Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Risk Management

Risk Tolerance

Simply put

Risk tolerance is the amount of risk or uncertainty an organization (or, in a financial context, an individual investor) is willing and able to accept when pursuing its objectives. It reflects the practical limit of what an entity can cope with, rather than the risks it actively seeks. The concept is applied differently across contexts, from information security governance to investment decision-making.

Formal definition

In organizational risk management, risk tolerance denotes the degree of risk or uncertainty that is acceptable to an organization, functioning as a boundary condition against which residual risk is evaluated. It is distinct from risk appetite, which concerns the amount and type of risk an organization is willing to pursue in seeking its goals; tolerance instead expresses what the organization can actually withstand or cope with. In a financial or investment context, the term is narrower, referring to the degree of uncertainty and potential financial loss an investor is willing and able to accept in exchange for possible higher returns, a determination shaped by multiple individual factors. This entry provides an informational definition only; the specific articulation, thresholds, and application of risk tolerance are organization- or investor-specific and depend on context, governance frameworks, and professional judgment. Readers should note that risk tolerance as used in security and governance standards (for example, NIST publications) is a voluntary or guidance-based concept unless incorporated by law or contract, and definitions may vary by framework and edition; verify against the current authoritative source.

Why it matters

Risk tolerance provides a practical boundary against which organizations and investors measure whether the risks they carry are acceptable. Without a clearly articulated tolerance, decision-makers lack a reference point for judging when residual risk—the risk remaining after controls or mitigations are applied—has crossed from acceptable to unacceptable. In governance and information security contexts, this boundary condition helps translate abstract objectives into concrete decisions about which risks to treat, transfer, accept, or avoid.

The concept also matters because it is frequently confused with risk appetite, and the two are not interchangeable. Risk appetite concerns the amount and type of risk an organization is willing to pursue in seeking its goals, whereas risk tolerance expresses what the organization can actually withstand or cope with. Conflating the two can lead an organization to accept exposures it cannot practically absorb, or conversely to constrain activity more tightly than its objectives require. Keeping the distinction clear supports more defensible and consistent risk decisions.

In a financial or investment setting, the stakes are more personal: an investor's risk tolerance shapes the balance struck between potential financial loss and the possibility of higher returns. Because tolerance is influenced by a variety of individual factors, a determination that suits one investor may be inappropriate for another. Misjudging one's own tolerance can result in decisions that are difficult to sustain when conditions become adverse, which is why the concept is treated as foundational in investor guidance.

Who it's relevant to

Risk and compliance officers
Those responsible for enterprise risk management use risk tolerance as the reference point for evaluating residual risk and deciding whether exposures fall within acceptable limits. They also need to keep tolerance distinct from risk appetite when documenting and communicating risk decisions, since the two serve different purposes.
Information security and governance professionals
Practitioners working with standards such as NIST publications encounter risk tolerance as a guidance-based concept that informs how acceptable risk is defined within a security program. Because such standards are voluntary unless incorporated by law or contract, these professionals should confirm how tolerance is defined in the specific framework and edition they apply.
Investors and financial advisers
For investors, risk tolerance describes the degree of uncertainty and potential financial loss they are willing and able to accept in pursuit of possible higher returns. Advisers and investor-education resources treat assessing this tolerance—shaped by a range of individual factors—as a foundational step, though its application to any particular person requires individual judgment.
Senior leadership and boards
Executives and directors setting the direction of risk-taking benefit from distinguishing what the organization is willing to pursue (appetite) from what it can practically withstand (tolerance). This distinction supports risk decisions that are consistent with both organizational objectives and the entity's actual capacity to cope with adverse outcomes.

Inside Risk Tolerance

Definition of Risk Tolerance
The level of variability in outcomes, or the acceptable deviation from a defined risk appetite, that an organization is willing to accept in pursuit of its objectives. Risk tolerance operationalizes the broader, more strategic concept of risk appetite into more specific, often measurable, thresholds.
Relationship to Risk Appetite
Risk tolerance is generally distinguished from risk appetite: appetite expresses the broad amount and type of risk an organization is willing to pursue at a strategic level, while tolerance defines the acceptable range or limits around that appetite. The two terms are related but should not be treated as interchangeable.
Thresholds and Limits
Tolerance is frequently articulated as quantitative or qualitative boundaries, such as maximum acceptable exposure, loss limits, or performance ranges. Breaching a defined threshold typically triggers escalation, review, or remediation, though the specific mechanisms depend on the organization's governance model.
Governance and Accountability
Risk tolerance is generally set and approved at a senior governance level (for example, a board or executive committee) and then cascaded through management. Ownership of monitoring and reporting against tolerance levels is usually assigned to designated roles or functions.
Context-Dependence
Tolerance levels vary by risk category (for example, financial, operational, information security, or compliance risk), by business unit, and by the organization's size, sector, and objectives. A single organization may maintain different tolerances for different risk types.
Relationship to Compliance and Standards
Risk tolerance is a management and governance concept rather than a legal requirement in itself. Certain regulatory regimes and voluntary frameworks encourage or expect organizations to define and document risk criteria, but the concept of tolerance as such is generally a matter of internal risk management practice rather than a prescribed legal threshold.

