Risk Treatment: Strategies and Plans Explained

Understand the importance of risk treatment and the four treatment options for effective strategizing.

A person in glasses holding a pen thoughtfully while working at a laptop.

What is risk treatment?

Risk treatment is the step in the risk management process where you choose and apply a specific response to a risk you've already identified and assessed. Under ISO 31000:2018, that response falls into one of four categories: avoid, reduce, transfer, or accept. It's essentially the strategy that determines what to do next once risks have been raised.

The four risk treatment options

These four options sit inside the widertype: entry-hyperlink id: 5Zukr69JCmyDNwDSYQRrVi, which also covers how a risk gets identified and scored before it ever reaches the treatment stage. Picking the right option isn't a formula. A risk manager weighs the cost of treatment against the risk's likelihood and impact, then checks the choice against the organization's risk appetite before it goes into the risk register.

Risk treatment Infographic

The Fours Ways to Treat a Risk

  1. Avoid (terminate). Stop the activity that creates the risk. This works best for high-impact threats where no amount of control brings the risk down to an acceptable level, such as pulling out of a contract with unmanageable liability.

  2. Reduce (mitigate). Add controls that lower the likelihood or the impact of the risk, without removing the activity itself. Most day-to-day treatment falls here.

  3. Transfer (share). Shift some or all of the financial impact to a third party, usually through insurance, a contract clause, or outsourcing.

  4. Accept (tolerate). Take no further action, because the cost of treating the risk outweighs the likely loss. This still needs a documented rationale, not silence.

Picking the right option isn't a formula. A risk manager weighs the cost of treatment against the risk's likelihood and impact, then checks the choice against the organization's risk appetite before it goes into the risk register. Another example is a manufacturer dealing with repeated forklift near-misses might reduce the risk with slower speed limits and pedestrian barriers, transfer part of it through equipment insurance, and accept the small residual risk of a rare mechanical failure once those controls are in place.

Take Control of Your Risk Landscape

Seamlessly identify and proactively mitigate risks to enhance organizational resilience and decision-making.

Risk treatment vs. risk mitigation

The two terms get used interchangeably, and that's where the confusion starts. Risk mitigation isn't a separate process. It's acts as one of the four treatment options: reduce.

Risk treatment is the umbrella decision covering all four responses. Risk mitigation is what happens specifically when a team chooses to reduce a risk's likelihood or impact throughtype: entry-hyperlink id: 2mgvHDT4SwIU0xoTfDQbA9, like installing fire suppression systems that cut a warehouse's fire risk score in half.

Put simply, every mitigation activity is a form of treatment, but not every treatment activity is mitigation. Transferring a risk to an insurer, or accepting it outright, is treatment without any mitigation involved at all.

Risk treatment strategies

Choosing a strategy is rarely just about matching a risk to one of the four categories. Most decisions come down to weighing several factors together:

  • The cost of treatment against the size of the potential loss

  • The organization's risk appetite and tolerance thresholds

  • Regulatory or contractual requirements tied to the risk

  • Reputational or stakeholder impact if the risk materializes

  • Whether the business has the resources or expertise to execute the treatment

A company facing a potential data breach illustrates how these factors combine in practice. It might reduce the risk with encryption and access controls, transfer part of it through cyber insurance, and accept the small residual risk of an extremely low-probability exploit once those controls are in place. For cybersecurity risks specifically, frameworks such as the NIST Cybersecurity Framework provide additional guidance on selecting and prioritizing treatment strategies based on severity.

The risk treatment process

Selecting a strategy is only one part of the process. In practice, treatment follows a consistent sequence:

  1. Identify the risk, pulled from thetype: entry-hyperlink id: 7BxL7DvMj8vwCayCDkvrB7or register

  2. Analyze it, assessing likelihood and potential impact

  3. Select a treatment option, one of the four covered above

  4. Document the plan, including a named owner, a target completion date, the resources required, and a residual risk rating

  5. Monitor and review, checking whether the treatment is still working as conditions change

This sequence mirrors the treatment step defined in ISO 31000:2018, which calls for selecting and implementing a response, then reviewing whether it worked. Skipping the review step is the most common failure point, since risk levels shift as controls age or circumstances change.

Byblos Construction digitized safety checklists, compliance checks, and risk assessments with Mitti (by SafetyCulture), letting teams quickly notify leaders of risks for faster action and fewer blind spots. This improved risk management, communication, and visibility for safer job sites.

byblos constructions mitti customer story western australia

Why use Mitti (by SafetyCulture)?

Mitti (by SafetyCulture) is a workplace operations platform adopted across industries such as manufacturing, mining, construction, retail, and hospitality. It’s designed to equip leaders and teams with the tools to do their best work– to the safest and highest standard.

Our solution is designed to help drive improvements in your enterprise operations.

Save time and reduce costs
✓ Stay on top of risks and incidents
✓ Boost productivity and efficiency
✓ Enhance communication and collaboration
✓ Discover improvement opportunities
✓ Make data-driven business decisions

FAQs about risk treatment

GC

Article by

Gabrielle Cayabyab

Mitti (by SafetyCulture) Content Specialist

View author profile