My issue is with how to show evidence of "acceptance of remaining risks after implementation of mitigating actions", ref. AS9100 7.1.2 e.
We had our renewal audit to AS9100-C last fall. For risk management we came up with some risk worksheets for certain processes. We were able to pass with that but before the auditor left he strongly suggested we figure out how to show evidence of risk acceptance in the future. I do not want to add another form or expand the risk worksheets our folks already use so I've suggested to them that after taking mitigating actions (if any) they record the results and acceptance at the bottom of the risk worksheet, keeping all risk documentation on one form. Thoughts?
We had our renewal audit to AS9100-C last fall. For risk management we came up with some risk worksheets for certain processes. We were able to pass with that but before the auditor left he strongly suggested we figure out how to show evidence of risk acceptance in the future. I do not want to add another form or expand the risk worksheets our folks already use so I've suggested to them that after taking mitigating actions (if any) they record the results and acceptance at the bottom of the risk worksheet, keeping all risk documentation on one form. Thoughts?

Remember - keep it simple - much of this stuff is new and unique to upper management and thus - by default will be embrace by few and followed by the rest.
