Reference — generated from the toolkit
Source of truth: toolkit/templates/risk-acceptance.md. Edit it there; this page is regenerated on build.
Risk-acceptance record — {short title}
- ID: RA-{NNNN} Date: {YYYY-MM-DD}
- Owner: … Approver(s): …
The risk accepted
What we are choosing not to fix, and why now.
Impact & likelihood
The exposure if it's realised (CVSS/EPSS/business exposure where relevant).
Compensating controls
What mitigates the risk in the meantime (monitoring, restrictions, manual checks).
Expiry
Hard date after which this acceptance lapses and the item re-enters the backlog / the gate re-blocks. No open-ended acceptances.
Sign-off
Named approver(s) with authority for this risk level (per the RACI). Logged in toolkit/registers/.