---
title: "Risk acceptance"
description: "A named, signed and expiring decision by someone with the authority a residual band requires, that a risk may remain for a bounded period under named compensating controls and a monitoring signal…"
canonical: https://aigovernanceengineer.com/glossary/risk-acceptance
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-24
---

# Risk acceptance

A named, signed and expiring decision by someone with the authority a residual band requires, that a risk may remain for a bounded period under named compensating controls and a monitoring signal that voids it [1]. Authority rises with the rating; a prohibited use cannot be accepted by anyone.

- Developed in: [ch. 13, Who may accept](https://aigovernanceengineer.com/bok/risk-management#who-may-accept); [ch. 12, Risk acceptance and exceptions](https://aigovernanceengineer.com/bok/governance-program#risk-acceptance-and-exceptions)
- Chapters: [ch. 12, Governance Program](https://aigovernanceengineer.com/bok/governance-program) · [ch. 13, Risk Management](https://aigovernanceengineer.com/bok/risk-management)
- Contrast with: [Exception register](https://aigovernanceengineer.com/glossary/exception-register)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-risk-acceptance

## Sources

[1] Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (risk tolerance and residual risk; seven trustworthy characteristics; transparency answers "what happened", explainability "how", interpretability "why"; MAP 1.1 intended purposes; MANAGE 1.1 go/no-go determination; profiles). NIST. 2023-01-26. https://doi.org/10.6028/NIST.AI.100-1 (verified: primary)
