Understanding the Risk Acceptance Criteria requirements for ISO 27001?
Risk acceptance criteria are the rules an organisation uses to decide whether an information security risk can remain at its current level or whether the business needs to take further action.
They form an important part of ISO/IEC 27001:2022 because risk management only works when people know how to distinguish an acceptable risk from one that needs treatment. Without clear criteria, two managers could assess very similar risks and make completely different decisions.
ISO guidance confirms that organisations need risk criteria that include criteria for accepting information security risk. Once an organisation has assessed a risk, it compares the result with those criteria to decide whether it needs treatment.
For a UK business, this process creates consistency and accountability. It helps management understand which risks can remain under observation, which need additional controls and which need urgent attention.
UK Cyber Compliance supports organisations with this work through its automated and AI-driven ISO 27001 platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. The platform helps organisations connect risk assessment, treatment, controls, policies, ownership, actions and evidence within a structured compliance process.
Why risk acceptance criteria matter
Every organisation accepts some level of risk.
Running a business without any risk would be impossible. Employees need access to systems, businesses rely on suppliers, organisations use cloud services and customers expect services to remain available.
Information security management therefore does not aim to remove every possible risk. It aims to understand risk, reduce unacceptable exposure and make informed decisions about what remains.
Risk acceptance criteria provide the rules for those decisions.
Imagine that an organisation identifies a risk involving temporary loss of an internal reporting system. Management may decide that the remaining exposure is low enough to accept.
Now consider a risk involving unauthorised access to a database containing sensitive customer information. The organisation may decide that this risk exceeds its acceptance threshold and requires stronger access controls, authentication, monitoring or another treatment.
Without agreed criteria, these decisions can depend too heavily on personal opinion.
ISO 27001 expects a consistent method
ISO/IEC 27001 requires organisations to establish an information security risk assessment process that produces consistent, valid and comparable results.
The organisation needs criteria for assessing risk and deciding when it can accept that risk. ISO committee guidance explains that organisations should establish risk acceptance criteria and compare assessed risk levels against them when deciding which risks require treatment.
This means the organisation should define its rules before individual managers start making decisions.
A simple risk method may examine likelihood and impact.
Likelihood considers how realistically an event could occur.
Impact considers the harm that the organisation could suffer if that event happened.
The organisation combines those assessments using its chosen methodology and then compares the result with its acceptance criteria.
ISO 27001 does not require one universal scoring formula. Organisations can create an approach that reflects their business, information, customers and security needs.
ISO/IEC 27005:2022 supports this approach by providing guidance for identifying, assessing, treating, communicating, monitoring and reviewing information security risk.
What is ISO 27001 Certification?
ISO 27001 certification provides independent assurance that an organisation operates an Information Security Management System that meets the requirements of ISO/IEC 27001.
ISO describes ISO/IEC 27001 as the world’s best-known standard for information security management systems. It provides requirements for establishing, implementing, maintaining and continually improving an ISMS.
An ISMS brings together business context, information security risk, leadership, objectives, controls, people, technology, suppliers, internal audit, management review and continual improvement.
Risk acceptance forms part of this wider system.
Certification does not mean that an organisation has removed every risk. That would not be realistic.
Instead, the organisation needs to demonstrate that it understands its information security risks, evaluates them consistently, treats unacceptable exposure and formally manages the risks it chooses to retain.
An auditor may therefore ask how management decides whether a risk is acceptable.
A clear and documented answer strengthens the ISMS considerably.
what is iso 27001
ISO 27001 is the commonly used name for ISO/IEC 27001:2022, the international requirements standard for information security management systems.
ISO states that organisations can use the standard to establish a risk management process adapted to their own objectives, processes and organisational structure.
The framework focuses on protecting confidentiality, integrity and availability.
Confidentiality means that information remains accessible only to authorised people and systems.
Integrity means that information remains accurate, complete and reliable.
Availability means authorised users can access information and services when they need them.
Risk acceptance criteria help the organisation decide how much remaining exposure to these areas it can tolerate.
A short outage affecting a low-priority internal service may fall within tolerance.
Unauthorised disclosure of sensitive customer information may not.
The business decides through an approved risk methodology rather than relying on guesswork.
Start with the organisation’s business context
Risk acceptance criteria should reflect the organisation rather than a generic template.
A professional consultancy, cloud software company, healthcare supplier and manufacturing business may all make different decisions because they face different consequences.
