Cyber Risk Appetite Statement Template
Turns an abstract appetite discussion into stated tolerance thresholds that can actually be tested against the register.
Available soon
- Format
- Word
- Size
- 63 KB
- Length
- 20 pages
- Version
- 1.1
- Updated
What's inside
- Part 1 — How to set your cyber risk appetite
- Part 2 — The statement template
- Part 3 — Worked example
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Part 1 — How to set your cyber risk appetite
A risk appetite statement says how much cyber risk [[Organisation Name]] is willing to take, and where it stops. Most statements fail because they stay abstract: "we have a low appetite for cyber risk" cannot be tested, so it never changes a decision. This template ties each category of risk to a band on the same 4 × 4 scale the risk register uses, so that every quarter the statement can be tested against every risk in the register, and the answer — within appetite, or not — is a count, not an opinion.
The scale, the bands and the rules are in the Risk Assessment Methodology & Scoring Model; the Risk Identification & Assessment Operating Procedure governs how risks reach the Information Security Risk Register. This template sets the appetite those risks are tested against (RM-05).
Part | What it is | What to do with it |
|---|---|---|
Part 1 — this guidance | How to choose levels, how they become a test, and what happens when a risk fails it | Read it before the appetite discussion. Do not copy it into the statement. |
Part 2 — the template | The statement: an overall statement, a row for each risk category, the test, the consequences, review and approval | Copy it into a new document, replace every [[placeholder]] and delete every guidance box. |
Part 3 — a completed example | The statement of the example organisation used across the pack (a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders), tested against its register as at 2026-09-30 | Use it to see the level of detail expected. Do not adopt its levels as they stand. |
Appetite and tolerance
- Appetite is the highest residual band the organisation accepts without escalation. A risk at or below it is managed by its owner and reviewed every quarter (RM-09).
- Tolerance is the highest band the organisation will tolerate for a time, while a plan brings the risk back within appetite. A risk above it has gone past the point at which the board said it must act, not just be told.
Both are set per category, in bands of the residual score: the score after existing controls (RM-03). Setting them in bands, not words, is what makes them testable. The three positions a risk can be in are the same words the board report uses (P03): Within appetite; Outside appetite, within tolerance; Outside tolerance.
Who decides
The board or management body sets and approves the appetite. Executive management proposes it, head of information security drafts it from the register, and each category owner — the executive who owns that kind of risk — agrees the level for their category before it goes to the board. Security does not set the appetite: it is a business decision about how much harm the organisation will risk for its objectives (ISO/IEC 27001 Clause 5.1, leadership and commitment).
- NIS2 essential and important entities: the management body must approve the cybersecurity risk-management measures and oversee how they are implemented. An appetite approved by the board is the clearest evidence that the management body has set the level of risk those measures must achieve.
- DORA financial entities: the ICT risk-management framework (DORA Article 6(1)) includes policies that must indicate the approval of the risk tolerance level for ICT risk (RTS 2024/1774 Article 3(a)). The Approval block in Part 2 records it: the approving body, the date, the minute, and that the tolerance bands were approved, not only the words.
Guidance — delete before approval
If your organisation has an enterprise risk appetite, this statement sits under it and uses the same levels and bands. Do not create a second scale for cyber risk: Risk Assessment Methodology & Scoring Model sets the scale; this statement sets the level for each category on it.
The three appetite levels
Each category takes one of three levels. The level sets both bands; nothing else needs to be decided per category. Critical is never within tolerance at any level.
Level | What it means | Appetite: highest band accepted | Tolerance: highest band tolerated |
|---|---|---|---|
Averse | We avoid this risk and act on anything above Low. | Low (1–3) | Medium (4–6) |
Cautious | We accept some risk for a clear business benefit, with controls. | Medium (4–6) | High (8–9) |
Open | We accept higher risk to pursue opportunity; Critical is never within tolerance. | High (8–9) | High (8–9) |
Note that at Open the appetite and the tolerance are the same band (High): an Open category has no "outside appetite, within tolerance" position, and a risk that leaves its appetite is already outside tolerance. Use Open only where the board is content to go straight from "note" to "decide".
