Risk Management

Risk Treatment Plan: A Step-by-Step ISO Guide

Standarity Editorial Team·ISO 31000 and ISO 27001 risk management practitioners
··6 min read

A risk treatment plan is a structured record of how each risk that exceeds an organisation tolerance will be addressed, by whom, and by when. Defined in ISO 31000 and required by ISO 27001 Clause 6.1.3, it captures the chosen treatment, the controls, the owner, the target date and the residual risk that remains.

Put simply, the risk assessment tells you what could go wrong and how badly; the risk treatment plan, or RTP, tells you what you are going to do about it. Without it, a risk register is just a list of worries. With it, every unacceptable risk has a named owner, an agreed action and a deadline, which is exactly what auditors and boards want to see.

What Is a Risk Treatment Plan?

ISO 31000 describes risk treatment as the process of selecting and implementing options for modifying risk. ISO 27001 Clause 6.1.3 makes this concrete for information security: organisations must select treatment options, determine the controls needed, compare them against Annex A, and produce both a risk treatment plan and a Statement of Applicability. The RTP is the project-management document that says who will do what, by when, to bring each risk within appetite.

Critically, the plan must be approved by risk owners, and any decision to simply accept a risk needs proper authority behind it. A common major non-conformance in ISO 27001 audits is the unauthorised acceptance of a high risk, where a risk is marked accept without the actual risk owner, often a department head or executive, signing off on the residual exposure.

The Four Risk Treatment Options

ISO 31000 and ISO 27001 recognise four broad ways to treat a risk. Every line in a treatment plan chooses one of them, and the choice must be justified against the organisation risk appetite.

  • Modify or reduce: apply technical or organisational controls to lower the likelihood or impact, the most common choice.
  • Avoid: eliminate the risk entirely by stopping the activity or removing the asset that creates it.
  • Share or transfer: move part of the impact to a third party, for example through insurance or an outsourcing contract.
  • Accept or retain: knowingly keep the risk because it already sits within appetite, with formal sign-off from the risk owner.

ISO 27001 Clause 6.1.3 requires that 100 percent of identified risks are addressed through a documented treatment decision and captured in the Statement of Applicability. There is no option to leave a risk unresolved: even accepting it is a formal, authorised choice that must be recorded.

How the RTP Flows from Risk Assessment

The treatment plan does not appear from nowhere. It is the direct output of the assessment stage. First you identify and analyse risks, usually scoring inherent risk on a matrix. Then, for every risk above your acceptance threshold, you select a treatment option, define the controls, and record the expected residual risk once those controls are in place. Our guide to the risk assessment matrix explains how those inherent scores are produced, and our article on inherent versus residual risk explains the before-and-after values the plan must capture.

This flow matters because residual risk is the number that decides whether treatment is finished. If the residual level still exceeds appetite after the planned controls, the plan is not complete: you either add controls or escalate for a formal acceptance decision.

What a Good Risk Treatment Plan Records

A weak RTP lists risks and vague intentions. A strong one is auditable and trackable because every entry carries the same core fields.

  • Risk description and reference back to the register entry.
  • Inherent risk level, the score before any new treatment.
  • Chosen treatment option: modify, avoid, share or accept.
  • Specific controls or actions selected, mapped to Annex A where relevant.
  • Risk owner, the named person accountable for the outcome.
  • Target completion date and current status.
  • Residual risk level expected once the actions are complete.

Where the person implementing an action differs from the risk owner, remember that the risk owner keeps ultimate accountability for ensuring the agreed treatment is delivered. That single line of accountability is what stops treatment plans from quietly stalling.

The Link to the Statement of Applicability

In ISO 27001 the RTP and the Statement of Applicability, or SoA, are two sides of the same coin. The RTP is the action plan: who does what, by when. The SoA is the definitive register of controls: which Annex A controls are included, why they were selected, and, for any excluded, the justification for leaving them out. The controls you commit to in the treatment plan must reconcile with those declared applicable in the SoA, and auditors will check that they match.

How to Track the Plan Over Time

A treatment plan is a living document, not a one-off deliverable. Assign a named owner to every action, set measurable milestones, and review progress on a regular cadence so that overdue treatments surface early. Report status to management, and re-evaluate residual risk once controls are implemented to confirm the risk has actually moved within appetite. Many teams manage this in a dedicated GRC platform that assigns ownership, tracks due dates and generates board-level reports, but a well-maintained spreadsheet works too, provided the reviews genuinely happen.

Common Risk Treatment Plan Mistakes

Several avoidable errors turn a compliant-looking plan into an audit finding. The most serious is the unauthorised acceptance already noted: a high risk marked accept without the risk owner formally signing off the residual exposure. Almost as common is a plan whose target dates have all quietly slipped, with no evidence of review, which signals to an auditor that treatment exists only on paper.

  • Actions with no named owner, so no one is accountable when a deadline passes.
  • Residual risk left blank, making it impossible to judge whether treatment is complete.
  • Controls in the RTP that do not reconcile with the Statement of Applicability.
  • Acceptance decisions taken by IT rather than the accountable business risk owner.

Fixing these is less about tooling and more about discipline. A plan that names owners, records before-and-after risk levels, and is genuinely reviewed each cycle will satisfy both an ISO 27001 auditor and, more importantly, the board that ultimately carries the risk.

Frequently Asked Questions

What are the four risk treatment options?

The four options recognised by ISO 31000 and ISO 27001 are modify or reduce the risk with controls, avoid the risk by stopping the activity, share or transfer the risk to a third party such as an insurer, and accept or retain the risk when it already falls within appetite. Reduction is the most common, and acceptance always requires formal sign-off from the risk owner.

What is the difference between a risk treatment plan and a Statement of Applicability?

The risk treatment plan is a project-management document that records who will do what, by when, to treat each risk. The Statement of Applicability is the definitive list of Annex A controls, stating which are included, why, and why any are excluded. The controls in the RTP must reconcile with those declared applicable in the SoA.

Who is responsible for the risk treatment plan?

Every treatment action should have a named owner accountable for delivering it, and where that person differs from the risk owner, the risk owner keeps ultimate accountability for ensuring the plan is implemented. Development can be supported by external consultants, but responsibility for implementation stays with the organisation, and only the actual risk owner can authorise accepting a residual risk.

What should a risk treatment plan include?

A strong RTP records the risk description, the inherent risk level, the chosen treatment option, the specific controls or actions, the named risk owner, the target completion date, the current status, and the expected residual risk once the actions are complete. Those fields make the plan auditable and trackable rather than a static list.

What is residual risk in a treatment plan?

Residual risk is the level of risk that remains after the planned controls have been applied. It is the number that decides whether treatment is complete: if residual risk still exceeds the organisation appetite, more controls are needed or the risk must be escalated for a formal acceptance decision by the risk owner.

Explore Courses on Udemy

Intermediate

ISO 31000: Risk Management Implementation Step by Step

Intermediate

CRISC Certification — IT Risk Management with AI Tools

Intermediate

ISO 27001:2022 Implementation Step by Step with Templates