ISO 27001 Risk Register Example for a SaaS Company
A useful risk register records scenarios, ownership, treatment and residual risk, not just a list of threats.
Write risk as a scenario
A useful statement explains the condition, event and impact. For example: because privileged access is not periodically reviewed, stale administrator access could remain active and enable unauthorised production changes.
Separate inherent and residual risk
Assess the risk before considering current controls, then assess what remains after those controls. This helps management see whether the treatment is actually reducing exposure.
Treatments need owners and dates
A risk register that has no action owner, due date or review date is usually just a catalogue. Treatment decisions should be trackable.
Acceptance is a decision
Residual risk can be accepted when the appropriate authority understands it. Risk acceptance should be explicit, recorded and reviewed.
Link evidence and exceptions
Where possible, connect risks to findings, control exceptions, corrective actions and evidence. This turns the risk register into part of the operating system rather than a yearly document.
Use the Readiness Review to define scope and the first assessment.