Knowella

Risk Appetite Statement

The recurring failure isn't skipping the statement — it's writing one for the audit file and never using it. A document that names no zero-tolerance areas, no quantified thresholds and no escalation triggers can't actually stop a bad acceptance decision. Six months later someone signs off a risk nobody would have approved, and there's no appetite statement precise enough to have caught it.

KnowComplyPlanCMP-027Pinned in navigation37 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 31000 cl.5.4
Workspace
KnowComply
Form type
Plan
Owner
Senior management, reviewed annually
Governs
Every risk acceptance and investment decision

The short version

  • A risk appetite statement is only useful if it is granular enough to decide a real case; a single organisation-wide sentence about being 'risk averse' settles nothing.
  • Zero-tolerance areas and quantified thresholds are what separate a governance document from a values statement — without them the appetite statement cannot be breached, so it cannot be enforced.
  • The statement has to be tested against actual recent decisions at each review, because appetite that isn't reflected in behaviour has already lapsed regardless of what the document says.
  • It is built against ISO 31000 cl.5.4, which is guidance rather than a certifiable requirement — the discipline comes from how the organisation uses it, not from an external auditor checking a box.

What this is

What is a risk appetite statement?

What is a risk appetite statement?

It is a written position, set by senior management, on how much risk the organisation will accept in each domain — financial, safety, environmental, reputational — before that risk needs escalating or treating further. It exists so that risk acceptance decisions are made against a stated position rather than an individual's private judgement on the day.

How is risk appetite different from risk tolerance?

Appetite is the strategic position — how much risk the organisation wants to carry in pursuit of its objectives. Tolerance is the operational boundary around a specific risk or metric, expressed as a threshold that triggers action. Appetite sets the direction; tolerance sets the trip wire. A statement that only states appetite in general terms, without tolerance thresholds beneath it, cannot be applied to a real decision.

Why does appetite need to be quantified rather than just described in words?

A qualitative appetite statement — 'we are cautious on safety risk' — cannot be tested against a real decision because two people can read it differently. Quantified thresholds, even approximate ones, let a manager check a specific risk against a number rather than a feeling, and let an auditor check whether the organisation actually behaved the way the statement says it would.

Scope

When is a risk appetite statement required?

This template sets the criteria other risk records are judged against. Using it to record an individual decision, or to hold the risks themselves, produces a document that can't do either job properly.

Use this template when

  • Setting or refreshing the organisation's risk position, typically annually or after a material change in strategy
  • A senior leadership or board cycle requires a documented statement of risk appetite before other risk governance work can proceed
  • An acceptance or investment decision needs a stated appetite to test against, and none currently exists or the existing one is out of date
  • A new domain of risk (a new site, a new product line, a new regulatory exposure) needs its own appetite position added
  • The statement is being checked against recent decisions as part of a scheduled review

Do not use it for

  • Enterprise Risk Register, which holds the risks themselves, above the level of individual task risk — the appetite statement sets the criteria the register is judged against, it doesn't list the risks.
  • Risk Acceptance Record, which documents one specific decision to accept a named risk — the appetite statement is the standing position that decision gets tested against, not the decision itself.
  • Bow Tie Analysis Record, which maps a single major hazard's threats, consequences and barriers — a hazard-level control review, not an organisation-wide risk position.
  • Site- or task-level risk assessments, which sit far below the strategic level this statement is written at
  • A values or mission statement — appetite is operational and testable, not aspirational language about being 'safety first'

Compliance mapping

Which ISO 31000 cl.5.4 requirements does this satisfy?

ISO 31000 cl.5.4 sits inside the framework clause, not the process clause — it's about designing risk management into how the organisation runs, which is why appetite has to reach into ownership, decision-making and review, not just sit as a policy paragraph.

ClauseRequirementWhere it lands
ISO 31000 cl.5.2Leadership demonstrably owns the appetite position, not just signs itHeader
ISO 31000 cl.6.3Appetite is stated per domain in usable, wherever possible quantified termsContent
ISO 31000 cl.5.4Zero-tolerance areas, escalation triggers and authority levels are named so the statement operates without further interpretationContent
ISO 31000 cl.5.3The statement is actually used in risk acceptance and investment decisions, not filed separately from themApplication
ISO 31000 cl.5.6Appetite is tested against recent real decisions, not just re-read at renewalApplication
ISO 31000 cl.6.5The linked enterprise risk register shows the appetite statement actually governing treatment and acceptance callsRelated records
ISO 31000 cl.5.7The statement is kept current, consistently applied and feeds into management reviewOutcome

What it does not cover

  • Zero Tolerance Areas Named, which if left blank or marked partial means there's no hard boundary in the statement, so no acceptance decision can ever be shown to have crossed one.
  • Tolerance Thresholds Quantified Where Possible, which without a number reduces the whole domain to a matter of opinion the day a real decision needs testing.
  • Escalation Triggers Defined, which if absent means a risk approaching the edge of appetite has nowhere defined to go before it's already been accepted.
  • Tested Against Recent Decisions, which if marked 'No' means the statement has never been checked against how the organisation actually behaves, so its currency is unverified.
  • Consistent With Actual Behaviour, which if marked 'No' or 'Partly' is the single clearest sign the statement is aspirational rather than operative.

