A risk that is deemed " unacceptable " to the organization is one where the residual risk (the remaining risk after controls are applied) exceeds the organization ' s risk tolerance level. This means that despite controls in place, the level of risk remains higher than what the organization is willing to accept. Identifying such risks is critical for ensuring appropriate management action to mitigate them further. References:
The IIA’s Practice Guide on Risk Management.
COSO’s Enterprise Risk Management – Integrating with Strategy and Performance.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit