Skip to main content
Category: Enterprise Risk Management

Risk Criteria

Also known as: Risk Criterion
Simply put

Risk criteria are the reference points an organization uses to judge whether a given risk is significant enough to matter and whether it can be accepted. They help translate an organization's objectives and its appetite for risk into consistent standards, so that different risks can be compared and the ones that need attention are escalated. What counts as acceptable typically varies by organization, sector, and the requirements it is subject to.

Formal definition

Risk criteria are the terms of reference against which the significance of a risk is evaluated, generally derived from organizational objectives, internal and external context, and any mandatory or regulatory requirements. In practice they establish thresholds and standards for what level of risk is acceptable or tolerable, enabling consistent risk evaluation, prioritization, and the escalation of risks that exceed defined trigger points. Risk criteria support comparison across disparate risks and help reduce individual bias in evaluation; the specific thresholds applied depend on the entity's context, applicable frameworks or regulatory expectations, and management judgment, and thus vary by organization and jurisdiction. This entry is educational and does not constitute legal, audit, or compliance advice.

Why it matters

Risk criteria are what make risk evaluation consistent rather than ad hoc. Without agreed reference points, two people looking at the same exposure may reach very different conclusions about whether it matters, and risks that deserve escalation can be quietly absorbed while trivial ones consume attention. By defining thresholds for what level of risk is acceptable or tolerable, risk criteria give an organization a common language for comparing disparate risks and deciding which ones need to be communicated upward.

A further benefit is that well-defined criteria help reduce individual bias in evaluation. When judgments about significance rest on personal intuition alone, they tend to reflect the risk-taking temperament of the individual rather than the organization's stated position. Trigger points that specify when a risk must be escalated help ensure that comparable exposures are treated comparably, and that decisions to accept risk are made against a standard rather than in isolation.

What counts as acceptable is not universal. Criteria are typically derived from an organization's objectives, its internal and external context, and any mandatory or regulatory requirements it is subject to. In some settings the relevant standard reflects a regulator's view of how much risk is acceptable or tolerable; in others it is set primarily by management judgment within the entity's own appetite. Because of this, criteria vary by organization, sector, and jurisdiction, and applying another entity's thresholds without regard to context can produce misleading results.

Who it's relevant to

Chief Risk Officers and risk management functions
Risk functions own the design and maintenance of risk criteria, translating organizational objectives and appetite into thresholds that support consistent evaluation and escalation. They are typically responsible for ensuring criteria remain aligned with the entity's context and applicable requirements, and for using them to compare and prioritize risks across the organization.
Boards and risk committees
Boards and their committees generally exercise oversight of risk criteria, satisfying themselves that the thresholds used to judge acceptability are consistent with the risk appetite they have approved. Their role is typically one of challenge and approval rather than day-to-day application; the criteria give them a defined basis for understanding which risks are escalated to their attention.
Management and operational risk owners
Management and the individuals accountable for specific risks apply the criteria when evaluating exposures in their areas, using the trigger points to determine when a risk must be communicated upward rather than accepted locally. This helps ensure decisions to accept risk are made against a common standard rather than individual judgment alone.
Internal audit and assurance providers
Assurance functions may assess whether risk criteria are appropriately defined and applied, and whether escalation actually occurs when thresholds are exceeded. Their focus is typically on evaluating the design and operation of the criteria as part of the wider risk management process, not on setting the thresholds themselves.
Compliance functions in regulated sectors
Where mandatory or regulatory requirements shape what level of risk is acceptable or tolerable, compliance functions have an interest in how those requirements are reflected in the organization's criteria. In some sectors the relevant reference point represents a regulator's view of acceptable risk, and the applicable expectations vary by jurisdiction and entity type.

Inside Risk Criteria

Definition and Purpose
Risk criteria are the terms of reference against which the significance of a risk is evaluated. Under ISO 31000, they are established at the outset of the risk management process to give consistency and structure to how risks are assessed, compared, and prioritized. They translate an organization's risk appetite and objectives into practical parameters for evaluation.
Likelihood and Impact Parameters
Criteria typically specify how likelihood (probability or frequency) and impact (consequence or severity) will be measured or described, whether through qualitative scales, quantitative thresholds, or a combination. Keeping likelihood and impact conceptually distinct is essential to sound evaluation.
Scales and Thresholds
Risk criteria often include rating scales (for example, descriptive bands or numeric ranges) and thresholds that indicate where a risk moves from acceptable to requiring treatment. These help distinguish tolerable exposures from those exceeding defined limits.
Link to Risk Appetite and Tolerance
Effective criteria reflect the organization's stated risk appetite and any more granular risk tolerances, so that evaluation results align with the level and type of risk the board and management have agreed to accept in pursuit of objectives. Appetite, tolerance, and capacity remain distinct concepts that the criteria operationalize.
Consideration of Inherent and Residual Risk
Criteria may be applied to inherent risk (before controls) and residual risk (after controls operate), and should make clear which is being evaluated so that comparisons are meaningful and control effectiveness is properly accounted for.
Contextual and Stakeholder Factors
Criteria generally take account of the organization's objectives, external and internal context, applicable obligations, and the concerns of relevant stakeholders, so that what counts as significant reflects the entity's actual circumstances rather than a generic template.

