Skip to main content

Overview

Risk Appetite defines the level and types of risk an organization is willing to accept in pursuit of its objectives. Risk Legion enables you to configure risk appetite at multiple levels and automatically flags risks that exceed your defined tolerance.

Understanding Risk Appetite

Key Definitions

TermDefinition
Risk AppetiteThe amount of risk an organization is willing to accept to achieve its strategic objectives
Risk ToleranceThe acceptable level of variation around risk appetite
Risk CapacityThe maximum amount of risk an organization can absorb
Risk ThresholdThe specific level at which risks require escalation

Risk Appetite vs. Risk Tolerance

Risk Capacity (Maximum)

        │  ⚠️ Breach Zone

Risk Appetite Threshold
        │  ✅ Acceptable Zone


Zero Risk (Theoretical)

Risk Levels in Risk Legion

Risk Legion uses a 5×5 risk matrix with four risk levels:
LevelScore RangeDescription
Low1-4Acceptable risk, routine monitoring
Medium5-9Elevated risk, enhanced monitoring
High10-15Significant risk, active management
Very High16-25Critical risk, immediate action required

Risk Score Calculation

Risk Score = Impact (1-5) × Likelihood (1-5)
Impact Scale:
ScoreLevelDescription
1InsignificantMinimal financial loss, no regulatory impact
2MinorSmall financial loss, minor regulatory attention
3ModerateModerate financial loss, regulatory review
4MajorSignificant financial loss, regulatory action
5CatastrophicSevere financial loss, license threat
Likelihood Scale:
ScoreLevelDescription
1RareMay occur only in exceptional circumstances
2UnlikelyNot expected but possible
3PossibleMight occur at some time
4LikelyWill probably occur
5Almost CertainExpected to occur frequently

Configuring Risk Appetite

Enterprise-Level Configuration

Set the default risk appetite for your entire organization:
  1. Navigate to Governance → Risk Appetite
  2. Click Configure Enterprise Appetite
  3. Select the maximum acceptable risk level
  4. Add description/rationale
  5. Click Save
{
  "risk_level": "Medium",
  "threshold_value": 9,
  "description": "Enterprise accepts Medium risk (score ≤9) as maximum tolerance"
}

Entity-Level Configuration

Override the enterprise default for specific Legal Entities:
  1. Navigate to Governance → Risk Appetite
  2. Click Add Entity Override
  3. Select the Legal Entity
  4. Set the risk level for that entity
  5. Click Save
Entity-level settings override the enterprise default. This allows for different risk profiles across your organization.

Hierarchical Resolution

Risk Legion resolves risk appetite using hierarchy:
1. Business Unit Level (if configured)

2. Legal Entity Level (if configured)

3. Enterprise Level (default)
Business Unit level risk appetite is planned for a future release. Currently, the hierarchy resolves from Legal Entity to Enterprise.

Risks Above Appetite

Automatic Detection

Risk Legion automatically identifies risks that exceed appetite:
  1. During BRA assessment, residual risk is calculated
  2. System compares residual risk score to applicable appetite threshold
  3. Risks above threshold are flagged as “Above Appetite”

Dashboard Visibility

The dashboard prominently displays:
  • “Within Appetite” Hero Card - Percentage of risks within tolerance
  • Risks Above Appetite Count - Number of scenarios exceeding appetite
  • Risk Distribution Chart - Visual breakdown by risk level

Automatic Mitigation Actions

When a risk exceeds appetite:
  1. System can automatically create mitigation actions
  2. Actions are linked to the specific risk scenario
  3. Default priority is set based on risk level
  4. Actions appear in the Action Plans module

Risk Appetite History

Risk Legion maintains a complete history of risk appetite changes:

Viewing History

  1. Navigate to Governance → Risk Appetite
  2. Click View History
  3. See all changes with:
    • Previous value
    • New value
    • Changed by
    • Changed at
    • Reason (if provided)

Audit Compliance

All risk appetite changes are:
  • Logged in the audit trail
  • Immutable once recorded
  • Available for compliance reporting
  • Retained per data retention policy

Best Practices

Risk appetite should be:
  • Approved by the Board or Risk Committee
  • Documented in formal risk appetite statement
  • Reviewed annually or after significant changes
  • Communicated across the organization
Risk appetite should reflect:
  • Strategic objectives
  • Regulatory requirements
  • Stakeholder expectations
  • Industry benchmarks
Consider different appetites for:
  • Compliance risks (typically low appetite)
  • Operational risks (varies by business)
  • Strategic risks (may accept higher levels)
  • Reputational risks (typically very low)
Review and update risk appetite:
  • After significant incidents
  • When strategy changes
  • Following regulatory changes
  • At least annually

Regulatory Considerations

Basel Framework

Under Basel III/IV, banks must:
  • Define risk appetite aligned with business strategy
  • Integrate risk appetite into risk management framework
  • Report on risks exceeding appetite
  • Demonstrate Board oversight of risk appetite

BACEN Requirements (Brazil)

Brazilian financial institutions must:
  • Maintain documented risk appetite statement
  • Review appetite annually
  • Report appetite breaches to management
  • Include in ICAAP/ILAAP documentation

API Reference

EndpointMethodDescription
/api/v1/governance/risk-appetiteGETGet current risk appetite configuration
/api/v1/governance/risk-appetitePOSTCreate/update risk appetite (upsert)
/api/v1/governance/risk-appetite/{id}DELETERemove entity-level override
/api/v1/governance/risk-appetite/historyGETGet risk appetite change history

Example: Set Enterprise Risk Appetite

curl -X POST /api/v1/governance/risk-appetite \
  -H "Authorization: Bearer $TOKEN" \
  -d '{
    "risk_level": "Medium",
    "threshold_value": 9,
    "description": "Enterprise risk appetite set to Medium per Board resolution 2026-01"
  }'

Example: Set Entity Override

curl -X POST /api/v1/governance/risk-appetite \
  -H "Authorization: Bearer $TOKEN" \
  -d '{
    "risk_level": "Low",
    "threshold_value": 4,
    "legal_entity_id": "le-001",
    "description": "Lower appetite for insurance subsidiary per regulatory requirement"
  }'
See API Reference for complete documentation.