Acceptance is one of the four classic risk treatments — alongside mitigation, transfer, and avoidance — and the only one that changes nothing except accountability. That is why the signature matters: the person accepting must own the consequence, which usually means an executive or the system owner, not the engineer who found the issue. Frameworks agree on the shape; ISO 27001 expects risk-treatment decisions and residual-risk approval from management, and auditors ask to see both the decision and who made it.
Legitimate acceptances are everywhere in real programs: a legacy system scheduled for decommission next quarter, a low-severity finding on an internal tool, a vendor gap offset by a compensating control, a fix whose cost dwarfs the asset it protects. Vendor reviews produce them constantly — a supplier fails one requirement, the business needs the supplier anyway, and someone senior signs for the difference; that workflow is built into Agency’s vendor security review. What acceptance must never become is the drawer where hard findings go to be forgotten.
An acceptance without an end date is a permanent exemption nobody actually approved. Each entry needs a review date matched to the risk’s volatility, and the register needs a recurring owner who re-confirms, escalates, or closes every item as conditions change. Auditors read the register with real interest: stale acceptances signed by long-departed employees say more about a program than any polished policy PDF.