The Bottom Line

A tolerance is not a prohibition. It is the point at which a decision leaves one person's authority and must be made deliberately, at the right level, on the record.

Escalation exists to inform and to route, not to block. And it should run in two directions: an opportunity that exceeds tolerance deserves to reach the decision-maker as surely as a risk does.

The cyber-era habit of treating tolerances as walls is the wrong reflex for an environment where the cost of a default no is measured in ceded ground.

The word tolerance carries a history, and the history is misleading here. In the risk standards most institutions inherited, in cybersecurity, in model risk, in third-party risk, a tolerance functioned as a boundary. It marked a line management was told not to cross, and crossing it meant the answer was no. That habit is now being carried into AI oversight, where it quietly miscalibrates how boards relate to risk.

A tolerance was never meant to be a denial. It is a threshold that says a decision has become consequential enough that it should be made deliberately, by the person who holds the authority for it, on the evidence. It is the trigger for a decision, not a substitute for one. Reading it any other way turns an instrument of judgment into an instrument of avoidance.

Escalation Is Routing, Not Refusal


What a tolerance actually does is route. When an activity reaches the threshold, the program moves the decision, and the evidence behind it, to the level authorized to make it. The intent is to inform, and to put the choice in the right hands while it still matters. Escalation is a delivery mechanism for judgment. It is not an alarm that ends the conversation.

Reading it this way changes what reaching a tolerance means inside the organization. Under the boundary reading, hitting a tolerance is a small failure, something to be avoided or engineered around. Under the decision-point reading, hitting a tolerance is the system working as designed: a consequential choice has arrived, and the program has put it in front of the person who should own it. The same event is either an alarm or a signal of health, depending entirely on which definition the institution holds.

Escalation Runs in Two Directions


Here is the part most programs miss. Escalation should be symmetric. The threshold that surfaces a downside should equally surface an opportunity that has outgrown the authority of the person who found it. If a tolerance is a decision point, then the decision it triggers can just as easily be whether to pursue something as whether to permit it.

Most governance escalates only bad news. The channels are built to carry incidents, breaches, and exceptions upward, and they carry opportunity nowhere. So an opportunity that exceeds a manager's authority dies at the manager's desk, not because anyone weighed it and declined, but because no path existed for it to travel up. That is a governance failure, and it is an invisible one, because nothing was ever recorded as refused.

A program that routes only threats is structurally biased toward caution, whatever its risk appetite statement declares. The appetite says the institution will accept risk in pursuit of reward. The escalation design says that only the risk half of that sentence will ever reach a decision-maker. When a stated intention and a built mechanism disagree, the mechanism wins. Symmetric escalation is how the mechanism is made to match the intention.

An opportunity that exceeds tolerance should travel upward as fast as a threat. In most programs, only one of the two has a road.

The Cyber Reflex Is the Wrong Inheritance


This is a specific case of a larger conviction the Center has argued from the start: AI requires a native oversight lens, distinct from the frames built for cyber, model risk, and third-party risk. The tolerance-as-wall habit is a direct inheritance from cybersecurity, and inside cybersecurity it was reasonable. The upside of a security control is rarely an opportunity that needs a board decision, so a security tolerance really was, for the most part, a downside boundary. Treating it as a wall cost the institution little.

AI does not behave that way. The same capability that carries the risk usually carries the reward, and the two cannot be separated at the tolerance line. A model that can price risk faster can also misprice it. An agent that can act without waiting for a person can also act wrongly. To treat the tolerance as a wall in this setting is to wall off the upside together with the downside, and to do it silently. The inherited reflex does not just slow the institution. It hides from the board the very decisions it exists to make.

Why This Environment Forces the Change


The reflexive no was survivable when the world moved slowly. It is not survivable now. Competitors are taking informed risks with AI at a cadence the old approval rhythm cannot match. New tools and use cases arrive faster than a boundary-based program can write rules for them. The cost of a default no is no longer neutral. It is ground conceded, and it compounds while the institution congratulates itself on its caution.

What this environment calls for is not a lower tolerance, or a higher one. It is a different relationship with the tolerance itself: the place where the institution decides, deliberately and on the record, whether a given risk is one it can manage through to the reward on the other side. Sometimes the answer will be no, and a well-run program will have made that no a real decision rather than a reflex. Often the answer is that the risk can be managed, and the reward is worth reaching for. Either way, the point of the tolerance is to get that decision made, by the right person, in time. That capability is what an oversight program exists to produce, and it is the same capability that lets an institution move with confidence rather than merely slowly.

What This Means For Your Board

→

When an AI opportunity exceeds a manager's authority, does a defined path exist for it to reach us, or does it simply stop there?

→

Do our escalation channels carry opportunity upward, or only incidents and exceptions?

→

Are we treating our AI tolerances as walls to be avoided, or as decision points we expect to reach and act on?

→

When we decline an AI initiative at a tolerance, is that a deliberate decision on the record, or does it happen by default because no one had to decide?