Evidence
What belongs in a risk treatment plan
The assessment identifies risk. The treatment plan is where somebody decides what to do about each one, and is accountable for it.
Facts checked — 2026-09-11
What are the risk treatment options?
Each risk is treated by modifying it (applying controls), sharing it (insurance, a supplier), avoiding it (stopping the activity), or retaining it (accepting). All four are legitimate; what is not legitimate is a plan where every risk is silently assumed to be treated by a control nobody has built.
Acceptance is the one most often left implicit, and it is the one auditors probe. An accepted risk needs a named person with the authority to accept it, a date, and ideally a review point. That is a defensible decision. An unmentioned risk is not.
The bottom line
Name an owner and a date for every risk, including the accepted ones. Especially the accepted ones.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.