Voice AI Risk Appetite: The Board Statement Framework
In short
A voice AI risk appetite statement is a board-level document that sets how much risk an enterprise will accept when an autonomous agent speaks for the brand. Dilr Voice treats it as the first governance artefact: it defines tolerance across customer harm, compliance, mis-resolution, reputational and financial exposure, then cascades into the gate thresholds delivery teams enforce.
DE
Dilr.ai EngineeringEngineering team
Published Aug 31, 2026Read 13 min
The moment a voice agent answers a customer call, it is acting on the organisation's behalf without a human in the loop. It resolves a query, quotes a policy, refuses a request or escalates. Each of those actions carries exposure, and the board question that comes first is not "what can the agent do" but "how much can go wrong before we intervene". That question has an answer only if someone has written it down. According to the 2026 Stanford AI Index, the AI Incident Database recorded 362 incidents in 2025, up from 233 in 2024, so the exposure is not hypothetical.
Most enterprises skip the top layer. Delivery teams set containment targets, confidence thresholds and escalation rules at the engineering level, but there is no board statement above them declaring how much risk the organisation is willing to carry in the first place. The result is a programme that optimises numbers nobody at board level ever chose. McKinsey's State of AI puts around 88 per cent of organisations using AI in some form, yet only about 6 per cent reaching real maturity, and the gap is rarely about the model. It is about the governance discipline sitting on top of it.
This guide sets out the board-level risk appetite statement for enterprise voice AI: what it is, the categories of exposure it should cover, and how it cascades down into the concrete gate thresholds and service levels the delivery team enforces every day. It is the artefact the rest of your numbers are supposed to derive from.
This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system.
What is a voice AI risk appetite statement?
A voice AI risk appetite statement is a board-level document that declares how much risk the organisation will accept when an autonomous agent speaks for the brand. It sets the outer limits, expressed for each category of exposure, from which every downstream control and gate threshold then derives. Dilr Voice deployments treat it as the first governance artefact, written before any containment target or escalation ceiling, because those numbers are meaningless until someone states the tolerance they enforce.
The concept is not new. Enterprise risk management has always distinguished between the risks an organisation identifies and the risks it chooses to bear. The US National Institute of Standards and Technology, in its AI Risk Management Framework, defines risk tolerance as an organisation's "readiness to bear the risk in order to achieve its objectives". A risk appetite statement is where the board records that readiness in advance, so the people running the agent are not making the call for them under pressure.
It helps to be precise about what this document is not. It is not a programme risk register, which lists the specific risks you have identified and tracks their mitigation. It is not the service level and error budget, which is the engineering reliability budget the delivery team spends. And it is not the board reporting pack, which shows what actually happened last quarter. The appetite statement sits above all three: the register catalogues risk, the appetite statement sets the ceiling, and the error budget and reports measure performance against that ceiling. This layering matters, because a common failure is to write detailed thresholds with no stated appetite to anchor them, which leaves the governance framework resting on preferences rather than a board decision.
Why does a voice AI programme need a board-level risk appetite before launch?
A voice AI programme needs a board-level risk appetite before launch because an autonomous agent removes the human judgement that used to absorb ambiguity at the edge of policy. When a person handled the call, tolerance was set implicitly by training and supervision. When the agent handles it, tolerance has to be explicit and encoded, and only the board can authorise how much of it the organisation will accept across financial, legal and reputational exposure.
The pressure is coming from three directions at once. Incidents are rising, as the Stanford figures above show. Regulation is hardening: the EU AI Act classifies AI systems into four risk tiers, from unacceptable through high, limited and minimal, and attaches real financial consequences to getting the classification wrong. And responsible-AI maturity remains thin even as deployment accelerates, with the Stanford AI Index reporting that the share of businesses with no responsible AI policies in place fell from 24 per cent to only 11 per cent, which still leaves roughly one in nine large adopters operating with nothing written down.
The financial exposure is now quantified in statute. Under the EU AI Act, the size of the fine depends on which obligation you breach, and the board is effectively setting an appetite against these numbers whether it does so deliberately or by omission.
