RSK-04Risk and Decisions

Appetite and indicators

Risk appetite is stated in terms someone can measure, with indicators and thresholds that trigger action.

Why it exists

Appetite that cannot be measured cannot be exceeded, so it is never discussed.

What usually proves it

Appetite statement, KRI definitions, threshold breach records.

Smaller organizations

Three indicators leadership actually watches.

Mapped to

  • Partially addressedSOC 2 Trust Services Criteria · CC3.1 — Objectives and tolerances are required; appetite language is not.
  • Partially addressedISO/IEC 27001 Annex A · 6.1.2(a) — Risk criteria including acceptance criteria.
  • Fully addressedNIST Cybersecurity Framework · GV.RM-02
  • Deliberately absentPCI DSS — Prescriptive standard; no appetite concept.
  • Deliberately absentHIPAA Security Rule — No appetite concept in the Security Rule.
  • Deliberately absentGDPR — Risk is assessed against individuals' rights, not against an organizational appetite.
  • Partially addressedEU AI Act · Art. 9(5) — Residual risk must be judged acceptable.
  • Fully addressedNIST AI Risk Management Framework · GOVERN 1.3