sxsphinxstack

Skills / Working / Build an enterprise risk appetite process

Working Start something skill

Build an enterprise risk appetite process

Build an enterprise risk appetite process that connects strategy, obligations, capacity, tolerances, indicators, escalation, decisions, and review.

When to use

  • Use for enterprise, portfolio, board, public-service, or regulated risk governance.
  • Do not reduce human safety, rights, or legal constraints to a tradeable financial threshold.

Procedure

  1. Define strategy, duties, stakeholders, risk taxonomy, decision horizons, governance bodies, and accountable executives.
  2. Separate non-negotiable constraints, appetite, tolerance, capacity, target exposure, and operational limits.
  3. Use scenarios, loss history, stress tests, dependencies, concentrations, stakeholder impact, and control confidence to calibrate bounds.
  4. Translate statements into measurable leading and lagging indicators with sources, owners, freshness, and uncertainty.
  5. Define breach severity, notification, containment, decision authority, remediation, temporary acceptance, and board escalation.
  6. Integrate appetite into planning, investment, product, supplier, credit, change, incident, and performance decisions.
  7. Back-test whether thresholds predicted harm, review incentives and aggregation, and revise with recorded rationale.

Failure plan

  • Escalate ambiguous or unmeasurable exposure and prohibit silent averaging that hides a severe local breach.

Worked example

A logistics company separates zero appetite for falsified safety inspections from a bounded appetite for delivery-delay variability.