The board and senior leadership should set direction, but operational owners need to maintain the statement and keep it aligned to changing business conditions. Review responsibilities should be explicit so appetite does not become stale when objectives, regulations, or risk exposure shift. Clear ownership is part of making governance enforceable.
How should ownership be split between the board and management?
risk appetite is a governance instrument, so the board should own the approved direction and the tolerance the organisation is willing to accept. Management should own the operating statement, proposed changes, and the cadence that keeps it usable. In practice, ownership works best when strategy is set at the top and day-to-day maintenance sits with the people closest to changing risk exposure.
That split matters because appetite is only useful when it can be translated into decisions about growth, controls, exceptions, and escalation. If the board tries to manage the wording itself, the statement tends to lag operations. If management owns it without clear board oversight, appetite can drift away from the organisation’s actual risk posture.
What should operational owners actually maintain?
Operational owners should keep the statement aligned to business model changes, control maturity, regulatory shifts, and emerging exposures. That includes proposing revisions, validating thresholds against current performance, and making sure the language still maps to how the organisation makes trade-offs in practice. Ownership should be explicit enough that updates do not depend on informal follow-up or annual memory.
Good ownership also means separating content maintenance from approval authority. Management can prepare the analysis and draft revisions, but the board or delegated committee should approve material changes. That separation preserves accountability while still letting the organisation react quickly when appetite needs to move.
For teams working on complex digital or AI-enabled environments, the same principle applies to board-level risk briefing and appetite questions: the people running the programme need to maintain the working statement, but the governing body must own the tolerance boundary.
How often should appetite be reviewed, and what should trigger change?
Review cadence should be regular, but the trigger should be event-driven as well as calendar-driven. A review should happen when objectives change, when regulations shift, when risk exposure moves materially, or when the organisation’s control environment changes enough that the old wording no longer matches reality. The right question is not whether the annual review happened, but whether the statement still reflects current business intent.
That means the review process should include a clear change threshold. Minor wording adjustments may stay with management, while material shifts in tolerance, scope, or decision authority should go back to the board. Without that distinction, appetite can become stale at exactly the point where the business most needs it to guide decisions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Risk appetite updates define how the organisation sets and reviews its risk tolerance. |
| GV.RM-02 — Risk Management Roles and Responsibilities | Ownership and review duties must be explicit for appetite to remain enforceable. | |
| Recommendation — Set and review risk appetite through a documented risk management strategy. Assign clear accountability for maintaining and approving risk appetite changes. | ||
| ISO/IEC 27001:2022 | A.5.4 — Management responsibilities | Governance ownership for security-related decisions must be assigned and maintained. |
| A.5.1 — Policies for information security | Risk appetite functions like a top-level policy statement that needs ongoing review. | |
| Recommendation — Assign management responsibility for maintaining and reviewing governance statements. Review policy statements regularly so they stay aligned with current risk. | ||
Practitioner Guidance
What to prioritise: Define a single accountable owner for upkeep, then define a separate approving authority for material changes. That prevents a common failure mode where everyone references risk appetite, but no one is clearly responsible for refreshing it.
What to verify: Confirm that every appetite statement has a review cadence, a trigger list, and an escalation path for material changes. If those elements are absent, the statement is more of a policy artifact than an operational governance tool.
Decision rule: If the change affects the organisation’s willingness to accept risk, board reapproval is needed; if it only updates wording, metrics, or supporting detail, management can maintain it under delegated authority.
Practitioner takeaway: The most effective model is board-owned direction with management-owned maintenance, because appetite stays credible only when the people closest to changing conditions are responsible for keeping it current.