Proceedings of the
European Safety and Reliability Conference (ESREL2026)
14 – 19 June 2026, Braga, Portugal
Improvements to the use of Risk Acceptance Criteria
Norwegian Ocean Industry Authority, Norway.
Norwegian Ocean Industry Authority, Norway.
ABSTRACT
This paper discusses how risk acceptance criteria (RAC) and other decision criteria can be defined and applied in the offshore industry to support risk-informed decision-making in accordance with a performance-based regulatory framework. The objective of the paper is to give insight into the work presently ongoing at the Norwegian offshore industry regulatory authority on this topic. The main message is that risk acceptance criteria are not synonymous with quantitative criteria, they may also be qualitative or hybrid. Furthermore, they should be consistent with the underlying risk understanding, the risk description (qualitative or quantitative) and the actual decision context. The paper highlights that traditional quantitative analyses often fail to capture all aspects of uncertainty, that the precision of quantitative risk indices is rarely sufficient to demonstrate compliance with quantitative acceptance criteria and that such indices may lead to "trivial verification" or be used incorrectly to argue against safety measures. The paper emphasizes that decision making processes should focus on understanding risk rather than an excessive focus on verification against risk acceptance criteria, such as FAR. Furthermore, it argues that the industry can achieve better safety by utilizing the flexibility in the regulatory framework, by tailoring decision-criteria to context and knowledge-strength, in addition to embedding risk acceptance criteria in actual decision-making processes. The work that is the basis for this paper seeks a more expedient use of risk acceptance criteria, aligned with the entirety of the regulatory framework (in particular Chapter III of the Norwegian Petroleum Management Regulations). This also includes clarifying the scope for the use of different types of criteria, such as the use of traditional quantitative acceptance criteria, standards, barrier requirements, "Worst Credible Event" approaches and knowledge-strength-sensitive requirements as criteria for defining sufficient safety.
Keywords: Risk acceptance criteria, regulatory regime.

