risks.sgit.ai / acceptance

The founding inversion

Traditional risk management predicts the probability of a future event. This model asks a named human to underwrite an exposure that already exists. Four ideas follow from that single move, and between them they carry the rest of the model. This is the section to read first, and the one that needs no GRC background at all.

“because what we describe is reality, we are not describing the risk of something happening, we are asking them to accept it, to underwrite it. Maybe the analogy is insurance: you are underwriting the damage, the same way an underwriter underwrites the cost. The business executive is ultimately accountable for everything, so whatever they accept, they are underwriting the risk.”
— arch-brief, 18 June 2026

The four ideas, in order

C1

Acceptance is underwriting, not prediction

The founding inversion. It relocates the discipline from actuarial estimation to accountable ownership: the question stops being how likely is this? and becomes who carries it, and for how long? The consequence that matters most is second-order — once somebody must sign, they start demanding evidence, and that demand is what funds everything underneath.

First appearance 4 June 2026, deepened 18 June · maturity: well-developed
C2

There is no deny button

A risk with a real vulnerability under it exists whether or not anyone acknowledges it. You cannot vote a fact out of existence, so denial is incoherent — it only ever worked because the risk had not yet materialised. Removing the button converts risk management from a gate into a forcing function.

First appearance 23 June 2026 · maturity: well-developed · the most immediately graspable idea in the corpus
C3

The interval is the decision

If the only choice is how long, then the duration is not metadata about the decision — it is the whole of it. Choosing a rung sets severity and commits resources in the same click, because each rung implies a specific operational response, and the response has a price.

Intervals 23 June, consolidated as a ladder 17 July 2026 · the single cleanest artefact in the corpus
C4

Unaccepted is rated critical

The sharpest inversion of incentives in the whole model. In most organisations a risk nobody escalated feels safest to the person holding it. Here it is the worst state available: the risk has not gone away, it has come to rest on whoever is nearest, and it rolls upward without anyone choosing to escalate it.

First appearance 17 July 2026, worked end-to-end 2 August · maturity: well-developed

And then two more

Those four are the inversion. Two more pages complete the acceptance model:

Why this order

C1 gives you the reason anyone would engage at all. C2 removes the escape hatch that makes conventional registers decorative. C3 replaces the removed button with something that carries more information than the button ever did. C4 closes the loop by making silence expensive. Read in any other order the model reads as a set of opinions; read in this one, each step is forced by the one before it.

A named gap, carried honestly. Eight documents in the corpus cross-reference a canonical “risk acceptance redefined vs industry definition” brief dated 7 July 2026. That file does not exist in the repository, and neither do three others referenced alongside it. A single canonical statement of the redefinition is therefore a real gap in the source material, and these pages assemble it from the surrounding documents rather than pretending it was already written. The rest of the open questions →

For an agent

The acceptance model in five sentences. (1) A risk is not a prediction to be rated but an exposure that already exists, and acceptance is a named person underwriting it, insurance-style, with personal accountability attached. (2) Because the exposure is real, it cannot be denied: there is no deny button — the only decision available is how long you accept it before re-accepting. (3) The interval is the decision, on a six-rung ladder (1h · 4h · 1d · 1w · 1m · 6m, default one month), because each rung implies a specific operational response and therefore a specific cost. (4) A risk nobody has accepted is rated critical and rolls up to the next altitude automatically — not doing something is a measurable action. (5) Acceptance flows upward through an underwriting graph in which a recorded refusal counts as much as a recorded acceptance. None of this is implemented in code.