Enterprise Risk Management

Moving the Deadline Is Not Risk Acceptance

A delayed fix and an approved risk are not the same thing. How CFOs and audit leaders can make the exposure, approval authority and next decision explicit.

By Kennedy Risk Group · Tue Sep 15 2026 · 9 min read

Moving the Deadline Is Not Risk Acceptance

Moving the deadline does not, by itself, approve the risk of waiting. When a material mitigation slips, management needs to decide whether the remaining exposure is tolerable, who has authority to accept it, and what would force another decision before the revised completion date.

That is different from asking whether the project manager has a credible recovery plan. The recovery plan explains how the work will finish. Risk acceptance explains why the business is willing to keep operating while it does not.

For a mid-market CFO or chief audit executive, the useful question is not simply, "Why is this late?" It is, "What are we agreeing to live with until it is fixed?"

Risk acceptance is a business choice, not a project status

Risk acceptance means choosing to retain an exposure rather than taking additional action to reduce that exposure. The University of Minnesota's ERM glossary makes this distinction between acceptance and mitigation. Existing safeguards can remain in place while management accepts the risk left over.

Acceptance can be sensible. A legacy system may be weeks from retirement. A workaround may provide enough protection for a limited period. An expensive permanent fix may offer little benefit before the underlying activity ends.

NIST SP 800-39, section 3.3, recognizes acceptance within risk tolerance and describes responses that change with time and circumstances. Its scope is information security. It does not prescribe a universal approval process for every enterprise risk.

The problem is not that a company accepts risk. The problem is that a deadline can move without anybody checking whether the assumptions supporting continued operation still hold.

An action marked "in progress" tells you something about effort. It tells you little about the exposure being carried today. Do not use the status of the future fix as evidence that today's risk is under control.

Before approving an extension, answer four questions

The following is KRG's recommended management check, not a new standard or a maturity score. Use it for material delayed mitigations and temporary exceptions. Keep routine, low-exposure scheduling changes proportionate.

A new date is not a risk decision. Four questions cover exposure, authority, safeguards and reopening. Approve the exposure, not just the extension.

01 Exposure: What are we living with?

Describe the consequence of waiting in operating terms. Name the affected product, process, commitment or financial objective. Separate controls operating now from improvements that exist only in the plan.

If you can support a financial range, include its assumptions and uncertainty. If you cannot, do not invent a dollar amount to make the approval look rigorous. A clear statement of the affected obligation and the conditions under which it could fail is more useful than unsupported precision.

02 Authority: Who can approve it?

The person responsible for delivering the fix does not automatically have authority to accept the consequences of delay. Use the company's delegation of authority and risk appetite and tolerance boundaries, not the seniority of whoever happens to attend the meeting.

Where the exposure crosses functions, identify the executive who can decide for the affected business as a whole. A purchasing manager should not silently commit Operations to a supply interruption or Finance to a cash requirement outside that manager's mandate.

03 Safeguards: What protects us until the fix?

Name the interim measure, its operator and the evidence that it is working. "Additional monitoring" is incomplete. Say what is checked, how often, who sees a breach and what action follows.

Also identify the limitation. An inventory check can warn that stock is falling. It does not manufacture replacement parts. Monitoring may buy decision time without materially reducing the underlying vulnerability.

04 Reopening: When must we decide again?

Give a temporary acceptance a defined end or review date and an earlier trigger for reassessment. A missed milestone, failed safeguard or changed operating condition may make the original decision obsolete before the calendar says it is due.

For temporary exceptions, KRG recommends no automatic renewal. A new approval should use current evidence and preserve the prior decision history. This is a governance recommendation, not a claim that every accepted risk must expire after a fixed number of days.

Together these questions make a practical distinction: approve the exposure, not just the extension. If the answers are missing, the revised date is a planning update, not a defensible acceptance record.

Keep the approval record small enough to use

Do not solve this by building a separate committee for overdue actions. Put the decision next to the existing risk and action records, with links to supporting evidence. The record should let a later reviewer understand the choice without interviewing everyone who attended the meeting.

Preserve both the original due date and the revised date. Otherwise repeated extensions can erase the history that would have prompted a different decision. Record why the work slipped, but spend more attention on what the delay changes than on defending the team's effort.

The table below is a working reference for the approval file. It expands the questions above into evidence to retain; it is not a requirement to create another form.

What to retain in the decision record

Record elementUseful evidence
Exposure and scopeAffected activity, current safeguards, consequence of waiting and material uncertainty.
Decision and rationaleWhat is being accepted, alternatives considered, reason for the chosen response and original versus revised action dates.
Approval authorityNamed decision-maker, approval date, delegation relied on and any required escalation.
Interim protectionControl operator, evidence of operation, known limitations and recipient of exception reports.
Reassessment and exitReview or expiry date, earlier reopening triggers, next action owner and evidence needed to end the exception.

A signature does not make an exposure tolerable. It establishes who made the choice. The substance still needs challenge, particularly when the approver is under pressure to protect a delivery date or avoid a budget request.

