What this is
What is a risk acceptance record?
What is a risk acceptance record?
It is the documented, deliberate decision to accept a specific risk rather than treat it further — recording who accepted it, on what basis, at what residual rating, and for how long. It exists so that accepting a risk is a traceable governance act rather than something that happens by default when treatment is deferred.
How is a risk acceptance different from just not doing anything about a risk?
Acceptance is an explicit, authorised decision made after treatment options and their cost have been considered and rejected for a stated reason. Doing nothing because a risk was never assessed, or because treatment was quietly deprioritised without a decision being made, is not acceptance — it's an unmanaged risk wearing the label.
Why does an acceptance need a review date rather than standing indefinitely?
The conditions that justified accepting a risk — controls in place, exposure levels, external context — change over time. A review date and an early-review trigger force the acceptance to be re-tested against current conditions rather than persisting on the strength of a decision made years earlier under different circumstances.
Scope
When is a risk acceptance record required?
This record documents one specific decision to accept one specific risk. Using it to hold risk criteria, or to list the risks themselves, produces a document that can't be relied on for either purpose.
Use this template when
- A risk has been assessed, treatment options considered, and the decision has been taken to accept the residual risk rather than treat it further
- Treatment is being deliberately deferred — not simply delayed by resourcing — and the deferral itself needs authorising as an acceptance
- A previously accepted risk has reached its review date and is being reconsidered against current conditions
- A linked interim control or the enterprise risk register needs a formal acceptance record to reference
- An acceptance is being extended, and the extension itself needs to be tested and re-authorised rather than rolled over automatically
Do not use it for
- Enterprise Risk Register, which holds the risks themselves at a strategic level — the acceptance record documents one decision made against one of those risks, not the risk inventory.
- Risk Appetite Statement, which sets the standing criteria for how much risk is acceptable in each domain — the acceptance record is tested against that statement, it doesn't set the criteria itself.
- Bow Tie Analysis Record, which maps the threats, top event and barriers for a major hazard — a hazard analysis, not a record of a specific acceptance decision.
- A routine task risk assessment where a control simply hasn't been implemented yet — that's an open action, not a deliberate acceptance
- Recording acceptance after the fact, once an incident has already made the decision moot — the record needs to precede or coincide with the decision, not reconstruct it
Compliance mapping
Which ISO 31000 cl.6.5 requirements does this satisfy?
ISO 31000 cl.6.5 places acceptance inside risk treatment, not as its absence — accepting a risk is one of the treatment options, and it carries the same expectation of a documented, authorised, monitored decision as implementing a control would.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 31000 cl.6.5 | Treatment options and their cost were genuinely considered before acceptance was chosen | Basis |
| ISO 31000 cl.6.4.4 | The residual rating is recorded and checked against the organisation's stated appetite | Header |
| ISO 31000 cl.5.4.3 | The acceptor sits above and independent of the level that benefits from the decision | Authority |
| ISO 31000 cl.6.7 | The basis for the decision is documented, not just the decision itself | Authority |
| ISO 31000 cl.6.6 | A review date and a named trigger for early review are both set at the point of acceptance | Duration |
| ISO 31000 cl.6.5 | An acceptance being extended is re-tested against current circumstances, not simply rolled forward | Duration |
| ISO 31000 cl.5.6 | The acceptance updates the linked register and feeds management review | Outcome |
What it does not cover
- Acceptor Independent Of The Benefit, which if marked 'Partly' or 'No' means the person accepting the risk is also the person who gains from not treating it — the decision cannot be relied on as governance.
- Review Date Set, which if left blank turns a time-bound decision into an open-ended one nobody is accountable for revisiting.
- Trigger For Early Review Defined, which without a named condition means the acceptance can only be caught by chance if something changes before the scheduled date.
- Basis Recorded Not Just The Decision, which if marked 'No' leaves a bare 'accepted' with no reasoning to test later against what actually happened.
- Circumstances Unchanged Since Acceptance, which if marked 'No' on a renewal and waved through anyway means the record is extending a decision made under conditions that no longer apply.
Global
Risk Acceptance Record requirements by country
Formal risk acceptance carries different legal weight depending on whether the risk sits in a safety, financial, or general operational domain — the reasonably practicable test in particular has direct statutory grounding in some jurisdictions and none in others.
Health and Safety at Work etc. Act 1974, s.2(1)
Employers must ensure health and safety so far as is reasonably practicable — a standard requiring an explicit weighing of risk against the cost, time and effort of further control, which the record's reasonably-practicable and cost-assessed fields exist to evidence.
For UK safety-domain acceptances, this record is close to the primary evidence a regulator or court would expect if the reasonably-practicable judgement is ever challenged after an incident.
OSHA General Duty Clause, s.5(a)(1)
Employers must furnish a workplace free from recognised hazards likely to cause death or serious harm; there is no formal statutory concept of documented risk acceptance, but a poorly evidenced acceptance can support a finding of employer knowledge of an uncontrolled hazard.
