Skip to main content
Reference — generated from the toolkit

Source of truth: toolkit/templates/risk-acceptance.md. Edit it there; this page is regenerated on build.

Risk-acceptance record — {short title}

  • ID: RA-{NNNN} Date: {YYYY-MM-DD}
  • Owner:Approver(s):

The risk accepted

What we are choosing not to fix, and why now.

Impact & likelihood

The exposure if it's realised (CVSS/EPSS/business exposure where relevant).

Compensating controls

What mitigates the risk in the meantime (monitoring, restrictions, manual checks).

Expiry

Hard date after which this acceptance lapses and the item re-enters the backlog / the gate re-blocks. No open-ended acceptances.

Sign-off

Named approver(s) with authority for this risk level (per the RACI). Logged in toolkit/registers/.