Who can accept a risk on behalf of the organisation?

Accepting a risk is a management decision. Learn how authority, criteria, governance and accountability relate to risk acceptance.

⏱️ Estimated reading time: 5–6 minutes

Risk acceptance is a management decision, not simply the outcome of a technical assessment. Identifying, analysing and rating a risk does not bring the risk management process to an end. When an organisation decides to retain a particular exposure, defer treatment or accept the risk that remains after controls have been implemented, that decision must be supported by criteria, authority and evidence.

But who can accept a risk on behalf of the organisation?

The answer depends on the governance model, established responsibilities and authorities, risk criteria and the exposure concerned. Those who identify or assess a risk do not necessarily have the authority to accept it.

Assessing a risk is not the same as accepting it

An information security team may identify a vulnerability. The risk management function may assess scenarios and apply the established criteria. An operational manager may propose treatment measures.

None of these activities means, in itself, that there is authority to accept the resulting risk.

The ISO 31000:2018 integrates risk management into governance and decision-making. In information security, ISO/IEC 27005:2022 provides guidance on managing information security risks in conjunction with ISO/IEC 27001.

The distinction is essential: a technically sound assessment provides information for decision-making; it does not replace the decision itself.

Risk acceptance: can a high risk be accepted?

A decision to accept a risk may be made, provided that it complies with the organisation’s criteria, responsibilities and authorities, as well as applicable legal, regulatory, contractual or other requirements.

Consider a technological dependency whose disruption could affect a critical process. Measures are available to reduce the exposure, but they require investment and several months to implement.

Implement all the measures? Select some of them? Change the process? Transfer part of the risk? Temporarily accept the residual risk?

A rating such as “high risk – 20” does not answer these questions.

The decision-maker needs to understand the scenario and its consequences, existing controls, treatment alternatives, costs and timescales, the expected residual risk and any applicable requirements. It should also be clear who will monitor the risk, how long the decision remains valid and what would trigger its reassessment.

Who has authority for risk acceptance?

Not necessarily the risk owner.

The risk owner has responsibilities for monitoring and managing the risk. The authority to accept a particular exposure should be consistent with the governance model.

The organisation may allow certain risks to be accepted at operational management level while requiring others to be escalated to a higher level of management or to the management body.

Furthermore, risks rarely respect organisational boundaries. A technological dependency may affect operations, business continuity, information security, personal data, contracts, customers and regulatory obligations.

For this reason, decision-making authority should reflect the nature and potential consequences of the risk.

DORA and NIS 2 reinforce management accountability

This relationship between risk and governance is particularly visible in European regulation.

In the financial sector, Regulation (EU) 2022/2554 – DORA assigns the management body responsibilities for defining, approving and overseeing the ICT risk management framework and determining the appropriate level of ICT risk tolerance.

Directive (EU) 2022/2555 – NIS 2 likewise establishes responsibilities for management bodies in approving and overseeing cybersecurity risk-management measures.

Behaviour addresses the operational implementation of these requirements in its DORA Compliance Lead Manager and NIS 2 Compliance Lead Manager programmes.

The conclusion is also relevant beyond these two pieces of legislation: risk management does not end with the function carrying out the technical analysis.

Acceptance does not mean closure

A risk acceptance decision is made within a particular context. That context can change.

A vulnerability may emerge, a supplier or dependency may change, an incident may occur, or a regulatory or contractual requirement may change.

Risk acceptance should therefore be linked, where applicable, to monitoring and review: what will be monitored, by whom, and which events will require the risk to be reassessed.

There is another question that should not be overlooked: if the scenario materialises, can the organisation continue, respond and recover?

This is where risk management and resilience intersect.

ISO 22301, also addressed in the ISO 22301 Essentials programme, provides the framework for business continuity management.

From assessment to decision

Consistent risk management should make it possible to answer clearly:

  • What risk are we assuming?
  • What alternatives were considered?
  • What risk will remain?
  • Who has the authority to decide?
  • How long is the decision valid?
  • What will trigger its review?

When these questions can be answered, the risk register no longer serves merely to document an assessment. It becomes a tool supporting governance, prioritisation, investment and decision-making.

Integrated Risk & Resilience Lead Manager | 6–9 October

The next edition of the Integrated Risk & Resilience Lead Manager (ISO 31000/ISO 27005) takes place from 6 to 9 October 2026, Live Online, and is confirmed.

The programme addresses integrated risk management throughout the lifecycle: governance, context and criteria, assessment and treatment, residual risk acceptance, the relationship between risk, controls and resilience, KRIs, executive reporting and continual improvement.

VIEW PROGRAMME AND PARTICIPATION DETAILS

Date:
Author: Behaviour
Copying or reproduction of this article is not permitted.