In this guide, you will learn what an ISO 27001 Risk Register is, how to write it yourself and I give you a template you can download and use right away.
Table of contents
- ISO 27001 Risk Register Explained
- Template
- Example
- How to write it yourself
- How to Create a Risk Register Video Tutorial
- How the ISO 27001 toolkit can help
- Information security standards that need it
- Relevant ISO 27001:2022 controls
- Applicability to Small Business, Tech Startups, and AI Companies
- ISO 27001 Risk Register FAQ
- About the author
ISO 27001 Risk Register Explained
ISO 27001 is a risk based system that means the inclusion of controls and the level of those controls is based on risk. You use a risk register to record what the risk is, you allocate it a risk score and decide how you are going to treat the risk. You then record the risk score after the change and this is your residual risk. Risks are allocated owners and action plans are tracked and managed as part of the management review team meeting.
A Risk Register is a living document – a spreadsheet, really – that helps you track and manage risks to your information. You list the risks, figure out how likely they are to happen, what their impact would be, and what you’re doing to fix them. It’s your personal risk diary, and it’s super important for showing you’re serious about security.
| Dimension | Requirement & Best Practice |
|---|---|
| Why | It is the foundation of ISO 27001 certification. It proves to auditors that you have identified potential threats and established a treatment plan. |
| When | Commence creation at the start of the ISO 27001 journey. Update regularly (at least every six months) or whenever significant business changes occur. |
| Who | Collaborative effort involving the entire team. While one person “owns” the register, IT, Sales, and Operations contribute specific domain risks. |
| Where | Stored in a safe, central location such as a secured shared drive or a dedicated information security management platform. |
| How | Follow a four-step process: 1. Identification (Brainstorming), 2. Analysis (Likelihood vs Impact), 3. Treatment (Mitigation strategy), and 4. Documentation. |
Template
The ISO 27001:2022 risk register template allows the recording and management of risks in this simple and effective template that also includes the management of residual risk and management reporting. is part of the Ultimate ISO 27001 Toolkit and also exclusively available stand-alone.

Example
This is a great example of the ISO 27001 risk register.

How to write it yourself
To implement an ISO 27001 Risk Register, organisations must create a structured spreadsheet that identifies information assets, quantifies threats via CIA impact scores, and documents a formal Risk Treatment Plan. This technical framework ensures compliance with Clause 6.1.2 by providing auditable evidence of risk ownership and residual risk management.
1. Provision the Spreadsheet Architecture
Using a spreadsheet application, create two distinct tabs. Name the first tab “Document Control” for governance and the second tab “Risk Register” for active threat logging. This separation ensures that administrative metadata does not interfere with the operational risk data.
2. Formalise Document Markup and Version Control
Apply document markup by placing the classification “Internal” in the header or footer. On the Document Control tab, provision a version control table including fields for Author, Date, Reason for Change, and Version Number to maintain a clear audit trail for ISO 27001 certification.
3. Establish Internal and External Reference Identifiers
Add a “Reference” field for unique internal IDs and an “External Reference” field to map risks to their source. Cross-reference these to Helpdesk tickets, internal audit numbers, specific Annex A controls, or GDPR clauses to ensure full traceability across your compliance framework.
4. Enumerate Assets and Technical Risk Descriptions
Provision an “Asset” field to identify the specific data set, system, or physical resource at risk. Add a “Risk Description” field to provide a digestible summary of the threat scenario, ensuring all stakeholders understand the specific context of the vulnerability.
5. Map Threats, Vulnerabilities, and Business Outcomes
Formalise three critical analytical fields: “Threat” (the potential cause of harm), “Vulnerability” (the weakness or lack of control), and “Outcome.” Describe the realized impact, such as financial penalties, loss of revenue, or reputational damage, to clarify the business risk.
6. Quantify CIA Impact and Existing Control Efficacy
Add a “CIA” field to indicate if the risk affects Confidentiality, Integrity, or Availability. Provision a “Current Control” field to describe existing safeguards and add “Impact” and “Likelihood” fields using a standard 1, 3, 9 scoring system to quantify raw risk levels.
7. Automate Risk Scoring and Treatment Strategy
Insert a “Risk Score” formula that multiplies Impact by Likelihood. Add a “Treatment” field to record the decision to Accept, Transfer, or Reduce the risk, and a “Treatment Plan” field to detail the specific remediation actions required to align with your Risk Appetite.
8. Assign Ownership and Measure Residual Risk
Add “Treatment Owner,” “Treatment Date,” and “Residual Risk” fields. Assigning a specific individual ensures accountability, while the residual risk score provides auditors with comparison data showing the effectiveness of implemented controls after remediation.
How to Create a Risk Register Video Tutorial
Risk Evaluation Criteria
| Score | Likelihood (Probability) | Impact (Business Severity) |
|---|---|---|
| 1 (Low) | Unlikely to occur; happens less than once every 5 years. | Minor operational glitch; negligible financial loss (e.g., < £1k). |
| 3 (Medium) | Possible occurrence; likely to happen once every 12-24 months. | Significant disruption; moderate financial impact or localized data breach. |
| 9 (High) | Highly probable; expected to occur multiple times per year. | Critical business failure; severe financial loss or major regulatory fine (GDPR). |
How the ISO 27001 toolkit can help
An ISO 27001 toolkit is a collection of pre-made documents, like a pre-filled Risk Register template. It makes the process much faster and easier, so you don’t have to guess what to write. It’s like having training wheels for your certification journey.
DO IT YOURSELF
ISO 27001
All the templates, tools, support and knowledge you need to do it yourself.
