Risk appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives — and, when expressed properly, the input that sets audit cadence.
Risk appetite statements are frequently unusable, and the reason is that they are written as sentiment rather than as thresholds. “We have a low appetite for regulatory risk” cannot be acted on. “We will not accept any control failure that could result in a reportable breach, and we will test the controls that prevent one monthly” can.
Appetite and tolerance are often used loosely as synonyms; the more useful reading is that appetite is the strategic willingness to take risk, and tolerance is the acceptable variation around it at an operational level. The second is what a threshold expresses.
The connection to modern auditing is direct and under-exploited. Once testing is a re-runnable definition, cadence stops being constrained by capacity, and the question “how often should we test this control?” has an actual answer: as often as the risk it addresses exceeds the tolerance you have stated. That turns an appetite statement from a governance artifact into an operating parameter — which is the first time most of them have done any work.
Related