Risk Treatment
What is Risk Treatment?
The process of selecting and implementing measures to modify risk. Options include: mitigate (reduce), accept (retain), avoid (eliminate), or transfer (share) the risk.
Related terms
Frameworks that govern risk treatment
What the standards actually require on risk treatment
Requirements naming risk treatment across 6 standards, quoted from the control text.
Select and implement treatment options for AI risks including avoidance, mitigation, transfer, or acceptance.
23894-6.5 · AI Risk Treatment →Requirement defined in ISO 27005:2022, clause 8.6.1 (Formulation of the risk treatment plan). See licensed source for normative text.
iso-27005-2022::8.6.1 · Formulation of the risk treatment plan →Implement the information security risk treatment plan and retain evidence of results.
27003-8.3 · Risk Treatment Implementation →Requirement defined in ISO 31000:2018, clause 6.5 (Risk treatment). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.
iso-31000-2018::6.5 · Risk treatment →Requirement defined in ISO/IEC 42001:2023, clause 6.1.3 (Risk treatment). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.
iso-iec-42001-2023::6.1.3 · Risk treatment →Risk treatment decisions are made for each threat scenario and Cybersecurity Assurance Levels (CAL 1-4) are determined to scale rigour of cybersecurity activities.
21434-15.9 · Cybersecurity Assurance Level (CAL) and Risk Treatment →Questions people ask about risk treatment
What is Risk Treatment?
Why is Risk Treatment important for compliance?
What concepts are related to Risk Treatment?
Which compliance frameworks address Risk Treatment?
Where can I learn more about Risk Treatment?
See how Risk Treatment applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.