This guide explains what a Risk Appetite Statement (RAS) is, outlines its value, and provides practical guidance on how to develop one. While the focus is on security risk, the broader aim is to support the integration of SRM into broad organisation-wide risk management (Enterprise Risk Management – ERM), ensuring that all risks are considered holistically rather than in isolation. By leveraging the strengths of existing security risk practices, organisations can strengthen overall risk management frameworks to create a more coherent, aligned, and effective approach.
This guidance can support security risk management (SRM) practitioners who want to ensure that security considerations are integrated into wider organisational risk management processes, rather than managed in isolation. It also supports senior leadership and governing bodies by explaining the strategic value of a risk appetite statement, how it strengthens governance and accountability, and practical steps for developing and implementing one effectively.
Download the guide using the yellow button on the left.
