forms part of the Management System Governance programme.
  • Written once and reviewed yearly. Owned by senior management.
  • The template holds 37 fields across 5 sections.
  • Scoring is statement current, where high is good.
  • ISO 31000 is risk management. Principles and a framework for managing risk of any kind. Guidance rather than certifiable.
  • It connects to the rest of the library: links Enterprise risk, Waivers.

What it is

What it is

What is a risk appetite statement?

A risk appetite statement is a plan used in KnowComply that states how much risk the organisation is prepared to accept in each domain, so decisions are consistent. It is built against ISO 31000 cl.5.4 and forms part of the Management System Governance programme.

When is a risk appetite statement completed?

A risk appetite statement is completed when the thing being planned is created, and again at the stated review interval. Written once and reviewed yearly.

When to use it

When to use it, and when not to

This plan is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.

Use it for

  • The event or activity this plan covers has occurred, or is about to
  • Authorisation is needed before the work can begin
  • A new record is needed; each one gets its own ID in the form RAS-2026-000
  • You are running the Management System Governance programme and this is one of its steps
  • A linked record needs this one to exist: links enterprise risk, waivers

Not for

  • Enterprise Risk Register, which holds the risks that could stop the organisation meeting its objectives, above the level of individual task risk.
  • Risk Acceptance Record, which records a deliberate decision to accept a risk rather than treat it, with who accepted it and for how long.
  • Bow Tie Analysis Record, which maps threats, the top event, consequences and the barriers on each side for a major hazard.
  • Anything outside KnowComply, which belongs in the workspace that owns that process

Standards

What it is built against

ISO 31000Risk management

Principles and a framework for managing risk of any kind. Guidance rather than certifiable.

ISOInternational Organization for Standardization

A voluntary international standard. Widely adopted, often required by customers, and certifiable where a management system standard.

FAQ

Frequently asked questions

What is the risk appetite statement template based on?+

It is built against ISO 31000 cl.5.4. ISO 31000 is risk management. Principles and a framework for managing risk of any kind. Guidance rather than certifiable. ISO is international Organization for Standardization. A voluntary international standard. Widely adopted, often required by customers, and certifiable where a management system standard.

What sections does the risk appetite statement contain?+

There are 5 sections: header, content, application, related records, outcome. Together they hold 37 fields, 32 of which are required.

How often is a risk appetite statement raised?+

A new record is raised when the thing being planned is created, and again at the stated review interval. Each one is given an ID in the form RAS-2026-000, so it can be traced and referenced from other records.

Which programme does the risk appetite statement belong to?+

It is part of Management System Governance. One integrated system rather than four running in parallel and exhausting the same people.

How is a risk appetite statement scored?+

Scoring is statement current. High is good. Scores exist to make the form tell you something, not to produce a percentage for its own sake.

Can the risk appetite statement template be changed?+

Yes. Every field, option, score and conditional rule is editable, and the links to other templates come with it. Most teams install it as it is, run it for a cycle, then adjust.

The agents

What the agents do with it

The form is the easy part. Keeping it current, routing it to the right owner and holding the evidence together is the work that actually slips.

KnowComply

Holds the risk appetite statement library against your registers, routes each record to its owner, and keeps the evidence trail together.

Ella

Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.

This template lives in KnowComplyaudit and governance. Audit programmes, legal register, management review, risk and certification.

Sources

Sources

  • ISO 31000 — Risk management
  • ISO — International Organization for Standardization
Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.