GuideGlobalISO/IEC 27005

ISO/IEC 27005 Residual Risk Approval

Residual risk is the risk remaining after treatment. The risk owner approves the treatment plan and decides whether the resulting risk is acceptable against defined criteria. If normal criteria are overridden, record the justification, decision authority, conditions, and time limit.

Approval of a plan and acceptance of residual risk are related but distinct decisions. If the risk remains unacceptable, revise treatment or reassess instead of closing the risk.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Approve only after the risk owner can understand the assessed risk, proposed treatment, expected or measured control effectiveness, remaining consequence and likelihood, and comparison with every approved acceptance rule. The owner approves the treatment plan and makes a separate decision on the residual risk. A higher management level may also need to agree when the criteria or delegated authority require it.

Section 1

What does ISO/IEC 27005 say about residual-risk approval?

ISO/IEC 27001 requires risk owners to approve risk treatment plans and decide whether to accept . ISO/IEC 27005 separates the two steps: first approve a plan that explains how the assessed risk will be treated; then use a follow-up assessment of consequence and likelihood, including expected or measured control effectiveness, to decide whether the remaining risk is acceptable. One controlled record can capture both decisions, but it should show the decision, evidence, authority, and date for each.

can include unidentified risk and retained risk, so acceptance is not a claim that risk has disappeared. Accepted risks remain subject to monitoring and review. If treatment has not yet been implemented, label the assessment as expected or target residual risk and do not present it as evidence of achieved reduction.

  • Risk owner: understand the assessment and plan, approve the plan, and decide on acceptance within delegated authority.
  • Control or action owner: provide implementation status and evidence needed to assess actual effectiveness.
  • Higher management: endorse or make the acceptance decision when the criteria assign the risk level, risk class, exception, or exposure period to a higher authority.
Section 2

Which records make residual-risk approval reviewable?

Keep the original assessment, approved treatment plan, rationale for the treatment option, necessary controls, action owners, resources and dates, implementation status, effectiveness evidence, follow-up assessment, and comparison with each applicable acceptance rule. The approval record should identify the risk and plan version, decision-maker, delegated authority, decision date, accepted level, conditions, exposure limit, expiry or review date, monitoring indicators, and required further action.

Separate current risk from target and achieved residual risk. Current risk reflects controls operating now; target residual risk estimates the result expected from planned treatment; achieved residual risk requires evidence after implementation. This distinction prevents an unimplemented plan from being recorded as completed risk reduction.

  • Link each claimed reduction in likelihood or consequence to the control and evidence that supports it.
  • Record uncertainty, assumptions, control dependencies, and the time period covered by the decision.
  • Keep rejected or superseded decisions so later reviewers can follow why treatment or acceptance changed.
  • If risk is shared through insurance, outsourcing, or another contract, record the agreement's scope and reliability and assess the exposure that remains with the organization.
Section 3

How should the residual-risk approval process operate?

Confirm the treatment-plan version and implementation status. Assess how each implemented or proposed control affects consequence, likelihood, or both, then determine the residual level using the same approved method and current evidence. Compare the result with all applicable acceptance criteria, including class-specific, extreme-consequence, time-based, legal, and contractual rules.

Route the plan and residual-risk decision to the risk owner and, where the criteria require it, higher management. Record acceptance, rejection, or conditional acceptance. A rejected risk returns to treatment or reassessment; an accepted risk enters monitoring with explicit triggers and review dates. Avoidance or sharing may replace the proposed treatment when the owner selects another supported option, but the organization still records the resulting risk.

  • Accept: the meets the criteria and the decision-maker has the required authority.
  • Accept with conditions: criteria allow a temporary or conditional exposure, with a defined extent, treatment commitment, deadline, monitoring indicator, and named owner.
  • Override normal criteria: record the prevailing circumstances, explicit justification, decision authority, conditions, and time limit rather than silently changing the criteria.
  • Do not accept: further treatment, avoidance, sharing, a revised plan, or another assessment is needed before a new decision.
Section 4

Which approval mistakes should teams avoid?

Do not treat a signed plan as proof that controls work or that is acceptable. Approval of the treatment plan, implementation of actions, effectiveness assessment, and acceptance of the remaining risk need distinct evidence even when one record captures all four.

  • Do not record target as achieved before implementation and effectiveness evidence exist.
  • Do not let a combined score bypass a separate acceptance rule or management-authority threshold.
  • Do not revise the criteria to fit one decision; document and authorize the exception instead.
  • Do not assume insurance or a supplier contract transfers every consequence, legal duty, or operational dependency.
Section 5

When should residual-risk approval be reviewed?

Review an accepted risk at its planned date and when its conditions expire. ISO/IEC 27005 sets no universal acceptance period. Reopen the decision sooner if context, objectives, assets, threats, vulnerabilities, consequences, likelihood, controls, incidents or near misses, suppliers, legal or contractual duties, risk appetite, criteria, or delegated authority change.

Monitoring should test the assumptions behind the decision and whether treatment remains on schedule. A trigger starts a review; the owner then determines whether the prior acceptance still applies, needs new conditions, or must return to treatment.

  • Name the person responsible for monitoring each condition and trigger.
  • Set an expiry date for temporary acceptance and do not renew it automatically.
  • Record the changed input, reassessment result, new authority decision, and effective date.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO/IEC 27001:2022 distinguishes risk treatment planning, risk-owner approval and acceptance, implementation, and retained results.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 defines accepted risks as subject to monitoring and review and identifies changes in context, threats, vulnerabilities, consequences, likelihood, and controls as review inputs.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.