EU AI Act maximum fines, euro millionsMaximum administrative fines under Article 99 of the EU AI Act, by category of breach, taken as the higher of the euro amount or the stated share of worldwide annual turnover. Source: EU AI Act, Article 99
Writing the appetite before launch also protects the programme commercially. A board that has agreed, in advance, how much mis-resolution it will tolerate has given the delivery team air cover to ship. Without it, every difficult decision escalates upward and the programme stalls in review. This is one of the reasons an AI placement diagnostic starts with governance posture rather than model selection: the technical work is straightforward once the tolerances are known.
The same discipline underpins our AI execution office engagements, where a standing appetite statement is what lets a programme make daily calls without a board meeting for each one.
What risk categories should a voice AI appetite statement cover?
A voice AI appetite statement should cover five categories of exposure: customer harm, compliance breach, mis-resolution, reputational damage and financial loss. For each one the board decides a level of tolerance, from zero through low, moderate or open, and states the reasoning. Naming the categories explicitly stops the organisation from quietly accepting a risk in one area because it was busy managing another, which is how voice AI programmes drift into trouble that nobody signed off.
The table below is the structure we use with enterprise boards. It is deliberately category-first rather than control-first, because the board's job is to set the tolerance, not to design the control. Naming the regulators in each row keeps the statement honest: the ICO and the UK GDPR govern the compliance row for personal data, the FCA governs it for regulated financial services, and the EU AI Act sits across all of them.
Exposure category
What the board is deciding
How tolerance is usually expressed
Where it cascades
Customer harm
How much risk to a vulnerable or distressed caller is acceptable
Tolerance for a data or conduct breach under GDPR, ICO or FCA rules
Zero to very low
Consent capture, retention limits, audit logging
Mis-resolution
How often the agent may resolve a call incorrectly
Low, with a defined confidence floor
Confidence thresholds, containment ceilings
Reputational
Exposure to a brand-damaging exchange going public
Low
Tone controls, refusal handling, transcript review
Financial
Direct loss from errors, refunds or missed obligations
Bounded to a stated figure
Transaction limits, human sign-off gates
The categories are platform-agnostic. Whether the agent runs on Dilr Voice or on a platform such as Vapi or Retell AI, the board is deciding the same five tolerances; only the controls that enforce them differ by vendor. That is worth stating in the document itself, so a future change of platform does not reopen the appetite question. It also connects the statement to the broader DATS methodology, which treats governance as a layer that survives any single technology choice.
How does board risk appetite cascade into gate thresholds and SLOs?
Board risk appetite cascades into gate thresholds and service levels through a deliberate translation: each stated tolerance becomes one or more measurable numbers that the delivery team can test, monitor and enforce. Appetite is qualitative and set by the board; thresholds are quantitative and owned by the programme. The cascade is what turns "we have a low tolerance for mis-resolution" into "the agent contains a call only above a defined confidence score, and everything below it routes to a human".
The chain has five links, and skipping any of them breaks the audit trail from board decision to runtime behaviour.
How appetite cascades to runtimeEach link is traceable to the one above it, so any threshold can be justified back to a board decision.
The detail of the service level layer, availability targets, error budgets and how you spend them, belongs to the error budget model and is out of scope here; the appetite statement only sets the ceiling those budgets operate under. What matters at board level is that the cascade is documented, so that when a regulator or an auditor asks why the containment threshold is set where it is, the answer traces cleanly back to a decision the board actually made. That traceability is also what makes the stage-gate funding model defensible, because each release of budget is tied to a gate the appetite defined.
How do you write the thresholds so they are testable?
You write the thresholds so they are testable by converting each category tolerance into a condition that can pass or fail on a single call, with no interpretation required at runtime. A tolerance that cannot be tested is a preference, not a threshold. The rule of thumb we give boards is that every line should be phrased so that an auditor could replay a recorded conversation and say, without debate, whether the agent stayed inside appetite.
