Identifying a risk is the easy part. The harder and more valuable work is deciding what to do about it. A risk treatment plan is where the decisions get made: which risks you will reduce, which you will transfer, which you will avoid altogether, and which you will simply accept. This guide explains what a treatment plan is, walks through the four treatment options, and shows you how to structure one and track it through to completion.
What You'll Learn
By the end of this article you'll understand the four treatment options, how to structure a treatment plan with actions, owners, due dates and a target residual risk, how to link treatments to controls, and how to report treatment progress to your board.
What Is a Risk Treatment Plan?
A risk treatment plan (sometimes called a risk response plan or risk mitigation plan) is the documented set of decisions and actions an organization takes to modify a risk. It sits between your risk register, which records what could go wrong, and your control environment, which records what you are doing about it.
Where the risk register answers "what is the risk and how bad is it?", the treatment plan answers "what are we going to do, who owns it, by when, and what does success look like?" In ISO 31000 terms, treatment is the process of selecting and implementing options for modifying risk. In practice, a treatment plan is a list of committed actions tied to specific risks.
A treatment plan is only meaningful when it is decision-driven. Every entry should be the result of a deliberate choice about how the organization will respond to a risk that sits above its tolerance. It is not a generic to-do list.
The Four Treatment Options
There are four fundamental ways to respond to a risk. Every treatment decision is one of these, or some combination of them:
| Option | What It Means | When to Use It |
|---|---|---|
| Avoid | Eliminate the risk by stopping or not starting the activity that creates it | When the risk is unacceptable and the activity is not essential, or no viable controls exist |
| Reduce (Mitigate) | Lower the likelihood or impact by implementing or strengthening controls | The most common option, used when the activity is worth keeping but the risk needs to come down |
| Transfer (Share) | Shift some or all of the financial consequence to a third party | When another party is better placed to bear the risk, through insurance, outsourcing, or contractual indemnities |
| Accept (Tolerate) | Acknowledge the risk and take no further action beyond monitoring | When the residual risk is within appetite, or the cost of treatment exceeds the benefit |
Avoid
Avoidance means removing the source of the risk entirely: declining to enter a market, discontinuing a product line, or not using a particular supplier. It is the most decisive option, but also the most expensive in terms of lost opportunity. Avoidance is rarely the right answer for routine risks because the activities that create them usually create value too.
Reduce
Reduction is the workhorse of risk treatment. You implement new controls or strengthen existing ones to push likelihood, impact, or both downward. This is where most treatment actions live, and where the link between treatment and your control environment is tightest. Reduction does not eliminate risk; it brings the residual level into an acceptable range.
Transfer
Transfer moves the consequence, not the risk itself. Insurance is the classic example: you still suffer the incident, but the financial blow is absorbed by the insurer. Outsourcing and contractual clauses (indemnities, limitations of liability, service-level penalties) are other forms. Remember that transfer is rarely complete. Reputational and operational consequences often stay with you even when the financial loss is covered.
Accept
Acceptance is a legitimate, documented choice, not a failure to act. You accept a risk when its residual level is already within your risk appetite, or when the cost of treating it further outweighs the benefit. The key is that acceptance must be conscious and recorded, with a named approver, so that "we decided to live with this" can be evidenced later.
Important
Acceptance by default is not acceptance. A risk you never treated because nobody got around to it is an untreated risk, not an accepted one. Genuine acceptance has an approver, a rationale, and a review date.
Want the full framework with worked examples?
How a Treatment Plan Is Structured
A treatment plan converts a treatment decision into one or more concrete actions. For each risk you choose to treat, capture the following fields:
| Field | Purpose | Example |
|---|---|---|
| Linked Risk ID | Ties the action back to a specific risk in the register | R-2026-018 |
| Treatment Option | Which of the four responses this action delivers | Reduce |
| Action Description | The specific, measurable thing being done | Deploy MFA across all admin accounts |
| Action Owner | One accountable person (not a team) | Head of IT Security |
| Due Date | The committed completion date | 2026-03-31 |
| Target Residual Risk | The risk score the action is expected to achieve | Likelihood 2 × Impact 4 = 8 (Medium) |
| Linked Control | The control the action creates or strengthens | CTRL-014 Multi-Factor Authentication |
| Status | Progress against the action | In Progress (60%) |
The two fields that distinguish a real plan from a wish list are owner and target residual risk. The owner makes the action accountable; the target makes it measurable. Without a target you cannot tell whether the action, once complete, actually achieved anything.
Treatment Plan for R-2026-018: Phishing-Led Credential Compromise
Inherent Risk: Likelihood 4 × Impact 5 = 20 (Critical)
Current Residual Risk: Likelihood 4 × Impact 4 = 16 (High), with only basic email filtering in place
Treatment Option: Reduce
Action 1: Deploy multi-factor authentication on all admin and remote-access accounts. Owner: Head of IT Security. Due: 2026-03-31.
Action 2: Roll out quarterly phishing simulation and awareness training. Owner: People & Culture Lead. Due: 2026-04-30.
Target Residual Risk: Likelihood 2 × Impact 4 = 8 (Medium), within appetite
Linked Controls: CTRL-014 (MFA), CTRL-022 (Security Awareness Programme)
Status: In Progress, next review 2026-02-28
Linking Treatments to Controls
Treatment actions and controls are closely related but not identical. A treatment action is something you do once: a project with a start, an end, and an owner. A control is something that operates continuously to keep risk down once the action is finished. When you deploy MFA, the deployment is the action; the MFA itself, running every day, is the control.