US acceptances carry less procedural weight in law but more evidentiary risk — a record showing a hazard was known and knowingly left untreated without a defensible basis is a liability exposure in its own right.
ISO 31000:2018 cl.6.5
Risk retention (acceptance) is named explicitly as one of several treatment options, without prescribing a specific approval or review mechanism.
Outside a specific statutory duty, the discipline around acceptance — who approves it, how long it lasts — is entirely a matter of the organisation's own governance, which is what this record is built to enforce.
How to complete it
How to complete a risk acceptance record, step by step
The fields are straightforward to fill in. What decides whether the acceptance holds up later is the judgement behind four specific calls.
The correct level is defined by exposure, not hierarchy for its own sake — it should be set high enough that the decision-maker has no personal stake in avoiding the cost of treatment, and enough authority to be genuinely accountable if the acceptance is later shown to be wrong.
Ask who bears the cost of treating the risk versus who bears the consequence of it materialising — if those are the same person or budget, independence is not satisfied regardless of job title, and the approval needs to move up or sideways.
Any material shift in exposure, control effectiveness, staffing, volume or external context since the last acceptance counts — the test should be applied deliberately at each renewal rather than defaulting to 'unchanged' because nothing dramatic has happened.
A time limit that matches the expected life of the interim control or the planned treatment date is legitimate; a time limit that simply matches the review cycle regardless of context is usually a sign the acceptance is being renewed by habit rather than re-tested.
What auditors find
Most common risk acceptance record findings
These are the defects that turn up most often when acceptance records are checked against what actually happened afterwards, rather than against the form alone.
| Finding | Clause | What fixes it |
|---|---|---|
| The acceptor is the same manager whose budget would fund the treatment | ISO 31000 cl.5.4.3 | Move approval to the next level up and record the independence check explicitly on the record. |
| No review date is set, or it was set and quietly passed with no action | ISO 31000 cl.6.6 | Set a firm review date at acceptance and route overdue reviews to the risk owner automatically rather than letting them lapse. |
| The record states 'accepted' with no documented basis for rejecting treatment | ISO 31000 cl.6.7 | Require the treatment options and cost assessment fields to be completed before the acceptance can be marked complete. |
| An acceptance has been extended three times with 'circumstances unchanged' marked each time without evidence | ISO 31000 cl.6.5 | Require a fresh residual-risk rating and appetite check at every extension, not just a repeated 'Yes'. |
| No interim controls are recorded despite a high residual rating | ISO 31000 cl.6.5 | Require an interim control record to be linked whenever residual rating is High or Very High. |
| The acceptance was never reflected in the enterprise risk register it relates to | ISO 31000 cl.5.6 | Make the register update field mandatory before the acceptance record can be closed. |
Case in point
Case in point: the acceptance that outlived its own reasoning
A logistics site accepted a residual fire-loading risk in a storage bay, citing a planned facility upgrade as the reason treatment could wait twelve months. The record was renewed twice more over the following two years, each time with 'circumstances unchanged' marked without a fresh check — while stock density in the bay had in fact increased well beyond the original assessment.
When an incident investigation pulled the acceptance record afterwards, the original reasoning was sound; the failure was that nobody had tested whether it still applied at either renewal. A time-limited acceptance with a real trigger for early review would have caught the change in stock density long before the renewal date arrived by default.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-028
- Archetype
- Record
- Record ID
- RAC-2026-000
- Scoring
- Acceptances reviewed
- Direction
- High is good
- Singleton
- Yes
- Basis
- ISO 31000 cl.6.5
- Links
- Links Risk register, Interim controls
- Tags
- Governance, Risk
- Sections
- 5
- Fields
- 45
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 4
Header
13 fieldsRecord ID*
Auto sequence. Format RAC-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Risk Accepted*
Source Register ID
Links to CMP-026 Register ID
Accepted By*
Residual Rating*
- Low3 pts
- Medium2 pts
- High1 pt
- Very high0 pts
Within Risk Appetite*
- Yes3 pts
- Marginal1 pt
- No0 pts
Acceptance Date*
Accepted And Never Revisited
A risk accepted three years ago under different conditions is the finding after an incident. Acceptance carries a review date or it is not acceptance.
