Risk register template

A free, auditor-tested risk register template for ISO 27001, ISO 9001, ISO 42001 and ISO 31000 — with the exact fields, 5×5 scoring anchors and review cadence a certification auditor expects to see. Download the PDF, or run the same register live with owners, treatments and evidence attached.

Run it live instead

What a risk register must contain

Most SME registers fail audit for the same three reasons: no named owner, no separation of inherent and residual risk, and no evidence the register was reviewed. These columns fix all three.

FieldWhy it mattersExample
Risk IDUnique, never reused — auditors trace findings by ID.R-014
Risk descriptionThreat + vulnerability + consequence, in one sentence.Phishing compromises a finance mailbox, enabling invoice fraud.
Asset / process affectedLink to the asset inventory entry so scope is provable.Microsoft 365 — Finance
Risk ownerA named person, not a department. Owners accept residual risk.Head of Finance
Inherent likelihood (1–5)Before controls. Use frequency anchors, not gut feel.4 — expected several times a year
Inherent impact (1–5)Worst credible outcome across cost, service and reputation.4 — £25k–£100k loss
Existing controlsMap to Annex A / your controls catalogue.A.8.23 web filtering, MFA, payment call-back
Residual likelihood / impactAfter controls — this is what you actually govern.2 / 3
Treatment decisionTreat, tolerate, transfer or terminate — with a rationale.Treat
Action, owner, due dateEach treatment needs one accountable person and a date.Roll out payment verification — Finance Ops — 30 Sep
Review dateQuarterly for high risks, annually for low. Evidence of Clause 8.2.Quarterly

Scoring: likelihood × impact

Multiply likelihood (1–5) by impact (1–5) to get a score out of 25. Write the anchors down — a register where two people score the same risk differently will not survive Stage 2.

High
Score 15–25

Treat now. Escalate to management review with a funded action plan.

Medium
Score 8–12

Treat or tolerate with a documented rationale and an owner.

Low
Score 1–6

Tolerate and monitor. Review annually.

How to fill it in — six steps

  1. 1Download the template and copy the column headings into your register.
  2. 2Seed it with 10–15 real risks from incidents, audits and supplier issues — not a generic list.
  3. 3Score inherent likelihood and impact using the anchors, before you credit any controls.
  4. 4Map existing controls to each risk so you can see where you are genuinely covered.
  5. 5Re-score residual risk, then pick a treatment decision for anything above your appetite.
  6. 6Assign an owner and due date to every treatment, and set the review cadence.

Where the PDF stops and the platform starts

  • Automatic residual scoring and a live 5×5 heatmap across the whole register
  • Risks linked to assets, controls, Annex A and your Statement of Applicability
  • Treatment tasks with owners, due dates and reminders — no chasing spreadsheets
  • Evidence attached to each treatment, exportable as an audit pack
  • CSV import so an existing spreadsheet register migrates in one pass

Frequently asked questions

Is this risk register template free?

Yes. The PDF is free to download and use commercially, with no watermark and no card required. You can also run the same structure live inside ISO-STANDARD.app.

Does it meet ISO 27001:2022 requirements?

The fields cover Clause 6.1.2 (risk assessment), 6.1.3 (risk treatment with Annex A mapping), 8.2 (periodic assessment) and 8.3 (treatment implementation). Clause 6.1.3 also requires a Statement of Applicability, which the platform generates from the same data.

Which standards can I use it for?

It is standard-agnostic. The same structure works for ISO 27001, ISO 9001, ISO 20000-1, ISO 42001 and ISO 31000 — only the risk sources and appetite change.

Should I use a 5×5 matrix or quantitative scoring?

Start with 5×5 with written anchors so scores are reproducible. Move to quantified ranges (frequency × loss) for your top three existential risks once the register is stable.

How often should the register be reviewed?

Review high risks quarterly, everything else annually, and any risk immediately after a related incident, supplier change or major system change.

Can I import it into the platform?

Yes — the platform includes CSV import with a downloadable template, so an existing spreadsheet register can be migrated in one pass.

Get the template

Take the PDF, or skip the spreadsheet entirely and run your register in ISO-STANDARD.app with owners, treatments, evidence and audit-ready exports already wired together.