Risk and Resilience

Risk Appetite Is a Strategic Boundary, Not a Compliance Statement

How boards and executives can use risk appetite to shape strategy, portfolio choices, tolerances and resource allocation before commitments are made.

EraNorth Insights · 30 Aug 2026 · 12 min read

Risk appetite matters most before the organisation commits to a strategy, not after the risks have already been inherited by projects.

Many organisations have a risk appetite statement.

Far fewer use it to decide which opportunities they will pursue, how much concentration they will accept, how aggressively they will grow or when a strategic initiative has moved beyond an acceptable boundary.

The statement exists, but the portfolio behaves as though it does not.

This reduces risk appetite to a governance artefact rather than a strategic decision tool. The board may approve a broad description of acceptable risk, while major investments, acquisitions, transformation programs and new-market decisions continue to be evaluated primarily through return and delivery feasibility.

By the time risk appetite is applied, the enterprise may already be committed.

The Strategic Context

The supplied Week 6 material places portfolio risk management above individual project risk processes. It emphasises that risk at portfolio level should be considered in relation to strategic objectives, aggregate exposure, interdependencies, capacity, capability and organisational value.

The supplied COSO 2012 thought-leadership paper makes the strategic link especially explicit. It describes risk appetite as the amount of risk an organisation is willing to accept in pursuit of value and connects that appetite to strategy setting, resource allocation, governance, culture, infrastructure and management decisions.

The document also distinguishes appetite from related concepts such as risk capacity, risk tolerance, risk profile and attitudes towards risk.

Although the COSO source is historical and should not be presented as a statement of current framework wording without verification, its core logic is durable:

strategy and risk are inseparable.

The enterprise does not first choose a strategy and then discover its risk appetite. The two should be considered together.

Related article: Portfolio Management Is Capital Allocation in Action

What Leaders Commonly Misread

The first misread is that a lower risk appetite is inherently more mature.

It is not.

A business facing technological disruption may need to accept substantial innovation risk because the alternative is strategic decline. A regulated utility may accept very little safety or compliance risk while accepting significant capital-project uncertainty. A technology company may tolerate product experimentation while maintaining near-zero tolerance for data privacy violations.

Risk maturity is not about minimising exposure.

It is about accepting the right exposure deliberately.

The second misread is that risk appetite can be expressed as one enterprise-wide sentence.

A broad statement can be useful, but meaningful choices often require more specific boundaries across risk categories, strategic objectives or business activities.

The third misread is that appetite and tolerance are interchangeable.

The COSO material distinguishes them conceptually. Appetite is broad and strategic. Tolerance translates that broad intent into acceptable variation around objectives and operating decisions.

The fourth misread is that risk appetite belongs to the risk function.

Risk specialists can facilitate analysis and challenge, but the decision belongs to management and governance because it determines what the organisation is prepared to pursue.

Reframing the Issue

Risk appetite is best understood as a strategic boundary around ambition.

Every strategy creates exposure.

Growth can create customer concentration, working-capital pressure and execution risk. Digital transformation can create cyber, privacy and operational transition risk. Global sourcing can reduce cost while increasing geopolitical and supply-chain exposure. Innovation can create technical and commercial uncertainty. Efficiency programs can reduce resilience if contingency is stripped too far.

The purpose of risk appetite is to make leadership explicit about how much of that exposure the organisation is prepared to carry in exchange for the expected value.

That makes appetite a portfolio selection question.

A project may be attractive on its own but unacceptable because the portfolio already contains too much exposure to the same client, technology, geography, supplier or capability constraint.

Related article: Risk Transparency Is Not Risk Control: Build Portfolio Coping Capacity

Appetite, Capacity, Tolerance and Profile

These concepts become useful when leaders keep them distinct.

Risk appetite

How much risk is the organisation willing to accept in pursuing value?

This is a strategic choice.

Risk capacity

How much risk can the organisation actually absorb without threatening viability, critical obligations or strategic continuity?

Capacity is a constraint, not a preference.

An organisation may want aggressive growth but lack the balance-sheet strength, capability or resilience to support the downside.

Risk tolerance

How much variation is acceptable around a particular objective or operating outcome?

Tolerance makes appetite actionable.

Risk profile

What risks is the organisation currently carrying, and how are they distributed?

The profile describes the present exposure. It should inform the decision but should not automatically define what future appetite ought to be.

These distinctions matter because an organisation can be operating above appetite while still remaining within capacity. That may be temporarily survivable but strategically undesirable.

It can also choose an appetite so aggressive that it approaches capacity. That decision demands stronger governance because failure has less room to be absorbed.

Risk Appetite Should Change Portfolio Construction

If risk appetite does not affect portfolio composition, it is not functioning as a strategic boundary.

Consider a hypothetical engineering business with an appetite for growth but a low tolerance for concentration risk.

A series of individually attractive contracts may all come from the same customer and use the same scarce engineering capability. Each project might pass its own business case and project risk review. The portfolio, however, could violate enterprise appetite because revenue, resource and contractual exposure have become concentrated.

The appropriate response might be to:

  • defer another contract;
  • renegotiate terms;
  • diversify customers;
  • strengthen capability before accepting further work;
  • retain more contingency;
  • change the contract mix.

That is portfolio risk management in practice.

The question is not simply whether each component is acceptable.

It is whether the combined portfolio remains inside the strategic risk boundary.

