Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
5 to work through
-
intermediate
A board sets a risk appetite statement: no production personal data in non-production environments, with no exceptions. Engineering accepts it. What has the organisation bought, what is it paying, and when does the cost surface?
2 min answer -
advanced
A board sets an appetite of at most two customer-visible material incidents a year. Engineering ships about 3000 production changes a year with a change failure rate near 15%. Roughly how many material incidents does that imply, and which lever actually closes the gap?
3 min answer -
advanced
A board's risk appetite statement allows at most four hours of customer-visible unavailability per year for the payments API. The service currently runs as two VMs in a single Azure availability set behind a load balancer, with a managed database in the same region. Roughly what availability does the appetite imply and does the design fit?
2 min answer -
advanced
An organisation states a risk appetite and teams still make inconsistent decisions. What is missing?
2 min answer -
advanced
An organisation states a risk appetite. How does that become something engineers can act on?
1 min answer
3 terms in this topic
Change Risk Budget
A stated ceiling on material customer-visible incidents per period, converted into the change failure rate and escape rate engineering must design fo…
conceptRisk Appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives, stated explicitly enough to guide a design decision.
conceptRisk Tolerance Statement
The board-level declaration of how much of each risk type the organisation will accept, which is what tells an architect which risks may be accepted …
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.