Risk Appetite and Tolerance in Setting Engagement Objectives
In CIA Part 2, engagement planning requires internal auditors to set engagement objectives that reflect the risks relevant to the activity under review. Risk appetite and risk tolerance shape how those objectives are framed and prioritized. Risk appetite is the broad amount and type of risk an orga… In CIA Part 2, engagement planning requires internal auditors to set engagement objectives that reflect the risks relevant to the activity under review. Risk appetite and risk tolerance shape how those objectives are framed and prioritized. Risk appetite is the broad amount and type of risk an organization is willing to accept in pursuit of its strategy and value creation. The board sets it, often with senior management, and frameworks such as COSO ERM describe it. Risk tolerance is narrower and more measurable. It is the acceptable range of variation around a specific objective or performance measure, such as a maximum error rate, a downtime limit, or a budget variance threshold. When setting engagement objectives, auditors first conduct a preliminary risk assessment of the activity, as required by IIA Standard 2210.A1 and Global Internal Audit Standards 13.2 and 13.3. Appetite and tolerance act as benchmarks in this assessment. Auditors ask whether residual risk, after management's controls and responses, falls within the stated appetite and tolerances. Areas where risk exposure approaches or exceeds tolerance levels deserve higher priority and more focused objectives. For example, suppose leadership tolerates no more than 2% late regulatory filings. An objective might then be to evaluate whether controls reliably keep late filings below that threshold. Tolerances also help define adequate evaluation criteria, which auditors need to judge whether controls and performance are acceptable. Where management has not formally defined appetite or tolerance, auditors may need to work with management to agree on suitable criteria. If auditors conclude that management has accepted a level of risk that may be unacceptable to the organization, the chief audit executive must discuss the matter with senior management. If it remains unresolved, the CAE escalates it to the board, as required by Standard 2600 and Global Standard 11.5. In short, aligning engagement objectives with risk appetite and tolerance keeps audits risk-based, relevant to strategy, and focused on exposures that matter most to stakeholders.
Risk Appetite and Tolerance in Setting Engagement Objectives (CIA Part 2: Engagement Planning)
Overview
Risk appetite and risk tolerance are core concepts in CIA Part 2 (Practice of Internal Auditing), especially in the Engagement Planning domain. When internal auditors set engagement objectives, they must consider the risks relevant to the activity under review. They must also consider how much risk management and the board are willing to accept. This guide explains what risk appetite and tolerance are, why they matter, how they shape engagement objectives, and how to answer exam questions on the topic.
1. What It Is: Key Definitions
Risk Appetite: The level of risk an organization is willing to accept in pursuit of its strategy and objectives. It is broad, strategic, and set by senior management with board oversight. For example, an organization may have a low appetite for regulatory non-compliance but a moderate appetite for investing in new markets.
Risk Tolerance: The acceptable variation in outcomes relative to a specific objective. It is narrower, measurable, and operational. Tolerance turns appetite into practical limits, such as "inventory shrinkage must not exceed 1.5% of stock value" or "system downtime must not exceed 4 hours per month."
Risk Capacity: The maximum amount of risk an organization can absorb before its viability is threatened. Appetite should always sit below capacity.
Residual Risk: The risk that remains after management's responses and controls are applied. Auditors compare residual risk with appetite and tolerance to judge whether controls are adequate.
Engagement Objectives: Broad statements of what the engagement is intended to accomplish. The Global Internal Audit Standards (2024) require them to reflect the results of the engagement-level risk assessment. Former IIA Standard 2210.A1 required auditors to assess risks relevant to the activity under review and to reflect them in engagement objectives.
Simple hierarchy to remember:
Risk Capacity (most the organization can bear)
> Risk Appetite (what it chooses to accept overall)
> Risk Tolerance (acceptable variation per objective or metric)
> Actual or Residual Risk (what currently exists)
2. Why It Is Important
Alignment with organizational priorities: Engagement objectives that ignore risk appetite may focus audit effort on areas management has knowingly accepted. Meanwhile, areas where risk exceeds tolerance may be neglected.
