workflow

Risk Appetite Definition & Board Reporting

Define enterprise risk appetite statements, tolerances, and KRIs, secure executive and board approval, monitor actuals against tolerances, and report the appetite position to the board. Runs as a standalone recurring instance per appetite cycle (typically annual): appetite spans the whole Risk register rather than a single item, so the register, tolerance and KRI matrix, monitoring workbook, and reporting pack attach to the workflow instance's steps as the versioned documents of record, with the existing Risk items as the linked reference data and KRI breaches recorded as Issue items (issue_type: exception, linked to their Risk). In scope: appetite-statement definition, tolerance and KRI design, executive validation, board approval, ongoing monitoring, and ERM board reporting. Out of scope: the enterprise-wide risk identification and scoring that produces the risk universe, and the assembly of the full quarterly board deck. Consumes the risk-assessment handoff package from the Enterprise Risk Assessment & Portfolio Oversight Cycle (the risk universe as Risk items plus inherent and residual ratings) rather than re-deriving it, and hands the board-approved appetite package to the Quarterly Board & Audit-Committee GRC Reporting workflow.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
grc
department
executive
lineOfDefense
monitor

Details

teams
  • executive
  • risk-management
domains
  • grc
standards
  • coso-erm
sourceTemplateId
workflow-library:grc-risk-appetite-board-reporting
releaseId
sha256:723ab74c727b8838bd39308f2744973e46edacb63b7c2394677b5adc452c10ed
canonicalUrl
https://workflow-library.com/all/?w=grc-risk-appetite-board-reporting
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-GOV-17
    • UC-RISK-03
    • UC-GOV-05
    • UC-RISK-13
    • UC-GOV-21
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:723ab74c727b8838bd39308f2744973e46edacb63b7c2394677b5adc452c10ed

            Connections