Risk appetite is the types and amount of risk an organization is willing to accept in pursuit of value. A key risk indicator (KRI) is a metric that gives an early signal of increasing risk exposure, so it shows whether the organization is moving toward the limits its appetite sets.
COSO sets out this topic in Risk Appetite: Critical to Success (May 2020) and Developing Key Risk Indicators to Strengthen Enterprise Risk Management (December 2010).
What is risk appetite? The types and amount of risk an organization is willing to accept in pursuit of value
COSO's 2017 Enterprise Risk Management framework defines risk appetite as "The types and amount of risk, on a broad level, an organization is willing to accept in pursuit of value." COSO draws out four points from that wording. Risk appetite is intentionally broad, focuses on the risk that needs to be taken to pursue strategies, recognizes that risk is more than individual decisions and links to value.
In plain English, risk appetite answers one question: how much risk is the organization prepared to take on to reach its objectives? The answer sets boundaries for decisions, and COSO notes that it can show an organization is taking too little risk as well as too much.
COSO also states that risk appetite is not limited to one sector: "It is embodied in many financial service regulations, but can help all organizations to better understand and manage performance."
Risk appetite statements: objective-focused and risk-focused styles
Organizations write down their appetite as a statement. COSO describes two styles. An objective-focused statement is tied to strategy and to how the organization intends to create value. COSO's sample reads: "We will pursue innovation to improve customer service and efficiency in operations unless such innovation potentially elevates risk relating to internal capabilities or creates risk of significant disruption to business operations."
A risk-focused statement ties to a category of risk in the risk register and states the expected outcome more precisely. COSO's example for a community bank reads: "Maintain exposure to geographic concentrations in any one region to 20% of the overall portfolio (risk: credit losses)." COSO suggests adopting an objective-focused approach that cascades into risk considerations, unless regulatory or other business reasons limit that choice.
Statements can also use broad terms such as low, medium and high. COSO observes that medium is often the hardest to interpret and encourages adding context. Some organizations go further and state a figure, such as: "We are not comfortable accepting more than a 10% probability that we will incur losses of more than $1 million in pursuit of a specific objective."
How to set and review risk appetite: discussion, validation and regular revision
COSO describes three approaches that organizations often use, alone or together, to bring out the views the board and management hold about appetite. They are facilitated discussions about mission and vision, discussions about strategies and objectives and analysis of performance. COSO adds that it is usually a mistake to focus only on senior management and overlook those who handle day-to-day activities.
Once appetite is stated, COSO says it needs to be validated, communicated and reviewed:
1. Validate it. Apply the statements to a series of past decisions to see whether decisions were made outside the intended guidance.
2. Communicate it in language that works for each audience, and make it precise enough to be used in decisions and monitoring.
3. Operationalize it through tolerances and, where necessary, policy.
4. Review it regularly. COSO states: "Appetite cannot be set once and then left alone for extended periods."
5. Assign someone accountable. COSO reports that without a person accountable, efforts to develop appetite are seldom sustained in practice.
COSO also suggests asking how often performance approaches the set boundaries. If an organization never approaches them, or constantly exceeds them, the strategy may be unclear, the appetite may be poorly constructed or the organization may not be behaving consistently with its own rules.
Risk appetite vs risk tolerance: how they differ and how indicators fit in
COSO notes that documents use the terms risk appetite and risk tolerance in different ways, sometimes interchangeably, and states that they are related but different ideas. It defines tolerance as "the boundaries of acceptable variation in performance relative to objectives." COSO's Figure 4 sets out three layers:
| Layer | Where it applies | What it focuses on |
| Appetite | Through the development of strategy and the setting of objectives | The overall goals of the business, and aids decision-making |
| Tolerance | In the execution of strategy | Objectives and variation from plan, tying objectives to measures |
| Indicators and triggers | At any level of the business | Specific risks, tying risks to measures |
COSO's own worked case shows how the layers connect. An organic food company states an appetite for innovation. It sets a performance target of 8 products in research and development at all times, with a tolerance, or acceptable range, of 6 to 10. When performance moves outside that range, COSO says management and the board should challenge the organization to bring it back in line. COSO also notes there may be business reasons to operate outside the boundaries, and that management may revisit the tolerance levels.
What is a key risk indicator? A metric that gives an early signal of increasing risk
COSO's paper on key risk indicators states: "Key risk indicators are metrics used by organizations to provide an early signal of increasing risk exposures in various areas of the enterprise." Some are simple key ratios. Others combine several individual indicators into a multi-dimensional score about emerging exposures.
The paper separates KRIs from key performance indicators (KPIs). KPIs often report on historical results, so they "mostly focus on results that have already occurred." A KRI looks ahead. COSO illustrates the difference with one objective, managing the collection of accounts receivable to reduce loss from write-offs:
| Key performance indicator (KPI) | Key risk indicator (KRI) |
| Data about write-offs of accounts in the most recent month, quarter and year | Analysis of the reported financial results of the company's 25 largest customers, or general collection challenges in the industry, that show trends signaling future collection concerns |
The KPI reports a risk event that has already happened, because a customer failed to pay. The KRI tries to anticipate collection problems before they occur.
