Findings and risk
Risk acceptance
Also called: accepted risk, risk acceptance memo
Risk acceptance is a documented decision not to remediate a finding, recording who accepted it, the rationale, any compensating controls, and when the decision will be revisited. It is a legitimate outcome when it is written down and owned.
An accepted risk with a named owner and a review date is a defensible position in an audit. A finding that was quietly ignored is not, and it reads the same way to a customer's security reviewer.
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.