Governance & Compliance · Data artifact
Risk Tolerance Policy
Data artifactGovernance & ComplianceSafety, Security & Governancearc:RiskTolerancePolicy
A governance-approved statement of the organization's risk appetite and tolerance for AI risks, reflecting regulatory constraints, stakeholder values, strategic priorities and affected-population severity rather than financial capacity.
Responsibility. Defines which levels of AI risk the organization will accept.
Also known as: Risk appetite statement, Risk tolerance
Relationships
configures structural
constrains control
Design guidance
- MUST be defined deliberately through governance processes, not defaulted to financial capacity to absorb losses.
- SHOULD treat risks affecting vulnerable populations or with severe harm potential as potentially unacceptable even if unlikely.
- SHOULD align with enterprise-wide risk appetite.
Classification
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)Reliability (ISO/IEC 25010 | NIST AI RMF: valid and reliable)
- Risks mitigated
- Accepting illegal or value-violating risks because losses are financially bearable
- Frameworks & regulations
- NIST AI RMF: GOVERNISO 31000
Sources
- Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.