The Incentive Test

The COSO material also links risk appetite to compensation and organisational behaviour.

This is one of the most useful governance tests.

An organisation may state that safety, customer trust or prudent capital allocation is central to its appetite. But if leaders are rewarded overwhelmingly for revenue growth, schedule or short-term margin, the practical appetite may be very different.

People learn what the organisation truly tolerates from:

  • promotion decisions;
  • incentive structures;
  • how bad news is treated;
  • whether risky success is celebrated more than disciplined restraint;
  • whether executives accept projects outside agreed thresholds when growth is under pressure;
  • whether risk owners can stop activity without political penalty.

The real appetite is therefore partly visible in decisions under pressure.

A beautifully written statement that conflicts with incentives is not governance. It is branding.

Decision Framework: Translate Appetite Into Portfolio Choices

A useful risk-appetite process can move through seven steps.

1. Clarify strategic objectives

What is the organisation trying to achieve, and which objectives require meaningful risk-taking?

2. Identify critical exposure categories

Which types of risk could materially affect value, viability, reputation, safety or strategic freedom?

3. Define appetite

Where is the organisation willing to accept more exposure, and where does it want tight boundaries?

4. Test capacity

Can the organisation absorb the downside implied by the chosen appetite?

5. Translate appetite into tolerances

Create observable thresholds for relevant portfolio decisions, such as concentration, capital at risk, dependency exposure, safety, schedule or benefit variance.

6. Apply to portfolio selection and balancing

Do not wait for project execution. Test candidate and existing components against the aggregate risk position.

7. Monitor and revise

Risk appetite should not be set once. The COSO source explicitly argues that it should be reviewed as business models and operating conditions change.

A portfolio decision that was acceptable last year may no longer be acceptable after a major loss, acquisition, regulatory change or deterioration in capability.

Risk Appetite Must Be Specific Enough to Change Behaviour

Statements such as “we have a moderate risk appetite” are usually too abstract to govern decisions.

A stronger articulation might distinguish:

  • high appetite for bounded product experimentation;
  • moderate appetite for entry into adjacent markets;
  • low appetite for customer concentration above a defined threshold;
  • very low appetite for safety, regulatory or ethical breaches;
  • controlled appetite for technology dependency where contingency exists.

The exact categories will differ by organisation.

The point is that managers should be able to infer what the statement means when deciding whether to approve, defer, redesign or stop work.

If two competent executives can read the same appetite statement and reach opposite conclusions about a major investment, the statement may be too vague.

From Strategy to Execution

Immediate action should test a small number of material portfolio decisions against current risk appetite. Where did the appetite actually change the decision? If the answer is nowhere, the framework may be ceremonial.

Medium-term capability building should connect enterprise appetite to portfolio thresholds, escalation rules and investment criteria. Risk should be visible alongside value, capacity and strategic alignment.

Long-term strategic positioning requires boards and executive teams to build a culture of deliberate risk-taking. That means not only preventing excessive exposure but also avoiding strategic paralysis. A risk appetite that forbids the risks necessary to execute the strategy is evidence that either the appetite or the strategy is incoherent.

Related article: Governance Should Fit the Organisation, Not the Template

Signals to Monitor

Risk appetite may be weakly embedded when:

  • major investments are approved without explicit discussion of aggregate exposure;
  • risk appetite is mentioned in policy but absent from portfolio papers;
  • tolerance breaches are known but repeatedly waived without strategic review;
  • incentives reward behaviour inconsistent with stated appetite;
  • business units interpret the same appetite statement differently;
  • the organisation becomes more conservative after every failure but never asks which risks are necessary for strategy;
  • project teams inherit risk from commercial or portfolio decisions made above them;
  • appetite is reviewed annually even when the business model has changed materially.

A mature system can explain both where it is willing to take risk and where it will refuse attractive opportunities because the portfolio exposure has become unacceptable.

References

  • Rittenberg, L. & Martens, F. 2012, Understanding and Communicating Risk Appetite, Committee of Sponsoring Organizations of the Treadway Commission.
  • Teller, J. & Kock, A. 2013, 'An empirical investigation on how portfolio risk management influences project portfolio success', International Journal of Project Management, vol. 31, no. 6, pp. 817-829.
  • University of South Australia, Portfolio Risk Management, Week 06 teaching materials supplied for this synthesis.

Questions for the Leadership Team

  1. Which strategic risks are we deliberately willing to take because the strategy requires them?
  2. Where does our current portfolio exceed stated appetite through concentration or interdependency?
  3. Are our risk tolerances specific enough to change operating and investment decisions?
  4. What is the difference between the risk we are willing to take and the risk we are actually carrying?
  5. Where do incentive systems encourage behaviour outside our stated appetite?
  6. Which attractive opportunities would we refuse because they would push the portfolio beyond an acceptable boundary?
  7. Has our risk appetite changed as our business model, capital position or capabilities have changed?

Closing Perspective

Risk appetite is not a statement about how cautious the organisation wishes to appear.

It is a choice about how much uncertainty and downside the enterprise will deliberately carry in pursuit of value.

Used properly, it constrains strategy, shapes portfolio construction, informs resource allocation and sets boundaries for operating decisions.

Used poorly, it becomes a policy document that project teams discover only after the real strategic commitments have already been made.

The leadership task is to make appetite visible at the point of choice.


About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.