Risk appetite and escalation

Risk appetite is the line between a risk you are willing to live with and one that needs a decision. Everything above the line requires either more treatment or a documented acceptance.

Where appetite is set

On the register, in Settings → Assessment. It is expressed as a band — for example, everything above High is out of appetite.

Why a band and not a number. A band is comparable across methodologies; a raw number is not. A score of 16 means something completely different on a 5×5 scale than on a 4×4, but “above appetite” means the same thing on both. This is what makes a group-level view possible when different registers score differently.

Bands and their obligations

Each band in your assessment methodology carries an obligation, not just a colour. Typical:

Band Obligation
Low Monitor. Review on the standard cadence.
Medium Treatment plan within 90 days.
High Mitigation plan within 30 days, owner confirmed.
Critical Executive notification, plan within 7 days.

These are configured per methodology — see Assessment methodologies. Setting them is what turns a colour-coded register into a governance process.

Seeing what is out of appetite

The register’s quick stats show the out-of-appetite count, and the appetite gap tile on each risk shows how far above the line it sits. Filter the risks table by appetite status to get the working list for a risk committee.

Accepting a risk above appetite

Sometimes the right answer is to accept a risk you cannot economically treat. Record this by setting the risk status to Acceptance and documenting the rationale in the narrative.

Known gap. Formal risk acceptance — a request, an approver with an authority limit, an expiry date and a scheduled re-review — is not yet a workflow in the app. Until it is, accepting a risk above appetite is a convention your organisation must enforce outside the tool. This is the single most audited decision in risk management, so agree how you will evidence it before you need to.