Determining Whether a Risk Is Unacceptable
Determining whether a risk is unacceptable is a key judgment the Chief Audit Executive (CAE) makes during the engagement results and monitoring phase. Under IIA Standard 2600 (Global Internal Audit Standards Standard 11.5, Communicating the Acceptance of Risks), when the CAE concludes that manageme… Determining whether a risk is unacceptable is a key judgment the Chief Audit Executive (CAE) makes during the engagement results and monitoring phase. Under IIA Standard 2600 (Global Internal Audit Standards Standard 11.5, Communicating the Acceptance of Risks), when the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If the issue is not resolved, the CAE must communicate it to the board. The situation usually arises during follow-up. Internal audit monitors whether management has implemented agreed corrective actions. If management fails to act, delays indefinitely, or explicitly decides not to address a finding, management has effectively accepted the residual risk. The CAE must then judge whether that acceptance is appropriate. Key criteria include: 1. Risk appetite and tolerance: Does the residual risk exceed the limits approved by the board or set out in the risk management framework? 2. Impact and likelihood: Could the risk materially harm strategic, operational, financial, or compliance objectives? 3. Legal and regulatory exposure: Does accepting the risk create possible violations, fines, or sanctions? 4. Reputational and ethical consequences: Could stakeholder trust be damaged, or does the risk conflict with the organization's code of conduct? 5. Authority: Was the risk accepted by someone with the proper level of authority to do so? 6. Cost-benefit: Is the cost of mitigation clearly disproportionate to the risk, or is management simply avoiding the effort? 7. Aggregation: Do several individually minor risks combine into a significant exposure? The CAE should document the analysis, management's rationale, and the communications that follow. Internal audit's role is not to accept or resolve the risk itself, because doing so would impair its independence. Instead, it ensures that risk acceptance decisions are transparent and made by the appropriate level of governance. Escalation follows a clear path. The CAE first discusses the matter with the responsible manager, then with senior management, and finally with the board if necessary. This sequence reinforces internal audit's assurance role and supports sound governance.
Determining Whether a Risk Is Unacceptable: A CIA Exam Guide to Risk Acceptance and Escalation
Overview
Internal audit engagements often end with recommendations that management chooses not to fully implement. Sometimes that choice is reasonable. Sometimes it leaves the organization exposed beyond what it is willing to bear. The CIA exam tests whether you can tell the two apart and whether you know what the Chief Audit Executive (CAE) must do when the risk is unacceptable.
This topic sits under Engagement Results and Monitoring. Under the IIA's Global Internal Audit Standards, the relevant requirement is Standard 11.5, Communicating the Acceptance of Risks. Under the 2017 IPPF it was Standard 2600.
1. Why This Topic Is Important
Governance protection: The board relies on internal audit to confirm that management keeps risk within approved limits. If management quietly accepts excessive risk, the board's oversight is undermined.
Accountability: Management owns risk and decides how to respond to it. Internal audit must make sure those decisions are visible to the right people.
Independence and objectivity: The CAE must not accept risk on management's behalf. The CAE also must not stay silent to avoid conflict. The escalation process protects internal audit's integrity.
Preventing loss: Many corporate failures involved known weaknesses that management accepted and that never reached the board. This standard exists to stop that.
Exam weight: Questions on this topic appear regularly. They are usually scenario based and ask what the CAE should do next.
2. What It Is
Risk acceptance is a legitimate risk response. Management may decide to bear a risk rather than avoid, reduce or share it. A common reason is that the cost of a control exceeds its benefit.
A risk becomes unacceptable when the level management has accepted:
• exceeds the organization's risk appetite or risk tolerance as set by the board and senior management;
• breaches laws, regulations, contracts or organizational policies;
• threatens the achievement of strategic or operational objectives;
• creates significant exposure to reputation, safety, fraud, financial misstatement or going-concern risk.
The requirement can be summarized as follows. When the CAE concludes that management has accepted a level of risk that may be unacceptable to the organization, the CAE must discuss the matter with senior management. If the matter is not resolved, the CAE must communicate it to the board.
3. How It Works: The Process
Step 1: Identify the accepted risk.
Accepted risks can surface in several ways:
• management's response to engagement observations;
• the follow-up and monitoring process, for example when action plans are overdue or abandoned;
• a management statement that it will not act on a recommendation;
• risk assessments, consulting engagements or ongoing monitoring;
• changes in the risk environment that make a previously accepted risk more severe.
Step 2: Evaluate whether the risk is unacceptable.
The CAE uses professional judgment and considers the following:
• Risk appetite and tolerance: Is the residual risk within the limits approved by the board?
• Impact and likelihood: How severe would the consequences be? Consider financial, legal, reputational, safety and strategic effects.
• Compliance: Does accepting the risk violate laws, regulations or policies?
• Authority: Was the acceptance made by someone with the authority to accept that level of risk?
• Understanding: Does management fully understand the risk, or is the decision based on incomplete information?
• Cost-benefit: Is not implementing the control a reasoned business decision, or simply avoidance?