Start by considering what the organisation does.
Ask how dependent the business is on information and technology.
Consider which information customers trust you to protect.
Review important contracts.
Understand legal and regulatory responsibilities.
Identify services where downtime would cause serious harm.
Consider supplier dependencies.
Look at customer expectations.
A risk that one organisation considers manageable may be unacceptable to another because the potential impact differs.
ISO committee guidance specifically notes that organisations can develop acceptance criteria according to their business, interested party expectations and dependencies on information.
Risk appetite and acceptance criteria are connected
Risk appetite describes the broad amount of risk an organisation is willing to pursue or retain while achieving its objectives.
Risk acceptance criteria turn that broad position into practical rules.
For example, senior management might state that the organisation has a very low appetite for risks that could expose confidential customer information.
The acceptance criteria could then state that any residual risk involving significant unauthorised disclosure requires director approval and further treatment unless exceptional circumstances apply.
Another area may have more flexibility.
The organisation might tolerate short periods of disruption to a low-priority internal service because the business impact remains small.
Risk appetite provides direction.
Acceptance criteria provide the decision rules.
The two should support each other.
Define likelihood clearly
A useful risk methodology needs clear likelihood criteria.
Do not rely on labels such as low, medium and high without explaining what they mean.
Likelihood may consider factors such as previous incidents, current threat activity, exposure to the internet, known vulnerabilities, employee access, supplier dependency and existing security controls.
For example, an organisation might describe a lower likelihood as an event that remains possible but has strong controls and limited exposure.
A higher likelihood may describe a credible event with significant exposure, known weaknesses or repeated previous incidents.
The exact wording should suit the organisation.
Consistency matters more than unnecessary complexity.
Different risk owners should be able to apply the method and reach reasonably comparable results.
Measure impact through business consequences
Impact should reflect what the risk could do to the business.
Technical damage provides only part of the picture.
Consider customer harm, contractual commitments, personal information, business interruption, reputation, legal duties, employee productivity, operational disruption and management attention.
A system outage may have a very different impact depending on the service involved.
Loss of an internal convenience tool for an hour may create little harm.
Loss of a customer-facing service that supports contractual commitments may create serious consequences.
The organisation should describe these distinctions within its methodology so risk owners can make consistent decisions.
Create practical acceptance thresholds
Once likelihood and impact have clear definitions, the organisation can decide how different risk levels will receive treatment.
A straightforward approach might place risks into four broad levels.
A lower risk may remain acceptable under normal control ownership.
A moderate risk may require review and documented monitoring.
A high risk may require treatment and senior approval before the organisation retains any remaining exposure.
A severe risk may require immediate escalation and may remain unacceptable until management reduces it.
ISO 27001 does not prescribe these exact categories.
The organisation decides what works based on its context.
The important point is that staff understand what each result means and which decision follows.
Numerical scores are useful, but they do not replace judgement
Many organisations multiply likelihood by impact to create a risk score.
For example, a five-point likelihood measure combined with a five-point impact measure can create a range of results that management groups into acceptance thresholds.
This method can work well because it gives teams a common language.
However, the number should support judgement rather than replace it.
A low-likelihood event with catastrophic consequences may still require attention.
A risk may also require treatment because of a customer contract or legal duty even when the numerical score falls within the normal acceptance range.
The methodology should allow management to recognise these circumstances.
Include overriding rules
Good acceptance criteria should consider situations where a numerical threshold alone cannot decide the outcome.
For example, the organisation may decide that it will not knowingly accept a situation that breaches a legal requirement.
It may also decide that certain contractual commitments always require treatment when current controls cannot meet them.
Other overriding rules could apply to risks involving sensitive personal information, privileged administrator access, critical customer services or serious safety concerns.
These rules stop a simple score from producing an inappropriate management decision.
Give approval authority to the right people
Risk acceptance needs authority.
A junior employee should not normally accept a major risk that could affect the whole organisation.
Define who can approve each level of residual risk.
A lower risk might receive acceptance from a service owner.
A moderate risk may require approval from a department manager.
A higher risk might require a director.
A particularly serious risk may need executive or board consideration.
The exact structure should fit the organisation.
Using role names rather than individual employee names can make the process easier to maintain when personnel change.
Risk owners play a central role
ISO risk management places significant emphasis on risk ownership.
A risk owner needs enough understanding and authority to make informed decisions about treatment and acceptance.
