Skip to main content
Category: Risk Assessment and Treatment

Risk Treatment Options

Also known as: Risk Treatment Strategies, Risk Treatment Methods
Simply put

Risk treatment options are the different choices an organization can make about how to handle a risk once it has been identified. These typically include reducing the risk, avoiding the activity that causes it, sharing or transferring it to another party, or accepting it as-is. The choice depends on the organization's priorities and how significant the risk is.

Formal definition

Risk treatment options are the set of actions available to modify a risk following risk assessment, generally aimed at reducing its likelihood, minimizing its impact, or otherwise changing how the risk is managed. Commonly cited options include risk avoidance (eliminating the activity or exposure), risk reduction or mitigation (applying controls to lower likelihood or impact), risk transfer or sharing (for example, through insurance or contractual arrangements), and risk acceptance (retaining the risk and its consequences). Some frameworks additionally describe increasing risk where doing so is expected to yield a benefit. In an ISO/IEC 27001 context, treatment options are selected during the risk treatment process, with resulting control selections documented and justified in the Statement of Applicability and informed by the risk assessment; the specific options and their application vary by organization, scope, and methodology.

Why it matters

Risk treatment options sit at the heart of any credible information security program because identifying a risk accomplishes little unless the organization makes a deliberate, documented decision about how to handle it. The way an organization chooses among reducing, avoiding, transferring, or accepting a risk directly shapes where it invests resources, which controls it implements, and which exposures it consciously retains. For compliance and GRC professionals, these decisions form the audit trail that demonstrates risk is being managed intentionally rather than ignored.

In an ISO/IEC 27001 context, the significance is heightened because treatment decisions drive the selection and justification of controls recorded in the Statement of Applicability, which in turn is central to certification against the ISMS requirements. A treatment decision that is poorly reasoned or undocumented can undermine the defensibility of the entire management system. In a SOC 2 examination, while the mechanics differ, the underlying discipline is similar: the controls a service organization operates typically reflect prior decisions about how identified risks are to be mitigated, and auditors evaluate whether those controls are suitably designed and, for a Type II, operating effectively over the review period.

Because the choice of treatment reflects organizational priorities and the significance of each risk, there is rarely a single correct answer. The value of framing treatment as a set of explicit options is that it forces accountability: someone must decide, and that decision can be reviewed, challenged, and revisited as circumstances change. Treating risk without this structure tends to leave gaps that surface later as unaddressed exposures.

Who it's relevant to

Compliance and GRC Managers
These professionals oversee the risk treatment process end to end, ensuring that each identified risk has a deliberate, documented decision behind it. In an ISO/IEC 27001 program they are typically responsible for the Statement of Applicability, where control selections arising from treatment decisions are recorded and justified, and for demonstrating that treatment reflects the organization's assessed risks and priorities.
Auditors and Assessors
Auditors review whether treatment decisions are reasoned, documented, and consistent with the risk assessment. In an ISO/IEC 27001 certification, they examine the linkage between assessed risks, chosen treatment options, and the controls justified in the Statement of Applicability. In a SOC 2 examination, they assess whether the controls reflecting those decisions are suitably designed and, for a Type II, operating effectively over the review period.
Risk Owners and Business Leaders
Risk owners are the individuals accountable for deciding how a given risk is treated, whether to avoid, reduce, transfer, accept, or in some frameworks increase it. Because the appropriate choice depends on organizational priorities and the significance of the risk, these decision-makers must weigh cost, benefit, and residual exposure, and remain prepared to revisit decisions as circumstances change.
Security Engineers and Control Implementers
When a treatment decision calls for risk reduction or mitigation, these practitioners translate it into operating controls that lower the likelihood or impact of the risk. Their work gives effect to abstract treatment choices and produces the evidence that auditors examine when evaluating control design and operating effectiveness.

Inside Risk Treatment Options

Risk Modification (Treatment/Mitigation)
Applying controls to reduce the likelihood or impact of a risk to an acceptable level. In an ISO/IEC 27001 ISMS, controls selected for this purpose are typically drawn from Annex A reference controls via the Statement of Applicability, though organizations may also define their own controls where appropriate.
Risk Retention (Acceptance)
A documented decision to accept a risk without further treatment, usually because it falls within defined risk acceptance criteria. This decision is typically recorded and approved by an appropriate risk owner as part of the ISMS clauses 4 through 10 requirements.
Risk Avoidance
Eliminating the risk by deciding not to start or to discontinue the activity that gives rise to it. This may involve withdrawing from a process, service, or technology whose associated risk cannot be reduced to an acceptable level.
Risk Sharing (Transfer)
Sharing the risk with another party, for example through insurance, contractual arrangements, or outsourcing. Sharing typically transfers financial or operational consequences but does not necessarily remove accountability, which often remains with the organization.
Statement of Applicability (SoA)
The document that records which Annex A reference controls have been selected, justified inclusions and exclusions, and their implementation status. It links the outcomes of risk treatment decisions to the specific controls chosen, and is a required element of the ISO/IEC 27001 ISMS.
Risk Treatment Plan
A plan documenting how selected treatment options will be implemented, including responsibilities, resources, and timelines. It typically also captures residual risk levels and the approval of relevant risk owners.

