Courseiva
CRISCChapter 10 of 16Objective 3.2

Risk Treatment Planning and Implementation

Failing to plan for a risk is the same as deciding to accept it, often without realising it. If you do not deliberately choose a treatment strategy for a risk, you have implicitly chosen to let it happen. For the CRISC exam, you must master the process of moving from 'we have a risk' to 'here is exactly how we will handle it and who will do it'.

12 min read
Intermediate
Updated Jul 23, 2026
Reviewed by Johnson Ajibi· Senior Network & Security Engineer · MSc IT Security

A simple way to picture Risk Treatment Planning and Implementation

The Home Renovation Project Analogy

You have saved £45,000 to renovate your cramped, outdated kitchen. You cannot just spend the money all at once. You need a plan. This is your risk treatment plan. First, you identify the specific problems: the electrical wiring is from 1972 and could start a fire (high risk), the plumbing leaks under the sink (medium risk), and the countertops are scratched but functional (low risk). For the wiring, you decide to 'mitigate' the risk by hiring a licensed electrician to rewire the entire room. This costs £12,000. For the plumbing, you 'mitigate' as well by replacing the pipes, costing £1,500. For the scratched countertops, you 'accept' the risk and live with the scratches because the cost to replace them is too high compared to the benefit you would get. You also decide to 'transfer' the risk of accidental fire to an insurance company by paying an extra £50 a year on your homeowner's policy. Each decision—to mitigate, accept, transfer, or avoid—is a specific 'control' you select. Your project manager (the risk owner) creates a schedule: electrician comes week 1, plumber week 2, countertop installer never. This schedule is your 'implementation plan'. Six months later, you inspect the work. The wiring is safe, the pipes are dry, and you have a receipt from the insurance company. You have successfully treated every identified risk.

The CRISC exam tests your ability to build this exact blueprint— selecting the right 'control' (the type of treatment) for each 'risk' (the specific problem) and then making sure someone is accountable for actually doing the work.

How It Actually Works

After you have identified and analysed your risks (in a risk assessment), you must decide what to do about them. This decision-making process is called 'Risk Treatment'. A 'Risk Treatment Plan' (RTP) is the formal document that lists each significant risk and the specific actions you will take to address it.

The four main ways to treat a risk are called the 'Risk Treatment Options' or 'Risk Responses'. They are:

- Mitigate (Reduce): You take action to reduce the likelihood that the risk happens, or reduce the impact if it does happen. This is the most common option. Example: installing a firewall to reduce the likelihood of a hacker breaking into your network. - Accept (Retain): You formally acknowledge the risk exists and choose to do nothing about it. This is not ignoring the risk; it is a conscious decision, often because the cost of treatment is higher than the potential loss. Example: a small company with a low risk of losing paper files might accept that risk rather than buying a £10,000 document scanner. - Transfer (Share): You shift the financial burden of the risk to another party, usually through insurance or a contract. Example: buying cyber liability insurance transfers the financial risk of a data breach to the insurance company. - Avoid: You change the activity or project to eliminate the risk entirely. Example: if a software project is too risky, you cancel it. If a specific data centre is in a flood zone, you choose a different location. Once you have chosen an option for each risk, you must select the specific 'controls' to implement those options. A 'control' (also called a 'safeguard' or 'countermeasure') is a specific mechanism, policy, procedure, or piece of technology. For example, if you decide to 'mitigate' the risk of unauthorised access, your 'control' might be a password policy. The 'Risk Treatment Plan' itself has several key sections: - Risk ID and Description: A unique identifier and a brief description of the risk. - Treatment Option: Which of the four options (mitigate, accept, transfer, avoid) was chosen. - Selected Control(s): The specific controls you will put in place. - Risk Owner: The person who is accountable for ensuring the treatment happens. They do not necessarily implement the control themselves, but they are responsible for making sure it gets done. - Implementation Date: The target date by which the control should be operational. - Residual Risk: The risk that remains after the control is implemented. For example, if you install a firewall (control), the residual risk might be that a sophisticated hacker still gets through. After the plan is written, the next phase is 'Implementation'. This is the actual work of deploying the controls. The Risk Owner manages this, often using a project management approach. The implementation must be monitored to ensure it is on schedule and effective. Finally, a 'Post-Implementation Review' is conducted to confirm that the control works as intended and that the residual risk is at an acceptable level. The entire process is iterative. After implementation, you go back to 'Risk Assessment' to see if new risks have emerged or if the treated risks have changed. This cycle is part of a larger system called 'Risk Management', which is the ongoing process of identifying, assessing, and treating risks.

This diagram shows the sequential flow from risk identification through treatment option selection, implementation, and review.

Walk-Through

1

Identify Treatment Options

For each significant risk from your risk assessment, determine which of the four treatment options (mitigate, accept, transfer, avoid) is most appropriate based on cost, benefit, and organisational strategy.

