Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 risk owner approving treatment plan and residual risk acceptance

ISO 27001 Risk Owner: Role and Duties 2026

The ISO 27001 risk owner is the person who answers for an information security risk: they approve how it will be treated and accept what is left. Auditors ask about risk owners early, because a risk register with an empty owner column shows that nobody has decided that the risks are acceptable. The requirement is short, but organisations often misread it, assigning owners who lack authority or naming the security team for every risk.

This guide explains what an ISO 27001 risk owner is, where the standard requires one, who should hold the role, what the owner must do and what evidence supports it in an audit.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

Where the ISO 27001 risk owner appears in the standard

ISO/IEC 27001:2022 clause 6.1.2 requires an information security risk assessment process that, among other things, identifies risk owners. Clause 6.1.3 requires a risk treatment process, and asks the organisation to obtain the risk owners’ approval of the risk treatment plan and their acceptance of the residual information security risks. The standard’s listing is on iso.org. ISO/IEC 27000 defines a risk owner as a person or entity with the accountability and authority to manage a risk.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

The key words are accountability and authority. A risk owner is not merely someone who fills in a spreadsheet. They must be able to decide what to do and to commit resources, or to obtain those resources from the people who control them.

Who should be the ISO 27001 risk owner

The best owner is a manager who is responsible for the asset, process or service the risk affects, and who has the authority to accept it. Typical choices include a head of engineering for a platform risk, a head of HR for a personnel risk and a facilities manager for a physical security risk. The information security manager usually coordinates the process, but should not own every risk, because the security team seldom controls the business decisions that create or accept them.

ChoiceWorks well whenProblem
Business or service ownerThey control the asset and budgetMay lack security knowledge; needs support
Information security managerRisk is about the security programme itselfOwning everything removes business accountability
Team or committeeNeverNo single accountable person
Generic role such as “IT”NeverCannot show who accepted the risk

Name a person or a specific role, and make sure they know they hold it. Owners who first learn of their role from an auditor are a common finding.

What the ISO 27001 risk owner must do

Understand the risk

The owner should review the risk description, the ratings and the reasoning. If the owner cannot explain in plain language what could go wrong and how it was rated, the acceptance that follows will not carry weight. Our guide to the ISO 27001 risk assessment methodology shows how the ratings are produced.

Approve the treatment plan

Owners approve the chosen treatment option and the controls that implement it: modify the risk with controls, retain it, avoid it or share it. They should also approve the resources, owners of actions and dates. See our guide to the ISO 27001 risk treatment plan for how the plan is documented.

Accept residual risk

After treatment, some risk remains. The owner must decide whether it is within the criteria you set in advance. The acceptance should be explicit, dated and recorded, with the reason. The criteria themselves come from your risk acceptability criteria, which define what level of risk can be accepted and by whom. A risk above the owner’s authority should go to a senior manager or committee.

Monitor and review

Risk ownership does not end at sign-off. The owner should watch whether the controls work, whether the risk changes, and whether anything new emerges. They should take part in periodic reviews and confirm or update their acceptance when circumstances change.

Evidence auditors ask for about the ISO 27001 risk owner

  • A risk register in which every risk has a named owner.
  • Evidence the owners were told of and accepted the role.
  • Signed or recorded approval of the risk treatment plan by owners.
  • Recorded acceptance of residual risks, with dates.
  • Criteria showing who may accept what level of risk.
  • Records of reviews where owners were involved.

Auditors often sample a few risks and interview the owners. An owner who says “I didn’t know I owned that” is an easy finding. Our overview of the ISO 27001 risk assessment covers what else they look for.

Supporting owners who are not security experts

Most owners are business managers, not security specialists, so give them what they need to decide. A one-page summary for each risk should state what could go wrong in plain terms, the rating and why, the options available, the cost and effect of each, and the recommendation of the security team. Offer a short briefing when someone takes on the role for the first time, covering the rating scales, the acceptance criteria and what signing off actually means.

Explain the consequences of acceptance clearly. Accepting a risk does not make it disappear; it means the owner agrees the organisation will live with the possibility of the loss and will answer for that decision if it occurs. When owners understand this, they ask sharper questions and are more willing to fund treatment for risks that matter.

Escalation when owners disagree

Sometimes an owner disputes a rating or declines to fund treatment. Set an escalation route in advance: first to the information security manager, then to a senior management forum. Record the outcome. A dispute settled through a defined route is a sign of a working process, while one settled by quiet inaction is an audit finding waiting to happen.

Risk owner versus asset owner

ISO 27001 also uses the idea of an asset owner, a person responsible for an asset such as a system or dataset. The two roles often coincide, but they are not identical. An asset owner looks after the asset day to day. A risk owner is accountable for a particular risk, which may span several assets. If the same person holds both roles, record both, so that the accountability is visible.

A hypothetical example of an ISO 27001 risk owner

The following is a hypothetical example invented for illustration. A software company identifies a risk that a supplier of its customer support tool could suffer a breach exposing customer tickets. The register initially names “IT” as owner. In a review the information security manager points out that the head of customer support owns the relationship and the budget, and reassigns the risk to her.

She reviews the rating, sees that the supplier’s assurance report is a year old, and approves a treatment plan that includes an annual report review, a contractual notification clause and a limit on the data stored in tickets. After treatment, the residual risk is medium, within the criteria that department heads may accept, and she records her acceptance with the date. When the supplier later changes hosting provider, she is told and reopens the risk. The auditor sees a complete trail from owner to decision.

Common mistakes with the ISO 27001 risk owner

Frequent problems include naming a team or generic function, assigning every risk to the security manager, choosing owners with no authority over the risk, failing to tell owners of their role, treating acceptance as a checkbox signed months later, having no criteria for who can accept what, and never revisiting acceptances. Another is departed staff who remain named owners, leaving a gap that nobody notices until an audit.

Keeping the ISO 27001 risk owner role current

Review ownership whenever people change roles or leave, and include an owner check in your joiner, mover and leaver process. Refresh acceptances at each risk review, and at once when a risk changes. Where the framework overlaps with ISO 31000, you may find the comparison in our note on ISO 31000 and ISO 27005 useful for aligning terms.

A structured report for the ISO 27001 risk owner

A consistent format helps you show owners, ratings, treatment and acceptance in one record. The ISO 27001 Risk Assessment Report and Workbook provides a report and workbook for documenting risks, owners, treatment and residual risk. Whichever tool you use, keep the same fields across every risk.

ISO 27001 risk owner FAQ

Does ISO 27001 require a risk owner for every risk?

The standard requires risk owners to be identified as part of the risk assessment process, and their approval of the treatment plan and acceptance of residual risk to be obtained. In practice, that means every risk needs an owner.

Can the information security manager own all risks?

It is possible, but weak. Risk owners should have authority over the risk. The security manager usually lacks it for business decisions, so business owners should own most risks.

Can a risk owner be a team?

No. Name a single accountable person or role, so it is clear who accepted the risk.

What if the owner refuses to accept the residual risk?

Then more treatment is needed, or the risk should go to a person with authority to decide, such as a senior manager or risk committee.

How often must owners review their risks?

The standard expects planned reviews; many organisations review at least annually and whenever a risk changes significantly.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.