What each level allows
The bands are easier to agree when they are read on the scale. For each impact level, this table shows the highest likelihood at which a risk is still within appetite (impact × likelihood, residual; bands Low 1–3, Medium 4–6, High 8–9, Critical 12–16).
Impact of the worst consequence | Within Averse appetite | Within Cautious appetite | Within Open appetite |
|---|---|---|---|
4 Severe | None: outside appetite at any likelihood | Up to Unlikely (score 4) | Up to Possible (score 8) |
3 Major | Up to Unlikely (score 3) | Up to Possible (score 6) | Up to Likely (score 9) |
2 Moderate | Up to Unlikely (score 2) | Up to Likely (score 6) | Up to Almost certain (score 8) |
1 Minor | Up to Likely (score 3) | Up to Almost certain (score 4) | Up to Almost certain (score 4) |
Likelihood is over the next 12 months: 1 Unlikely, 2 Possible, 3 Likely, 4 Almost certain. Read the table as a sentence for the board: "for customer data we are Cautious, which means we accept a severe impact only if it is unlikely".
Choosing a level for each category
The template starts with six categories, the ones the pack's example uses. Rename, merge or add categories to match your business, but keep few enough (usually five to eight) that the board can hold them in mind, and give every risk in the Information Security Risk Register exactly one category.
ID | Category | What it covers |
|---|---|---|
RC-01 | Service availability | Losing or degrading the services customers and staff depend on: ransomware, outages, failed recovery |
RC-02 | Customer and personal data | Confidentiality of customer and personal data: exposure, theft, loss, misuse |
RC-03 | Financial fraud | Money lost through deception or compromise: payment fraud, invoice redirection, business email compromise |
RC-04 | Regulatory compliance | Breaching a legal, regulatory or contractual security duty: reporting deadlines, required controls |
RC-05 | Third-party dependency | Harm that arrives through a supplier or service provider: their failure, compromise or access |
RC-06 | People and insider | Harm caused by the organisation's own people, deliberately or by mistake, or through their accounts |
- Start from the register, not from a blank page. List the current top risks in each category with their residual scores. The appetite discussion is then about real risks: "are we content to carry R-05 at this score?"
- Ask each category owner the business question. Which harm in this category would the board not accept, even for a clear benefit? Use the impact areas in the methodology — money, service, data, legal, reputation — so the answer is in the same terms the scores use.
- Choose the level from the answer. Averse where the harm is unacceptable at almost any likelihood (typically legal and regulatory duties); Cautious where some risk buys a clear benefit; Open only where the organisation deliberately trades risk for opportunity.
- Test the draft against the register before approval. Apply the test below to every current risk. If the draft statement puts most of the register outside appetite, either the level is not what the board will fund, or the scores are wrong; resolve which before approving. If it puts nothing outside appetite in a category the board worries about, the level may be too loose.
- Write one sentence per category in business words (Part 2, "In words"), and check it says the same as the bands.
Guidance — delete before approval
A statement that shows everything within appetite on the day it is approved is not necessarily wrong, but ask why the board is worried if every risk is acceptable. A statement that shows half the register outside appetite will be ignored within a quarter. Aim for a statement that separates the few risks that need a decision from the many that do not.
How a level becomes a test against the register
Each risk's residual band is compared with its category's appetite and tolerance, giving its position in words. (RM-05). For each risk in the register:
- Take its residual score and band from the register (RM-03, RM-04).
- Look up its category's level, and from the level its appetite and tolerance bands.
- If the residual band is above the tolerance band, the risk is Outside tolerance.
- Otherwise, if it is above the appetite band, it is Outside appetite, within tolerance.
- Otherwise it is Within appetite.
Count the risks outside appetite, and of those the risks past tolerance: that pair is RMM-01, risks outside appetite and past tolerance — the same figure as the board measure BM-01 in the Board Metric Selection Catalogue (P03). The organisation's own position follows from its risks' positions (the P03 rule): outside tolerance if any top risk is past its own tolerance limit; otherwise Outside appetite, within tolerance if any top risk is above appetite; otherwise Within appetite.
