Risk register template
A free, auditor-tested risk register template for ISO 27001, ISO 9001, ISO 42001 and ISO 31000 — with the exact fields, 5×5 scoring anchors and review cadence a certification auditor expects to see. Download the PDF, or run the same register live with owners, treatments and evidence attached.
What a risk register must contain
Most SME registers fail audit for the same three reasons: no named owner, no separation of inherent and residual risk, and no evidence the register was reviewed. These columns fix all three.
| Field | Why it matters | Example |
|---|---|---|
| Risk ID | Unique, never reused — auditors trace findings by ID. | R-014 |
| Risk description | Threat + vulnerability + consequence, in one sentence. | Phishing compromises a finance mailbox, enabling invoice fraud. |
| Asset / process affected | Link to the asset inventory entry so scope is provable. | Microsoft 365 — Finance |
| Risk owner | A named person, not a department. Owners accept residual risk. | Head of Finance |
| Inherent likelihood (1–5) | Before controls. Use frequency anchors, not gut feel. | 4 — expected several times a year |
| Inherent impact (1–5) | Worst credible outcome across cost, service and reputation. | 4 — £25k–£100k loss |
| Existing controls | Map to Annex A / your controls catalogue. | A.8.23 web filtering, MFA, payment call-back |
| Residual likelihood / impact | After controls — this is what you actually govern. | 2 / 3 |
| Treatment decision | Treat, tolerate, transfer or terminate — with a rationale. | Treat |
| Action, owner, due date | Each treatment needs one accountable person and a date. | Roll out payment verification — Finance Ops — 30 Sep |
| Review date | Quarterly for high risks, annually for low. Evidence of Clause 8.2. | Quarterly |
Scoring: likelihood × impact
Multiply likelihood (1–5) by impact (1–5) to get a score out of 25. Write the anchors down — a register where two people score the same risk differently will not survive Stage 2.
Treat now. Escalate to management review with a funded action plan.
Treat or tolerate with a documented rationale and an owner.
Tolerate and monitor. Review annually.
How to fill it in — six steps
- 1Download the template and copy the column headings into your register.
- 2Seed it with 10–15 real risks from incidents, audits and supplier issues — not a generic list.
- 3Score inherent likelihood and impact using the anchors, before you credit any controls.
- 4Map existing controls to each risk so you can see where you are genuinely covered.
- 5Re-score residual risk, then pick a treatment decision for anything above your appetite.
- 6Assign an owner and due date to every treatment, and set the review cadence.
Where the PDF stops and the platform starts
- Automatic residual scoring and a live 5×5 heatmap across the whole register
- Risks linked to assets, controls, Annex A and your Statement of Applicability
- Treatment tasks with owners, due dates and reminders — no chasing spreadsheets
- Evidence attached to each treatment, exportable as an audit pack
- CSV import so an existing spreadsheet register migrates in one pass
Frequently asked questions
Is this risk register template free?
Yes. The PDF is free to download and use commercially, with no watermark and no card required. You can also run the same structure live inside ISO-STANDARD.app.
Does it meet ISO 27001:2022 requirements?
The fields cover Clause 6.1.2 (risk assessment), 6.1.3 (risk treatment with Annex A mapping), 8.2 (periodic assessment) and 8.3 (treatment implementation). Clause 6.1.3 also requires a Statement of Applicability, which the platform generates from the same data.
Which standards can I use it for?
It is standard-agnostic. The same structure works for ISO 27001, ISO 9001, ISO 20000-1, ISO 42001 and ISO 31000 — only the risk sources and appetite change.
Should I use a 5×5 matrix or quantitative scoring?
Start with 5×5 with written anchors so scores are reproducible. Move to quantified ranges (frequency × loss) for your top three existential risks once the register is stable.
How often should the register be reviewed?
Review high risks quarterly, everything else annually, and any risk immediately after a related incident, supplier change or major system change.
Can I import it into the platform?
Yes — the platform includes CSV import with a downloadable template, so an existing spreadsheet register can be migrated in one pass.
Get the template
Take the PDF, or skip the spreadsheet entirely and run your register in ISO-STANDARD.app with owners, treatments, evidence and audit-ready exports already wired together.
