Auditen
contrarian

The Risk Was Accepted. The Fine Was Still Issued.

You'll hear this a lot in compliance circles these days, mostly whispered among consultants like some kind of secret gospel, and the idea is that you can actually "manage" an unpatched vulnerability just by writing it down. Basically, if you get a formal sign-off accepting the risk, then what started as a technical failure becomes a governance success story; you aren't neglecting a patch. No. According to this logic, you are executing a mature risk deferral process.

I hate this idea.

Call your patching program "mature" while keeping a list of things you refuse to fix, and you're deceiving yourself. You aren't managing risk. You are simply prepping the paperwork for when they finally dig up your body.

Consider the French hospital fined half a million euros by CNIL this week. More than 727,000 records got exposed, and I'd bet my life that they had a process in place for those systems. They certainly had a spreadsheet explaining why specific legacy servers couldn't be touched without breaking some critical clinical tool. There was almost certainly a director who signed off on it, and someone who didn't grasp the technical danger but wanted to keep the lights on by "accepting" the risk.

Here is what actually happens on a Tuesday.

Auditors don't care about your risk acceptance form in a vacuum. I don't start with the sign-off when I sit across from you. I look at the vulnerability first. Then I ask what you actually did to lower the risk once you decided against patching.

If you tell me you signed a form, you didn't implement a control. You documented a gap. That form isn't a shield, and it's a map for the regulator. It shows them where the body is buried and gives them a signed confession that you knew the hole existed.

Conventional wisdom says documenting these deferrals makes the auditor happy. Maybe it does for some checkbox-ticker who wants to see governance in action; it won't satisfy someone looking for evidence of effectiveness.

Why would I see a mature program if you show me ten critical vulnerabilities and ten corresponding forms? I see ten ways for an attacker to get into your environment; compensating controls are the only thing that matter. Did you put the machine on its own VLAN? Did you restrict firewall rules to two specific IPs? If you can't prove those technical changes on a Tuesday afternoon, your risk acceptance is just gambling with a fancy name.

Some people object by pointing to NIST or ISO frameworks that allow for risk acceptance. Consultants will tell you that you're compliant as long as the business owner signs off and the process is followed.

Compliance is not security.

Regulators don't hand out fines because you missed some paperwork. They fine you because data leaked. When CNIL looked at that French hospital, they didn't care if the deferral process was mature. They cared that nearly three-quarters of a million records were exposed, and to a regulator, signing a risk acceptance for a known critical vulnerability isn't good governance. It's proof of willful negligence.

This leaves auditors in a bad spot, and an audit firm signs off on a mature control environment based on these paper trails and suddenly their reputation is tied to those signatures. Look at the 422,000 account IDs leaked from Weverse in South Korea. When that happens, people ask who audited it and why they said it was fine.

The firm then has to explain why a folder of waivers counts as evidence of a working control. It's a cycle where the auditor becomes a liability for the client and the client becomes one for the auditor; everyone is just pretending that paperwork equals protection.

Does this delusion happen elsewhere? Sure. Firms often think process protects them from legal reality. ISS is fighting the SEC over subpoenas right now. Some corporate mindsets believe that if they have a consistent internal policy for refusing documents, that policy is a legal defense. It isn't. A policy isn't a law. Refusing a subpoena because your internal governance says so isn't a strategy. It's an invitation for an enforcement action.

If you want to know if your risk acceptance process actually works, stop looking at the signatures and start looking at the network traffic.

Ask your team what technical wall they built around a server they didn't patch; if they can't show you that wall in the console, toss the sign-off form in the trash. It isn't evidence. It's a liability.

I'll change my mind once a regulator lowers a fine because some company kept a neat folder of reasons for why they didn't fix things. Until then, a signed waiver is just a confession you paid a consultant to write.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Why the SEC Should Repeal Its Climate Disclosure Rule - The National Interest Compliance Week (Google News)
  2. CNIL Fines French Hospital €500K, 727K Records Hit [2026] - tech-insider.org Data Privacy (Google News)
  3. SEC Moves to Nix Rule on Investment Adviser, Political Donations - bloomberg.com Compliance Week (Google News)
  4. ISS Faces SEC Enforcement Action Over Document Refusal - coinfomania.com Compliance Week (Google News)
  5. Thailand’s SEC finalizes crypto Travel Rule, effective February 2027 - Bitget Compliance Week (Google News)
  6. Deferred, Not Ignored: Explaining Unpatched Vulnerabilities to Your Auditor - corporatecomplianceinsights.com InfoSec Compliance (Google News)
  7. Nixxy Receives Nasdaq Notice on Minimum Bid Compliance - The Globe and Mail Compliance Week (Google News)
  8. K-pop fan platform Weverse reports data breach of 422,000 account IDs in South Korea - mlex.com Data Privacy (Google News)

How stories are selected and assessed