If decryption is not possible, the associated risks should be formally documented, together with the legal and business justification for continued retention, the impact of the data’s inaccessibility, and recommended next steps. This documentation should be submitted to the appropriate management and governance authorities for review, approval, and a risk-informed decision on the future disposition of the encrypted data.