Risk Appetite, Tolerance and Capacity Are Not Synonyms
Only one of the three has a real number behind it.
The question arrives in a reasonable form: how much risk should we be taking? What comes back is three terms used as though they were interchangeable, in language that cannot be tested against anything. The distinction is not academic. Two of these are choices, one is arithmetic, and confusing them is how organizations end up with an appetite they could never have afforded.
Published
Key Takeaways
- Appetite is a strategic preference about which risks to take. Tolerance is the acceptable variation around a specific objective. Capacity is the maximum the organization can absorb before it breaches an obligation. Only capacity is computed rather than chosen.
- An appetite set above capacity is not a preference, it is a scheduled failure. That check is arithmetic, takes an afternoon, and is almost never performed.
- On anything quantified, the confidence level is the appetite statement. Approving a budget at P50 accepts a one in two chance of exceeding it. That is testable, attaches to a decision, and can actually be violated, which is more than most published appetite statements can claim.
Research foundation
Definitions are taken from COSO ERM (2017) and ISO 31000:2018 with ISO Guide 73:2009, and the conceptual critique from Aven (2013) in Risk Analysis and Purdy (2010) on the standard's design intent. The confidence level bridge is anchored in the GAO Cost Estimating and Assessment Guide (GAO-20-195G) and FTA Oversight Procedure 40. Where a claim is practice rather than published finding, it is marked as such. The Four A's are the executive lens applied on top.
Start with the observation that makes the rest of this worth reading. In most organizations, the risk appetite statement and the capital budget approval are produced by different people, in different documents, at different times of year, and are never checked against each other. The appetite statement says the organization has a low tolerance for financial risk. The budget is approved at a figure with a fifty percent chance of being exceeded. Both are signed. Neither references the other.
That is not a failure of either document. It is a failure to notice that they are about the same thing.
What does each term actually mean?
Appetite is about what you are willing to pursue
COSO frames risk appetite as the types and amount of risk, on a broad level, an organization is willing to accept in pursuit of value. Two features of that definition matter and both are routinely dropped. It is expressed at a broad level, so it is a statement about classes of risk rather than individual exposures. And it exists in pursuit of value, so it is not a limit imposed on the organization from outside but a description of the risks it takes on purpose because it wants the return.
An organization with genuinely no appetite for risk is not being prudent. It is refusing to build anything.
Tolerance is about how far a specific measure may move
Tolerance attaches to an objective and a measure. If the objective is to open the facility in the third quarter, tolerance is the amount of slip that will be absorbed before the organization does something different. It is narrower than appetite, operational rather than strategic, and it belongs to a performance measure rather than to a category.
The relationship between the two produces a situation that confuses boards. An organization can be well within its stated appetite for construction risk while badly outside tolerance on a particular project, because appetite says construction risk is a risk this organization takes and tolerance says this specific job has drifted past where anyone intended.
Capacity is about what would break
Capacity is the maximum the organization can absorb before it fails an obligation. Not what it would prefer to absorb. What it can.
This is where the concepts diverge in kind rather than degree. Appetite and tolerance are chosen and can be revised at a board meeting. Capacity is a property of the funding plan, the reserve position, the debt covenants and the statutory obligations, and it does not move because anyone wishes it to. For a public agency running a capital program, capacity is the overrun the funding plan can carry before it forces a service reduction, a scope cut, a rate change or new debt. That is a computable number, and organizations that establish reserve floors in financial policy, in the manner encouraged by the Government Finance Officers Association's fund balance guidance, have already done part of the work.
ISO 31000 handles this territory differently and it is worth knowing why. The standard leans on risk criteria, the terms of reference against which significance is evaluated, rather than on appetite as a headline concept. Purdy's account of the design intent is that the standard was written to attach risk management to actual decisions and objectives rather than to establish a parallel vocabulary. Aven went further and argued that risk appetite as commonly used is not precise enough to carry the weight placed on it, conflating willingness to accept risk with the description of the risk being accepted.
The check almost nobody runs
Put appetite and capacity on the same page and compare them.
Suppose the program is budgeted at 400 million dollars, the simulation puts the P80 at 470 million, and the funding plan can absorb 30 million of overrun before it requires a scope reduction or additional debt. Capacity is 430 million. The organization has approved a budget whose modelled eightieth percentile exceeds its capacity by 40 million.
Nothing in that situation is hidden. Every number is in a document somewhere. They are simply in different documents, and the comparison is nobody's assigned job.
An appetite set above capacity is not a risk preference. It is a decision to breach an obligation, deferred until the arithmetic catches up.
When this surfaces, the response is usually to argue with the model. The productive response is to notice that the organization has exactly three options and they are all legitimate: fund to a higher confidence level, reduce the scope until the P80 fits inside capacity, or expand capacity by arranging the additional financing in advance rather than in a crisis. Choosing consciously among those is what risk appetite is for. The failure is not picking the wrong one, it is never being shown the choice.
How the confidence level makes appetite auditable
Here is the move that changes this from a vocabulary discussion into a governance instrument.
