Skip to content
SecuriFii

Evidence

What belongs in a risk treatment plan

The assessment identifies risk. The treatment plan is where somebody decides what to do about each one, and is accountable for it.

Facts checked2026-09-11

What are the risk treatment options?

Each risk is treated by modifying it (applying controls), sharing it (insurance, a supplier), avoiding it (stopping the activity), or retaining it (accepting). All four are legitimate; what is not legitimate is a plan where every risk is silently assumed to be treated by a control nobody has built.

Acceptance is the one most often left implicit, and it is the one auditors probe. An accepted risk needs a named person with the authority to accept it, a date, and ideally a review point. That is a defensible decision. An unmentioned risk is not.

The bottom line

Name an owner and a date for every risk, including the accepted ones. Especially the accepted ones.

Related insights