A risk owner is the person or accountable business role authorized to make decisions about a defined risk, including treatment, acceptance, monitoring and escalation. In IGA, a risk owner may approve policy exceptions or compensating controls that ordinary access approvers cannot authorize.
Risk ownership should be documented and should not be confused with technical system administration.