• Aggregation: Do several individually small accepted risks combine into a significant exposure?
• Organizational guidance: What do the risk management framework, ERM policies and prior board direction say?
Step 3: Discuss with senior management.
The CAE first raises the matter with senior management. This gives management the chance to:
• explain its rationale;
• provide information the auditor did not have;
• reconsider and implement mitigation;
• formally escalate the acceptance to the right level of authority.
Step 4: Escalate to the board if unresolved.
If senior management does not resolve the matter, the CAE must communicate it to the board or audit committee. The CAE presents the facts, the risk and management's position. The board then decides. Internal audit does not make the final decision.
Step 5: Document and monitor.
The CAE documents:
• the observation;
• the discussions held;
• the decisions reached;
• the communications made.
If the board accepts the risk, internal audit's obligation is generally fulfilled. The CAE may continue to monitor the risk and consider it in future risk-based planning.
4. Key Roles and Responsibilities
Management: owns the risk, decides on the response and is accountable for it.
CAE / internal audit: identifies, evaluates and communicates. It escalates when needed. It never accepts risk on management's behalf and never forces implementation.
Senior management: the first escalation point. It can resolve the issue or confirm the acceptance.
Board / audit committee: the final escalation point. It decides whether the risk is acceptable to the organization.
5. Illustrative Scenarios
Scenario A: A department manager declines to fix a minor control gap because the cost exceeds the potential loss, and the risk is within tolerance. This is an acceptable, reasoned decision. No escalation is needed. Document management's response.
Scenario B: The IT director refuses to patch a critical vulnerability exposing customer data. This breaches data-protection regulations and exceeds stated cyber risk tolerance. The CAE discusses it with senior management. If unresolved, the CAE reports to the audit committee.
Scenario C: Senior management agrees with the CAE but still chooses not to act. The matter remains unresolved. The CAE communicates it to the board.
6. Common Misconceptions
• 'Internal audit must make management implement all recommendations.' False. Management decides. Internal audit communicates and escalates.
• 'Any declined recommendation must go to the board.' False. Escalation applies only when the accepted risk may be unacceptable to the organization.
• 'The CAE should go straight to the board.' Generally false. Discussion with senior management comes first.
• 'The CAE should notify regulators or external auditors.' Not the standard response. Reporting outside the organization happens only where law, regulation or the internal audit charter specifically requires it.
• 'Risk acceptance is a failure.' False. Acceptance is a valid response when the risk is within appetite.
Exam Tips: Answering Questions on Determining Whether a Risk Is Unacceptable
1. Remember the escalation order. The sequence is: identify the risk, evaluate it, discuss with senior management, then report to the board if unresolved. Answers that skip senior management or bypass the board are usually wrong.
2. Use risk appetite as the benchmark. If a scenario mentions that the risk exceeds appetite or tolerance, or breaches law or policy, it points to an unacceptable risk. If the risk is within appetite and the cost-benefit reasoning is sound, acceptance is fine.
3. Eliminate answers where internal audit takes ownership. Rule out options in which the CAE does any of the following:
• implements the control;
• overrides management;
• accepts the risk;
• withholds the report until management complies.
These options impair objectivity or misplace accountability.
4. Eliminate do-nothing answers. Rule out options that ignore a significant risk or simply note it in the working papers. The same applies to options that wait until the next audit cycle. When a risk is unacceptable, the CAE must act.
5. Be wary of external reporting options. Rule out answers that send the issue to regulators, the media or external auditors as the first step. External reporting is correct only when the question mentions a legal or charter requirement.
6. Recognize the board as the final arbiter. Once the board is informed and decides, internal audit's responsibility is met. Do not choose answers in which the CAE keeps escalating beyond the board or refuses to accept the board's decision.
7. Watch the trigger words. Some words signal escalation: exceeds risk appetite, significant, regulatory violation, fraud, refused, unresolved and senior management disagrees. Other words suggest acceptance is fine: within tolerance, cost exceeds benefit, minor and compensating controls exist.
8. Link the topic to follow-up. Questions on monitoring often describe action plans that are overdue or abandoned. The key test is whether the outstanding risk is unacceptable. If it is, the escalation process applies.
9. Choose the most appropriate next step. When several options seem plausible, pick the one that best reflects the immediate next action in the sequence. That is usually discussion with senior management, unless the scenario says this has already happened.
10. Know the standard reference. Associate this topic with Communicating the Acceptance of Risks. That is Standard 11.5 under the Global Internal Audit Standards and Standard 2600 under the 2017 IPPF. Recognizing the concept helps you spot the intended answer quickly.
Summary
Determining whether a risk is unacceptable requires judgment. The CAE compares the accepted risk against the organization's risk appetite, tolerance, legal obligations and objectives. Management owns the decision to accept risk. The CAE's duty is to communicate it: first to senior management, then to the board if the matter is unresolved. For the exam, follow the escalation sequence, keep internal audit out of risk ownership, and treat the board as the final decision maker.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!