AI9GM
Type to search documentation.

Accept residual risk within a risk domain

Draft

Allocation

L4-RSK-02
DecidesDomain owner: CISO for security, DPO for privacy, Head of Risk for enterprise
ConsultedModel Owner and Head of Internal Audit
ExecutesModel Owner
EvidenceSigned, time-bounded domain risk acceptance
Delegated bandDelegated

In plain terms

A domain owner accepts what remains after controls, within their domain and within their limit.

What is being judged

What is actually left. Residual risk is what remains after the controls that are operating, not after the controls that are designed. A control specified but not yet running does not reduce residual risk, and treating design as operation is the most common error in this decision.

Three properties. Acceptance is within one domain; a CISO accepting security risk has said nothing about privacy. It is within a stated limit from the risk appetite statement, expressed in the domain’s own units rather than converted to a common scale, because conversion loses the thing that made it a domain. And it is time-bounded, always.

What this decision does not cover

It does not accept the system. That is L4-RSK-03, and the difference is the reason both exist.

When it fires

On event. Before deployment. On material change to the system or its environment. On a control failure in the domain. On expiry.

On cycle. At the stated expiry.

What you need before deciding

Evidence which controls are operating, distinct from which are specified. The domain limit from the risk appetite statement. The consequence class. What the acceptance costs if wrong, in the domain’s own terms.

How this goes wrong

Accepting designed rather than operating controls, above. The perpetual acceptance: no expiry, or one that passed and was never revisited, so a time-bounded decision became a permanent condition without anyone deciding it should. Converting to a common scale: expressing privacy risk in currency to compare it with security risk, which produces a comparable number and an incomparable judgment. Acceptance above the limit: which is L4-RSK-04 and belongs to the Board.

Upstream L4-RSK-01 appetite, L4-CLS-04 classification.

Downstream L4-RSK-03 composite.

Escalation L4-RSK-04 above limit, L4-RSK-05 arbitration.

Convention evidence currency, §0.1: the composite record above this expires when this does.

Instrument references

ISO 31000 and COBIT APO12 both specify risk treatment and acceptance. ISO/IEC 27001 clause 6.1.3 requires risk acceptance by a risk owner. The domain separation and the composite record above it are AI9GM’s.

Correction

Correct L4-RSK-02

The maintainer answers corrections. There is no service level. Responses are best-effort and opportunistic within a reasonable time: a correction raised on a Monday is answered that week or sooner.

Attribution