ISO 27005:2022
Context establishment – ISO 27005:2022

ISO 27005:2022 6.4.2: Risk acceptance criteria

Acceptance criteria decide in evaluation whether a risk is acceptable and in treatment whether a proposed treatment is enough or more is needed, and the organisation defines levels of acceptance. In building them it considers: alignment with its general risk acceptance criteria; which management level holds delegated authority to accept; that there can be several thresholds with acceptance authority at different levels; that criteria can rest on likelihood and consequence alone or also weigh the cost of controls against prospective loss; that different classes of risk can have different criteria (risks of legal non-compliance may not be retainable, while contractually required acceptance may be allowed); that criteria can allow future treatment, retaining a risk above threshold for a short time when there is approved commitment to controls within a set period; that criteria derive from risk appetite; and that they can be absolute or conditional. Influencing factors, not exhaustive, are organisational objectives and opportunities, legal and regulatory aspects, operations, technological and financial constraints, processes, supplier relationships and human factors such as privacy. A yes or no test is often not enough: thresholds may be needed for extreme consequences whatever their likelihood, or very high likelihoods whatever the consequence, so criteria ideally consider likelihood and consequence separately and management cost, not only the combined level. A keener appetite means a higher threshold and guards against over-control; criteria can vary with how long a risk will exist; they are reviewed and updated as context changes; and authorised management approves them.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 1 control

  • 7.3 Establishing auditor evaluation criteria

ISO/IEC 38500:2024 · 1 control

  • 5.10 Risk governance

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Context establishment – ISO 27005:2022

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.