Skip to content

Risk acceptances

A risk acceptance is the formal record that management chose to tolerate a risk rather than treat it further. It names the scenarios being accepted, the person who approved the decision, the justification behind it, and the date the decision stops being valid. Without that record, an accepted risk is indistinguishable from a forgotten one.

Governance → Risk acceptances in the sidebar.

An acceptance carries a Name and Description, the Risk scenarios it covers (they must belong to the chosen domain), an Approver — the risk owner who is accountable for the decision — an Expiry date after which the acceptance no longer applies, and a Justification explaining the rationale. The justification is editable only by the approver: it is their reasoning, recorded in their words.

StateMeaning
CreatedDrafted but not yet sent for approval
SubmittedAwaiting the approver’s decision
AcceptedValidated by the approver
RejectedDeclined by the approver
RevokedPreviously accepted, then withdrawn

CyberGuard stamps the Acceptance date, Rejection date or Revocation date as each transition happens, so the timeline is reconstructable later.

A newly created acceptance shows a banner saying it has not yet been submitted. Press Submit to send it for validation — the button stays disabled until an approver is set, because there is nobody to send it to.

Once submitted, only the named approver sees the decision buttons. Their banner reminds them to review the acceptance before deciding, because the decision cannot be undone from that screen:

  • Validate accepts the risk. Every linked risk scenario has its treatment set to Accept automatically.
  • Reject declines it.

A submitted acceptance can be pulled back to Draft before a decision is made.

An accepted acceptance can still be Revoked by its approver, but revocation is irreversible — to reinstate the decision you duplicate the acceptance with a new version. Revoking releases the scenarios: any scenario still marked Accept, and not covered by another live acceptance, returns to the Open treatment so it re-enters the action plan.

The Expiry date is what makes an acceptance a decision rather than a permanent exemption. CyberGuard surfaces two problems for you:

  • An acceptance with no expiry date — nothing will ever force a re-examination.
  • An acceptance that has expired — the date has passed, so either the status or the date needs updating.

Both appear in X-rays, alongside the related check for a risk scenario marked as accepted with no acceptance attached. Approvers also see a reminder of how many acceptances are waiting on them when they sign in, and pending items show on the Calendar.

  • Risk scenarios — where the treatment decision lands.
  • Exceptions — the shorter-lived cousin, for deviations from a control or policy.
  • Risk model — how acceptances sit in the risk object graph.