Residual-Risk Acceptance Signoff¶
Decision record — instantiates Residual Harm Accounting and Allocation
A signed, authority-bound record that a specific residual harm is knowingly accepted rather than repaired — with the rationale, the accepting authority, and the trigger that reopens it.
A Residual-Risk Acceptance Signoff is a decision record for a conscious "we will carry this". Its defining feature is that it makes acceptance explicit, authorized, and reviewable: a named person with the authority to accept the harm signs a record stating what residual is being accepted, why, on whose behalf, and under what condition the decision must be revisited. It exists precisely because the alternative — silent abandonment, where a harm is simply not addressed and no one ever decided so — is worse and less accountable. It is not a rule about who qualifies and not a repair; it is the artifact that converts an implicit shrug into a signed, owned, time-bounded acceptance that an auditor can later find and challenge.
Example¶
An industrial plant carries a residual hazard: a legacy pressure line that, in a rare failure mode, could injure a maintenance worker. Full elimination would require rebuilding the unit at a cost the safety case judges grossly disproportionate to the tiny reduction in risk — the harm has been driven as low as reasonably practicable[1], and a sliver remains. Rather than let that sliver sit unaddressed, the plant produces a Residual-Risk Acceptance Signoff. It states the specific residual (the failure mode and its assessed likelihood and severity), the rationale (further reduction is grossly disproportionate), the accepting authority (the site director, who holds the standing to accept a harm on the operator's behalf and owns the consequences), and the review trigger (any change to the line, any near-miss, or an eighteen-month expiry — whichever comes first).
The signoff's value is entirely in its accountability: the residual is now owned by a named person, funded from that owner's budget for monitoring and any eventual response, and it carries an expiry so "accepted" cannot silently harden into "forgotten." What the signoff does not do is decide the criteria by which this hazard was deemed acceptable rather than mandatory-to-fix, or provide a route to compensate the worker if the failure occurs — it records the acceptance and names its owner, nothing more.
How it works¶
- State the specific residual. Record exactly which harm is being accepted, at what assessed likelihood and severity — not a vague "some risk remains."
- Give a rationale. Document why acceptance (rather than further reduction) is the reasoned choice, so the decision can be judged, not just asserted.
- Bind an accepting authority. Name a person with genuine standing to accept the harm on the bearer's behalf, and assign them the monitoring cost and consequences.
- Set a review trigger. Attach an expiry or a condition — a change, a near-miss, a date — that forces re-examination, so acceptance is never permanent by default.
- Lodge it where audit can find it. File the record in the register so accepted residuals remain visible and challengeable.
Tuning parameters¶
- Authority level — how senior the accepting signer must be, scaled to the harm's severity. Higher forces serious harms up to real accountability but slows routine ones.
- Rationale rigor — how much justification acceptance demands. Rigorous resists rubber-stamping but adds friction.
- Review trigger tightness — how short the expiry and how sensitive the reopening conditions. Tight prevents drift into permanence but churns re-reviews.
- Bearer consent — whether the party who carries the harm is consulted or merely informed. Consulted is more legitimate; informed is faster and often the reality.
- Scope of a single signoff — one hazard or a bundled class. Bundling is efficient but hides individual acceptances.
When it helps, and when it misleads¶
Its strength is accountability for the unavoidable: some residual harm genuinely should be accepted, and a signed, owned, expiring record is far safer than silence — it gives the acceptance a name, a reason, and a date, and makes it auditable. It is the honest way to say "we are choosing to carry this."
Its failure mode is normalization of deviance: a signoff renewed reflexively at each expiry lets a once-scrutinized acceptance quietly become permanent, and repeated acceptance can launder harm that should have been fixed — exactly the "residualizing preventable harm" the archetype forbids. It also risks accepting harm on behalf of a bearer who never agreed and may not even know. The guarding discipline is a hard expiry with substantive (not pro-forma) re-justification, an authority senior enough to feel the consequence, and — where feasible — the bearer's informed involvement rather than acceptance done over their head.
How it implements the components¶
residual_acceptance_record— it is this component: the explicit record of a knowingly accepted residual, with rationale and a review trigger, kept reviewable rather than silent.responsibility_and_funding_assignment— it binds the accepting authority who owns the accepted harm and funds its monitoring and any downstream consequence.
It does not implement residual_harm_boundary — deciding which harms are eligible to be accepted (versus mandatory to fix) is the general gate of Residual Harm Eligibility Rule, its nearest governance twin: the rule sets who qualifies, this record signs off one specific acceptance. Nor remediation_or_compensation_path, since a signoff explicitly declines to repair — the make-whole route, if any, is Claims and Compensation Fund.
Related¶
- Instantiates: Residual Harm Accounting and Allocation — supplies the authorized, reviewable record of consciously accepted residual harm.
- Consumes: Post-Incident Residual-Loss Assessment — the characterized residual whose acceptance is being signed off.
- Sibling mechanisms: Residual Harm Eligibility Rule · Post-Incident Residual-Loss Assessment · Claims and Compensation Fund · Loss and Damage Register · Harm-Bearer Agreement · Managed Retreat or Relocation Package · Restorative Remedy Plan · Adaptation Gap Report · After-Action Loss Feedback Review
Editorial Notes¶
Form Classification¶
Form family: Record, Log & Register
Rationale: Residual-Risk Acceptance Signoff operates as a persistent ledger, log, register, or case record that preserves history and traceability because it a signed, authority-bound record that a specific residual harm is knowingly accepted rather than repaired — with the rationale, the accepting authority, and the trigger that reopens it.
Independent corroboration: The frozen evidence defines Residual-Risk Acceptance Signoff as 'A signed, authority-bound record that a specific residual harm is knowingly accepted rather than repaired — with the rationale, the accepting authority, and the trigger that reopens it', so its operative form is Record, Log & Register.
Nearest alternative: Decision, Gate & Allocation — Residual-Risk Acceptance Signoff includes features of a case-specific gate, selection, routing, prioritization, or resource disposition, but its defining operation is a persistent ledger, log, register, or case record that preserves history and traceability.
Review outcome: Independent reviewer agreement; medium confidence.
Origin Attribution¶
Primary origin: Engineering & Design
Origin pattern: Convergent development
Present-day reach: Multi-domain
Rationale: Authority-bound acceptance of risk remaining after controls is canonical safety and systems engineering.
Related originating lineages:
- Law & Governance — Regulatory responsibility materially shapes formal acceptance and reopening conditions.
- Organizational & Management Science — Enterprise risk governance independently developed named risk-owner signoff.
Review resolution: Both blind reviewers agree that engineering_design is the primary historical origin. Explicit reconciliation of alternate origin disagreement, encyclopedia synthesis disagreement adopts reviewer_a's evidence: Authority-bound acceptance of risk remaining after controls is canonical safety and systems engineering. The selected record uses alternates=law_governance, organizational_management, origin_mode=convergent, and domain_reach=multi_domain; the other review proposed alternates=law_governance, systems_cybernetics, origin_mode=convergent, and domain_reach=multi_domain. The selected combination better preserves the mechanism-specific formative lineages and calibrated scope; broader present-day use is not treated as proof of additional historical origin.
Review outcome: Reconciled after independent review; high confidence.
References¶
[1] Health and Safety Executive. Reducing Risks, Protecting People: HSE's Decision-Making Process. HSE Books (2001). Explains that ALARP leaves residual risk when the cost of further reduction is judged grossly disproportionate. registry ↩