risks.sgit.ai / acceptable / appetite

Appetite as a revealed band

Risk appetite is usually a paragraph in a policy document that nobody can act on. Three moves make it operational: it is a band rather than a number, it is a fractal network of bands rather than one organisational figure, and — the move that matters most — it is discovered rather than declared, because any company that has been operating for a while already has one.

“risk appetite is that band, that interval between two numbers, if you think of zero to one hundred in terms of risk, it is a spectrum, and it can be wider or shorter.”

Why a band and not a number

A single threshold implies that everything below it is equally fine, which nobody believes and no organisation behaves as though it believes. A band has two edges, and both do work:

EdgeWhat crossing it meansWhat it costs to be on the wrong side
Above the bandYou are carrying risk the owners will not underwriteExposure the business has already said it does not want, held without a signature
Inside the bandThe target state. Operating where the business has said it is content to operate
Below the bandYou are spending to reduce risk the business was content to carryAttrition and slowness, bought for nothing. The under-discussed failure, and the expensive one

The lower edge is the half that conventional risk practice has no vocabulary for. Being too safe is not free — it is paid for in delivery speed, in controls nobody asked for, and in the erosion of the security function's credibility every time it blocks something the business would happily have carried. The corpus calls the target the Goldilocks zone, and the name is doing honest work: the goal is neither maximal safety nor minimal cost.

Fractal: one band per accepting entity

There is no single organisational appetite, any more than there is a single organisational register. Each division and each team has its own band, consolidated upward — a payments team and a marketing team should not, and do not, have the same tolerance for the same class of exposure.

This mirrors the register structure exactly, and for the same reason: wherever there is a stakeholder who accepts a risk, there must be a band they accept it against. Fractal risk registers →

Discovered, not declared — from two signals

The strongest claim on this page. An organisation that has operated for years has been making acceptance decisions all along, without recording them as such. The band already exists; the work is to read it off, not to write it down.

SIGNAL 1 · WHAT WAS PAID TO REDUCE

Every past remediation is a datapoint: the business looked at an exposure and paid to lower it. The set of things it funded, and the point at which it stopped funding each, traces the upper edge of the band historically.

SIGNAL 2 · EVERY FRESH ACCEPTANCE

Each new acceptance decision — its level, its interval, its direction — is a fresh datapoint. The band is therefore a living dataset that sharpens with use rather than a document that goes stale.

This is also the mechanism by which the whole model pays for itself over time. A register that records who accepted what, at what level, for how long, is already collecting the data that defines the appetite it is supposed to be measured against.

Declared versus revealed: the gap is the finding

Where the policy document and the decision history disagree, the disagreement is the most valuable thing on the page — and the decision history is the one telling the truth.

A statement of appetite that no acceptance decision has ever respected is not a statement of appetite; it is aspiration, and treating it as a control is how a register becomes decorative. Measuring the two against each other converts an unfalsifiable policy sentence into a testable claim. It also gives the meta-risk family a clean instance: our declared appetite and our revealed appetite differ by this much is a rateable risk with an owner and an interval, and rating it is what funds closing the gap. Meta-risks →

Prior art: the “good enough” threshold, a year early

The appetite argument existed in the founder's public writing before it had this vocabulary. Finding the “Good Enough” Threshold: Optimizing Risk, Creativity, and Product Decisions (6 July 2025, 4,924 words) makes the same case — that the useful question is where to stop rather than how to minimise — and carries fifteen mentions of risk acceptance and appetite, the highest density of any article in that corpus.

Provenance. That article was published on docs.diniscruz.ai under CC0, a year before the corpus this site is built from. It is cited here rather than republished; the canonical link and the original publication date are the things that matter, and both stay with the source. All eight prior-art articles, with dates and canonical URLs →

For an agent

C25 — appetite as a revealed band. Risk appetite is (1) a band between two numbers, not a threshold — above it you carry risk the owners will not underwrite, below it you buy attrition and slowness for nothing, and the target is to operate inside it; (2) a fractal network of bands, one per division and team, consolidated upward, mirroring the fractal register structure; and (3) revealed rather than declared — it is computed from two signals: what the business has paid to reduce in the past, and every fresh acceptance decision going forward. It therefore already exists in any organisation that has been operating for a while, and the work is to read it off rather than to write it down. The gap between declared and revealed appetite is the finding, and it is itself a rateable meta-risk. Prior art: “Finding the Good Enough Threshold” (docs.diniscruz.ai, 6 July 2025, CC0) makes the argument a year before the vocabulary existed. Not implemented in code.