Risk appetite is often described well and used poorly. Boards approve statements, metrics are documented and dashboards turn red or amber, yet teams are still unclear about what action a threshold breach should trigger. A useful risk appetite framework does more than express risk tolerance. It guides decisions.
This is one of the most common gaps in operational risk frameworks that otherwise look mature. The board has signed off on a thoughtfully worded appetite statement. KRIs are being tracked and reported. And yet, when a metric actually breaches its threshold, what happens next is often unclear, inconsistent, or dependent entirely on who happens to notice and how seriously they take it. A framework where the consequences of a breach are not pre-agreed is not really managing risk against appetite. It is measuring it and hoping someone responds appropriately.
Start with the difference between appetite, tolerance and capacity
Risk appetite is the level and type of risk the firm is prepared to take in pursuit of objectives. Tolerance is the boundary around acceptable variation. Capacity is the outer limit beyond which the organisation cannot safely operate. Keeping those ideas separate is what helps management interpret KRIs correctly.
These three concepts are frequently used interchangeably in practice, which causes real confusion when a metric moves. Appetite describes where the firm chooses to operate: a deliberate, strategic positioning that reflects the organisation's objectives and risk culture. Tolerance describes the acceptable range of variation around that chosen position, recognising that risk levels naturally fluctuate and a firm cannot expect to sit precisely on its appetite level at all times. Capacity is different again: it is the absolute maximum the organisation could withstand before its viability or regulatory standing is genuinely threatened, regardless of what the firm would prefer. A KRI moving from green to amber typically signals movement within tolerance that warrants attention. A KRI approaching capacity signals something far more serious that should trigger an entirely different level of response. Conflating these three concepts, or failing to define them distinctly within the framework, is a major reason firms struggle to interpret their own metrics consistently.
Write appetite statements that can actually be used
Good appetite statements are clear, plain and tied to business outcomes. They explain where the firm is comfortable, where it is cautious and where it has near-zero tolerance. They should not read like vague aspirations. They should give managers a basis for escalation, prioritisation and challenge.
A statement such as "the firm has a low appetite for operational risk" is not actionable by anyone. It does not tell a manager whether a particular decision falls within or outside that appetite, because "low" is undefined and unmeasurable. A more useful statement specifies the dimension of risk and gives it concrete boundaries: for example, "the firm has very low appetite for customer-impacting IT outages, and will not tolerate more than two hours of unplanned downtime to core customer-facing systems in any single incident, or more than eight hours of cumulative downtime in any rolling twelve-month period." That statement gives a clear basis for a manager to assess whether a current incident, or a proposed change that introduces new technical risk, sits within or outside the board's stated tolerance. It also gives the second line something concrete to monitor and report against, rather than a subjective judgement call about what "low" means in any given context.
The most useful appetite frameworks typically cover several dimensions explicitly: financial loss tolerance, customer impact tolerance, regulatory and compliance tolerance, and reputational tolerance, with each given its own specific, measurable boundary rather than a single blended statement trying to cover everything at once.
Choose KRIs that measure meaningful exposure
Measure what matters
KRIs should track the conditions that indicate rising exposure: outage duration, failed reconciliations, incident frequency, backlog age, service-level breaches or unresolved actions. They should not be selected simply because the data is easy to obtain.
This last point deserves emphasis because it is one of the most common ways KRI programmes lose their value over time. It is genuinely easier to track metrics that already exist in some system somewhere than to build the capability to track the metric that actually matters most. The result, in many firms, is a dashboard full of indicators that are easy to produce but only loosely connected to the risks the board actually cares about. A useful discipline is to start from the appetite statement and work backwards: for each material risk the firm has defined an appetite for, what would genuinely tell management, in advance, that exposure is rising toward an unacceptable level? Sometimes that data already exists and is easy to capture. Often it requires some investment to build the capability to track it properly. That investment is usually worthwhile, because a KRI that does not actually measure the thing it claims to measure provides false reassurance, which is arguably worse than having no indicator at all.
Set thresholds that lead to action
Warning and action thresholds should align with board-approved appetite. A red result is not useful if nobody knows whether it triggers investigation, remediation, acceptance or board escalation. Thresholds need owners, reporting frequency and playbooks.
A genuinely useful threshold structure typically has at least two levels. An amber or warning threshold signals that exposure is rising and warrants closer attention, perhaps triggering a review by the risk owner or a note in the next management reporting cycle. A red or action threshold signals that the firm is at or near the edge of its stated appetite, and should trigger a specific, pre-agreed response: an investigation into root cause, a remediation plan with defined timelines, immediate escalation to a named committee or the board, or, in some cases, a deliberate and documented decision to accept the position temporarily with clear reasoning. What should never happen is a red KRI sitting on a dashboard for several reporting cycles in succession with no documented response, because that pattern signals to everyone watching, including any external reviewer, that the appetite framework is not actually being used to manage anything.
Review and recalibrate
KRIs should evolve as the business changes. Historical events, stress scenarios, new products, operating model changes and control improvements all affect whether thresholds remain appropriate. Static KRIs can create false reassurance.
A threshold that was appropriately calibrated when the firm had a particular volume of transactions, a particular technology stack, or a particular product mix may no longer be appropriate two years later if the business has grown, changed direction, or strengthened its underlying controls. Firms that set KRI thresholds once and never revisit them often end up in one of two unhelpful positions: thresholds that are consistently breached because the business has genuinely grown beyond the original calibration, which trains people to ignore breaches as routine noise, or thresholds that are never approached because they were set too conservatively relative to where the business now actually operates, which provides false comfort that risk is well within bounds when the indicator has simply stopped being a meaningful test.
Common mistakes to avoid
The most common mistakes are too many indicators, weak ownership, confused definitions, unclear escalation and no relationship between appetite, controls and incidents. If your dashboard is colourful but not decision-useful, simplify it. Better a handful of trusted KRIs than dozens of low-value metrics.
Too many indicators is a particularly common trap, often born from good intentions: each business area wants its own metrics represented, and over successive reporting cycles the dashboard grows until it contains forty or fifty indicators that no board member can meaningfully absorb in a single sitting. At that point, the dashboard stops functioning as an early warning tool and starts functioning as an exercise in data collection. A smaller set of well-chosen, well-understood KRIs, each clearly tied to a specific appetite statement and each with a clear owner and escalation path, will do far more genuine work than a comprehensive but unwieldy dashboard that overwhelms rather than informs.
Conclusion
Risk appetite is where strategy meets discipline. KRIs make that discipline visible. When the two are designed together, firms get an early-warning mechanism that supports better management action instead of retrospective explanation.
Designing an appetite framework and KRI set that genuinely drives decisions, rather than simply producing a dashboard, is covered in detail in our full whitepaper, including practical guidance on setting thresholds, defining escalation playbooks, and calibrating indicators as the business changes. Download the complete Operational Risk whitepaper for the full approach to risk appetite and KRI design.