Power of Risk Appetite

Risk appetite setting is a powerful tool to encourage the taking of risks across all parts of the organisation.

Historically risk appetite setting has been completed as an isolated risk process that occurs to reduce risk-taking. However, organisations are in the business of taking risks, and a forward-looking, positive risk appetite framework and risk-setting process will empower management and employees to deliver risk-based outcomes in line with the Board’s expectations.

What is the alternative approach?

Deloitte outline in “Risk appetite frameworks – How to spot the genuine article” that,

Everyone these days seems to agree that risk appetite frameworks are good things – even if no-one can quite agree what a good one looks like.

The alternative approach to risk appetite setting is to not focus on the process but on the business engagement. In essence, facilitating constructive challenges, debates and discussions on the key business activities with the business leaders, and then having them and their teams embrace the risk settings as a business enabler.

To support this facilitation, the usage of a structure that enhances the discussion is critical and that is where the simple attributes thrive.

Simple Attributes for Risk Appetite

In our alternative approach there are 4 simple attributes to setting risk appetite:

  1. Target or “Sweet Spot”;
  2. Operating range;
  3. Tolerance; and
  4. Exceeding.

Further information on each is outlined below.

“Sweet Spot”

Firstly, we define the “sweet spot” for the business strategy and operations being delivered every day by our people.

This “sweet spot” defines the point we are aspiring to move to; whether that is a growth/increasing position or a contracting/decreasing position. These terms must be adapted to each organisations culture and language. The key here is to use human language that people operate within in their daily interactions.

To support the development of this attribute, our posting on Agile Risk Management outlines the importance of undertaking shorter sprints of activity. This requires us to critically assess our approach to the right sweet spot for risks in each sprint.

Operating Range

Once you have established the “sweet spot” we recommend developing an “operating range”.

The “operating range” is the range of risk the business is willing to take to execute its strategy and operational outcomes. This range will have an upper and lower bound, providing for movements in risk-taking due to internal and external factors and forces.

A good operating range allows factors that are part of normal business operations and part of expected strategic decisions to occur, without exceeding your normal expectations.

Tolerance

The third step is then to set a “tolerance” level, which although we do not want to move within this territory, we are willing to accept a brief entry.

Developing a tolerance should include exploring the “what ifs” and the “black swan” events that could impact your business. The “what ifs” help ensure the level of appetite incorporates some of the unknowns, however, it must not be too wide so as to accept the unknowns as part of risk-taking. By this we mean, we need to test the boundaries of the Board and management in undertaking those business activities and strategic plans.

The key aspect is when an organisation is in the tolerance level, actions must be taken to move back within the operating range.

Exceeding

The final step is to set the level(s) where we are exceeding the organisation’s appetite.

In these circumstances, management will take immediate action to move back within tolerance and then the operating range. In these circumstances, there may need to be consequence management on those responsible for exceeding appetite (i.e. some form of “cost” of exceeding appetite, including training, coaching, and/or potential financial penalty).

In Summary

These simple steps provide a template for understanding, documenting and monitoring your appetite settings.

The setting of risk appetite is powerful in ensuring organisations operate effectively and take the risk needed to be successful.

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.