Your Risk Appetite Statement Never Reached the Person Spending It
If you lead an organization that has done the work on risk appetite, you have a document. Leadership discussed it. Someone built ordinal scales and attached numbers so the system could operate on them. It was approved, and it is real.
Now go find the last significant equipment purchase your organization made and look at how it was evaluated.
Throughput. Price. Lead time. Maybe floor space and installation window.
Guarding standard, probably not. Noise exposure, probably not. Lockout compatibility, ergonomic reach for the operator who has to clear a jam at 2 a.m. — almost certainly not. And the retrofit cost that would have changed which machine was actually the cheapest never entered the comparison at all.
That is not a safety failure first. It is a bad purchase on procurement's own terms, made by a competent buyer who answered every question the process put in front of them.
The appetite existed. It just never became a criterion at the point where someone spent it.
Appetite is a judgment, not a calculation
Risk appetite is the definition of what risk the organization can swallow. It is not derived from a formula and it is not a property of the risk itself. It is read off the environment: what the industry treats as normal, what customers expect and will tolerate, what regulators are actively pressing on, and — the input people are least comfortable naming out loud — how aggressive the board, ownership, or executive team actually is.
That last input is legitimate. Two organizations in the same industry facing identical exposure can hold different appetites and both be right, because appetite reflects what leadership is willing to carry, not what the hazard is.
Once declared, the judgment gets encoded. Ordinal qualitative scales, numerical values assigned to each band, thresholds set. That encoding matters — it is what allows the organization to quantify, to compare unlike risks against a common frame, and to say where acceptance stops and control establishment begins. It is the structure an ISO 31000 risk management framework formalizes: principles and process for how risk is understood and governed, rather than a certificate to hold.
But the number is not the appetite. The number is the encoding of a judgment leadership already made. Organizations that confuse the two end up trying to calculate their way to a position that only leadership can take.
There are two decompositions, and most organizations finish one
Getting appetite from a boardroom to the point of work is two separate movements.
The first is judgment into scale. Leadership declares the position; someone builds the scales and thresholds that make it operable. Most organizations that take risk seriously complete this step, and completing it feels like finishing. An enterprise risk management program that stops here has built the top half properly and left the bottom half unbuilt.
The second is scale into criteria at the point of decision. The threshold has to become a question on the form, a field in the planning software, a rule the person choosing between two options is actually evaluated against.
The second movement is where appetite dies. This is the same failure this cluster described one altitude down, where an enterprise risk never decomposes into a process control. Appetite fails the same way and for the same reason: downward decomposition is unglamorous work that no one owns by default, and the artifact at the top looks finished without it.
An appetite statement that never became criteria was never installed. It was published.
The tell is a field that says N/A
The diagnostic is small and specific. Somewhere in your purchasing process — a manual requisition, a field in the ERP, a step in the planning software — there is likely a line that asks the requester or buyer to identify any health and safety risks associated with the purchase.
Open the last six months of them and read that field.
If it consistently reads N/A, or None, or is left blank, resist the instinct to treat that as carelessness. In most organizations it is not a requirement to evaluate OHS risk during procurement, and where it exists at all, the risk is expected to be identified by some other expert somewhere else in the organization. The buyer looked at a field with no criteria attached, saw nothing in the purchase that presented itself as a safety decision, and answered honestly.
An empty field and a field that reads “exceeds the noise threshold; accepted because the enclosure is already specified in the install scope” look nothing alike. Organizations treat both as a completed step. One is a decision. The other is evidence that no decision was available to make.
Two designs work
There are exactly two ways to install appetite at a decision point, and both are legitimate.
Design one: criteria and competence in the function
The evaluation criteria go into the process the function already runs, and the competence to apply them is delivered to the people running it. The buyer evaluates the OHS dimension themselves, against thresholds, as part of the same evaluation that covers cost and lead time.
This works when OHS is already part of how that function understands its own job — either because the safety function is tightly woven into purchasing day to day, or because OHS training in the organization puts real weight on procurement's role in safety outcomes. Under those conditions the criteria are not foreign. They are an articulation of judgment the buyer already carries. Creating that condition deliberately, rather than hoping for it, is where an ISO 45001 consultant earns the engagement — not in writing the manual, but in deciding which functions should carry safety criteria themselves.
Design two: triage criteria that flag and route
The process carries a preliminary set of triggers whose only job is to recognize that a purchase has an OHS dimension and route it to a stakeholder who performs the assessment. The buyer is not asked to evaluate. They are asked to recognize and hand off.
