Back to blog
GRC Fundamentals

The four risk treatment options, and when each is the right answer

Mitigate, transfer, avoid, accept. Three of them are used properly; one is used as a synonym for doing nothing. How to choose, document and evidence each - including what insurance actually transfers.
GRC Copilot Team
The four risk treatment options, and when each is the right answer

Every identified risk gets one of four treatments. The mechanics are simple; the discipline is in documenting the decision and the residual risk that remains after it. Frameworks care less about which option you chose than whether an accountable person chose it knowingly.

1. Mitigate (modify)

Reduce likelihood or impact by implementing controls. The default for most risks, and the one that generates your control set.

  • Reduce likelihood: MFA, patching, segmentation, training.
  • Reduce impact: encryption, backups, segregation, incident response.

Document which controls address which risk. That linkage is what lets you demonstrate control effectiveness later - and it is why a risk register with no control references is hard to audit.

2. Transfer (share)

Move some of the consequence to another party - insurance, outsourcing, or contractual allocation.

The critical caveat: you transfer financial consequence, not accountability. Cyber insurance pays some costs; it does not make the breach not your responsibility, and regulators still hold you answerable. Outsourcing to a provider moves execution, not obligation - which is exactly why every framework has a third-party risk domain.

Transfer is the most over-claimed treatment. "We have insurance" and "the provider handles it" are frequently recorded as full transfer when they are partial at best. Record what is genuinely transferred and what remains with you.

3. Avoid (terminate)

Stop doing the activity that creates the risk. Do not collect the data, retire the legacy system, exit the market, decline the integration.

Underused, because it feels like defeat. It is often the cheapest and most complete option - particularly for data you hold with no clear purpose. Deleting data you do not need eliminates a whole class of risk permanently, and privacy law encourages it independently.

4. Accept (retain)

Take the risk knowingly, because treatment costs more than the exposure or no practical option exists.

Legitimate - and the most abused. Acceptance requires:

  • A named accepter with authority proportionate to the risk level.
  • An explicit, dated record - not silence.
  • A review date, so acceptance expires rather than becoming permanent.
  • Rationale, so a successor understands why.

Acceptance by default - a risk nobody treated and nobody formally accepted - is the state auditors flag, because it means the decision was never actually made.

Track treatment decisions to closure

GRC Copilot links each risk to its treatment, the controls that mitigate it, the residual score and who accepted it - with review dates that do not quietly lapse.

Choosing between them

  1. Can we stop doing this? If the activity has marginal value, avoidance is cleanest.
  2. Can we reduce it economically? If treatment cost is proportionate to exposure, mitigate.
  3. Can someone else carry the consequence better? Transfer - knowing accountability stays.
  4. Is residual exposure within appetite? Accept, formally and temporarily.

Combinations are normal. A single risk is commonly mitigated with controls, partially transferred through insurance, and the remainder accepted. Record all three parts rather than picking one label.

Residual risk is the point

Treatment does not eliminate risk; it moves it from inherent to residual. Your register should show both, and the residual score is what gets compared against appetite and formally accepted. A register showing only inherent risk cannot answer the question leadership actually asks: where are we exposed now?

What frameworks expect

ISO 27001 requires a risk treatment plan, risk owner approval of the plan, and acceptance of residual risks. The NCA ECC and SAMA CSF expect documented risk management with governance oversight. SOC 2 expects a risk assessment with evidence that risks were addressed. The common thread is documented decisions with named owners - not a particular methodology.

Frequently asked questions

Does insurance count as risk transfer?

Partially. It transfers defined financial consequences subject to policy conditions. It does not transfer regulatory accountability, customer trust, or operational disruption - and policies increasingly require specific controls to be in place.

Who should accept a risk?

Someone with authority proportionate to the exposure - a risk owner for low levels, an executive or board for anything outside appetite. Never the person who identified it, acting alone.

Can we accept a risk permanently?

Acceptance should always carry a review date. Environments change, and an acceptance that made sense two years ago may not now. Permanent acceptance is how exceptions become invisible.

What if we cannot afford to treat a high risk?

That is a legitimate acceptance decision - taken explicitly at the right level, documented, time-bound and reported. What is not acceptable is leaving it untreated and unrecorded.

Key takeaways

  • Mitigate, transfer, avoid, accept - and combinations are normal.
  • Transfer moves consequence, never accountability.
  • Avoidance is underused and often the cheapest complete answer.
  • Acceptance needs a named accepter, a date and an expiry.
#risk-treatment #mitigate #transfer #avoid #accept