For Board · Heads-of

AI Risk Appetite Statement Template

A fill-in template and companion tracker for setting AI risk appetite across six risk dimensions and four decision-consequence tiers, with a measurable tolerance threshold and a pre-agreed trigger in every cell.

  • risk appetite
  • board oversight
  • iso-42001
  • governance
  • model risk

Why this tool exists

Give a board something it can actually govern with. Most AI risk appetite statements express a single qualitative posture across all AI activity, which nothing can falsify, so nothing ever breaches it. This template replaces that with a matrix: risk dimension against consequence tier, a threshold naming a metric and a measurement frequency in each cell, and an action attached to every threshold.

How it's used

Used when a board is asked to approve an AI risk appetite for the first time, or when an existing enterprise appetite statement has to be extended to cover AI systems. Also used by a second line function preparing the paper that goes to that board. For UK banks it maps directly onto the PRA SS1/23 Principle 2 expectation that the board sets a model risk appetite.

What you get

A 12-page Word template covering scope, the four consequence tiers, appetite and tolerance across six risk dimensions, governance and approval, and a traceability appendix. Alongside it, a six-sheet Excel workbook holding the same structure as a live tracker: an appetite matrix, a system register, a tolerance tracker that calculates breach status and review dates, and a dashboard.

The four terms it keeps apart

Appetite is what the board chooses to accept. Tolerance is the measurable boundary management works within. Capacity is the maximum the organisation could absorb, which is a fact and not a choice. A trigger is what happens when a tolerance is breached, decided in advance. Most statements omit the fourth, which is the commonest reason they never change a decision.

The six dimensions

Performance and accuracy, fairness and discrimination, transparency and explainability, security and adversarial exposure, autonomy and human oversight, and third-party dependency. Fewer than six collapses distinct exposures together. Many more stops being something a board can hold in mind.

On the example figures

The worked thresholds in both files are illustrative and clearly marked as such. They are plausible defaults chosen to show the structure, and they are not benchmarks. Do not adopt them without deciding they are right for your organisation.

What it does not do

It does not tell you where to set your appetite. That judgement depends on your business model, your regulatory perimeter and your risk capacity, and no template can supply it.

Further reading

See the companion article, Setting an AI Risk Appetite, and the risk appetite glossary entry for the underlying distinctions this template is built on, including appetite versus tolerance versus capacity.

Available formats

Downloads route through a short-lived signed link.

DOCX · v1.0 · 18 KB

AI risk appetite statement template (Word)

Member access

Sign in to download
XLSX · v1.0 · 28 KB

AI risk tolerance matrix (Excel)

Member access

Sign in to download

Framework and clause references

FrameworkClauseTitle
ISO/IEC 42001:2023Annex A.2Policies related to AI
SS1/23: Model Risk Management Principles for BanksPrinciple 2Model risk governance
ISO/IEC 42001:2023Clause 6Planning & risk