Communicating Risk Acceptance
Communicating risk acceptance covers what the Chief Audit Executive (CAE) must do when management decides to accept a risk instead of fixing it. Under the IIA Standards (formerly Standard 2600, now Standard 11.5 of the Global Internal Audit Standards), if the CAE concludes that management has accep… Communicating risk acceptance covers what the Chief Audit Executive (CAE) must do when management decides to accept a risk instead of fixing it. Under the IIA Standards (formerly Standard 2600, now Standard 11.5 of the Global Internal Audit Standards), if the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If the CAE still believes the issue has not been resolved, the CAE must communicate it to the board. This topic falls under Engagement Results and Monitoring because risk acceptance usually appears during monitoring and follow-up. For example, management may decline to implement agreed corrective actions, delay them indefinitely, or say the cost of remediation outweighs the benefit. Management may legitimately accept risk, since it owns risk and decides how to respond to it. Internal audit's role is to judge whether the accepted risk exceeds the organization's risk appetite or tolerance, conflicts with policy or regulation, or could seriously harm the organization's objectives or reputation. The process typically follows these steps: (1) identify the accepted risk through follow-up or engagement work; (2) understand management's rationale, any compensating controls, and the decision authority involved; (3) assess the residual risk against established risk appetite; (4) document the acceptance and the discussions; (5) discuss concerns with senior management; and (6) escalate unresolved matters to the board, which makes the final governance decision. Key exam points: internal audit does not resolve the risk or override management, because doing so would impair objectivity. The CAE's duty is to communicate and escalate. Communication should be timely, objective, and supported by evidence. The board, not internal audit, decides whether the accepted risk is appropriate. Documenting risk acceptance also protects the internal audit activity and supports accountability, transparency, and effective governance.
Communicating Risk Acceptance: A Complete Guide for the CIA Exam
Introduction
Communicating risk acceptance is one of the most sensitive responsibilities of the Chief Audit Executive (CAE). It covers what internal audit must do when management chooses not to act on a risk, or not to act enough, and that choice may leave the organization exposed beyond what it can tolerate. The topic sits under Engagement Results and Monitoring. Exam questions are usually scenario-based. They test whether you know who must act, when they must act, to whom the matter is escalated, and what internal audit must not do. The topic is examined mainly in CIA Part 2 under the current syllabus, but the same principles appear wherever engagement results and monitoring are tested.
1. What Is Communicating Risk Acceptance?
Management owns the organization's risks. It may legitimately decide to accept a risk instead of mitigating, transferring or avoiding it, for example when the cost of a control exceeds the benefit. Internal audit does not challenge every acceptance decision. The issue arises only when the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization. Under the Global Internal Audit Standards, this means a risk that exceeds the organization's risk appetite or risk tolerance.
The authoritative requirement
Former IPPF Standard 2600 – Communicating the Acceptance of Risks: When the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If the CAE determines that the matter has not been resolved, the CAE must communicate the matter to the board.
Global Internal Audit Standards (2024), Standard 11.5 – Communicating the Acceptance of Risks: The CAE must communicate unacceptable levels of risk. When the CAE concludes that management has accepted a level of risk that exceeds the organization's risk appetite or tolerance, the CAE must discuss the matter with senior management. If the matter is not resolved, the CAE must communicate it to the board. The Standard also makes clear that resolving the risk is not the CAE's responsibility.
Key terms
- Risk acceptance: A deliberate management decision to retain a risk without further action.
- Risk appetite: The amount and type of risk the organization is willing to pursue or retain in pursuit of its objectives.
- Risk tolerance: The acceptable variation around objectives, that is, the boundaries of acceptable risk-taking.
- Senior management: The executives responsible for running the organization and owning its risks.
- Board: The highest governing body, often acting through the audit committee, which oversees management.
2. Why Is It Important?
- Protects the organization: It keeps significant exposures from staying hidden at lower management levels.
- Supports governance: The board relies on internal audit for assurance. It cannot oversee risks it is unaware of.
- Reinforces independence and objectivity: The CAE's direct functional reporting line to the board exists so that uncomfortable matters can be raised without interference.
- Clarifies accountability: Management owns and decides on risk. Internal audit identifies, evaluates and communicates it. The board oversees.
- Closes the monitoring loop: Follow-up of engagement results often reveals that management has not implemented agreed actions. That inaction is itself a form of risk acceptance.
- Protects internal audit: Documented discussion and escalation show that the CAE met professional obligations if the risk later materializes.
3. How It Works: The Step-by-Step Process
Step 1 – Identify that a risk has been accepted.
Risk acceptance can surface in several ways:
- through an assurance or advisory engagement;
- during monitoring and follow-up, when management has not implemented agreed action plans;
- when management formally declines a recommendation;
- through other means, such as risk assessments, enterprise risk management (ERM) reports or management meetings.
Step 2 – Evaluate whether the accepted risk is unacceptable.
The CAE compares the residual risk with the organization's risk appetite and tolerance. Relevant factors include:
- the likelihood and impact of the risk;
- regulatory, legal and reputational implications;
- whether compensating controls exist;
- whether the person accepting the risk has the authority to do so.
Acceptance within appetite needs no escalation. The trigger is the CAE's professional judgment that the risk may exceed what the organization can tolerate.
Step 3 – Understand management's rationale.
Before escalating, the CAE should understand why management accepted the risk. Possible reasons include cost, resource constraints, timing or strategic priorities. Management may hold information the auditor lacks.
