A Comprehensive Guide to Creating a Risk Treatment Plan
This guide shows how to document, assign, and track the way your organization responds to identified risks.

This guide shows how to document, assign, and track the way your organization responds to identified risks.

A risk treatment plan documents how your organization will carry out its response to a specific risk. It names the option chosen, assigns an owner, sets a deadline, and tracks the result.
Where a risk assessment tells you how serious a risk is, and risk treatment tells you which responses to use, the plan is the documentation that proves you actually did something about it. Auditors don't just want to see that a risk was scored. They want to see who owns it, what's being done, and by when.
Writing the plan itself comes down to three steps: work out which risks need one, assign the work, then get it down on paper in a way that holds up later. This sits inside the wider risk management process, which also covers how a risk gets identified and scored before it ever reaches this stage.

3 Steps to Writing a Risk Treatment Plan
Not every risk on your risk register needs a formal treatment plan. Start with anything that scored above your organization's risk appetite threshold, then work down the list by severity. A near-miss with a low likelihood score can usually wait. A control failure with a high severity score can't.
Every action needs a named owner, not a department. "IT" isn't accountable for anything, a named person is. Assign someone with the authority to actually implement the control, not just report on it, and give them a realistic deadline based on the risk's severity.
Write the plan in the same place you track the risk itself, whether that's a risk register or a dedicated GRC platform, so treatment status stays visible alongside the original risk score. Use your risk assessment matrix to confirm the residual risk rating once controls are in place. That number tells you whether the treatment actually worked or just felt like it did.
Neither standard mandates a specific template, but both expect specific evidence. Structure your plan around these three points and it satisfies both without extra paperwork.
Clause 6.1.3 requires organizations to define a risk treatment process, select controls, typically from Annex A, and produce a Statement of Applicability. Your plan is the evidence that the controls named in the SoA are actually being implemented, not just listed. For IT and cybersecurity risks specifically, organizations increasingly compare their Annex A controls against the NIST Cybersecurity Framework when deciding which controls to apply.
ISO 31000:2018 frames treatment as selecting and implementing options to modify risk, then reviewing whether that modification worked. Structuring your plan around that same sequence, chosen option, action taken, review scheduled, keeps it aligned with the standard without extra paperwork.
The SoA lists which Annex A controls apply to your organization and why. Your risk treatment plan is the operational layer underneath it: for every control the SoA claims you've applied, the plan should show who's responsible, when it was implemented, and what evidence backs it up. An SoA with no matching plan is one of the first things an auditor will flag.
A treatment plan isn't finished once it's signed off. Set a review cadence based on the risk's severity, quarterly for high-severity risks, annually for low ones, and re-score the residual risk at each review. If the number hasn't moved, the treatment isn't working.
The person who wrote the plan isn't always the person who should review it. Build in a second reviewer, ideally someone outside the original owner's team, so treatment decisions don't get rubber-stamped by the same person who made them.
Mitti (by SafetyCulture) is a workplace operations platform adopted across industries such as manufacturing, mining, construction, retail, and hospitality. It’s designed to equip leaders and teams with the tools to do their best work– to the safest and highest standard.
Our solution is designed to help drive improvements in your enterprise operations.
✓ Save time and reduce costs
✓ Stay on top of risks and incidents
✓ Boost productivity and efficiency
✓ Enhance communication and collaboration
✓ Discover improvement opportunities
✓ Make data-driven business decisions