In an AI context

Risk appetite is a general risk-management idea that behaves unusually badly when applied to AI, for three reasons worth stating before any threshold is set.

AI risk is not one risk. A system can fail by being wrong, by being unfair, by being inexplicable, by being manipulated, by acting beyond its authority, or by depending on a supplier that changes underneath you. These carry genuinely different appetites. An organisation might reasonably accept a meaningful error rate in document tagging while accepting none at all in that same system's handling of protected characteristics. A single posture across all of it destroys the information.

Appetite is consequence-dependent, not system-dependent. The same model at the same accuracy is prudent in one deployment and reckless in another. A 4% false-positive rate is unremarkable where a human reviews every flagged item and unacceptable where applications are declined automatically. Appetite therefore attaches to the decision the model influences, not to the model.

It degrades without anyone acting. A credit policy does not become more permissive because time passed. A model does. Model drift means the risk position on the day the board approved it is not the position six months later, with no decision having been taken by anyone. An appetite with no re-measurement cadence is a snapshot presented as a control.

The practical consequence is that a usable AI risk appetite is a matrix rather than a statement: risk dimension against decision-consequence tier, with a measurable threshold in each cell.

Appetite, tolerance and capacity

These three are routinely used interchangeably, and the confusion is not pedantic — it determines who is allowed to decide what.

Appetite is how much risk the organisation chooses to accept in pursuit of its objectives. Forward-looking, strategic, set by the board. A statement of intent.

Tolerance is the boundary of acceptable variation around that intent, expressed as measurable thresholds. Operational, and set by management within the appetite the board approved. Appetite says "we accept limited error in customer-facing automation." Tolerance says "false-positive rate above 3.5%, measured weekly."

Capacity is the maximum exposure the organisation could absorb before something breaks — regulatory standing, operational resilience, solvency. It is a fact about the organisation, not a choice. Appetite should sit meaningfully below it; where the two are close, the organisation is running without margin whatever its statement says.

There is a fourth element most statements omit, and its absence is the commonest single reason they do not work. A trigger is what happens when a tolerance is breached, decided in advance — not "escalate to the risk committee", which describes a meeting rather than an action, but the specific consequence: the system reverts to human review, the feature is disabled for new users, the model rolls back. Without one, a breach produces a discussion, and discussions held during an incident are how organisations discover their appetite statement was decorative.

What good looks like

Three properties distinguish an appetite statement that changes decisions from one that decorates a board pack.

Every threshold names a metric, a population and a frequency. "High accuracy" is not a threshold. "Precision at or above 0.95 on the weekly production sample" is. A threshold that cannot be measured is more dangerous than no threshold, because it looks like a control.

Every dimension has a trigger that is an action. If the answer to "what happens when this is breached" is a meeting, the appetite has not been set.

It is allowed to say no. An appetite statement whose every cell is a number has quietly decided that everything is permitted at some price. "Not permitted without specific board approval" is a legitimate and often correct entry, particularly for automated decisions materially affecting a person's rights, finances, health or employment.

The test of whether it worked is not that the statement exists. It is that six months later a threshold was breached, the pre-agreed trigger fired, and nobody had to convene a meeting to decide whether it mattered.

Common failure modes

The unfalsifiable appetite. "We have a low appetite for AI risk." Nothing can breach it, so nothing does, so it never changes a decision. Test: can you name a specific measurement that would put the organisation outside its stated appetite? If not, it is a value, not an appetite.

The uninstrumented threshold. Appetite set against metrics nobody collects — fairness thresholds on a demographic breakdown the organisation does not record, drift thresholds with no production monitoring behind them. Test: for each threshold, name the system that produces the number and the person who reads it.

The frozen appetite. Set at deployment and never revisited while the model drifts, the deployment scope creeps and the regulatory floor rises underneath it. Test: when was it last changed, and what changed it?

Where it appears in frameworks

ISO/IEC 42001, Clause 6.1.2 requires the organisation to establish and maintain AI risk criteria including criteria for accepting risk — the standard's formal expression of appetite. Clause 6.1.3 then requires every identified risk to be treated by a documented choice to mitigate, avoid, transfer or accept, captured in a Statement of Applicability. An auditor asking how acceptance decisions were made is asking to see appetite.

NIST AI RMF, GOVERN 1.3 requires that processes are in place to determine the needed level of risk management activity based on the organisation's risk tolerance, and its playbook is explicit that tolerance should account for distinct sources of risk — financial, operational, safety and wellbeing, reputational, model. It deliberately does not prescribe levels; it requires that the organisation set them and apply them consistently.

PRA SS1/23, Principle 2 — for UK banks this is not advisory. The supervisory statement provides that the board should set a model risk appetite articulating the level and types of model risk the firm is willing to accept, and requires aggregate model risk to be kept within it. In effect since 17 May 2024, and every material AI system is a model.

Frequently asked questions

What is the difference between risk appetite and risk tolerance? Appetite is the strategic intent the board sets — how much risk the organisation wants to take. Tolerance is the measurable boundary management works within, expressed as specific thresholds. Appetite is a sentence; tolerance is a number with a metric, a population and a measurement frequency attached.

What is the difference between risk appetite and risk capacity? Capacity is the maximum the organisation could absorb before something breaks. It is a fact, not a choice. Appetite is what the organisation chooses to accept, and should sit meaningfully below capacity. An appetite set at capacity leaves no margin for the risk you did not model.

How do you set a risk appetite for AI systems? Set it across distinct risk dimensions — performance, fairness, explainability, security, autonomy, third-party dependency — and across tiers of decision consequence, rather than as a single organisational posture. Give each cell a threshold expressed in a metric you already collect, and attach a pre-agreed trigger to every threshold.

What are risk appetite metrics and indicators for AI? The usable ones are already instrumented: precision and recall against a named validation population, false-positive and false-negative rates separately rather than a single accuracy figure, outcome disparity ratios between demographic groups, drift measures against a deployment baseline, and override rates where a human can intervene. A metric nobody currently collects belongs in the instrumentation plan, not the appetite statement.

What are risk appetite levels? Most organisations express appetite qualitatively — averse, minimal, cautious, open — which works for enterprise risk and fails for AI, because the same label means different things at different decision consequences. The more useful structure is a tier: informational output a person acts on independently, advisory output that shapes a decision, automated output that takes effect without review, and automated output that materially affects a person's rights or finances. Appetite falls sharply across those four, and should.