CORAA
Resources · Internal Audit Governance

Internal audit risk acceptance and escalation register.

Accepted risk should not be a polite way to close an uncomfortable observation. Internal audit needs a register that records who accepted the residual risk, what authority they had, what compensating controls exist, when the decision expires, and whether the Audit Committee must see it.

Open committee packOpen closure checklist
Downloads

Accepted-risk register template

Download the Excel/PDF pack for accepted-risk fields, authority tests, escalation triggers, status logic, red flags and future product workflow fields.

Register fields

What the register should capture capture

Observation / risk ID

Tie the accepted risk to the original observation, RCM test, monitoring exception or committee decision.

Residual risk statement

State the risk that remains after management action, not only the action that was delayed or rejected.

Why action is not being taken now

Record cost, system dependency, business constraint, alternate control or explicit management choice.

Acceptance authority

Name the person or forum authorised to accept the risk under the entity charter or governance matrix.

Compensating controls

Document temporary or alternate controls that reduce exposure while the main action remains open.

Expiry / review date

Accepted risk should not be indefinite. Set a review date and trigger for re-escalation.

Committee visibility

Flag whether the item must be reported to the Audit Committee, Board, risk committee or senior management.

Internal audit conclusion

Record whether internal audit accepts the basis, disagrees, escalates or reports limitation/accepted risk.

Acceptance tests

Before you accept the status valid

Authority test

Does the person accepting the risk actually have authority for the exposure, value, compliance impact and reporting consequence?

Informed decision test

Has management seen the condition, cause, impact, exposure, alternatives and consequence of not fixing the issue?

Compensating-control test

Are temporary controls defined, owned, operating and evidenced, or is this merely unmanaged risk?

Time-bound test

Is there an expiry date, review date or trigger event, or has the item been parked indefinitely?

Escalation test

Does the rating, repeat nature, fraud/compliance exposure or stakeholder impact require committee visibility?

Documentation test

Can the file defend the acceptance basis, authority, decision date, internal audit view and next review?

Escalation triggers

When risk acceptance is not enough escalate

High-rated issue remains open

Escalate when a high issue is delayed, disputed, accepted or repeatedly re-dated.

Repeat finding after closure

Escalate when the same root cause returns after management claimed closure.

Owner lacks authority

Escalate when a process owner accepts risk that belongs to CFO, CEO, Board, Audit Committee or legal/compliance.

Regulatory or fraud exposure

Escalate when accepted risk can cause statutory non-compliance, fraud pathway, data/privacy exposure or reporting misstatement.

No compensating control

Escalate when management accepts risk without interim control, monitoring or evidence.

Expired accepted risk

Escalate when review date passed and the exposure remains unresolved.

Status logic

Use status that preserves disagreement visible

Accepted with authority

Appropriate owner or forum accepted the residual risk with documented basis, expiry and compensating controls.

Accepted with conditions

Risk is accepted only if interim controls, monitoring, budget approval or a future system change is completed.

Not accepted by internal audit

Management accepts the risk, but internal audit disagrees with authority, basis, evidence or exposure treatment.

Escalated

Risk acceptance is routed to senior management, Audit Committee, Board or another governance forum.

Expired / review due

Previously accepted risk has reached review date and needs fresh decision, remediation or escalation.

Red flags

Weak accepted-risk files avoid

Risk acceptance is verbal

No one can prove who accepted what exposure, when, and with what authority.

Accepted by the control owner only

The person responsible for the weak control may not have authority to accept financial, compliance or fraud exposure.

No expiry date

Accepted risk becomes permanent because there is no review trigger.

No compensating control

Management has accepted exposure but not reduced or monitored it.

Internal audit silently closes it

Closure without reporting accepted risk can hide unresolved exposure from the committee.

Repeated deferrals renamed as accepted risk

The same overdue action is recycled without a new basis, authority or escalation.

Authority anchors

Risk acceptance depends on governance authority authority

ICAI Standards on Internal Audit

Use SIA 250 for communication with those charged with governance, SIA 360 for management communication, SIA 370 for reporting results and SIA 390 for monitoring/reporting prior audit issues.

IIA Global Internal Audit Standards

Use the IIA standards as a governance benchmark for communicating accepted risk, escalation, board communication and action-plan monitoring.

Entity charter and delegation matrix

The authority to accept risk should come from the committee charter, risk appetite statement, delegation matrix or Board-approved governance framework. The internal audit charter should define reporting and escalation rights, not transfer management risk ownership to internal audit.

Product reuse

Reusable product fields workflow

ArtifactModuleLikely fields
Accepted-risk registerGovernance workflowRisk ID, owner, authority, basis, residual exposure, expiry, committee flag, internal audit view.
Escalation engineObservation and ATR workflowRating, ageing, repeat flag, disputed issue, expired acceptance, escalation destination.
Compensating-control trackerMonitoring workflowTemporary control, owner, cadence, evidence source, exception count, review date.
Authority matrixInternal Audit settingsDecision type, approval level, committee route, risk appetite threshold, documentation requirement.
Dashboard metricAudit Committee reportingOpen accepted risks, expired accepted risks, high accepted risks, items not accepted by internal audit.
Related resources

Use this with closure and committee reporting next

Closure Evidence & Retesting Checklist

Do not close ATR items until evidence, retesting and acceptance status are defensible.

Audit Committee Reporting Pack

Escalate high accepted risk, expired items and unresolved disagreements.

Root Cause & Remediation Plan

Separate genuine accepted risk from weak or non-retestable action plans.

Internal Audit Dashboard KPIs

Track accepted risk counts, ageing, high issues and repeat findings in dashboards.

Three Lines Assurance Map

Confirm who owns risk and which assurance providers cover the exposure.

Internal Audit ATR Tracker

Route accepted risk and escalated items back into owner and due-date tracking.

FAQ

Common questions answers

What is risk acceptance in internal audit?

Risk acceptance is management or the appropriate governance body deciding to live with a residual risk instead of fully remediating it now. Internal audit should document the basis, authority, compensating controls, expiry date and reporting route.

Can internal audit accept risk on behalf of management?

No. Management owns risk acceptance. Internal audit can assess whether the basis is reasonable, document disagreement, escalate where needed and report accepted risk, but it should not accept or operate the risk itself.

When should accepted risk be reported to the Audit Committee?

Accepted risk should be reported when it is high-rated, repeated, overdue, expired, disputed, outside management authority or linked to financial reporting, compliance, fraud, data/privacy or significant operational exposure.

What should an accepted-risk register include?

The register should include risk ID, residual risk, management basis, acceptance authority, decision date, compensating controls, expiry/review date, internal audit view, committee flag and next action.