Treat risk acceptance as a dated decision
Supplier risk spans financial health, information security, privacy, sanctions, quality, continuity, concentration, geography, sustainability, and other domains. Not every supplier warrants the same depth, but every material finding needs an affected scope, owner, proposed treatment, evidence, decision authority, and review date. A red flag without an owner is reporting, not management.
Acceptance is a treatment, not the absence of one. Record who accepted the residual exposure, within what authority, for which relationship, until what date, and on which evidence. Expiry should return the decision to a queue. That prevents a temporary exception granted during a launch from becoming a permanent control failure simply because nobody remembered it.