Controls & Treatment

How to write a risk treatment plan on Mac

RiskOS keeps the decision, the plan, the date and the work on the risk itself, where the score can answer back.

A score says how much a risk could cost you. A treatment plan says what you have decided to do about it, by when, and what will be different afterwards. That second record is the one a board, an auditor or your successor actually reads, and it is the whole difference between a register that observes problems and one that moves them.

Note

Treatment is a decision, not a calculation. Choosing Mitigate never moves a score by itself — only the controls you link, or an effectiveness value you set by hand, change what the register reports.

Where the treatment plan lives

Choose Risks in the sidebar and click the row you want. The panel on the right holds the risk's sections in order, and Treatment sits below Assessment. It is deliberately short: the strategy, the plan itself, and a due date. Beneath it, Actions carries the individual pieces of work the plan breaks into, each one editable where it sits.

Two neighbouring sections matter while you are writing. Appetite shows the threshold this risk is measured against and where that threshold is inherited from. Controls holds what you already rely on, with a picker to link an existing control or create a new one. A plan written without a glance at both tends to promise something the register cannot later show.

Write a treatment plan, step by step

  1. Open the risk and read where it stands

    Choose Risks, select the row, and open Assessment. Note three things before writing a word: the inherent score, the residual score your linked controls produce, and whether the header carries the over-appetite flag. A treatment plan is a response to the distance between those numbers, and RiskOS keeps all three in the same panel so that distance stays in front of you.

  2. Set the target you intend to reach

    Set the target likelihood and impact at the foot of Assessment. The comparison grid then lays out inherent, residual, target and the gap still to cover, with a line naming what strength of control would close it. A plan without a target is an activity. A plan with one is a commitment somebody can check in six months.

  3. Choose one of the four strategies

    Open Treatment and choose Mitigate, Accept, Transfer or Avoid. Choose against the residual position rather than the inherent one: the question is not how frightening the risk would be with nothing in place, but whether what is left is something you are willing to carry.

  4. Write the plan so a stranger could follow it

    Use the plan field to name the change, not the intention. Say what will be different, what will prove it happened, and what the work depends on. Write for somebody who has never met the risk — a colleague picking this up next year, or an assessor reading the register cold. Changes save as you type.

  5. Give the plan a due date

    Set the due date on the same section. Pick the date the change is meant to be real, not the date you hope to start, and prefer a near date you will meet to a distant one nobody will remember. An undated plan cannot be late, which sounds comfortable and is the reason nothing moves.

  6. Break the plan into actions with owners

    Open Actions in the same panel and add the pieces of work the plan implies. Each row takes a title, a status of Not Started, In Progress or Done, a priority of High, Normal or Low, an owner and a due date, all edited in place. Three or four concrete actions beat one heroic sentence every time.

  7. Open Controls and link what already exists, then use the picker to create the control your plan is going to build and leave its status as planned. Only controls that are implemented or operating reduce a score, so the residual stays honest while the work is outstanding and answers on the day you change the status.

  8. Set the cadence that brings it back

    In Summary, set the review cadence and the next review date. That is what puts the risk back in front of you — in the overdue counts, and in Review, which walks the risks that are due one at a time, worst first, with the plan, the actions and the controls beside the scoring inputs.

The four strategies, and when each is honest

The four words are old and worn, which makes them easy to choose carelessly. Each one commits you to something visible, and the register is where that visibility either appears or does not. RiskOS holds the choice as a field on the risk, so it can be sorted, filtered, changed in bulk and reported on, rather than living in a paragraph somebody has to go and read.

The four treatment strategies and what each one commits you to
StrategyWhat you are sayingWhat should then be visible on the risk
MitigateYou will reduce the likelihood, the impact, or both.A target below the residual, dated actions, and at least one control being built or strengthened.
AcceptYou will carry this exposure as it stands.A residual inside appetite, or a written reason for sitting above it, and a review date that brings it back.
TransferSomeone else will carry part of the consequence.The counterparty recorded as a vendor, and a plan naming the portion you still keep.
AvoidYou will stop doing the thing that creates the risk.A date the activity ends, and the risk closed rather than deleted once it has.

Accept is a decision, not a default

Acceptance is the most useful of the four and the most abused. Used well, it is a named person saying the cost of treatment exceeds the cost of the exposure, recorded where anyone can find it. Used badly, it is what a risk drifts into when nobody has time for it. The test is simple: if you cannot write a sentence in the plan field explaining why carrying it is reasonable, you have not accepted the risk, you have ignored it. Accepted risks stay in the register and stay visible; the register's filters let you show or hide closed and accepted rows depending on the pass you are making.

Transfer moves the cost, not the accountability

Insurance, a contractual cap, an outsourced service: each moves part of the financial consequence elsewhere. None of them moves the disruption, the regulatory exposure or the phone call to your customers. Write the residual portion into the plan explicitly, record the counterparty under Vendors with a criticality and a relationship owner, and remember that transferring to a supplier usually creates a second, quieter risk — concentration in that supplier.

What a plan should actually say

Most treatment plans fail in the writing rather than the doing. They describe a direction rather than a change, which means nobody can tell whether the work is finished. Four lines, rewritten, show the pattern.

Weak treatment plan lines and stronger replacements
A line that will not surviveWhy it failsA line that will
Improve backups.No one can say when it is finished.Complete a full restore rehearsal of the finance file share and record the result as evidence on CTL-0003.
Staff awareness.Names no change to likelihood or impact.Run a phishing exercise each quarter and track the reporting rate as an indicator with a warning threshold.
Monitor the situation.Monitoring is measurement, not treatment.Record failed privileged logins weekly as an indicator, with a warning threshold and a breach threshold agreed with the platform team.
Move to multi-region.True, but unowned and undated.Stand up multi-region failover for the customer portal by the end of Q2, evidenced by a documented failover test.

Say what evidence will prove it

A plan that names its evidence finishes itself. A restore rehearsal produces a result, a policy produces a version, an access review produces a list of what changed. Record that evidence in the control's own evidence notes as it arrives, so the control carries its proof rather than pointing at somebody's memory of a meeting.

Put the constraint in writing

Every plan that slips had a reason, and the reason was usually known on the day the plan was written: a budget round, a vendor's release schedule, one engineer who has to be free. Write it into the plan. It costs a sentence, and it converts a missed date from an embarrassment into a decision somebody can make early.

Keep the plan and the actions distinct

The plan is the argument: what you will do, why, and what good looks like. The actions are the steps, each with an owner and a date of its own. Keeping them apart is what stops a plan from becoming a stale paragraph — the argument changes rarely, the steps change weekly, and each lives where it can be maintained.

Make the plan agree with the appetite

Appetite is the highest residual score your organisation has agreed to tolerate. A risk above it is flagged wherever it appears, and that flag is the strongest argument a treatment plan has. Where the threshold comes from is resolved in a fixed order: an override on the risk itself, then the category's threshold, then the organisation-wide figure, and if none is set, none applies. The Appetite section explains which of those the risk is being measured against.

When the target is still above appetite

This happens more often than people admit, and it is worth catching at the point of writing rather than at the board meeting. If the target you have set is still above the threshold, the plan as written does not finish the job. Either the plan needs to be more ambitious, or the risk needs an appetite override with a reason, or the category's tolerance was never realistic. All three are defensible. Saying nothing is not.

Use the gap line as a sanity check

Beneath the comparison grid, a line states what strength of control would take the residual to the target. Read it before you commit to a date. If it calls for a high-effectiveness control and your plan produces a moderate one, you have a target you will not reach, and it is better to know that now than after two quarters of effort.

Treatment across the whole register

Writing one plan well is a good afternoon. Keeping ninety plans current is a different job, and it is mostly done from the list rather than the panel.

Set a strategy on many risks at once

Select several risks and the panel becomes a bulk editor. Tick the fields you want to change — treatment strategy, owner, business unit, category, status, review cadence — set their values, and apply them to every selected risk. Anything you leave unticked stays exactly as it was. This is the quick way to bring a batch of low-band risks to a consistent accepted position, or to hand a category to a new owner without opening twelve panels.

Find the risks whose plans are missing

Filter the register to over-appetite only, sort by residual, and work down. Those are the rows where an absent or vague plan does the most damage. Once you have a combination you keep rebuilding, Save Current Filter… names it so the same view is one click away next month.

Watch the work rather than the words

Choose Actions in the sidebar to see every action across the register in one place, grouped by due state: Just Added, Overdue, Due Soon, Later, No Due Date and Closed. Each row shows the risk or control it belongs to, so an overdue item tells you immediately which plan is slipping. Filter by owner before a one-to-one and the conversation writes itself.

Troubleshooting

I chose Mitigate but the score did not move

It is not meant to. The strategy records a decision; the score follows the controls. The residual falls when a linked control is implemented or operating, or when you set an effectiveness value by hand. A planned control, however strong it will eventually be, reduces nothing yet, and the control's own panel says so.

