Learning Objectives:
-
Define risk appetite and risk tolerance in the context of cyber risk.
-
Understand the importance of articulating cyber risk appetite.
-
Apply risk appetite frameworks to central bank operations.
-
Recognise the role of risk appetite in governance and decision-making.
3.1 Defining Risk Appetite and Risk Tolerance
Risk appetite is the amount of risk an organisation is willing to accept in pursuit of its objectives. Risk tolerance is the acceptable level of variation around the risk appetite. In the context of cyber risk, risk appetite defines the level of cyber risk the institution is willing to accept.
The Brunei Darussalam Central Bank’s Operational Resilience Planning Methodology identifies confirming risk appetite as a critical stage that provides the foundation for aligning operational resilience efforts with the Bank’s broader mandate of safeguarding monetary and financial stability, supervising institutions, and ensuring public confidence in the financial system .
The Central Bank of Nigeria’s Framework requires that the cybersecurity risk appetite is defined in the SFI’s Enterprise-wide Risk Management (ERM) framework . This ensures that cyber risk is managed consistently with other risks across the institution.
The Monetary Authority of Singapore has proposed that the board or a committee delegated by it will be responsible to ensure that AI risks, where material, are explicitly addressed within the financial institution’s risk appetite framework . This reflects the growing importance of articulating risk appetite for emerging risks.
3.2 Articulating Cyber Risk Appetite
Cyber risk appetite should be articulated in clear, measurable terms. The Brunei Darussalam Central Bank’s methodology provides examples of risk appetite statements :
Liquidity Risk Appetite: “BDCB accepts minor short-term deviations (e.g., ≤ 5% shortfall in domestic liquidity as a proportion of liabilities), contingent on corrective measures within 24 hours of identification.”
Regulatory Compliance Appetite:Â “BDCB maintains a zero-tolerance stance for AML/CFT breaches involving significant penalties or reputational risk; any findings must be remediated within 30 days.”
Technology/Digital Payments Risk Appetite:Â “BDCB tolerates a maximum of 1% service availability downtime per quarter, acknowledging the critical nature of the digital payment hub being integrated regionally via RPC.”
3.3 Implementing Risk Appetite in Governance
The Brunei Darussalam Central Bank’s methodology outlines steps for implementing risk appetite in governance :
Step 1: Define Strategic Objectives and Risk Domains:Â Restate core strategic objectives and map associated operational risk domains, including supervisory risk, monetary operations risk, technology/digital payments risk, and compliance/AML risk.
Step 2: Engage Stakeholders Across Levels:Â Convene workshops among senior executives, risk management, IT operations, supervision, and external advisors.
Step 3: Articulate Qualitative and Quantitative Statements:Â Develop statements for each risk domain.
Step 4: Link Metrics to Governance and Decision Criteria:Â Assign responsibility for monitoring each appetite metric and set escalation tiers.
Step 5: Integrate into Stress Testing and Scenario Planning:Â Overlay risk appetites on stress-test scenarios.
Step 6: Document, Approve, and Communicate:Â Formalise risk appetite statements in internal policy documents.
3.4 Risk Tolerance and Escalation
Risk tolerance defines the acceptable level of variation around the risk appetite. The Brunei Darussalam Central Bank’s methodology sets escalation tiers :
-
Escalation to Deputy Governor:Â If digital payments downtime exceeds 0.5% per month.
-
Full Board Review:Â If downtime exceeds 1% per month.
This escalation framework ensures that risk breaches are escalated to the appropriate level of management for decision-making.