Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 risk treatment plan diagram showing the six steps of clause 6.1.3

ISO 27001 Risk Treatment Plan: The Complete 2026 Guide

An ISO 27001 risk treatment plan is the document that turns your risk assessment into a dated, owned and funded list of actions, and it is one of the first records a certification auditor asks to see. Get it right and Stage 2 becomes a walkthrough of work you have already finished. Get it wrong and you spend two days explaining why forty risks have no owner and no due date.

This guide covers what ISO/IEC 27001:2022 actually requires of an ISO 27001 risk treatment plan, which fields it needs, how it differs from the risk register and the Statement of Applicability, and the five mistakes that reliably become findings. It is written for the person who has to produce the document this quarter, not for someone browsing definitions.

What ISO 27001 Requires From a Risk Treatment Plan

The requirement sits in clause 6.1.3 of ISO/IEC 27001:2022, the third edition of the standard, published in October 2022. The clause sets out six lettered steps that follow on from the risk assessment in clause 6.1.2:

  1. 6.1.3 a) Select appropriate information security risk treatment options, taking account of the risk assessment results.
  2. 6.1.3 b) Determine all controls necessary to implement the treatment options you chose.
  3. 6.1.3 c) Compare those controls against Annex A and verify that no necessary control has been omitted.
  4. 6.1.3 d) Produce a Statement of Applicability.
  5. 6.1.3 e) Formulate an information security risk treatment plan.
  6. 6.1.3 f) Obtain risk owners approval of the plan and their acceptance of the residual information security risks.

Two things follow from that structure. First, the plan is mandatory documented information: clause 6.1.3 requires records of the risk treatment process to be retained, and clause 8.3 requires you to implement the plan and keep evidence of the results. Second, the ISO 27001 risk treatment plan is not the Statement of Applicability. They are separate outputs of the same clause and auditors sample them separately.

Pay attention to the order. Controls come out of your treatment decisions first; Annex A is used afterwards as a completeness check. Annex A holds 93 controls in four themes: 37 organizational, 8 people, 14 physical and 34 technological. It is a catalogue to check yourself against, not a shopping list to start from. An ISO 27001 risk treatment plan assembled by working down Annex A instead of up from real risks is the most common structural error auditors see, because it produces controls with no traceable risk behind them.

What an ISO 27001 Risk Treatment Plan Must Contain

The standard prescribes no template, no scoring scale and no file format. A spreadsheet is perfectly acceptable. What matters is that every treated risk can be traced from the assessment through to a control, an owner, a date and a residual decision. These are the fields an ISO 27001 risk treatment plan needs in order to survive an audit:

FieldWhy the auditor cares
Risk IDTies the row back to the risk assessment. Without it there is no traceability.
Risk description and assetShows the risk is real and scoped, not generic boilerplate.
Risk ownerClause 6.1.3 f) requires named approval. A department is not an owner.
Inherent ratingEstablishes the starting point that treatment is supposed to move.
Treatment optionModify, avoid, share or retain. Evidence of a conscious decision.
Annex A control referenceLinks the row to the Statement of Applicability and proves clause 6.1.3 c) was done.
Action to be takenThe actual work. A control number alone is not a plan.
Action ownerOften different from the risk owner. This is who does the work.
Target dateDates are what turn a wish list into a plan. Overdue rows must be explained.
Resources or budgetDemonstrates management support under clause 5.1.
Residual ratingShows the treatment achieved something measurable.
Residual risk accepted by, and dateThe clause 6.1.3 f) sign-off. Missing dates are a classic minor nonconformity.
Status and evidence referencePoints the auditor at the ticket, invoice or config that proves completion.

If your ISO 27001 risk assessment already carries the first four columns, the ISO 27001 risk treatment plan can be an extension of the same workbook rather than a separate file. Auditors do not mind one document or two, as long as the approval and the dates are unambiguous.

The Four Risk Treatment Options

Every risk you decide to treat has to land in one of four buckets, and every row of an ISO 27001 risk treatment plan should say which one. Naming the option explicitly in each row takes seconds and closes off an entire line of audit questioning.

OptionWhat it meansEvidence the auditor expects
Modify (mitigate)Apply controls to reduce likelihood or impact.Implemented control, plus a residual rating that is lower than the inherent one.
AvoidStop or change the activity that creates the risk.Decision record, and proof the activity or system was actually retired.
Share (transfer)Move part of the exposure to an insurer or supplier.Signed contract or policy. Note that reputational and regulatory exposure rarely transfers.
Retain (accept)Live with the risk as it stands.Named risk owner acceptance with a date, and a review trigger.