For example, the example organisation's R-01 (ransomware takes online ordering offline for more than 2 days) scores 4 × 2 = 8, High. Its category, Service availability, is Cautious: appetite Medium, tolerance High. High is above Medium and not above High, so R-01 is outside appetite, within tolerance.
Guidance — delete before approval
Test the residual score, not the inherent one. The inherent score shows what the controls are worth; the residual score is the risk the organisation is actually carrying, and the only one the appetite can be compared with.
Supporting measures (a recovery test, a training rate) help the board see a category from another side, but they are not the test. Keep one test — the register — so there is one answer to "are we within appetite?".
Outside appetite, outside tolerance: what happens
The position decides what must happen next, who may accept the risk instead of treating it, and who is told when.
Position | What must happen | Who may accept the risk instead | Who is told, and when |
|---|---|---|---|
Within appetite | Nothing beyond the normal cycle: the owner reviews the risk every quarter (RM-09). | The approvers for its band (RM-04): Low: risk owner; Medium: risk owner and Head of Information Security; High: accountable executive and Head of Information Security. | Executive management, in the quarterly risk report (RM-12). |
Outside appetite, within tolerance | A treatment decision within [[30]] calendar days of the risk first being assessed outside appetite (RM-06); later reviews do not restart the clock. Reduce, avoid, transfer or accept. A reduce decision has an action with an owner, a due date, a cost and the expected residual score (RM-07). | The approvers for its band, and executive management as well (RM-08). For example, High: accountable executive and Head of Information Security, and executive management as well. | Executive management every quarter (RM-12); the board in its next quarterly report, which opens with the position (P03, BR-02). |
Outside tolerance | The board decides: fund or order treatment, accept the risk explicitly and record why, or change the appetite. | The band's approvers recommend; only the board or its equivalent may accept (RM-08). | Out of cycle (P03): within [[5]] working days of a major incident or of any top risk moving outside its tolerance limit, to the chair (a move outside appetite but within tolerance waits for the next report). Then the board at its next meeting. |
Accepting a risk outside appetite does not bring it within appetite. It stays counted in RMM-01 until its residual score falls, or the board changes the appetite; the acceptance is recorded on the Risk Acceptance Form & Approval Record with its conditions and review date. Critical residual risk is outside tolerance at every level, so it is always the board's decision; its acceptance is reviewed within 3 months.
Reviewing and changing the statement
Review the statement at least every [[12]] months, with the yearly reassessment of the register (RM-09), and sooner after:
- A change in strategy, such as a new market, product, acquisition or major outsourcing
- A major incident, or a risk found outside tolerance
- A change in law or regulation that changes what the organisation must not accept
- The quarterly test showing the same category outside appetite for [[two]] quarters in a row
Changing a level is a board decision, recorded with its reason. Raising the appetite for a category to bring a risk back within it is a legitimate choice — P03 lists it as one of the board's options when a risk is outside tolerance — but it must be made openly, as a decision, never as a silent edit to the register or to this statement.
Before you send it for approval
- Every [[placeholder]] is replaced and every guidance box deleted.
- Every category has one level, and its appetite and tolerance bands are the ones that level sets.
- Every risk in the register has exactly one category in this statement.
- The draft has been tested against the current register, and the result — how many risks in each position — goes to the board with it.
- Each category owner has agreed their category's level and sentence.
- The Approval block names the body, the date and the minute, and records that the tolerance bands were approved.
Part 2 — The statement template
Guidance — delete before approval
Copy everything from here to the end of Part 2 into a new document. Promote the headings one level and delete this box.
Keep the three levels and their bands identical to the Risk Assessment Methodology & Scoring Model. If your methodology uses different bands, change it there first, then here.
Our overall statement
[[Organisation Name]] takes cyber risk in pursuit of [[its strategy, in a few words: e.g. growing its online services]]. It accepts [[a moderate]] level of cyber risk where there is a clear business benefit and the risk is controlled, and it does not accept [[the harms it will not accept, in business terms: e.g. a core customer service stopped for more than 2 days, or customer personal data exposed at scale]].
