6.2 Designing and Implementing Risk Treatment Plans
Key Takeaways
- ISO 31000:2018 Clause 6.5.3 requires risk treatment plans to document reasons for treatment selection, expected benefits, assigned accountabilities, required resources, performance measures, and implementation schedules.
- Cost-benefit analysis (CBA) for risk treatment evaluates whether the net reduction in risk exposure (Risk Reduction Value) justifies the direct, operational, and capital expenditures of proposed controls.
- Residual risk—the exposure remaining after treatment controls are applied—must be explicitly measured against organizational risk criteria and formally accepted by designated authority levels.
- Risk treatment plans must be seamlessly integrated into organizational operations, management systems, budget planning, and governance workflows rather than maintained as standalone compliance documents.
6.2 Designing and Implementing Risk Treatment Plans
Selecting a risk treatment option is only a decision point; converting that decision into measurable risk reduction requires the formulation and execution of a Risk Treatment Plan. Governed by ISO 31000:2018 Clause 6.5.3, risk treatment plans specify how chosen treatment options will be implemented in practice, ensuring that accountabilities are clear, resources are allocated, and progress can be monitored.
Rather than treating risk action plans as isolated compliance paperwork, ISO 31000 emphasizes that treatment plans must be integrated into the organization's business plans, operational budgets, project management frameworks, and performance management systems.
Mandatory ISO 31000 Treatment Plan Components
Clause 6.5.3 explicitly mandates that information provided in risk treatment plans should include the following core elements:
- Rationale for Selection: Clear justification of why specific treatment options were chosen, detailing expected benefits in relation to organizational objectives and risk appetite.
- Accountabilities and Responsibilities: Designation of specific roles for approving and implementing the plan. ISO 31000 distinguishes between:
- Risk Owner: The executive or manager holding ultimate accountability for managing the risk profile and accepting residual risk levels.
- Action Owner (Treatment Owner): The operational individual responsible for executing specific treatment tasks, controls, or milestones.
- Proposed Actions and Timelines: Detailed breakdown of control implementations, task sequences, start dates, key milestones, and target completion dates.
- Resource Requirements: Comprehensive allocation of required financial budget, human capital, specialized technology, training, and external consulting support.
- Performance Measures and KPIs: Quantifiable key performance indicators used to verify whether treatment actions are progressing on schedule and functioning as intended.
- Constraints and Fallback Plans: Identification of operational, regulatory, or technical constraints, alongside contingency plans if primary treatment controls fail or encounter delays.
- Reporting and Monitoring Schedules: Defined frequencies and channels for updating executive leadership and governance committees on plan execution.
Cost-Benefit Analysis (CBA) & Economic Justification
Risk treatment controls consume organizational resources. ISO 31000 requires organizations to justify treatment decisions by conducting a cost-benefit analysis (CBA) to ensure that treatment expenditures are economically proportionate to the risk reduction achieved.
The CBA Decision Rule
A treatment plan is economically justified when the Risk Reduction Value (RRV) exceeds the Total Cost of Treatment (TCT):
Where:
- Inherent Risk Exposure (IRE) = Financial / operational impact $\times$ inherent likelihood.
- Residual Risk Exposure (RRE) = Financial / operational impact $\times$ post-treatment likelihood.
- Risk Reduction Value (RRV) = $\text{IRE} - \text{RRE}$.
- Total Cost of Treatment (TCT) = Initial Capital Expenditure (CapEx) + Ongoing Operational Expenditure (OpEx) over the control lifecycle.
Economic Trade-Off Principles
- ALARP Principle (As Low As Reasonably Practicable): Treatment should be pursued until the cost of further risk reduction becomes grossly disproportionate to the benefit gained.
- Secondary Risks: Implementing treatment controls can introduce new risks (e.g., complex multi-factor authentication controls creating user friction and driving employees to bypass security protocols). CBA must account for the management of secondary risks.
ISO 31000 Risk Treatment Plan Content Framework
| Plan Element | ISO 31000 Requirement | Governance Focus | Practical Implementation Example |
|---|---|---|---|
| Rationale | Justify option selection against objectives | Strategic alignment | Aligning zero-trust network access with cloud migration goals |
| Accountability | Assign Risk Owner & Action Owner | Governance & operational execution | Chief Information Security Officer (Risk Owner); Network Engineering Lead (Action Owner) |
| Actions & Schedule | Milestones, start & completion dates | Project management | Phase 1 identity deployment (Q1); Phase 2 micro-segmentation (Q2) |
| Resources | Budget, staffing, technology allocation | Financial & resource planning | $450,000 CapEx; $75,000 annual OpEx; 2 full-time systems engineers |
| Performance Metrics | Track treatment efficiency & progress | Control effectiveness | 100% endpoint agent installation; zero unpatched critical vulnerabilities > 14 days |
| Constraints & Fallbacks | Address barriers; define contingency | Resiliency planning | Legacy mainframe incompatibility fallback: isolated air-gapped network segment |
| Reporting | Set progress review frequencies | Executive oversight | Monthly progress report to Risk Committee; quarterly Board dashboard update |
Residual Risk Evaluation and Formal Acceptance
Once a risk treatment plan is executed (or designed), the organization must evaluate the residual risk—the risk exposure remaining after treatment controls are applied.
Inherent Risk (Unmitigated) ──> [ Risk Treatment Controls ] ──> Residual Risk (Remaining)
Residual Risk Governance Workflow
- Comparison against Criteria: The residual risk rating is compared directly against the organization's pre-established risk criteria and risk appetite.
- Acceptability Decision:
- If Residual Risk $\le$ Risk Appetite: The Risk Owner formally approves and accepts the residual risk, transferring the risk profile into continuous monitoring.
- If Residual Risk $>$ Risk Appetite: The treatment plan is deemed insufficient. The Risk Owner must either iterate treatment design (seeking additional controls) or escalate the risk to executive leadership/Board for formal risk appetite exception approval.
Real-World Implementation Scenario: Cloud Banking Migration
A commercial bank migrates core customer ledgers to a public cloud environment.
- Inherent Risk: Catastrophic data breach involving 5,000,000 customer records (Inherent Exposure: $50,000,000).
- Treatment Plan Design:
- Option: Change Likelihood (Encryption at rest/in transit + IAM) & Share Risk ($25M Cyber Policy).
- Cost: $2,000,000 CapEx + $300,000 annual OpEx.
- Expected Residual Exposure: $3,000,000.
- CBA Result: RRV ($47,000,000) far exceeds TCT ($2,300,000), producing a Net Benefit of $44,700,000.
- Residual Acceptance: The $3,000,000 residual risk falls within the Board's $5,000,000 cyber risk appetite threshold. The Chief Risk Officer formally signs the residual risk acceptance log.
An organization completes the design of a $500,000 cybersecurity treatment plan expected to reduce potential breach losses from $5,000,000 to $800,000. However, the residual risk of $800,000 still exceeds the operational risk tolerance of $500,000. What is the most appropriate next step for the Risk Manager under ISO 31000:2018?
During the design of a risk treatment plan for an industrial facility, the project team designates the Operations Vice President as the "Risk Owner" and the Plant Engineer as the "Action Owner." What is the fundamental difference between these two roles in ISO 31000 governance?
What is a primary consideration when conducting a cost-benefit analysis (CBA) for a proposed risk treatment plan?