A ready-to-use risk register with scoring guidance, automatic ratings and worked examples. Built by people who have sat on both sides of the audit table.
2 worksheets, 3 worked examples, automatic scoring · Excel (.xlsx) · Free, no email required
A ready-to-use information security risk register for ISO/IEC 27001:2022, with a 5×5 scoring model built in. Enter likelihood and impact and the score and High / Medium / Low rating calculate automatically. Three worked example risks show the level of detail auditors expect.
| Column | What it captures |
|---|---|
| Risk description & asset affected | What could go wrong, and to which information, system or process |
| CIA impact | Whether confidentiality, integrity or availability is at stake |
| Likelihood & impact (1–5) | Scored against the guidance on the How to use sheet; score and rating calculate automatically |
| Treatment option | Avoid, Reduce, Transfer or Accept, with actions, owner and due date |
| Linked Annex A controls | The controls that treat the risk, feeding your Statement of Applicability |
| Status & next review | Keeps the register alive between audits instead of a one-off exercise |
It is the document where you record each information security risk, score its likelihood and impact, decide how to treat it, and track the treatment to completion. It is the working output of the risk assessment process required by clause 6.1.2 of ISO/IEC 27001:2022.
The standard requires a documented risk assessment process and retained results, and in practice every certification auditor expects a maintained register with scoring, owners, treatment decisions and review dates.
There is no required number, but most small businesses certifying for the first time identify 20 to 60 risks. Quality matters more than quantity: auditors look for risks specific to your business, each with an owner and a treatment decision.
In ISOvault, risks link to your actual assets, suppliers and Annex A controls, reviews are chased automatically, and the register exports as a Word document for your auditor. 14 days free, no card required.