Back to templates
    Template

    Risk acceptance record

    A fifteen-column record for accepted risks, with the authority table that says who may accept each level and an expiry log that forces a re-decision.

    Risk5 Sept 20263 min read

    ISO 31000:2018ISO/IEC 27001:2022
    On this page
    Download the template

    risk-acceptance-record.xlsx · 11 kBLicensed CC BY 4.0

    What this is

    Three working sheets carry one decision. Acceptances holds one row per accepted risk. Authority table says who may accept each residual level, and for how long. Expiry log records what happened when an acceptance reached its date. It is the artefact produced by sections 3.1, 3.2 and 3.7 of Risk acceptance and residual risk, and it answers one question per row. Who took this exposure, inside whose authority, and until when?

    How to use it

    1. Delete every row marked EXAMPLE - delete. The rows are invented and describe no real organisation or decision.
    2. Fill the Authority table first, from the approved risk criteria. Responsibilities for risk management activities are defined and allocated, in particular the acceptance of residual risks 1. See the playbook, section 3.1.
    3. Open a row only for an informed decision. Accepted risks stay under monitoring and review 2.
    4. Record the treatment considered and the reason it was declined. Retaining a risk by informed decision is a listed treatment option, so the rationale belongs in the record 3.
    5. Recompute the residual level after treatment, never before. Residual risk is the risk remaining after treatment 2. See the playbook, section 3.2.
    6. Test that level against the criteria using 1. Within or 2. Above tolerance. Above tolerance is an escalation, not a stronger acceptance.
    7. Name the compensating controls as controls, each with an owner. A control is a measure that maintains or modifies risk, and does not always exert the effect assumed of it 4.
    8. Set an expiry and an event-based review trigger. Run the Expiry log before every forum, so each acceptance is re-decided or lapses back to the treatment queue.

    What good looks like

    Six of the fifteen columns, from the rows shipped in the workbook.

    IDAssessed levelResidual levelAgainst criteriaExpiryStatus
    A-001HighMedium1. Within2027-04-141. Active
    A-002HighHigh2. Above tolerance2026-12-021. Active
    A-003MediumMedium1. Within2026-06-302. Expired

    Fields

    FieldRequiredMeaningCommon mistake
    Risk statementyesThe risk as assessed, copied from the register rowDescribing the control gap instead of the risk
    Treatment considered, Reason declinedyesThe option costed, and why it was not takenLeaving the reason blank, so only the outcome survives
    Residual levelyesThe level after treatment, recomputedCarrying the pre-treatment level forward
    Against criteriayes1. Within or 2. Above tolerance, tested against the criteriaA free-text answer that the expiry report cannot read
    Compensating controlsyesNamed controls with owners, not intentions"Increased monitoring" with no rule and no queue
    Risk owner, ApproveryesThe role that holds the risk, and the role that signedAn approver outside the band the authority table sets
    Expiry, Review triggeryesThe end date, and the event that reopens it earlierAn open-ended acceptance with a calendar date only

    Download

    • File: risk-acceptance-record.xlsx (xlsx, 11 KB) — four sheets: Read first, Acceptances, Authority table, Expiry log.
    • Markdown variant: the same tables in plain markdown, at content/templates/assets/_risk-acceptance-record.md.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-05. No personal data and no organisation names; the rows are invented.

    References

    1. ISO/IEC. Information security, cybersecurity and privacy protection — Guidance on managing information security risks. ISO/IEC 27005:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27005:ed-4:v1:en 2
    2. ISO. Risk management — Guidelines. ISO 31000:2018. https://www.iso.org/standard/65694.html 5
    3. ISO/IEC. Information security, cybersecurity and privacy protection — Information security controls. ISO/IEC 27002:2022. https://www.iso.org/standard/75652.html 1

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO/IEC 27002:2022 control 5.2, licensed copy · verified 2026-09-05
    2. 2ISO OBP iso:std:iso-iec:27005:ed-4:v1:en · verified 2026-09-03
    3. 3ISO 31000:2018 clause 6.5.2, licensed copy · verified 2026-09-05
    4. 4ISO 31000:2018 clause 3.8, licensed copy · verified 2026-09-05
    5. 5ISO 31000:2018 clauses 3.8 and 6.5.2, licensed copy · verified 2026-09-05