Global

Risk Appetite Statement requirements by country

ISO 31000 itself is voluntary guidance with no certification body behind it, so the statement's practical weight comes from where it intersects mandatory disclosure or duty-of-care obligations.

United Kingdom

UK Corporate Governance Code, Provision 28

Listed companies must describe their principal risks and how the board has assessed the company's risk appetite as part of the annual report.

For a UK listed entity, the appetite statement isn't just internal governance hygiene — it's the evidence base for a public disclosure the board is accountable for.

United States

COSO Enterprise Risk Management Framework (2017)

COSO treats risk appetite as a named component of ERM and expects it to be articulated, communicated and monitored, though it is not itself a statutory requirement.

US organisations subject to SOX-adjacent governance expectations or investor scrutiny are typically expected to evidence an appetite statement even without a specific statute naming it.

International

ISO 31000:2018 cl.5.4

A voluntary, non-certifiable framework clause on designing risk management, including establishing risk criteria consistent with objectives.

There is no external auditor who will fail an organisation for a weak appetite statement under ISO 31000 alone — the discipline has to be self-imposed and tested against real decisions.

How to complete it

How to complete a risk appetite statement, step by step

Filling in every field is the easy part. The judgement calls below are what decide whether the finished statement can actually be tested against a real decision six months from now.

How granular does 'per domain' need to be?

A single line covering all safety risk is too coarse to be useful once the organisation has more than one hazard profile across its sites; splitting appetite by domain and, where risk profiles differ materially, by site or activity, is what makes the statement usable rather than decorative.

Qualitative or quantified thresholds?

Quantify wherever a number exists to quantify with — loss values, frequency rates, headcount exposure. Where no number is honest, name a specific, observable boundary condition instead of a general sentiment; a boundary that can't be pointed to in a real case isn't a threshold.

Who counts as senior enough to approve?

Approval has to sit above the level that benefits from a lenient appetite, and above the level that will be making acceptance decisions against it day to day — otherwise the same manager is effectively setting and applying their own limit.

How do you actually test consistency against behaviour?

Pull a sample of recent risk acceptance and investment decisions and check each one against the stated appetite line by line; a statement that passes this test on paper but fails against three of the last five real decisions needs rewriting, not defending.

What auditors find

Most common risk appetite statement findings

These are the gaps that show up most often when an appetite statement is checked against how the organisation actually behaves, not just against the template.

FindingClauseWhat fixes it
Appetite is described in general prose with no per-domain breakdownISO 31000 cl.6.3Rewrite as a short table: domain, stated appetite, quantified threshold where possible, escalation trigger.
No zero-tolerance areas are named anywhere in the statementISO 31000 cl.5.4Name the specific control failures or outcomes the organisation will never accept, regardless of cost or schedule pressure.
The statement has not been checked against a real acceptance decision since it was issuedISO 31000 cl.5.6Pull the last three risk acceptance records and test each against the current statement before the next review is signed off.
Approval sits at a level that also owns the risk being acceptedISO 31000 cl.5.4Move sign-off to the next level up, and record that independence explicitly on the statement's approval line.
Escalation triggers exist for safety domains but not for financial or reputational onesISO 31000 cl.5.4Add a named trigger and route for every domain the statement covers, not just the highest-profile one.
The statement was reviewed on the anniversary date but not after a significant loss event in betweenISO 31000 cl.5.7Add an event-triggered review clause alongside the annual cycle, and back-date a review against the event that was missed.

Case in point

Case in point: an appetite statement that never met a real decision

A distribution business carried a risk appetite statement that had been signed annually for four years, each time with 'Yes' against consistently applied and no supporting evidence attached. When a warehouse manager accepted a fire-loading risk that would have breached the stated financial threshold by a wide margin, nobody had checked the acceptance against the statement — because nobody ever had, on any prior decision.

