The Board’s Technology Risk Appetite: A Practical Articulation

A practical articulation framework for the technology risk appetite that boards are expected to have — written for the chairs, NEDs, and CTOs working through DORA, SS1/21, and similar governance regimes.

Boards are expected to articulate a technology risk appetite. DORA expects it. PRA SS1/21 expects it. CySEC, the FCA, the ECB, and similar supervisors expect it. The expectation is not new; it has been consistent across operational resilience regimes for the past five years. What is new is that supervisors increasingly examine whether the articulated appetite is something the firm can actually operate against, rather than a paragraph of board minutes.

This is a practical framework for articulating a technology risk appetite that is specific, testable, and connected to operational decisions — not a generic statement that satisfies no one and constrains nothing.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

What technology risk appetite means concretely

Technology risk appetite is the board’s expression of how much technology-related risk the firm is willing to accept in pursuit of its objectives. Concretely, this has to translate into:

  • Acceptable recovery times for important business services in the event of disruption (the operational resilience tolerances).
  • Acceptable third-party concentration at the provider, sector, and geographic level.
  • Acceptable cyber risk position relative to defined threat scenarios and the firm’s exposure.
  • Acceptable technical debt levels and the investment trajectory to manage them.
  • Acceptable rates of change — how much the firm is willing to change its technology estate in a given period, given the operational risk that change introduces.
  • Acceptable investment levels in technology resilience — what proportion of the technology budget goes to resilience versus growth.

Each of these should have a specific articulation that management can operate against and that internal audit and supervisors can examine.

Who this is for

  • The board chair or senior independent director whose committee charter includes technology risk oversight.
  • The CTO whose function has to operate against the articulated appetite.
  • The CRO whose risk framework integrates technology risk alongside financial, operational, and conduct risks.

The board’s role and management’s role

The board owns the articulation of risk appetite — what risks the firm is willing to accept, at what level, for what return. Management owns the operation within that appetite — how the firm runs its technology to remain within the board’s stated tolerances.

The boundary matters because supervisors examine both:

  • Did the board articulate the appetite at sufficient specificity?
  • Did management operate within it — and if breached, escalate appropriately?

A board appetite that says “the firm should have appropriate technology resilience” is too generic for management to operate against and too generic for supervisors to test. A board appetite that says “important business services should recover within 4 hours of disruption” is operational; management can be measured against it.

A practical articulation framework

For each of the six concrete areas above, the board’s articulation should include:

The metric. What is being measured. Specific enough that management can compute it monthly.

The acceptable range. What level the board is comfortable with, what level triggers attention, and what level breaches the appetite.

The reporting cadence. How often the board sees the position. Quarterly is typical for most metrics; some require monthly visibility.

The escalation path. What happens when the position moves out of acceptable range. Who is notified, on what timeline, with what authority to act.

This framework can fit onto a single page. It does not need to be long. It does need to be specific.

Common pitfalls

The appetite is too generic. “Appropriate”, “robust”, “industry-standard”. None of these are operational. Management cannot tell whether they are inside or outside the appetite. The board cannot tell whether it has been breached.

The appetite is not testable. The metrics are defined but the firm has no way to compute them. The annual review reports “within appetite” without evidence.

The appetite is disconnected from operational decisions. The board approves the appetite; management makes operational decisions that do not reference it. The two run in parallel rather than connected.

The appetite does not change. The same paragraph appears in the annual report year after year. The firm’s actual risk position has changed; the appetite has not been updated.

The appetite ignores investment. The board articulates tolerance for technology risk without articulating the investment level that achieves it. The two are linked.

How this feeds operational resilience

The technology risk appetite is the parent of the operational resilience tolerances. Tolerances for important business service recovery, for incident severity, for third-party failure, for cyber event impact — all of these flow from the board’s articulated appetite. A firm whose tolerances cannot be traced back to a board-level appetite has tolerances that were set by management without governance backing. Supervisors examining the resilience framework will look for the connection.

How we engage with this

I work with boards and CTOs on technology risk appetite as part of Fractional CTO engagements and as a stand-alone Decision Rights for Technology review. The work is to articulate the appetite specifically, connect it to the operational metrics the firm can actually compute, and produce the board reporting that demonstrates the firm operates within it.

I do not sit on the board. I do not approve risk appetite. I help articulate it and operationalise it.

Pricing is published at /pricing/. If your board is working through technology risk appetite articulation — either ahead of a supervisory engagement or as part of broader governance refresh — the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming