Summary
In short
- A risk acceptance record is a record used in KnowComply that records a deliberate decision to accept a risk rather than treat it, with who accepted it and for how long. It is built against ISO 31000 cl.6.5 and forms part of the Management System Governance programme.
- Raised whenever treatment is declined or deferred. Approved above the level benefiting from the decision.
- The template holds 45 fields across 5 sections.
- Scoring is acceptances reviewed, where high is good.
- ISO 31000 is risk management. Principles and a framework for managing risk of any kind. Guidance rather than certifiable.
- It connects to the rest of the library: links Risk register, Interim controls.
What it is
What it is
What is a risk acceptance record?
A risk acceptance record is a record used in KnowComply that records a deliberate decision to accept a risk rather than treat it, with who accepted it and for how long. It is built against ISO 31000 cl.6.5 and forms part of the Management System Governance programme.
When is a risk acceptance record completed?
A risk acceptance record is completed at the moment the event happens, rather than reconstructed afterwards. Raised whenever treatment is declined or deferred.
When to use it
When to use it, and when not to
This record is one step in a larger programme. Using it for work that belongs to a neighbouring template produces records that are hard to report on later.
Use it for
- The event or activity this record covers has occurred, or is about to
- The workspace is being set up, or the register needs an entry added or retired
- You are running the Management System Governance programme and this is one of its steps
- A linked record needs this one to exist: links risk register, interim controls
Not for
- Enterprise Risk Register, which holds the risks that could stop the organisation meeting its objectives, above the level of individual task risk.
- Risk Appetite Statement, which states how much risk the organisation is prepared to accept in each domain, so decisions are consistent.
- Bow Tie Analysis Record, which maps threats, the top event, consequences and the barriers on each side for a major hazard.
- Anything outside KnowComply, which belongs in the workspace that owns that process
Standards
What it is built against
ISO 31000Risk management
Principles and a framework for managing risk of any kind. Guidance rather than certifiable.
ISOInternational Organization for Standardization
A voluntary international standard. Widely adopted, often required by customers, and certifiable where a management system standard.
FAQ
Frequently asked questions
What is the risk acceptance record template based on?+
It is built against ISO 31000 cl.6.5. ISO 31000 is risk management. Principles and a framework for managing risk of any kind. Guidance rather than certifiable. ISO is international Organization for Standardization. A voluntary international standard. Widely adopted, often required by customers, and certifiable where a management system standard.
What sections does the risk acceptance record contain?+
There are 5 sections: header, basis, authority, duration, outcome. Together they hold 45 fields, 39 of which are required.
How many risk acceptance record records should we have?+
This is a singleton. One record per workspace, set up once and maintained, rather than one per event. Other templates refer back to it.
Which programme does the risk acceptance record belong to?+
It is part of Management System Governance. One integrated system rather than four running in parallel and exhausting the same people.
How is a risk acceptance record scored?+
Scoring is acceptances reviewed. High is good. Scores exist to make the form tell you something, not to produce a percentage for its own sake.
Can the risk acceptance record template be changed?+
Yes. Every field, option, score and conditional rule is editable, and the links to other templates come with it. Most teams install it as it is, run it for a cycle, then adjust.
The agents
What the agents do with it
The form is the easy part. Keeping it current, routing it to the right owner and holding the evidence together is the work that actually slips.
Holds the risk acceptance record library against your registers, routes each record to its owner, and keeps the evidence trail together.
Coordinates the crew, rolls completion and exceptions into one view, and holds every write for your approval before it touches a record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Sources
Sources
- ISO 31000 — Risk management
- ISO — International Organization for Standardization