ISO/IEC 27001 FAQGlobal ISMS guidanceISO/IEC 27001

ISO/IEC 27001 FAQ Risk Acceptance

How should teams handle Risk Acceptance under ISO/IEC 27001:2022 Information Security Management System?

Define acceptance criteria before evaluating risk, identify the risk owner, record treatment and residual risk, and reassess at planned intervals or after significant change.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

is the 's recorded decision to accept the associated with an approved treatment plan. ISO/IEC 27001 requires the organization to define risk-acceptance criteria, identify risk owners, formulate the treatment plan, and obtain their approval and acceptance. Acceptance does not waive a legal, regulatory, or contractual duty.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

What does ISO/IEC 27001 require before accepting risk?

Clause 6.1.2 requires the risk-assessment process to establish and maintain . The organization identifies risks associated with loss of confidentiality, integrity, and availability within the ISMS scope, identifies risk owners, analyses consequence and realistic likelihood, determines risk levels, compares the results with its criteria, and prioritizes risks for treatment.

Clause 6.1.3 then requires appropriate treatment options, all necessary controls, comparison with Annex A, a Statement of Applicability, and a treatment plan. The risk owners approve that plan and accept the residual information security risks. The standard does not prescribe one scoring scale, approval form, or universal monetary threshold.

  • Apply the approved acceptance criteria consistently; do not invent a different threshold for a difficult exception.
  • Identify the in the assessment and obtain that owner's approval of the treatment plan and residual-.
  • Keep legal, regulatory, contractual, and interested-party requirements visible: accepting an information security risk does not waive an external obligation.
  • Decision sequence: assess against the maintained criteria; select and document treatment; determine necessary controls and the residual result; check external obligations; route the plan and residual risk to the identified owner or defined escalation authority; then record the decision and reassessment triggers.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 clauses 6.1.2 and 6.1.3 establish risk-acceptance criteria, risk-owner identification, risk evaluation, treatment planning, and risk-owner approval and residual-risk acceptance.

ISO/IEC 27002:2022 standard page

ISO/IEC 27002:2022 provides control guidance that may support selected treatment controls; it does not replace the risk decision required by ISO/IEC 27001.

Question 2

What should a risk-acceptance record contain?

ISO/IEC 27001 requires documented information about the risk-assessment and risk-treatment processes and their results, but it does not prescribe a risk-acceptance form. The record should let another reviewer understand the scoped risk scenario, affected information or process, confidentiality-integrity-availability impact, criteria used, likelihood and consequence rationale, current controls, chosen treatment, residual-risk result, and owner approval.

Link the accepted residual risk to the and the Statement of Applicability where controls are involved. An acceptance entry that conflicts with an SoA implementation status or an overdue treatment needs correction or explicit reconciliation.

  • Record the decision date, approving , acceptance period if used, assumptions, dependencies, and reassessment triggers.
  • Distinguish inherent or pre-treatment risk from residual risk after the chosen treatment.
  • Retain the risk assessment and treatment process records required by Clauses 6.1.2 and 6.1.3, not only an approval email.
  • Show planned controls separately from implemented controls. If a planned control has not operated, do not count its expected effect in the current residual result without an explicit, supported method that permits that treatment of future action.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 provides guidance on managing information security risks and can inform the organization's record design and monitoring approach.

Question 3

Who may accept residual information security risk?

ISO/IEC 27001 assigns approval of the and acceptance of to risk owners. Security or compliance teams may coordinate the assessment, challenge the evidence, and administer the register, but they should not approve risk on behalf of an unnamed business owner.

The organization should define authority levels for different risk levels. That governance model is an organizational design choice; the standard's fixed point is that the is identified and provides the required approval and acceptance. A committee may supply escalation or collective governance, but the record should still show the identified risk owner and the authority used for the decision.

  • Name the and the authority under which that person accepts the residual risk.
  • Escalate risks above delegated thresholds to the defined governance body without losing the named .
  • Separate control-owner evidence from the 's acceptance decision.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 clause 6.1.3(f) assigns approval of the treatment plan and acceptance of residual information security risks to risk owners.

Question 4

When must an accepted risk be reassessed?

Clause 8.2 requires information security risk assessments at planned intervals and when significant changes are proposed or occur. Apply that rule to accepted risks rather than treating the approval as permanent.

A significant incident, threat change, control failure, new vulnerability, supplier change, scope change, or changed legal or contractual requirement may invalidate the earlier decision. Whether a change is significant depends on the organization's maintained criteria and the facts; record that assessment rather than treating every change as an automatic new acceptance.

  • Set the next planned review and event-based triggers in the acceptance record.
  • Recalculate the risk with the same maintained criteria unless the criteria themselves have been formally changed.
  • Route changed treatment and residual-risk decisions back to the and update the SoA where control decisions changed.
Citations
ISO/IEC 27001:2022 standard page

ISO/IEC 27001:2022 clause 8.2 requires risk assessment at planned intervals and when significant changes are proposed or occur, with documented results.

Primary sources

References and citations

iso.org
Referenced sections
  • ISO/IEC 27001:2022 clause 8.2 requires risk assessment at planned intervals and when significant changes are proposed or occur, with documented results.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27002:2022 provides guidance relevant to reviewing controls whose operation affects residual risk.
"Information security controls"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 provides guidance on managing information security risks and can inform the organization's record design and monitoring approach.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.