Skip to content

Risk Appetite

Definition

The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing body. Risk appetite sets the threshold above which identified risks require treatment; it is expressed differently in qualitative (a rating threshold) and quantitative (a monetary ceiling) frameworks.

Set by
The organisation's governing body (board or senior management)
Function
Threshold above which identified risks require treatment
Qualitative form
A rating threshold, e.g. only treat 'high' or above
Quantitative form
A monetary ceiling on acceptable exposure

Common questions

How does risk appetite differ from risk tolerance?+

Risk appetite is the broad, strategic amount of risk an organisation chooses to accept in pursuit of its objectives; risk tolerance is the narrower, operational variation permitted around a specific target or control before action is triggered. Appetite sets the boundary, tolerance fine-tunes it day to day.

Why does a fraud investigator need to know an organisation's risk appetite?+

It determines which findings in a risk assessment get escalated for remediation versus accepted as within bounds, so an investigator scoping a fraud risk assessment calibrates recommendations against the client's stated appetite rather than an abstract zero-tolerance standard.

Can risk appetite change over time?+

Yes. It is typically reviewed periodically by the governing body and can shift after a major loss event, a regulatory change, or a change in organisational strategy, which in turn changes what the risk register flags for treatment.

Related terms

ALE (Annualised Loss Expectancy)
The expected monetary loss from a specific threat over a one-year period. Calculated as: ALE = SLE x ARO (Annualised Rate of...
CISO (Chief Information Security Officer)
The senior executive responsible for developing and maintaining the information security programme. The CISO reports to the board or a board committee...
Control Gap
A deficiency in the design or operation of a control that leaves a fraud scheme inadequately mitigated. Design gaps exist where no...
COSO Fraud Risk Management Guide
A framework published by the Committee of Sponsoring Organizations of the Treadway Commission that provides a methodology for identifying, assessing, and responding...
FAIR (Factor Analysis of Information Risk)
A quantitative risk framework standardised by The Open Group (Open FAIR) that decomposes risk into Loss Event Frequency and Loss Magnitude, each...
Governance, Risk, and Compliance (GRC)
An integrated discipline that combines governance structures, risk management processes, and compliance monitoring into a unified programme. GRC platforms and frameworks allow...
Inherent Fraud Risk
The level of fraud risk present in a business process or transaction type before any controls are applied. Scored on likelihood and...
Policy Hierarchy
The layered document set that translates governance intent into operational requirements. Tiers typically run: information security policy, topic-specific policies, standards, procedures, and...
Qualitative Risk Assessment
A methodology that rates likelihood and impact on descriptive or ordinal scales (such as 1-5 or low/medium/high) and combines them in a...
Quantitative Risk Assessment
A methodology that assigns monetary values to threat scenarios using metrics such as asset value, exposure factor, SLE, ARO, and ALE. Outputs...
Residual Fraud Risk
The level of fraud risk that remains after existing controls are applied and operating. If residual risk exceeds the organisation's risk appetite...
Residual Risk
The risk that remains after controls are applied. If residual risk exceeds the organisation's risk appetite, further treatment is required or management...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.