A risk treatment plan is a structured record of how each risk that exceeds an organisation tolerance will be addressed, by whom, and by when. Defined in ISO 31000 and required by ISO 27001 Clause 6.1.3, it captures the chosen treatment, the controls, the owner, the target date and the residual risk that remains.
Put simply, the risk assessment tells you what could go wrong and how badly; the risk treatment plan, or RTP, tells you what you are going to do about it. Without it, a risk register is just a list of worries. With it, every unacceptable risk has a named owner, an agreed action and a deadline, which is exactly what auditors and boards want to see.
What Is a Risk Treatment Plan?
ISO 31000 describes risk treatment as the process of selecting and implementing options for modifying risk. ISO 27001 Clause 6.1.3 makes this concrete for information security: organisations must select treatment options, determine the controls needed, compare them against Annex A, and produce both a risk treatment plan and a Statement of Applicability. The RTP is the project-management document that says who will do what, by when, to bring each risk within appetite.
Critically, the plan must be approved by risk owners, and any decision to simply accept a risk needs proper authority behind it. A common major non-conformance in ISO 27001 audits is the unauthorised acceptance of a high risk, where a risk is marked accept without the actual risk owner, often a department head or executive, signing off on the residual exposure.
The Four Risk Treatment Options
ISO 31000 and ISO 27001 recognise four broad ways to treat a risk. Every line in a treatment plan chooses one of them, and the choice must be justified against the organisation risk appetite.
- Modify or reduce: apply technical or organisational controls to lower the likelihood or impact, the most common choice.
- Avoid: eliminate the risk entirely by stopping the activity or removing the asset that creates it.
- Share or transfer: move part of the impact to a third party, for example through insurance or an outsourcing contract.
- Accept or retain: knowingly keep the risk because it already sits within appetite, with formal sign-off from the risk owner.
ISO 27001 Clause 6.1.3 requires that 100 percent of identified risks are addressed through a documented treatment decision and captured in the Statement of Applicability. There is no option to leave a risk unresolved: even accepting it is a formal, authorised choice that must be recorded.
How the RTP Flows from Risk Assessment
The treatment plan does not appear from nowhere. It is the direct output of the assessment stage. First you identify and analyse risks, usually scoring inherent risk on a matrix. Then, for every risk above your acceptance threshold, you select a treatment option, define the controls, and record the expected residual risk once those controls are in place. Our guide to the risk assessment matrix explains how those inherent scores are produced, and our article on inherent versus residual risk explains the before-and-after values the plan must capture.
This flow matters because residual risk is the number that decides whether treatment is finished. If the residual level still exceeds appetite after the planned controls, the plan is not complete: you either add controls or escalate for a formal acceptance decision.
What a Good Risk Treatment Plan Records
A weak RTP lists risks and vague intentions. A strong one is auditable and trackable because every entry carries the same core fields.
- Risk description and reference back to the register entry.
- Inherent risk level, the score before any new treatment.
- Chosen treatment option: modify, avoid, share or accept.
- Specific controls or actions selected, mapped to Annex A where relevant.
- Risk owner, the named person accountable for the outcome.
- Target completion date and current status.
- Residual risk level expected once the actions are complete.
Where the person implementing an action differs from the risk owner, remember that the risk owner keeps ultimate accountability for ensuring the agreed treatment is delivered. That single line of accountability is what stops treatment plans from quietly stalling.
The Link to the Statement of Applicability
In ISO 27001 the RTP and the Statement of Applicability, or SoA, are two sides of the same coin. The RTP is the action plan: who does what, by when. The SoA is the definitive register of controls: which Annex A controls are included, why they were selected, and, for any excluded, the justification for leaving them out. The controls you commit to in the treatment plan must reconcile with those declared applicable in the SoA, and auditors will check that they match.
How to Track the Plan Over Time
A treatment plan is a living document, not a one-off deliverable. Assign a named owner to every action, set measurable milestones, and review progress on a regular cadence so that overdue treatments surface early. Report status to management, and re-evaluate residual risk once controls are implemented to confirm the risk has actually moved within appetite. Many teams manage this in a dedicated GRC platform that assigns ownership, tracks due dates and generates board-level reports, but a well-maintained spreadsheet works too, provided the reviews genuinely happen.
Common Risk Treatment Plan Mistakes
Several avoidable errors turn a compliant-looking plan into an audit finding. The most serious is the unauthorised acceptance already noted: a high risk marked accept without the risk owner formally signing off the residual exposure. Almost as common is a plan whose target dates have all quietly slipped, with no evidence of review, which signals to an auditor that treatment exists only on paper.
- Actions with no named owner, so no one is accountable when a deadline passes.
- Residual risk left blank, making it impossible to judge whether treatment is complete.
- Controls in the RTP that do not reconcile with the Statement of Applicability.
- Acceptance decisions taken by IT rather than the accountable business risk owner.
Fixing these is less about tooling and more about discipline. A plan that names owners, records before-and-after risk levels, and is genuinely reviewed each cycle will satisfy both an ISO 27001 auditor and, more importantly, the board that ultimately carries the risk.