A residual risk in the Critical band (12–16) is never within tolerance in any category: the [[Board]] decides whether it is treated or accepted, and reviews any acceptance within 3 months. Where a risk goes above the appetite set below, it is treated or accepted at the level this statement sets; where it goes above the tolerance, the [[Board]] decides.
The appetite levels we use
Each category below has one of three levels. A level sets two bands on the Risk Assessment Methodology & Scoring Model's 4 × 4 scale: the appetite (the highest residual band [[Organisation Name]] accepts without escalation) and the tolerance (the highest band it will tolerate while a plan brings the risk back). Critical is never within tolerance.
Level | What it means | Appetite: highest band accepted | Tolerance: highest band tolerated |
|---|---|---|---|
Averse | We avoid this risk and act on anything above Low. | Low (1–3) | Medium (4–6) |
Cautious | We accept some risk for a clear business benefit, with controls. | Medium (4–6) | High (8–9) |
Open | We accept higher risk to pursue opportunity; Critical is never within tolerance. | High (8–9) | High (8–9) |
Appetite and tolerance by category
Set one level for each category. The bands follow from the level: copy them from the table above.
Category | Level | Appetite | Tolerance | Tested by | Owner |
|---|---|---|---|---|---|
RC-01 Service availability | [[Averse / Cautious / Open]] | [[band]] | [[band]] | RMM-01 for RC-01 risks; [[supporting measure, or none]] | [[Role]] |
RC-02 Customer and personal data | [[Averse / Cautious / Open]] | [[band]] | [[band]] | RMM-01 for RC-02 risks; [[supporting measure, or none]] | [[Role]] |
RC-03 Financial fraud | [[Averse / Cautious / Open]] | [[band]] | [[band]] | RMM-01 for RC-03 risks; [[supporting measure, or none]] | [[Role]] |
RC-04 Regulatory compliance | [[Averse / Cautious / Open]] | [[band]] | [[band]] | RMM-01 for RC-04 risks; [[supporting measure, or none]] | [[Role]] |
RC-05 Third-party dependency | [[Averse / Cautious / Open]] | [[band]] | [[band]] | RMM-01 for RC-05 risks; [[supporting measure, or none]] | [[Role]] |
RC-06 People and insider | [[Averse / Cautious / Open]] | [[band]] | [[band]] | RMM-01 for RC-06 risks; [[supporting measure, or none]] | [[Role]] |
In words. One sentence per category, saying what the organisation will and will not accept:
RC-01 Service availability. [[What we accept, and what we will not accept, in one sentence — in terms of services, customers, money or law]]
RC-02 Customer and personal data. [[What we accept, and what we will not accept, in one sentence — in terms of services, customers, money or law]]
RC-03 Financial fraud. [[What we accept, and what we will not accept, in one sentence — in terms of services, customers, money or law]]
RC-04 Regulatory compliance. [[What we accept, and what we will not accept, in one sentence — in terms of services, customers, money or law]]
RC-05 Third-party dependency. [[What we accept, and what we will not accept, in one sentence — in terms of services, customers, money or law]]
RC-06 People and insider. [[What we accept, and what we will not accept, in one sentence — in terms of services, customers, money or law]]
How this statement is tested
Every quarter, head of information security compares each risk in the Information Security Risk Register with its category's row above (RM-05): a risk whose residual band is above the category's appetite is outside appetite; above its tolerance, outside tolerance. The number of risks in each position is reported as RMM-01, risks outside appetite and past tolerance.
[[Name any supporting measure the board watches for a category, with its source.]]
When a risk is outside appetite or tolerance
- Outside appetite, within tolerance: a treatment decision within [[30]] calendar days of the risk first being assessed outside appetite (RM-06); acceptance needs, beyond the approvers for its band, at least executive management [[e.g. the Executive Committee]]; reported to executive management every quarter and in the next board report.
- Outside tolerance: reported to the chair of the [[Board]] within [[5]] working days; only the board or its equivalent may accept it (RM-08), and it decides whether to fund treatment, accept the risk, or change this statement.
