RSK-03Risk and Decisions

Acceptances expire

Accepted risks and control exceptions carry an accountable executive, a compensating control and an expiry date.

Why it exists

An acceptance without an end date is a decision nobody revisits.

What usually proves it

Exception register with expiry and review outcomes.

Smaller organizations

The founder accepts in writing and revisits every quarter.

Mapped to

  • Partially addressedSOC 2 Trust Services Criteria · CC3.4 — Implicit in risk response; expiry is not required.
  • Partially addressedISO/IEC 27001 Annex A · 6.1.3(f) — Acceptance is required to be approved, not time-bound.
  • Partially addressedNIST Cybersecurity Framework · GV.RM-06 — Expressed as risk response tracking.
  • Partially addressedPCI DSS · 12.3.3 — Applies to compensating controls, reviewed annually.
  • Deliberately absentHIPAA Security Rule — No exception mechanism is defined; addressable specifications carry their own documented rationale instead.
  • Deliberately absentGDPR — No concept of accepting non-compliance.
  • Deliberately absentEU AI Act — No exception mechanism for high-risk obligations.
  • Partially addressedNIST AI Risk Management Framework · MANAGE 1.2 — Risk acceptance is described but not time-bound.