Basis for evaluating adequacy of controls: Under the Standards, auditors evaluate whether controls are adequately designed and operating effectively. "Adequate" means risks are managed to a level consistent with the organization's risk appetite. Without knowing the appetite, auditors cannot judge adequacy.
Value-adding assurance: Internal audit adds value by providing assurance that risks are within acceptable levels. Auditing against appetite makes findings relevant to the board and senior management.
Efficient resource allocation: Limited audit resources should target areas where residual risk may exceed tolerance or where appetite is low, such as safety, compliance, and fraud.
Communicating unacceptable risk: If management has accepted a level of risk that may be unacceptable to the organization, the chief audit executive (CAE) must discuss it with senior management. If unresolved, the CAE must communicate it to the board. This responsibility requires an understanding of appetite. It appears as Standard 14.5 in the 2024 Global Internal Audit Standards and as former Standard 2600.
Governance link: Under the Three Lines Model, the board sets the tone for risk appetite, management owns and manages risk within it, and internal audit provides independent assurance on whether risk is managed within appetite.
3. How It Works in Engagement Planning
Step 1: Understand the activity under review. Identify its objectives, strategies, and the means by which performance is monitored.
Step 2: Obtain the organization's risk appetite and tolerance. Sources include:
- the risk appetite statement
- the ERM framework and risk register
- board and risk committee minutes
- KPIs and KRIs (key risk indicators)
- policies and limits, such as credit limits, investment limits, and materiality thresholds
- interviews with management
Step 3: Perform an engagement-level risk assessment. Identify significant risks to the activity's objectives. Assess their likelihood and impact. Evaluate management's responses: accept, avoid, reduce, or share/transfer.
Step 4: Compare residual risk with appetite and tolerance.
- If residual risk is within tolerance, objectives may focus on confirming controls continue to operate effectively. Less extensive testing may suffice.
- If residual risk may exceed tolerance, objectives should focus on evaluating the design and effectiveness of controls over that risk. Testing should go deeper.
- If controls exceed what appetite requires (over-control), objectives may include identifying efficiency opportunities. This can be valuable consulting input.
Step 5: Set engagement objectives. Objectives should address significant risks and the adequacy of risk management relative to appetite. Auditors must also consider the probability of significant errors, fraud, non-compliance, and other exposures.
Step 6: Establish evaluation criteria. Criteria are needed to assess governance, risk management, and controls. Risk tolerances often provide ready-made criteria, such as approved thresholds and limits. If management's criteria are inadequate, auditors should identify suitable criteria through discussion with management and the board.
Step 7: Determine scope and the work program. Areas where risk approaches or exceeds tolerance receive greater scope and testing intensity.
Example: A bank's board sets a low appetite for credit losses, with a tolerance of non-performing loans not exceeding 3% of the portfolio. During planning, the auditor learns that NPLs are at 2.8% and rising, and that loan approvals bypassed credit reviews in one region. An appropriate engagement objective would be: "Evaluate whether credit approval controls are adequately designed and operating effectively to maintain non-performing loans within the board-approved tolerance of 3%."
Where no formal appetite exists: Less mature organizations may lack a formal risk appetite statement. The auditor should:
- infer appetite from policies, management discussions, and board direction
- document assumptions
- possibly recommend that management formalize risk appetite (a consulting or advisory opportunity)
The auditor should not set the organization's appetite. Doing so would impair objectivity and assume a management responsibility.
4. Key Roles and Responsibilities
- Board: Approves and oversees risk appetite.
- Senior management: Sets and implements appetite and tolerances and owns risk responses.
- Internal audit: Understands and uses appetite to plan engagements. It evaluates whether risk management keeps risks within appetite and escalates unacceptable risk acceptance. Internal audit does not determine appetite, accept risks on behalf of management, or manage risks.