Review
This statement is reviewed at least every [[12]] months, and sooner after [[the triggers in Part 1]]. A change to a level or a band is approved by the [[Board]], and recorded with its reason.
Approval
Approval of the cyber risk appetite statement | |||
Proposed by | [[e.g. Executive Committee, on the Head of Information Security's draft]] | Date proposed | [[YYYY-MM-DD]] |
Approved by the board or management body | [[Board, or the management body]] | Approval date | [[YYYY-MM-DD]] |
Tolerance levels approved? RTS 2024/1774 Art 3(a) | [[Yes — the tolerance band for each category, as above]] | Minute reference | [[Meeting and item]] |
Effective from | [[YYYY-MM-DD]] | Next review by | [[YYYY-MM-DD]] |
Signed for the approving body chair | [[Name, role]] | Signature and date | [[Signature, date]] |
Guidance — delete before approval
Tested by: the register test (RMM-01 for the category) is always the test. Add one supporting measure only where the board already sees one that shows the same risk from another side — for example, recovery tests for service availability, or supplier assessments for third-party dependency.
Owner: the executive who owns the category's most serious risks, and who agrees the level for it. Name a role, not a person.
In words: read the level on the table "What each level allows" in Part 1 and say the same in business terms. If the sentence and the bands disagree, the bands win in the quarterly test, so fix the sentence.
Part 3 — Worked example
This is the completed statement of the fictional example organisation used across the Information Security Risk Management pack: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. The levels are the example levels of the six categories; the register it is tested against is the example Information Security Risk Register, as at 2026-09-30 (the end of Q3 2026). The same organisation and quarter appear in the P03 board reporting pack.
Guidance — delete before approval
The "as at" date 2026-09-30 is fixed so the example does not change; in your own statement, the test is run on the date of each quarterly report.
The organisation, its roles and dates are fictional. Delete this example from your adopted template.
Our overall statement
We take cyber risk in pursuit of growing our online ordering service. In five of our six categories we are Cautious: we accept some risk for a clear business benefit, with controls. In regulatory compliance we are Averse: we avoid this risk and act on anything above Low. (EXAMPLE)
A residual risk in the Critical band is never within tolerance in any category: the Board decides whether it is treated or accepted, and reviews any acceptance within 3 months. Where a risk goes above the appetite set below, it is treated or accepted at the level this statement sets; where it goes above the tolerance, the Board decides. (EXAMPLE)
The appetite levels we use
Each category below has one of three levels. A level sets two bands on the Risk Assessment Methodology & Scoring Model's 4 × 4 scale: the appetite (the highest residual band the Company accepts without escalation) and the tolerance (the highest band it will tolerate while a plan brings the risk back). Critical is never within tolerance.
Level | What it means | Appetite: highest band accepted | Tolerance: highest band tolerated |
|---|---|---|---|
Averse | We avoid this risk and act on anything above Low. | Low (1–3) | Medium (4–6) |
Cautious | We accept some risk for a clear business benefit, with controls. | Medium (4–6) | High (8–9) |
Open | We accept higher risk to pursue opportunity; Critical is never within tolerance. | High (8–9) | High (8–9) |
Appetite and tolerance by category
EXAMPLE. The level, bands, test and owner for each category.
