Working Start something skill
Build an enterprise risk appetite process
Build an enterprise risk appetite process that connects strategy, obligations, capacity, tolerances, indicators, escalation, decisions, and review.
When to use
- Use for enterprise, portfolio, board, public-service, or regulated risk governance.
- Do not reduce human safety, rights, or legal constraints to a tradeable financial threshold.
Procedure
- Define strategy, duties, stakeholders, risk taxonomy, decision horizons, governance bodies, and accountable executives.
- Separate non-negotiable constraints, appetite, tolerance, capacity, target exposure, and operational limits.
- Use scenarios, loss history, stress tests, dependencies, concentrations, stakeholder impact, and control confidence to calibrate bounds.
- Translate statements into measurable leading and lagging indicators with sources, owners, freshness, and uncertainty.
- Define breach severity, notification, containment, decision authority, remediation, temporary acceptance, and board escalation.
- Integrate appetite into planning, investment, product, supplier, credit, change, incident, and performance decisions.
- Back-test whether thresholds predicted harm, review incentives and aggregation, and revise with recorded rationale.
Failure plan
- Escalate ambiguous or unmeasurable exposure and prohibit silent averaging that hides a severe local breach.
Worked example
A logistics company separates zero appetite for falsified safety inspections from a bounded appetite for delivery-delay variability.
--- name: build-an-enterprise-risk-appetite-process category: start description: Build an enterprise risk appetite process that connects strategy, obligations, capacity, tolerances, indicators, escalation, decisions, and review. Use when risk statements must guide real resource and operating choices. --- # build-an-enterprise-risk-appetite-process ## When to use - Use for enterprise, portfolio, board, public-service, or regulated risk governance. - Do not reduce human safety, rights, or legal constraints to a tradeable financial threshold. ## Procedure 1. Define strategy, duties, stakeholders, risk taxonomy, decision horizons, governance bodies, and accountable executives. 2. Separate non-negotiable constraints, appetite, tolerance, capacity, target exposure, and operational limits. 3. Use scenarios, loss history, stress tests, dependencies, concentrations, stakeholder impact, and control confidence to calibrate bounds. 4. Translate statements into measurable leading and lagging indicators with sources, owners, freshness, and uncertainty. 5. Define breach severity, notification, containment, decision authority, remediation, temporary acceptance, and board escalation. 6. Integrate appetite into planning, investment, product, supplier, credit, change, incident, and performance decisions. 7. Back-test whether thresholds predicted harm, review incentives and aggregation, and revise with recorded rationale. ## Failure plan - Escalate ambiguous or unmeasurable exposure and prohibit silent averaging that hides a severe local breach. ## Worked example A logistics company separates zero appetite for falsified safety inspections from a bounded appetite for delivery-delay variability. ## Done - A risk appetite process records strategy, constraints, capacity, tolerances, indicators, decisions, escalation, and review - Scenario, calibration, data, breach, decision, back-test, incentive, and governance evidence verifies the process