Skip to content

Risk Treatment

What is Risk Treatment?

The process of selecting and implementing measures to modify risk. Options include: mitigate (reduce), accept (retain), avoid (eliminate), or transfer (share) the risk.

Risk Management

What the standards actually require on risk treatment

Requirements naming risk treatment across 6 standards, quoted from the control text.

Select and implement treatment options for AI risks including avoidance, mitigation, transfer, or acceptance.

23894-6.5 · AI Risk Treatment
ISO 27005:20225 controls

Requirement defined in ISO 27005:2022, clause 8.6.1 (Formulation of the risk treatment plan). See licensed source for normative text.

iso-27005-2022::8.6.1 · Formulation of the risk treatment plan

Implement the information security risk treatment plan and retain evidence of results.

27003-8.3 · Risk Treatment Implementation
ISO 31000:20183 controls

Requirement defined in ISO 31000:2018, clause 6.5 (Risk treatment). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-31000-2018::6.5 · Risk treatment

Requirement defined in ISO/IEC 42001:2023, clause 6.1.3 (Risk treatment). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-iec-42001-2023::6.1.3 · Risk treatment
ISO/SAE 214342 controls

Risk treatment decisions are made for each threat scenario and Cybersecurity Assurance Levels (CAL 1-4) are determined to scale rigour of cybersecurity activities.

21434-15.9 · Cybersecurity Assurance Level (CAL) and Risk Treatment

Questions people ask about risk treatment

What is Risk Treatment?
The process of selecting and implementing measures to modify risk. Options include: mitigate (reduce), accept (retain), avoid (eliminate), or transfer (share) the risk.
Why is Risk Treatment important for compliance?
Risk Treatment is a key concept in Risk Management. Understanding risk treatment helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Risk Treatment?
Key concepts related to Risk Treatment include Risk Assessment. Understanding these interconnected concepts provides a more comprehensive view of Risk Management requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Risk Treatment?
Risk Treatment appears in the requirement text of ISO/IEC 23894:2023, ISO 27005:2022, ISO/IEC 27003:2017, ISO 31000:2018, ISO/IEC 42001:2023. Across these standards we have identified 23 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Treatment?
Explore our compliance framework pages to see how risk treatment applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Treatment applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.