Common questions

Answers to the questions practitioners most commonly ask about Risk Treatment Options.

Are risk treatment options an ISO 27001 concept, a SOC 2 concept, or both?
Risk treatment options are formally defined within the ISO 27001 ISMS requirements (clauses 4 through 10), where the standard requires organizations to select treatment options following a risk assessment and to document their choices, including in the Statement of Applicability. SOC 2 does not prescribe a specific set of named treatment options in the same way; instead, a SOC 2 examination evaluates whether the controls in scope are suitably designed and, for a Type II, operating effectively against the selected Trust Services Criteria. While both frameworks involve managing risk, the structured menu of treatment options is characteristic of the ISO 27001 approach, and the two should not be treated as interchangeable.
Does choosing to 'accept' a risk mean an organization is ignoring it or failing an audit?
No. Risk acceptance is a legitimate, documented treatment decision rather than a lapse. In most ISO 27001 engagements, accepting a risk means the organization has evaluated it, determined it falls within its risk appetite, and recorded the rationale and the appropriate authority approving it. What auditors and certification bodies typically look for is evidence that the decision was made deliberately and documented, not that every risk was reduced. An undocumented or unconsidered risk is a different matter from a consciously accepted one.
How do risk treatment decisions connect to the Statement of Applicability in ISO 27001?
In ISO 27001, the risk assessment informs which risks require treatment, and the treatment decisions drive the selection of reference controls from Annex A. The Statement of Applicability documents which Annex A controls are included or excluded and the justification for each. Because Annex A was restructured in the 2022 revision, the specific controls referenced depend on the edition being used, so it is good practice to state the version. The Statement of Applicability effectively records the outcome of the treatment process for the controls dimension of the ISMS.
What evidence should we retain to demonstrate our risk treatment decisions during an audit?
Depending on scope and the expectations of the certification body or auditor, organizations typically retain the risk assessment results, the documented treatment option selected for each risk, the rationale, the approving authority, and any residual risk acceptance sign-off. Where controls are chosen to reduce risk, evidence linking the treatment decision to the implemented controls and to the Statement of Applicability is generally helpful. The precise expectations vary by certification body and engagement, so confirming documentation requirements in advance is advisable.
How often should risk treatment decisions be reviewed?
Review frequency is set by the organization's own ISMS processes and risk management approach rather than a single fixed interval. In most engagements, treatment decisions are revisited when the risk assessment is updated, when significant changes occur to the environment or scope, or on a periodic cycle defined by the organization. The goal is to keep treatment decisions aligned with the current risk picture, and the specifics depend on scope and internal policy.
Can a single risk be addressed with more than one treatment option?
Yes, in many cases a risk is managed through a combination of approaches, such as reducing part of the exposure through controls while transferring another portion, or reducing a risk and then accepting the remaining residual risk. The appropriate mix depends on the organization's risk appetite, scope, and the outcome of the risk assessment. What matters is that the combined decision and any residual risk are documented and appropriately approved.

Common misconceptions

Every identified risk must be mitigated by applying a control.
Modification is only one of several treatment options. Depending on scope and risk acceptance criteria, an organization may also retain, avoid, or share a risk. Retention (acceptance) is a legitimate documented option, provided it is approved by an appropriate risk owner.
Risk treatment in ISO/IEC 27001 means implementing all Annex A controls.
Annex A is a list of reference controls that are selected based on the risk assessment and documented in the Statement of Applicability. Controls may be included or excluded with justification, and organizations may define additional controls not listed in Annex A. Note that Annex A was restructured in the 2022 revision, so control counts and structure depend on the edition.
Sharing or transferring a risk removes the organization's responsibility for it.
Risk sharing (for example via insurance or outsourcing) may transfer financial or operational consequences, but accountability for the risk typically remains with the organization. The treatment decision should reflect this residual accountability.

Best practices

Evaluate all treatment options (modify, retain, avoid, share) for each significant risk rather than defaulting to control implementation, and document the rationale for the chosen option.
Record risk acceptance decisions formally and obtain approval from an appropriate risk owner, in line with defined risk acceptance criteria.
Maintain a Statement of Applicability that traces each selected or excluded Annex A control back to the risk assessment, citing the specific ISO/IEC 27001 edition to keep control references accurate.
Capture residual risk levels in the risk treatment plan so that stakeholders understand what remains after controls are applied.
Where risk is shared with a third party, document that accountability typically remains with the organization and reflect this in contractual and monitoring arrangements.
Review and update treatment decisions periodically and when scope, threats, or the ISMS environment change, since appropriate treatment depends on scope and current risk conditions.