Articles tagged with: ISO 31000

Who can accept a risk on behalf of the organisation?

Who can accept a risk on behalf of the organisation_Behaviour Group

Who can accept a risk on behalf of the organisation?

Accepting a risk is a management decision. Learn how authority, criteria, governance and accountability relate to risk acceptance.

⏱️ Estimated reading time: 5–6 minutes

Risk acceptance is a management decision, not simply the outcome of a technical assessment. Identifying, analysing and rating a risk does not bring the risk management process to an end. When an organisation decides to retain a particular exposure, defer treatment or accept the risk that remains after controls have been implemented, that decision must be supported by criteria, authority and evidence.

But who can accept a risk on behalf of the organisation?

The answer depends on the governance model, established responsibilities and authorities, risk criteria and the exposure concerned. Those who identify or assess a risk do not necessarily have the authority to accept it.

Training in risk management, business continuity and information security: how to choose?

Business_Continuity_Risk_Information_Security_Management_Training

Training in risk management, business continuity and information security: how to choose?

A team may need training because it is about to start implementing ISO 27001. Another may already have the system in place but need to review responsibilities and records. The course may be the same, even though the work to be carried out afterwards is different.

⏱️ Estimated reading time: 4 minutes

When choosing training in risk management, business continuity or information security, the enrolment request should specify that work. This allows business unit management and HR to assess the course programme, select participants and plan when they will apply what they have learnt.