Risk acceptance spends organisational tolerance
Each accepted risk uses up some of the total the organisation can carry, and they are rarely counted together.
Individually every acceptance looked reasonable. Collectively they may exceed what anybody would have agreed to in one go. Aggregating them periodically is uncomfortable and it is the only way to know whether the sum of small sensible decisions has produced an unacceptable position.
More on Governance and risk
- 'compliance means secure'Certified, and propped open
- Risk is about uncertain impact, not merely bad thingsWhere it might land
- A risk register is a decision queue, not a museumNot a display case
- Control effectiveness is separate from control existenceTicked, and still empty
- Risk owners need authority over the consequenceThe name, not the lever
- Risk aggregation can reveal concentrationAll on one leg