2

Select Controls

If the chosen option is mitigate, select specific controls (e.g., firewall, encryption, policy) that will reduce the risk. For transfer, identify the insurance or contract. For accept, document the decision. For avoid, plan to stop the activity.

3

Assign Risk Owner

Appoint a person who is accountable for managing the risk and ensuring the treatment is implemented. This step formalises responsibility and prevents risks from being ignored.

4

Create Implementation Schedule

Develop a timeline for deploying the selected controls, including target dates, milestones, and resource assignments. This turns the plan into an actionable project.

5

Implement Controls

Execute the schedule by actually deploying the controls. This may involve installing software, changing processes, training staff, or signing contracts. The risk owner monitors progress.

6

Conduct Post-Implementation Review

After controls are deployed, verify that they work as intended. Assess the new residual risk level. If it is still too high, you may need to select additional controls or change the treatment option.

What This Looks Like on the Job

Consider a medium-sized retail company called 'ShopSmart' that wants to launch a new online payment system. The risk manager has identified a significant risk: a hacker could steal customer credit card numbers during the transaction. The risk manager calculates the risk level as 'High' because the likelihood of a breach is moderate and the financial impact (fines, lawsuits, reputation damage) is very high. The company decides to 'mitigate' this risk. Now, the risk manager must select controls. They evaluate several options: - Encryption: A control that scrambles the card number so it cannot be read if intercepted. - Tokenisation: A control that replaces the actual card number with a unique, worthless token. - Firewall: A control that blocks unauthorised network traffic. - Employee Training: A control to prevent employees from falling for phishing scams that could steal credentials. The risk manager, along with the IT department and the business owner, selects a combination of controls: encryption for data in transit (moving between the customer's browser and ShopSmart's server), tokenisation for data at rest (stored in the database), and a firewall. This set of controls is called a 'defence in depth' strategy. Next, a risk owner is assigned: the Head of IT Security. The implementation plan assigns specific tasks: the encryption software must be installed by 31 March, the tokenisation service must be contracted by 15 April, and the firewall configuration must be tested by 20 April. During implementation, the Head of IT Security discovers that the tokenisation service provider cannot deliver on time. This is a new risk that requires a new treatment decision (e.g., accept the delay, or choose a different provider). This shows how the process is not a straight line. After all controls are implemented, the risk manager performs a post-implementation review. They test the encryption, check the firewall logs, and confirm the tokenisation is working. The residual risk is now assessed as 'Low', which is within the company's 'risk appetite' (the amount of risk they are willing to take). The plan is documented in the official 'Risk Treatment Plan' and approved by senior management.

How CRISC Actually Tests This

The CRISC exam will test you on the specifics of risk treatment, not just general knowledge. You must be precise about which option to use in which scenario. Exam Topic 1: The Four Treatment Options. You will be given a scenario and asked which treatment option is most appropriate. The trap is that 'Accept' is often the correct answer when the cost of controls exceeds the expected loss. Do not assume 'Mitigate' is always the best answer. Exam Topic 2: Residual vs. Inherent Risk. The exam loves this distinction. 'Inherent risk' is the level of risk before any controls are applied. 'Residual risk' is the level after controls are applied. A risk treatment plan is designed to bring residual risk down to an acceptable level. Exam Topic 3: Risk Owner vs. Control Owner. A 'risk owner' is accountable for the treatment of a specific risk. A 'control owner' is accountable for the proper operation of a specific control. These are often different people. The exam will test whether you understand that the risk owner remains accountable even if another person implements the control. Exam Topic 4: The Importance of the Risk Treatment Plan (RTP) Document. They will ask about what must be included in a plan. Key items: risk ID, treatment option, selected controls, risk owner, implementation date, and residual risk. Leaving out the residual risk is a common exam trap. Trap Pattern: 'Accept' vs. 'Ignore'. The exam will set a trap where a manager says 'we will do nothing about this risk'. The correct answer is 'accept the risk' only if it is a formal, documented decision. If it is just ignoring it, it is not 'accept' in the risk management sense. Trap Pattern: 'Avoid' vs. 'Mitigate'. Avoid means stopping the activity entirely. Mitigate means reducing the risk while continuing the activity. If a scenario describes a company that decides not to launch a risky project, the answer is 'avoid', not 'mitigate'. Key Definitions to Memorise: - Risk Treatment: The process of selecting and implementing measures to modify risk. - Control: A measure that modifies risk. - Residual Risk: Risk remaining after risk treatment. - Risk Owner: A person or entity with the accountability and authority to manage a risk. - Risk Appetite: The amount of risk an organisation is willing to accept.

Key Takeaways

The four risk treatment options are mitigate, accept, transfer, and avoid; knowing when to use each is a core CRISC objective.

A risk treatment plan must document the residual risk after controls are applied, not just the inherent risk before controls.

