Back to templates
    Template

    Risk register template

    A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.

    Risk3 Sept 20263 min readUpdated 5 Sept 2026

    ISO 31000:2018ISO/IEC 27001:2022ISO/IEC 27005:2022
    On this page
    Download the template

    risk-register.xlsx · 13 kBLicensed CC BY 4.0

    What this is

    A working information security risk register: one sheet for the rows, one for the anchored scales and acceptance criteria, and one for the licence and the standing rules. It is the artefact produced by the method in The risk register other people trust, and it supports one decision per row: treat the risk, or accept it, with a name and a date. A register that records no decision is a list, and a list is not evidence.

    How to use it

    1. Fill the Scales sheet first. Consequence and likelihood both run 1 to 5, and each value carries a sentence-level anchor rather than an adjective. Replace every anchor with wording the organisation's own management forum will recognise. See the playbook, section 3.1.
    2. Have management approve the acceptance criteria on the same sheet: who may accept each level, for how long, and what record is required. See the playbook, section 3.7.
    3. Delete the three example rows, then fill the Register sheet left to right. The Fields table below names each column; the playbook, sections 3.3 to 3.5, explains the thinking.
    4. Read Inherent level off the published lookup on the Scales sheet, never from multiplying likelihood by consequence.
    5. Take the two mandatory decisions on every row. Treatment option is exactly one of modify, retain, avoid or share; Accepted by and Accepted on are filled together or not at all.
    6. Close the row. Review date is mandatory, and Status moves through open, planned, in progress, accepted and closed.

    Delete a column only if the organisation has no use for it, and record that on the Read first sheet.

    What good looks like

    Six of the sixteen columns, from the rows shipped in the workbook.

    IDRisk statementLikelihoodConsequenceTreatmentAccepted by / on
    R-001Bought credentials used to sign in to the customer portal and export personal data44Modify—
    R-002A hosting region unavailable past the agreed recovery time stops the ordering service24RetainRevenue objective owner / 2026-08-18
    R-003An unreviewed production access change removes a control the Statement of Applicability records as implemented33Modify—

    Fields

    FieldRequiredMeaningCommon mistake
    Risk statementyesSource, event, consequence, in one sentenceA missing control written as a risk
    Asset or objectiveyesWhat the consequence lands onA class too broad to score
    Likelihood, ConsequenceyesThe anchored 1-5 valuesScoring against undefined adjectives
    Inherent level, Residual levelhouse ruleThe level before and after existing controlsMultiplying the two scores
    Treatment option, Control refsyesThe decision, and the link to the Statement of ApplicabilityA blank option, or references that do not reconcile
    Risk owner, Accepted by, Accepted onyes when retainingWho holds the risk, who accepted it, and whenAn acceptance with no name, date or expiry
    Review date, StatusyesWhen the row is next examined, and where it standsA date that passes with no review logged

    Download

    • File: risk-register.xlsx (xlsx, 13 KB) — three sheets: Register, Scales, Read first.
    • Markdown variant: the same three tables in plain markdown, at content/templates/assets/_risk-register.md.
    • Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
    • Version: 1.0, 2026-09-03. No personal data or organisation names; the example rows are invented.

    References

    1. ISO/IEC. Information security, cybersecurity and privacy protection — Guidance on managing information security risks. ISO/IEC 27005:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27005:ed-4:v1:en [1](#grcide-source-1)
    2. ISO/IEC. Information security, cybersecurity and privacy protection — Information security management systems — Requirements. ISO/IEC 27001:2022. https://www.iso.org/obp/ui/en/#iso:std:iso-iec:27001:ed-3:v1:en [1](#grcide-source-1)
    3. ISO. Risk management — Guidelines. ISO 31000:2018. https://www.iso.org/obp/ui/en/#iso:std:iso:31000:ed-2:v1:en [1](#grcide-source-1)

    Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by ISO, IEC, NIST or any other standards body.

    Sources

    1. 1ISO OBP · verified 2026-09-03