Information security standards that need it
This risk register is a key part of ISO 27001, which is an international standard for managing information security. Other standards that need it include:
| Standard / Regulation | Relationship to Information Security Risk Management |
|---|---|
| ISO 27001 | The core international standard requirement under Clause 6.1.2 for establishing an effective Information Security Management System (ISMS). |
| GDPR | Mandates technical and organisational measures to protect personal data, requiring a risk-based approach to data privacy. |
| CCPA | Requires safeguarding consumer privacy through systematic risk assessment and the implementation of reasonable security procedures. |
| DORA | Essential for financial sector operational resilience, requiring detailed mapping of ICT-related risks and vulnerabilities. |
| NIS2 | Enhances information security risk management requirements for essential and important entities across the European Union. |
| SOC 2 | Forms a key component of the Trust Services Criteria (TSC) regarding how an organisation identifies and manages internal and external risks. |
| NIST | Aligned with the NIST Cybersecurity Framework (CSF) for identifying threats and assessing risks to critical infrastructure systems. |
| HIPAA | Required for protecting PHI (Protected Health Information) through formal administrative safeguards and risk analysis. |
Relevant ISO 27001:2022 controls
The ISO 27001:2022 standard has specific controls that require a risk register. Some of the most important ones include:
| ISO 27001:2022 Clause | Relationship to the Risk Register |
|---|---|
| Clause 6.1.2 | Mandates the establishment and documentation of a formal risk assessment process to identify threats to information confidentiality, integrity, and availability. |
| Clause 6.1.3 | Requires the selection of risk treatment options and the determination of controls (from Annex A or elsewhere) needed to implement the chosen treatment strategy. |
| Clause 8.2 | Focuses on the operational execution of the assessment process at planned intervals or when significant changes occur to ensure the threat landscape remains current. |
| Clause 8.3 | Demands the actual implementation of the Risk Treatment Plan (RTP) and the retention of documented information as evidence of the results. |
Applicability to Small Business, Tech Startups, and AI Companies
This risk register is super important for different types of businesses, but for slightly different reasons.
| Sector | Strategic Benefit | Example Threat Scenario & Treatment |
|---|---|---|
| Small Businesses | Protects customer lists and financial data while preventing operational overwhelm. | Risk: Stolen laptop. Impact: Exposed PII. Treatment: Enforce full-disk encryption. |
| Tech Startups | Secures intellectual property (IP) and proves trustworthiness to potential investors. | Risk: Code leak on public GitHub. Impact: IP theft. Treatment: Mandatory peer code reviews. |
| AI Companies | Safeguards proprietary models and the high-value datasets they are trained on. | Risk: Biased training data. Impact: Reputational/Legal damage. Treatment: Regular bias audits. |
ISO 27001 Risk Register FAQ
Is ISO 27001 Risk-Based?
Yes, ISO 27001 is a risk-based management system. This means the entire framework is designed to help you prioritize security efforts based on the specific threats to your unique business environment rather than following a generic “one-size-fits-all” checklist.
What is a risk-based management system?
A risk-based management system is a framework where the selection of security controls is determined by the specific level of risk identified. It allows an organisation to accept minor risks and focus high-rigour controls on critical threats, ensuring a cost-effective and proportionate security posture.
Do I need a risk register for ISO 27001?
Yes, a Risk Register is a fundamental requirement of the ISO 27001 standard. It is the primary tool used to record, quantify, and manage information security risks, providing the auditable evidence required to satisfy Clauses 6.1.2 and 6.1.3 of the standard.
Can I use the company’s general risk register?
Yes, but we do not recommend it. A dedicated Risk Register for Information Security (GRC) allows for more granular management of technical vulnerabilities and Annex A controls. General company registers often lack the technical depth required to satisfy an ISO 27001 auditor.
Should I buy a dedicated risk management tool?
No, you do not need to purchase expensive risk management software. While tools are useful for large, multi-departmental teams, a simple, well-structured spreadsheet is more than adequate for most organisations and offers 100% data ownership and lower complexity.
What’s the difference between a risk and a threat?
A threat is a potential negative event (e.g., a hacker), whereas a risk is the probability of that threat occurring combined with the severity of its impact (e.g., the likelihood of a hacker stealing your specific customer data and the resulting financial damage).
Is a Risk Register a one-time thing?
No, the Risk Register is a “living document” that must be updated regularly. You should review and update it at least once a year, or whenever a significant change occurs in your business, such as a new software launch or office relocation.
What is a Risk Owner?
A Risk Owner is the specific individual accountable for managing and remediating a particular risk. They must have the authority to implement the treatment plan and are responsible for ensuring the risk remains within the organisation’s accepted appetite.
Do I need to list every single risk?
No, you should focus on the risks that matter most. An effective Risk Register prioritises “significant risks”—those with a high likelihood of happening or a severe business impact—to ensure management attention is focused where it is needed most.
What if a risk isn’t fixable?
You can choose to “Accept” the risk. If the cost of fixing a vulnerability is higher than the potential loss from the threat, formal management sign-off to accept the residual risk is a valid strategy under ISO 27001 Clause 6.1.3.
What is risk treatment?
Risk treatment is your formal plan to deal with a threat. Under ISO 27001, you have four options: 1. Reduce (apply controls), 2. Accept (tolerate), 3. Transfer (buy insurance), or 4. Avoid (stop the risky activity entirely).
What is a risk score?
A risk score is a numerical value derived from multiplying Likelihood x Impact (e.g., on a 1–9 scale). This quantification allows you to objectively prioritise your security budget and focus implementation on the highest-scoring threats.