5. Common Exam Traps
- Confusing appetite (broad, strategic) with tolerance (specific, measurable variation).
- Choosing answers where internal audit sets risk appetite or decides which risks to accept. This is always a management or board role.
- Believing that low-risk areas within appetite need no audit attention at all. They may still need periodic coverage, but with lower intensity.
- Assuming the CAE goes directly to the board when management accepts excessive risk. The correct sequence is discussion with senior management first, then the board if unresolved.
- Forgetting that engagement objectives must reflect the risk assessment, not just management requests.
Exam Tips: Answering Questions on Risk Appetite and Tolerance in Setting Engagement Objectives
Tip 1: Identify the role being tested. If an answer option has internal audit setting, approving, or accepting risk levels, eliminate it. Internal audit evaluates and provides assurance. Management and the board decide.
Tip 2: Look for the comparison of residual risk with appetite. The best answer usually involves assessing whether residual risk falls within the organization's appetite or tolerance. That comparison is the basis for focusing engagement objectives.
Tip 3: Match key words to concepts.
- "Overall amount," "strategic," "willing to accept in pursuit of value" points to appetite.
- "Acceptable variation," "specific objective," "threshold," "measurable" points to tolerance.
- "Maximum that can be absorbed" points to capacity.
Tip 4: Prioritize risks closest to or exceeding tolerance. When asked which area deserves the most audit focus, choose the one where residual risk exceeds or approaches tolerance, especially where appetite is low. Areas with the highest inherent risk but strong controls are not automatically the answer.
Tip 5: Remember the escalation sequence. Management accepts unacceptable risk, then the CAE discusses with senior management, then, if unresolved, the CAE communicates to the board. The CAE does not resolve the risk personally.
Tip 6: Use tolerances as criteria. Questions about evaluation criteria often have a correct answer referencing management-established thresholds or limits. If these are absent or inadequate, the auditor works with management and the board to develop suitable criteria.
Tip 7: Recognize over-control scenarios. If controls reduce risk far below appetite at high cost, the best answer may involve recommending efficiency improvements. Risk management aims to keep risk within appetite, not to eliminate it.
Tip 8: Handle the 'no formal appetite' scenario. The best response is to gain an understanding through discussions with management and the board and to document it. Recommending formalization is also acceptable. Internal audit defining appetite itself is wrong.
Tip 9: Think 'first' or 'best' carefully. For questions asking what the auditor should do first in planning, the answer is often to understand the activity's objectives and the organization's risk appetite before performing detailed risk assessment or setting objectives.
Tip 10: Apply the Standards language. Answers echoing phrases like "engagement objectives must reflect the results of the risk assessment" and "adequate controls manage risk within the organization's risk appetite" are typically correct.
Quick Practice Question
During planning, an internal auditor learns that management has a stated tolerance of 2% for invoice processing errors. Current error rates are 4%, but management states it has accepted this level. What should the auditor do?
A. Revise the tolerance to 4% to reflect current practice.
B. Set engagement objectives to evaluate controls over invoice processing against the approved 2% tolerance, and escalate per the Standards if management's acceptance appears inconsistent with the organization's appetite.
C. Exclude invoice processing from scope since management accepted the risk.
D. Implement new controls to reduce errors.
Answer: B.
- A is wrong because auditors do not set tolerances.
- C is wrong because the risk exceeds the approved tolerance, so it needs attention.
- D is wrong because implementing controls is a management responsibility and would impair objectivity.
Summary
Risk appetite defines how much risk the organization will accept overall. Risk tolerance sets measurable limits around specific objectives. In engagement planning, internal auditors use both to focus engagement objectives on risks that may exceed acceptable levels, to establish evaluation criteria, and to judge control adequacy. For the exam, keep roles distinct: management and the board own appetite, and internal audit evaluates against it and escalates when necessary.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!