ISO 27001 Risk Treatment Plan: Actions and Template
How to turn assessed information-security risks into concrete actions, accountable owners, residual-risk decisions and auditable evidence.
A risk assessment shows where your ISMS is exposed. It does not yet decide what happens next. That is the role of the risk treatment plan: it turns risks into reasoned decisions, concrete actions, owners, due dates and evidence.
This is more than an IT task list. Management must decide which risks may be accepted, owners must implement the actions and the organisation must later show whether those actions work. A useful plan keeps that chain visible.
What a risk treatment plan does
The plan turns the risk register into a controlled implementation process. For each relevant risk, it should be possible to trace:
- the scenario being treated and the underlying assessment,
- why a treatment option was selected,
- what action is intended to change the risk,
- who owns implementation and the decision,
- how effectiveness will be checked and where evidence is stored,
- what residual risk remains after treatment.
Your ISO 27001 risk assessment provides the starting point. The treatment plan carries it into implementation.
The four treatment options
| Option | When it fits | Example |
|---|---|---|
| Reduce | The risk remains relevant, but controls can bring it within the accepted level. | Introduce access reviews and stronger authentication. |
| Avoid | The risky activity is stopped or redesigned. | Discontinue an insecure data-transfer method. |
| Transfer | Some consequences are shifted contractually or through insurance. | Use a cloud provider with defined security requirements and liability terms. |
| Accept | The residual risk is within approved acceptance criteria. | Document and approve a low risk that is not proportionate to reduce further. |
Transfer does not mean the organisation gives away responsibility for the risk. Contracts or insurance may limit consequences, but they do not replace your own assessment, supplier management or oversight.
Turning a risk into an actionable measure
An action should describe a verifiable result, not merely repeat a control name. Compare these examples:
| Too vague | Controllable |
|---|---|
| “Improve access” | “By 30 September, privileged access to all production systems will be reviewed quarterly; deviations will be handled within five working days.” |
| “Train employees” | “All employees within the ISMS scope complete the annual awareness module; attendance and the knowledge check are retained in the training register.” |
The second wording defines result, scope, timing and evidence. The owner can act on it, and an auditor can later assess whether the action was implemented and effective.
Residual risk and approval
A risk rarely disappears completely after treatment. The plan should therefore record the expected residual rating and the decision about it. Residual risk should only be accepted when:
- acceptance criteria were defined in advance,
- the authorised decision-maker is clear,
- legal, regulatory and contractual obligations were considered,
- assumptions and remaining dependencies are documented.
Sequence matters: an action is not automatically effective just because it is marked complete. Schedule an effectiveness review and keep its outcome as evidence.
Connecting the plan to the Statement of Applicability
The risk treatment plan and the Statement of Applicability have different jobs. The plan manages risks and actions. The SoA documents the selection and justification of controls. They must still agree: a control selected to treat a relevant risk should be traceable in the SoA, the action plan and the evidence.
Additional controls outside the reference set may be appropriate when they result from your own risk process. The important point is not the number of controls, but the quality of the reasoning.
How to use the Excel template
Start with “Risks & Treatment” and add risks that require a decision or action. Link each action through the risk ID. In “Treatment Plan”, describe the intended result rather than only the activity. Then use “Controls & SoA” to connect relevant controls and evidence references.
Use “Approvals & Reviews” for decisions that should not be made by a technical owner alone. Change a status only when a concrete result exists. Leave the effectiveness-review field open when an action is implemented but has not yet been observed for long enough to support a reliable conclusion.
Download: ISO 27001 Risk Treatment Plan
The Excel template includes dropdowns for treatment option, priority, status, implementation stage and residual-risk decision. It is designed as a working register and should be managed within your ISMS with controlled versioning, access rules and approval.
Download the Excel templateCommon practical mistakes
- “Reduce risk” is recorded without a concrete action, owner or due date.
- The SoA is updated while the actual action status remains outdated elsewhere.
- Residual risk is silently accepted instead of being approved by the responsible role.
- Evidence shows only that a policy exists, not that the measure works in daily practice.
- Dependencies on suppliers, budgets or system changes are absent from the plan.
The audit perspective
Before Stage 1 or Stage 2, an auditor should be able to follow the chain from risk to treatment, control, owner and evidence. The ISO 27001 audit preparation checklist helps structure open points and interviews. A clear treatment plan also shows which items are deliberately open and which are simply waiting for an effectiveness review.
Normative reference
Requirements for an ISMS and its risk-treatment process should always be checked against the standard edition and certification scheme applicable to your organisation. The official ISO/IEC 27001:2022 overview from ISO is a suitable starting point.
How Sternberg Consulting supports you
We help SMEs connect risk assessment, treatment, the SoA and audit evidence in a lean, functioning ISMS. Our ISO 27001 consulting covers scoping, gap analysis, implementation and audit preparation.
Frequently asked questions
Is a risk treatment plan the same as a risk register?
No. The risk register describes and assesses risks. The treatment plan records decisions and manages the actions used to change, avoid, transfer or accept those risks.
Does every action have to match an Annex A control?
No. Controls are an important reference, but your own risk process may require additional measures. The selection and rationale should be traceable.
Who may accept residual risk?
This depends on your acceptance criteria and governance. The role should have authority over the affected information or process, and the decision should be documented.
Related articles
For context, read the ISO 27001 certification process for SMEs and the overview of Clauses 4 to 10 and the 93 controls.