- ISO/IEC 27001:2022 distinguishes risk treatment planning, risk-owner approval and acceptance, implementation, and retained results.
"Information security management systems — Requirements"
Residual risk is the risk remaining after treatment. The risk owner approves the treatment plan and decides whether the resulting risk is acceptable against defined criteria. If normal criteria are overridden, record the justification, decision authority, conditions, and time limit.
Approval of a plan and acceptance of residual risk are related but distinct decisions. If the risk remains unacceptable, revise treatment or reassess instead of closing the risk.
Structured answer sets in this page tree.
Cited legal and guidance references.
Approve only after the risk owner can understand the assessed risk, proposed treatment, expected or measured control effectiveness, remaining consequence and likelihood, and comparison with every approved acceptance rule. The owner approves the treatment plan and makes a separate decision on the residual risk. A higher management level may also need to agree when the criteria or delegated authority require it.
ISO/IEC 27001 requires risk owners to approve risk treatment plans and decide whether to accept . ISO/IEC 27005 separates the two steps: first approve a plan that explains how the assessed risk will be treated; then use a follow-up assessment of consequence and likelihood, including expected or measured control effectiveness, to decide whether the remaining risk is acceptable. One controlled record can capture both decisions, but it should show the decision, evidence, authority, and date for each.
can include unidentified risk and retained risk, so acceptance is not a claim that risk has disappeared. Accepted risks remain subject to monitoring and review. If treatment has not yet been implemented, label the assessment as expected or target residual risk and do not present it as evidence of achieved reduction.
Keep the original assessment, approved treatment plan, rationale for the treatment option, necessary controls, action owners, resources and dates, implementation status, effectiveness evidence, follow-up assessment, and comparison with each applicable acceptance rule. The approval record should identify the risk and plan version, decision-maker, delegated authority, decision date, accepted level, conditions, exposure limit, expiry or review date, monitoring indicators, and required further action.
Separate current risk from target and achieved residual risk. Current risk reflects controls operating now; target residual risk estimates the result expected from planned treatment; achieved residual risk requires evidence after implementation. This distinction prevents an unimplemented plan from being recorded as completed risk reduction.
Define owner, evidence requirements, evidence requests, and the next review date before approval.
Confirm the treatment-plan version and implementation status. Assess how each implemented or proposed control affects consequence, likelihood, or both, then determine the residual level using the same approved method and current evidence. Compare the result with all applicable acceptance criteria, including class-specific, extreme-consequence, time-based, legal, and contractual rules.
Route the plan and residual-risk decision to the risk owner and, where the criteria require it, higher management. Record acceptance, rejection, or conditional acceptance. A rejected risk returns to treatment or reassessment; an accepted risk enters monitoring with explicit triggers and review dates. Avoidance or sharing may replace the proposed treatment when the owner selects another supported option, but the organization still records the resulting risk.
Do not treat a signed plan as proof that controls work or that is acceptable. Approval of the treatment plan, implementation of actions, effectiveness assessment, and acceptance of the remaining risk need distinct evidence even when one record captures all four.
Review an accepted risk at its planned date and when its conditions expire. ISO/IEC 27005 sets no universal acceptance period. Reopen the decision sooner if context, objectives, assets, threats, vulnerabilities, consequences, likelihood, controls, incidents or near misses, suppliers, legal or contractual duties, risk appetite, criteria, or delegated authority change.
Monitoring should test the assumptions behind the decision and whether treatment remains on schedule. A trigger starts a review; the owner then determines whether the prior acceptance still applies, needs new conditions, or must return to treatment.
"Information security management systems — Requirements"
"Guidance on managing information security risks"