Governance

Setting a risk appetite the board will actually use

Board-approved appetite bands are the single lever that stops risk management from becoming compliance theatre. Here's how to write them.

James Rutledge, Advisor February 12, 2026 6 min read Appetite

A risk appetite statement is a decision-making shortcut. Its whole job is to move a class of decisions off the exec's desk and onto the risk owner's. If your appetite statement doesn't make anyone's life easier this quarter, it's a slogan, not a policy.

What good looks like

One page. Four bands (Low / Moderate / High / Critical). For each band, two decisions: is it auto-acceptable, and who signs off if it's not. Then a short note per band explaining why.

The four bands, in plain English

  • Low - acceptable without approval. Log it and move on.
  • Moderate - acceptable, but the owner records a rationale.
  • High - approver sign-off required, with an expiry date.
  • Critical - board notification within 24 hours; no auto-acceptance.

The threshold

Set the appetite breach threshold to High by default. If your business genuinely tolerates High risks (e.g. an early-stage fintech), be explicit about which categories - Cybersecurity almost always stays at Moderate.

Versioning

Appetite changes. New board, new threshold. Version every appetite statement (v1, v2, v3) and stamp every risk assessment with the appetite version it was scored against. Auditors love this. You will too when the board asks 'when did we start accepting High cyber risks?'

Common failure modes

  • Appetite = zero tolerance for everything. This is fear, not governance. Board will ignore it in six months.
  • Appetite that changes silently. If the risk manager can rewrite the bands without a board minute, you don't have an appetite - you have a preference.
  • Appetite that isn't linked to actual acceptance workflows. If a Moderate risk still triggers an all-hands review, the appetite isn't wired into the process.

In RiskEye every risk assessment stores appetite_version so you can prove which policy each historical decision was made under. That's the difference between a defensible governance record and a photo-op.

Talk to us
Want us to walk this through with your team?

A 30-minute session with a seQure advisor is free. We'll seed a private tenant, walk through the working, and hand you super-admin keys the same day.

Keep reading