Methodology

Risk treatment: options, plans and controls

Risk treatment is the step where assessment turns into action, and it is where everything else in this suite ends up pointing: a bow tie exists so you can decide which controls to add, a quantification exists so you can decide which treatments earn their cost. ISO 31000:2018 clause 6.5.1 gives the purpose in one sentence: "to select and implement options for addressing risk".

The same clause makes treatment explicitly iterative: formulate and select options, plan and implement them, assess whether they worked, decide whether the remaining risk is acceptable, and if it is not, treat again. Treatment is a loop, not a checkbox at the end of a register row.

The seven options of clause 6.5.2

ISO 31000:2018 6.5.2 lists the options for treating risk, prefaced by a warning that they "are not necessarily mutually exclusive or appropriate in all circumstances":

  • Avoid: decide not to start or continue with the activity that gives rise to the risk.
  • Take or increase the risk in order to pursue an opportunity. Treatment is not only about reducing: an organisation can deliberately take on more risk.
  • Remove the risk source: take away the thing the left-hand side of a bow tie is made of.
  • Change the likelihood: the work of preventive controls.
  • Change the consequences: the work of mitigating, corrective and recovery controls.
  • Share the risk, "e.g. through contracts, buying insurance". Note the standard says share, not transfer: a contract moves money, not the whole risk, and the reputational half usually stays put.
  • Retain the risk by informed decision. Retention is a legitimate treatment, but only the informed kind; a risk nobody looked at is not "retained", it is missed.

Two more sentences from 6.5.2 deserve to be quoted because they are so routinely ignored in practice. Selecting options "involves balancing the potential benefits derived in relation to the achievement of the objectives against costs, effort or disadvantages of implementation": treatment selection is a cost-benefit judgement, which is exactly what Event Risk Exposure puts a number on. And "risk treatment can also introduce new risks that need to be managed": the standard expects you to assess your treatments, not just admire them.

Treatment versus control

The two words are often used interchangeably and the standards keep them deliberately distinct. A treatment is a process: ISO 31073:2022 3.3.32 defines risk treatment as a "process to modify risk". A control is a measure: ISO 31000:2018 3.8 defines it as a "measure that maintains and/or modifies risk", and its second note is the humbling one: "controls may not always exert the intended or assumed modifying effect".

The cleanest statement of how the two relate comes from the RMIA's risk treatment domain (RMBoK Domain 4): "once the risk treatment has been implemented, it becomes a control or it modifies existing control(s)". Treatment is the journey; a control is what is standing there when the journey ends. That is exactly the distinction Beau-Tie draws with control status: a planned control with an implementation timeline is a treatment in flight, and flipping it to existing (with an effectiveness score in place of the timeline) is the moment the treatment lands as a control.

What belongs in a treatment plan

Clause 6.5.3 exists because a list of good intentions is not a plan. The purpose of a treatment plan is "to specify how the chosen treatment options will be implemented, so that arrangements are understood by those involved, and progress against the plan can be monitored", and the standard is specific that the plan "should clearly identify the order in which risk treatment should be implemented". The information it says a plan should carry:

  • the rationale for the selected options, including the expected benefits;
  • those accountable and responsible for approving and implementing the plan;
  • the proposed actions;
  • "the resources required, including contingencies";
  • the performance measures;
  • the constraints;
  • the required reporting and monitoring;
  • "when actions are expected to be undertaken and completed".

Read that list against your own register. Most registers carry an action and an owner; almost none carry expected benefits, performance measures or a completion criterion, which is why so many "treatments" are still open three review cycles later with nobody able to say whether they worked.

Closing the loop: did it work?

The techniques standard puts the loop-closing obligation in one sentence (AS/NZS IEC 31010:2020, its own clause 6.5.2): "once risks have been evaluated and treatments decided, the risk assessment process can be repeated to check that proposed treatments have not created additional adverse risks and that the risk remaining after treatment is within the organization's risk appetite". Re-assessment after treatment is not paranoia; it is the method. Which level of remaining risk counts as acceptable is an appetite and criteria question, not a modelling one.

Where treatment lives in Monty & Co

Each tool carries a different slice of the treatment loop, and it is worth being precise:

  • Beau-Tie: treatments appear as planned controls(with a 0–3, 3–6, 6–12 or 12+ month implementation timeline) alongside existing controls, and the target rating records where you expect the risk to sit once they land. The exports flag weak existing controls as a watch list, which is where the next round of treatment options usually comes from.
  • Event Risk Exposure: the fullest treatment surface. Treatments carry a cost, reduce likelihood and/or consequence across one or more targets, and the engine runs baseline-versus-treated with a leave-one-out cost-benefit ratio per treatment: clause 6.5.2's "balancing the potential benefits… against costs" as an actual number.
  • PRQ: the platform file format carries a per-risk treatment record (expected cost, post-treatment probability, post-treatment impact distribution, post-treatment rating, owner and target date), but the PRQ screen does not yet expose it: today you model a treated register by editing the probabilities and distributions to their expected post-treatment values and re-running. The record exists so that a proper pre/post register comparison can be built without a file-format change.

Sources

  • AS/NZS ISO 31000:2018, clauses 6.5.1–6.5.3 (treatment purpose, options, plans) and 3.8 (control). Read in full for this page.
  • ISO 31073:2022, 3.3.32 (risk treatment) and 3.3.38 (residual risk).
  • AS/NZS IEC 31010:2020, clause 6.5.2, on repeating assessment after treatment.
  • RMIA Risk Management Body of Knowledge, Domain 4 (Risk Treatment), v2.4, on treatments becoming controls. Note its options list merges the standard's seven into six; where the two differ, this page follows ISO 31000.