For Board · Heads-of
AI Risk Appetite Statement Template
A fill-in template and companion tracker for setting AI risk appetite across six risk dimensions and four decision-consequence tiers, with a measurable tolerance threshold and a pre-agreed trigger in every cell.
- risk appetite
- board oversight
- iso-42001
- governance
- model risk
Why this tool exists
Give a board something it can actually govern with. Most AI risk appetite statements express a single qualitative posture across all AI activity, which nothing can falsify, so nothing ever breaches it. This template replaces that with a matrix: risk dimension against consequence tier, a threshold naming a metric and a measurement frequency in each cell, and an action attached to every threshold.
How it's used
Used when a board is asked to approve an AI risk appetite for the first time, or when an existing enterprise appetite statement has to be extended to cover AI systems. Also used by a second line function preparing the paper that goes to that board. For UK banks it maps directly onto the PRA SS1/23 Principle 2 expectation that the board sets a model risk appetite.
What you get
A 12-page Word template covering scope, the four consequence tiers, appetite and tolerance across six risk dimensions, governance and approval, and a traceability appendix. Alongside it, a six-sheet Excel workbook holding the same structure as a live tracker: an appetite matrix, a system register, a tolerance tracker that calculates breach status and review dates, and a dashboard.
The four terms it keeps apart
Appetite is what the board chooses to accept. Tolerance is the measurable boundary management works within. Capacity is the maximum the organisation could absorb, which is a fact and not a choice. A trigger is what happens when a tolerance is breached, decided in advance. Most statements omit the fourth, which is the commonest reason they never change a decision.
The six dimensions
Performance and accuracy, fairness and discrimination, transparency and explainability, security and adversarial exposure, autonomy and human oversight, and third-party dependency. Fewer than six collapses distinct exposures together. Many more stops being something a board can hold in mind.
On the example figures
The worked thresholds in both files are illustrative and clearly marked as such. They are plausible defaults chosen to show the structure, and they are not benchmarks. Do not adopt them without deciding they are right for your organisation.
What it does not do
It does not tell you where to set your appetite. That judgement depends on your business model, your regulatory perimeter and your risk capacity, and no template can supply it.
Further reading
See the companion article, Setting an AI Risk Appetite, and the risk appetite glossary entry for the underlying distinctions this template is built on, including appetite versus tolerance versus capacity.
Available formats
Downloads route through a short-lived signed link.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| ISO/IEC 42001:2023 | Annex A.2 | Policies related to AI |
| SS1/23: Model Risk Management Principles for Banks | Principle 2 | Model risk governance |
| ISO/IEC 42001:2023 | Clause 6 | Planning & risk |