Their responsibilities may include reviewing the risk scenario, confirming business impact, evaluating current controls, approving treatment activity and reviewing the remaining exposure.
Risk owners should also understand when the decision exceeds their authority.
For example, a service manager may identify a high residual risk but need director approval before the organisation accepts it.
ISO terminology defines risk acceptance as an informed decision to retain a particular risk and notes that accepted risks still require monitoring and review.
That final point matters.
Acceptance does not mean forgetting the risk.
Current risk and residual risk are not the same
A useful ISO 27001 risk process distinguishes between the exposure the organisation faces now and the exposure expected after treatment.
Suppose a business identifies a high risk of account compromise.
Current controls may include passwords and basic monitoring.
Management decides to add multi-factor authentication and stronger access review.
The current risk reflects the situation before those planned actions have fully taken effect.
Residual risk reflects the exposure that remains after the organisation implements and verifies the treatment.
Risk owners normally need to decide whether that remaining exposure meets the acceptance criteria.
Do not reduce the residual score simply because an action appears in a treatment plan.
The organisation should confirm that the control operates before claiming the resulting reduction.
Acceptance belongs at the end of an informed process
The organisation should avoid using acceptance as a shortcut.
A proper decision normally follows risk identification, analysis, evaluation and consideration of treatment options.
Management needs to understand what could happen, why it could happen, which controls already exist and what additional treatment would require.
Only then can the relevant owner make an informed decision.
ISO committee guidance describes risk treatment as the point where the organisation considers whether to accept, avoid or reduce a risk through suitable measures.
This makes acceptance part of risk management rather than an alternative to it.
Temporary risk acceptance can be useful
Sometimes an organisation cannot complete treatment immediately.
A supplier may need time to deliver a security feature.
A business may need to replace an older system during a planned project.
A technical change may require scheduled testing before deployment.
Temporary acceptance can help management control these situations.
The record should explain why immediate treatment cannot happen, which interim safeguards exist, who approved the decision and when the organisation will review it.
A target date prevents temporary acceptance from becoming permanent through neglect.
The organisation should escalate overdue decisions rather than continually extending them without review.
Document why the risk remains acceptable
A simple “accepted” label provides weak evidence.
Record the reasoning.
A strong record may explain that the likelihood remains low because several controls operate effectively and the potential business impact falls within the approved tolerance.
Another decision may explain that the organisation accepts the risk temporarily because replacement activity is already underway and interim safeguards reduce exposure.
The reasoning allows future managers and auditors to understand the decision.
It also helps the organisation reassess the risk when circumstances change.
Connect acceptance with the risk register
The risk register should provide enough information to show how the organisation reached each decision.
Useful records normally include the risk reference, scenario, owner, likelihood, impact, current rating, controls, treatment decision, planned actions, residual rating, acceptance decision, approver and review date.
A business does not need an unnecessarily complicated register.
It needs enough information to demonstrate clear reasoning and accountability.
The register should also remain current.
An accepted risk from two years ago may no longer reflect the organisation’s technology, customers or threat exposure.
Connect acceptance with the Statement of Applicability
Risk treatment and the Statement of Applicability, commonly called the SoA, should support each other.
When the organisation determines that it needs controls to reduce a risk, it compares its chosen controls against Annex A to make sure it has not overlooked relevant measures.
A risk involving compromised administrator accounts may lead to controls addressing access rights, authentication, logging and monitoring.
A supplier availability risk may involve supplier assurance, continuity and recovery measures.
The SoA should reflect those decisions.
If the risk register says a control remains necessary but the SoA marks it as irrelevant, the organisation should investigate the inconsistency.
Clear traceability makes the ISMS easier to manage and easier to audit.
Do not accept a risk because treatment feels inconvenient
Risk acceptance should reflect informed business judgement.
It should not become a way to avoid difficult work.
For example, an organisation discovers that unsupported software creates serious exposure.
Replacing the software may require effort.
That inconvenience does not automatically make the risk acceptable.
Management should compare the risk against its agreed criteria, consider contractual and legal requirements and assess available treatment.
A strong ISMS encourages transparent decisions.
If management decides to retain significant exposure, the organisation should record who approved that decision and why.
Use evidence when assessing whether a risk is acceptable
Evidence improves risk decisions.
Relevant information may include access reviews, vulnerability reports, incident history, security monitoring, supplier assurance, backup testing, audit findings and control testing.
Consider a risk involving cloud account compromise.
A manager may believe the risk is low.
