Practical toolGlobalISO/IEC 27001

ISO/IEC 27001 Risk Treatment Register Workflow

Use one traceable workflow from assessed risk to treatment option, necessary control, implementation action, residual-risk decision, and approval.

The register supports the risk-treatment plan but does not replace the SoA: keep risk actions and approvals linked to Annex A applicability, exclusions, status, and control evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ISO/IEC 27001 requires documented risk-assessment results, a risk-treatment plan, risk-owner approval, acceptance of , and documented treatment results. It does not require a document named 'risk-treatment register.' Use this register format when one controlled record helps connect those required outputs from assessed risk through implementation and review.

Section 1

Which decisions belong in a risk-treatment register?

Begin with an assessed information security risk, its owner, level, and priority under the organization's documented criteria. Then capture the chosen treatment option, every necessary control, the Annex A completeness comparison, planned actions, owners, resources, target dates, and dependencies. ISO/IEC 27001 requires appropriate treatment options but does not prescribe labels such as reduce, avoid, share, or accept.

After implementation, record results and the recalculated . Close the decision only when the risk owner has approved the treatment plan and accepted the residual risk under the organization's criteria. If implementation is incomplete, the rating exceeds the acceptance criteria, or the risk owner refuses acceptance, keep the record open and revise the treatment, resources, deadline, or escalation.

  • Keep treatment status distinct from risk status and control implementation status.
  • Link necessary controls to the SoA, including controls outside Annex A.
  • Record risk-owner approval, acceptance date, assumptions, and reassessment triggers.
Section 2

Which fields preserve the evidence chain?

Stable identifiers are a practical traceability control, not a prescribed ISO field. Use them to connect the assessment, treatment plan, SoA, implementation tickets, operating evidence, effectiveness result, and acceptance when those records live in different systems.

Preserve both planned and actual dates and both pre-treatment and residual ratings. That distinction prevents incomplete actions from appearing as completed risk reduction.

  • Risk fields: scenario, scope, owner, criteria, likelihood, consequence, level, and priority.
  • Treatment fields: option, control, SoA link, action, owner, resource, dependency, target, and actual completion.
  • Result fields: implementation evidence, effectiveness test, residual rating, exception, and open gap.
  • Approval fields: risk owner, plan approval, residual acceptance, date, and review trigger.
Recommended next step

Track treatment from assessment to acceptance

Assign actions, connect necessary controls to the SoA, retain implementation evidence, and record risk-owner approval and residual-risk acceptance.

Section 3

How should teams route assessment, treatment, and approval?

The assessor applies the approved method and identifies the risk owner. The organization chooses who proposes treatment and implements controls. Clause 6.1.3 requires the risk owner to approve the treatment plan and accept the ; it does not prescribe a committee, assessor, or control-owner title.

Governance can set thresholds and escalation paths, but it should not erase accountability. A committee approval without a named risk owner does not satisfy the standard's explicit risk-owner approval and acceptance step.

  • Assessment gate: valid, comparable result and named owner.
  • Plan gate: approved treatment, necessary controls, SoA impact, resources, and deadlines.
  • Implementation gate: evidence and effectiveness result support the revised rating.
  • Acceptance gate: named risk owner accepts and records the next review.
Section 4

Which register mistakes hide ownership or residual risk?

Common failures are using a generic 'security' owner, recording only the target rating, treating planned controls as implemented, or closing treatment without evidence and residual-risk acceptance.

Another failure is limiting controls to Annex A. Necessary controls can be designed by the organization or identified from any source. Annex A is then used to check whether a necessary control was overlooked.

  • Do not cite a standard title as evidence that a process is operating.
  • Do not reuse an old audit artifact after the scope, service, supplier, or risk has changed.
  • Do not hide exceptions; record them as risk acceptance, corrective action, or management-review inputs.
Section 5

Which events should reopen a treatment record?

ISO/IEC 27001 requires risk assessment at planned intervals and when significant changes are proposed or occur. Reopen the register entry when that assessment changes the risk result or when scope, assets, suppliers, threats, vulnerabilities, incidents, controls, or implementation evidence invalidate the recorded decision.

Preserve the old rating and approval as history, calculate the current consistently, and route changed treatment or acceptance decisions to the accountable risk owner.

  • Set a review date and a change-trigger rule.
  • Track findings until closure and connect them to corrective actions or risk acceptance.
  • Use management review to decide needed ISMS changes and improvement actions, including resources, scope, risk criteria, or evidence controls where relevant.
Primary sources

References and citations

iso.org
Referenced sections
  • This source is the governing requirements context for ISO/IEC 27001 scope, control governance, and review cadence in ISMS operations.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • The ISO/IEC 27002 standard page identifies the control-guidance standard used to connect risk treatment choices to practical control evidence.
"Information security controls"
iso.org
Referenced sections
  • The ISO/IEC 27005 standard page identifies the risk-management guidance used to structure information-security risk assessment and treatment workflow decisions.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit and Management Review Guide
Keep ISO/IEC 27001 internal audit and management review distinct and connected: independent audit evidence, top-management decisions, corrective actions, resources, and improvement records.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.