Risk acceptance record
A fifteen-column record for accepted risks, with the authority table that says who may accept each level and an expiry log that forces a re-decision.
Risk5 Sept 20263 min read
On this page
risk-acceptance-record.xlsx · 11 kBLicensed CC BY 4.0
What this is
Three working sheets carry one decision. Acceptances holds one row per accepted risk. Authority table says who may accept each residual level, and for how long. Expiry log records what happened when an acceptance reached its date. It is the artefact produced by sections 3.1, 3.2 and 3.7 of Risk acceptance and residual risk, and it answers one question per row. Who took this exposure, inside whose authority, and until when?
How to use it
- Delete every row marked EXAMPLE - delete. The rows are invented and describe no real organisation or decision.
- Fill the Authority table first, from the approved risk criteria. Responsibilities for risk management activities are defined and allocated, in particular the acceptance of residual risks 1. See the playbook, section 3.1.
- Open a row only for an informed decision. Accepted risks stay under monitoring and review 2.
- Record the treatment considered and the reason it was declined. Retaining a risk by informed decision is a listed treatment option, so the rationale belongs in the record 3.
- Recompute the residual level after treatment, never before. Residual risk is the risk remaining after treatment 2. See the playbook, section 3.2.
- Test that level against the criteria using 1. Within or 2. Above tolerance. Above tolerance is an escalation, not a stronger acceptance.
- Name the compensating controls as controls, each with an owner. A control is a measure that maintains or modifies risk, and does not always exert the effect assumed of it 4.
- Set an expiry and an event-based review trigger. Run the Expiry log before every forum, so each acceptance is re-decided or lapses back to the treatment queue.
What good looks like
Six of the fifteen columns, from the rows shipped in the workbook.
| ID | Assessed level | Residual level | Against criteria | Expiry | Status |
|---|---|---|---|---|---|
| A-001 | High | Medium | 1. Within | 2027-04-14 | 1. Active |
| A-002 | High | High | 2. Above tolerance | 2026-12-02 | 1. Active |
| A-003 | Medium | Medium | 1. Within | 2026-06-30 | 2. Expired |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Risk statement | yes | The risk as assessed, copied from the register row | Describing the control gap instead of the risk |
| Treatment considered, Reason declined | yes | The option costed, and why it was not taken | Leaving the reason blank, so only the outcome survives |
| Residual level | yes | The level after treatment, recomputed | Carrying the pre-treatment level forward |
| Against criteria | yes | 1. Within or 2. Above tolerance, tested against the criteria | A free-text answer that the expiry report cannot read |
| Compensating controls | yes | Named controls with owners, not intentions | "Increased monitoring" with no rule and no queue |
| Risk owner, Approver | yes | The role that holds the risk, and the role that signed | An approver outside the band the authority table sets |
| Expiry, Review trigger | yes | The end date, and the event that reopens it earlier | An open-ended acceptance with a calendar date only |
Download
- File:
risk-acceptance-record.xlsx(xlsx, 11 KB) — four sheets: Read first, Acceptances, Authority table, Expiry log. - Markdown variant: the same tables in plain markdown, at
content/templates/assets/_risk-acceptance-record.md. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data and no organisation names; the rows are invented.
Related
- Playbook: Risk acceptance and residual risk
- Playbook: Risk appetite and criteria, for the criteria the Against criteria column tests.
- Template: Risk register, which holds the residual level.
References
- ISO/IEC. Information security, cybersecurity and privacy protection — Guidance on managing information security risks. ISO/IEC 27005:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27005:ed-4:v1:en 2
- ISO. Risk management — Guidelines. ISO 31000:2018. https://www.iso.org/standard/65694.html 5
- ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html 1
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1ISO/IEC 27002:2022 control 5.2, licensed copy · verified 2026-09-05
- 2ISO OBP iso:std:iso-iec:27005:ed-4:v1:en · verified 2026-09-03
- 3ISO 31000:2018 clause 6.5.2, licensed copy · verified 2026-09-05
- 4ISO 31000:2018 clause 3.8, licensed copy · verified 2026-09-05
- 5ISO 31000:2018 clauses 3.8 and 6.5.2, licensed copy · verified 2026-09-05