ISO 27001 Risk Register: Ultimate Guide

ISO 27001 Risk Register

In this guide, you will learn what an ISO 27001 Risk Register is, how to write it yourself and I give you a template you can download and use right away.

What is a Risk Register

ISO 27001 is a risk based system that means the inclusion of controls and the level of those controls is based on risk. You use a risk register to record what the risk is, you allocate it a risk score and decide how you are going to treat the risk. You then record the risk score after the change and this is your residual risk. Risks are allocated owners and action plans are tracked and managed as part of the management review team meeting.

ISO 27001 Risk Register Template

The ISO 27001:2022 risk register template allows the recording and management of risks in this simple and effective template that also includes the management of residual risk and management reporting.

ISO 27001 Risk Register Template

The fully compliant and ready to go ISO 27001 Risk Register

How to create a risk register step-by-step

To implement an ISO 27001 Risk Register, you will create a structured spreadsheet that identifies information assets, quantifies threats via CIA impact scores, and documents a formal Risk Treatment Plan.

  1. Create an Excel spreadsheet with two tabs: Using a spreadsheet application create two tabs. The first tab is the document control and the second tab is the actual risk register.
  2. Add document mark up: Document mark up is required. This document is not confidential so place the document classification ‘internal’ in the footer or header. Add a version control table to the document control tab that includes the author, the date, the reason for change and the version number.
  3. Add a reference field: This is an internal reference that you will refer to the risk by.
  4. Add an External Reference field: External reference number that shows where the risk came from, for example a Helpdesk ticket, an audit number, an Annex A control, a GDPR clause.
  5. Add a Risk Description: A description of what the risk is can be very useful.
  6. Add an Asset Field: The thing that the risk applies to, for example a data set, a system, a website, a building, a group of people, a physical order book.
  7. Add a Threat Field: The threat to the asset.
  8. Add a Vulnerability Field: The vulnerability in the control or lack of control.
  9. Add an Outcome Field: Cover what will happen if the risk is realised, for example a financial penalty, a loss of customers, a loss of revenue.
  10. Add a CIA Field: Whether the risk impacts on the confidentiality, integrity or availability of the asset – can be a combination.
  11. Add a Current Control Field: If there is a current control in place, a description of what it is or state no current control.
  12. Add an Impact Field: The impact as a score, usual 1, 3 or 9 that scores the impact from low to high.
  13. Add a Likelihood Field: The likelihood as a score, usual 1, 3 or 9 that scores the impact from low to high.
  14. Add a Risk Score Field: A formula that multiplies the impact by the likelihood. The higher the score the higher the risk and the more likely you will want to address the risk.
  15. Add a Treatment Field: Record if you accept the risk, are transferring the risk or reducing the risk
  16. Add a Treatment Plan Field: What is the plan to address the risk
  17. Add a Treatment Owner field:Who is going to do the remediation and implement the treatment plan
  18. Add a Treatment Date field: By what date will the treatment plan be implemented.
  19. Add a Residual Risk field: Residual risk that shows the score after the plan was implemented and the affect that had on the risk sore by comparison.
ISO 27001 Toolkit Business Edition

Risk Evaluation Criteria

ScoreLikelihood (Probability)Impact (Business Severity)
1 (Low)Unlikely to occur; happens less than once every 5 years.Minor operational glitch; negligible financial loss (e.g., < £1k).
3 (Medium)Possible occurrence; likely to happen once every 12-24 months.Significant disruption; moderate financial impact or localized data breach.
9 (High)Highly probable; expected to occur multiple times per year.Critical business failure; severe financial loss or major regulatory fine (GDPR).

How to create an ISO 27001 Risk Register – Video

If you want to create a risk register yourself and do not want to download the template then in this tutorial video I show you how to create a risk register in just under 5 minutes. It has been viewed nearly 10,000 times. Risk management is the foundation of data security and many industry certifications including GDPR, ISO 27001, PCI DSS, SOC and a host of others. Risk Management doesn’t have to be hard and it really is easy to create a basic functioning risk register from scratch.

Relevant ISO 27001:2022 controls

The ISO 27001:2022 standard has specific controls that require a risk register. Some of the most important ones include:

ISO 27001:2022 ClauseRelationship to the Risk Register
Clause 6.1.2Mandates the establishment and documentation of a formal risk assessment process to identify threats to information confidentiality, integrity, and availability.
Clause 6.1.3Requires the selection of risk treatment options and the determination of controls (from Annex A or elsewhere) needed to implement the chosen treatment strategy.
Clause 8.2Focuses on the operational execution of the assessment process at planned intervals or when significant changes occur to ensure the threat landscape remains current.
Clause 8.3Demands the actual implementation of the Risk Treatment Plan (RTP) and the retention of documented information as evidence of the results.

ISO 27001 Risk Register FAQ

Is ISO 27001 Risk-Based?

Yes ISO 27001 is a risk based management system.

What is a risk based management system?

A risk based management system is a system of controls where the selection of the controls is based on risk. It is acceptable not to implement certain controls and the risk accepted. The higher the risk the more control rigour you would implement.

Do I need a risk register for ISO 27001?


Yes a risk register is a fundamental part of the ISO 27001 standard and management system. It allows you to record and manage risk.

Can I use the company or other risk register?

Yes but we do not recommend it. Having a risk register that is dedicated to governance risk and compliance is preferred. Different risk registers often address different concerns and having a separate risk register can greatly aid its management.

Should I buy a risk management tool?

You do not need to purchase a risk management tool. They can be expensive and restrictive once you understand risk management. They are ideal for the novice user or for teams where consistency of approach and repletion are key across multiple departments but a simple spreadsheet as described in the tutorial is more than adequate.

Should I keep versions of my risk registers?

This is not a requirement if you have document version control but is good practice.

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top