Free MSP resource

Free AI Risk Acceptance Form Template

Document when a client declines a recommended AI security control. Give them a clear choice to mitigate the risk or formally accept it.

Built for MSPs. Free to copy, customize, and use with clients.

Download Word (.docx)

Prefer plain text?

The form

AI Risk Acceptance Form

Client: [CLIENT NAME]

MSP: [MSP NAME]

Date: [DATE]

AI Exposure Identified

[BRIEFLY DESCRIBE THE IDENTIFIED AI USE, CONTROL GAP, OR SECURITY EXPOSURE]

Examples may include use of unapproved AI tools, personal AI accounts, sensitive data being submitted to AI services, or unauthorized AI applications connected to company systems.

Potential Business Risk

The identified exposure may increase the risk of:

☐ Confidential, customer, or regulated data disclosure

☐ Intellectual property or proprietary information exposure

☐ Credential, account, or system compromise

☐ Regulatory, contractual, or policy violations

☐ Financial, legal, or reputational harm

☐ Other: ______________________________________

Recommended Action

[DESCRIBE THE RECOMMENDED AI SECURITY OR GOVERNANCE CONTROL]

Client Decision

Please select one:

Authorize the recommended AI security controls

Decline the recommendation and accept the identified AI-related risk

By selecting risk acceptance, [CLIENT NAME] acknowledges that the identified exposure and potential business risks have been communicated by [MSP NAME], and that [CLIENT NAME] has chosen not to implement the recommended controls at this time.

The signer below confirms that they are authorized to make this decision on behalf of [CLIENT NAME].

Authorized Representative: ______________________________

Title: _________________________________________________

Signature: _____________________________________________

Date: _________________________________________________

This form documents the Client's decision and does not modify or replace the terms of any existing agreement between [CLIENT NAME] and [MSP NAME].

This template is provided for general informational purposes and is not legal advice. MSPs should have qualified legal counsel review it before use.

Replace bracketed placeholders ([CLIENT NAME], [MSP NAME], [DATE], etc.) with the details of the specific finding. Have your legal counsel review the form before you put it in front of clients.

How to use it

How MSPs can use the AI risk acceptance form

  1. Identify the exposure: Document the specific AI use or control gap you found, in plain terms: which tool, which people, which systems or data it touches.
  2. Explain the business risk: Translate the technical finding into what it could actually mean for the client: data disclosure, IP loss, account compromise, or regulatory exposure.
  3. Recommend a control and record the decision: Give the client the option to remediate the issue or formally accept the remaining risk, then capture a signature from someone authorized to make that call.

Worked example

Exposure
Employees are using personal ChatGPT accounts for company work.
Risk
Confidential company or customer data could be submitted to an uncontrolled third party.
Recommended control
Restrict personal AI accounts and require approved business accounts.

Keeping those three separate is what makes the form useful. The exposure is the condition that exists, the risk is the consequence it could lead to, and the control is what you are recommending be done about it. A finding written as “employees use personal AI accounts” is an exposure, not a risk, and on its own it does not tell the client what they are being asked to decide.

Why it matters

Why document rejected security recommendations?

When a client declines a recommendation, the conversation usually happens verbally and then disappears. A signed form leaves a record of what was identified, what you recommended, what consequences you communicated, and who made the decision to accept the remaining risk. Six months later, that record is the difference between a documented decision and two parties remembering the same meeting differently.

A consistent risk-acceptance process is also useful outside the client relationship. It gives you something concrete to point to during governance reviews, internal security reviews, and cyber-insurance conversations, where being able to show how declined recommendations are handled is more credible than describing it. It does not by itself change your premium, guarantee coverage, or settle where liability sits.

Which document do I need?

AI risk acceptance form vs. AI acceptable use policy

These solve different problems and most clients need both. One sets the rules for everybody up front. The other records a single decision after you have found something specific.

AI acceptable use policy

Defines how employees are allowed to use AI: which tools are approved, which data must never be submitted, and what happens when someone breaks the rules.

Standing policy · applies to everyone · reviewed annually

AI risk acceptance form

Documents one specific business decision: you found an exposure, recommended a control, and the client chose to authorize it or to accept the risk instead.

Point-in-time record · one finding · signed per decision

Need the employee policy too? Get the free AI Acceptable Use Policy Template.

This form is the last step of a wider motion. See where it fits in the MSP sales process: you assess, you propose, and the client either fixes the risk or formally accepts it.

Frequently asked

Risk acceptance form FAQ

What is an AI risk acceptance form?

An AI risk acceptance form is a short document that records four things: the AI exposure identified, the potential business risk it creates, the control the MSP recommended, and the client's decision to accept the remaining risk instead of implementing that control. It is signed and dated by someone authorized to accept risk for the client.

When should an MSP use a risk acceptance form?

Use one whenever a client declines, delays, or chooses not to implement a recommended AI security or governance control. The trigger is a specific declined recommendation, not a general policy conversation. If the client authorizes the work instead, the same form records that decision and closes the loop.

Is a risk acceptance form the same as a liability waiver?

No. A risk acceptance form documents that the client was informed and made a decision. It is a record, not a release. It does not replace the limitation-of-liability and client-obligation language in your master services agreement, and it is not a substitute for legal advice on how those provisions are drafted.

What is the difference between a risk acceptance form and a risk acceptance letter?

They serve essentially the same purpose. A risk acceptance form is generally more structured, with fixed fields and checkboxes, while a risk acceptance letter is usually written as correspondence on letterhead. This template is designed as a short structured form so it is faster to complete and easier to file consistently.

Does a signed risk acceptance form remove an MSP's liability?

It does not remove liability. It creates documentation that the recommendation was made and the client declined it. What legal effect that documentation carries depends on your contracts, your jurisdiction, the facts of the situation, and applicable law. Have counsel review how this form interacts with your MSA before you use it.

What should be included in a cybersecurity risk acceptance form?

At minimum: the identified exposure, the potential business consequence, the recommended control, the client's decision, the name and title of an authorized signer, and the date. For a client-facing MSP form, additional risk scoring, framework mapping, and approval workflow fields are usually unnecessary.

Don’t just document AI risk. Reduce it.

ShadowLock helps MSPs discover and control shadow AI across client environments, so fewer findings end up needing a signature in the first place.

  • Detect unauthorized AI use
  • Block risky AI websites and desktop apps
  • Prevent sensitive data from being pasted or uploaded
  • Detect risky Microsoft 365 AI OAuth apps
  • Generate client-ready AI risk reporting