Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 27001 & Information SecurityPublished: 16 July 2026

ISO 27001 Risk Treatment Plan: Actions and Template

How to turn assessed information-security risks into concrete actions, accountable owners, residual-risk decisions and auditable evidence.

A risk assessment shows where your ISMS is exposed. It does not yet decide what happens next. That is the role of the risk treatment plan: it turns risks into reasoned decisions, concrete actions, owners, due dates and evidence.

This is more than an IT task list. Management must decide which risks may be accepted, owners must implement the actions and the organisation must later show whether those actions work. A useful plan keeps that chain visible.

What a risk treatment plan does

The plan turns the risk register into a controlled implementation process. For each relevant risk, it should be possible to trace:

  • the scenario being treated and the underlying assessment,
  • why a treatment option was selected,
  • what action is intended to change the risk,
  • who owns implementation and the decision,
  • how effectiveness will be checked and where evidence is stored,
  • what residual risk remains after treatment.

Your ISO 27001 risk assessment provides the starting point. The treatment plan carries it into implementation.

The four treatment options

Table 1: ISO 27001 Risk Treatment Plan: Actions and Template
OptionWhen it fitsExample
ReduceThe risk remains relevant, but controls can bring it within the accepted level.Introduce access reviews and stronger authentication.
AvoidThe risky activity is stopped or redesigned.Discontinue an insecure data-transfer method.
TransferSome consequences are shifted contractually or through insurance.Use a cloud provider with defined security requirements and liability terms.
AcceptThe residual risk is within approved acceptance criteria.Document and approve a low risk that is not proportionate to reduce further.

Transfer does not mean the organisation gives away responsibility for the risk. Contracts or insurance may limit consequences, but they do not replace your own assessment, supplier management or oversight.

Turning a risk into an actionable measure

An action should describe a verifiable result, not merely repeat a control name. Compare these examples:

Table 2: ISO 27001 Risk Treatment Plan: Actions and Template
Too vagueControllable
“Improve access”“By 30 September, privileged access to all production systems will be reviewed quarterly; deviations will be handled within five working days.”
“Train employees”“All employees within the ISMS scope complete the annual awareness module; attendance and the knowledge check are retained in the training register.”

The second wording defines result, scope, timing and evidence. The owner can act on it, and an auditor can later assess whether the action was implemented and effective.

Residual risk and approval

A risk rarely disappears completely after treatment. The plan should therefore record the expected residual rating and the decision about it. Residual risk should only be accepted when:

  • acceptance criteria were defined in advance,
  • the authorised decision-maker is clear,
  • legal, regulatory and contractual obligations were considered,
  • assumptions and remaining dependencies are documented.

Sequence matters: an action is not automatically effective just because it is marked complete. Schedule an effectiveness review and keep its outcome as evidence.

Connecting the plan to the Statement of Applicability

The risk treatment plan and the Statement of Applicability have different jobs. The plan manages risks and actions. The SoA documents the selection and justification of controls. They must still agree: a control selected to treat a relevant risk should be traceable in the SoA, the action plan and the evidence.

Additional controls outside the reference set may be appropriate when they result from your own risk process. The important point is not the number of controls, but the quality of the reasoning.

How to use the Excel template

Start with “Risks & Treatment” and add risks that require a decision or action. Link each action through the risk ID. In “Treatment Plan”, describe the intended result rather than only the activity. Then use “Controls & SoA” to connect relevant controls and evidence references.

Use “Approvals & Reviews” for decisions that should not be made by a technical owner alone. Change a status only when a concrete result exists. Leave the effectiveness-review field open when an action is implemented but has not yet been observed for long enough to support a reliable conclusion.

Download: ISO 27001 Risk Treatment Plan

The Excel template includes dropdowns for treatment option, priority, status, implementation stage and residual-risk decision. It is designed as a working register and should be managed within your ISMS with controlled versioning, access rules and approval.

Download the Excel template

Common practical mistakes

  • “Reduce risk” is recorded without a concrete action, owner or due date.
  • The SoA is updated while the actual action status remains outdated elsewhere.
  • Residual risk is silently accepted instead of being approved by the responsible role.
  • Evidence shows only that a policy exists, not that the measure works in daily practice.
  • Dependencies on suppliers, budgets or system changes are absent from the plan.

The audit perspective

Before Stage 1 or Stage 2, an auditor should be able to follow the chain from risk to treatment, control, owner and evidence. The ISO 27001 audit preparation checklist helps structure open points and interviews. A clear treatment plan also shows which items are deliberately open and which are simply waiting for an effectiveness review.

Normative reference

Requirements for an ISMS and its risk-treatment process should always be checked against the standard edition and certification scheme applicable to your organisation. The official ISO/IEC 27001:2022 overview from ISO is a suitable starting point.

How Sternberg Consulting supports you

We help SMEs connect risk assessment, treatment, the SoA and audit evidence in a lean, functioning ISMS. Our ISO 27001 consulting covers scoping, gap analysis, implementation and audit preparation.

Discuss your project

Frequently asked questions

Is a risk treatment plan the same as a risk register?

No. The risk register describes and assesses risks. The treatment plan records decisions and manages the actions used to change, avoid, transfer or accept those risks.

Does every action have to match an Annex A control?

No. Controls are an important reference, but your own risk process may require additional measures. The selection and rationale should be traceable.

Who may accept residual risk?

This depends on your acceptance criteria and governance. The role should have authority over the affected information or process, and the decision should be documented.

For context, read the ISO 27001 certification process for SMEs and the overview of Clauses 4 to 10 and the 93 controls.

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.