Basis
6 fieldsTreatment Options Considered*
- Yes3 pts
- Partly1 pt
- No0 pts
Cost Of Treatment Assessed*
- Yes3 pts
- Partly1 pt
- No0 pts
Reasonably Practicable Test Applied*
- Yes3 pts
- Partly1 pt
- No0 pts
Legal Compliance Confirmed*
- Yes3 pts
- Partly1 pt
- No0 pts
Workers Consulted Where Affected*
- Yes3 pts
- Partly1 pt
- No0 pts
Alternative Controls Considered*
- Yes3 pts
- Partly1 pt
- No0 pts
Authority
6 fieldsAccepted At The Correct Level*
- Yes3 pts
- Partly1 pt
- No0 pts
Acceptor Independent Of The Benefit*
- Yes3 pts
- Partly1 pt
- No0 pts
Decision Documented*
- Yes3 pts
- Partly1 pt
- No0 pts
Basis Recorded Not Just The Decision*
- Yes3 pts
- Partly1 pt
- No0 pts
Interim Controls Applied*
- Yes3 pts
- Partly1 pt
- No0 pts
Monitoring Arrangement Set*
- Yes3 pts
- No0 pts
Duration
6 fieldsAcceptance Time Limited*
- Yes3 pts
- Partly1 pt
- No0 pts
Review Date Set*
- Yes3 pts
- Partly1 pt
- No0 pts
Trigger For Early Review Defined*
- Yes3 pts
- Partly1 pt
- No0 pts
Previously Accepted And Extended*
- Yes3 pts
- Partly1 pt
- No0 pts
Circumstances Unchanged Since Acceptance*
- Yes2 pts
- No0 pts
- N/Aexcluded from denominator
Still Within Appetite*
- Yes3 pts
- Partly1 pt
- No0 pts
Outcome
14 fieldsAcceptance Valid*
- Yes3 pts
- Questionable1 pt
- No0 pts
Reconsideration Required*
- No3 pts
- Yes0 pts
Interim Control ID
Links to FDN-032 Interim ID
Register Updated*
- Yes3 pts
- No0 pts
Feeds Management Review*
- Yes3 pts
- Partly1 pt
- No0 pts
Review Date*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Risk Owner*
Signature*
Site Manager*
Second Signature*
CMP-028 · record IDs look like RAC-2026-000 · Links Risk register, Interim controls
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
Raising the record is a five-minute decision. Keeping every open acceptance honest against its review date is the part that gets missed without something watching it continuously.
Holds the acceptance register against the enterprise risk register and appetite statement, and flags any acceptance running past its review date or renewed without a fresh circumstances check.
Links interim controls and near-miss data on the accepted hazard back to the record, so a change in exposure on the floor triggers an early review rather than waiting for the scheduled date.
Tracks operational conditions referenced in the acceptance basis — volume, staffing, throughput — and surfaces when they've moved enough to invalidate the 'circumstances unchanged' assumption.

Rolls every open and overdue acceptance into one view for the risk owner, drafts the reconsideration prompt when a trigger fires, and holds every write for approval before it touches the record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Risk Acceptance Record definitions and key terms
- Risk acceptance
- A deliberate, authorised decision to retain a risk at its current residual level rather than apply further treatment, made after treatment options have been considered.
- Reasonably practicable
- A UK legal standard requiring risk to be reduced until the cost, time and effort of further control would be grossly disproportionate to the benefit gained.
- Residual risk
- The level of risk remaining after existing controls and treatments are accounted for, which is what an acceptance decision is actually made against.
- Interim control
- A temporary measure put in place to manage a risk during the period an acceptance is time-limited, pending permanent treatment or a further decision.
- Risk appetite
- The organisation's standing position on how much risk it is willing to accept in a given domain, which an individual acceptance decision should be tested against.
FAQ
Frequently asked questions about risk acceptance record
Who should approve a risk acceptance?+
Someone above the level that would benefit from avoiding the cost of treatment, and with enough authority to be genuinely accountable for the decision later. The same person who owns the risk and the budget to treat it should not be the one accepting it.
Can a risk acceptance be permanent?+
In practice, no acceptance should be left open-ended. Even a low-risk, low-cost item should carry a review date, because the conditions behind any acceptance can change, and a permanent acceptance is one nobody is checking.
What's the difference between accepting a risk and simply not treating it?+
Acceptance requires that treatment options were considered and rejected for a documented reason, by someone with the authority to make that call. Not treating a risk because it was never assessed, or because treatment was deprioritised without a decision, is an unmanaged risk, not an acceptance.
Does every accepted risk need an interim control?+
Not always, but any acceptance with a High or Very High residual rating should have one, and the record should show it was considered even where none was applied.
What happens if circumstances change before the review date?+
The named early-review trigger should force reconsideration immediately, rather than waiting for the scheduled date — that's the entire purpose of setting a trigger separately from the review date.
How many risk acceptance records should an organisation have?+
One record per decision, but the template itself is a singleton per workspace — a single running register of acceptances that other records and reviews refer back to, rather than a fresh standalone document each time.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Management System Governance
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
More in Risk Governance
Enterprise Risk Register
Holds the risks that could stop the organisation meeting its objectives, above the level of individual task risk
Risk Appetite Statement
States how much risk the organisation is prepared to accept in each domain, so decisions are consistent
Bow Tie Analysis Record
Maps threats, the top event, consequences and the barriers on each side for a major hazard
Barrier Health Review
Reviews whether the barriers relied on in a bow tie are actually in place and working

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 31000:2018 cl.6.5 — Risk treatment
- ISO 31000:2018 cl.6.4.4 — Risk evaluation
- ISO 31000:2018 cl.6.6 — Monitoring and review
- Health and Safety at Work etc. Act 1974, s.2(1) (UK)
- OSHA General Duty Clause, s.5(a)(1) (US)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.