Evidence showing multi-factor authentication coverage, limited administrator access and regular account reviews provides stronger support for that judgement.
Without evidence, the rating may rely too heavily on assumption.
ISO 27001 works best when decisions connect with real operational information.
Accepted risk still needs monitoring
Acceptance does not permanently close a risk.
ISO terminology explicitly notes that accepted risks remain subject to monitoring and review.
Set a review date.
Also define events that trigger an earlier review.
These may include a security incident, serious vulnerability, major customer requirement, supplier change, cloud migration, acquisition, new service or significant audit finding.
A risk that met the criteria six months ago may exceed them today.
Threats and business circumstances change.
The risk process needs to change with them.
Review criteria when the organisation changes
The acceptance criteria themselves also need periodic review.
A business may move into a regulated market.
It may begin handling more sensitive information.
A major customer may introduce stricter security requirements.
The organisation may become much more dependent on a particular cloud service.
Management may change its overall appetite for operational risk.
Each of these circumstances can affect what the organisation considers acceptable.
Reviewing the criteria keeps the risk methodology aligned with business reality.
Current UK cyber statistics support structured risk decisions
UK organisations continue to face regular cyber security threats.
The Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months, representing approximately 612,000 UK businesses.
Reported prevalence rose among larger organisations. The survey found that 65 per cent of medium businesses and 69 per cent of large businesses identified a breach or attack during the period.
Phishing remained the most common reported attack method and affected 38 per cent of businesses.
The survey also found that only 30 per cent of businesses carried out risk assessments covering cyber security during the period.
These figures reinforce why formal risk assessment and acceptance processes matter.
An organisation cannot prioritise effectively if it has no consistent method for deciding which exposure requires action.
Who needs iso 27001 certification
ISO 27001 certification can benefit organisations that handle important information or need to demonstrate systematic information security management.
Technology providers, software businesses, managed service providers, professional firms, manufacturers, healthcare suppliers, financial organisations, charities and public-sector suppliers may all gain value from the framework.
ISO explains that ISO/IEC 27001 can support organisations across sectors and allows them to adapt risk management according to their own structure and needs.
Customer requirements often drive certification.
A customer may want assurance that a supplier understands information security risk and makes consistent decisions.
Contracts, tenders and supply-chain assurance can also create demand.
Risk acceptance criteria strengthen that assurance because they demonstrate that management uses defined rules rather than informal judgement when deciding which security risks the organisation retains.
ISO 27001 Certification Levels
ISO 27001 does not use formal achievement bands such as bronze, silver or gold.
An organisation either achieves certification for its defined ISMS scope or it does not.
Businesses still move through practical readiness stages.
They define scope, understand interested parties, establish the risk method, identify risks, set acceptance criteria, treat unacceptable exposure, select controls, prepare the Statement of Applicability, gather evidence, complete internal audit and hold management review.
The ISMS can become more mature after certification through better monitoring, clearer evidence and stronger governance.
That improvement does not create another formal certification band.
Risk criteria may also evolve as the management system becomes more mature.
How the Certification Works
The organisation starts by understanding its context, interested parties and ISMS scope.
Management then establishes the information security risk assessment method, including criteria for evaluating risk and deciding whether the remaining exposure can be accepted.
The organisation identifies information security risk, analyses likelihood and consequences and compares the result against the agreed criteria.
Risks that exceed the acceptance threshold need treatment.
The organisation determines suitable controls, compares those controls with Annex A and records relevant decisions in the Statement of Applicability.
Control owners put the measures into operation and gather supporting evidence.
Risk owners then assess the remaining exposure and make or escalate acceptance decisions according to the organisation’s authority rules.
Internal audit checks whether the process works consistently.
Management review provides senior leaders with visibility of important risks, accepted exposure, overdue treatment and improvement needs.
An independent certification body then assesses whether the ISMS meets ISO/IEC 27001 requirements.
ISO describes conformity with ISO/IEC 27001 as having a system that manages risks relating to information security in line with the requirements of the standard.
What an auditor may ask about risk acceptance
An auditor may select a risk and follow the decision through the ISMS.
They might ask how the organisation determined likelihood.
They may ask why the impact received its rating.
The auditor could compare the result with the documented acceptance threshold.
They may examine the controls listed against the risk.
They may check whether planned treatment actually took place.
The auditor could also ask who accepted the residual exposure and whether that person had suitable authority.
Clear records make these questions straightforward.