Do not treat internal acceptance as permission to disregard a binding obligation. Bring legal or compliance specialists into decisions involving mandatory requirements or contractual commitments. This article describes management governance, not a legal waiver process.

What the CAE should do when management keeps delaying

The IIA's Global Internal Audit Standards address this directly. Under Standard 15.2, where agreed implementation dates are not met, internal auditors obtain and document management's explanation and discuss it with the CAE. The CAE judges whether delay or inaction amounts to acceptance beyond risk tolerance.

Standard 11.5 requires the CAE to discuss accepted risk exceeding appetite or tolerance with senior management and escalate an unresolved concern to the board. Resolving the risk is not the CAE's responsibility. Its implementation guidance starts with discussion with the management responsible for the area. See printed pages 84 to 85 and 114 to 115.

This is not an automatic board escalation for every overdue task. The professional judgment concerns the risk, not lateness alone. The standards govern internal audit practice; the operating workflow proposed here is KRG's recommendation for management.

For leadership, the practical implication is to separate a request for more time from a request to carry more exposure. A familiar deadline problem may now need someone with different authority to make the decision. Establish that route through the existing risk governance structure, including how urgent concerns reach decision-makers between scheduled meetings.

Illustrative scenario: the inventory trigger arrives first

Consider a constructed manufacturer scenario, not a KRG client engagement. Qualification of a backup supplier is late. Management wants to keep buying from the current supplier while the qualification work finishes. The company's designated approver can authorize temporary acceptance only while stated operating conditions remain satisfied.

The fix can wait. The decision cannot. In this illustrative scenario, that means a temporary supplier-risk acceptance with a condition that can reopen it early, not permission to wait regardless of what happens.

Illustrative scenario: day 0 approves a 30-day supplier-risk acceptance with weekly inventory checks; day 12 reopens it when stock falls below the agreed floor; day 30 allows no automatic renewal. A trigger overrides the calendar.

1. Day 0: Approve. The designated executive approves a 30-day acceptance window, supported by weekly inventory checks. Operations owns those checks and the exception alert. The approval records an agreed inventory floor and the action required if stock falls below it. The supplier qualification action remains open.

2. Day 12: Reopen. Stock falls below the agreed floor. Operations escalates before the next review. The original approval no longer supports waiting without reassessment. Management considers the available response, which could include restricting new commitments or accelerating an alternative supply route. The right choice depends on actual options, not the date printed on the approval.

3. Day 30: No auto-renewal. Any temporary acceptance still in force reaches its decision point. Management must reassess, replace or end the temporary acceptance. If circumstances already forced a replacement decision on day 12, the record should show that history instead of pretending the original approval remained unchanged.

A trigger overrides the calendar. The example's days and controls are constructed to explain the method, not benchmarks for supplier risk or a prescribed review frequency. Set the real interval according to how quickly the exposure can change and how much time a response needs.

Notice what did not happen: the team did not wait for the qualification project to finish before revisiting the business decision. That is the difference between tracking an action and governing the risk during the delay.

Do not turn acceptance into a paperwork penalty

There is a legitimate counterargument: a company can spend more time renewing exceptions than managing the underlying exposure. If every minor reschedule needs an executive memo, the process will compete with the work it is meant to improve.

Use a short approval trail for material exceptions. Allow routine decisions within documented authority. Reserve deeper review for changed exposure, repeated extensions, weak safeguards or boundaries that the current approver cannot authorize. The issue is the significance of the choice, not how many boxes the form contains.

Some risks are deliberately retained for the long term. They need an accountable owner and a review cadence, not a permanent fiction that a fix is due next month. Distinguish that standing acceptance from a temporary bridge to a specific mitigation.

When a temporary fix is complete, verify the evidence before ending the exception. If a recommendation is closed because management accepted the exposure instead, label that outcome honestly. "Accepted" and "mitigated" should not become interchangeable simply because both remove an item from an overdue report.

Make the next review useful

At the next risk review, take one material action whose date has moved. Ask who approved the exposure, what protects the business while it waits, and what would reopen the decision. If the record cannot answer, you have a specific governance gap to address.

The Board-Ready Risk Reporting Scorecard offers a broader check on whether your risk process supports executive decisions. Start there if the same gap keeps appearing across the register.

Check Your Risk Reporting

Frequently Asked Questions

What is the difference between risk acceptance and a deadline extension?

An extension changes when work is due. Acceptance records the decision to retain a defined exposure. They may be approved together, but a revised date alone does not explain the risk, the approver's authority or the conditions of continued operation.

Who should approve temporary risk acceptance?

Use the organization's delegated authority, the size and scope of the exposure, and its tolerance boundaries. The action owner may recommend acceptance without being authorized to approve it. Cross-functional consequences may require an executive with a wider mandate.

How long should a risk acceptance last?

There is no universal duration. For temporary exceptions, KRG recommends a defined review or expiry date plus earlier triggers tied to changing exposure. Long-term retained risks need an owner and periodic review, not repeated fictional remediation deadlines.