Risk acceptance and risk appetite
Risk acceptance is the deliberate, documented decision to bear a remaining risk, while risk appetite is the level of risk-taking set by top management, from which an ISMS derives its risk acceptance criteria.
Risk appetite, as defined in ISO 31000, is the amount and type of risk an organisation is willing to take in pursuit of its objectives. It is a statement by top management and therefore a strategic steering parameter, not a figure calculated by the IT department. Operational risk acceptance criteria are derived from it: concrete thresholds that determine when a risk may be carried without further action, when it must be treated, and when it triggers escalation. Risk acceptance is the individual application of that rule — the reasoned decision to bear an assessed risk at its remaining level. It is emphatically not the same as inaction or ignorance: only a risk that has first been identified, analysed and evaluated can be accepted.
ISO/IEC 27001:2022 makes both mandatory. Clause 6.1.2 a) requires the organisation to define and maintain criteria for accepting risks as well as criteria for performing risk assessments; clause 6.1.3 requires risk owners to approve the risk treatment plan and to explicitly accept the residual risks. The acceptance decision is therefore documented information and auditable in a certification audit. In practice the criteria are usually multi-dimensional: by risk class from the risk matrix, by the security objective affected (confidentiality, integrity, availability), by potential loss, and by approval level. A low risk may be accepted by a department head, a high one only by the executive board — and often only for a limited period and with a scheduled review.
As a steering parameter, risk appetite cuts both ways. Set too narrowly, it produces a flood of treatment measures, ties budget to immaterial risks, and pushes exceptions outside the formal process. Set too widely, the risk register degenerates into a filing cabinet for untreated findings. The NIS2 Directive raises the stakes further: Article 20 makes the management bodies of essential and important entities personally responsible for approving the cybersecurity risk-management measures and overseeing their implementation. Germany's transposing legislation was substantially delayed against the EU deadline of 17 October 2024. Blanket acceptance of high risks without justification, deadline and named owner is therefore neither compliant with the standard nor prudent from a liability perspective. Risk appetite belongs on the agenda of the management review and should be reconfirmed whenever the organisational context, the threat landscape or the business model changes materially.
Legal Basis
ISO/IEC 27001:2022 (clauses 6.1.2, 6.1.3, 8.2, 8.3, 9.3), ISO/IEC 27005, ISO 31000; Articles 20 and 21 of the NIS2 Directive (EU) 2022/2555; BSI Standard 200-3 (risk analysis)
Practical Example
The information security officer of a mid-sized automotive supplier agrees a three-tier acceptance rule with the executive board: risks rated "low" are accepted by default and merely tracked in the register, risks rated "medium" may be accepted by the responsible department head for no more than twelve months, and risks rated "high" or "very high" only by the board, in writing, with a named risk owner and a review date. When a legacy manufacturing execution system cannot be replaced in the short term, the board accepts the remaining risk for a fixed period of nine months, flanked by network segmentation and enhanced logging as compensating controls. The decision is recorded in the risk register with date, rationale and expiry, linked to the risk treatment plan, and revisited at the next management review. In the surveillance audit this gives him a complete trail showing that the acceptance was a conscious management decision rather than an overlooked finding.