The ISO 27001 risk treatment plan
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · ISO 27001
The risk assessment finds the risks; the risk treatment plan does something about them. One without the other is half a control.
From assessment to action
A risk assessment that identifies risks but does nothing about them is incomplete. The risk treatment plan is the bridge: for each risk you decide to treat, it records the treatment option (reduce, accept, avoid, transfer) and the specific controls that implement it. It is where risk management becomes a to-do list.
How it relates to the SoA
The risk treatment plan and the Statement of Applicability are tightly linked. Treating a risk by reducing it usually means selecting Annex A controls — which then appear as "applicable" in the SoA with the risk as their justification. The plan explains why the SoA looks the way it does.
What each entry holds
For each treated risk: the risk, the chosen treatment, the controls (often Annex A references) that implement it, an owner, a target date, and the residual risk after treatment. Accepted risks should carry an explicit sign-off by someone with authority to accept them.
Keep it alive
Risks evolve and treatments complete or change, so the plan is not a one-time artifact — it is reviewed alongside the risk assessment. A stale treatment plan that no longer reflects reality is a finding. SentinelPanda links risks, treatments, controls, and the SoA so the plan stays consistent as things change.