Skip to main content
Category: Risk Assessment and Treatment

Risk Acceptance Criteria

Also known as: RAC, Risk Acceptance Criterion, Risk Tolerance Criteria
Simply put

Risk acceptance criteria are the guidelines or thresholds an organization sets to decide when a given risk is low enough to be tolerated rather than eliminated, avoided, or reduced. When a risk falls within these limits, the organization can formally choose to accept it and take no further action. These criteria give decision-makers a consistent basis for judging which risks are acceptable.

Formal definition

Risk acceptance criteria are predefined thresholds or reference levels used as a basis for decisions about acceptable risk, expressing the overall risk level an organization considers tolerable for a specific activity or period. They provide a framework for evaluating assessed risks and determining whether to accept a risk versus applying other treatment options such as avoidance, mitigation, or transfer. In practice, these criteria are typically established during risk assessment and informed by an organization's risk tolerance, and the acceptance of a residual risk is a documented decision that varies depending on the organization's scope, context, and appetite.

Why it matters

Risk acceptance criteria give an organization a defensible, consistent basis for deciding which risks it will tolerate rather than treat. Without predefined thresholds, acceptance decisions tend to be made ad hoc and inconsistently, which undermines both internal governance and the evidence an auditor or certification body expects to see. Clear criteria allow decision-makers to distinguish risks that fall within tolerable limits from those that require avoidance, mitigation, or transfer, and they create a repeatable framework for evaluating assessed risks over time.

In the context of ISO/IEC 27001, risk acceptance criteria are closely tied to the risk assessment and treatment process that supports the information security management system. Under a SOC 2 examination, an organization's approach to identifying and responding to risk is relevant to how the auditor evaluates the design and operating effectiveness of controls, though the specifics depend on the scope and criteria selected for the engagement. In both cases, the value of the criteria lies in making acceptance a documented, deliberate decision rather than an implicit one.

It is important to recognize the limits of risk acceptance. Accepting a residual risk does not eliminate it; the underlying exposure remains, and the organization bears the consequences if it materializes. Because these decisions depend on an organization's scope, context, and appetite, criteria that are appropriate for one organization may not be suitable for another, and they typically require periodic review as circumstances change.

Who it's relevant to

GRC and Risk Management Professionals
Those responsible for the risk assessment and treatment process rely on risk acceptance criteria to make consistent, defensible decisions about which risks to accept versus treat. They typically define the thresholds, align them with the organization's risk tolerance, and ensure acceptance decisions are documented.
ISO 27001 Certification Candidates
Organizations pursuing or maintaining ISO/IEC 27001 certification use risk acceptance criteria as part of the ISMS risk assessment and treatment activities. Clear criteria support how assessed risks are evaluated and how residual risk acceptance is recorded, though the exact approach depends on the organization's defined scope and context.
Auditors and Certification Body Assessors
Assessors examine whether an organization has established and applied consistent criteria for accepting risk, and whether acceptance decisions are documented. In a SOC 2 examination, this feeds into the evaluation of how controls are designed and operate; the relevance depends on the scope and criteria selected for the engagement.
Executive and Business Decision-Makers
Leaders who own the organization's risk appetite ultimately set and approve the tolerable risk levels reflected in these criteria. They benefit from a consistent framework that clarifies when a risk is low enough to accept, while remaining accountable for the residual exposure that acceptance leaves in place.

Inside RAC

Risk Thresholds
Defined levels of risk, often expressed against a risk scale or matrix, that determine whether a given risk falls within the organization's tolerance or requires treatment. These thresholds are set by the organization and should be documented as part of the risk management process.
Evaluation Basis
The parameters against which risk is measured, typically some combination of likelihood and impact, used consistently to compare assessed risks to the acceptance criteria. The specific method depends on the organization's chosen risk assessment approach.
Alignment with Risk Assessment
The connection between the acceptance criteria and the broader risk assessment and risk treatment activities required by ISO/IEC 27001 clauses 4 through 10, ensuring that decisions to accept, treat, transfer, or avoid risk are made on a defined and repeatable basis.
Authority and Accountability
Identification of who holds the responsibility to accept residual risk. In most implementations this authority rests with management or a designated risk owner, so that acceptance decisions are traceable to an accountable party.
Documentation and Traceability
Records that show which risks were accepted, on what basis, and by whom. This documentation typically feeds into the Statement of Applicability and risk treatment outputs, supporting evidence during an ISO 27001 certification audit.

Common questions

Answers to the questions practitioners most commonly ask about RAC.

