If risk owners avoid updating the treatment plan, check how much work a routine update requires. A short schedule with clear actions, owners, deadlines and monitoring can make maintenance part of normal work.

A risk treatment plan template: why simpler beats comprehensive
There is a persistent belief that a good risk treatment schedule needs to capture everything: original rating, target rating, budget, sub-tasks, dependencies, linked controls, review history. Each addition is individually defensible. Together, they produce a document so heavy that only one person in the organisation can maintain it, and when that person leaves, the schedule stops being touched within a quarter.
A treatment plan’s job is narrow: tell you what is being done about a risk, who is doing it, by when, whether it is working, and how you would know. Everything beyond that belongs in a separate risk register, a project plan, or a budget line — not bolted onto the same sheet where a manager is supposed to update progress in five minutes on a Friday afternoon.
The six columns
- Risk, by priority. Not the full risk description — a short reference back to the register entry, ordered so the highest-priority items sit at the top where they get looked at first.
- Treatment strategy. One of a small, fixed set: treat, tolerate, transfer, or terminate the activity that creates the risk. Forcing a choice from four options, rather than a free-text paragraph, keeps this scannable and comparable across the whole schedule.
- Residual risk. The rating expected once the treatment is complete, so anyone reading the schedule can see what “done” is supposed to look like without cross-referencing a separate document.
- Person responsible. One name. Not a team, not a department — a single accountable person who can be asked directly why an item has not moved.
- Implementation deadline. A date, not a quarter or a financial year. Vague deadlines are the single easiest way for an item to sit untouched for a year without anyone technically being overdue.
- Monitoring method. How progress and effectiveness will actually be checked — an audit, a test, a report, a re-assessment — so the schedule does not rely on the responsible person simply asserting the risk is now under control.
A worked example: Bramfield Council
Bramfield Council is a fictional local government body managing a moderate-risk finding from its last audit: contractor access to the finance system was not being reviewed after contract completion.
| Risk (priority) | Treatment strategy | Residual risk | Responsible | Deadline | Monitoring method |
|---|---|---|---|---|---|
| Contractor access not reviewed post-completion (High) | Treat | Low | IT Systems Manager | 31 Oct | Quarterly access audit, reported to Risk Committee |
| Single point of failure in payroll processing (Medium) | Treat | Medium | Finance Manager | 15 Dec | Cross-training completion sign-off |
| Reputational exposure from social media policy gaps (Low) | Tolerate | Low | Communications Lead | — | Annual policy review |
Three rows, six columns each, and a reader can tell in under a minute what is happening, who owns it, when it is due, and how anyone will know if it worked. The tolerated risk is included deliberately — a treatment schedule that only lists items being actively treated hides the fact that some risks were assessed and consciously accepted, which is itself a decision worth recording.
Why “monitoring method” is the column people skip, and shouldn’t
A monitoring method that reads “ongoing” or is left blank does not explain how anyone will verify progress. This turns the whole plan into an honesty exercise — the responsible person reports progress, and nobody has an independent way to check it. A monitoring method does not need to be elaborate. It needs to specify a mechanism that exists independently of the person doing the work: a scheduled audit, a system report, a second person’s sign-off, a test result. If you cannot name that mechanism, the treatment is not actually being monitored, whatever the schedule implies.
How often the schedule should actually be reviewed
A six-column schedule is only as good as the discipline around updating it. Reviewing every item on the same fixed cycle — quarterly, say, regardless of priority — is how high-priority items end up getting the same cursory glance as low-priority ones that were correctly left to tolerate. Tie review frequency to urgency, consequences and the speed at which conditions can change. Monthly, quarterly and annual reviews may suit some activities, while urgent treatments need much more frequent follow-up. Record event-triggered reviews as well as calendar dates.
This does not need a seventh column. It can be a simple standing rule applied by priority band, stated once at the top of the schedule or in the governing policy, rather than negotiated item by item. The point is to put review effort where the risk actually is, rather than spreading it evenly across items that do not carry equal weight. A council or a mid-size firm running this discipline consistently will find that the schedule becomes a genuine agenda item for a risk committee, rather than a document tabled and skimmed once a quarter out of habit.
Common mistakes
- Free-text treatment strategies instead of a fixed set. “Working on it” is not a strategy. Forcing treat, tolerate, transfer or terminate keeps the schedule comparable and makes tolerated risks visible instead of silently dropped.
- A deadline of “Q3” or “ongoing.” Both function as no deadline at all. Use a date.
- Listing a team or department as responsible. Shared accountability is no accountability. One name, one person who can answer for the item.
- No independent monitoring method. Self-reported progress with nothing to verify it is a plan that looks complete and is not.
- Mixing the treatment schedule with the full risk register. Keeping every field of the register duplicated onto the treatment schedule is exactly the bloat that makes people stop updating it. Link back to the register; do not rebuild it here.
Where this fits with the rest of your documentation
A treatment schedule this lean only works if the plan it sits inside is equally clear about roles and escalation — see How to Write a Security Plan (Free Outline Template) if that structure is not yet in place. It is also worth checking that the risks driving this schedule were properly assessed at a personnel level in the first place, particularly where access and contractor risk are involved; Insider Threat Self-Assessment for Senior Managers (Free Checklist) is a useful companion for that. And if part of your treatment plan involves staff using AI tools to draft policy language or analyse register data, it is worth a quick gut check first — Is It Safe to Paste This Into ChatGPT? A Thirty-Second Test covers exactly that.
Get the template
The SRMBOK Template 13.4 Risk Treatment Schedule is built around this same six-column discipline — risk by priority, treatment strategy, residual risk, person responsible, implementation deadline and monitoring method — with compiler and reviewer fields so it is clear who built the schedule and who checked it. Download the SRMBOK Template 13.4 Risk Treatment Schedule and replace whatever spreadsheet nobody has opened since March.