Common questions

Answers to the questions practitioners most commonly ask about Risk Criteria.

Are risk criteria the same thing as risk appetite?
No. Risk appetite is a higher-level expression of the amount and type of risk an organization is generally willing to pursue or accept in pursuit of its objectives, typically set by the board. Risk criteria are the specific reference points, such as scales, thresholds, and definitions of likelihood and impact, used to evaluate the significance of individual risks during assessment. Risk criteria generally operationalize risk appetite and risk tolerance so that risks can be consistently analyzed and compared, but the terms are not interchangeable. Under frameworks such as ISO 31000, risk criteria are established to support risk evaluation, whereas risk appetite guides the boundaries within which those evaluations are interpreted.
Once we set risk criteria, are they fixed rather than something we revisit?
Risk criteria are generally not intended to be static. They typically reflect the organization's objectives, context, and stakeholder expectations at a given point in time, all of which can change. Many frameworks treat the review of risk criteria as part of ongoing monitoring, meaning criteria are revisited as circumstances, strategy, the external environment, or risk appetite evolve. Treating criteria as permanent can cause risk evaluations to drift out of alignment with current priorities. How often they are reviewed generally depends on the organization's context and its own judgment rather than a universal rule.
Who is typically responsible for setting and approving risk criteria?
Responsibility generally varies by organization and governance model. In many structures, management proposes risk criteria that reflect the organization's context and objectives, while the board or a relevant committee provides oversight and may approve or endorse criteria to ensure alignment with risk appetite and strategy. Assurance functions such as internal audit typically do not own the criteria but may evaluate whether they are applied consistently. The precise allocation of these roles depends on the entity type, applicable governance codes, and the organization's own framework, so this should be confirmed against internal policy.
How should risk criteria address both likelihood and impact?
Risk criteria commonly define separate scales for likelihood (how probable an event is) and impact (the consequence if it occurs), since these are distinct dimensions and should not be treated as interchangeable. Impact criteria may cover multiple consequence types, such as financial, operational, legal or regulatory, reputational, and safety, so that a risk can be evaluated across the dimensions relevant to the organization. Defining what each rating level means in concrete terms generally supports more consistent and comparable assessments. The appropriate number of levels and the specific definitions depend on the organization's context and judgment.
How do risk criteria connect to the distinction between inherent and residual risk?
Risk criteria provide the reference scales used to evaluate risk, and the same criteria can be applied both before and after controls are considered. Inherent risk generally refers to the level of risk before accounting for controls, while residual risk reflects the level after existing controls are taken into account. Applying consistent criteria to both allows an organization to see the effect of its controls and to compare residual risk against its thresholds. The criteria themselves do not determine which risks are inherent or residual; they are the measuring reference applied at each stage.
How can an organization keep risk criteria applied consistently across different functions?
Consistency generally depends on clearly documenting the criteria, providing definitions and examples for each rating level, and communicating them to those who perform assessments. Some organizations support consistency through training, calibration discussions, and periodic review of how criteria are being applied across business units. Assurance functions may review application for consistency as part of their work. Even with documented criteria, some judgment is typically involved, so mechanisms to compare and reconcile ratings across functions can help. The specific approach depends on the organization's structure and resources.

Common misconceptions

Risk criteria are a fixed, one-size-fits-all standard that applies to any organization.
Risk criteria are typically tailored to a specific organization's objectives, context, appetite, and obligations. Under frameworks such as ISO 31000 they are established and reviewed by the organization itself, and appropriate criteria vary by entity type, sector, and jurisdiction. There is no universal mandatory set of criteria.
Risk criteria and risk appetite are the same thing.
They are related but distinct. Risk appetite expresses the amount and type of risk an organization is willing to pursue or accept, while risk criteria are the operational terms of reference used to measure and evaluate individual risks against that appetite. Criteria are the mechanism that helps translate appetite into consistent assessment.
Setting risk criteria is a technical exercise owned entirely by the risk function.
While a risk function often facilitates and maintains the criteria, they should reflect direction set through governance. The board or a relevant committee typically oversees risk appetite and expects criteria to align with it, and management applies the criteria operationally. Accountability for oversight and for operational use sits in different places.

Best practices

Define risk criteria at the start of the risk assessment process and document how likelihood and impact will be described or measured, keeping the two dimensions distinct.
Align criteria explicitly with the board-approved risk appetite and any supporting risk tolerances, so that evaluation outcomes are consistent with the level of risk the organization has agreed to accept.
State clearly whether criteria are being applied to inherent or residual risk in a given assessment, and ensure control effectiveness is considered when evaluating residual exposure.
Tailor criteria to the organization's objectives, context, sector, and applicable obligations rather than adopting a generic scale, and calibrate scales and thresholds to be meaningful for the decisions they support.
Review and update criteria periodically and when context changes, and involve the appropriate governance body or committee so that oversight of appetite and criteria remains connected.
Communicate the criteria to those performing assessments so they are applied consistently across the organization, and document any assumptions or limitations, recognizing that judgment and facts specific to each risk still apply.