Jones & Associates

Board Risk Appetite Report

Heritage Community Bank | Threat-Informed Cyber Risk Assessment
Document ID: DEL-005 | Version 1.0 | July 2026
Regulatory Basis: MRA 2026-IT-002 (Board risk appetite articulation)
Portfolio Sample — Synthetic Demonstration
Synthetic Demonstration
Heritage Community Bank is a fictional institution. All board members, regulatory findings, risk appetite data, and deliverables shown here are simulated for research and portfolio purposes. This report demonstrates a Board Risk Appetite methodology developed by Tristan Jones. ← Back to Portfolio

Table of Contents

1Executive Summary
2Purpose and Authority
3Methodology
4Participation
5Board Risk Appetite Indices
6Consensus Baseline
7Divergence Resolution
8Board Motions Adopted
9Assessment Severity Calibration
10Governance Framework Decisions
11Recommendations
12Certification
Section 1

Executive Summary

The Board of Directors of Heritage Community Bank completed a comprehensive risk appetite assessment through the Board Risk Appetite Questionnaire (DEL-004), followed by a Board Working Session to resolve areas of divergence. This report documents the Board's formally adopted risk appetite baseline, which will govern severity calibration throughout the threat-informed cyber risk assessment.

1.39
Overall Appetite
Very Low (1-5 scale)
5/5
Directors Responded
100% participation
25
Consensus Areas
Spread ≤ 1 point
6
Motions Adopted
All divergences resolved
Calibration Effect: The Board's 1.39 appetite means the assessment applies strict severity scoring. Control gaps that might be rated "moderate" at a higher-appetite institution will be rated "high" here. Any gap in a zero-tolerance area (11 questions scored 1.0) is automatically a Critical or High finding.
Section 2

Purpose and Authority

This report serves three functions:

  1. Assessment Baseline. Establishes the Board-approved risk appetite against which all assessment findings will be calibrated. A control gap is measured not just by technical severity but by its distance from the Board's stated tolerance.
  2. Regulatory Evidence. Documents the Board's active engagement in risk governance, directly addressing MRA 2026-IT-002, which cited that "the Board of Directors has not formally documented its risk appetite for cybersecurity, information technology, artificial intelligence, or operational resilience at a level of specificity sufficient to guide management's risk-taking decisions." This report, together with the Board's adopted motions, satisfies the FDIC's corrective action requirement for Board-level risk appetite articulation within 90 days.
  3. Governance Record. Records the Board's formal positions through 6 adopted motions on cybersecurity investment, AI governance, risk acceptance authority, financial loss thresholds, Board competency, and organizational defense structure.
Confidentiality: Individual director responses are confidential to Jones & Associates. No scores, quotes, or positions in this report are attributed to individual directors. All data is presented in aggregate.
Section 3

Methodology

3.1 Risk Appetite Intake Pathway. Before administering its own questionnaire, Jones & Associates determines whether the Bank has an existing Board-approved risk appetite assessment:

PathwayConditionFirm Action
A — Existing Bank has a current, Board-approved risk appetite statement or assessment Request the existing document. Review for completeness, currency, and scope alignment. If sufficient, adopt the Board's stated appetite as the severity baseline. No questionnaire administered.
B — None Bank has no formal risk appetite statement, or the existing statement does not address cyber, AI, or operational resilience Administer the full Jones & Associates Board Risk Appetite Questionnaire. Aggregate, present, resolve divergences, produce this report.
C — Partial Bank has a statement that partially covers the scope, is outdated, or lacks domain-level granularity Request the existing document. Identify gaps. Administer a targeted supplemental questionnaire covering only missing domains. Merge existing positions with supplemental results.
Heritage Community Bank — Pathway B. The Bank does not have a formal Board-level risk appetite statement addressing cybersecurity, AI governance, or operational resilience at the granularity required for threat-informed severity calibration. The full questionnaire was administered.

3.2 Questionnaire Design. 10 sections, 44 questions covering cyber, operational resilience, third-party, data protection, AI, governance, regulatory, and Board oversight domains.

