Risk Sign-off
Some designs should be approvable even though the automated checks say "not clean": a control fails for a reason the business accepts, an architect overrode the model for cause, or the design review raised a blocker that is a known trade-off. Risk sign-off is the governed way through: a named authority accepts the residual risk, on the record, before approval can happen.
When It Is Required
The readiness board requires sign-off whenever the design carries judgment the checks did not endorse:
- Failing controls: the design is approvable only with the risk formally accepted.
- Architect overrides: a manually edited design carries human decisions the automated evaluation did not choose.
- A blocked design review: the reviewers found something that must not pass silently.
A clean, unmodified, unblocked design needs no sign-off at all.
Who Signs
Sign-off is performed on the Assurance tab by someone holding the accept-risk authority, with separation of duties enforced: the person accepting the risk cannot be the person whose work created it. The sign-off records who accepted, when, and against which design version.
What It Covers, and When It Resets
A sign-off covers the specific design version it was given for. If the design materially changes afterward (a re-run, an edit) the acceptance no longer applies and the readiness board asks again; risk acceptance never silently extends to work the authority never saw.
Sign-off Is Acceptance, Not Absolution
Signing off does not fix anything: the failing control stays failing and visible, and drift detection keeps watching it after approval. What changes is accountability: the risk is now carried knowingly, by a named person, on a dated record.