The statement was accurate on paper and useless in practice. Rewriting it after the event added nothing the organisation didn't already know; what was missing was the habit of testing real decisions against it, which is the only thing that makes an appetite statement worth more than the page it's printed on.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

37fields
5 sections
Reference
CMP-027
Archetype
Plan
Record ID
RAS-2026-000
Scoring
Statement current
Direction
High is good
Singleton
No
Basis
ISO 31000 cl.5.4
Links
Links Enterprise risk, Waivers
Tags
Governance, Risk
Sections
5
Fields
37
Follow up fields
3
Repeating sections
0
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

11 fields
Text

Statement ID*

Generated on save

Auto sequence. Format RAS-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Version*

Date & Time

Issue Date*

Date & Time

Next Review Due*

Users

Owner*

Users

Approved By*

Single Choice

Approved At Senior Level*

Scored
  • Yes3 pts
  • No0 pts
Info

Without It Every Acceptance Is A Personal Judgement

When somebody accepts a risk with no stated appetite behind them, they are exposed personally and the decision cannot be defended later.

Content

6 fields
Single Choice

Appetite Stated By Domain*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Expressed In Usable Terms*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Zero Tolerance Areas Named*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Tolerance Thresholds Quantified Where Possible*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Escalation Triggers Defined*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Authority Levels Defined*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Application

6 fields
Single Choice

Used In Risk Acceptance Decisions*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Used In Investment Decisions*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Managers Understand It*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Consistent With Actual Behaviour*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Tested Against Recent Decisions*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Reviewed After Significant Events*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Related records

1 field
Text

Enterprise Risk Register ID

OptionalLinked

The register this appetite statement governs.

Links to CMP-026 Register ID

Outcome

13 fields
Single Choice

Statement Current*

Scored
  • Yes3 pts
  • Overdue0 pts
Single Choice

Consistently Applied*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Communicated To Managers*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Feeds Management Review*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Date & Time

Next Review Due*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Compliance Lead*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-027 · record IDs look like RAS-2026-000 · Links Enterprise risk, Waivers

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The statement itself is short. What actually takes ongoing effort is checking it against real decisions, routing exceptions to the right level, and catching when it's gone stale.

KnowComply

Holds the appetite statement against the enterprise risk register and acceptance records, and flags when a decision has gone through without being tested against the current position.

KnowSafe

Feeds safety-domain incident and near-miss data back into the appetite review, so the safety line of the statement is tested against what's actually happening on site, not just re-signed from memory.

KnowEnviro

Surfaces environmental exceedances and permit near-misses against the environmental appetite line, so that domain doesn't drift unnoticed between annual reviews.

Ella
Ella

Coordinates the review across domains, rolls exceptions and overdue tests into one view for the board cycle, and holds every write for approval before it touches the record.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Risk Appetite Statement definitions and key terms

Risk appetite
The amount and type of risk an organisation is willing to pursue or retain in order to meet its objectives, set at a strategic level by senior management.
Risk tolerance
The specific, measurable boundary around a risk or metric that operationalises appetite — the number or condition that triggers escalation or action.
Risk criteria
The terms of reference an organisation uses to evaluate the significance of risk, including how likelihood and consequence are scored and combined.
Escalation trigger
A defined condition or threshold that, once met, requires a decision to be referred to a higher level of authority than the one that would normally make it.
Residual risk
The risk remaining after treatment or controls have been applied, which is what a risk acceptance decision is actually measured against.

FAQ

Frequently asked questions about risk appetite statement

Does every organisation need a formal risk appetite statement?+

Not by law in most sectors, but any organisation making risk acceptance decisions without one is doing so on an ad hoc, undocumented basis. Once decisions start being challenged after the fact — by a regulator, an insurer, or an incident investigation — the absence of a statement becomes the finding.

Can risk appetite differ by site or business unit?+

Yes, and for most organisations it should. A single group-wide appetite statement that ignores real differences in hazard profile, regulatory exposure or maturity between sites ends up too vague to apply anywhere specifically.

What happens if a decision falls outside the stated appetite?+

It should trigger the escalation route named in the statement, going to a decision-maker at or above the level the statement specifies — it should not be quietly approved at the original level with a note that appetite was exceeded.

How often should the statement actually be reviewed?+

At minimum annually, but also immediately after any event that tests it — a significant loss, a near miss, a material change in strategy or regulatory environment. An appetite statement reviewed only on the calendar and never after an event is reviewing the wrong trigger.

Who should sign the appetite statement?+

Senior management, at a level that sits above the day-to-day owners of the risks being governed. A statement signed only by the risk function without line management ownership tends to be ignored the first time it's inconvenient.

Does the statement need to name specific numbers?+

Wherever a defensible number exists, yes. Where it genuinely doesn't, name an observable condition instead — but avoid defaulting to vague language purely because quantifying is harder; that's usually the domain that needs the most discipline.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 31000:2018 cl.5.4 — Design of the framework for managing risk
  • ISO 31000:2018 cl.6.3 — Scope, context and criteria
  • ISO 31000:2018 cl.5.6 — Evaluation
  • UK Corporate Governance Code (2018), Provision 28
  • COSO Enterprise Risk Management Framework (2017) — Risk Appetite component

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.