Scoring & the Matrix

How to set a risk appetite on Mac

RiskOS holds one threshold for the whole register, lets a category or a single risk depart from it, and marks every breach wherever the risk appears.

Appetite is the line between exposure an organisation is content to carry and exposure it is not. Agreed only as a form of words, it stays a matter of opinion the moment a particular row comes up. Set as a number in the register it starts doing work: every risk that crosses it is marked, counted and put in front of you, and nobody has to remember which rows were the worrying ones.

Note

Appetite is compared against the residual score — what is left once your controls are taken into account — never against the inherent rating you set by hand.

Where risk appetite lives

Press , to open Settings, or choose Settings in the sidebar under Output, then open Appetite. Two things sit there: the organisation-wide threshold — the highest residual score you are willing to carry — and per-category thresholds, each with room for a rationale.

The threshold then shows up in three more places. The risk table has an Appetite column and an over appetite only filter. Each risk's panel has an Appetite section with an override toggle, and its header flags a risk above the line. Review offers Above appetite as a scope.

Set an organisation-wide appetite

  1. Open Settings and choose Appetite

    Press , from anywhere in RiskOS and select Appetite. The organisation threshold is at the top, the per-category list beneath it. A change applies to the register as soon as you make it.

  2. Decide the highest residual score you will carry

    The threshold is one number on the same 1–25 scale the register scores on, so decide it as a sentence first: we carry Medium risks without escalation, and anything above needs a plan and a date. That sentence is an appetite of 9, because Medium runs 5–9 and High starts at 10.

  3. Set the organisation threshold

    Set the number in Settings ▸ Appetite. It applies at once to every risk with no more specific threshold of its own, which on a new register is all of them. Nothing is re-scored: the threshold changes what counts as a breach, not what anything is rated.

  4. Look at what it flagged

    Choose Risks in the sidebar and turn on the over appetite only filter. The filter icon fills while a filter is on, so you can see at a glance that this is a subset. Read the list. If it is empty, or if it is the whole register, the number you chose is wrong.

  5. Bring the Appetite column into view

    Right-click the table header, show the Appetite column and reorder it to sit beside Residual, so the score and the threshold judging it are read together. RiskOS remembers the arrangement, so the table opens this way next time.

  6. Save the over-appetite view

    With the filter still on, choose Save Current Filter… and name it something you will recognise in a hurry; Over appetite does the job. It comes back with one click, which matters when this is the view you open before a management meeting.

  7. Override the threshold where a risk genuinely differs

    Open a risk and go to its Appetite section. It names the threshold the risk inherited and where that came from, so you can see what you are departing from. Turn on the override and set the risk's own threshold on the stepper. An override belongs to that one risk, so keep it for genuine exceptions.

  8. Work the breaches down in one pass

    Choose Review and pick Above appetite as the scope. Risks arrive one at a time, worst first, with owner, controls and actions beside the scoring inputs. Press to confirm a rating, to save and move on, to skip.

How the threshold is chosen for each risk

Every risk is judged against exactly one threshold, and RiskOS resolves which one in a fixed order, taking the most specific setting that exists. Learn the order before you add exceptions: it explains why a change in Settings can appear to do nothing to a particular row.

The order in which a risk's appetite threshold is resolved
OrderSourceWhen it appliesWhere you set it
1Risk overrideThe risk has its own threshold switched onThe risk's Appetite section
2Category thresholdThe risk's category has a threshold of its ownSettings ▸ Appetite
3Organisation thresholdEverything elseSettings ▸ Appetite
4NoneNo threshold is set at any levelNothing is flagged

The fourth row is the one to watch on a new register. Until a threshold exists somewhere, no flag appears and the Above appetite scope counts zero — an appetite nobody has set yet.

Choosing a number you can defend

The threshold is a statement about the organisation rather than the register, so it belongs to whoever answers for the consequences. What makes it defensible is that it lines up with a band boundary and with a sentence somebody said out loud.

Common appetite thresholds and what each one flags
ThresholdCarried without escalationFlagged as a breachA reading
4Low only (1–4)Medium, High and CriticalTight. Suits regulated work and small registers.
9Low and Medium (1–9)High and CriticalThe common choice. A breach means "plan and date".
16Up to High (1–16)Critical only (17–25)Loose. For large registers where Critical means board-level.

Start from the band, not the number

Scores on a 5×5 methodology are not evenly spread — there is no way to score 11, 13 or 14 — so thresholds of 10 and 12 flag different sets of risks for reasons nobody will reconstruct later. Put the line at the top of a band: 4, 9 or 16. The boundary is then explainable in one sentence when someone asks why a risk was escalated.

Sanity-check against the register you already have

Set the threshold, turn on the over appetite only filter and count. A register of twelve active risks averaging 9.6 out of 25 might show four over an appetite of 9: short enough to act on, long enough to be honest. A third of the register flagged is a queue nobody will clear.

Write the reasoning down

Per-category thresholds take a rationale, and it is the most valuable box on the page. A year later the number is obvious and the reason is gone, so record what drove it: a regulator's expectation, a contract, a board decision. A rationale turns a threshold into a position.

What a breach actually does

Going over appetite changes nothing about a risk's rating. It is a judgement about that rating, and RiskOS treats it as a property of the risk rather than of one view.

In the register

The Appetite column shows the threshold the risk is judged against, and the row is marked when the residual score exceeds it. The over appetite only filter narrows the table to those rows, and combines with the band filter and the search field.

