Templates / ISO 27001 risk register template

ISO 27001 risk register template

ISO 27001 Clause 6.1 requires a documented information-security risk assessment and treatment — a risk register is the artefact auditors look for. The worked example below lists common information-security risks with ratings and controls, free to download or open live.

Open live in Urna — free Download the CSV

No sign-up needed to download. Opening it live lets you edit, score your own risks, and get a suggested remediation for each.

Worked example: iso 27001 risk register template

RiskCategoryLikelihoodImpactRatingSuggested remediation
Phishing and credential theftAn attacker tricks a staff member into revealing a password or approving a login, or steals a session, and gains access to email, files or business systems.securityhighhighhighEnforce phishing-resistant multi-factor authentication (passkeys or hardware security keys) on email and any account that reaches sensitive data.
Ransomware and extortionMalware encrypts systems or an attacker steals data and threatens to leak it, halting operations and demanding payment.operationalmediumhighhighKeep tested, offline or immutable backups of critical data and rehearse restoring from them.
Breach of personal or customer dataPersonal data about customers, users or staff is exfiltrated and leaked or sold, triggering notification duties and loss of trust.legalmediumhighhighEncrypt personal data at rest and in transit and apply least-privilege so only staff who need it can reach it.
Insider threat or misuse of accessA current or former staff member, contractor or privileged user misuses their access — to steal data, cause damage, or act carelessly — and the activity blends into normal work.securitymediumhighhighGrant least-privilege access and review it regularly, especially after a role change; revoke everything promptly when someone leaves.
Supplier or third-party compromiseA vulnerability, breach or malicious update at a vendor, hosting provider or software dependency reaches your systems or data through the trusted connection.securitymediumhighhighKeep an inventory of suppliers and the systems and data each can reach, and set security expectations in the contract before onboarding.
Cloud misconfiguration or exposed storageA storage bucket, database or admin interface is left publicly reachable or without authentication through a configuration mistake, exposing data or a way in.securityhighhighhighBuild systems from a hardened, documented baseline that turns off public access and default credentials, and block deployments that drift from it.
Unpatched or end-of-life systemsA known vulnerability in software, a device or a dependency is left unpatched — or the product is past end of support — and an attacker exploits it.securityhighhighhighKeep a live inventory of software and versions and scan for known vulnerabilities, prioritising internet-facing and critical systems.

Ratings are derived from likelihood, impact and vulnerability. This is a starting point to adapt — read each row and keep what applies.

Questions

Does ISO 27001 require a risk register?

ISO 27001 requires a documented risk assessment and treatment process (Clause 6.1). The risk register is the standard evidence: a central list of risks with likelihood/impact ratings, treatment decisions, owners, and applied controls — reviewed by leadership.

What does an auditor look for in the register?

A centralised list with consistent scoring, mapped controls, owners, review dates, and evidence that risk acceptances were reviewed by leadership. Urna's register plus its change history covers this.

Is the template free?

Yes — CSV download with no sign-up, or open it live in Urna. Free, no card.

Build your own in Urna — free

Urna is a free risk register: start from curated libraries instead of a blank page, score against recognised frameworks, and get a suggested remediation for every risk you log. Export any time. No card.

Start free See how it works