The risk owner is accountable for the treatment of a specific risk, even if they delegate the implementation of controls.

Risk acceptance is a formal, documented decision, not an oversight or denial of the risk.

Controls must be monitored and reviewed regularly because they can become ineffective over time.

Residual risk is the level of risk that remains after treatment and must be formally accepted if it exceeds the risk appetite.

Easy to Mix Up

These come up on the exam all the time. Here's how to tell them apart.

Risk Owner

Accountable for managing a specific risk

Has authority to decide treatment options

Remains accountable even if work is delegated

Control Owner

Accountable for the correct operation of a specific control

Implements and maintains the control

Reports to the risk owner on control status

Inherent Risk

Risk level before any controls are applied

Higher than residual risk if controls are effective

Used to determine if treatment is necessary

Residual Risk

Risk level after controls are implemented

Should be within the organisation's risk appetite

Must be documented in the risk treatment plan

Mitigate (Reduce)

Reduces likelihood or impact of a risk

Activity continues at a lower risk level

Common for operational risks

Avoid (Eliminate)

Eliminates the risk entirely by not doing the activity

Activity is cancelled or not started

Used when the risk is too high to accept or mitigate

Accept (Retain)

Organisation keeps the full risk

No action taken to reduce or shift the risk

Used when treatment cost exceeds potential loss

Transfer (Share)

Financial burden is shifted to a third party

Risk is not eliminated; loss still occurs

Commonly done through insurance

Watch Out for These

Mistake

Once you implement a control, the risk is gone forever.

Correct

Risk treatment is not a one-time event. Controls can fail, new risks can emerge, and the effectiveness of controls must be monitored and reviewed regularly.

Beginners often think of risk management as a checklist that is completed and closed, similar to fixing a broken window. In reality, it is a continuous cycle.

Mistake

Risk acceptance means you are doing nothing about a risk, which is irresponsible.

Correct

Risk acceptance is a formal, documented decision to retain the risk because the cost of treatment exceeds the benefit. It is a valid and responsible strategy when done properly.

The word 'accept' sounds passive and lazy, so beginners assume it is always wrong. The exam deliberately tests this by asking about scenarios where acceptance is the correct choice.

Mistake

The risk owner must personally implement all the controls for their risk.

Correct

The risk owner is accountable for the treatment of the risk, but they often delegate the implementation to a control owner or another team. Accountability cannot be delegated, but the hands-on work can be.

People confuse 'accountability' with 'doing the work'. The exam uses this to test whether you understand that a manager can be responsible for a risk even if they are not an IT technician.

Mistake

If you transfer a risk (e.g., buy insurance), you no longer have to worry about that risk at all.

Correct

Transferring a risk (like buying insurance) does not make the risk disappear. It only transfers the financial consequence. The operational risk (e.g., the data breach still happens, customer data is still exposed) remains with the organisation.

Beginners think 'transfer' means 'get rid of'. They do not realise that insurance compensates you after the loss—it does not prevent the loss from happening.

Mistake

A risk treatment plan is the same thing as a business continuity plan.

Correct

A risk treatment plan focuses on specific risks and how to treat them before they materialise. A business continuity plan focuses on how to keep operating after a disaster has occurred. They are related but different documents.

Both terms involve planning for problems, so beginners lump them together. The exam tests the distinct purpose of each document.

Do You Actually Know This?

Reveal each answer, then mark whether you got it right. Score 60%+ to unlock the next chapter.

Frequently Asked Questions

What is the difference between inherent risk and residual risk?

Inherent risk is the level of risk before any controls are applied. Residual risk is the level of risk that remains after controls are implemented. The goal of risk treatment is to reduce inherent risk to an acceptable residual risk.

If we accept a risk, do we have to write it down?

Yes. Risk acceptance must be a formal, documented decision, typically approved by senior management. If it is not documented, it is not 'acceptance'—it is neglect.

Can we use more than one treatment option for a single risk?

Yes. For example, you might mitigate a risk by installing a firewall and also transfer the remaining financial risk by buying insurance. The combination of treatments is part of your overall risk treatment plan.

Who decides which treatment option to use?

The decision is typically made by the risk owner in consultation with the risk manager and senior management. The choice is based on the risk assessment, cost-benefit analysis, and the organisation's risk appetite.

What does a risk treatment plan look like?

It is a formal document, usually a spreadsheet or database, that lists each risk, the chosen treatment option, the specific controls, the risk owner, implementation dates, and the residual risk level.

Is risk treatment the same as risk management?

No. Risk treatment is one part of the broader risk management process. Risk management includes risk identification, risk assessment, risk treatment, and ongoing monitoring and review.

Terms Worth Knowing

Keep going

You've finished Risk Treatment Planning and Implementation. Continue through the CRISC study guide to build a complete picture of the exam.

Done with this chapter?