A Comprehensive Guide to Creating a Risk Treatment Plan

This guide shows how to document, assign, and track the way your organization responds to identified risks.

A group of colleagues reviewing data on a tablet during a meeting.

What is a risk treatment plan?

A risk treatment plan documents how your organization will carry out its response to a specific risk. It names the option chosen, assigns an owner, sets a deadline, and tracks the result.

Where a risk assessment tells you how serious a risk is, and risk treatment tells you which responses to use, the plan is the documentation that proves you actually did something about it. Auditors don't just want to see that a risk was scored. They want to see who owns it, what's being done, and by when.

How to write a risk treatment plan: step by step

Writing the plan itself comes down to three steps: work out which risks need one, assign the work, then get it down on paper in a way that holds up later. This sits inside the wider risk management process, which also covers how a risk gets identified and scored before it ever reaches this stage.

risk-treatment-plan-infog

3 Steps to Writing a Risk Treatment Plan

Step 1: Identify and prioritize which risks need a plan

Not every risk on your risk register needs a formal treatment plan. Start with anything that scored above your organization's risk appetite threshold, then work down the list by severity. A near-miss with a low likelihood score can usually wait. A control failure with a high severity score can't.

Step 2: Assign treatment actions and ownership

Every action needs a named owner, not a department. "IT" isn't accountable for anything, a named person is. Assign someone with the authority to actually implement the control, not just report on it, and give them a realistic deadline based on the risk's severity.

Step 3: Document and implement the plan

Write the plan in the same place you track the risk itself, whether that's a risk register or a dedicated GRC platform, so treatment status stays visible alongside the original risk score. Use your risk assessment matrix to confirm the residual risk rating once controls are in place. That number tells you whether the treatment actually worked or just felt like it did.

Take Control of Your Risk Landscape

Identify and proactively mitigate risks to enhance organizational resilience and decision-making.

Risk treatment plan requirements for ISO 27001 and ISO 31000

Neither standard mandates a specific template, but both expect specific evidence. Structure your plan around these three points and it satisfies both without extra paperwork.

ISO 27001 Clause 6.1.3 explained

Clause 6.1.3 requires organizations to define a risk treatment process, select controls, typically from Annex A, and produce a Statement of Applicability. Your plan is the evidence that the controls named in the SoA are actually being implemented, not just listed. For IT and cybersecurity risks specifically, organizations increasingly compare their Annex A controls against the NIST Cybersecurity Framework when deciding which controls to apply.

ISO 31000's risk treatment process

ISO 31000:2018 frames treatment as selecting and implementing options to modify risk, then reviewing whether that modification worked. Structuring your plan around that same sequence, chosen option, action taken, review scheduled, keeps it aligned with the standard without extra paperwork.

The Statement of Applicability (SoA) and how it connects

The SoA lists which Annex A controls apply to your organization and why. Your risk treatment plan is the operational layer underneath it: for every control the SoA claims you've applied, the plan should show who's responsible, when it was implemented, and what evidence backs it up. An SoA with no matching plan is one of the first things an auditor will flag.

Transform Your Compliance Strategy

Automate tracking and harness digital workflows to ensure compliance with evolving regulations.

How to monitor and review your plan

Tracking effectiveness over time

A treatment plan isn't finished once it's signed off. Set a review cadence based on the risk's severity, quarterly for high-severity risks, annually for low ones, and re-score the residual risk at each review. If the number hasn't moved, the treatment isn't working.

Roles and responsibilities in ongoing treatment

The person who wrote the plan isn't always the person who should review it. Build in a second reviewer, ideally someone outside the original owner's team, so treatment decisions don't get rubber-stamped by the same person who made them.

Why use Mitti (by SafetyCulture)?

Mitti (by SafetyCulture) is a workplace operations platform adopted across industries such as manufacturing, mining, construction, retail, and hospitality. It’s designed to equip leaders and teams with the tools to do their best work– to the safest and highest standard.

Our solution is designed to help drive improvements in your enterprise operations.

Save time and reduce costs
✓ Stay on top of risks and incidents
✓ Boost productivity and efficiency
✓ Enhance communication and collaboration
✓ Discover improvement opportunities
✓ Make data-driven business decisions

FAQs about risk treatment plans

GC

Article by

Gabrielle Cayabyab

Mitti (by SafetyCulture) Content Specialist

View author profile