Skip to main content
Category: Risk Assessment and Treatment

Risk Treatment Plan

Also known as: RTP, Risk Treatment Plan, RTP
Simply put

A Risk Treatment Plan is a structured document that sets out the specific actions an organization will take to address each risk it has identified. For every risk, the plan describes how it will be handled, acting as a roadmap for putting the chosen responses into practice. It typically covers how controls will be implemented to reduce either the likelihood or the impact of a risk.

Formal definition

A Risk Treatment Plan (RTP) is a documented roadmap that specifies how identified risks from a risk assessment will be treated, detailing the controls or actions to be implemented to reduce the likelihood or impact of each risk. In the context of ISO/IEC 27001, the RTP operationalizes the outcomes of the risk assessment and risk treatment process within the ISMS, translating treatment decisions into planned implementation activities; it works in conjunction with the Statement of Applicability, which records the selection and justification of Annex A reference controls. The RTP's scope and level of detail vary depending on the organization's risk methodology and scoping decisions, and the plan emphasizes implementation as the critical component rather than documentation alone.

Why it matters

The Risk Treatment Plan is where an ISO/IEC 27001 Information Security Management System (ISMS) moves from analysis to action. A risk assessment identifies and evaluates risks, but on its own it changes nothing; the RTP translates those findings into concrete, planned activities that reduce the likelihood or impact of each risk. Without a documented plan tying treatment decisions to specific actions, an organization has opinions about its risks rather than a defensible approach to managing them.

Because the RTP is a roadmap for implementation, its value depends heavily on execution rather than paperwork. A well-written plan that is never carried out provides little protection and, during a certification audit, can expose a gap between what the organization intended and what it actually did. Certification bodies typically expect to see evidence that treatment actions have been progressed, not simply that a plan exists on paper. In this sense the RTP serves both as an internal management tool and as auditable evidence that the risk treatment process is operating.

The RTP also works alongside the Statement of Applicability (SoA), which records which Annex A reference controls have been selected and the justification for their inclusion or exclusion. The two documents are complementary: the SoA captures the selection and rationale for controls, while the RTP describes how the chosen treatments will be put into practice. Note that an RTP addresses only the risks identified within the defined scope of the ISMS and using the organization's chosen methodology; it does not guarantee that all risks are eliminated or that no incidents will occur.

Who it's relevant to

ISMS Managers and Information Security Leads
Those responsible for running the ISMS use the RTP as their central roadmap for putting risk treatment decisions into practice, tracking each planned action to completion and keeping the plan aligned with the risk assessment and Statement of Applicability.
ISO 27001 Auditors and Certification Bodies
Auditors reviewing an ISMS typically examine the RTP as evidence that identified risks are being treated in a structured way, and look for signs that planned actions are being implemented rather than existing only on paper. The RTP applies only to risks within the defined ISMS scope.
Risk Owners
Individuals accountable for specific risks rely on the RTP to understand which treatment actions and controls they are responsible for delivering, and by when, giving them a clear view of their obligations within the broader plan.
GRC and Compliance Professionals
Those managing compliance tooling and documentation use the RTP to connect the risk register, treatment decisions, and control selection into a coherent, auditable record, adjusting its detail to fit the organization's chosen risk methodology and scope.

Inside RTP

Identified Risks
The set of risks derived from the ISMS risk assessment that the plan addresses, each typically linked back to assessed likelihood and impact so treatment decisions are traceable to the underlying analysis.
Risk Treatment Options
The chosen approach for each risk, generally selected from options such as modifying (reducing) the risk through controls, retaining (accepting) it, avoiding the activity that gives rise to it, or sharing it with another party. The specific mix depends on scope and the organization's risk criteria.
Selected Controls
The controls chosen to modify risk, which under ISO/IEC 27001 are cross-referenced against Annex A reference controls and documented in the Statement of Applicability. Annex A was restructured in the 2022 revision into 93 controls across four themes, compared with 114 controls in the 2013 version, so the applicable set depends on the edition and version cited.
Statement of Applicability Linkage
The connection between the treatment plan and the Statement of Applicability, which records which reference controls are applicable, their inclusion or exclusion, and the justification, informed by the risk assessment.
Ownership and Responsibility
Assignment of accountable risk owners and, where relevant, control owners responsible for implementing and maintaining each treatment, supporting follow-up and review.
Residual Risk and Acceptance
The level of risk remaining after treatment is applied, together with the record of acceptance by the appropriate risk owner, so that retained risk is documented rather than implicit.
Implementation Timeline and Status
Target dates, milestones, and current progress for planned treatments, enabling the ISMS to demonstrate that treatment is actively managed rather than only planned.

Common questions

Answers to the questions practitioners most commonly ask about RTP.