How to build key risk indicators: objectives, root causes, thresholds and reporting
COSO's paper sets out a method for building KRIs. Each step is described in the paper:
1. Start from objectives. Selecting effective KRIs starts with a firm grasp of organizational objectives and the risk events that might affect them.
2. Work backwards from a risk event. Identify the intermediate and root cause events that led to it. COSO notes that the closer a KRI is to the root cause, the more time management has to act.
3. Start small. COSO suggests taking the top 5 to 10 most significant risks and asking each risk owner to identify one or two KRIs.
4. Set thresholds in advance. Management pre-determines levels for each KRI that trigger action, with action plans pinpointed in advance.
5. Define the data. Everyone collecting and aggregating KRI data needs to be clear about the definition of each data item, and the quality and source of the data matter.
6. Report at the right level. Boards and senior management should be kept updated on KRIs for the top risk exposures. COSO notes that dashboards overlaying trigger points, with green, yellow and red status colors, give an intuitive view.
7. Validate and refresh. Even well-designed KRIs can lose value as objectives and strategies change, so their predictive ability needs ongoing assessment.
COSO lists six qualities of well-designed KRIs. They are based on established practices or benchmarks, developed consistently across the organization, unambiguous and intuitive, comparable across time and business units, able to assess the performance of risk owners on a timely basis and efficient in the resources they consume.
COSO also gives a caution: "a KRI does not manage or treat risk, and can lead to a false sense of security if poorly designed."
How risk appetite, tolerance and KRIs fit together: a fictional walk-through
This scenario is illustrative. It applies the COSO material above and does not describe a real company.
A regional parcel delivery company has an objective to deliver parcels on time. Its appetite statement says it has a low appetite for decisions that put on-time delivery at risk and a moderate appetite for trialing new routes. Its tolerance sets a target on-time rate with an acceptable range either side. The company then picks a KRI that sits closer to the root cause than the on-time rate itself, such as the number of unfilled driver roles each month. COSO lists key staff turnover among its examples of indicators of conditions that may start a chain of events.
The company sets a threshold for that KRI in advance and agrees what happens when it is crossed, such as a review of rosters. COSO describes the same mechanism: when a KRI reaches a pre-determined level, management acts to adjust before the risk event occurs. COSO's paper also notes that mapping KRI measures to appetite and tolerance levels makes a KRI a useful tool for articulating appetite.
Risk culture: how a risk-aware culture reinforces appetite
This section covers only what COSO says about culture in the context of appetite. COSO states that applying appetite requires "a culture that is aware of strategy, objectives, and risk." In an effective culture, "each member of the organization is clear on what is acceptable and what is not." COSO says a risk-aware culture helps reinforce appetite by supporting:
- consistency between appetite, strategy, objectives and relevant reward systems
- consistent understanding of appetite and related tolerances in each organizational unit
- consistent implementation across units
- understanding of changes in appetite
COSO's paper on KRIs makes a similar point: developing a set of KRIs "requires sensitivity to organizational culture and a strong message of the importance of this task from top management and the board of directors."
Frequently asked questions about risk appetite and key risk indicators
What is the difference between risk appetite and risk tolerance?
Risk appetite is the types and amount of risk an organization is willing to accept in pursuit of value, and it applies through strategy and objective setting. Risk tolerance is the boundaries of acceptable variation in performance relative to objectives, and it applies in the execution of strategy (COSO, Risk Appetite: Critical to Success).
Is risk appetite only relevant to financial services?
No. COSO states that risk appetite is embodied in many financial service regulations but can help all organizations to better understand and manage performance.
What is the difference between a KPI and a KRI?
A KPI usually reports on results that have already occurred. A KRI provides an early signal of increasing risk exposure, so management can act before a risk event occurs (COSO, Developing Key Risk Indicators).
Does a key risk indicator reduce risk?
No. COSO states that a KRI does not manage or treat risk and can create a false sense of security if poorly designed. A KRI can trigger action, and the action is what treats the risk.
From appetite to action: how KRIs connect to third-party risk, controls and enterprise risk management
Appetite applies to suppliers as well as to strategy. The G7's elements for third-party cyber risk management list "setting a risk tolerance for third-party relationships" within governance, and the same document says an entity "may collect and analyse cyber risk metrics and risk indicators to support monitoring."
KRIs sit alongside controls, which are the actions that keep risk inside appetite.
COSO suggests incorporating appetite and tolerance measures into an existing governance, risk and compliance system. Ideagen Risk Management connects risks, controls and objectives in one system for financial, operational and strategic risk.
Explore risk management solutions
Roll up your risk into one system for full visibility, maximum control coverage and joined-up reporting.