Category | Level | Appetite | Tolerance | Tested by | Owner |
|---|---|---|---|---|---|
RC-01 Service availability | Cautious | Medium | High | RMM-01 for RC-01 risks. Also watched: BM-02 Critical exposure fixed on time; BM-06 Critical services restored in tests (P03 board measures) | Chief Operating Officer |
RC-02 Customer and personal data | Cautious | Medium | High | RMM-01 for RC-02 risks. Also watched: BM-04 Significant incidents and time to contain (P03 board measures) | Chief Operating Officer |
RC-03 Financial fraud | Cautious | Medium | High | RMM-01 for RC-03 risks. No supporting measure: the register test alone | Chief Financial Officer |
RC-04 Regulatory compliance | Averse | Low | Medium | RMM-01 for RC-04 risks. Also watched: BM-04 Significant incidents and time to contain (P03 board measures) | Head of Information Security |
RC-05 Third-party dependency | Cautious | Medium | High | RMM-01 for RC-05 risks. Also watched: BM-05 Critical suppliers assessed (P03 board measures) | Head of IT |
RC-06 People and insider | Cautious | Medium | High | RMM-01 for RC-06 risks. Also watched: BM-08 Board and staff security training (P03 board measures) | HR Director |
In words. One sentence per category, saying what the organisation will and will not accept:
RC-01 Service availability. We accept a severe impact only where it is unlikely, and a major one only up to possible; anything more is treated. (EXAMPLE)
RC-02 Customer and personal data. We accept a severe impact only where it is unlikely, and a major one only up to possible; anything more is treated. (EXAMPLE)
RC-03 Financial fraud. We accept a severe impact only where it is unlikely, and a major one only up to possible; anything more is treated. (EXAMPLE)
RC-04 Regulatory compliance. We accept at most a major impact, and only where it is unlikely; a severe impact is treated at any likelihood. (EXAMPLE)
RC-05 Third-party dependency. We accept a severe impact only where it is unlikely, and a major one only up to possible; anything more is treated. (EXAMPLE)
RC-06 People and insider. We accept a severe impact only where it is unlikely, and a major one only up to possible; anything more is treated. (EXAMPLE)
How this statement is tested
Every quarter, the Head of Information Security compares each risk in the Company's risk register with its category's row above (RM-05). The number outside appetite, and of those past tolerance, is reported to the Executive Committee and the Board as RMM-01 (the Board's BM-01). (EXAMPLE)
The supporting measures named in the table come from the Company's board report; they are not a second test. A category can be within appetite while its supporting measure is below target, and the board report says so. (EXAMPLE)
When a risk is outside appetite or tolerance
- Outside appetite, within tolerance: the risk owner brings a treatment decision within 30 calendar days of the risk first being assessed outside appetite; later reviews do not restart the clock (RM-06). Acceptance needs, beyond the approvers for its band, a decision of the Executive Committee. Reported to the Executive Committee every quarter and in the next Board report. (EXAMPLE)
- Outside tolerance: reported to the Chair within 5 working days. Only the Board may accept it (RM-08); it decides whether to fund treatment, accept the risk, or change this statement. (EXAMPLE)
Review
Reviewed every 12 months, at the Board's January meeting, and sooner after a change in strategy, a major incident, a risk outside tolerance, or a change in law. Next review by 2027-01-29. (EXAMPLE)
Approval
Approval of the cyber risk appetite statement — EXAMPLE | |||
Proposed by | Executive Committee, on the Head of Information Security's draft | Date proposed | 2026-01-29, at the same meeting |
Approved by the board or management body | Board | Approval date | 2026-01-29 |
Tolerance levels approved? RTS 2024/1774 Art 3(a) | Yes — for each category, as in the table | Minute reference | Board minutes, 2026-01-29, item on cyber risk |
Effective from | 2026-01-29 | Next review by | 2027-01-29 |
Signed for the approving body chair | Chair of the Board | Signature and date | Signed, 2026-01-29 |
Tested against the register
EXAMPLE, as at 2026-09-30. Every top risk in the example register, with its residual score (impact × likelihood), band, its category's level and the position the test gives.
