Knowella

Risk Acceptance Record

The recurring failure isn't accepting the risk — sometimes that's the right call. It's accepting it once, under conditions that no longer hold, and never revisiting it. A record with no review date and no early-review trigger isn't an acceptance, it's a decision quietly left open forever. When conditions change and nobody notices, the accepted risk becomes the finding in the incident report.

KnowComplyRecordCMP-028Pinned in navigation45 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 31000 cl.6.5
Workspace
KnowComply
Form type
Record
Approved by
A level above the one benefiting from the decision
Review
Time-limited, with a set date and an early-review trigger

The short version

  • A risk acceptance record is only defensible if it shows treatment was genuinely considered and rejected for a stated reason — a record raised simply because treatment was too slow or too expensive to prioritise is not the same decision.
  • Approval has to sit above the person or function that benefits from accepting the risk; self-approval at the level that carries the benefit is the single most common defect in these records.
  • Every acceptance needs a review date and a named trigger for early review — an acceptance with no expiry is a decision nobody is actually accountable for maintaining.
  • It is built against ISO 31000 cl.6.5, and this template is a singleton per workspace — one register of acceptances that other records refer back to, not a fresh document per event.

What this is

What is a risk acceptance record?

What is a risk acceptance record?

It is the documented, deliberate decision to accept a specific risk rather than treat it further — recording who accepted it, on what basis, at what residual rating, and for how long. It exists so that accepting a risk is a traceable governance act rather than something that happens by default when treatment is deferred.

How is a risk acceptance different from just not doing anything about a risk?

Acceptance is an explicit, authorised decision made after treatment options and their cost have been considered and rejected for a stated reason. Doing nothing because a risk was never assessed, or because treatment was quietly deprioritised without a decision being made, is not acceptance — it's an unmanaged risk wearing the label.

Why does an acceptance need a review date rather than standing indefinitely?

The conditions that justified accepting a risk — controls in place, exposure levels, external context — change over time. A review date and an early-review trigger force the acceptance to be re-tested against current conditions rather than persisting on the strength of a decision made years earlier under different circumstances.

Scope

When is a risk acceptance record required?

This record documents one specific decision to accept one specific risk. Using it to hold risk criteria, or to list the risks themselves, produces a document that can't be relied on for either purpose.

Use this template when

  • A risk has been assessed, treatment options considered, and the decision has been taken to accept the residual risk rather than treat it further
  • Treatment is being deliberately deferred — not simply delayed by resourcing — and the deferral itself needs authorising as an acceptance
  • A previously accepted risk has reached its review date and is being reconsidered against current conditions
  • A linked interim control or the enterprise risk register needs a formal acceptance record to reference
  • An acceptance is being extended, and the extension itself needs to be tested and re-authorised rather than rolled over automatically

Do not use it for

  • Enterprise Risk Register, which holds the risks themselves at a strategic level — the acceptance record documents one decision made against one of those risks, not the risk inventory.
  • Risk Appetite Statement, which sets the standing criteria for how much risk is acceptable in each domain — the acceptance record is tested against that statement, it doesn't set the criteria itself.
  • Bow Tie Analysis Record, which maps the threats, top event and barriers for a major hazard — a hazard analysis, not a record of a specific acceptance decision.
  • A routine task risk assessment where a control simply hasn't been implemented yet — that's an open action, not a deliberate acceptance
  • Recording acceptance after the fact, once an incident has already made the decision moot — the record needs to precede or coincide with the decision, not reconstruct it

Compliance mapping

Which ISO 31000 cl.6.5 requirements does this satisfy?

ISO 31000 cl.6.5 places acceptance inside risk treatment, not as its absence — accepting a risk is one of the treatment options, and it carries the same expectation of a documented, authorised, monitored decision as implementing a control would.

ClauseRequirementWhere it lands
ISO 31000 cl.6.5Treatment options and their cost were genuinely considered before acceptance was chosenBasis
ISO 31000 cl.6.4.4The residual rating is recorded and checked against the organisation's stated appetiteHeader
ISO 31000 cl.5.4.3The acceptor sits above and independent of the level that benefits from the decisionAuthority
ISO 31000 cl.6.7The basis for the decision is documented, not just the decision itselfAuthority
ISO 31000 cl.6.6A review date and a named trigger for early review are both set at the point of acceptanceDuration
ISO 31000 cl.6.5An acceptance being extended is re-tested against current circumstances, not simply rolled forwardDuration
ISO 31000 cl.5.6The acceptance updates the linked register and feeds management reviewOutcome

What it does not cover

  • Acceptor Independent Of The Benefit, which if marked 'Partly' or 'No' means the person accepting the risk is also the person who gains from not treating it — the decision cannot be relied on as governance.
  • Review Date Set, which if left blank turns a time-bound decision into an open-ended one nobody is accountable for revisiting.
  • Trigger For Early Review Defined, which without a named condition means the acceptance can only be caught by chance if something changes before the scheduled date.
  • Basis Recorded Not Just The Decision, which if marked 'No' leaves a bare 'accepted' with no reasoning to test later against what actually happened.
  • Circumstances Unchanged Since Acceptance, which if marked 'No' on a renewal and waved through anyway means the record is extending a decision made under conditions that no longer apply.

