Risk appetite and risk tolerance are core concepts in risk management and GRC, helping organisations connect strategic intent with risk decision-making. And sometimes, going back to basics is exactly what we need.
A simple distinction:
Risk appetite sets the overall direction.
Risk tolerance makes that direction usable for specific decisions.
In this article, I look at where these concepts come from, how COSO, ISO and NIST frame them, and how they connect governance with practical risk decisions.
The key question is not simply whether an organisation has a risk appetite statement.
It is whether that statement can actually guide risk acceptance, treatment, exceptions, escalation and reporting.
Where do these concepts come from?
The modern concepts of risk appetite and risk tolerance developed through financial risk management, corporate governance and Enterprise Risk Management, before being incorporated into international risk management standards.
Turnbull Guidance (1999): helped frame the underlying governance question by asking boards to consider the extent and categories of risk acceptable for the company to bear.
COSO ERM (2004): formalised the distinction more explicitly. Risk appetite was positioned at the broader enterprise level, while risk tolerance described the acceptable variation relative to achieving specific objectives.
COSO ERM (2017): further integrated risk appetite with strategy and performance. Subsequent COSO guidance describes tolerance in terms of acceptable variation in performance relative to objectives, reinforcing the link between risk-taking, strategy and execution.
ISO Guide 73:2009: incorporated both risk appetite and risk tolerance into the ISO risk management vocabulary. Its successor, ISO 31073:2022, retains both concepts, defining risk appetite as the amount and type of risk an organisation is willing to pursue or retain, and risk tolerance as the organisation's or an interested party's readiness to bear residual risk in order to achieve its objectives.
FSB Principles for an Effective Risk Appetite Framework (2013): following the global financial crisis, connected risk capacity, appetite, limits and risk profile with strategy and board oversight.
The terminology differs across frameworks.
COSO emphasises acceptable variation around objectives and performance, while ISO expresses tolerance in terms of readiness to bear residual risk.
Despite those differences, both seek to translate an organisation's attitude toward risk into guidance for decision-making.
One picture, two concepts

Illustrative relationship between expected performance, risk appetite, risk tolerance and the broader risk universe.
Source NIST SP 800-161 Rev. 1 Update 1, Figure 16, printed page 268 (PDF page 282).
The diagram places expected performance within a broader risk universe, ranging from the best to the worst possible outcomes.
Risk appetite represents the range within which the organisation intends to operate.
Risk tolerance may establish wider boundaries, providing some flexibility around that appetite.
Between the two lies the review zone: a departure from appetite that remains within tolerance, but warrants attention and review.
In simple terms:
Appetite provides the direction.
Tolerance establishes the boundaries around that direction.
From governance to decisions
A simple way to view the relationship is:
Objectives → Risk Appetite → Risk Tolerance → Risk Decisions
Risk appetite provides overarching guidance about the risks an organisation is prepared to take in pursuit of its objectives.
Risk tolerance translates that direction into more specific boundaries.
Together, they help communicate risk expectations, support consistent decision-making, and determine when a risk may require treatment, acceptance, exception or escalation.
Those boundaries should remain aligned with senior leadership direction and take into account applicable legal, regulatory and contractual requirements.
What it looks like in practice

Illustrative examples from NIST SP 800-221, Table 3.
Take the government agency example.
The appetite establishes the direction: mission-critical systems should be protected from known ICT vulnerabilities.
The corresponding tolerance makes that direction actionable by defining a 14-day remediation boundary for critical vulnerabilities on systems designated as mission-critical.
The academic institution example shows that tolerance can also be conditional.
Some loss of student devices is expected and accepted, while there is no appetite for the loss of sensitive institutional information. The tolerance therefore applies only if sensitive information is prohibited from being stored on those devices.
The thresholds themselves are illustrative, not universal.
A 14-day remediation period, a four-hour outage or a particular loss threshold should not become an organisational tolerance simply because it appears in guidance.
What matters is that the tolerance is specific enough to make the broader appetite usable in governance and decision-making.
In a GRC context
Risk appetite and tolerance should not exist as isolated statements.
They should inform the organisation's broader GRC mechanisms, including risk assessment and acceptance criteria, policies, controls, exceptions, remediation, escalation and reporting.
This connection is explicit in NIST CSF 2.0, where GV.RM-02 expects risk appetite and risk tolerance statements to be established, communicated and maintained.
ISO/IEC 27001 also requires organisations to establish information security risk acceptance criteria. It does not define risk appetite or tolerance itself, but those concepts can help inform how such criteria are established.
This is ultimately what makes appetite and tolerance useful: they connect strategic risk direction with the way risk is governed across the organisation.
Risk appetite sets the direction.
Risk tolerance makes that direction usable for governance and decision-making.
Sources & further reading
- NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
- NIST SP 800-221, Enterprise Impact of Information and Communications Technology Risk: Governing and Managing ICT Risk Programs Within an Enterprise Risk Portfolio
- ISO 31073:2022, Risk management — Vocabulary
- COSO – Risk Appetite: Critical to Success (2020)
