Risk Management
Risk Appetite vs Exposure
Plots current exposure against board-set appetite thresholds to flag categories breaching tolerance.
Why appetite versus exposure matters
King IV requires the governing body to set and communicate the institution's risk appetite and tolerance, and the MFMA and PFMA frameworks expect management to operate within those board-approved limits. Plotting current exposure against appetite thresholds turns an abstract policy statement into an operational control that flags the moment a category breaches tolerance. AuditPro Core overlays live exposure on board-set thresholds so breaches trigger attention before they become audit findings or service-delivery failures.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Categories tracked
6
Within appetite
4
Breaching appetite
2
exposure > tolerance
Appetite reviewed
Q1 2026
Exposure vs appetite by category
Appetite breach status
| Category | Exposure | Appetite | Status |
|---|---|---|---|
| Financial | 12 | 14 | Within |
| Operational | 15 | 12 | Breach |
| Compliance | 8 | 10 | Within |
| Strategic | 13 | 13 | At limit |
| Technology | 17 | 12 | Breach |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Risk appetite
Risk appetite is the amount of risk the governing body is willing to accept in pursuit of objectives. It is a deliberate board decision, not an emergent property of how much risk the institution happens to carry.
Tolerance thresholds
Tolerance is the acceptable variation around appetite before action is required. Breaching tolerance should trigger a defined escalation, not merely a note in the register.
Exposure measurement
Exposure is the institution's actual current risk position by category. It is only meaningful when measured on the same scale as the appetite threshold it is compared against.
Breach escalation
A category exceeding its threshold demands a documented management response: accept formally, treat, or revise appetite with board approval. Silent breaches undermine the whole framework.
How AuditPro Core Bridges the Gap
- Threshold overlay: board-approved appetite limits are configured per category and rendered against live exposure for instant breach visibility.
- Breach exception workflow: a category crossing tolerance raises an exception that routes to the risk owner for documented response.
- Board traceability: appetite thresholds carry the approval reference and date, evidencing governing-body authorisation for AGSA review.
- Continuous monitoring: exposure is refreshed as assessments change so breaches surface in-period, not at year-end.
Key Takeaways
- Appetite is a board decision that must be set, approved and recorded.
- Tolerance breaches should trigger a defined escalation, never silence.
- Measure exposure on the same scale as the threshold to keep comparisons valid.
- Retain approval references to evidence governing-body authorisation of limits.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
