During an engagement, situations may arise where executive management disagrees with an audit observation and chooses to accept the identified risk rather than implementing the auditor’s remediation recommendations. This can occur when management believes the cost to operate the recommended control exceeds the financial value of the underlying asset exposure.
                  ┌────────────────────────────────────────┐
                  │      MANAGEMENT ACCEPTS RISK GAP       │
                  └───────────────────┬────────────────────┘
                                      ▼
                  ┌────────────────────────────────────────┐
                  │      CAE EVALUATES ENTERPRISE RISK     │
                  │   • Fits within appetite? Close log.   │
                  │   • Exceeds appetite? Initiate Path.   │
                  └───────────────────┬────────────────────┘
                                      ▼
                  ┌────────────────────────────────────────┐
                  │     ESCALATE TO AUDIT COMMITTEE        │
                  │   • Independent board review panel     │
                  │   • Final governance veto boundary     │
                  └────────────────────────────────────────┘

When management chooses to accept a risk, the CAE must initiate a formal evaluation and escalation workflow:
  • Evaluate Against Corporate Appetite: The CAE assesses whether the accepted risk fits within the parameters defined in the organization’s corporate Risk Appetite Statement. If the risk is low and fits within appetite boundaries, the decision is logged in the risk platform and closed.
  • Escalation to Executive Risk Committees: If the accepted risk is high and threatens broader operational resilience, the CAE must document the exposure and escalate the issue to the Chief Risk Officer (CRO) and the Group Risk Committee to review the strategic implications.
  • Final Veto Boundary via the Audit Committee: If the executive leadership team continues to accept a risk that the CAE believes exceeds acceptable corporate thresholds, the CAE must present the issue directly to the independent Audit Committee. The Audit Committee reviews the finding, hears arguments from both executive management and the audit function, and issues a final, binding directive regarding whether management must remediate the vulnerability.