#SectionQuestionsType
1Cybersecurity Risk Tolerance9Scale + Choice + Open
2Operational Resilience5Scale + Choice
3Third-Party / Vendor Risk4Scale
4Data Protection and Privacy4Scale
5AI and Emerging Technology6Scale + Choice
6AI Governance and Controls5Scale + Choice
7AI Oversight and Human Control4Choice
8Strategic and Regulatory6Scale + Choice
9Risk Governance Structure4Choice
10Board Oversight Preferences6Choice

Scoring: Scale questions use a 1-5 range (1 = Very Low appetite / zero tolerance, 5 = Very High appetite / full acceptance). Consensus is defined as spread ≤ 1 point. Divergence (spread ≥ 2) requires Board discussion and formal resolution.

Index Calculation:

IndexSectionsQuestions
Board Cyber Appetite Index1 (Cyber), 4 (Data), 8 (Regulatory)19
Board AI Appetite Index5 (AI Tech), 6 (AI Gov), 7 (AI Oversight)15
Operational Resilience Index2 (Resilience), 3 (Third Party)9
Section 4

Participation

DirectorTitleResponse FiledDelegation
Richard AldermanBoard Chair, IndependentYesNone
Catherine WhitfieldCEO / PresidentYesNone
James OkaforDirector, IndependentYesNone
Patricia NavarroDirector, IndependentYesNone
William TrentDirector, IndependentYesNone
Note: One director did not respond to 13 of 44 questions, primarily in AI governance sections. Rationale fields indicated unfamiliarity with the subject matter and an explicit request for educational briefings. This pattern is addressed in Board Motion #5 (Board Competency).
Section 5

Board Risk Appetite Indices

Overall Board Risk Appetite
1.39
Very Low Appetite — out of 5.0
Board Cyber Appetite Index
1.45
Very Low Appetite
Sections 1, 4, 8
Board AI Appetite Index
1.12
Very Low Appetite
Sections 5, 6, 7
Operational Resilience Index
1.40
Very Low Appetite
Sections 2, 3

The AI index is notably lower than the other two domains, reflecting the Board's near-unanimous caution toward AI adoption. The 0.33-point gap between AI appetite (1.12) and cyber appetite (1.45) indicates the Board views AI as the higher-risk category.

Section 6

Consensus Baseline — 25 Areas of Board Alignment

The following questions achieved Board consensus (spread ≤ 1 point). These scores are adopted as the assessment severity baseline without further Board action.

Zero-Tolerance Areas (Mean = 1.0)
Q#TopicMeanResp.
Q2.4Ransomware recovery capability risk1.05/5
Q3.3Data stored outside the US1.05/5
Q4.1Customer PII risk1.05/5
Q4.3Unencrypted sensitive data1.05/5
Q5.3AI-generated customer communications1.05/5
Q5.4Black-box AI models1.04/5
Q5.6AI vendor retention of prompts/outputs1.04/5
Q6.5Shadow AI / unapproved AI use1.05/5
Q8.1Regulatory risk — cybersecurity1.05/5
Q8.2Reputational risk — cyber incident1.05/5
Q8.3Compliance demonstration capability1.04/5
Assessment Rule: Any control gap in a zero-tolerance area is automatically a Critical or High severity finding. The Board has spoken unanimously — there is no appetite for residual risk in these domains.
Very Low Appetite Areas (Mean 1.1 – 1.5)
Q#TopicMeanResp.
Q2.5Untested DR procedures tolerance1.25/5
Q3.2Vendors lacking SOC 2 Type II1.25/5
Q4.2Breach detection and response capability1.25/5
Q6.4AI supply chain risk1.24/5
Q7.3AI model risk appetite1.25/5
Q8.4Regulatory risk — AI use1.25/5
Q1.2Residual risk in internet-facing systems1.45/5
Q2.3Single points of failure tolerance1.45/5
Q5.2AI automating human judgment decisions1.45/5
Low Appetite Areas (Mean 1.6 – 2.5)
Q#TopicMeanResp.
Q1.1Cyber risk tolerance for digital banking growth1.85/5
Q1.7Attacker detection capability risk1.84/5
Q4.4Data classification practices1.84/5
Q1.3Risk in internal operations systems2.04/5
Q8.5Quantum computing risk2.45/5
Section 7

Divergence Resolution

Five scale questions had a spread of 2 or more points, indicating structural disagreement. All were resolved through Board motions at the Working Session.

Q#TopicMeanSpreadResolution
Q1.6 Cybersecurity underinvestment tolerance 2.0 3 Motion #1
Q1.4 Known vulnerabilities with compensating controls 2.0 2 Motion #1
Q1.5 End-of-life / unsupported systems 1.6 2 Motion #1
Q3.1 Vendor concentration risk 2.0 2 Motion #1
Q3.4 Fourth-party risk visibility 2.0 2 Motion #1

Additional structural issues resolved via motions: AI governance policy (Motion #2), risk acceptance authority (Motion #3), financial loss threshold (Motion #4), Board competency (Motion #5), and three lines of defense (Motion #6).

Section 8

Board Motions Adopted

The following motions were adopted at the Board Working Session. These constitute the Board's formal risk appetite positions and supersede individual questionnaire responses in areas of divergence.

Motion #1 — Cybersecurity Investment
RESOLVED, that the Board of Directors of Heritage Community Bank adopts a risk appetite for cybersecurity investment at or above peer benchmarks as established by the FFIEC and relevant regulatory guidance. Management shall present a cybersecurity budget proposal aligned with this position within 90 days.
Effect: The Board rejects minimum-compliance spending. Adopted appetite score for Q1.6: 1 (Very Low) — no tolerance for underinvestment.
Motion #2 — AI Governance Framework
RESOLVED, that the Board adopts a phased approach to AI governance: (a) immediate prohibition on all AI processing of confidential data pending Board-approved framework; (b) management shall develop and present an AI governance framework within 12 months; (c) the framework must address data handling, vendor evaluation, human oversight, and regulatory compliance before any AI system is approved.
Effect: Current position is prohibition. Adopted appetite for AI with confidential data: 1 (Prohibited) until framework is approved.
Motion #3 — Risk Acceptance Authority
RESOLVED, that the Board adopts tiered risk acceptance authority: (a) CISO/CIO for routine operational exceptions (90-day maximum, documented compensating controls); (b) Risk Committee for material exceptions involving regulatory, reputational, or customer data risk; (c) full Board for strategic risk decisions and exceptions exceeding the financial loss materiality threshold.
Effect: Clear authority levels established. Management cannot accept material risk without Committee or Board oversight.
Motion #4 — Financial Loss Materiality Threshold
RESOLVED, that the Board adopts a financial loss materiality threshold of $750,000 from a single cyber event within any 12-month period. Any incident meeting or exceeding this threshold requires immediate Board notification, independent review, and formal Board response. This threshold shall be reviewed annually.
Effect: $750,000 adopted (approximately 1.5% of Tier 1 capital). This threshold serves as a materiality gate in the assessment's risk scoring.
Motion #5 — Board Cyber and AI Competency
RESOLVED, that the Board commits to mandatory annual cybersecurity and AI literacy training for all directors, beginning within 60 days. The Board Chair shall engage external resources within 30 days. The Governance Committee shall evaluate whether Board composition should include technology/cybersecurity expertise.
Effect: Addresses the competency gap identified in the questionnaire. Ensures all directors can participate in technology risk oversight.
Motion #6 — Three Lines of Defense Review
RESOLVED, that management conduct a structural review of the three lines of defense within 90 days, examining: (a) compliance function reporting independence; (b) internal audit scope and independence for IT/cybersecurity; (c) first-line risk ownership within IT operations. Findings to be presented to the Risk Committee.
Effect: Proactive action on a likely examination finding. Demonstrates Board commitment to governance improvement.
Section 9

Assessment Severity Calibration

The Board's risk appetite baseline directly governs how assessment findings are scored:

Board Appetite ScoreControl Gap SeverityRationale
1.0 (Zero Tolerance) Critical or High Board has no appetite — any gap is unacceptable
1.1 – 1.5 (Very Low) High Board expects near-complete control — gaps are significant
1.6 – 2.0 (Low) High or Medium Board accepts minimal risk — material gaps are notable
2.1 – 2.5 (Low-Moderate) Medium Board accepts some risk with compensating controls
2.6+ (Moderate+) Medium or Low Board has accepted risk — gap must be substantial
Calibration Effect: At 1.39 overall appetite, Heritage Community Bank's severity curve is shifted one full tier above a "moderate appetite" institution. A gap rated Medium elsewhere is High here. A gap rated Low elsewhere is Medium here.

Non-Negotiable Positions: The following Board positions are absolute — findings in these areas cannot be moderated regardless of compensating controls:

  1. Customer PII protection (Q4.1, mean 1.0)
  2. Unencrypted sensitive data (Q4.3, mean 1.0)
  3. Shadow AI (Q6.5, mean 1.0)
  4. Regulatory compliance (Q8.1, mean 1.0)
  5. Ransomware recovery (Q2.4, mean 1.0)
Section 10

Governance Framework Decisions

TopicBoard PositionStatus
Risk reporting formatDashboard with trends and movement indicatorsAdopted (3/5)
Briefing frequencyQuarterly, aligned with Board meetingsAdopted (4/5)
Human review of AI outputFull human review requiredAdopted (5/5)
Board approval of AI agentsBoard approves each agent before deploymentAdopted (3/4)
AI change managementFull change management requiredAdopted (4/4)
AI use disclosureMandatory on all AI-assisted workAdopted (4/4)
External AI tool policyStrict prohibition, no exceptionsAdopted (4/5)
Bank data for vendor AI trainingProhibitedAdopted (4/5)
Emerging tech approachReactive — wait for regulatory guidanceAdopted (3/5)
Incident reporting (non-escalated)Quarterly summary in Board packetAdopted (3/5)
Risk capacity vs. appetiteNot formally distinguishedAdvisory
Section 11

Recommendations

Immediate (within 30 days)
  1. Document adopted motions in Board minutes and distribute to all directors
  2. Update the Bank's Risk Appetite Statement with 1.39 overall appetite, domain indices, and $750K threshold
  3. Issue formal AI prohibition notice to all employees pending framework development
  4. Engage a cybersecurity training provider for Board education
Near-Term (within 90 days)
  1. Present cybersecurity budget proposal aligned with peer benchmarks (Motion #1)
  2. Complete three lines of defense structural review (Motion #6)
  3. Establish tiered risk acceptance authority in written policy (Motion #3)
Ongoing
  1. Annual reassessment — administer questionnaire annually and on material risk profile changes
  2. AI governance framework development — 12-month timeline per Motion #2
  3. Board competency monitoring — annual self-assessment against OCC guidance
Section 12

Certification

This report accurately reflects the aggregated results of the Board Risk Appetite Questionnaire (DEL-004) and the formal motions adopted at the Board Working Session.

Prepared By
RoleNameOrganizationDate
Lead AssessorTristan JonesJones & Associates
Board Certification

We, the undersigned members of the Board of Directors of Heritage Community Bank, certify that:

  1. We have reviewed this Board Risk Appetite Report
  2. The adopted motions accurately reflect the Board's positions as discussed and voted upon
  3. We authorize the use of the risk appetite baseline documented herein for severity calibration in the Threat-Informed Cyber Risk Assessment
DirectorTitleSignatureDate
Richard Alderman Board Chair    
Catherine Whitfield CEO / President    
James Okafor Director    
Patricia Navarro Director    
William Trent Director    
Provenance: Created by ACF-TW-001 [Opus] | Review pending: ACF-QA-001 [Sonnet] | Human signoff pending: T. Jones