Back to Articles and Learning
Risk Management10 min read

How to Build a Risk Appetite Statement That Actually Works

Elliot Poublan
Aug 19, 2026
How to Build a Risk Appetite Statement That Actually Works

A surprising number of firms have a risk appetite statement and still cannot answer a simple question from the board: are we inside appetite on this risk, today? The document exists. It was approved last March. It says the firm has a "low to moderate appetite for operational risk" and a "zero appetite for regulatory breaches". None of that can be compared to the residual scores in the register, so the conversation stays qualitative until something has already gone wrong.

A risk appetite statement that actually works is not a values page. It is a set of decision rules. You should be able to take any principal residual position, put it next to the statement, and get a yes, a no, or a documented exception.

In short

Write appetite as thresholds against residual risk, not as adjectives. Split appetite (what you choose to take), tolerance (how far you can drift before you must act) and capacity (the outer limit). Then report residual against those thresholds every cycle.

  • By principal risk - one slogan for the whole firm is not usable.
  • On the same scale as the register - if residual is 1-25, appetite lives on 1-25.
  • Breaches are visible - an owner, a decision, a date.
  • Reviewed when strategy changes - not only when the policy calendar says so.

Appetite, Tolerance and Capacity Are Not Synonyms

Most failed statements collapse three different ideas into one sentence. Keep them apart. The scoring context for residual vs inherent is in inherent vs residual vs appetite; this article is about turning appetite into a document the board can use.

Term Meaning Question it answers
Risk appetite The residual risk you are willing to take in pursuit of an objective What will we accept?
Risk tolerance The variation around appetite before escalation is mandatory How far can we drift?
Risk capacity The maximum the organisation could absorb before viability is threatened What would break us?
Target risk The residual level you are working toward after planned actions Where are we heading?

Appetite is a choice aligned to strategy. Capacity is a fact aligned to capital, cash, licences and reputation. A growth-stage firm might have a higher appetite for market risk than a mutual, but both still have a capacity they cannot cross. Tolerance is the tripwire between "we chose this" and "we need a decision now".

Why Most Statements Fail

  • They are slogans. "We have a conservative appetite" cannot be compared to a residual score of 12.
  • They mix ethics with measurement. "Zero appetite for fraud" sounds strong and is almost never operationally true. You can have a very low appetite, with detective controls and a defined loss threshold. Pretending the residual is zero just hides the real position.
  • They are written once a year and dropped from packs. If residual vs appetite is not in the board report, the statement is not part of governance. See what boards actually need in board-level risk reporting.
  • They sit on a different scale to the register. Narrative appetite plus a 5x5 residual score is two systems that never meet.
Common Pitfall

The "zero appetite" line that nobody can use

A mid-market insurer writes "we have zero appetite for customer harm" into the annual statement. Six months later, complaint volumes and redress are rising. The committee argues about whether that is a breach, because "zero" was never translated into a residual threshold, a KRI, or an escalation rule. The honest version is: very low appetite for customer harm; residual above X on conduct risk, or KRI Y turning red, requires an executive paper and a treatment plan within 30 days. That can be enforced. "Zero" cannot.

What a Usable Statement Contains

Keep the front section short: strategy, who sets appetite, how often it is reviewed, and how breaches are escalated. Then do the real work in a table, one row per principal risk.

Each row should answer:

  • Risk - the same name as the register, not a new taxonomy invented for the policy.
  • Appetite - the residual band or score you are willing to live with (for example residual 1-8, or Low).
  • Tolerance - the band that triggers mandatory action (for example 9-12 requires a plan; 13+ requires committee).
  • Quantitative trigger - where you have one: capital, loss, downtime, complaint rate, concentration.
  • Who acts on a breach - named role, not "management".

If you score on a 5x5 matrix, express appetite in those same bands. Do not invent a parallel colour system. The matrix is already the language of the register; appetite should speak it.

How to Write It (Without a 40-Page Policy)

  1. Start from strategy, not from a template. A firm pursuing acquisition has a different appetite for integration and culture risk than a firm protecting a closed book. Copy-paste statements fail because they ignore that.
  2. Use the existing principal-risk list. If the board already sees ten principal risks, those are the rows. Do not create an appetite taxonomy that does not match the pack.
  3. Draft thresholds with the first line, not only with risk. The COO has to live with an operational residual of 10. If they never agreed it, they will not own the breach.
  4. Challenge "low" everywhere. If every row is Low, you have not made choices. Some risks (growth, change, credit within policy) should be Moderate by design.
  5. Board workshop, then freeze. Appetite is a board decision. After approval, the second line's job is to report against it, not to rewrite it between meetings.

Worked Example: Conduct Risk Row

A UK mid-market wealth manager. Principal risk: conduct / customer outcomes.

  • Appetite: residual Low (score 1-6 on a 5x5). The firm will not grow distribution in a way that pushes residual above that band.
  • Tolerance: residual 7-9 requires an executive treatment plan within 30 days. Residual 10+ is a committee paper at the next meeting, with a go/no-go on the activity creating the risk.
  • Quantitative triggers: upheld complaints above 1.5% of active clients; average redress above £X per quarter; any FCA notification. Any trigger is treated as a tolerance breach even if the qualitative residual has not yet been rescored.
  • Owner on breach: Chief Operating Officer, with second-line challenge from Head of Risk.

That row can be audited. A paragraph that says "we put customers first" cannot.

Reporting Against Appetite Every Cycle

The statement only becomes real in the pack. For each principal risk show: inherent, residual, appetite, and movement since last time. Colour the residual vs appetite comparison, not the residual in isolation. A residual of 12 is not automatically "bad"; it is a problem if appetite was 8.

On a breach, the pack should answer four questions in one block:

  • Why did residual move (control fail, volume, external event, better information)?
  • Is this inside tolerance or a true appetite breach?
  • Treat, transfer, terminate, or accept with a time limit?
  • When will we look again?

If residual moved because a key control failed operating effectiveness, say so. That is the link to control testing: appetite is meaningless if residual is scored as if every control worked.

How Initia Risk Operationalises Appetite

Initia Risk scores inherent and residual on the same configurable matrix, then overlays appetite thresholds on those residual positions. Breaches are visible in the register and in board-ready outputs, rather than living only in a PDF policy. When control assessments change, residual can move, and the appetite comparison moves with it.

That is the point of a statement that works: it is not a document you re-approve. It is a rule the system can show you are keeping, or breaking, in time to do something about it. For the rest of the ERM spine this sits on, see how to build an ERM framework and how to create real risk ownership. For the one-line definition, see risk appetite in the glossary.

See Initia in action

Book a demo.

An exploratory call to discuss what works and what doesn't, what's still done on Excel, and what you're looking for in a tool.

By submitting, you agree to allow Initia Risk to store and process your personal data.

Initia Risk
As a professional risk manager with over 16 years' experience, I have seen many systems over the years. Initia Risk is without doubt one of the most user-friendly and intuitive platforms I have encountered.
Elaine Atkinson · Risk Manager