Risk Treatment Plan
A Risk Treatment Plan is a structured document that sets out the specific actions an organization will take to address each risk it has identified. For every risk, the plan describes how it will be handled, acting as a roadmap for putting the chosen responses into practice. It typically covers how controls will be implemented to reduce either the likelihood or the impact of a risk.
A Risk Treatment Plan (RTP) is a documented roadmap that specifies how identified risks from a risk assessment will be treated, detailing the controls or actions to be implemented to reduce the likelihood or impact of each risk. In the context of ISO/IEC 27001, the RTP operationalizes the outcomes of the risk assessment and risk treatment process within the ISMS, translating treatment decisions into planned implementation activities; it works in conjunction with the Statement of Applicability, which records the selection and justification of Annex A reference controls. The RTP's scope and level of detail vary depending on the organization's risk methodology and scoping decisions, and the plan emphasizes implementation as the critical component rather than documentation alone.
Why it matters
The Risk Treatment Plan is where an ISO/IEC 27001 Information Security Management System (ISMS) moves from analysis to action. A risk assessment identifies and evaluates risks, but on its own it changes nothing; the RTP translates those findings into concrete, planned activities that reduce the likelihood or impact of each risk. Without a documented plan tying treatment decisions to specific actions, an organization has opinions about its risks rather than a defensible approach to managing them.
Because the RTP is a roadmap for implementation, its value depends heavily on execution rather than paperwork. A well-written plan that is never carried out provides little protection and, during a certification audit, can expose a gap between what the organization intended and what it actually did. Certification bodies typically expect to see evidence that treatment actions have been progressed, not simply that a plan exists on paper. In this sense the RTP serves both as an internal management tool and as auditable evidence that the risk treatment process is operating.
The RTP also works alongside the Statement of Applicability (SoA), which records which Annex A reference controls have been selected and the justification for their inclusion or exclusion. The two documents are complementary: the SoA captures the selection and rationale for controls, while the RTP describes how the chosen treatments will be put into practice. Note that an RTP addresses only the risks identified within the defined scope of the ISMS and using the organization's chosen methodology; it does not guarantee that all risks are eliminated or that no incidents will occur.
Who it's relevant to
Inside RTP
Common questions
Answers to the questions practitioners most commonly ask about RTP.