An organization's risk owner formally accepts a residual risk that exceeds the normal acceptance criteria, recording a justification and time-bound review. Under Clauses 8.3 and 6.1.3, is this acceptable during operation?
- A.No, residual risk above the criteria can never be accepted under any circumstance
- B.Yes, but only the auditor may accept residual risk
- C.No, because risk acceptance is prohibited once the ISMS is certified
- D.Yes, residual risk may be retained if formally accepted by the accountable risk owner, with the decision documented
Why D is correct
Clause 6.1.3 requires risk owners to approve the treatment plan and accept residual risks, and Clause 8.3 implements that plan. A documented, owner-approved acceptance of residual risk, ideally with review timing, is a legitimate operational outcome even when the residual exceeds the default acceptance criteria.
Know someone studying for ISO 27001? Send them this one.