Risk Management
Risk Tolerance Breach Log
Instances where residual exposure has crossed the board-approved tolerance threshold this year.
Why crossing tolerance demands a documented response
Risk appetite and tolerance set by the governing body are meaningless unless breaches are detected, logged and acted upon, a discipline King IV places squarely with the board. When residual exposure crosses an approved tolerance threshold, the institution is knowingly operating outside its sanctioned risk posture and must either accept, reduce or escalate it. AuditPro Core maintains a year-to-date breach log so every tolerance excursion is visible, dated and accountable.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Breaches YTD
23
▲ 5 vs prior
Open breaches
9
unresolved
Avg days in breach
47
Escalated to board
6
Tolerance breaches by quarter
Open tolerance breaches
| Risk | Tolerance | Residual | Days open |
|---|---|---|---|
| Cash coverage ratio | 12 | 19 | 88 |
| Irregular expenditure | 10 | 16 | 54 |
| Cyber intrusion | 14 | 18 | 31 |
| Vacancy rate | 11 | 15 | 23 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Appetite versus tolerance
Appetite is the risk the institution is willing to seek; tolerance is the outer limit it will accept on any given risk. A breach crosses that outer limit.
Residual exposure
Tolerance is tested against residual risk, the exposure remaining after controls. A breach signals that current controls are not holding the risk within sanctioned limits.
The breach decision
Every breach forces a choice: accept formally, invest in further mitigation, or escalate to the governing body. Doing nothing is itself an undocumented acceptance.
Pattern in breaches
Recurring breaches on the same risk suggest the tolerance is wrong or the control strategy is failing. The log turns isolated events into a reviewable pattern.
How AuditPro Core Bridges the Gap
- Threshold monitoring: residual scores are checked against board-approved tolerances and breaches are logged automatically.
- Breach workflow: each entry routes to an accept, mitigate or escalate decision with a named decision-maker.
- Continuous monitoring: the log accumulates year-to-date so patterns and repeat breaches become visible.
- Traceability to source: every breach links to the risk, its controls and the approving authority for the tolerance.
Key Takeaways
- A breach means residual risk has crossed the board's sanctioned limit.
- Every breach requires an explicit accept, mitigate or escalate decision.
- Silence on a breach is an undocumented and indefensible acceptance.
- Repeat breaches signal a wrong tolerance or a failing control strategy.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