Is a Risk Treatment Plan the same thing as the Statement of Applicability?
No. They are related but distinct documents in ISO/IEC 27001. The Risk Treatment Plan documents how identified risks will be addressed, including the treatment options selected and the actions, ownership, and timelines involved. The Statement of Applicability records which Annex A reference controls have been deemed applicable or excluded, along with justification. The plan describes the treatment actions, while the Statement of Applicability documents the control selection decisions; in most implementations they cross-reference one another rather than being interchangeable.
Is a Risk Treatment Plan required for SOC 2 the same way it is for ISO 27001?
Not in the same way. A formal Risk Treatment Plan is a concept tied to the ISO/IEC 27001 ISMS requirements in clauses 4 through 10, where risk treatment is an explicit requirement. A SOC 2 examination is an attestation performed by a licensed CPA firm under the AICPA SSAE 18 standard against the Trust Services Criteria, and it does not mandate an ISO-style Risk Treatment Plan by name. That said, risk assessment and related processes are addressed within the Common Criteria, so organizations often maintain risk documentation that supports both frameworks, though satisfying one does not automatically satisfy the other.
What information is typically captured in a Risk Treatment Plan?
Contents vary by organization and scope, but a Risk Treatment Plan typically records the identified risks, the selected treatment option for each (such as modifying, retaining, avoiding, or sharing the risk), the specific actions or controls chosen, assigned owners, target timelines, and the expected residual risk. Many organizations also link each treatment entry back to the relevant risk assessment results and, where applicable, to the corresponding Annex A reference controls documented in the Statement of Applicability.
How often should a Risk Treatment Plan be reviewed and updated?
The appropriate cadence depends on the organization's risk environment and internal policy rather than a fixed universal rule. In most implementations, the plan is reviewed when the underlying risk assessment is updated, when significant changes occur to the ISMS scope, systems, or threat landscape, and as part of periodic management review. Maintaining evidence of these reviews is generally useful, since a certification body assessing an ISO 27001 ISMS will typically look for demonstrable, ongoing maintenance rather than a one-time exercise.
Who should own and approve the Risk Treatment Plan?
Ownership arrangements vary by organization, but the plan is typically developed with input from control and process owners and approved by those with appropriate authority over the risks concerned. In ISO/IEC 27001 implementations, top management involvement in the ISMS is a recurring theme, and it is common for management to approve the plan and to accept residual risks. The specific approval structure depends on the organization's governance model rather than being dictated in a single prescribed form.
How does the Risk Treatment Plan relate to selecting Annex A controls?
In ISO/IEC 27001, Annex A provides a set of reference controls that are selected based on the outcomes of the risk assessment and risk treatment process, with the selections documented in the Statement of Applicability. The Risk Treatment Plan typically captures how those selected controls will be implemented to address specific risks. Because Annex A was restructured in the 2022 revision, organizations should reference the applicable version when aligning their plan to control selections, and should treat control choice as risk-driven rather than assuming any particular control is mandatory unless required by their own determinations.

Common misconceptions

A Risk Treatment Plan is the same document as the Statement of Applicability.
They are related but distinct. The Statement of Applicability records which Annex A reference controls are applicable and why, while the Risk Treatment Plan describes how identified risks are treated, including chosen options, owners, and timelines. The two are cross-referenced but serve different purposes within the ISMS clauses 4 through 10 requirements.
Every identified risk must be reduced through controls.
Risk treatment typically allows more than one option, such as modifying, retaining, avoiding, or sharing risk. Depending on the organization's risk criteria and scope, accepting a risk with documented justification can be a valid treatment; controls are not universally required for every risk.
Having a Risk Treatment Plan satisfies SOC 2 requirements as well.
The plan is an ISO/IEC 27001 ISMS artifact and does not by itself satisfy a SOC 2 examination. SOC 2 is an attestation performed by a licensed CPA firm under the AICPA SSAE 18 standard against the Trust Services Criteria, and mapping between the frameworks is only partial. Satisfying one does not automatically satisfy the other.

Best practices

Trace each treatment decision back to the risk assessment so that likelihood, impact, and the selected treatment option are clearly linked and auditable.
Keep the Risk Treatment Plan and the Statement of Applicability consistent, cross-referencing selected controls against the correct Annex A version and specifying whether you are working from the 2013 or 2022 edition.
Assign a named risk owner to each risk and record formal acceptance of residual risk by the appropriate owner rather than leaving retained risk implicit.
Document treatment options beyond control implementation, including retaining, avoiding, or sharing risk where justified by the organization's risk criteria and scope.
Track implementation status with target dates and milestones, reviewing progress periodically so the plan reflects the current state of the ISMS.
Review and update the plan when the risk assessment, scope, or environment changes, and treat any mapping to SOC 2 Trust Services Criteria as partial rather than assuming equivalence.