This distinction matters because treatment plans close out but controls live on. Once an action is complete, its output should be captured as an entry in your controls register, where it can be tested and monitored over time. Skip this step and you lose the connection between the risk, the action that reduced it, and the control that keeps it reduced.
For a deeper walk-through of how these three layers connect, see our guide on linking risks, controls, and actions. The short version: every treatment action should either create a new control or strengthen an existing one, and that link should be recorded explicitly.
Pro Tip
When an action completes, don't just mark it "done." Update the risk's residual score, confirm whether the target was met, and create or update the linked control. A completed action with no residual-risk change is a signal the action wasn't effective.
Tracking Progress
A treatment plan is a commitment, and commitments need follow-through. Track progress with a simple, consistent status taxonomy so that anyone reading the plan understands where each action stands:
- Not Started: Action is approved but no work has begun
- In Progress: Work is underway, ideally with a percentage or milestone
- Blocked: Work has stalled and needs escalation or a decision
- Complete: Action is finished and the residual risk has been re-scored
- Overdue: The due date has passed without completion
Review cadence should follow the severity of the underlying risk. Actions tied to critical risks warrant fortnightly check-ins; actions tied to medium risks can be reviewed monthly or quarterly. The most useful metric is not how many actions exist, but how many are overdue. An overdue rate that creeps up over time is the clearest sign a risk program is losing momentum.
Tie completion back to your control effectiveness assessment. An action marked complete whose new control later tests as ineffective has not actually treated the risk, and the residual score should reflect that reality rather than the optimistic target.
Board Reporting on Treatment
Boards and risk committees don't want to read every action line. They want to know whether the organization's most significant risks are being brought under control on schedule. Summarize treatment progress at a portfolio level:
- Movement of top risks: Are the highest-rated risks trending down toward target residual levels?
- Action completion rate: What proportion of committed actions are on track, and how many are overdue?
- Appetite breaches: Which risks remain above appetite, and what is the plan to close the gap?
- Accepted risks: Which significant risks have been formally accepted, and who approved them?
This portfolio view feeds directly into your board risk report, where treatment progress is one of the core sections directors expect to see. Frame it in terms of direction of travel: a risk that is still High but moving toward Medium on schedule tells a very different story to one that has been stuck above appetite for three quarters.
Common Mistakes to Avoid
1. Actions Without Owners
"The team will improve access controls" is not an action; it is a hope. Every action needs one named, accountable owner who can be asked, "where are we with this?"
2. No Target Residual Risk
If you don't state what the action is meant to achieve, you can't tell whether it worked. Set a target residual score before you start and check against it when you finish.
3. Confusing Actions With Controls
A one-time project is an action; a continuously operating safeguard is a control. Treating them as the same thing means completed actions vanish instead of becoming durable controls in your controls register.
4. Treating Everything
Not every risk needs treatment. Risks already within appetite should be accepted and monitored. Spreading effort across low-priority risks starves the critical ones of attention.
5. Acceptance by Neglect
Letting a risk sit untreated is not the same as accepting it. Real acceptance is documented, approved, and given a review date so it doesn't quietly drift out of appetite.
Summary
- A risk treatment plan turns risk decisions into committed actions with owners, due dates, and measurable targets
- There are four treatment options: avoid, reduce, transfer, and accept
- Every action needs a single owner and a target residual risk to be meaningful
- Treatment actions are one-off projects; their output should become durable controls in your controls register
- Track progress with a consistent status taxonomy and watch the overdue rate closely
- Report treatment to the board at portfolio level, where direction of travel matters more than line-item detail
Frequently Asked Questions
What is the difference between a risk treatment plan and a risk register?
The risk register records what could go wrong and how serious each risk is. The treatment plan records what you are going to do about it: the specific actions, owners, due dates, and target residual risk for each risk you choose to treat. They are closely linked, and most registers embed treatment actions against each risk.
What are the four risk treatment options?
Avoid (eliminate the activity creating the risk), reduce (implement controls to lower likelihood or impact), transfer (shift the financial consequence to a third party such as an insurer), and accept (consciously tolerate the risk and monitor it). Reduce is by far the most common.
What is target residual risk?
Target residual risk is the risk score you expect to reach once a treatment action is complete. It turns an action into something measurable: when the work is done, you re-score the risk and check whether you hit the target. See our guide on inherent vs residual risk for the underlying concepts.
Is risk acceptance the same as ignoring a risk?
No. Acceptance is a deliberate, documented decision, with a named approver, a rationale, and a review date, to tolerate a risk because it is within appetite or because treatment isn't cost-effective. Ignoring a risk leaves it untreated and unmonitored, which is a control failure, not a treatment choice.
How does a treatment action become a control?
A treatment action is a one-time project, for example deploying MFA. Once that project completes, the thing it created (MFA running every day) is an ongoing control. You record it in your controls register so it can be tested and monitored long after the action is closed.
How often should a treatment plan be reviewed?
Review cadence should match the severity of the underlying risk. Actions tied to critical risks deserve fortnightly check-ins; medium-risk actions can be reviewed monthly or quarterly. Always re-review when an action's due date passes or when the underlying risk changes materially.
Save this guide for later
Download the PDF version to read offline or share with your team.

