ISO 27001 Risk Register Template
Manage information security risk identification, assessment, and mitigation in one structured worksheet.
In short
A risk register is the worksheet where an organisation records every information security risk together with its owner, likelihood and impact scores, treatment option, and the residual risk left after controls are applied. ISO 27001 clauses 6.1.2 and 6.1.3 require this process to be documented, and the register is the evidence auditors ask for at the stage 2 audit.
- Format
- XLSX
- Size
- 19 KB
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
What This Document Is For
Almost every organisation that stumbles at the stage 1 audit stumbles on the same thing: a risk assessment that cannot be shown. Not because the risks were never considered, but because that thinking is scattered across meeting notes, conversations, and one or two people's heads — with no single place that can be handed to an auditor.
This template provides that place. Its structure follows the path auditors examine: from assets and threats, to the risk score before controls, to the treatment decision with its owner and deadline, and finally to the residual risk management accepts. The columns are deliberately no more numerous than needed — an over-elaborate register stops being filled in by the third month.
Most Useful For
- Organisations beginning an ISO 27001 implementation with no register at all
- Teams with an existing register whose auditor asked them to tidy its structure and approval trail
- Risk managers wanting IT risk and information security risk in a single format
What's Inside
Risk identification
Affected asset, threat, vulnerability, and risk category on one row that reads without verbal explanation.
Analysis & evaluation
Likelihood × impact scoring against defined scales, inherent risk level, and a flag for risks exceeding the organisation's risk appetite.
Risk treatment
Treatment option (mitigate, transfer, avoid, accept), the Annex A controls selected, the risk owner, and the target date.
Residual risk
The score once controls are operating, plus risk owner sign-off — the section most often left blank and most often asked about.
Scoring scales
A separate sheet defining the likelihood and impact scales, so scores stay comparable between assessors.
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Clauses 6.1.2 & 6.1.3 | The information security risk assessment and treatment process and its documented results. |
| ISO/IEC 27001:2022 | Clauses 8.2 & 8.3 | Risk assessment and treatment performed at planned intervals, not once at certification time. |
| ISO/IEC 27005 | Whole document | The information security risk management guidance this register's structure follows. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
What risk scale does this template use?
A 1–5 scale for likelihood and impact, producing a 1–25 score across four risk levels. The scale can be changed — what matters is that its definition is written on the scale sheet and applied consistently by every assessor. Auditors check consistency, not a particular number.
How many risks should a register hold?
There is no required number. Small single-product organisations typically end up with 30–60 risks; mid-sized ones with 80–150. What draws an auditor's attention is a register with five risks, or one with five hundred that has clearly never been reviewed.
Is this register enough for a certification audit?
A register evidences the outcome, not the process. Auditors will also ask for a written risk assessment methodology and proof that assessments actually run on schedule. This template covers the outcome side; the methodology and review cycle you need to write yourself.
Related Reading
Background that helps you fill this document in correctly, rather than merely filling it in.
Documents Often Taken Together With This One
Statement of Applicability (SoA) Template — ISO 27001:2022
Document the applicability of all 93 ISO 27001:2022 Annex A controls along with their justifications.
Free DownloadInformation Security Policy Template
An organization-level information security policy framework ready to tailor to your business context.
Free DownloadROPA Template — Records of Processing Activities
Document all of your organization's personal data processing activities in a structured format, as mandated by Indonesia's PDP Law No. 27 of 2022.
Free DownloadNeed guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.