Risk Acceptance
Risk acceptance provides a formal governance mechanism for deciding whether residual AI risk can be tolerated under defined conditions.Purpose
Not every identified risk can be eliminated. Organizations therefore need a controlled process for deciding when residual risk is acceptable.Acceptance considerations
A risk acceptance decision may consider:- residual risk level
- applicable requirements
- control effectiveness
- available mitigations
- business justification
- affected stakeholders
- decision authority
- review period
- conditions or limitations
Accountability
Risk acceptance should be made by an authorized decision-maker and recorded with sufficient evidence to explain the decision.Review
Accepted risks should be revisited when:- the risk changes
- controls change
- incidents occur
- the system changes
- applicable requirements change
- the acceptance period expires
Source
The canonical procedure is maintained in:guidance/02-procedures/11-AIGO-AI-Risk-Acceptance-Procedure-v0.1.md