Risk appetite and acceptance criteria: deciding how much risk is acceptable
Risk appetite is a leadership call; acceptance is real once written, owned and dated.

An organisation cannot remove every risk, so it has to decide how much it is willing to live with. Risk appetite is that decision at the top: NISTIR 8286r1 defines it as “the amount and type of risk that an organization is willing to take in meeting its objectives”. Risk tolerance is narrower: NISTIR 8286r1 gives the federal-entity wording as “the acceptable level of variance in performance relative to the achievement of objectives”, citing OMB Circular A-123, while NIST SP 800-37 Revision 2 defines it as “the degree of risk or uncertainty that is acceptable to an organization”. Neither figure is the security team’s to set: appetite is a decision about objectives, not a calculation about findings. What turns “we accepted this risk” into a governance record is the acceptance decision itself — a named decision maker, the evidence behind it, and an expiry.
The model: from objectives to a dated acceptance decision
business objectives
↓
risk appetite statement how much risk leadership is willing to take in meeting objectives
↓
risk tolerance thresholds the acceptable variance around each objective
↓
documented acceptance decision decision maker · evidence · expiry
↓
review still within appetite, still the right response?
Appetite cannot be read off the assets, the threats or the findings: it follows from what the organisation is trying to achieve. Objectives come first, then the willingness to take risk, then a threshold per objective, then a decision that is written down. That last step is what makes the earlier ones real — an appetite that never produces a dated decision is a statement nobody has used.
The mechanism: appetite, tolerance, and the acceptance decision
- Objectives. Start from what the organisation is trying to achieve before naming any risk. CSF 2.0 states it as GV.RM-01: risk management objectives are established and agreed to by organisational stakeholders.
- Appetite. Leadership states the amount and type of risk it is willing to take in meeting those objectives. NISTIR 8286r1 adds who decides: “Risk appetite is established by the enterprise’s most senior-level leadership and serves as the guidepost for decisions, such as setting strategy and selecting objectives.”
- Tolerance. For each objective, a tolerance states the acceptable level of variance. NISTIR 8286r1 offers a worked pair: appetite — “email service shall be available during the large majority of a 24-hour period”; tolerance — “email services shall not be interrupted for more than five minutes during core hours”
- Response options. CSF 2.0 asks at GV.RM-04 for strategic direction describing appropriate risk response options. NIST SP 800-30 Revision 1 lists them: acceptance, avoidance, mitigation, sharing or transfer.
- Acceptance decision. Accepting is one of those options, not the absence of one. It becomes a record when it names who decided, on what evidence, and until when.
- Review. Risks accepted as residual risk stay in the register and continue to be monitored, so the decision is revisited rather than filed.
What an acceptance criterion must name
These six elements are the acceptance criteria themselves. A criterion that omits the decision maker is not an acceptance, it is a description of a problem; one that omits the expiry is permanent by default, which no real tolerance allows. The table names each element and the question it settles.
| Element | The question it answers |
|---|---|
| Decision maker | Who has the authority to accept this risk, and did they exercise it? |
| Scope | Which asset, process or objective is this risk attached to? |
| Evidence | What was assessed, and what was known at the time of the decision? |
| Response | Why acceptance rather than mitigation, avoidance or transfer? |
| Expiry | Until when is the decision valid? |
| Review | Who re-checks it, and against which threshold? |
A common misconception: “we accepted it, so we can forget it”
Two errors hide behind the same sentence.
The first is that risk appetite is a number the security team sets. It is not: appetite expresses what leadership is willing to trade for its objectives. NIST SP 800-39 is explicit that there is no correct level of tolerance — the degree of risk tolerance is generally indicative of organisational culture, may differ for different types of loss, and is highly influenced by the subjective tolerance of senior leaders.
The second error is that accepting a risk means ignoring it. Acceptance is a deliberate response, chosen by the accountable role, and it is a legitimate outcome rather than a failure: NISTIR 8286r1 notes that risks accepted as residual risk continue to be monitored, and NIST SP 800-37 Revision 2 treats the acceptance of risk, in federal systems, as an inherent responsibility for which senior executives are held responsible and accountable. What makes an acceptance defensible is the record, not the optimism.
What to remember
- Risk appetite is the amount and type of risk leadership is willing to take in meeting its objectives; it is a leadership decision, not a security-team calculation.
- Risk tolerance is the acceptable level of variance in performance against an objective — narrower and more concrete than appetite.
- Accepting a risk is a legitimate response (accept, avoid, mitigate, share, transfer), not a missing one.
- An acceptance is documented only when it names the decision maker, the evidence, the expiry and the review.
- Accepted residual risks keep being monitored: acceptance is a decision with a date, not a state.
Level and prerequisites
L1 — fundamentals: the vocabulary and the decision model, with no procedure for scoring, quantifying or recording risk. Prerequisites: nothing beyond a rough sense of what an asset, a risk and an owner are; the sibling sheets on risk factors and on risk owners supply the rest. How a risk register is structured, how exceptions are approved and how they are tracked are operational material (L2–L3).
Where to go next
- Cybersecurity Governance — the area this sheet belongs to.
- The technical work of detecting, mitigating and monitoring controls belongs to Networking, Server & Virtualization and AI & LLM (roadmap §6).
References
- NIST, NISTIR 8286r1 — Integrating Cybersecurity and Enterprise Risk Management (ERM) (December 2025; the October 2020 NISTIR 8286 is withdrawn and superseded by this edition) — the definition of risk appetite, the appetite/tolerance distinction and the worked email pair.
- NIST, SP 800-37 Revision 2 — Risk Management Framework for Information Systems and Organizations — the definition of risk tolerance and acceptance of risk as a senior-executive responsibility.
- NIST, SP 800-39 — Managing Information Security Risk — risk tolerance has no correct level; accountability for accepting risk.
- NIST, SP 800-30 Revision 1 — Guide for Conducting Risk Assessments — the five risk response options.
- NIST, CSF 2.0 (CSWP 29) — GV.RM-01 and GV.RM-04 subcategories.