Global

Risk Acceptance Record requirements by country

Formal risk acceptance carries different legal weight depending on whether the risk sits in a safety, financial, or general operational domain — the reasonably practicable test in particular has direct statutory grounding in some jurisdictions and none in others.

United Kingdom

Health and Safety at Work etc. Act 1974, s.2(1)

Employers must ensure health and safety so far as is reasonably practicable — a standard requiring an explicit weighing of risk against the cost, time and effort of further control, which the record's reasonably-practicable and cost-assessed fields exist to evidence.

For UK safety-domain acceptances, this record is close to the primary evidence a regulator or court would expect if the reasonably-practicable judgement is ever challenged after an incident.

United States

OSHA General Duty Clause, s.5(a)(1)

Employers must furnish a workplace free from recognised hazards likely to cause death or serious harm; there is no formal statutory concept of documented risk acceptance, but a poorly evidenced acceptance can support a finding of employer knowledge of an uncontrolled hazard.

US acceptances carry less procedural weight in law but more evidentiary risk — a record showing a hazard was known and knowingly left untreated without a defensible basis is a liability exposure in its own right.

International

ISO 31000:2018 cl.6.5

Risk retention (acceptance) is named explicitly as one of several treatment options, without prescribing a specific approval or review mechanism.

Outside a specific statutory duty, the discipline around acceptance — who approves it, how long it lasts — is entirely a matter of the organisation's own governance, which is what this record is built to enforce.

How to complete it

How to complete a risk acceptance record, step by step

The fields are straightforward to fill in. What decides whether the acceptance holds up later is the judgement behind four specific calls.

What counts as the 'correct level' of authority?

The correct level is defined by exposure, not hierarchy for its own sake — it should be set high enough that the decision-maker has no personal stake in avoiding the cost of treatment, and enough authority to be genuinely accountable if the acceptance is later shown to be wrong.

How do you test that the acceptor is actually independent?

Ask who bears the cost of treating the risk versus who bears the consequence of it materialising — if those are the same person or budget, independence is not satisfied regardless of job title, and the approval needs to move up or sideways.

What counts as 'circumstances changed' at renewal?

Any material shift in exposure, control effectiveness, staffing, volume or external context since the last acceptance counts — the test should be applied deliberately at each renewal rather than defaulting to 'unchanged' because nothing dramatic has happened.

How long is a legitimate time limit before it needs fresh justification rather than a rollover?

A time limit that matches the expected life of the interim control or the planned treatment date is legitimate; a time limit that simply matches the review cycle regardless of context is usually a sign the acceptance is being renewed by habit rather than re-tested.

What auditors find

Most common risk acceptance record findings

These are the defects that turn up most often when acceptance records are checked against what actually happened afterwards, rather than against the form alone.

FindingClauseWhat fixes it
The acceptor is the same manager whose budget would fund the treatmentISO 31000 cl.5.4.3Move approval to the next level up and record the independence check explicitly on the record.
No review date is set, or it was set and quietly passed with no actionISO 31000 cl.6.6Set a firm review date at acceptance and route overdue reviews to the risk owner automatically rather than letting them lapse.
The record states 'accepted' with no documented basis for rejecting treatmentISO 31000 cl.6.7Require the treatment options and cost assessment fields to be completed before the acceptance can be marked complete.
An acceptance has been extended three times with 'circumstances unchanged' marked each time without evidenceISO 31000 cl.6.5Require a fresh residual-risk rating and appetite check at every extension, not just a repeated 'Yes'.
No interim controls are recorded despite a high residual ratingISO 31000 cl.6.5Require an interim control record to be linked whenever residual rating is High or Very High.
The acceptance was never reflected in the enterprise risk register it relates toISO 31000 cl.5.6Make the register update field mandatory before the acceptance record can be closed.

Case in point

Case in point: the acceptance that outlived its own reasoning

A logistics site accepted a residual fire-loading risk in a storage bay, citing a planned facility upgrade as the reason treatment could wait twelve months. The record was renewed twice more over the following two years, each time with 'circumstances unchanged' marked without a fresh check — while stock density in the bay had in fact increased well beyond the original assessment.

When an incident investigation pulled the acceptance record afterwards, the original reasoning was sound; the failure was that nobody had tested whether it still applied at either renewal. A time-limited acceptance with a real trigger for early review would have caught the change in stock density long before the renewal date arrived by default.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

45fields
5 sections
Reference
CMP-028
Archetype
Record
Record ID
RAC-2026-000
Scoring
Acceptances reviewed
Direction
High is good
Singleton
Yes
Basis
ISO 31000 cl.6.5
Links
Links Risk register, Interim controls
Tags
Governance, Risk
Sections
5
Fields
45
Follow up fields
3
Repeating sections
0
Links out
4
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

13 fields
Text

Record ID*

Generated on save

Auto sequence. Format RAC-2026-000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Completed By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Text

Risk Accepted*

Text

Source Register ID

OptionalLinked

Links to CMP-026 Register ID

Users

Accepted By*

Single Choice

Residual Rating*

Scored
  • Low3 pts
  • Medium2 pts
  • High1 pt
  • Very high0 pts
Single Choice

Within Risk Appetite*

Scored
  • Yes3 pts
  • Marginal1 pt
  • No0 pts
Date & Time

Acceptance Date*

Info

Accepted And Never Revisited

A risk accepted three years ago under different conditions is the finding after an incident. Acceptance carries a review date or it is not acceptance.

