Skip to content
atlas

Don't confuse these

Risk acceptance vs Risk avoidance

Why they differ

Acceptance keeps the activity and its risk; avoidance stops the activity so the risk disappears.

Risk acceptance

Risk management

A deliberate, recorded decision to live with a risk instead of spending more to reduce it.

Formal

The risk treatment option in which the organisation knowingly keeps a risk, because it is within the risk appetite or further controls would cost more than the harm; the decision is made and signed by someone with the authority to own the risk.

In plain English

Like driving on with a small chip at the edge of the windscreen - you note it, decide a new glass is not worth it yet, and look at it again after the winter.

In practice

At a ferry company, the IT manager writes down that the test server has no backup, the director signs that this is acceptable for one year, and the item is put on the list for review.

Why it matters

Accepting a risk is fine; ignoring it is not - the written decision shows who owns it and stops risks from being accepted without anyone deciding.

Risk avoidance

Risk management

Removing a risk entirely by not doing, or no longer doing, the activity that creates it.

Formal

The risk treatment option in which the organisation decides not to start, or to stop, the activity, system or data handling that gives rise to the risk, so the risk no longer exists.

In plain English

Like selling the trampoline because the children keep getting hurt - no more jumping, but also no more broken arms.

In practice

A fitness chain finds an old database of former members that nobody uses; rather than protect it, it deletes it - data it no longer holds cannot leak.

Why it matters

It is the only option that removes a risk completely, but it also gives up whatever value the activity had, so it suits risks that bring the business little gain.

Shared connections

Atlas is in beta.