Security Assurance · GRC · Secure AutomationRemote delivery for growing technology businesses
Security Assurance Insight

ISO 27001 Risk Register Example for a SaaS Company

A useful risk register records scenarios, ownership, treatment and residual risk, not just a list of threats.

Published 2026-09-03 · Tech Turn Technology

Write risk as a scenario

A useful statement explains the condition, event and impact. For example: because privileged access is not periodically reviewed, stale administrator access could remain active and enable unauthorised production changes.

Separate inherent and residual risk

Assess the risk before considering current controls, then assess what remains after those controls. This helps management see whether the treatment is actually reducing exposure.

Treatments need owners and dates

A risk register that has no action owner, due date or review date is usually just a catalogue. Treatment decisions should be trackable.

Acceptance is a decision

Residual risk can be accepted when the appropriate authority understands it. Risk acceptance should be explicit, recorded and reviewed.

Where possible, connect risks to findings, control exceptions, corrective actions and evidence. This turns the risk register into part of the operating system rather than a yearly document.

Need an evidence-based view of your own environment?
Use the Readiness Review to define scope and the first assessment.