Basis

6 fields
Single Choice

Treatment Options Considered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Cost Of Treatment Assessed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Reasonably Practicable Test Applied*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Legal Compliance Confirmed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Workers Consulted Where Affected*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Alternative Controls Considered*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Authority

6 fields
Single Choice

Accepted At The Correct Level*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Acceptor Independent Of The Benefit*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Decision Documented*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Basis Recorded Not Just The Decision*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Interim Controls Applied*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Monitoring Arrangement Set*

Scored
  • Yes3 pts
  • No0 pts

Duration

6 fields
Single Choice

Acceptance Time Limited*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Review Date Set*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Trigger For Early Review Defined*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Previously Accepted And Extended*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Circumstances Unchanged Since Acceptance*

Scored
  • Yes2 pts
  • No0 pts
  • N/Aexcluded from denominator
Single Choice

Still Within Appetite*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts

Outcome

14 fields
Single Choice

Acceptance Valid*

Scored
  • Yes3 pts
  • Questionable1 pt
  • No0 pts
Single Choice

Reconsideration Required*

Scored
  • No3 pts
  • Yes0 pts
Text

Interim Control ID

OptionalLinked

Links to FDN-032 Interim ID

Single Choice

Register Updated*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Feeds Management Review*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Date & Time

Review Date*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Risk Owner*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

CMP-028 · record IDs look like RAC-2026-000 · Links Risk register, Interim controls

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

Raising the record is a five-minute decision. Keeping every open acceptance honest against its review date is the part that gets missed without something watching it continuously.

KnowComply

Holds the acceptance register against the enterprise risk register and appetite statement, and flags any acceptance running past its review date or renewed without a fresh circumstances check.

KnowSafe

Links interim controls and near-miss data on the accepted hazard back to the record, so a change in exposure on the floor triggers an early review rather than waiting for the scheduled date.

KnowOps

Tracks operational conditions referenced in the acceptance basis — volume, staffing, throughput — and surfaces when they've moved enough to invalidate the 'circumstances unchanged' assumption.

Ella
Ella

Rolls every open and overdue acceptance into one view for the risk owner, drafts the reconsideration prompt when a trigger fires, and holds every write for approval before it touches the record.

This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.

Meet KnowComply→

Glossary

Risk Acceptance Record definitions and key terms

Risk acceptance
A deliberate, authorised decision to retain a risk at its current residual level rather than apply further treatment, made after treatment options have been considered.
Reasonably practicable
A UK legal standard requiring risk to be reduced until the cost, time and effort of further control would be grossly disproportionate to the benefit gained.
Residual risk
The level of risk remaining after existing controls and treatments are accounted for, which is what an acceptance decision is actually made against.
Interim control
A temporary measure put in place to manage a risk during the period an acceptance is time-limited, pending permanent treatment or a further decision.
Risk appetite
The organisation's standing position on how much risk it is willing to accept in a given domain, which an individual acceptance decision should be tested against.

FAQ

Frequently asked questions about risk acceptance record

Who should approve a risk acceptance?+

Someone above the level that would benefit from avoiding the cost of treatment, and with enough authority to be genuinely accountable for the decision later. The same person who owns the risk and the budget to treat it should not be the one accepting it.

Can a risk acceptance be permanent?+

In practice, no acceptance should be left open-ended. Even a low-risk, low-cost item should carry a review date, because the conditions behind any acceptance can change, and a permanent acceptance is one nobody is checking.

What's the difference between accepting a risk and simply not treating it?+

Acceptance requires that treatment options were considered and rejected for a documented reason, by someone with the authority to make that call. Not treating a risk because it was never assessed, or because treatment was deprioritised without a decision, is an unmanaged risk, not an acceptance.

Does every accepted risk need an interim control?+

Not always, but any acceptance with a High or Very High residual rating should have one, and the record should show it was considered even where none was applied.

What happens if circumstances change before the review date?+

The named early-review trigger should force reconsideration immediately, rather than waiting for the scheduled date — that's the entire purpose of setting a trigger separately from the review date.

How many risk acceptance records should an organisation have?+

One record per decision, but the template itself is a singleton per workspace — a single running register of acceptances that other records and reviews refer back to, rather than a fresh standalone document each time.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 31000:2018 cl.6.5 — Risk treatment
  • ISO 31000:2018 cl.6.4.4 — Risk evaluation
  • ISO 31000:2018 cl.6.6 — Monitoring and review
  • Health and Safety at Work etc. Act 1974, s.2(1) (UK)
  • OSHA General Duty Clause, s.5(a)(1) (US)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.