In the risk panel

The header carries the over-appetite flag beside the band badge and the trend, so a breach is visible the moment you open the risk. The Appetite section below names the threshold that applies and where it came from.

In review and in the headline figures

RiskOS offers Above appetite as a review scope with a live count beside it, so the breach list doubles as an agenda: the scope tells you how many risks are over the line before you start the pass. Read that figure alongside the register's average residual score and it becomes a measure you can track, making movement visible month to month rather than only at year end.

Appetite and target are different instruments

These two are confused more than any other pair in a register, because both are numbers about the future. They answer different questions, and different people set them.

Risk appetite compared with a target risk score
AppetiteTarget
What it statesThe highest residual score you will carryWhere you intend to get this risk to
ScopeOrganisation, category, or one risk by overrideAlways one risk
Set inSettings ▸ Appetite, or the risk's own sectionThe risk's Assessment section
What it drivesThe breach flag, filter and review scopeThe gap, and the control strength to close it

A healthy risk has a target at or below the appetite. RSK-0007, Backup restoration has never been tested end to end, sits at a residual of 15 with a target of 4 against an appetite of 9: six points over the line today, with a stated intention to finish well inside it. The comparison grid in its Assessment section names the control strength that would get there.

Appetite across client profiles

If you keep separate profiles for separate clients or business units, each carries its own appetite alongside its own methodology and report defaults. Switching profile switches the threshold, so the same discipline runs at a different line for each organisation.

A profile's appetite is a snapshot. Change the threshold in Settings ▸ Appetite and the profile keeps the figure it captured until you choose Update from Current Settings. That stops a client's agreed threshold drifting because you adjusted your own.

Troubleshooting

Nothing is flagged, even though I have High risks

Either no threshold is set at any level, or the one that is set sits above every residual score in the register. Check the organisation figure in Settings ▸ Appetite. The comparison is against residual, not inherent: a well-controlled register can hold inherent Criticals and breach nothing.

Almost every risk is over appetite

Usually the threshold was set against how the risks feel rather than how they score, and has landed below the register's working level. Raise it to the number you would defend in front of an executive, then look again. If the list is still long, the threshold is right and the register is telling you something: take it into Review instead of moving the line.

A risk is flagged but we have formally accepted it

Accepting a risk records the decision in Treatment; it does not change the residual score, so the exposure is still above the threshold and the flag stays. That is the honest outcome, and an accepted breach is the sort of thing a report should carry. Where tolerance genuinely differs, use the override in its Appetite section and note the reasoning in the plan.

I raised the threshold and one risk is still flagged

That risk is judged against something more specific. Open it and read its Appetite section: it either has its own override switched on or belongs to a category with a threshold. The most specific setting wins, so the organisation figure never reaches a risk with an exception.

A client profile still shows the old appetite

Profiles hold appetite as a snapshot rather than a live link. Switch to the profile and choose Update from Current Settings to bring it in line. Until you do it keeps the threshold it was given, which stops a client's agreed line from moving without anyone deciding it should.

A routine that keeps appetite honest

A threshold set once and never revisited becomes decoration. A few habits keep it load-bearing.

  • Review the number annually, not monthly. Moving it after a bad quarter turns appetite into a description of the register rather than a constraint on it.
  • Open the saved over-appetite view before a management meeting. One click, one list, and the agenda writes itself.
  • Count the breaches, not only the rows. Four over appetite in March and six in June is a trend worth a sentence in the executive summary.
  • Give every breach an owner and a date. A flagged risk with no action against it is a threshold being noted rather than acted on.
  • Keep overrides rare and reasoned. When several risks in the same category need one, that is a category threshold waiting to be set instead.
  • Sort by residual and read down to the line. The rows a point under the threshold are next quarter's breaches, and far cheaper to treat now.

Frequently asked questions

What is a risk appetite?

It is the amount of risk an organisation is willing to carry in pursuit of its objectives. In RiskOS it is a number: the highest residual score you will tolerate, on the same 1–25 scale the register scores on. Any risk whose residual score exceeds it is flagged as over appetite wherever it appears.

How do I decide what my risk appetite should be?

Say it as a sentence first — which band you will carry without escalation — then put the number at the top of that band. Carrying Medium risk gives an appetite of 9. Set it, filter the register to breaches, and count. A handful of flagged risks is a working list; a third of the register is not.

Is risk appetite measured against inherent or residual risk?

Residual. The threshold is compared with what is left once the effectiveness of your linked controls has been taken into account, not the inherent rating you set by hand. That is why strengthening a control can clear a breach without anyone touching the likelihood or impact of the risk.

What is the difference between risk appetite and risk tolerance?

Appetite is the line set in advance; tolerance is usually described as the variation around it you will live with in practice. RiskOS keeps one threshold per level rather than a band, across three levels — organisation, category and risk — so a genuine exception is recorded as an override rather than argued each time.

Can different parts of the business have different risk appetites?

Yes. Any category can carry its own threshold with a rationale beside it, which is how compliance risk ends up held to a tighter line than project delivery. A category threshold overrides the organisation figure for every risk in it, and a single risk can still depart from both.

What happens when a risk goes over appetite?

Nothing about the rating changes. The risk is marked in the register table, carries a flag in its panel header, joins the count of breaches in the headline figures, and appears under the Above appetite review scope. It is a judgement about the score rather than a change to it, so it follows the risk everywhere.

Where is my risk appetite setting kept?

In Settings, on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine. The threshold travels only when you export a report or back the register up yourself, and both of those land wherever you choose to put them.