Step 4 – Discuss with senior management.
The first escalation is always to senior management, not directly to the board. The aim is to make sure senior management understands the exposure and has made an informed decision. Senior management may decide to:
- reverse the decision;
- implement mitigating actions;
- formally confirm the acceptance as within appetite.
Step 5 – Escalate to the board if unresolved.
If senior management does not resolve the matter and the CAE still believes the risk is unacceptable, the CAE must communicate it to the board, typically the audit committee. Communicating the matter is mandatory, not optional.
Step 6 – Document.
The CAE should record the following:
- the risk;
- the CAE's assessment;
- the discussions held;
- management's response;
- the escalation path followed;
- the board's response.
Some organizations require management to sign a formal risk acceptance form.
Step 7 – Continue monitoring.
The board makes the final oversight decision. The CAE may include the matter in future risk assessments and audit plans.
4. What the CAE Must NOT Do
- Resolve the risk personally: Implementing controls or forcing management's hand impairs objectivity. Management owns the risk.
- Accept the risk on management's behalf: The CAE has no authority to do so.
- Skip senior management: Going straight to the board is wrong unless senior management itself is implicated, for example in fraud or an integrity issue.
- Ignore the matter or drop it: Doing so just because management disagrees is a failure of professional duty.
- Report externally first: External reporting to regulators is governed by laws, regulations and the internal audit charter. It is not the default step under this Standard.
5. Illustrative Scenario
A follow-up review finds that IT management has decided not to patch a critical vulnerability in a customer database, citing cost. The organization's risk appetite states zero tolerance for customer data breaches.
- The CAE judges that the accepted risk exceeds appetite.
- The CAE first discusses the matter with the CIO and the CEO (senior management).
- The CEO supports the CIO and no action follows.
- The CAE must now report the matter to the audit committee.
- The CAE does not patch the system or order IT to do so.
6. Relationship to Other Standards and Concepts
- Monitoring progress and follow-up (former Standard 2500; GIAS 15.2, Confirming the Implementation of Recommendations or Action Plans): Unimplemented actions often trigger risk acceptance communication.
- Communicating results (former 2400 series; GIAS 15.1): Final reports should note management's response, including any refusal to act.
- Board interaction (former 2060; GIAS Domain III): The CAE's direct access to the board makes escalation possible.
- Three Lines Model: Management (first and second lines) owns risk. Internal audit (third line) provides independent assurance. The governing body oversees.
7. Exam Tips: Answering Questions on Communicating Risk Acceptance
Tip 1 – Memorize the sequence.
CAE concludes the risk is unacceptable, then discusses with senior management, then, if unresolved, communicates to the board. Any answer that reverses or skips this order is usually wrong.
Tip 2 – Look for the trigger words.
Phrases such as may be unacceptable to the organization, exceeds risk appetite or tolerance or management declined to implement signal this Standard.
Tip 3 – The CAE is responsible, not the staff auditor.
If an option says the engagement auditor should report directly to the board, be cautious. Escalation is the CAE's duty.
Tip 4 – Eliminate options where internal audit fixes the problem.
Answers such as implement the control, require management to comply or accept the risk on behalf of the organization violate objectivity and management's ownership of risk.
Tip 5 – Not every accepted risk is escalated.
If the scenario shows the risk is within appetite, or that management has the authority and has made an informed decision, the correct answer may be to document the acceptance and continue monitoring.
Tip 6 – Watch for the senior management exception.
If senior management is the source of the problem, for example by being involved in fraud, direct communication with the board is appropriate.
Tip 7 – External regulators are rarely the first answer.
Choose external reporting only if the question explicitly mentions legal or regulatory requirements or the charter.
Tip 8 – Use the word MUST.
The Standards say the CAE must discuss and must communicate. Options describing escalation as optional or merely recommended are likely incorrect.
Tip 9 – Pick the BEST next step.
Many questions ask what the CAE should do first or next. Locate where the scenario currently sits in the sequence and pick the immediate next step, not the final one.
Tip 10 – Link to follow-up.
When a question describes overdue or abandoned corrective actions, recognize that this may constitute risk acceptance requiring this process.
8. Practice Questions
Q1: During follow-up, the CAE learns that a department head has decided not to implement a control addressing a significant compliance risk. The CAE believes the risk exceeds the organization's tolerance. What should the CAE do first?
A. Report the matter to the audit committee
B. Discuss the matter with senior management
C. Implement the control to protect the organization
D. Close the finding since management accepted the risk
Answer: B. Senior management must be engaged before the board. C impairs objectivity, and D ignores the CAE's duty.
Q2: Senior management agrees with the department head and declines further action. The CAE still considers the risk unacceptable. What is the CAE's responsibility?
Answer: Communicate the matter to the board. The CAE is not required to resolve the risk.
Q3: Which statement is TRUE about communicating risk acceptance?
A. The CAE must ensure the risk is mitigated
B. The CAE may accept risks below a set threshold
C. The CAE must communicate unresolved, unacceptable risks to the board
D. Staff auditors report risk acceptance directly to regulators
Answer: C.
Summary
- Management owns risk and may accept it.
- When the CAE concludes that the accepted risk may be unacceptable, meaning it exceeds appetite or tolerance, the CAE must discuss it with senior management.
- If the matter remains unresolved, the CAE must communicate it to the board.
- The CAE escalates and documents but never resolves or accepts the risk.
Remembering the sequence Identify, Evaluate, Senior Management, Board, Document will help you answer most exam questions on this topic.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!