Element
|
Description
|
Purpose
|
To establish and confirm the organisation’s risk appetite and tolerance thresholds in the context of operational resilience, ensuring alignment with enterprise strategy, stakeholder expectations, and regulatory requirements.
|
Objectives |
- Define acceptable levels of disruption to critical business services.
- Align operational resilience risk appetite with the enterprise risk management (ERM) framework.
- Ensure compliance with regulatory expectations.
- Provide clear boundaries for decision-making, resource allocation, and resilience investments.
|
Inputs
|
- Enterprise Risk Management (ERM) policies and framework.
- Existing risk appetite statements (strategic, financial, operational).
- Regulatory requirements (e.g., MAS, FCA, PRA, Basel guidelines).
- Business Impact Analysis (BIA) and risk assessments.
- Board and senior management directives.
|
Activities
|
- Review Organisational Risk Appetite Framework – Assess current ERM and appetite statements for alignment gaps.
- Define OR-Specific Risk Appetite – Establish risk tolerance thresholds for disruption scenarios (e.g., maximum tolerable outage, financial/reputational impacts).
- Engage Stakeholders – Conduct consultations with board, senior management, and business unit heads.
- Document and validate – Draft resilience-specific risk appetite statements and obtain governance approval.
- Communicate and Integrate – Disseminate confirmed risk appetite and embed into OR planning, testing, and reporting.
|
Outputs
|
- Approved Operational Resilience Risk Appetite Statement.
- Defined tolerance thresholds for critical business services.
- Alignment of OR risk appetite with ERM framework.
- Documented governance endorsement and stakeholder buy-in.
|
Linkages
|
- Preceding Stages: P1-S1 Establish Governance, P1-S2 Define Critical Business Services, P1-S3 Identify Important Business Services and Dependencies.
- Subsequent Stage: P1-S5 Set Impact Tolerances (builds upon confirmed risk appetite).
- Related OR BoK: Risk Management and Oversight, Scenario Testing.
|