{"description":"Runs on the existing risk item. Set or recalibrate the appetite statement and tolerance thresholds for a risk, test the current position against them, and approve the escalation record. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-appetite-statement-appetite-closure","source":"appetite-statement","target":"appetite-closure"}],"isPublic":true,"itemTypeSlug":"risk","metadata":{"capabilities":["risk-appetite-tolerance-calibration"],"controlVerbs":{"UC-RISK-03":"operates"},"controls":["UC-RISK-03"],"department":"risk-management","domains":["grc"],"kind":"risk-appetite-tolerance-calibration","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:risk-appetite-tolerance-calibration"}],"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-appetite-tolerance-calibration","contentDigest":"sha256:ef1f3206472603b0255f897b5c9116be6a0e6aa07910eba61064f586d24e13fb","prerequisites":{"anchorItemType":{"slug":"risk"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:grc-risk-appetite-board-reporting"}],"roles":[{"contribution":"expertise","description":"Risk appetite authority. Set appetite statement and tolerance thresholds.","id":"reviewer-1","nodeIds":["appetite-statement"]},{"contribution":"approval","description":"Risk oversight owner. Approve appetite and escalation record.","id":"reviewer-2","nodeIds":["appetite-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:risk-appetite-tolerance-calibration"}],"releaseId":"sha256:ef1f3206472603b0255f897b5c9116be6a0e6aa07910eba61064f586d24e13fb","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-risk-appetite-tolerance-calibration"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-risk-appetite-tolerance-calibration","source":"coworkcanvas-gallery","standards":[],"teams":["risk-management"]},"name":"Risk Appetite & Tolerance Calibration","nodes":[{"data":{"instructions":"**Objective**\nSet appetite statement and tolerance thresholds. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the Risk item, board and committee charters, strategy and objective statements, prior appetite statements, capital and liquidity constraints, regulatory expectations, and the approved risk criteria.\n2. Use the confirmed mandate, the risk assessment and its scoring rubric, loss history, control effectiveness results, monitoring indicators, industry and peer benchmarks, and stakeholder expectations.\n\n**Procedure**\n1. Confirm which body owns the appetite decision, reconcile the stated period against the planning cycle, identify the objectives and constraints the appetite must respect, and document any mandate ambiguity before setting thresholds.\n2. Draft an appetite statement in decision-useful language, define threshold values with units and measurement basis, nominate the indicators that evidence position, test the thresholds against historical data for realism, and record rejected calibrations.\n\n**Record in AssureSwarm**\n1. Capture the appetite period, governance mandate, approving authority, objectives served, binding constraints, prior statement reference, and unresolved mandate questions.\n2. Document the appetite statement, threshold values with units and measurement basis, nominated indicators and their data sources, calibration rationale, rejected alternatives, and measurement limitations. Also record tolerance thresholds.\n\n**Exit criteria**\nRisk appetite authority provides expertise: The approving authority and period are unambiguous, the objectives and constraints are documented, and mandate gaps are escalated rather than assumed. The appetite statement is measurable through named indicators, thresholds are reproducible from a stated basis, and measurement limitations are carried into the position test.","kind":"task","label":"Set appetite statement and tolerance thresholds","requiredApprovals":1},"id":"appetite-statement"},{"data":{"controls":["UC-RISK-03"],"instructions":"**Objective**\nApprove appetite and escalation record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the calibrated thresholds, current residual rating, indicator readings and their as-of dates, control testing results, open issues and remediations, and the escalation matrix in the governance mandate.\n2. Review all stage records, calibration rationale and rejected alternatives, indicator readings, threshold comparisons, breach responses, escalation confirmations, and open measurement limitations.\n\n**Procedure**\n1. Read each indicator against its threshold, classify the status, evaluate whether a breach requires acceptance, mitigation, or escalation, define trigger points for re-measurement, and route breaches to the authorized body before advancing.\n2. Trace the statement and thresholds to their stated basis, verify escalations reached the authorized body, confirm monitoring cadence and indicator ownership, and return unsupported calibration with precise comments.\n\n**Record in AssureSwarm**\n1. Record the tolerance status, indicator readings with as-of dates, threshold comparisons, breach response, escalation route and recipients, re-measurement triggers, and any indicator that could not be measured. Also record breach or monitoring response.\n2. Capture the authorized reviewer, the calibration summary, accepted appetite statement and thresholds, effective date, review cadence, escalation confirmations, open limitations, owners, and due dates.\n\n**Exit criteria**\nRisk oversight owner provides approval: An approver accepts that the status follows from the measured readings, breaches are routed to the authorized body, and unmeasurable indicators are declared rather than assumed compliant. The authorized reviewer accepts the calibration as a traceable record of appetite decisions, monitoring can proceed against named indicators, and closure implies no assurance that the position will remain within tolerance.","kind":"task","label":"Approve appetite and escalation record","requiredApprovals":1},"id":"appetite-closure"}],"sourceTemplateId":"workflow-library:grc-risk-appetite-tolerance-calibration"}