Retain is legitimate and under-used. Accepting a low risk in writing is far stronger evidence of a working ISMS than inventing a control you have no intention of operating. What auditors object to is silent acceptance, where a risk simply stops being mentioned.

How to Build an ISO 27001 Risk Treatment Plan in Six Steps

  1. Freeze the risk assessment. Treatment against a moving list produces mismatched IDs. Version the assessment, date it, and treat that version.
  2. Sort by inherent rating and treat top-down. Most organizations have a small number of risks that carry most of the exposure. Deal with those first so that early budget conversations are about the risks that matter.
  3. Choose the option before the control. Decide modify, avoid, share or retain, then pick controls. Doing it the other way round is how teams end up implementing controls nobody needed.
  4. Run the Annex A comparison. List the controls you determined, walk the 93 Annex A controls, and record any you added as a result. This step is clause 6.1.3 c) and it feeds directly into the Statement of Applicability. Keep a note of the comparison itself, because auditors ask how you did it.
  5. Assign owners, dates and budget. Every row gets a named action owner and a target date that someone has agreed to. Rows with a target date in the past and no explanation are the fastest route to a finding.
  6. Get risk owner approval in writing. Sign-off on both the ISO 27001 risk treatment plan and the residual risks, with names and dates. Minuted approval at a management review meeting is the cleanest form of this evidence.

After approval the plan becomes an operating document, not an archive. Clause 8.3 expects the ISO 27001 risk treatment plan to be executed and the results retained, so review it on the same cadence as your management reviews and update the status column as work lands.

Risk Register vs Statement of Applicability vs ISO 27001 Risk Treatment Plan

These three documents overlap enough that people merge them and then cannot answer basic audit questions. Here is the split that works:

Risk registerRisk treatment planStatement of Applicability
Clause6.1.26.1.3 e)6.1.3 d)
Organized byRiskActionAnnex A control
AnswersWhat could go wrong and how bad is it?Who is fixing what, by when, and who accepted what is left?Which controls apply, which do not, and why?
Mandatory recordYesYesYes, named explicitly in the standard
Changes whenNew risks or ratings emergeActions complete or slipApplicability or implementation status changes

All three sit on the list of ISO 27001 mandatory documents, and all three get sampled at Stage 2.

Five Mistakes That Turn Into Audit Findings

  1. No named residual risk acceptance. Clause 6.1.3 f) is explicit. A plan with no approver, or with approval by a job title and no date, is a minor nonconformity waiting to happen.
  2. Target dates that have all passed. An expired plan tells the auditor the ISMS is not being operated. Either reforecast the dates through your change process or record why the action was dropped.
  3. Controls with no parent risk. If a row cites Annex A 8.16 but no risk ID, the auditor cannot verify clause 6.1.3 b), and the whole traceability chain is questioned.
  4. Residual ratings identical to inherent ratings. If treatment moved nothing, either the control is not implemented or the scoring is decorative. Both are worth explaining before the audit rather than during it.
  5. A plan that contradicts the Statement of Applicability. A control marked implemented in the SoA but still open in the plan is the single easiest inconsistency for an auditor to find. Reconcile the two before your ISO 27001 internal audit, not after.

Frequently Asked Questions

Is an ISO 27001 risk treatment plan mandatory?

Yes. Clause 6.1.3 e) requires you to formulate one, and clause 6.1.3 requires documented information about the risk treatment process to be retained. There is no route to certification without it.

Can the risk treatment plan and the risk register be the same document?

Yes, provided the combined document carries treatment options, actions, owners, dates and residual acceptance. Many organizations use one workbook with additional columns. The standard cares about content and approval, not file count.

Who has to approve the plan?

Risk owners. The person accountable for the asset or process, not the person who wrote the plan. In smaller companies that is often a director or the CTO, and approval is usually minuted at a management review.

How long does it take to produce?

For a small or mid-sized organization with a completed risk assessment, drafting the plan typically takes one to three weeks of part-time effort, most of it spent chasing owners for realistic dates rather than writing. Executing the plan is what takes months, and it is the main driver of the overall ISO 27001 certification timeline.

Does the plan need updating after certification?

Yes. Surveillance audits check that the plan is live: new risks treated, completed actions closed with evidence, and residual acceptances refreshed. A plan that has not changed since the certificate was issued is a red flag.

Getting the Documentation Right

Most of the pain in this process comes from building the structure from scratch while also doing the analysis. The ISO 27001 Toolkit from Governance Docs includes a ready-made ISO 27001 risk treatment plan, a risk register, a risk assessment worksheet and a Statement of Applicability that already reference each other correctly, alongside 162 editable ISO/IEC 27001:2022 templates for $99. If you would rather start from a working document than a blank page, that is where to begin.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.