Accepting a risk is a decision, and should look like one
Most acceptance happens by omission.
Formally, an organisation may treat, transfer, avoid or accept a risk. In practice a large proportion is accepted by nobody deciding anything: the entry sits at a moderate rating, the treatment is listed as ongoing monitoring, and years pass.
Explicit acceptance is a much stronger position and costs only a sentence. It records that a named person, with authority, considered the exposure and concluded that the cost of further treatment exceeded the benefit. That is a defensible decision. Drift is not, and it is indistinguishable from oversight after the event.
It also has an operational benefit, which is that accepted risks can be removed from active review. A register in which everything is perpetually being monitored provides no signal about where attention should go, and separating accepted items from active ones restores it.
Acceptance should carry a review trigger rather than a review date: what would have to change for this to be reconsidered. That is more useful than an annual cycle, because the conditions that make an acceptable risk unacceptable rarely arrive on schedule.
The other point about acceptance is that it should be proportionate to who is accepting. A team leader accepting an exposure that could materially affect the organisation is not an adequate acceptance regardless of how well it is documented, and the level at which acceptance is valid for a given size of exposure should be stated rather than assumed.