Zero-tolerance categories are the easiest to make testable, because zero is a number. If the board's appetite for safeguarding failures is zero, the threshold is that 100 per cent of calls flagged with a distress or vulnerability signal must route to a human within the same session, and any that do not are a breach by definition. Bounded categories are the next tier: a stated financial appetite becomes a hard transaction limit above which the agent cannot act alone, and a stated mis-resolution appetite becomes a confidence floor below which the agent must hand off rather than guess.
Moderate and open tolerances need the most care, because they invite drift. Here the discipline is to attach the threshold to a monitored rate rather than a fixed rule, and to define in advance what the programme does when the rate crosses the line. This is the point where an appetite statement earns its keep, because the board has pre-authorised the response, and the delivery team does not have to convene a governance meeting mid-incident. The AI operating model work we run turns each of these lines into a standing owner and a review cadence, so a threshold never sits unwatched.
Who owns the risk appetite statement, and how often is it reviewed?
The board owns the risk appetite statement, and it should be reviewed at least once a year. In practice a board rarely drafts the document itself; it delegates authorship to a risk or technology committee, or to the steering committee that runs the programme, then formally adopts the statement so that accountability sits at the top. Ownership at board level distinguishes an appetite statement from an internal engineering guideline, and it is what a regulator looks for first.
The annual review is not a house rule; for many organisations it is now an expectation of the UK Corporate Governance Code. Under the 2024 Code, Provision 29 requires the board to monitor the company's risk management and internal control framework and to review its effectiveness at least annually, with the material-controls declaration taking effect for financial years beginning on or after 1 January 2026. A voice agent that makes autonomous decisions is squarely inside that framework, so its appetite statement should be on the same review clock as every other principal control.
Between annual reviews, the appetite statement should be revisited on trigger events: a material change in call volume or scope, a new regulatory deadline such as the EU AI Act high-risk obligations now due on 2 December 2027, a serious incident, or a change of platform. The board reporting pack is where the board sees whether the programme is operating inside appetite between those reviews, which is why the reporting metrics should map one-to-one onto the appetite categories rather than to whatever the vendor dashboard happens to show.
What is the best risk appetite framework for enterprise voice AI in 2026?
The best risk appetite framework for enterprise voice AI in 2026 is not a single named standard but a small stack: use ISO 31000 for the risk-management vocabulary, the NIST AI Risk Management Framework for the AI-specific functions, and map both onto the EU AI Act risk tiers so your internal appetite lines up with your external obligations. For most enterprises that combination is stronger than adopting any one framework alone, because each covers a gap the others leave open.
The trade-offs are real, and a good statement concedes them. If your organisation is pursuing formal certification, ISO 42001, the AI management system standard, is the better anchor because it is auditable and buyers increasingly ask for it, though it is heavier to implement than most voice AI programmes need on day one. If you are a regulated financial services firm, the FCA's expectations and existing operational-resilience rules will dominate, and the AI-specific frameworks become a supporting layer rather than the primary one. And if you are early and small, a single-page appetite statement grounded in the NIST tolerance definition beats a certified management system you cannot yet resource. The honest verdict is that the framework matters less than whether the board has actually set the numbers, reviewed them, and can trace them to what the agent does. On that test, a plain statement that is genuinely owned outperforms a sophisticated framework that is filed and forgotten.
Is a risk appetite statement the same as a risk register?
No. A risk appetite statement sets how much risk the board will accept, expressed as tolerance per category, while a risk register lists the specific risks you have identified and tracks their likelihood, impact and mitigation. The appetite statement is the ceiling; the register is the inventory measured against it. You need both, and for voice AI the register work is covered separately in our guide to the programme risk register.
Does the EU AI Act require a risk appetite statement?
Not by that name. The EU AI Act requires providers and deployers of high-risk AI systems to operate a risk management system and to classify systems by risk tier, but it does not mandate a board appetite statement specifically. In practice a documented appetite statement is one of the cleanest ways to evidence that your risk management is deliberate and board-owned, which is exactly what a conformity assessment or an audit under the Act will probe.
Can a small team skip the board risk appetite statement?
