RSK-03Risk and Decisions
Acceptances expire
Accepted risks and control exceptions carry an accountable executive, a compensating control and an expiry date.
Why it exists
An acceptance without an end date is a decision nobody revisits.
What usually proves it
Exception register with expiry and review outcomes.
Smaller organizations
The founder accepts in writing and revisits every quarter.
Mapped to
- Partially addressedSOC 2 Trust Services Criteria · CC3.4 — Implicit in risk response; expiry is not required.
- Partially addressedISO/IEC 27001 Annex A · 6.1.3(f) — Acceptance is required to be approved, not time-bound.
- Partially addressedNIST Cybersecurity Framework · GV.RM-06 — Expressed as risk response tracking.
- Partially addressedPCI DSS · 12.3.3 — Applies to compensating controls, reviewed annually.
- Deliberately absentHIPAA Security Rule — No exception mechanism is defined; addressable specifications carry their own documented rationale instead.
- Deliberately absentGDPR — No concept of accepting non-compliance.
- Deliberately absentEU AI Act — No exception mechanism for high-risk obligations.
- Partially addressedNIST AI Risk Management Framework · MANAGE 1.2 — Risk acceptance is described but not time-bound.