Back to templates
    Template

    Risk register template

    A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.

    Risk3 Sept 20265 min read

    ISO 31000:2018ISO/IEC 27001:2022ISO/IEC 27005:2022
    On this page
    Download the template

    risk-register.xlsx · 13 kBLicensed CC BY 4.0

    What this is

    A working information security risk register: one sheet for the rows, one for the anchored scales and acceptance criteria, and one for the licence and the standing rules. It is the artefact produced by the method in The risk register other people trust. It exists to support one decision per row — treat the risk, or accept it, with a name and a date against the answer. A register that records no decision is a list, and a list is not evidence.

    How to use it

    1. Fill the Scales sheet first. Consequence and likelihood both run 1 to 5, and each value carries a sentence-level anchor rather than an adjective. Replace every anchor with wording the organisation's own management forum will recognise. See the playbook, section 3.1.
    2. Have management approve the acceptance criteria on the same sheet: who may accept each level, for how long, and what record is required. Setting them is a management act. See the playbook, section 3.7.
    3. Delete the three example rows on the Register sheet before the first workshop. They show the shape of a row and nothing else.
    4. Write column B as a sentence. Risk statement takes a risk source, an event, a consequence and the affected asset or objective, which column C names separately. If a row starts "lack of", it is a control gap, not a risk. See the playbook, section 3.3.
    5. Score D then E, then read F. Likelihood and Consequence use the anchored values; Inherent level comes off the published lookup on the Scales sheet, never from multiplying the two. Record the evidence behind each score in the row.
    6. List what already exists in G, then set H. Existing controls is what is running today; Residual level is the level with those controls working as described.
    7. Take the two mandatory decisions. Treatment option is exactly one of modify, retain, avoid or share; a blank cell is an unmade decision. Accepted by and Accepted on are filled together or not at all.
    8. Close the loop in J, K and L. Treatment plan names the action, Control refs ties the row to the Statement of Applicability, and Risk owner names the role that holds both the accountability and the authority.
    9. Set O and P. Review date is mandatory on every row; Status moves through open, planned, in progress, accepted and closed.

    Delete columns only where the organisation genuinely has no use for them, and record the change on the Read first sheet. Inherent level is the usual candidate: it is a house convention, not a term the standards define.

    What good looks like

    Six of the sixteen columns, from the example rows shipped in the workbook.

    IDRisk statement (source / event / consequence)LikelihoodConsequenceTreatment optionAccepted by / on
    R-001An external attacker using bought credentials signs in to the customer portal from an unmanaged device and exports personal data belonging to portal users44Modify
    R-002A single hosting region becomes unavailable for longer than the agreed recovery time and the ordering service stops accepting orders24RetainExecutive accountable for the revenue objective / 2026-08-18
    R-003An administrator with standing privileges makes an unreviewed change to a production access rule and removes a control the Statement of Applicability records as implemented33Modify

    Fields

    FieldRequiredMeaningCommon mistake
    Risk statementyesSource, event, consequence, in one sentenceNaming a missing control instead of a risk
    Asset or objectiveyesWhat the consequence lands onAn asset class so broad that scoring is meaningless
    Likelihood, ConsequenceyesThe anchored 1-5 valuesScoring against adjectives the scales never define
    Inherent level, Residual levelhouse ruleThe level before and after existing controlsDeriving either by multiplying the two scores
    Treatment optionyesOne of modify, retain, avoid, shareLeaving it blank, which records no decision
    Control refs (Annex A)yes when treatingThe link to the Statement of ApplicabilityReferences that do not reconcile in both directions
    Risk owneryesThe role with accountability and authorityThe security function owning a business risk
    Accepted by, Accepted onyes when retainingWho accepted the residual level, and whenAn acceptance with no name, no date and no expiry
    Review dateyesWhen this row is next examinedA date that passes without a review being logged

    Download

    • File: risk-register.xlsx (xlsx, 13 KB) — three sheets: Register, Scales, Read first.
    • Markdown variant: the same three tables in plain markdown, at content/templates/assets/_risk-register.md in the content repository, for anyone who keeps their register in a text file or a wiki.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-03. Contains no personal data and no organisation names; the example rows are invented and describe no real event.
    • Playbook: The risk register other people trust
    • Reference: the clause mapping in that playbook, section 7, ties every column to ISO/IEC 27005:2022, ISO/IEC 27001:2022 and ISO 31000:2018.

    References

    1. ISO/IEC. Information security, cybersecurity and privacy protection — Guidance on managing information security risks. ISO/IEC 27005:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27005:ed-4:v1:en [1](#grcide-source-1)
    2. ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27001:ed-3:v1:en [1](#grcide-source-1)
    3. ISO. Risk management — Guidelines. ISO 31000:2018. https://www.iso.org/obp/ui/en/#iso:std:iso:31000:ed-2:v1:en [1](#grcide-source-1)

    Claims checked at write time, in the same columns the site's source log uses.

    Date accessedClaimSource titleURL
    2026-09-03Column set and sheet layout follow clauses 6.4, 7.2.1, 7.2.2, 7.3.2-7.3.4, 7.4, 8.2, 8.3-8.5 and 8.6.1-8.6.3; level of risk is defined as a combination, not a product (3.1.15), and the treatment options are those listed at 3.2.7ISO/IEC 27005:2022(en), Table of contents and Clause 3, ISO Online Browsing Platformhttps://www.iso.org/obp/ui/en/#iso:std:iso-iec:27005:ed-4:v1:en
    2026-09-03The control-reference column points at Annex A, Information security controls reference; assessment and treatment are operations under 8.2 and 8.3ISO/IEC 27001:2022(en), Table of contents, ISO Online Browsing Platformhttps://www.iso.org/obp/ui/en/#iso:std:iso-iec:27001:ed-3:v1:en
    2026-09-03The Scales sheet follows 6.3.4 Defining risk criteria, and the review column follows 6.6 Monitoring and reviewISO 31000:2018(en), Table of contents, ISO Online Browsing Platformhttps://www.iso.org/obp/ui/en/#iso:std:iso:31000:ed-2:v1:en

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO OBP · verified 2026-09-03