ISTQB Mock App

Risk Appetite

Risk appetite is the amount and type of risk that an organization is willing to accept while pursuing its objectives.

Official definition
ISTQB Official Glossary Definition
The amount and type of risk an organization is willing to pursue or retain.

(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)

View the complete ISTQB Glossary

What is Risk Appetite?

It guides decision-making by defining acceptable levels of uncertainty and influencing project planning, testing, and release decisions.

Business driven: Reflects organizational goals and priorities.

Decision support: Helps determine acceptable risk levels.

Varies by organization: Different organizations tolerate different levels of risk.

Real World Example

A tester who previously worked at a startup building consumer apps joins a medical infusion pump manufacturer bound by strict regulatory requirements.

The tester recommends the same "ship now, patch fast" exit criteria that worked fine at the startup, not realizing that an identical list of open, low-severity defects can be completely unacceptable once patient safety and regulation are involved.

Before setting exit criteria for the release decision, the test manager has the team explicitly confirm the organization's Risk appetite — its documented tolerance for open defects, which here is near-zero for anything touching dosage accuracy — and calibrates test depth and the release go/no-go bar to that tolerance rather than to a generic industry norm.

The team requires every dosage-related defect to be closed and adds extra regression cycles before release, a stricter bar than the tester's previous company would ever have needed for a similar-looking defect list — because the same residual risk means something very different depending on the organization's Risk appetite.

Practice Questions

Question 1

A tester who previously worked at a startup with a high tolerance for post-release patching joins a medical device company with strict regulatory requirements, and initially recommends the same "ship now, patch fast" exit criteria. What has the tester failed to account for?

Question 2

Which factor SHOULD MOST directly influence an organization's test exit criteria and release go/no-go decision?

Test your knowledge with real ISTQB-style questions

You’ve learned Risk Appetite. Test your understanding with topic-specific questions in our Mock Exams.

Go to Mock Exams