<!-- Generated from acceptable.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — Accepted is not acceptable

Accepted is an act: somebody with standing says they carry the risk. Acceptable is a threshold: the point where the business stops funding remediation. They are orthogonal, not sequential — which gives four real states, each needing a different action. And the EU AI Act mandates the judgement without defining the word.

Source: https://riskmandate.ai/acceptable.html

---

# Accepted is not acceptable.

Two words the business world uses interchangeably that mean entirely different things. One is an act somebody performs. The other is a line the business draws. Getting them confused is why risk registers fill up with items nobody can close — and why "what is our risk appetite?" never gets a usable answer.

## One is an act. One is a line.

Somebody with the standing to do it says: **I carry this.**

It attaches to a named role, it carries a date, and it runs for an interval. It is not optional, because the risk exists as a fact whether or not anyone has signed for it. The only variable is how long.

The level at which the business is happy to **stop funding remediation.**

It is a property of the business, not of the risk. It describes a level rather than an event, and it is what determines whether any more work is warranted.

## They are orthogonal, not sequential.

The common error is to treat these as two points on one line — work the risk down until it becomes acceptable, then accept it. They are independent properties. All four combinations are real, they occur constantly, and each one needs a different action. Select a cell.

## Acceptable is risk appetite, under a more useful name.

"What is our risk appetite?" is a question most organisations answer with an adjective. Naming the same thing _acceptable_ makes it operational, because a stated acceptable level is not a sentiment — it is the instruction that stops work.

As appetite

“We have a low appetite for operational risk.”

Cannot be acted on. Nobody knows what it forbids, and no piece of work stops because of it.

As an acceptable level

“Below this, we stop funding remediation.”

Can be acted on today. It tells a team when to stop, which is the only instruction that actually frees budget.

## The Act mandates the judgement — not the word.

The obligation reaches the same place independently, and leaves the hardest part to you.

EU AI Act, Article 9(5)

Residual risk must be **judged acceptable**. Elsewhere the instrument requires testing against thresholds **defined in advance**.

And "acceptable" is not defined anywhere in the instrument's own definitions. The obligation is imposed; the standard is not supplied.

You must decide your line. You must show you decided.

Not having defined it is itself a first-class risk — an organisation that has never set an acceptable level cannot know whether it is finished, or whether to keep spending. It is carrying a risk about its own risk management.

The stated line, versus where remediation actually stopped.

The gap between the two is the finding. It needs no tooling to answer — you can work it out from last year's decisions — and it is almost never answered.

Legal points here are factual and are not legal advice. A maturity rating never implies presumption of conformity with any instrument.

## There is no deny and no wait. Only how long.

Ask someone to accept a risk and they will do neither — treat acceptance as a choice and you have handed them a third door: do nothing. The risk is already on the books, so the only real decision is the duration. And the duration you pick commits you to a response, which is what makes it the severity decision rather than a form field.

### Anything under a week is an incident

The rung simply names which grade. If you picked a short interval, you have already declared an incident — the only question left is whether the organisation is behaving like it.

### Distance to the line sets the clock

The further above the acceptable line a risk sits, the sooner it should return to the desk: roughly a month far above, three months mid, six months at or near the line.

### An unaccepted risk is critical

A risk nobody has accepted is critical for whoever holds it, until something above has accepted it — because right now that person is personally accountable. It belongs on their dashboard today.

### An interval you cannot honour is a finding

If the interval implies "pull the plug" and the capability to pull it does not exist, that is a finding — not a scheduling problem. It is where this page meets [the plug profile](plug.html).

## Accept first. Then adjust the level.

For a risk you already have evidence for, the first step is not to mitigate it — it is to get it accepted as it stands, at its current level, on the record. An owned risk is a funded risk. An unowned one festers through exactly the period when nobody is accountable.

The level is a ledger, not a number

A dated series of owned adjustments, each of them re-accepted. Exactly three things move it:

The board sees a living trajectory — the accepted level, its adjustments, the projects driving it down, and the names against each — rather than a static red square.

The worked example is agents themselves

- **Accept it now.** An unknown, largely over-permissioned agent population holds access to enterprise assets, at a high and uncertain level — owned by named executives. You cannot mitigate what you cannot count.
- **Fund discovery.** Unknown becomes a number, and the level is re-rated — usually _upward_ at first, as the true extent appears.
- **Fund scoping and revocation.** The agents' reach shrinks, and the level is re-rated down.
- **Any incident calibrates it** — and sends the team hunting for what else was missed.

Accept-first is not doing nothing. It is the opposite: it is what funds and directs everything that follows.

## Where do you stop funding remediation?

If that has an answer, we will show you where remediation actually stopped last year and whether the two agree. If it does not, that is the finding — and it is where we start.
