Risk Tolerance
Risk tolerance is the amount of risk or uncertainty an organization (or, in a financial context, an individual investor) is willing and able to accept when pursuing its objectives. It reflects the practical limit of what an entity can cope with, rather than the risks it actively seeks. The concept is applied differently across contexts, from information security governance to investment decision-making.
In organizational risk management, risk tolerance denotes the degree of risk or uncertainty that is acceptable to an organization, functioning as a boundary condition against which residual risk is evaluated. It is distinct from risk appetite, which concerns the amount and type of risk an organization is willing to pursue in seeking its goals; tolerance instead expresses what the organization can actually withstand or cope with. In a financial or investment context, the term is narrower, referring to the degree of uncertainty and potential financial loss an investor is willing and able to accept in exchange for possible higher returns, a determination shaped by multiple individual factors. This entry provides an informational definition only; the specific articulation, thresholds, and application of risk tolerance are organization- or investor-specific and depend on context, governance frameworks, and professional judgment. Readers should note that risk tolerance as used in security and governance standards (for example, NIST publications) is a voluntary or guidance-based concept unless incorporated by law or contract, and definitions may vary by framework and edition; verify against the current authoritative source.
Why it matters
Risk tolerance provides a practical boundary against which organizations and investors measure whether the risks they carry are acceptable. Without a clearly articulated tolerance, decision-makers lack a reference point for judging when residual risk—the risk remaining after controls or mitigations are applied—has crossed from acceptable to unacceptable. In governance and information security contexts, this boundary condition helps translate abstract objectives into concrete decisions about which risks to treat, transfer, accept, or avoid.
The concept also matters because it is frequently confused with risk appetite, and the two are not interchangeable. Risk appetite concerns the amount and type of risk an organization is willing to pursue in seeking its goals, whereas risk tolerance expresses what the organization can actually withstand or cope with. Conflating the two can lead an organization to accept exposures it cannot practically absorb, or conversely to constrain activity more tightly than its objectives require. Keeping the distinction clear supports more defensible and consistent risk decisions.
In a financial or investment setting, the stakes are more personal: an investor's risk tolerance shapes the balance struck between potential financial loss and the possibility of higher returns. Because tolerance is influenced by a variety of individual factors, a determination that suits one investor may be inappropriate for another. Misjudging one's own tolerance can result in decisions that are difficult to sustain when conditions become adverse, which is why the concept is treated as foundational in investor guidance.
Who it's relevant to
Inside Risk Tolerance
Common questions
Answers to the questions practitioners most commonly ask about Risk Tolerance.