Risk | Category | Level | Residual | Band | Position |
|---|---|---|---|---|---|
R-01 Ransomware takes online ordering offline for more than 2 days | RC-01 | Cautious | 4 × 2 = 8 | High | Outside appetite, within tolerance |
R-02 Payment fraud through a compromised supplier email account | RC-03 | Cautious | 3 × 3 = 9 | High | Outside appetite, within tolerance |
R-03 Customer data exposed through the ordering service | RC-02 | Cautious | 4 × 1 = 4 | Medium | Within appetite |
R-04 Ransomware spreads from warehouse office PCs to warehouse systems | RC-01 | Cautious | 2 × 2 = 4 | Medium | Within appetite |
R-05 Critical weaknesses on internet-facing systems exploited before they are fixed | RC-01 | Cautious | 3 × 2 = 6 | Medium | Within appetite |
R-06 Managed IT provider fails or is compromised | RC-05 | Cautious | 3 × 1 = 3 | Low | Within appetite |
R-07 Administrator misuses privileged access | RC-06 | Cautious | 3 × 1 = 3 | Low | Within appetite |
R-08 Significant incident not reported to the authority on time (NIS2) | RC-04 | Averse | 2 × 1 = 2 | Low | Within appetite |
R-09 Staff account taken over through phishing | RC-06 | Cautious | 2 × 3 = 6 | Medium | Within appetite |
R-10 Backups cannot restore a critical system | RC-01 | Cautious | 4 × 1 = 4 | Medium | Within appetite |
R-11 Cloud storage misconfigured and customer files exposed | RC-02 | Cautious | 3 × 1 = 3 | Low | Within appetite |
R-12 Customer data on an unencrypted laptop at the smaller warehouse site is lost or stolen | RC-02 | Cautious | 2 × 2 = 4 | Medium | Within appetite |
EXAMPLE result by category:
Category | Level | Risks | Within appetite | Outside appetite, within tolerance | Outside tolerance |
|---|---|---|---|---|---|
RC-01 Service availability | Cautious | 4 | R-04, R-05, R-10 | R-01 | — |
RC-02 Customer and personal data | Cautious | 3 | R-03, R-11, R-12 | — | — |
RC-03 Financial fraud | Cautious | 1 | — | R-02 | — |
RC-04 Regulatory compliance | Averse | 1 | R-08 | — | — |
RC-05 Third-party dependency | Cautious | 1 | R-06 | — | — |
RC-06 People and insider | Cautious | 2 | R-07, R-09 | — | — |
Result: 2 of 12 top risks outside appetite, none past tolerance (RMM-01). The Company's position is therefore Outside appetite, within tolerance — the opening sentence of its Q3 2026 board report (P03). (EXAMPLE)
Movement. R-04 (ransomware spreads from warehouse office PCs to warehouse systems) was 3 × 3 = 9, High, last quarter — outside the Cautious appetite for service availability — and is now 2 × 2 = 4, Medium, after the warehouse network was separated from the office network. (EXAMPLE)
What follows for the two risks outside appetite. Each has a treatment decision (RM-06) and an action expected to bring it back within appetite (EXAMPLE):
Risk | Action | Due | Residual now | Expected after | Expected position |
|---|---|---|---|---|---|
R-01 | TA-01 Rebuild the ordering platform's recovery so it can be restored within 24 hours (Head of IT; awaiting board approval) | 2026-12-15 | 4 × 2 = 8 High | 4 × 1 = 4 Medium | Within appetite |
R-02 | TA-02 Call-back verification of every change to supplier bank details, and a payment verification service (Chief Financial Officer; in progress) | 2026-11-30 | 3 × 3 = 9 High | 3 × 2 = 6 Medium | Within appetite |
R-01's action, TA-01, is the decision the Board is asked to take in the Q3 2026 report. Neither risk is accepted: accepting either (High, outside appetite, within tolerance) would need the accountable executive and Head of Information Security, and executive management as well — here, the Executive Committee — and both would still count as outside appetite. (EXAMPLE)
The one accepted risk in the register, R-12 (customer data on an unencrypted laptop at the smaller warehouse site is lost or stolen), is Medium and within the Cautious appetite for customer and personal data, so its band's approvers were enough: Head of Logistics (risk owner) and Head of Information Security, on 2026-06-15, for review within 12 months. It is recorded on the Risk Acceptance Form & Approval Record. (EXAMPLE)
Guidance — delete before approval
Note what the test does for the board: of twelve top risks, it names the two that need a decision and says why, in the board's own terms. The other ten are within appetite and are not discussed, unless their supporting measures say something the register does not.
