Heritage Community Bank is a fictional institution. All board members, regulatory findings, risk appetite data, and deliverables shown here are simulated for research and portfolio purposes. This report demonstrates a Board Risk Appetite methodology developed by Tristan Jones. ← Back to Portfolio
Table of Contents
Executive Summary
The Board of Directors of Heritage Community Bank completed a comprehensive risk appetite assessment through the Board Risk Appetite Questionnaire (DEL-004), followed by a Board Working Session to resolve areas of divergence. This report documents the Board's formally adopted risk appetite baseline, which will govern severity calibration throughout the threat-informed cyber risk assessment.
Purpose and Authority
This report serves three functions:
- Assessment Baseline. Establishes the Board-approved risk appetite against which all assessment findings will be calibrated. A control gap is measured not just by technical severity but by its distance from the Board's stated tolerance.
- Regulatory Evidence. Documents the Board's active engagement in risk governance, directly addressing MRA 2026-IT-002, which cited that "the Board of Directors has not formally documented its risk appetite for cybersecurity, information technology, artificial intelligence, or operational resilience at a level of specificity sufficient to guide management's risk-taking decisions." This report, together with the Board's adopted motions, satisfies the FDIC's corrective action requirement for Board-level risk appetite articulation within 90 days.
- Governance Record. Records the Board's formal positions through 6 adopted motions on cybersecurity investment, AI governance, risk acceptance authority, financial loss thresholds, Board competency, and organizational defense structure.
Methodology
3.1 Risk Appetite Intake Pathway. Before administering its own questionnaire, Jones & Associates determines whether the Bank has an existing Board-approved risk appetite assessment:
| Pathway | Condition | Firm Action |
|---|---|---|
| A — Existing | Bank has a current, Board-approved risk appetite statement or assessment | Request the existing document. Review for completeness, currency, and scope alignment. If sufficient, adopt the Board's stated appetite as the severity baseline. No questionnaire administered. |
| B — None | Bank has no formal risk appetite statement, or the existing statement does not address cyber, AI, or operational resilience | Administer the full Jones & Associates Board Risk Appetite Questionnaire. Aggregate, present, resolve divergences, produce this report. |
| C — Partial | Bank has a statement that partially covers the scope, is outdated, or lacks domain-level granularity | Request the existing document. Identify gaps. Administer a targeted supplemental questionnaire covering only missing domains. Merge existing positions with supplemental results. |
3.2 Questionnaire Design. 10 sections, 44 questions covering cyber, operational resilience, third-party, data protection, AI, governance, regulatory, and Board oversight domains.
| # | Section | Questions | Type |
|---|---|---|---|
| 1 | Cybersecurity Risk Tolerance | 9 | Scale + Choice + Open |
| 2 | Operational Resilience | 5 | Scale + Choice |
| 3 | Third-Party / Vendor Risk | 4 | Scale |
| 4 | Data Protection and Privacy | 4 | Scale |
| 5 | AI and Emerging Technology | 6 | Scale + Choice |
| 6 | AI Governance and Controls | 5 | Scale + Choice |
| 7 | AI Oversight and Human Control | 4 | Choice |
| 8 | Strategic and Regulatory | 6 | Scale + Choice |
| 9 | Risk Governance Structure | 4 | Choice |
| 10 | Board Oversight Preferences | 6 | Choice |
Scoring: Scale questions use a 1-5 range (1 = Very Low appetite / zero tolerance, 5 = Very High appetite / full acceptance). Consensus is defined as spread ≤ 1 point. Divergence (spread ≥ 2) requires Board discussion and formal resolution.
