Risk acceptance is the formal choice to live with a risk rather than reduce, transfer or avoid it. In a risk register it records the risk, the reason for tolerating it, any compensating control, the owner who signed, and the date the decision will be reviewed.
Accepting a risk is legitimate and often necessary. Legacy systems, change freezes and operational constraints mean no organisation can fix everything immediately. The trouble is that each acceptance rests on assumptions about likelihood, and those assumptions age. An acceptance written when exploits took weeks to build is mis-scored once they take hours, even though nothing in the system has changed.
A sound acceptance has three features: an expiry date tied to how exposed the asset is, triggers that reopen it early (a public exploit, a KEV listing, a new attacker capability), and an owner senior enough to weigh downtime against breach. An acceptance without an expiry date is a deferral nobody is tracking.