Related documents
Document | Relationship |
|---|---|
Risk Assessment Methodology & Scoring Model | Sets the 4 × 4 scale, the bands and the rules this statement applies (RM-01 to RM-12) |
Risk Identification & Assessment Operating Procedure | The procedure that brings risks into the register, where they are tested against this statement |
Information Security Risk Register | The register every risk is tested against, every quarter (RM-05, RM-11) |
Risk Treatment Plan | Records the treatment decided for each risk outside appetite (RM-06, RM-07) |
Risk Acceptance Form & Approval Record | Records each accepted risk, with the approval this statement requires outside appetite and tolerance (RM-08) |
Risk Reporting Dashboard | Reports the position against this statement, RMM-01, to executive management (RM-12) |
Board Reporting Narrative Model | P03 pack: how the position is reported to the board, and the out-of-cycle rule |
Adapting this template
Guidance — delete before approval
Small organisation: keep the three levels and the register test; you may use fewer categories (three or four is enough) and a single owner for several. The board may be the owners or directors meeting as such; record their approval in the same way. Where the Head of Information Security is also the IT manager, the appetite is still approved above them, by the owners or directors.
Regulated entity (NIS2, DORA, GDPR): NIS2 Article 21(1) requires measures appropriate and proportionate to the risks: the appetite is how you show what "proportionate" means for you, and the management body approves it. DORA Article 6(1) requires a documented ICT risk-management framework, and Article 8 regular identification and assessment of ICT risk; RTS 2024/1774 Article 3 requires the risk-management policy to indicate the approval of the risk tolerance level (Article 3(a)) and to bring ICT risk within that tolerance. Keep the approval block and minute as evidence. Where personal data is involved, GDPR Article 32 requires security appropriate to the risk to people, not only to the organisation: do not set an Open level for a category that covers personal data.
IT run by a service provider: the appetite is yours and cannot be delegated. Put risks that arrive through the provider in a third-party category, tell the provider which categories its services touch and their levels, and require it in the contract to report anything that could move one of your risks outside appetite.
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; Regulation (EU) 2016/679 (GDPR).
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Clause 5.1 — Leadership and commitment | Who decides: the board or management body sets and approves the appetite |
ISO/IEC 27001:2022 | Clause 6.1.1 — General (actions to address risks and opportunities) | Parts 1 and 2: the appetite that risk actions are planned against |
NIST CSF 2.0 | GV.RM-01 — “Risk management objectives are established and agreed to by organizational stakeholders” | Part 2: the overall statement and category levels, agreed by owners and approved |
NIST CSF 2.0 | GV.RM-02 — “Risk appetite and risk tolerance statements are established, communicated, and maintained” | Whole template: appetite and tolerance statements established, tested every quarter and reviewed |
DORA — Regulation (EU) 2022/2554 | Article 6(1) — a sound, comprehensive and well-documented ICT risk management framework as part of the overall risk management system | Whole template: the appetite as part of a documented ICT risk-management framework |
DORA — Delegated Regulation (EU) 2024/1774 | Article 3(a) — an indication of the approval of the risk tolerance level for ICT risk | Part 2, Approval: the approval of the tolerance level recorded |
Definitions
Term | Meaning in this template |
|---|---|
Appetite | The highest residual band a category's risks may reach and be accepted without escalation. |
Tolerance | The highest residual band a category's risks may reach for a time, while a plan brings them back within appetite. Critical is never within tolerance. |
Appetite level | One of Averse, Cautious, Open: the setting for a category that fixes its appetite and tolerance bands. |
Band | The range a score falls in: Low (1–3), Medium (4–6), High (8–9), Critical (12–16). |
Category | A group of risks that share an appetite level and an owner, such as service availability or financial fraud. |
Position | Where a risk, or the organisation, stands against the appetite: Within appetite; Outside appetite, within tolerance; Outside tolerance. |
Residual score | Impact × likelihood after existing controls, each rated 1 to 4 (RM-03). |
Register test | Comparing every risk's residual band with its category's appetite and tolerance, every quarter (RM-05). |
RMM-01 | Risks outside appetite and past tolerance: top risks whose residual band is above their category's appetite; and of those, above its tolerance. |