Templates / ISO 27001 risk register template
ISO 27001 risk register template
ISO 27001 Clause 6.1 requires a documented information-security risk assessment and treatment — a risk register is the artefact auditors look for. The worked example below lists common information-security risks with ratings and controls, free to download or open live.
No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.
Worked example: iso 27001 risk register template
| Risk | Category | Likelihood | Impact | Rating | Suggested remediation |
|---|---|---|---|---|---|
| Phishing and credential theftAn attacker tricks a staff member into revealing a password or approving a login, or steals a session, and gains access to email, files or business systems. | security | high | high | Enforce phishing-resistant multi-factor authentication (passkeys or hardware security keys) on email and any account that reaches sensitive data. | |
| Ransomware and extortionMalware encrypts systems or an attacker steals data and threatens to leak it, halting operations and demanding payment. | operational | medium | high | Keep tested, offline or immutable backups of critical data and rehearse restoring from them. | |
| Breach of personal or customer dataPersonal data about customers, users or staff is exfiltrated and leaked or sold, triggering notification duties and loss of trust. | legal | medium | high | Encrypt personal data at rest and in transit and apply least-privilege so only staff who need it can reach it. | |
| Insider threat or misuse of accessA current or former staff member, contractor or privileged user misuses their access — to steal data, cause damage, or act carelessly — and the activity blends into normal work. | security | medium | high | Grant least-privilege access and review it regularly, especially after a role change; revoke everything promptly when someone leaves. | |
| Supplier or third-party compromiseA vulnerability, breach or malicious update at a vendor, hosting provider or software dependency reaches your systems or data through the trusted connection. | security | medium | high | Keep an inventory of suppliers and the systems and data each can reach, and set security expectations in the contract before onboarding. | |
| Cloud misconfiguration or exposed storageA storage bucket, database or admin interface is left publicly reachable or without authentication through a configuration mistake, exposing data or a way in. | security | high | high | Build systems from a hardened, documented baseline that turns off public access and default credentials, and block deployments that drift from it. | |
| Unpatched or end-of-life systemsA known vulnerability in software, a device or a dependency is left unpatched — or the product is past end of support — and an attacker exploits it. | security | high | high | Keep a live inventory of software and versions and scan for known vulnerabilities, prioritising internet-facing and critical systems. |
Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.
Questions
Does ISO 27001 require a risk register?
ISO 27001 requires a documented risk assessment and treatment process (Clause 6.1). The risk register is the standard evidence: a central list of risks with likelihood/impact ratings, treatment decisions, owners, and applied controls — reviewed by leadership.
What does an auditor look for in the register?
A centralised list with consistent scoring, mapped controls, owners, review dates, and evidence that risk acceptances were reviewed by leadership. Urna's register plus its change history covers this.
Is the template free?
Yes — CSV download with no sign-up, or open it live in Urna. Free, no card.
Build your own in Urna — free
Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.