Risk appetite, risk tolerance, and risk threshold are key terms organizations use to define how much risk they are willing to accept, though inconsistent definitions across the industry make practical application challenging.
Business Risk Concepts
When a company is doing business they're taking on risk. Just the fact that they're doing business is a risk in itself. You can't get rid of risk completely, and every business is going to have to determine what level of risk they're on.
When it comes to a lot of terms, people don't necessarily see eye to eye. People have different perspectives on what these terms mean. This is especially true when it's talking about risk and different risk terms. You may see terms out there like risk appetite, risk tolerance, risk threshold, risk capacity, risk preference, risk propensity, risk attitude, risk aptitude. All of these terms have overlapping meanings and people view them differently. So what we're going to do is attempt to answer some of what these terms mean, but more specifically I'm going to tell you what we're trying to get to, what we're trying to get at, what we're trying to understand.
There's this funny word called semantics. Semantics just means the meaning of a word or a sentence or a phrase or some sort of text. And so what we have right here is several different words: risk appetite, tolerance, threshold. There's a lot of semantics discussions out there around what the meaning of these terms is. To me this really irritates me, because if we don't have a common definition, what's even the point? We can argue and we can see it different ways and stuff, but if there's no actionable items, how do I apply it to my business? What do I implement in my business? Then it's a little goofy as far as I'm concerned. So what we're going to talk about here is we're going to define some of it, but I'm also going to talk about some of the goofy aspects that I see revolving around these terms out there.
What is it that we're really trying to get at? What is our end goal here? Our end goal is to determine what the risk appetite of the business is, what the business is willing to accept as far as risk levels are concerned. And a good correlation to this is the size of the business, because there's a general correlation between how risky a business can be and the size of the company.
Initially, when you are a startup, you're getting funding from a lot of venture capitalists. They're investing into your business. So your business is small, and a lot of your value, a lot of your assets, is just cash, and you're willing to spend this cash to move quickly, to get into the market, to really start moving forward. And so we've got this riskiness level where businesses are willing to be a lot more risky. But then as you grow and you start gaining more assets — maybe you're buying some buildings, maybe you're getting a consistent revenue — you're not willing to be as risky. And then when you became a big business and you own big buildings and you own a lot of assets and you don't want to compromise those assets, now your risk level goes down significantly.
We can put names to this: expansionary, when you're a business that's growing; neutral, when you are now balanced in between; and then you go to the conservative side, where you don't want to risk the assets and the value that you already have in the company. Other terms I've seen are risk taking versus risk accepting versus risk adverse. Risk adverse means that you don't want the risk, you're adverse to the risk, that is not something that you want to take on. Versus risk accepting is like, well, there is some risk involved here, but it's not something that we necessarily want a lot of. And then risk taking is those businesses that are willing to take on a lot more risk because they need to grow quickly, and they can't do that when they're trying to be careful.
One of those terms that's a little more solid is this term risk appetite. Risk appetite is just the idea of what is the appetite of the company. Are they willing to be more expansionary, risk-taking, or are they more conservative and risk adverse, or perhaps they're in between? So this is just the risk level, or the risk appetite, that the company has.
Now I'm not a big fan of the word appetite in this case right here. Appetite means a strong desire for something. Well, a company doesn't have a strong desire for risk, and so it's really a little bit mislabeled as far as I'm concerned here — again getting into that semantics game. It's mislabeled because you don't have a desire for risk, but you're willing to take on a certain amount of risk for you to be able to do business and expand. But here we are: the term risk appetite really does mean how much risk are you willing to take on as a company.
Then there's this term risk threshold. A threshold is something that is a line that we've drawn and we can't pass that line. So an example might be, maybe our company is worth taking risks up to $10,000, that maybe under $10,000 it's like, well, that's not really going to move the needle for us, it's not that big of a deal. But if you go past $10,000 we need to start looking at ways to mitigate that risk to get it below $10,000, and so then we start looking for solutions on how to mitigate that risk.
Then we have this term called risk tolerance, and perhaps this has the most controversy around it. When you study the word tolerance, there's really two different meanings. A tolerance is what are you willing to accept. So we can say, well, we're willing to accept a risk that is $10,000 or under. Well, this all sounds a lot like risk threshold, so I have a duplicate here. So this is not a great example of what the definition of risk tolerance is.
There is, however, another definition for tolerance, just the term tolerance, and that is a range, something that you operate within. So in this case right here, if we're talking about a risk, maybe we have these lines that we draw, and this is the risk tolerance, this range right here, and so we operate within this range. Now this is a really goofy measurement as far as I'm concerned, because we still have the risk threshold right here, what we are not willing to go past, but this hints towards this fact that there's this other line that we don't want to go below. Why would we not want to go below? We want this needle to be as far down as possible. Ultimately we don't want risk if we can avoid it. So really, why do we have this line right here? And so it doesn't really make sense to me why this would be the standard definition for it.
So there's a lot of, once again, discussions out there — you can do more research on it — but essentially those are the two types of terms that are the going terms for risk tolerance that is out there. I'm not completely opposed to using this term risk tolerance. We're still trying to understand what the tolerance is for the company to take on risk. However, we just have to understand that there's a lot of controversy around what tolerance actually means, and you can find a lot of different definitions out there. I wouldn't get wrapped up about the specific definition, but using it in a general term I feel like is fine.
So let's take a look at the two terms that are a little more standardized, risk appetite versus risk threshold, and we're going to actually just ignore this risk tolerance since it doesn't really make a whole lot of sense.
From a risk appetite standpoint, here we have just a statement, and it's how much risk a company is willing to take on, and it's more of just a concept level. So in this: we are a leading edge agile company. We accept that our fast-paced culture and fail-fast attitude carries an element of risk. We take some steps in assessing and mitigating risks, but we're not in the business of mitigating all risks. So this is telling us that we need to take a iCal effort to mitigate our risk, but don't go wild with it — let's just move forward, let's be very agile and move forward.
Versus a risk threshold: here now we've got actual numbers involved with this. A risk over $10,000 should be analyzed for possible mitigation. So now if it's between 10,000 and what we see here is 100,000, we're going to have to evaluate to see if there's any — not spend a ton of time on it, but is there any way to mitigate against that. If it's over 100,000, then that's unacceptable. So now we have these definitive elements, these thresholds that we have to operate within.
I will say that there's always room for exceptions. Sometimes we make risk exceptions. So maybe we have a risk that's $110,000, and so it goes above our 100,000 mark. What we can do is we can then propose it and bring it up and say, this is the risk that we have with this particular maybe project or something that we're rolling out, this is the risk that we have right here. And you bring it up to the board and say, but what we have potential for earnings is maybe millions of dollars, so it's well worth this risk that we can't really avoid, for the chance at this millions of dollars that we could possibly have access to. And so now the board may say, yes, we are going to accept that risk and move forward based off of this information. So that's risk exceptions.
Ultimately, in the end, we're really looking at getting to the risk appetite, or what the company is willing to take on from a risk perspective, and how risky does the company need to be.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →