Risk tolerance versus risk capacity
I have seen IT risk practitioners use the phrases risk tolerance and risk capacity interchangeably, but this is not correct.
An organization going a little beyond the risk appetite is still within the risk tolerance, which is manageable as long as there are some compensating controls in place. However, when the risk tolerance crosses a certain threshold, it enters into the territory of risk capacity. As we saw in the earlier definition, anything over risk capacity could impact the existence of the organization, and that is something that has to be avoided at all costs.
That said, an organization can still operate as intended within its risk tolerance and under the risk capacity, but its existence will be in question if it crosses the risk capacity.
In the following section, we will see the relationship between risk appetite and business objectives.