Does ISO 27001 define specific risk acceptance criteria that every organization must adopt?
No. ISO 27001 requires that an organization establish and maintain risk acceptance criteria as part of its risk assessment process, but it does not prescribe the specific thresholds or values. The criteria are defined by the organization itself, typically based on its risk appetite, context, and objectives. What is acceptable in one ISMS may be unacceptable in another, and certification bodies generally assess whether the criteria are documented and applied consistently rather than whether they match a fixed standard.
Are risk acceptance criteria a SOC 2 concept, or do they belong to ISO 27001?
Formal risk acceptance criteria are primarily an ISO 27001 concept, tied to the ISMS requirements in clauses 4 through 10 that govern risk assessment and treatment. SOC 2, as an attestation examination under the AICPA's SSAE 18 standard, evaluates controls against the Trust Services Criteria and does not mandate documented risk acceptance criteria in the same structured way. Some organizations undergoing a SOC 2 examination maintain risk-related documentation, but this is not the same defined requirement as under ISO 27001, and the two should not be conflated.
Who typically approves risk acceptance decisions within an ISMS?
In most ISMS implementations, risk acceptance decisions are approved by a designated risk owner or by management with appropriate authority, consistent with the organization's governance structure. ISO 27001 emphasizes that risk owners are identified and that acceptance is a documented, accountable decision. The specific role or committee that signs off varies by organization and is defined in the organization's own risk management process.
How do risk acceptance criteria relate to the Statement of Applicability?
Risk acceptance criteria inform the risk assessment and treatment process, which in turn feeds the Statement of Applicability (SoA). The SoA documents which Annex A reference controls are applicable and the justification for inclusion or exclusion. When a risk falls within acceptance criteria, the organization may decide not to apply certain controls, and this reasoning is typically reflected in the treatment decisions that support the SoA. The two documents are related but distinct: the criteria set the threshold, while the SoA records control selection.
How often should risk acceptance criteria be reviewed?
Review frequency is determined by the organization rather than fixed by the standard, though ISO 27001's requirements for monitoring, measurement, and management review generally drive periodic reassessment. In most implementations, criteria are revisited when the organization's context, risk appetite, or threat landscape changes, and at planned intervals aligned with the ISMS review cycle. The appropriate cadence depends on scope and organizational circumstances.
Can an accepted risk still result in an audit finding during certification?
Potentially yes, depending on how the acceptance was reached and documented. A certification body typically examines whether the risk acceptance was made against defined criteria, by an appropriate risk owner, and with adequate justification and documentation. If a risk is accepted outside the established criteria, without proper authority, or without supporting rationale, an auditor may raise a nonconformity. Acceptance itself is a legitimate treatment option, but the process behind it is what is assessed, and outcomes vary by auditor and scope.

Common misconceptions

Risk acceptance criteria are a SOC 2 concept defined by the Trust Services Criteria.
Formal risk acceptance criteria are most directly associated with the ISMS requirements in ISO/IEC 27001 clauses 4 through 10. While a SOC 2 examination may consider an organization's risk assessment activities, the SOC 2 report is an attestation performed by a licensed CPA firm against the Trust Services Criteria and does not prescribe risk acceptance criteria in the same structured way. The two frameworks should not be conflated.
Accepting a risk means the organization has eliminated or fully addressed it.
Risk acceptance is a treatment decision to tolerate a residual risk that falls within defined thresholds, not a control that removes the risk. Accepted risks typically remain subject to ongoing monitoring and periodic review, and acceptance does not guarantee the absence of an incident related to that risk.
There is a single mandatory, universal risk acceptance threshold that all organizations must use.
ISO/IEC 27001 requires that an organization define its own criteria, but it does not impose a fixed numeric threshold. In most implementations the specific thresholds and scales are set by the organization based on its context, scope, and risk appetite, so they vary between organizations and certification bodies may assess them for reasonableness rather than against a single prescribed value.

Best practices

Define and document risk acceptance criteria before conducting the risk assessment, so that assessed risks can be compared against a consistent and repeatable basis rather than judged case by case.
Ensure the criteria explicitly identify who has the authority to accept residual risk, and route acceptance decisions to that accountable management or risk owner role for traceable sign-off.
Align the criteria with the ISMS requirements in ISO/IEC 27001 clauses 4 through 10 and connect accepted risks to the Statement of Applicability and risk treatment outputs so that evidence is available during a certification audit.
Record each accepted risk together with its basis for acceptance and the approving party, maintaining documentation that supports traceability over time.
Review accepted risks periodically, since acceptance reflects a point-in-time decision that may need revisiting as context, scope, or the threat environment changes.
Avoid treating risk acceptance criteria as interchangeable across frameworks; where an organization pursues both SOC 2 and ISO 27001, note that mapping is partial and that satisfying one framework's expectations does not automatically satisfy the other's.