Risk Treatment
Risk treatment is the process of addressing identified risks to reduce them to acceptable levels.
Treatment Options
Mitigate
Implement controls to reduce likelihood or impact.
- Most common treatment
- Links to control library
- Reduces residual risk
Accept
Acknowledge the risk and monitor it.
- For low-level risks
- Within risk appetite
- Requires documentation
Transfer
Shift risk to a third party.
- Insurance policies
- Outsourcing
- Contractual arrangements
Avoid
Eliminate the risk source entirely.
- Stop the risky activity
- Change business process
- Most drastic option
Setting Treatment
- Open a risk
- Go to Overview tab
- Select Treatment type
- Document the treatment plan
- Save
Treatment Plans
For each treatment, document:
| Element | Description |
|---|---|
| Treatment Type | Mitigate, Accept, Transfer, Avoid |
| Description | How the risk will be treated |
| Controls | Linked controls (for mitigation) |
| Owner | Person responsible |
| Target Date | When treatment should be complete |
| Status | Progress of treatment |
Linking Controls
For mitigation treatment:
- Open the risk
- Go to Controls tab
- Click Map Controls
- Select controls that address this risk
- Confirm mapping
This shows:
- Which controls mitigate the risk
- Expected risk reduction
- Gaps in coverage
Residual Risk
After treatment, assess residual risk:
- Implement planned controls
- Perform residual risk assessment
- Compare to inherent risk
- Verify risk is within appetite
Residual Risk Formula
Residual Risk = Inherent Risk - Control Effectiveness
Treatment Tasks
Create tasks to track treatment:
- Open the risk
- Go to Tasks tab
- Click Create Task
- Define:
- Task title
- Assignee
- Due date
- Description
- Track to completion
Treatment Status
| Status | Description |
|---|---|
| Planned | Treatment identified, not started |
| In Progress | Treatment being implemented |
| Completed | Treatment fully implemented |
| Verified | Effectiveness confirmed |
Monitoring
After treatment:
- Schedule periodic reviews
- Reassess risk levels
- Update treatment as needed
- Document changes
Best Practices
- Match treatment to risk — High risks need strong treatment
- Document decisions — Explain why you chose each treatment
- Set deadlines — Treatment should have target dates
- Verify effectiveness — Reassess after treatment
- Review regularly — Treatments may need adjustment