Common questions

Answers to the questions practitioners most commonly ask about Risk Tolerance.

Is risk tolerance the same thing as risk appetite?
No, though the terms are related and sometimes used loosely as if interchangeable. In common usage within risk management practice, risk appetite generally refers to the broad amount and type of risk an organization is willing to pursue or accept in pursuit of its objectives, expressed at a strategic level. Risk tolerance is typically narrower, describing the acceptable variation or the specific thresholds an organization is prepared to bear around particular risks or objectives. Precise definitions vary across frameworks and internal governance documents, so readers should confirm how each term is defined in the specific standard, framework, or policy they are applying rather than assuming a universal distinction.
Does a defined risk tolerance make an organization compliant with a regulation?
Not by itself. Setting a risk tolerance is an internal governance and risk-management activity; it does not substitute for meeting binding legal obligations. Where a regulation imposes specific requirements, those requirements generally must be satisfied regardless of an organization's stated tolerance, and an organization cannot lower a legal obligation by declaring a higher tolerance for the associated risk. Risk tolerance may inform how an organization prioritizes and allocates resources within the discretion a rule allows, but compliance and risk tolerance are distinct concepts. Application to a particular obligation is fact-specific and may require professional judgment.
Who within an organization should set risk tolerance?
Responsibility for defining risk tolerance is generally assigned to senior leadership or a governing body, since it reflects strategic decisions about what variation the organization is prepared to accept. Operational and specialist functions may propose thresholds and provide input, but final ownership typically sits at a level with authority over organizational objectives and resources. The specific allocation of this responsibility depends on the organization's governance structure and any applicable framework or policy, which should be consulted to confirm roles.
How is risk tolerance typically documented?
Risk tolerance is commonly recorded in governance artifacts such as a risk management policy, a risk appetite or tolerance statement, or supporting registers that link tolerances to specific objectives, risk categories, or metrics. Documentation practices vary by organization and by the framework being followed. The form and level of detail should be verified against the relevant internal policy and any standard the organization has adopted, as these determine what is expected.
How often should risk tolerance be reviewed?
Review frequency is generally driven by the organization's governance cycle and by changes in circumstances, such as shifts in objectives, the operating environment, the threat landscape, or applicable obligations. Many organizations revisit tolerance on a periodic basis and also on the occurrence of significant change. There is no single universal interval; the appropriate cadence should be established in internal policy and confirmed against any framework the organization applies.
How does risk tolerance relate to selecting and applying controls?
Risk tolerance can inform decisions about how much control effort to apply to a given risk, helping an organization prioritize where residual risk should be reduced and where it may be accepted within stated thresholds. However, this discretion generally operates only within the bounds of applicable legal and contractual requirements, which may mandate specific controls regardless of tolerance. Because the interaction between tolerance and control selection is fact-specific, organizations should assess it against their own risk methodology and the requirements of any standard or regulation that applies.

Common misconceptions

Risk tolerance and risk appetite mean the same thing and can be used interchangeably.
They are related but distinct. Risk appetite expresses the broad, strategic amount and type of risk an organization is willing to pursue, while risk tolerance defines the acceptable range or limits around that appetite. Conflating the two can obscure where strategic direction ends and operational limits begin.
Risk tolerance is dictated by law, so an organization simply adopts a legally mandated level.
Risk tolerance is generally an internal management and governance concept rather than a fixed legal requirement. While some regulations and voluntary frameworks encourage organizations to define and document risk criteria, the specific tolerance levels are typically set by the organization itself and depend on its objectives, sector, and circumstances.
An organization has a single, fixed risk tolerance that applies uniformly across all activities.
Tolerance levels commonly differ by risk category, business unit, and context, and they are periodically reviewed and adjusted. A uniform, permanent figure rarely reflects how tolerance operates in practice.

Best practices

Define risk tolerance in relation to, but separately from, risk appetite, making clear how strategic appetite translates into operational limits and thresholds.
Where practical, express tolerance in measurable terms (limits, ranges, or thresholds) so that breaches can be identified, escalated, and acted upon consistently.
Assign clear ownership for setting, approving, monitoring, and reporting tolerance levels, typically with senior governance approval and defined accountability at the management level.
Differentiate tolerance by risk category and business context rather than applying a single uniform figure across the organization.
Review and update tolerance levels periodically and after significant changes in objectives, operating environment, or regulatory context, and document the rationale for changes.
Verify any framework or regulatory expectations relating to risk criteria against the latest authoritative source, and apply professional judgment when translating general concepts to specific circumstances.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.