The plan is written but nothing is happening

Look for actions. A plan with no actions beneath it has nobody's name on any step and no date anything can be late against. Add two or three specific items in Actions, each with an owner and a due date; overdue rows then carry a badge and gather in the Overdue group of the Actions section, where they are hard to keep ignoring.

An accepted risk keeps appearing in reports

Acceptance is a decision about tolerance, not a way of removing a row. The register's filters include a show closed and accepted toggle, and a report's scope has its own switch for including closed and accepted risks. Turn that off for a board pack that should carry only live exposure, and leave it on for an assurance pack that needs the whole picture.

My target is lower than any control could reach

The comparison grid will tell you, in the line under the gap. A residual score can never fall below 1 and can never exceed the inherent score, and a control only takes off what its effectiveness justifies. If the arithmetic cannot reach your target, the honest fix is usually Avoid — stop the activity — or a revised target with the reason recorded.

Nobody can remember why we accepted this

Open History on the risk. Every assessment ever made is kept with the reason given at the time and the score it produced, alongside a chart of how the residual has moved. Between that, the plan field and the rationale on the category's appetite threshold, the argument should be reconstructable without anyone's diary.

Routines that keep a plan alive

Plans decay quietly. A few habits keep them honest without adding a governance ritual to anybody's week.

  • Write the plan the same day you score. The reasoning is never as clear again as it is in the hour you rated the risk.
  • Date everything, even loosely. A date you later move is a working plan. A blank date is a plan that has quietly been abandoned.
  • Re-read accepted risks quarterly. Acceptance ages faster than mitigation, because the world moves while the plan says nothing has to.
  • Close the loop on the control. When the work lands, change the control's status — every risk deriving from it re-scores at once, and the plan finally shows in the numbers.
  • Start from a worked example. Risk Library carries thirty-nine example risks, each with a typical treatment and the controls worth considering, as a first draft rather than an answer.
  • Let indicators argue with the plan. A key risk indicator that breaches while a mitigation is in flight is telling you the plan is too slow, not that the indicator is wrong.
  • Put open actions in the report. A treatment plan with visible dates in front of the people who fund it is the version that gets resourced.
  • Review in one pass. Review brings the due risks forward worst first, with the plan and its actions beside the scoring inputs, so decisions are made with the context rather than from memory.

Frequently asked questions

What is a risk treatment plan?

It is the record of what you have decided to do about a risk: one of four strategies, a written plan explaining the decision, and a date by which the change should be real. In RiskOS it lives on the risk itself, next to the score it is meant to move and the actions that carry out the work.

What are the four risk treatment options?

Mitigate, Accept, Transfer and Avoid. Mitigate reduces the likelihood, the impact or both. Accept carries the exposure knowingly. Transfer moves part of the consequence to another party, usually by contract or insurance. Avoid stops the activity that creates the risk. RiskOS records the choice on the risk's Treatment section, alongside the plan and its due date.

Does choosing a treatment strategy change the risk score?

No. The strategy is a decision, and decisions do not reduce exposure on their own. The residual score is calculated from the effectiveness of the controls you link, or from a value you set by hand. Change a control's status from planned to operating and every risk relying on it re-scores immediately.

What is the difference between a treatment plan and an action?

The plan is the argument — what you will do about the risk, why, and what finished looks like. An action is one concrete step towards it, with its own title, status, priority, owner and due date. One plan usually needs several actions, and they appear together on the risk as well as in the register-wide Actions list.

Who should own a risk treatment plan?

The risk owner named in the Summary section owns the outcome, which means the plan and its date. Individual actions can sit with whoever does the work, and each carries its own owner. Keeping those separate means one person answers for the risk while several people can move it, and the Actions list can be filtered by either.

When should I accept a risk rather than mitigate it?

When the residual score is already within appetite, or when the cost of treatment clearly exceeds the exposure and you are willing to say so in writing. Acceptance needs a reason in the plan field and a review date, because tolerance ages. A risk accepted while still above appetite stays flagged everywhere it appears.

How do I show an auditor why a risk was accepted?

Open the risk's History, which keeps every assessment with the reason given at the time and the score it produced. Read that with the plan field, the review dates and the appetite threshold the risk was measured against, and include the register and its open actions in an exported report so the same record leaves the app intact.

Does my treatment plan leave my Mac?

No. Everything here happens on your Mac. There is no account, nothing is uploaded, and your register never leaves the machine unless you export or back it up yourself. The only network use is Apple's App Store, for purchases, and it never sees a single risk, plan or action you have written.