Skip to content

The ISO 27001 risk treatment plan

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001

The risk assessment finds the risks; the risk treatment plan does something about them. One without the other is half a control.

From assessment to action

A risk assessment that identifies risks but does nothing about them is incomplete. The risk treatment plan is the bridge: for each risk you decide to treat, it records the treatment option (reduce, accept, avoid, transfer) and the specific controls that implement it. It is where risk management becomes a to-do list.

How it relates to the SoA

The risk treatment plan and the Statement of Applicability are tightly linked. Treating a risk by reducing it usually means selecting Annex A controls — which then appear as "applicable" in the SoA with the risk as their justification. The plan explains why the SoA looks the way it does.

What each entry holds

For each treated risk: the risk, the chosen treatment, the controls (often Annex A references) that implement it, an owner, a target date, and the residual risk after treatment. Accepted risks should carry an explicit sign-off by someone with authority to accept them.

Keep it alive

Risks evolve and treatments complete or change, so the plan is not a one-time artifact — it is reviewed alongside the risk assessment. A stale treatment plan that no longer reflects reality is a finding. SentinelPanda links risks, treatments, controls, and the SoA so the plan stays consistent as things change.

ISO 27001 risk assessment ISO 27001 Statement of Applicability How to build a risk register

Run your compliance program in one workspace.