4 Myths About Risk Acceptance That Operations Leaders Still Believe
Risk acceptance is not a permission slip for unresolved exposure. These four myths show why decision authority, evidence, and temporary controls must remain visible after a risk is accepted.

Key takeaways
- 01Risk acceptance is a bounded management decision, not proof that the hazard is controlled.
- 02The person who accepts risk needs authority, evidence, an expiry condition, and a clear review cadence.
- 03A temporary control becomes dangerous when its owner, replacement date, and failure trigger are unclear.
- 04Operations leaders should separate residual risk, risk appetite, and production pressure before approving continued work.
- 05Andreza Araujo’s work across 250+ cultural transformation projects supports a practical test: every acceptance decision should change what leaders verify in the field.
A production leader signs a risk acceptance form because a replacement part will arrive next week. The work continues, the document enters a folder, and the temporary arrangement becomes normal. Three months later, the original decision is still being treated as evidence that the exposure was reviewed, even though nobody can explain who owns the remaining risk or what condition should stop the job.
Risk acceptance is useful only when it keeps a difficult decision visible. It should identify the remaining exposure, the controls that make continued work defensible, the person with authority to approve the condition, and the evidence that will reopen the decision. When those elements disappear, acceptance becomes administrative cover rather than risk management.
Across 25+ years in executive EHS roles, Andreza Araujo has treated the quality of a safety system as visible in the decisions that follow field evidence. The same principle applies here. A signed form has little value if it does not change supervision, funding, maintenance priority, or the conditions under which work may continue.
Why risk acceptance is often misunderstood
Organizations need a way to make decisions when a hazard cannot be removed immediately. A failed component, a weather disruption, a critical maintenance window, or a temporary change in process can create a gap between the desired control and the control that is available today. Refusing to name that gap does not make the exposure safer.
The problem begins when the organization confuses a decision with a result. Acceptance does not reduce the hazard by itself. It establishes who has decided to proceed, under which conditions, for how long, and with what obligation to reduce the exposure. ISO 45001:2018 reinforces the need to control changes and operational risks, but the standard cannot supply the decision authority that the organization has failed to define.
James Reason’s work on latent failures helps explain why weak acceptance systems persist. The visible event is often a signature or an overdue action, while the deeper failure sits in authority, planning, design, staffing, or verification. The four myths below are common because each one turns a complicated management choice into a comforting shortcut.
Myth 1: A signed form means the risk is controlled
A signature proves that someone completed a step. It does not prove that the person understood the exposure, had the authority to approve it, or verified that the temporary controls were present where the work occurred.
This distinction matters when the accepted condition involves a critical control. A leader may approve work with a temporary barrier, reduced operating speed, additional supervision, or a restricted access route. Each measure can be reasonable, but only if the field arrangement matches the written condition and somebody checks that it remains intact.
The trap is especially strong when the document contains technical language that sounds precise. A risk score, a consequence label, and a due date can create the appearance of rigor while leaving the actual decision unanswered. What task may continue? What must not happen? Which control is non-negotiable? Who can stop the work when the condition changes?
Leaders should review a sample of accepted risks in the field and compare the record with the work as performed. If the document cannot be translated into a visible verification, it is not controlling the exposure. It is recording an intention.
Myth 2: The safety function should own every acceptance decision
Safety professionals often hold the technical expertise needed to challenge an assessment, identify missing barriers, and test whether the proposed controls are credible. That role is essential, although it does not automatically make the safety function the owner of every operational decision.
When EHS becomes the default approver, operating leaders can begin to treat risk as a specialist problem. The manager who controls staffing, production sequencing, maintenance funds, and stop-work support remains distant from the consequence, while the safety adviser becomes responsible for a decision that cannot be implemented without line authority.
A stronger arrangement separates challenge from ownership. The operating leader accepts the residual exposure within the authority assigned to the role. EHS tests the evidence, questions the assumptions, and escalates when the decision exceeds the agreed boundary. Engineering, maintenance, procurement, and human resources may also own parts of the control plan, depending on what created the exposure.
Andreza Araujo’s leadership approach places accountability where choices become visible. If a leader can authorize continued work, that leader must also explain the temporary protection, the resources committed to the permanent fix, and the condition that will trigger a stop or escalation.
Myth 3: A temporary control is safe until its due date
A due date is a planning signal, not a protective barrier. The temporary control can fail before the date arrives because the work changes, the control degrades, a new crew takes over, or production pressure makes the original arrangement difficult to maintain.
Consider a temporary access restriction around damaged equipment. The restriction may be adequate during a day shift when a supervisor is present, yet weak during a night shift when contractors need to enter the area for an unrelated task. The risk has changed even though the calendar has not.
Every temporary control needs four visible conditions. It needs a named owner who can maintain it, a verification method that can detect loss of protection, a trigger that requires immediate review, and a replacement path whose progress is reported to the person who approved the exposure. The trigger might be a change in work scope, a weather event, a control failure, an incident, or a shift in personnel.
Review the condition at the point of work rather than only in the action tracker. A control that exists in a spreadsheet but cannot be found, understood, or maintained by the crew is not a reliable control. The acceptance should be withdrawn when the assumptions that made it defensible are no longer true.
Myth 4: Production pressure is a valid reason to accept any residual risk
Operational urgency is real. Customer commitments, supply interruptions, financial loss, and emergency demand can influence a decision, but urgency does not create authority where none exists and it does not make a weak barrier stronger.
The dangerous shortcut is to present schedule impact as if it were a risk criterion. A missed shipment may be costly, yet it does not answer whether a person can be exposed to uncontrolled energy, whether the emergency arrangement is sustainable, or whether the organization has crossed its own boundary for serious harm.
Leaders should place production pressure beside the safety decision, not inside the safety criterion. The review should show the consequence of delaying the work, the consequence of continuing it, the controls available now, the controls that require investment, and the person who has authority to choose between those paths. This makes the tradeoff visible without disguising it as a technical conclusion.
The decision also needs a challenge path. A supervisor or worker who believes the accepted condition no longer matches reality should know whom to contact, what information to provide, and what protection applies while the concern is reviewed. Silence is not agreement, especially when the person closest to the exposure has no practical route to question the decision.
What leaders should verify before accepting residual risk
Before approving continued work, ask whether the hazard and the remaining exposure are described in operational language that the crew can recognize. Confirm that the proposed controls are present, that their failure modes are understood, and that the people who will perform the task have been included in the review.
| Decision question | Weak evidence | Stronger evidence |
|---|---|---|
| Who owns the decision? | A generic EHS approval or a group signature | A named operating leader with authority over the work and resources |
| What makes continued work defensible? | A risk score with no field condition | Specific controls, boundaries, and verification evidence |
| When does the decision expire? | A date that moves without explanation | A date, a replacement milestone, and a condition that triggers review |
| What happens when reality changes? | Workers are expected to use personal judgment | A defined stop, escalation, and response pathway |
The review should also test whether the accepted exposure is consistent with the organization’s risk criteria and appetite. If the decision requires an exception, say so plainly and send it to the level that can authorize an exception. Hidden exceptions are difficult to govern because leaders cannot see how often the organization is operating outside its stated boundary.
What to do now
Choose one active risk acceptance record and follow it to the field. Check whether the crew can describe the remaining exposure, whether the temporary controls are visible, whether the owner has responded to changes, and whether the permanent action is receiving the attention promised when the work was approved.
Then review the decision with the operating leader, not only with the person who maintains the register. Ask which assumption would make the acceptance invalid, what evidence would show that the risk is reducing, and what support the person raising a concern can expect. Those questions move acceptance from paperwork into management practice.
Risk acceptance is not a failure when it is bounded, authorized, and temporary. It becomes a failure when the organization uses a decision record to avoid making the next decision. The leader’s responsibility is to keep the exposure visible until the control is improved, the work is changed, or the activity is stopped.
For a deeper view of how leadership choices shape safety culture, explore risk criteria and the boundaries leaders must set alongside Andreza Araujo’s book Safety Culture: From Theory to Practice. The goal is not to eliminate every difficult decision. It is to make each decision traceable, challengeable, and connected to a real reduction in exposure.
Frequently asked questions
What does risk acceptance mean in workplace safety?
Who should approve an operational safety risk?
How long can a temporary risk control remain in place?
Is accepted risk the same as acceptable risk?
About the author
Andreza Araújo
Safety Culture Expert | Senior EHS Executive
Andreza Araújo is a safety culture expert and senior EHS executive with more than 25 years of experience in environment, health and safety. She is a Civil Engineer and Occupational Safety Engineer from Unicamp, holds a Master's degree in Environmental Diplomacy from the University of Geneva, and completed sustainability studies at IMD Switzerland. Andreza has served in Global Head of EHS roles in Fortune 500 environments, leading cultural transformation programs across multinational operations. She has represented Brazil as a speaker at the United Nations in Paris and has spoken at the International Labour Organization in Turin. She is the author of more than 16 books on safety culture in Portuguese, Spanish, English and German. Her work has earned more than 10 EHS awards, including two recognitions from Indra Nooyi, former PepsiCo CEO.
- Civil & Safety Engineer (Unicamp)
- M.A. Environmental Diplomacy (University of Geneva)
- Sustainability Cert (IMD Switzerland)
- People Management & Coaching (Ohio University)
- UN Paris speaker representative for Brazil
- ILO Turin speaker
- LinkedIn Top Voice
- Indra Nooyi PepsiCo CEO recognition (2x)
Documentaries
Watch Andreza's documentaries
Three productions on safety culture, organizational failure and the human lessons behind major disasters.
Podcasts
Listen to Andreza's podcasts
She hosts three shows on safety leadership, EHS and organizational culture, in English and Portuguese.