D1 · General

What is risk acceptance?

Risk acceptance is a formal management decision to acknowledge a risk without further mitigation — when the cost of control exceeds the risk impact, or for temporary situations.
Risk acceptance should be documented, reviewed periodically, and made by appropriate authority level. "We know about it but accept it" without documentation is negligence. Include accepted risks in a risk register.
← Back to Glossary Practice Questions →