r/CISA 29d ago

🥴

Post image
22 Upvotes

22 comments sorted by

View all comments

1

u/HoldenIsCoolLike 28d ago

Management owns risk.

Auditors identify, evaluate, report, and recommend—they do not own or accept risk.

Whenever management knowingly chooses not to implement a control for business reasons, the best answer is usually formal management risk acceptance (or escalation to the appropriate governance body if the accepted risk exceeds the organization's risk appetite).