RSK-04Risk and Decisions
Appetite and indicators
Risk appetite is stated in terms someone can measure, with indicators and thresholds that trigger action.
Why it exists
Appetite that cannot be measured cannot be exceeded, so it is never discussed.
What usually proves it
Appetite statement, KRI definitions, threshold breach records.
Smaller organizations
Three indicators leadership actually watches.
Mapped to
- Partially addressedSOC 2 Trust Services Criteria · CC3.1 — Objectives and tolerances are required; appetite language is not.
- Partially addressedISO/IEC 27001 Annex A · 6.1.2(a) — Risk criteria including acceptance criteria.
- Fully addressedNIST Cybersecurity Framework · GV.RM-02
- Deliberately absentPCI DSS — Prescriptive standard; no appetite concept.
- Deliberately absentHIPAA Security Rule — No appetite concept in the Security Rule.
- Deliberately absentGDPR — Risk is assessed against individuals' rights, not against an organizational appetite.
- Partially addressedEU AI Act · Art. 9(5) — Residual risk must be judged acceptable.
- Fully addressedNIST AI Risk Management Framework · GOVERN 1.3