---
title: "Risk tolerance"
description: "The readiness to bear a given risk in order to achieve objectives."
canonical: https://aigovernanceengineer.com/glossary/risk-tolerance
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-24
---

# Risk tolerance

The readiness to bear a given risk in order to achieve objectives [1]. Engineered as the highest residual band a system tier may carry before a deploy gate requires a signed acceptance.

- Developed in: [ch. 13, Risk appetite and tolerance, compiled into gates](https://aigovernanceengineer.com/bok/risk-management#risk-appetite-and-tolerance-compiled-into-gates)
- Chapters: [ch. 13, Risk Management](https://aigovernanceengineer.com/bok/risk-management)
- Contrast with: [Risk appetite](https://aigovernanceengineer.com/glossary/risk-appetite)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-risk-tolerance

## Commonly confused

- **Risk appetite** vs **Risk tolerance**: How much risk the organisation will take on overall, against the residual band one system may carry Appetite is a board statement compiled to data; tolerance is the threshold a deploy gate reads

## Sources

[1] Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (risk tolerance and residual risk; seven trustworthy characteristics; transparency answers "what happened", explainability "how", interpretability "why"; MAP 1.1 intended purposes; MANAGE 1.1 go/no-go determination; profiles). NIST. 2023-01-26. https://doi.org/10.6028/NIST.AI.100-1 (verified: primary)
