Quick Read
SPK DDMS2000:2026 Section 6.6 requires organisations to formally determine, document, and obtain governing body approval for their risk appetite and tolerance levels—specifying how much residual risk they will accept by subject type and where they will accept none at all—rather than leaving this as an implicit assumption buried in screening tool defaults. Certification audits whether this determination exists, was properly approved, is consistently applied, and is periodically reviewed in response to material changes in context, but does not judge whether the organisation's chosen risk tolerance is correct; that remains a business governance decision. The standard deliberately positions risk appetite as a business decision within the "Understanding Risks" section, not as a compliance checkbox, making explicit what most organisations have never formally written down.
Why This Whitepaper Exists
Ask most organisations what their risk appetite for due diligence purposes actually is, and the honest answer is usually that nobody has ever written it down. Tier thresholds exist. A screening tool has default settings. But the underlying question — how much residual risk is this organisation, as a matter of considered governance decision, actually willing to accept — has never been put in front of the people with the authority to answer it.
SPK DDMS2000:2026 makes this a governed, documented, and reviewable decision at Section 6.6, deliberately separated from the mechanics of risk scoring covered elsewhere in the standard. This whitepaper sets out why the standard insists on treating risk appetite as a business decision, and what a genuine determination looks like in practice.
This standard is risk-based by design, and the risk itself is the organisation's to define. Certification tests whether this determination exists, was properly approved, is being followed consistently, and is periodically reviewed — not whether Speeki or any auditor agrees with where the organisation has set its own risk tolerance.
What the Standard Actually Says
Section 6.6.1 requires the organisation to formally determine and document its risk appetite and risk tolerance for due diligence purposes — how much residual risk it is willing to accept, by subject type and module, and where it is not willing to accept residual risk at all, regardless of commercial pressure. Section 6.6.2 requires that this determination, together with the tiering methodology it produces, be submitted to the governing body, or an appropriately senior level under Section 7.5, for formal approval before it is used as the basis for the due diligence management system. Section 6.6.3 requires the determination to be reviewed at planned intervals and following material changes in context — new markets, new subject types, regulatory change tracked in Annex D, or adverse outcomes surfaced through the performance monitoring at Section 12.1.
The standard is explicit about what certification does and does not test here. It tests whether the determination exists, was properly approved, is being followed consistently, and is periodically reviewed. It does not test whether the specific level of risk the organisation has chosen to accept is the right level — that judgement belongs to the organisation's own governance, not to an external assessor.
Why This Sits in “Understanding Risks,” Not “Planning”
Risk appetite determination sits within Section 6 (Understanding Risks), immediately after the risk assessment methodology at Section 6.4 and the tier grouping at Section 6.5, and before the objectives and strategy set out in Section 8. This placement is deliberate: the standard treats the organisation's inherent risk profile and its appetite for that risk as a contextual fact about who the organisation is, not as a planning output to be decided after the fact. Objectives, in Section 8, are then built on top of a risk appetite that has already been determined — not the reverse.
What a Genuine Determination Looks Like
A risk appetite determination that satisfies Section 6.6 is a governance artefact, not a paragraph in a policy document. It needs to answer specific questions, and each answer needs to trace forward into how the rest of the DDMS actually operates.
Question the determination must answer | Where it is used downstream |
|---|---|
How much residual risk are we willing to accept, by subject type and module? | Sets the tier thresholds at Section 6.4.2 and the escalation logic at Section 10.22.5 |
Where are we not willing to accept residual risk at all, regardless of commercial pressure? | Becomes an override provision under Section 6.4.4 and Annex A.2, bypassing aggregate scoring entirely |
Who has the authority to approve this determination, and who can change it? | Anchors the approval requirement at Section 6.6.2 and the change-control process at Section 8.5.5 |
What triggers a review of this determination before its next scheduled cycle? | Feeds the review triggers at Section 6.6.3, including Annex D regulatory change and outcome data under Section 12.1.7 |
If residual risk still exceeds our appetite after controls, what happens? | Drives the risk evaluation and treatment steps at Section 6.7.4–6.7.5 |
The Non-Negotiable Lines
The most consequential part of Section 6.6.1 is often the least developed in practice: where is the organisation not willing to accept residual risk at all, regardless of commercial pressure. This is where a risk appetite determination earns its place as a governance decision rather than a compliance formality — it requires the organisation's leadership to say, in advance and in writing, which findings will never be commercially overridden, before a specific deal or relationship puts that principle under pressure.
These non-negotiable lines become the override provisions referenced at Section 6.4.4 and illustrated in Annex A.2 — the mechanism that lets a single confirmed sanctions hit or comparable finding bypass an aggregate score entirely, precisely because the organisation decided, before any specific case existed, that no amount of otherwise-low risk should be allowed to offset it.
When Residual Risk Still Exceeds Appetite
A risk appetite determination is not complete once it exists — it has to be actively reconciled against what the organisation's controls actually achieve. Section 6.7.4 requires a documented risk evaluation comparing assessed residual risk, after existing controls, against the appetite determined under Section 6.6, for each applicable module. Where residual risk exceeds the organisation's stated appetite even after controls, Section 6.7.4 does not allow this to be treated as an acceptable steady state: the organisation must strengthen controls, escalate the specific gap to the governing body for a documented risk acceptance decision, or reduce exposure by declining or exiting the relationship or activity concerned.
Section 6.7.5 closes the loop: any instance where residual risk was knowingly accepted above the organisation's stated appetite must be recorded, including the approving authority and the review date for that acceptance, and an unreviewed or unapproved acceptance of excess residual risk is itself treated as a nonconformity under Section 14.2. This is the mechanism that prevents an organisation's actual risk tolerance from silently drifting away from what its governing body believes it has approved.
Common Gaps Worth Checking
Tier thresholds exist in a procedure document, but no separate risk appetite determination was ever produced or approved at governing body level.
The organisation cannot point to any documented non-negotiable line — findings that should never be commercially overridden, regardless of relationship value.
The risk appetite determination has not been reviewed since it was first written, despite material changes in the organisation's markets, subject types, or applicable obligations.
Instances exist where residual risk clearly exceeded the organisation's stated appetite, but no documented risk acceptance decision, approving authority, or review date can be produced.
How Speeki Sentinel Certification Assesses This
Certification against SPK DDMS2000:2026 tests for the existence, approval, and consistent application of the risk appetite determination — including whether instances of accepted excess residual risk were properly documented and approved rather than left silent. An assessor does not evaluate whether the organisation's chosen risk appetite is itself appropriate; that determination belongs to the organisation's own governance.
Speeki Sentinel is the certification product through which this assessment is delivered. Organisations may determine and document their own risk appetite independently of Sentinel; certification is a separate, optional step available once an organisation believes its determination and the governance around it are ready to be independently tested.
Speeki is an accredited certification body. For current information on the specific accreditations Speeki holds and their scope, please refer to speeki.com rather than relying on this whitepaper, as accreditation status and scope are maintained centrally and can change.
Closing Note
A due diligence management system without a documented risk appetite determination is not neutral — it simply has an unstated, unowned appetite, set by default by whoever configured the screening tool or built the tiering spreadsheet. Section 6.6 asks an organisation's leadership to own that decision explicitly, put it in writing, and stand behind it — including the parts that will occasionally cost the organisation a relationship it might otherwise have been tempted to accept.