Accept residual risk within a risk domain
Draft
Accept residual risk within a risk domain
Layer 4. Control RSKRisk acceptance
Allocation
| L4-RSK-02 | |
|---|---|
| Decides | Domain owner: CISO for security, DPO for privacy, Head of Risk for enterprise |
| Consulted | Model Owner and Head of Internal Audit |
| Executes | Model Owner |
| Evidence | Signed, time-bounded domain risk acceptance |
| Delegated band | Delegated |
In plain terms
A domain owner accepts what remains after controls, within their domain and within their limit.
What is being judged
What is actually left. Residual risk is what remains after the controls that are operating, not after the controls that are designed. A control specified but not yet running does not reduce residual risk, and treating design as operation is the most common error in this decision.
Three properties. Acceptance is within one domain; a CISO accepting security risk has said nothing about privacy. It is within a stated limit from the risk appetite statement, expressed in the domain’s own units rather than converted to a common scale, because conversion loses the thing that made it a domain. And it is time-bounded, always.
What this decision does not cover
It does not accept the system. That is L4-RSK-03, and the difference is the reason both exist.
When it fires
On event. Before deployment. On material change to the system or its environment. On a control failure in the domain. On expiry.
On cycle. At the stated expiry.
What you need before deciding
Evidence which controls are operating, distinct from which are specified. The domain limit from the risk appetite statement. The consequence class. What the acceptance costs if wrong, in the domain’s own terms.
How this goes wrong
Accepting designed rather than operating controls, above. The perpetual acceptance: no expiry, or one that passed and was never revisited, so a time-bounded decision became a permanent condition without anyone deciding it should. Converting to a common scale: expressing privacy risk in currency to compare it with security risk, which produces a comparable number and an incomparable judgment. Acceptance above the limit: which is L4-RSK-04 and belongs to the Board.
Related decisions
Upstream L4-RSK-01 appetite, L4-CLS-04 classification.
Downstream L4-RSK-03 composite.
Escalation L4-RSK-04 above limit, L4-RSK-05 arbitration.
Convention evidence currency, §0.1: the composite record above this expires when this does.
Instrument references
ISO 31000 and COBIT APO12 both specify risk treatment and acceptance. ISO/IEC 27001 clause 6.1.3 requires risk acceptance by a risk owner. The domain separation and the composite record above it are AI9GM’s.
Correction
The maintainer answers corrections. There is no service level. Responses are best-effort and opportunistic within a reasonable time: a correction raised on a Monday is answered that week or sooner.