A weak process forces employees to reconstruct decisions from memory.
Common mistakes with acceptance criteria
One common weakness involves setting thresholds without defining what the scores mean.
Another involves allowing every manager to accept risks regardless of their seriousness.
Some organisations reduce residual scores before implementing the planned controls.
Others accept risks indefinitely without setting review dates.
A further problem occurs when legal or contractual requirements receive no consideration.
The organisation may also create criteria that bear little relationship to its actual business risk.
Avoid copying another company’s methodology without adaptation.
Your criteria need to reflect your services, information, customers and responsibilities.
Management review should challenge accepted risks
Management review gives leaders an opportunity to examine significant accepted exposure.
Senior managers should understand which high risks remain open and why.
They can ask whether the controls remain effective, whether treatment has become practical and whether changes in the business have altered the original decision.
Management can also examine overdue temporary acceptance.
If the organisation repeatedly postpones important treatment, that pattern may indicate insufficient resources or weak governance.
Risk acceptance should remain visible at the level appropriate to the potential business impact.
Internal audit should test consistency
Internal audit can check whether employees follow the approved methodology.
An auditor might compare several risks with similar ratings and examine whether management treated them consistently.
They can review whether acceptance authority matched the documented rules.
They may also check whether residual risk ratings have evidence behind them.
This testing helps the organisation identify inconsistencies before the external certification audit.
It also provides useful feedback about whether the criteria remain practical.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can obtain ISO 27001 support from information security consultancies, compliance specialists, managed service providers, internal audit professionals and platform-led services.
UK Cyber Compliance supports ISO 27001 through an automated and AI-driven platform. Its current material includes guidance on risk assessment and risk acceptance criteria and describes a platform designed to streamline ISO 27001 compliance.
A capable provider should help the organisation understand its own risk rather than simply provide generic scores.
Support may include developing the methodology, defining likelihood and impact, establishing acceptance thresholds, assigning risk ownership, planning treatment and connecting decisions with Annex A controls.
The organisation should retain responsibility for the final decisions.
An adviser can guide management, but risk owners need to understand why they accept the remaining exposure.
How UK Cyber Compliance supports risk acceptance
Managing risk through separate spreadsheets can become difficult as an organisation adds owners, treatment actions, control mappings and evidence.
UK Cyber Compliance provides a central compliance environment that can help organisations keep these relationships visible.
The platform’s current material describes risk assessment functionality alongside automated compliance and AI-driven support for ISO 27001.
This central approach can help management see which risks exceed acceptance thresholds, which treatments remain outstanding and which risks need approval.
It can also support audit preparation by keeping the reasoning and evidence connected.
Technology does not make acceptance decisions on behalf of the organisation.
Management still defines the criteria.
Risk owners still assess the business consequences.
Authorised leaders still approve significant residual exposure.
The platform helps organise that process.
A practical approach to creating your criteria
Begin by agreeing what information security risk means within your organisation.
Define the likelihood scale clearly.
Define the impact scale using business consequences.
Create the method for combining those assessments.
Decide which results the organisation can normally tolerate.
Set clear escalation thresholds.
Define who can approve each level of residual risk.
Add overriding rules for important legal, contractual or customer requirements.
Define how temporary acceptance works.
Set review requirements.
Record how accepted risks will be monitored.
Test the methodology against several realistic scenarios before formally approving it.
If the process produces results that management considers unreasonable, refine the criteria before using them throughout the ISMS.
Make acceptance a business decision, not an administrative one
Risk acceptance criteria turn security assessment into a management process.
They tell employees when a risk needs more action and when the remaining exposure fits within the organisation’s approved tolerance.
They also create accountability.
Management knows who can accept risk.
Risk owners know when they need to escalate.
Control owners understand why particular safeguards matter.
Auditors can trace decisions from the original risk through treatment and residual acceptance.
Start with the business context.
Define likelihood and impact clearly.
Set meaningful thresholds.
Consider legal and contractual obligations.
Assign authority.
Treat risks that exceed the agreed criteria.
Assess the remaining exposure after controls operate.
Record the decision and review it when circumstances change.
UK Cyber Compliance helps organisations bring these activities together through an automated and AI-driven platform that connects risk assessment, controls, ownership, evidence and wider ISO 27001 activity.
Clear risk acceptance criteria do not remove uncertainty from business. They give the organisation a disciplined way to decide which uncertainty it can live with and which exposure needs further action.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