On anything that has been quantified, the confidence level at which the budget or the date is set is the risk appetite, expressed numerically, attached to a specific decision, at a specific moment, by a named body.
Approve at the 50th percentile and the organization has stated that it accepts roughly a one in two chance of exceeding the figure. Approve at the 65th and it accepts roughly one in three. Approve at the 80th and it accepts one in five. These are not interpretations of the decision, they are the decision, and they are the only form of appetite statement that can be tested against a subsequent outcome.
Notice also that this is what a funder does when it sets a percentile requirement. The Federal Transit Administration's cost contingency expectation at the 65th percentile is not a technical convention. It is a risk appetite, set by the party with the money, imposed on the sponsor because the sponsor left the question open. Organizations that never set their own confidence level should not be surprised when someone else sets it for them.
And the trade-off becomes visible in a way qualitative statements never allow. Moving from P50 to P80 on a large program can require tens of millions of additional committed contingency, money that is unavailable for other work while it is held. That is a real cost, and it belongs in front of the board as a cost. A low appetite for schedule risk that costs nothing to declare is not an appetite. Once it is denominated in withheld capital, it becomes a genuine choice.
What a usable statement looks like
Four properties, and they are all testable.
- It names a measure, not a mood. Confidence level, dollars of exposure, days of float consumed, not moderate.
- It states a threshold that can be crossed. If no decision could ever violate it, it is not a constraint.
- It names what happens when the threshold is crossed, and who does it. An appetite without a consequence is a preference.
- It has been compared against capacity, and that comparison is written down. This is the step that is almost always missing.
Most organizations already hold every input required to produce this. What they lack is a forum in which the strategic statement and the program-level number are examined together, by people with the authority to change one of them.
Evidence matrix
| Claim | Evidence tier | Source |
|---|---|---|
| Appetite is the type and amount of risk accepted in pursuit of value, stated broadly | Institutional standard | COSO ERM (2017) |
| Tolerance attaches to an objective and a performance measure | Institutional standard | COSO ERM (2017) |
| ISO 31000 works through risk criteria rather than appetite as a headline concept | International standard | ISO 31000:2018; ISO Guide 73:2009 |
| The risk appetite concept as commonly used is insufficiently precise | Peer reviewed | Aven (2013), Risk Analysis 33(3) |
| The standard was designed to attach risk work to decisions and objectives | Peer reviewed | Purdy (2010), Risk Analysis 30(6) |
| A funder can set the sponsor's effective appetite by mandating a percentile | Government requirement | FTA Oversight Procedure 40 |
| A single agreed definition of risk capacity exists across the standards | Not established | Neither COSO nor ISO defines capacity as a distinct term |
| Appetite and capacity are compared in fewer organizations than claim to manage both | Named field experience | Capital program practice, Mission Intelligence Systems |
What to do with this
Take the largest program currently in flight and write three numbers on one page: the approved budget, the confidence level that budget represents, and the overrun the funding plan can absorb before something has to give.
If the second number does not exist, the organization has no appetite statement regardless of what the governance manual says. If the third exceeds the second, the position is defensible and should be recorded as such. If it does not, the board is carrying an exposure it has not been shown, and showing it costs one page.
References
- Committee of Sponsoring Organizations of the Treadway Commission. Enterprise Risk Management: Integrating with Strategy and Performance. COSO, 2017. coso.org/guidance-erm. Risk appetite and risk tolerance as defined for the enterprise framework.
- Aven, Terje. “On the Meaning and Use of the Risk Appetite Concept.” Risk Analysis, vol. 33, no. 3, 2013, pp. 462–468. doi.org/10.1111/j.1539-6924.2012.01887.x.
- Purdy, Grant. “ISO 31000:2009: Setting a New Standard for Risk Management.” Risk Analysis, vol. 30, no. 6, 2010, pp. 881–886. doi.org/10.1111/j.1539-6924.2010.01442.x.
- International Organization for Standardization. Risk Management: Guidelines. ISO 31000:2018. iso.org/standard/65694.html. Risk criteria and the establishment of scope and context.
- International Organization for Standardization. Risk Management: Vocabulary. ISO Guide 73:2009. iso.org/standard/44651.html.
- U.S. Government Accountability Office. Cost Estimating and Assessment Guide: Best Practices for Developing and Managing Program Costs. GAO-20-195G, March 2020. gao.gov/products/gao-20-195g.
- Federal Transit Administration. Oversight Procedure 40: Risk and Contingency Review. FTA. transit.dot.gov. Cost contingency funded at the 65th percentile.
- Government Finance Officers Association. Fund Balance Guidelines for the General Fund. GFOA best practice. gfoa.org. Reserve policy as a component of absorptive capacity.
- Hubbard, Douglas W., and Dylan Evans. “Problems with Scoring Methods and Ordinal Scales in Risk Assessment.” IBM Journal of Research and Development, vol. 54, no. 3, 2010. doi.org/10.1147/JRD.2010.2042914. Why qualitative bands do not support the comparisons made of them.
About the Author
Dan Flynn
Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build
Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.
His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.
