CIMA P3: Why Confusing Risk Appetite With a Risk Register Costs Marks
A risk register logs and mitigates; risk appetite decides when a risk needs to go to the board instead. P3 scenarios are built to test that you can tell the two apart.
Two terms turn up constantly in CIMA P3 scenarios: risk appetite and risk register. Candidates usually know what both words mean in isolation. Where marks disappear is in the middle of a scenario question, when an examiner describes a risk and expects the candidate to work out which of these two tools actually applies to it — and a surprising number of scripts reach for the wrong one, or use both interchangeably as if they were the same thing.
They are not the same thing, and P3 is built to test whether you know the difference. Getting this right is often the difference between an answer that sounds sensible and one that actually answers the requirement, which is why it belongs alongside the other core ideas on Learnsignal's CIMA P3 Risk Management course.
Risk appetite: a board-level statement of intent
Risk appetite is the amount and type of risk an organisation is willing to accept in pursuit of its objectives. It is set at board level, shaped by factors such as the industry the organisation operates in, its financial capacity to absorb losses, the experience and attitude of its directors, and its reputation with stakeholders. Risk appetite is strategic in nature — it is a statement about what kind of organisation this is prepared to be, not a list of specific threats. A conservative organisation might state that it will accept no risk to regulatory compliance under any circumstances, while tolerating moderate commercial risk in pursuit of growth. That statement then becomes the yardstick against which every subsequent risk decision is measured.
The risk register: an operational recording tool
A risk register is a very different kind of document. It is the practical, operational tool used to identify individual risks, assess their likelihood and impact, assign an owner, and record the mitigating actions being taken against each one. Where risk appetite answers "what are we willing to accept, in general," the risk register answers "what specific risks have we found, how serious are they, and what are we doing about each one." It is typically reviewed regularly, updated as new risks emerge or existing ones change in severity, and used as a day-to-day management tool by people well below board level.
Both are necessary. Neither replaces the other. The register is where risk management happens operationally; risk appetite is the strategic boundary that tells the organisation when an operationally-managed risk has actually become a strategic problem.
Where P3 scenarios test the distinction
The examinable skill is knowing when a risk described in a scenario should simply be logged, assessed and mitigated through the register, and when it should instead be recognised as exceeding the organisation's stated risk appetite — which is a different, more serious situation requiring escalation to the board and, potentially, a change in strategy rather than a mitigating action at operational level.
A common scenario structure gives you an organisation with a clearly stated risk appetite — say, low appetite for reputational risk — and then describes an operational decision, such as outsourcing a customer-facing process to a supplier with a patchy service record. A candidate who treats this purely as a register exercise will discuss likelihood, impact, and mitigating controls, and stop there. That misses the point of the question. The correct observation is that this specific risk, given its reputational nature and the organisation's stated low appetite for exactly that type of risk, sits outside what the board has said it is willing to accept — so the appropriate response is to escalate the decision and query the strategy itself, not simply to add a mitigation line to the register and proceed.
This is the same underlying skill tested elsewhere in the CIMA strategic papers: matching a strategic-level framework to the specific fact pattern in front of you rather than defaulting to a generic operational response. The E3 Ansoff matrix strategic fit post covers a closely related version of the same examiner trap in a growth-strategy context.
A practical test to apply in the exam
When a scenario presents a risk, ask two questions in order. First, has the organisation stated an appetite that is directly relevant to this type of risk? Second, does the likelihood and impact of the risk as described push it outside that stated appetite? If the answer to both is yes, the discussion needs to go beyond the register and address escalation, board-level reconsideration, or a change of strategic direction. If the risk sits comfortably within the stated appetite, the register-level response — identify, assess, assign an owner, mitigate — is the correct and complete answer, and reaching for escalation language would be over-engineering a straightforward operational point.
This distinction also matters when scenarios ask you to critique an organisation's risk management approach. A common weakness examiners build into scenarios is an organisation that maintains a detailed, well-populated risk register but has never actually articulated its risk appetite, or has one that is vague and unusable at board level. Recognising that gap — a strong operational tool sitting on top of no strategic boundary — is itself a valid and often expected observation.
Frequently asked questions
Is risk appetite the same as risk tolerance?
They are related but distinct in most risk management frameworks referenced by P3: risk appetite is the broad, board-level statement of the amount and type of risk the organisation will pursue, while risk tolerance typically refers to the acceptable variation around that appetite for a specific risk or objective — a narrower, more operational band within the wider appetite statement.
Who is responsible for setting and reviewing risk appetite?
Risk appetite is set and owned by the board, since it is a strategic statement about the organisation's objectives and its willingness to take risk in pursuit of them. The risk register, by contrast, is typically maintained operationally, with individual risk owners and periodic review by risk management or internal audit functions, though the board retains oversight of the overall risk management process.
Can a risk register include risks that exceed risk appetite?
Yes, and this is exactly the situation a good risk management process should surface rather than hide. A risk can appear on the register with its likelihood and impact properly assessed, but the register entry alone does not resolve it if the risk exceeds stated appetite — that assessment should trigger escalation to the board rather than being treated as fully addressed once a mitigating action is logged.
Risk appetite and the risk register do different jobs, and P3 scenarios are built around candidates who can tell which job a given risk actually needs. Practise spotting the moment a risk stops being an operational item for the register and becomes a strategic question for the board, and this becomes one of the more reliable sources of marks in the paper. Learnsignal's CIMA P3 Risk Management course works through this distinction, and the wider risk management process, in the detail the exam demands.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team