A small team should not skip it, but it can shrink it. The value is in the board decision, not the page count, so a single page stating a tolerance for each of the five categories and naming an owner is enough. What a small team must not do is let the delivery team set tolerances by default through the thresholds they configure, because that quietly moves a board decision to an engineer: the shadow governance problem in another form.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.
voice AI risk appetite statement enterprisevoice AI board risk appetiteAI risk tolerance enterprisevoice AI governance frameworkvoice ai governance redditbest AI governance framework 2026Dilr Voice
Questions this article answers
What is a voice AI risk appetite statement?
A voice AI risk appetite statement is a board-level document that declares how much risk the organisation will accept when an autonomous agent speaks for the brand. It sets the outer limits, expressed for each category of exposure, from which every downstream control and gate threshold then derives. Dilr Voice deployments treat it as the first governance artefact, written before any containment target or escalation ceiling, because those numbers are meaningless until someone states the tolerance they enforce.
Why does a voice AI programme need a board-level risk appetite before launch?
A voice AI programme needs a board-level risk appetite before launch because an autonomous agent removes the human judgement that used to absorb ambiguity at the edge of policy. When a person handled the call, tolerance was set implicitly by training and supervision. When the agent handles it, tolerance has to be explicit and encoded, and only the board can authorise how much of it the organisation will accept across financial, legal and reputational exposure.
What risk categories should a voice AI appetite statement cover?
A voice AI appetite statement should cover five categories of exposure: customer harm, compliance breach, mis-resolution, reputational damage and financial loss. For each one the board decides a level of tolerance, from zero through low, moderate or open, and states the reasoning. Naming the categories explicitly stops the organisation from quietly accepting a risk in one area because it was busy managing another, which is how voice AI programmes drift into trouble that nobody signed off.
How does board risk appetite cascade into gate thresholds and SLOs?
Board risk appetite cascades into gate thresholds and service levels through a deliberate translation: each stated tolerance becomes one or more measurable numbers that the delivery team can test, monitor and enforce. Appetite is qualitative and set by the board; thresholds are quantitative and owned by the programme. The cascade is what turns "we have a low tolerance for mis-resolution" into "the agent contains a call only above a defined confidence score, and everything below it routes to a human".
How do you write the thresholds so they are testable?
You write the thresholds so they are testable by converting each category tolerance into a condition that can pass or fail on a single call, with no interpretation required at runtime. A tolerance that cannot be tested is a preference, not a threshold. The rule of thumb we give boards is that every line should be phrased so that an auditor could replay a recorded conversation and say, without debate, whether the agent stayed inside appetite.
Who owns the risk appetite statement, and how often is it reviewed?
The board owns the risk appetite statement, and it should be reviewed at least once a year. In practice a board rarely drafts the document itself; it delegates authorship to a risk or technology committee, or to the steering committee that runs the programme, then formally adopts the statement so that accountability sits at the top. Ownership at board level distinguishes an appetite statement from an internal engineering guideline, and it is what a regulator looks for first.
What is the best risk appetite framework for enterprise voice AI in 2026?
The best risk appetite framework for enterprise voice AI in 2026 is not a single named standard but a small stack: use ISO 31000 for the risk-management vocabulary, the NIST AI Risk Management Framework for the AI-specific functions, and map both onto the EU AI Act risk tiers so your internal appetite lines up with your external obligations. For most enterprises that combination is stronger than adopting any one framework alone, because each covers a gap the others leave open.
Is a risk appetite statement the same as a risk register?
No. A risk appetite statement sets how much risk the board will accept, expressed as tolerance per category, while a risk register lists the specific risks you have identified and tracks their likelihood, impact and mitigation. The appetite statement is the ceiling; the register is the inventory measured against it. You need both, and for voice AI the register work is covered separately in our guide to the programme risk register.
DE
Dilr.ai Engineering
Engineering team
AI consulting (DATS)
Place AI where the P&L moves
The DATS system runs from a fixed-fee placement diagnostic through to embedded delivery, so AI reaches production instead of staying a pilot.