Skip to content

Risk Sign-off

Some designs should be approvable even though the automated checks say "not clean": a control fails for a reason the business accepts, an architect overrode the model for cause, or the design review raised a blocker that is a known trade-off. Risk sign-off is the governed way through: a named authority accepts the residual risk, on the record, before approval can happen.

When It Is Required

The readiness board requires sign-off whenever the design carries judgment the checks did not endorse:

  • Failing controls: the design is approvable only with the risk formally accepted.
  • Architect overrides: a manually edited design carries human decisions the automated evaluation did not choose.
  • A blocked design review: the reviewers found something that must not pass silently.

A clean, unmodified, unblocked design needs no sign-off at all.

Who Signs

Sign-off is performed on the Assurance tab by someone holding the accept-risk authority, with separation of duties enforced: the person accepting the risk cannot be the person whose work created it. The sign-off records who accepted, when, and against which design version.

What It Covers, and When It Resets

A sign-off covers the specific design version it was given for. If the design materially changes afterward (a re-run, an edit) the acceptance no longer applies and the readiness board asks again; risk acceptance never silently extends to work the authority never saw.

Sign-off Is Acceptance, Not Absolution

Signing off does not fix anything: the failing control stays failing and visible, and drift detection keeps watching it after approval. What changes is accountability: the risk is now carried knowingly, by a named person, on a dated record.