Accept, Mitigate, or Transfer. But Decide on Purpose.

For each logged risk, record what the organization decided to do. The register should capture the treatment, owner, rationale, due date, and follow-through.

Sorena AI TeamRisk and Governance4 min read

Choose a treatment for every risk

Risk treatment requires a decision. NIST defines risk response as accepting, avoiding, mitigating, sharing, or transferring risk.

Accept means you understand the exposure and choose to carry it. Mitigate means you add controls to reduce likelihood or impact. Share or transfer means another party carries part of the consequence through insurance, contract, outsourcing, or another mechanism. Avoid means you stop or redesign the activity that creates the risk.

"Ignore indefinitely" is not a treatment. Every material risk needs a response, evidence, an owner, and a review date.

The fifth outcome nobody chose

A risk with no assigned treatment remains open. The register may call it pending, but the organization still carries the exposure without a formal acceptance decision.

Deliberate acceptance means someone weighed the exposure, judged it tolerable, recorded a rationale, and took ownership. An untreated risk has none of that documentation.

Assign a treatment before the risk sits unresolved.

Treatment is a verb, not a column

Writing "mitigate" in a spreadsheet cell only labels the decision. The organization still has to implement and monitor the treatment.

Mitigation requires funded controls and confirmation that they work. Transfer requires a policy or contract that covers the relevant scenario. Avoidance requires stopping or redesigning the activity. Acceptance requires review as the exposure changes.

A treatment plan needs an owner, due date, control, and check. NIST SP 800-39 says risk responses must be implemented and monitored, not merely selected.

Use a treatment decision tree, not vibes

Base risk treatment on impact, likelihood, appetite, and cost. Avoid the risk when the activity can stop or change without unacceptable business harm. Mitigate it when a reasonable control can reduce exposure below appetite. Share or transfer it when insurance, contract terms, or another party can carry part of the consequence. Accept the residual risk only after the accountable owner judges it tolerable.

Record the residual risk, evidence, owner, rationale, and review date. For example: "Finance accepts this residual exposure until 30 September because the mitigation cost exceeds the estimated exposure."

How a treatment decision quietly evaporates

Busy teams can leave a risk untreated without deciding to. A risk gets logged with a plan to return to it. The meeting ends, priorities change, and nobody makes the treatment decision.

A decision can also fail in execution. The team chooses mitigation but never funds the control. A risk is marked as transferred, but the insurance clause excludes the relevant scenario. The label no longer matches the exposure.

Make, record, assign, and monitor every treatment decision. Otherwise the organization continues to carry the risk by default. That discipline belongs in a working risk management practice.

Record the decision so it can be reviewed

A recorded treatment can be reviewed and corrected. Teams sometimes delay because they are unsure whether to mitigate or accept, but the organization carries the exposure while they wait.

A treatment record shows the rationale, owner, and trade-off. A board can review it, an auditor can trace it, and the owner can reopen it when new information arrives.

An untreated risk has no equivalent record. If it materializes, the organization may be unable to show who considered it or why no action followed.

A system should force the question. A person should answer it.

People choose the treatment; the system makes sure every risk gets a choice. People weigh exposure against cost and select accept, mitigate, transfer, or avoid. A system can track the follow-through across risks, owners, and reorganizations.

A risk with no treatment should remain visibly open until someone answers what to do, who owns it, and whether the plan happened. A mitigation with no control behind it should appear as a gap.

Sorena tracks whether every risk has an owned treatment and whether the plan was executed. Human judgment stays with the accountable people, while the system keeps untreated and half-treated risks visible.

Decide on purpose, or the default decides for you

Open the register and check whether every treatment has a real plan behind it. Blank treatments, unfunded mitigations, and transfers that do not cover the scenario all leave the organization carrying exposure without an effective decision.

Accept, mitigate, transfer, or avoid the risk. Record the owner, rationale, plan, and review date so neglect does not make the choice.

Frequently asked questions

What are the main options for responding to a risk?+

NIST SP 800-37 lists accept, avoid, mitigate, share, and transfer as risk responses. In practical registers, teams often group those into accept, mitigate, transfer/share, and avoid. Accept means carrying the exposure after judging it tolerable. Mitigate means adding controls to reduce likelihood or impact. Transfer or share means another party carries part of the consequence through insurance, contract, outsourcing, or another mechanism. Avoid means eliminating or redesigning the activity that creates the risk. Leaving a material risk without a chosen response keeps the exposure open without a decision record.

What happens to a risk if you never choose a treatment?+

The organization continues to carry the exposure without a formal acceptance decision. Deliberate acceptance has a rationale and an owner on record. An untreated risk has neither, so it should remain visibly open until an accountable person chooses and records a response.

Why record a treatment decision if it may change?+

The record shows the rationale, owner, residual risk, and review date. That lets a board, auditor, or successor understand the decision and reopen it when the exposure or available controls change. Without a decision record, the organization continues carrying the risk without showing who considered it or why.

Sources

Share

See Sorena do the work

Book a demo and watch one real compliance workflow go from question to audit-ready output.