Skip to main content

Risk Acceptance

Risk acceptance provides a formal governance mechanism for deciding whether residual AI risk can be tolerated under defined conditions.

Purpose

Not every identified risk can be eliminated. Organizations therefore need a controlled process for deciding when residual risk is acceptable.

Acceptance considerations

A risk acceptance decision may consider:
  • residual risk level
  • applicable requirements
  • control effectiveness
  • available mitigations
  • business justification
  • affected stakeholders
  • decision authority
  • review period
  • conditions or limitations

Accountability

Risk acceptance should be made by an authorized decision-maker and recorded with sufficient evidence to explain the decision.

Review

Accepted risks should be revisited when:
  • the risk changes
  • controls change
  • incidents occur
  • the system changes
  • applicable requirements change
  • the acceptance period expires

Source

The canonical procedure is maintained in: guidance/02-procedures/11-AIGO-AI-Risk-Acceptance-Procedure-v0.1.md