Glossary

Risk Appetite

Risk appetite is the amount and type of risk your organization has decided it’s willing to accept in pursuit of its objectives — set by leadership, in writing. It’s the threshold that makes a risk register actionable: risks above appetite demand treatment; risks below it can be accepted with a clear conscience and a recorded signature.

What a usable statement looks like

Not “we have a low risk appetite” — that’s a mood, not a threshold. Usable versions are operational: “residual risks scoring High or above must be treated within 90 days; Medium risks may be accepted by the CTO; anything touching customer data requires CEO acceptance.” Thresholds, owners, and authority levels.

Why frameworks care

ISO 27001 expects risk acceptance criteria as part of the ISMS; SOC 2 auditors probe who approved living with the risks you didn’t mitigate; regulators (MAS among them) ask whether the board understands the appetite it has implicitly signed. The recurring audit question isn’t “is your appetite right?” — it’s “who set it, do they have the authority, and do your acceptance decisions actually follow it?”

The common failure

Appetite set once, in a policy nobody rereads, while actual acceptance decisions happen ad hoc in Slack. When the register says “accepted” and no one with authority did the accepting, that’s not risk management — it’s risk accumulation with extra steps.

Related Terms

ISMS — An ISMS is the management system ISO 27001 certifies — the loop of risk assessment, controls, internal audit, and review that runs your security program.

Inherent vs Residual Risk — Inherent risk is exposure before controls; residual risk is what remains after. Auditors check that the gap between them maps to real, operating controls.

Risk Register — A risk register is the living record of identified risks, their scores, owners, and treatments — sampled in every SOC 2 and ISO 27001 audit.