Index Calculation:
| Index | Sections | Questions |
|---|---|---|
| Board Cyber Appetite Index | 1 (Cyber), 4 (Data), 8 (Regulatory) | 19 |
| Board AI Appetite Index | 5 (AI Tech), 6 (AI Gov), 7 (AI Oversight) | 15 |
| Operational Resilience Index | 2 (Resilience), 3 (Third Party) | 9 |
Participation
| Director | Title | Response Filed | Delegation |
|---|---|---|---|
| Richard Alderman | Board Chair, Independent | Yes | None |
| Catherine Whitfield | CEO / President | Yes | None |
| James Okafor | Director, Independent | Yes | None |
| Patricia Navarro | Director, Independent | Yes | None |
| William Trent | Director, Independent | Yes | None |
Board Risk Appetite Indices
The AI index is notably lower than the other two domains, reflecting the Board's near-unanimous caution toward AI adoption. The 0.33-point gap between AI appetite (1.12) and cyber appetite (1.45) indicates the Board views AI as the higher-risk category.
Consensus Baseline — 25 Areas of Board Alignment
The following questions achieved Board consensus (spread ≤ 1 point). These scores are adopted as the assessment severity baseline without further Board action.
| Q# | Topic | Mean | Resp. |
|---|---|---|---|
| Q2.4 | Ransomware recovery capability risk | 1.0 | 5/5 |
| Q3.3 | Data stored outside the US | 1.0 | 5/5 |
| Q4.1 | Customer PII risk | 1.0 | 5/5 |
| Q4.3 | Unencrypted sensitive data | 1.0 | 5/5 |
| Q5.3 | AI-generated customer communications | 1.0 | 5/5 |
| Q5.4 | Black-box AI models | 1.0 | 4/5 |
| Q5.6 | AI vendor retention of prompts/outputs | 1.0 | 4/5 |
| Q6.5 | Shadow AI / unapproved AI use | 1.0 | 5/5 |
| Q8.1 | Regulatory risk — cybersecurity | 1.0 | 5/5 |
| Q8.2 | Reputational risk — cyber incident | 1.0 | 5/5 |
| Q8.3 | Compliance demonstration capability | 1.0 | 4/5 |
| Q# | Topic | Mean | Resp. |
|---|---|---|---|
| Q2.5 | Untested DR procedures tolerance | 1.2 | 5/5 |
| Q3.2 | Vendors lacking SOC 2 Type II | 1.2 | 5/5 |
| Q4.2 | Breach detection and response capability | 1.2 | 5/5 |
| Q6.4 | AI supply chain risk | 1.2 | 4/5 |
| Q7.3 | AI model risk appetite | 1.2 | 5/5 |
| Q8.4 | Regulatory risk — AI use | 1.2 | 5/5 |
| Q1.2 | Residual risk in internet-facing systems | 1.4 | 5/5 |
| Q2.3 | Single points of failure tolerance | 1.4 | 5/5 |
| Q5.2 | AI automating human judgment decisions | 1.4 | 5/5 |
| Q# | Topic | Mean | Resp. |
|---|---|---|---|
| Q1.1 | Cyber risk tolerance for digital banking growth | 1.8 | 5/5 |
| Q1.7 | Attacker detection capability risk | 1.8 | 4/5 |
| Q4.4 | Data classification practices | 1.8 | 4/5 |
| Q1.3 | Risk in internal operations systems | 2.0 | 4/5 |
| Q8.5 | Quantum computing risk | 2.4 | 5/5 |
Divergence Resolution
Five scale questions had a spread of 2 or more points, indicating structural disagreement. All were resolved through Board motions at the Working Session.
| Q# | Topic | Mean | Spread | Resolution |
|---|---|---|---|---|
| Q1.6 | Cybersecurity underinvestment tolerance | 2.0 | 3 | Motion #1 |
| Q1.4 | Known vulnerabilities with compensating controls | 2.0 | 2 | Motion #1 |
| Q1.5 | End-of-life / unsupported systems | 1.6 | 2 | Motion #1 |
| Q3.1 | Vendor concentration risk | 2.0 | 2 | Motion #1 |
| Q3.4 | Fourth-party risk visibility | 2.0 | 2 | Motion #1 |
Additional structural issues resolved via motions: AI governance policy (Motion #2), risk acceptance authority (Motion #3), financial loss threshold (Motion #4), Board competency (Motion #5), and three lines of defense (Motion #6).
