Governance & Compliance · Data artifact

Risk Tolerance Policy

Data artifactGovernance & ComplianceSafety, Security & Governancearc:RiskTolerancePolicy

A governance-approved statement of the organization's risk appetite and tolerance for AI risks, reflecting regulatory constraints, stakeholder values, strategic priorities and affected-population severity rather than financial capacity.

Responsibility. Defines which levels of AI risk the organization will accept.

Also known as: Risk appetite statement, Risk tolerance

configuresconstrainsRisk Monitor: configuresRisk MonitorRisk Treatment Plan: constrainsRisk Treatment Plan
Direct neighbourhood (hover for relationship types)

Relationships

configures structural

constrains control

Design guidance

Classification

Quality attributes
Transparency and accountability (NIST AI RMF: accountable and transparent)Reliability (ISO/IEC 25010 | NIST AI RMF: valid and reliable)
Risks mitigated
Accepting illegal or value-violating risks because losses are financially bearable
Frameworks & regulations
NIST AI RMF: GOVERNISO 31000

Sources

  1. Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.