A risk treatment plan records what you have decided to do about each identified risk, who owns that decision, and by when.
The four options
- Modify — apply controls to reduce likelihood or impact. The most common.
- Retain — accept the risk knowingly, at the appropriate level of authority.
- Avoid — stop doing the activity that creates the risk.
- Share — transfer part of the consequence, typically through insurance or contract.
Retaining a risk is a legitimate treatment, not a failure. What matters is that acceptance is a documented decision by someone with the authority to make it, rather than an oversight.
Risk owners
ISO 27001 requires risk owners to approve the plan and to accept residual risks. The risk owner is the person accountable for the risk, not the person implementing the control — and in practice they should be senior enough that accepting the risk is genuinely their call.
This is a frequent audit finding: plans approved by the information security manager alone, for risks that belong to operations, finance or the board.
Its relationship to the SoA
The risk treatment plan says what you will do about your risks. The Statement of Applicability says which Annex A controls apply and why. They are different documents that must tell a consistent story — a control marked applicable in the SoA with no corresponding treatment, or a treatment referencing a control excluded in the SoA, is an obvious inconsistency.
Residual risk
After treatment, some risk remains. Recording residual risk and having it formally accepted closes the loop, and is the part most often left incomplete.