A risk treatment plan records what you decided to do about each risk you identified, which controls implement that decision, who owns it and by when.
The short answer
The risk treatment plan, or RTP, is the document that turns a risk register into action. For every risk above your acceptance threshold it states the treatment chosen, the controls that deliver it, the owner, the target date and the residual risk that remains afterwards. ISO 27001 requires it under Clause 6.1.3.
The risk assessment tells you what the risks are. The treatment plan is where someone commits to doing something about them.
On this page
The four treatment options
Every risk gets exactly one of these. Most get the first.
What the plan contains
| Field | Why the auditor looks at it |
|---|---|
| Risk reference | Ties the row back to the risk register so the chain can be followed |
| Treatment option | Shows a decision was made rather than deferred |
| Controls selected | Links the decision to specific Annex A references and to the SoA |
| Owner and target date | Evidence that the action is assigned and time-bound |
| Status | Whether the treatment is planned, in progress or complete |
| Residual risk | What remains after treatment, and whether that is acceptable |
Residual risk and sign-off
No control reduces a risk to zero. Whatever is left after treatment is the residual risk, and ISO 27001 requires risk owners to approve the plan and to accept the residual risks explicitly. That acceptance is a record, not a conversation.
The chain auditors follow
Risk register entry, then treatment decision, then selected control, then Statement of Applicability row, then evidence the control operates. A break anywhere in that chain is the most common finding at a Stage 2 audit.
How Osto supports it
Where the treatment is modify, the controls have to exist and keep working. Osto deploys and runs those technical controls, and maps their evidence to the Annex A references cited in the plan, so a row marked complete can be demonstrated. Treatment decisions, owners and residual risk acceptance remain with the organisation.
Free security assessment
Where the treatment is modify, the controls have to work
Osto deploys and runs those controls, and maps the evidence to the Annex A references your plan cites.
Get a free security assessment Book a platform walkthroughDeploys in hours · Mapped to your plan · One platform, everything
Frequently asked questions
What is a risk treatment plan?
It is the document recording what an organisation decided to do about each identified risk: the treatment option chosen, the controls implementing it, the owner, the target date and the residual risk remaining. ISO 27001 requires it under Clause 6.1.3.
What are the risk treatment options?
Four: modify the risk by applying controls, avoid it by ceasing the activity, share it with another party through insurance or contract, or retain it by accepting it knowingly with documented sign-off.
How is it different from the Statement of Applicability?
The treatment plan records decisions and actions per risk. The Statement of Applicability records, per Annex A control, whether it applies and why. The plan explains the reasoning; the SoA is the control-by-control view of the result.
Can a risk simply be accepted?
Yes, if it falls within the acceptance criteria set during the risk assessment and a named risk owner signs off. Acceptance without a record is treated as an unmanaged risk.

