Risk Acceptance
What is Risk Acceptance?
A conscious decision to acknowledge and tolerate a specific risk without additional mitigation when the cost of treatment exceeds the potential impact.
Terms that appear alongside risk acceptance
Each of these is named in at least one of the same controls as risk acceptance. The number is how many controls name both.
- residual risk 15 shared controls
- risk assessment 8 shared controls
- risk treatment 8 shared controls
- vulnerability 6 shared controls
- governance 5 shared controls
- policy 5 shared controls
- nist 4 shared controls
- risk register 4 shared controls
Frameworks that govern risk acceptance
What the standards actually require on risk acceptance
Requirements naming risk acceptance across 6 standards, quoted from the control text.
Document STIG requirements that cannot be met as exceptions with risk acceptance and a Plan of Action and Milestones (POA&M) approved by the authorising official.
STIG-GOV-EXC · Exception and risk acceptance (POA&M) →Requirement defined in ISO 27005:2022, clause 6.4.2 (Risk acceptance criteria). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.
iso-27005-2022::6.4.2 · Risk acceptance criteria →Document and formally accept residual privacy risks by the appropriate risk owner including individuals impacted.
ISO27557-7.4 · Residual Privacy Risk Acceptance →Establish Generative AI governance per NIST AI 600-1 governance actions including: dedicated GAI governance function with named accountable officer + policies covering data + model + deployment + use cases + risk acceptance and residual risk decisions document...
NISTAI600-2 · GAI Governance - Roles, Policies, and Risk Acceptance →HKMA C-RAF Domain 1 GOVERNANCE + Domain 2 IDENTIFICATION. DOMAIN 1 GOVERNANCE (5 sub-areas): (1) CYBER RISK GOVERNANCE - board + senior management oversight + governance structure + reporting lines + delegation; board cyber-risk literacy + training;
HKMA-CRAF-Domain1-2-Governance-Identification · HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment →Route every deviation from security policies, instructions and the related controls through the risk management process, secure risk owner approval and residual risk acceptance, record each deviation with a defined expiry, and have risk owners reconfirm its ap...
C5-SP-03 · Exceptions from Existing Policies and Instructions →Questions people ask about risk acceptance
What is Risk Acceptance?
Why is Risk Acceptance important for compliance?
Which compliance frameworks address Risk Acceptance?
Where can I learn more about Risk Acceptance?
See how Risk Acceptance applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.