Back to templates
    Template

    Risk criteria and appetite statement

    Appetite per risk category, anchored consequence and likelihood scales, and a published lookup that says which level is accepted, treated or escalated.

    Risk5 Sept 20263 min read

    ISO 31000:2018ISO/IEC 27001:2022
    On this page
    Download the template

    risk-criteria-and-appetite.xlsx · 13 kBLicensed CC BY 4.0

    What this is

    The instrument a risk register is scored against. One sheet holds the appetite, written as a decision per risk category rather than an adjective. Two anchor consequence and likelihood in sentences anyone can test. A fourth publishes the level-of-risk lookup, marks the acceptance line and names who decides. It supports one question: may this level of risk be taken, and by whom.

    How to use it

    1. Fill the Appetite sheet first. Each row needs all three fields: tolerated, escalated and to whom, and never accepted. See the playbook, section 3.2.
    2. Anchor the consequence scale. Six dimensions ship with the file; drop safety where no safety duty exists. Each function confirms its own column. See 3.3.
    3. Anchor the likelihood scale. Every level takes a time-bound frequency band and a named evidence source, so a score is claimed by citing something. See 3.4.
    4. Read the Matrix sheet, do not compute it. The level comes off the published lookup, never from multiplying two ordinal scores. See 3.5.
    5. Apply the decision table. Each level carries a default decision of 1. Accept, 2. Treat or 3. Escalate, the role that may take it, and the record required.
    6. Calibrate before approval. Score ten known risks independently, then rewrite every anchor that produced a spread of more than one level. See 3.6.
    7. Take the set for approval as a decision, and record the approving role, the version and the dates on the Appetite sheet. See 3.7.
    8. Copy the approved scales into the register. They become its Scales sheet, and the register stamps the version used. See 3.8.

    Delete the example rows first. Each is invented and prefixed EXAMPLE - delete.

    What good looks like

    Three of the nine Appetite columns, from two of the workbook's example rows.

    Risk categoryAppetite statement (a decision, not an adjective)Never accepted
    Suppliers and third partiesPersonal data reaches a supplier only where an assessed and recorded transfer basis exists.Special-category data at a supplier with no completed assessment.
    Service availabilityPlanned degradation is accepted where it stays inside the published recovery objective.Removing a tested recovery route with no equivalent replacement.

    Fields

    FieldRequiredMeaningCommon mistake
    Appetite statementyesThe standing decision for that category, in one testable sentenceAn adjective and a category name, deciding nothing
    Tolerance thresholdyesWhere a single exposure stops being routineA threshold with no unit and no period
    Never acceptedyesThe absolute the organisation will not crossLeaving it blank, which makes the row a preference
    Approved by, Approved onyesThe role that approved the row, and whenAn approval recorded as a slide, not a minute
    Scale anchorsyesA sentence per consequence level per dimension; a frequency band, with its evidence, per likelihood levelA one-word band two people read differently
    Default decisionyesOne of 1. Accept, 2. Treat, 3. EscalateA fourth value, invented to avoid escalating

    Download

    • File: risk-criteria-and-appetite.xlsx (xlsx, 13 KB) — five sheets: Read first, Appetite, Consequence scale, Likelihood scale, Matrix.
    • Markdown variant: the same tables in plain markdown, at content/templates/assets/_risk-criteria-and-appetite.md.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data, no organisation names, no macros.

    References

    1. ISO. Risk management — Guidelines. ISO 31000:2018. Read in a licensed copy of the identical national adoption 1
    2. ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022 2
    3. ISO/IEC. Guidance on managing information security risks. ISO/IEC 27005:2022, publisher's preview 3
    4. National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, 2024 4

    Delegation limits and acceptance periods are organisational choices, not requirements of any standard cited here.

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO 31000:2018 clauses 5.2, 6.3.4, 6.4.4, 6.5.2 and 6.7, licensed copy · verified 2026-09-05
    2. 2ISO/IEC 27001:2022 clauses 6.1.2 and 6.1.3, iso.org/obp · verified 2026-09-03
    3. 3ISO/IEC 27005:2022 clauses 3.1.7 and 3.1.8, publisher preview · verified 2026-09-05
    4. 4NIST CSWP 29 Appendix A GV.RM, nvlpubs.nist.gov · verified 2026-09-05