
Who can accept a risk on behalf of the organisation?
Accepting a risk is a management decision. Learn how authority, criteria, governance and accountability relate to risk acceptance.
⏱️ Estimated reading time: 5–6 minutes
Risk acceptance is a management decision, not simply the outcome of a technical assessment. Identifying, analysing and rating a risk does not bring the risk management process to an end. When an organisation decides to retain a particular exposure, defer treatment or accept the risk that remains after controls have been implemented, that decision must be supported by criteria, authority and evidence.
But who can accept a risk on behalf of the organisation?
The answer depends on the governance model, established responsibilities and authorities, risk criteria and the exposure concerned. Those who identify or assess a risk do not necessarily have the authority to accept it.