The Risk Appetite Statement (RAS) converts high-level qualitative strategic intent into measurable, quantifiable operational limits and thresholds. A vague statement like “We have a low tolerance for technology outages” is ineffective for governance. A professional RAS translates that intent into precise engineering and financial metrics.
[Total Risk Capacity: Maximum balance sheet survivable loss]
     └── [Risk Appetite: Maximum loss target for planned operations]
              └── [Risk Tolerance: Hard variation limits per business line]

To structure a metrics-driven RAS, the framework establishes three distinct tracking zones:
  • Risk Appetite: The targeted level of risk an organization actively chooses to accept (e.g., “We target system uptime of 99.9% across core banking interfaces”).
  • Risk Tolerance: The maximum acceptable variation around the risk appetite baseline (e.g., “We tolerate occasional drops to 99.5% uptime during major system maintenance windows”).
  • Risk Capacity: The absolute maximum level of loss the organization can absorb before experiencing structural capital insolvency or regulatory license revocation.

Operational Risk Discipline Quantitative Metric Indicator RAS Limit Target Hard Tolerance Ceiling
Cybersecurity Infrastructure Unpatched critical system vulnerabilities older than 14 days. 0 Less than 3
Data Protection Unauthorized customer record exposure via external leakage. 0 records 0 records
Transaction Execution Daily value of processing errors and settlement failures. Less than $10,000 Max $50,000
Third-Party Resilience Total downtime of tier-1 cloud service providers. 0 minutes Max 15 minutes / quarter

Â