home/glossary/Risk tolerance

Risk tolerance

nounverified·updated Aug 28, 2026

The level of risk an entity is willing to assume in order to achieve a potential desired result.

MWENIST Cybersecurity Framework

Senses

ISACA Cybersecurity Glossary

The acceptable level of variation that management is willing to allow for any particular risk as the enterprise pursues its objectives

CPMI-IOSCO Guidance on Cyber Resilience for Financial Market Infrastructures

The amount and type of risk that an organisation is willing to take in order to meet its strategic objectives (may also be referred to as “risk appetite”).

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2sense 2 pending review

The defined impacts to an enterprise’s information systems that an entity is willing to accept.

NIST AI RMF 1.0

Risk tolerance refers to the organization’s or AI actor’s ... readiness to bear the risk in order to achieve its objectives. Risk tolerance can be influenced by legal or regulatory requirements.

Classifications

Entity Type

Metric85%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

60%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Information Class

70%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Variants

synonym
acceptable level of variation
alternatephrasing
Risk Tolerance
plural
Risk tolerances
possessive
Risk tolerance's
pluralpossessive
Risk tolerances'