Board Motions Adopted
The following motions were adopted at the Board Working Session. These constitute the Board's formal risk appetite positions and supersede individual questionnaire responses in areas of divergence.
Assessment Severity Calibration
The Board's risk appetite baseline directly governs how assessment findings are scored:
| Board Appetite Score | Control Gap Severity | Rationale |
|---|---|---|
| 1.0 (Zero Tolerance) | Critical or High | Board has no appetite — any gap is unacceptable |
| 1.1 – 1.5 (Very Low) | High | Board expects near-complete control — gaps are significant |
| 1.6 – 2.0 (Low) | High or Medium | Board accepts minimal risk — material gaps are notable |
| 2.1 – 2.5 (Low-Moderate) | Medium | Board accepts some risk with compensating controls |
| 2.6+ (Moderate+) | Medium or Low | Board has accepted risk — gap must be substantial |
Non-Negotiable Positions: The following Board positions are absolute — findings in these areas cannot be moderated regardless of compensating controls:
- Customer PII protection (Q4.1, mean 1.0)
- Unencrypted sensitive data (Q4.3, mean 1.0)
- Shadow AI (Q6.5, mean 1.0)
- Regulatory compliance (Q8.1, mean 1.0)
- Ransomware recovery (Q2.4, mean 1.0)
Governance Framework Decisions
| Topic | Board Position | Status |
|---|---|---|
| Risk reporting format | Dashboard with trends and movement indicators | Adopted (3/5) |
| Briefing frequency | Quarterly, aligned with Board meetings | Adopted (4/5) |
| Human review of AI output | Full human review required | Adopted (5/5) |
| Board approval of AI agents | Board approves each agent before deployment | Adopted (3/4) |
| AI change management | Full change management required | Adopted (4/4) |
| AI use disclosure | Mandatory on all AI-assisted work | Adopted (4/4) |
| External AI tool policy | Strict prohibition, no exceptions | Adopted (4/5) |
| Bank data for vendor AI training | Prohibited | Adopted (4/5) |
| Emerging tech approach | Reactive — wait for regulatory guidance | Adopted (3/5) |
| Incident reporting (non-escalated) | Quarterly summary in Board packet | Adopted (3/5) |
| Risk capacity vs. appetite | Not formally distinguished | Advisory |
Recommendations
- Document adopted motions in Board minutes and distribute to all directors
- Update the Bank's Risk Appetite Statement with 1.39 overall appetite, domain indices, and $750K threshold
- Issue formal AI prohibition notice to all employees pending framework development
- Engage a cybersecurity training provider for Board education
- Present cybersecurity budget proposal aligned with peer benchmarks (Motion #1)
- Complete three lines of defense structural review (Motion #6)
- Establish tiered risk acceptance authority in written policy (Motion #3)
- Annual reassessment — administer questionnaire annually and on material risk profile changes
- AI governance framework development — 12-month timeline per Motion #2
- Board competency monitoring — annual self-assessment against OCC guidance
Certification
This report accurately reflects the aggregated results of the Board Risk Appetite Questionnaire (DEL-004) and the formal motions adopted at the Board Working Session.
| Role | Name | Organization | Date |
|---|---|---|---|
| Lead Assessor | Tristan Jones | Jones & Associates |
We, the undersigned members of the Board of Directors of Heritage Community Bank, certify that:
- We have reviewed this Board Risk Appetite Report
- The adopted motions accurately reflect the Board's positions as discussed and voted upon
- We authorize the use of the risk appetite baseline documented herein for severity calibration in the Threat-Informed Cyber Risk Assessment
| Director | Title | Signature | Date |
|---|---|---|---|
| Richard Alderman | Board Chair | ||
| Catherine Whitfield | CEO / President | ||
| James Okafor | Director | ||
| Patricia Navarro | Director | ||
| William Trent | Director |