This works when the decision is infrequent, when the judgment is complex or consequential enough that a specialist should own it, or when the competence would take longer to build than the decision frequency justifies.
How to read the placement
Choosing between the two is not a philosophical question. It is read from the operation:
Competence at the point of work. What do the people in that workflow already understand, and how close is that to what the criteria demand?
How easily that competence develops. Some criteria can be taught in an afternoon and applied reliably. Others require judgment that takes years.
Complexity and criticality of the criteria. Higher on either dimension pushes toward the specialist.
Where escalation creates a bottleneck. One purchasing department with a small team of buyers will stall if every requisition needs review.
The counterintuitive input is frequency, and it does not point where most people expect.
The obvious argument says route rare, high-consequence decisions to the specialist because the specialist has bandwidth for the rare ones. That is true, but it is the weaker reason. The stronger one is that criteria which are relevant to two percent of what a buyer touches never become live competence. Nothing in the buyer's week reinforces them. The step gets pattern-matched past, not out of negligence but because that is what infrequent steps do inside a high-volume workflow. So you route not to protect the OHS person's calendar. You route because criteria exercised twice a year decay into a checkbox.
Registers decay because nothing reopens them. Criteria decay because nothing exercises them.
And the mirror holds: when OHS is genuinely integrated into purchasing — through proximity or through training that treats procurement as a safety function — the criteria stay live, and embedding them in the process is the better design because it removes a handoff without losing rigor. Either way this is business process consulting before it is safety work: the criteria have to live inside a workflow that already exists and already has its own pressures.
The third thing most organizations have is not a design
Between those two sits the arrangement that appears most often in practice: a line in the procedure or a field on the checklist instructing the requester to select or identify the OHS risks that apply.
It confers no criteria. No threshold. No routing. No competence.
It implies authority without conferring the means to exercise it, which means the organization has assigned an evaluation to someone who was never equipped to perform it and then treated the completed field as evidence the evaluation happened. This is the arrangement that produces N/A, and it is worse than having nothing, because nothing does not generate a record that looks like assurance.
Escalation places the same way
Once thresholds exist, someone will need to exceed one. Whether the buyer can approve that departure themselves with a recorded reason, or whether breaching the threshold is itself the routing trigger, is decided by the same logic — where the true decision authority does and should sit. Build the escalation path into the process rather than leaving it to be discovered. That is a placement question in its own right, and it is the subject of its own discussion.
The departure justification is the defensibility mechanism
A threshold that can be exceeded with a recorded reason is what separates an accepted risk from an ignored one.
Acceptance is a legitimate risk treatment. Organizations accept risk deliberately and correctly all the time. What makes acceptance defensible is that somebody saw the threshold, chose to depart from it, and recorded why. The record is not bureaucracy. It is the artifact that proves a decision occurred and lets a future reader — an auditor, an investigator, a successor in the role — understand the reasoning without reconstructing it from memory. It is also the connective tissue of any risk, governance, and compliance structure that has to survive outside scrutiny.
Which makes the absence of departure justifications the strongest tell available. If your records contain no departures at all, the likely explanation is not that your organization never exceeds a threshold. It is that nobody at the point of decision knew a threshold applied.
This is not only a safety problem
Safety makes the argument legible because the consequence is physical and the cost of an untranslated appetite is least deniable, which is why occupational health and safety management systems are the cleanest place to see the break. But the structure is domain-independent. Information security appetite that never becomes a criterion in vendor selection, quality appetite that never becomes a criterion in supplier approval, and privacy appetite that never becomes a criterion in feature scoping all fail in exactly the same place, for exactly the same reason. Organizations running several of these at once discover the problem is not four separate translation failures but one missing mechanism, which is the argument for integrated risk management over four parallel programs.
Where safety differs is timing. In most domains an untranslated appetite surfaces as a finding. In safety it surfaces as an incident, and the review that follows asks who decided — which is the moment the organization discovers that nobody did.
Start here
Do not start with the appetite statement. Start at the other end.
Pull ten requisitions or purchase records from the last six months, weighted toward equipment, consumables with a protective function, and contracted labor. Find the field where safety is supposed to appear. Count how many say N/A.
Then take one threshold from your appetite statement — any one — and trace it forward until you reach the form a person fills in. If the trace stops before it reaches a field, you have found where your appetite is being spent without anyone deciding to spend it. A structured ISO 45001 gap analysis will find every instance of that break faster than you can, but the first one you can find yourself this afternoon.