Risk register template
A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.
Risk3 Sept 20265 min read
On this page
risk-register.xlsx · 13 kBLicensed CC BY 4.0
What this is
A working information security risk register: one sheet for the rows, one for the anchored scales and acceptance criteria, and one for the licence and the standing rules. It is the artefact produced by the method in The risk register other people trust. It exists to support one decision per row — treat the risk, or accept it, with a name and a date against the answer. A register that records no decision is a list, and a list is not evidence.
How to use it
- Fill the Scales sheet first. Consequence and likelihood both run 1 to 5, and each value carries a sentence-level anchor rather than an adjective. Replace every anchor with wording the organisation's own management forum will recognise. See the playbook, section 3.1.
- Have management approve the acceptance criteria on the same sheet: who may accept each level, for how long, and what record is required. Setting them is a management act. See the playbook, section 3.7.
- Delete the three example rows on the Register sheet before the first workshop. They show the shape of a row and nothing else.
- Write column B as a sentence. Risk statement takes a risk source, an event, a consequence and the affected asset or objective, which column C names separately. If a row starts "lack of", it is a control gap, not a risk. See the playbook, section 3.3.
- Score D then E, then read F. Likelihood and Consequence use the anchored values; Inherent level comes off the published lookup on the Scales sheet, never from multiplying the two. Record the evidence behind each score in the row.
- List what already exists in G, then set H. Existing controls is what is running today; Residual level is the level with those controls working as described.
- Take the two mandatory decisions. Treatment option is exactly one of modify, retain, avoid or share; a blank cell is an unmade decision. Accepted by and Accepted on are filled together or not at all.
- Close the loop in J, K and L. Treatment plan names the action, Control refs ties the row to the Statement of Applicability, and Risk owner names the role that holds both the accountability and the authority.
- Set O and P. Review date is mandatory on every row; Status moves through open, planned, in progress, accepted and closed.
Delete columns only where the organisation genuinely has no use for them, and record the change on the Read first sheet. Inherent level is the usual candidate: it is a house convention, not a term the standards define.
What good looks like
Six of the sixteen columns, from the example rows shipped in the workbook.
| ID | Risk statement (source / event / consequence) | Likelihood | Consequence | Treatment option | Accepted by / on |
|---|---|---|---|---|---|
| R-001 | An external attacker using bought credentials signs in to the customer portal from an unmanaged device and exports personal data belonging to portal users | 4 | 4 | Modify | — |
| R-002 | A single hosting region becomes unavailable for longer than the agreed recovery time and the ordering service stops accepting orders | 2 | 4 | Retain | Executive accountable for the revenue objective / 2026-08-18 |
| R-003 | An administrator with standing privileges makes an unreviewed change to a production access rule and removes a control the Statement of Applicability records as implemented | 3 | 3 | Modify | — |
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Risk statement | yes | Source, event, consequence, in one sentence | Naming a missing control instead of a risk |
| Asset or objective | yes | What the consequence lands on | An asset class so broad that scoring is meaningless |
| Likelihood, Consequence | yes | The anchored 1-5 values | Scoring against adjectives the scales never define |
| Inherent level, Residual level | house rule | The level before and after existing controls | Deriving either by multiplying the two scores |
| Treatment option | yes | One of modify, retain, avoid, share | Leaving it blank, which records no decision |
| Control refs (Annex A) | yes when treating | The link to the Statement of Applicability | References that do not reconcile in both directions |
| Risk owner | yes | The role with accountability and authority | The security function owning a business risk |
| Accepted by, Accepted on | yes when retaining | Who accepted the residual level, and when | An acceptance with no name, no date and no expiry |
| Review date | yes | When this row is next examined | A date that passes without a review being logged |
Download
- File:
risk-register.xlsx(xlsx, 13 KB) — three sheets: Register, Scales, Read first. - Markdown variant: the same three tables in plain markdown, at
content/templates/assets/_risk-register.mdin the content repository, for anyone who keeps their register in a text file or a wiki. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-03. Contains no personal data and no organisation names; the example rows are invented and describe no real event.
Related
- Playbook: The risk register other people trust
- Reference: the clause mapping in that playbook, section 7, ties every column to ISO/IEC 27005:2022, ISO/IEC 27001:2022 and ISO 31000:2018.
References
- ISO/IEC. Information security, cybersecurity and privacy protection — Guidance on managing information security risks. ISO/IEC 27005:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27005:ed-4:v1:en
[1](#grcide-source-1) - ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27001:ed-3:v1:en
[1](#grcide-source-1) - ISO. Risk management — Guidelines. ISO 31000:2018. https://www.iso.org/obp/ui/en/#iso:std:iso:31000:ed-2:v1:en
[1](#grcide-source-1)
Claims checked at write time, in the same columns the site's source log uses.
| Date accessed | Claim | Source title | URL |
|---|---|---|---|
| 2026-09-03 | Column set and sheet layout follow clauses 6.4, 7.2.1, 7.2.2, 7.3.2-7.3.4, 7.4, 8.2, 8.3-8.5 and 8.6.1-8.6.3; level of risk is defined as a combination, not a product (3.1.15), and the treatment options are those listed at 3.2.7 | ISO/IEC 27005:2022(en), Table of contents and Clause 3, ISO Online Browsing Platform | https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27005:ed-4:v1:en |
| 2026-09-03 | The control-reference column points at Annex A, Information security controls reference; assessment and treatment are operations under 8.2 and 8.3 | ISO/IEC 27001:2022(en), Table of contents, ISO Online Browsing Platform | https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27001:ed-3:v1:en |
| 2026-09-03 | The Scales sheet follows 6.3.4 Defining risk criteria, and the review column follows 6.6 Monitoring and review | ISO 31000:2018(en), Table of contents, ISO Online Browsing Platform | https://www.iso.org/obp/ui/en/#iso:std:iso:31000:ed-2:v1:en |
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.
Sources
- 1ISO OBP · verified 2026-09-03