Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 risk acceptance flow from residual risk rating through criteria check to owner approval and record

ISO 27001 Risk Acceptance Criteria Guide 2026

ISO 27001 risk acceptance is the formal decision to live with a risk that remains after treatment, made by someone with the authority to accept it and recorded so that it can be reviewed. It is a small part of the standard that auditors examine closely, because it shows whether the risk process leads to real decisions or merely produces a register.

This guide explains what ISO/IEC 27001:2022 requires for risk acceptance, how to write acceptance criteria, who may approve, how to handle exceptions and time-limited acceptance, and what evidence auditors expect to see.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

What ISO 27001 requires for risk acceptance

Two requirements matter. Clause 6.1.2 requires the organization to define and apply a risk assessment process that includes establishing and maintaining risk criteria, which cover both risk acceptance criteria and criteria for performing risk assessments. Clause 6.1.3 then requires a risk treatment process, and within it the organization must formulate a risk treatment plan and obtain the risk owners’ approval of that plan and their acceptance of the residual information security risks. The organization must keep documented information about both. You can read the official listing at ISO/IEC 27001 on iso.org.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

In short, you must decide in advance what level of risk is acceptable, and a named owner must accept what remains after controls are applied. Our overview of the ISO 27001 risk assessment puts these requirements in the context of the whole process.

Writing criteria for ISO 27001 risk acceptance

Criteria are rules, not intentions. They should tell an assessor, without a meeting, whether a given risk can be accepted, and by whom. Base them on your risk scale and your appetite. Our guide to risk appetite explains how to set the underlying limits.

Residual risk levelTypical ruleApprover
LowMay be accepted without further treatmentRisk owner
MediumAccepted only with a documented reason and a review dateRisk owner with information security manager review
HighTreat further, or accept for a defined period with compensating controlsSenior management
Very highNot acceptable; must be treated, avoided or transferredTop management only by exception

Add conditions that go beyond the score. For example, risks involving legal breaches, safety issues or unencrypted regulated data may be unacceptable at any score. Set time limits so that acceptance does not become permanent by default.

Avoid criteria that cannot be tested

Statements such as risks will be accepted where reasonable are not criteria. An auditor will ask how you decided, and a vague statement gives you nothing to point to. Tie the criteria to the scale used in the register, so that each risk’s rating shows immediately which rule applies.

Who may approve ISO 27001 risk acceptance

The standard says risk owners approve acceptance of residual risk. A risk owner is a person or entity with the accountability and authority to manage a risk. That means someone with budget and decision rights, not merely the person who administers the system. Where the risk exceeds the owner’s authority, escalate it to a higher level. Our guide to the ISO 27001 risk owner explains how to assign these roles, and the article on the ISO 27001 risk treatment plan shows where the approval is recorded.

  1. Assess the risk and rate its inherent level.
  2. Select and apply controls through the treatment plan.
  3. Rate the residual risk using the same scale.
  4. Check the residual rating against the acceptance criteria.
  5. Obtain approval from the owner or the escalation level the criteria require.
  6. Record and schedule review.

What to record for each accepted risk

A useful record includes the risk description, its inherent and residual ratings, the controls in place, the reason for accepting instead of treating further, the approver’s name and role, the date of approval, the conditions attached and the date of the next review. Keep this in the risk register or the risk treatment plan so that the acceptance can be found next to the risk. Where the decision is significant, attach the supporting analysis, such as a cost estimate or a note about why further controls are impractical.

Time-limited acceptance and exceptions

Some risks will remain above the usual threshold because the fix depends on a system replacement, a supplier release or a budget cycle. Treat these as time-limited exceptions. State the period, the compensating controls, who approved it and what triggers an earlier review. Track exceptions in a register, and review the list at management review. If the same exceptions are renewed year after year, investigate. Either the plan to close them is not working or the acceptance criteria are set too tightly.

Linking acceptance to the Statement of Applicability

Acceptance interacts with control selection. If you choose not to implement a control that would reduce a risk, you should be able to explain why, and the resulting residual risk should be accepted by the owner. Auditors compare the Statement of Applicability, the risk treatment plan and the risk register, and inconsistent stories between them are a common source of findings. Check them side by side before an audit, and see our guide to the ISO 27001 asset-based risk assessment for how the register is built.

What auditors look for

Auditors usually ask for the documented acceptance criteria, then pick several risks and trace them. They check that residual ratings were calculated on the defined scale, that the approval came from an appropriate person and that dates are recent. They look for approvals that were made in bulk by a single signature without discussion, or that predate the risk assessment. They also look at whether top management has been informed of significant residual risks through the management review. A record that shows only a signature and no reasoning is a weak one.

Reporting ISO 27001 risk acceptance to top management

Clause 9.3 requires management review to consider the results of risk assessment and the status of the risk treatment plan. Use that meeting to show the accepted risks, not just the treated ones. A short table listing each accepted risk above the low band, its owner, its residual rating, the expiry of the approval and the compensating controls gives leaders what they need to challenge the decisions. Highlight changes since the last review, such as risks that were accepted for a time and are now due, and any acceptance that has been extended more than once.

Where top management has not seen significant residual risks, the standard’s requirement for leadership involvement is hard to demonstrate. Minutes that record the discussion, and any decisions to keep, change or withdraw an acceptance, are among the best evidence you can give an auditor that the process operates at the right level.

A short worked example

An organization identifies a legacy application that cannot support multi-factor authentication. Its inherent rating is high. The team adds network segmentation, extra logging and privileged access reviews, bringing the residual rating to medium. Under the criteria, a medium residual rating needs the risk owner’s approval with a reason and a review date. The owner, the head of finance operations, accepts the risk for twelve months on the condition that the replacement project remains funded, and the information security manager reviews the decision. The record notes the reason, the compensating controls and the trigger for an earlier review if a related incident occurs.

Common mistakes with ISO 27001 risk acceptance

Organizations approve every risk in a single annual signature, use criteria that cannot be tested, let the security team accept risks that belong to the business, fail to set review dates, forget to update acceptance after changes and cannot show that top management saw the significant ones. Another is treating acceptance as a way to close a finding without any thought. Each accepted risk is a decision that someone will be asked to explain, so record it with that in mind.

Using a ready structure

If you want to avoid building the records from scratch, the ISO 27001 Risk Assessment Report and Workbook provides a structured report with scoring, treatment and acceptance fields in a working register. The ISO 27001 risk assessment methodology guide adds the method behind the scales. Whatever tool you use, make ISO 27001 risk acceptance a documented decision with a named person, a reason and a review date.

ISO 27001 risk acceptance FAQ

What is ISO 27001 risk acceptance?

It is the decision by a risk owner to accept the residual risk that remains after treatment, based on criteria defined in advance, and recorded as documented information.

Who can accept a risk?

The risk owner, meaning a person with the accountability and authority to manage that risk. Higher risks should be escalated to senior management according to your criteria.

Do I need written acceptance criteria?

Yes. Clause 6.1.2 requires risk acceptance criteria to be established and maintained as part of the risk assessment process, and auditors will ask to see them.

Can a risk be accepted permanently?

Acceptance should be reviewed at planned intervals and when circumstances change. Time limits prevent decisions from becoming permanent by default.

What happens if a risk exceeds the criteria?

It must be treated further, avoided or transferred, or escalated for a time-limited exception approved at the right level with compensating controls and a review date.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.