Risk Criteria Explained: 4 Boundaries Leaders Must Set
Risk criteria are the decision rules that make risk ratings defensible, separating appetite, tolerance, and matrix scores in day-to-day safety governance.

Key takeaways
- 01Define the consequence boundary before you score the hazard, because risk criteria fail when the acceptable line stays implicit and nobody can defend the decision later.
- 02Separate criteria from appetite and tolerance, since each one answers a different governance question and belongs to a different owner in the hierarchy.
- 03Use Bow-Tie, the risk matrix, and LOPA together, because each method exposes a different layer of the same decision and reduces false confidence.
- 04Define escalation rules before the job starts, especially for changes, contractor work, and permits that can drift once the work is live.
- 05Read Antifragile Leadership and, if needed, consult Andreza Araújo team to turn the rule into a practical standard.
When a supervisor calls a risk acceptable without a rule, the operation is not managing risk. It is guessing. ISO 31000: 2018 treats risk criteria as the yardstick that makes the judgment defensible, and this quick explainer shows the 4 parts that keep the yardstick readable in the field.
Risk criteria are the agreed rules for judging whether a risk is acceptable, tolerable, or unacceptable. They turn a vague discussion about danger into a decision rule, which is why they matter in ISO 31000, risk matrices, Bow-Tie reviews, and escalation meetings where leaders must choose action.
What are risk criteria?
Risk criteria are not the same as the risk score, and they are not the same as the method that produces the score. A risk matrix can rank hazards, but it cannot tell the operation what level of consequence is still acceptable unless the rule was set beforehand.
Across 25+ years of executive EHS and more than 250 cultural-transformation projects in 30+ countries, Andreza Araújo has seen that the sites with the most polished scoring are often the ones where the decision rule is least visible. In Antifragile Leadership, she argues that leaders need clear decision rules before uncertainty rises, because volatility always exposes the gap between paperwork and action.
What are the 4 parts of risk criteria?
The four parts are easier to manage when the team can name them separately, which is why a Bow-Tie analysis often clarifies the logic better than a single score. The method shows barriers, while risk criteria decide where the line sits.
- Consequence boundary
- The level of harm, loss, or disruption that the organization will treat as acceptable, tolerable, or unacceptable.
- Likelihood bands
- The frequency ranges that define how often an event can happen before it moves into a different risk class.
- Control assumptions
- The barriers, permits, or supervision steps that the score assumes are working when the judgment is made.
- Escalation rule
- The point where the case must move to a higher authority instead of being left inside routine approval.
If you cannot say which of these four pieces changed, then the score changed for cosmetic reasons only. That is how teams end up trusting a number that nobody can defend, even though the worksite still behaves the same way.
How do risk criteria differ from risk appetite and risk tolerance?
Risk criteria answer the question, "What must be true for this risk to be acceptable?" Risk appetite answers, "How much risk does the business choose to carry to pursue value?" Risk tolerance answers, "How far can we deviate before escalation?" A LOPA review only works when those questions stay separate. If they collapse into one line, the result is weaker governance.
| Concept | What it answers | Typical owner | Common failure |
|---|---|---|---|
| Risk criteria | What makes a risk acceptable or not | Leadership and EHS | The team scores hazards without a real decision line |
| Risk appetite | How much risk the business is willing to carry | Board and executives | It is stated once, then forgotten in the field |
| Risk tolerance | How much deviation can be absorbed before escalation | Process owners and managers | It becomes a permanent green light instead of a limit |
| Risk matrix | How the hazard is ranked | EHS and engineers | The score is mistaken for the decision itself |
A risk matrix, which many teams treat as the decision itself, only becomes useful when the organization has already agreed on consequence boundaries, escalation thresholds, and the control assumptions that sit behind the score. Without that, the matrix becomes decoration.
When should leaders define risk criteria?
Leaders should define risk criteria before design freezes, before a major change, before contractor mobilization, and before a permit-to-work is approved. That order matters because criteria set the line, while execution only tests it. In prevention through design, the most effective control is the one where the hazard never reaches the scoring debate.
A supervisor whose permit is approved by a rule no one can explain will default to habit, not governance. That is the same trap that shows up when teams use a matrix but never define the threshold for escalation, so the next incident is surprising only because the rule was missing.
What should you do next?
Start by writing the four criteria on one page, then test them against one high-risk job, one routine task, and one change request. If the supervisor cannot apply the rule in 30 seconds, it is not ready for the field.
If you want support turning criteria into practice, visit Andreza Araújo. The point is not a prettier template, but a rule set that lets leaders make the same decision in the office and on the floor.
Frequently asked questions
What are risk criteria in ISO 31000?
Who should define risk criteria in a plant?
Can a risk matrix replace risk criteria?
What is the difference between risk criteria and Bow-Tie analysis?
When should risk criteria be reviewed?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.