What is risk treatment?
Risk treatment is deciding what to do about each identified risk. The four standard options are to mitigate it with controls, accept it, transfer it (for example through insurance), or avoid it by stopping the activity. Accepted risks should have a named owner and a review date.
What the buyer is really asking
Once a risk is rated, what happens to it? Explain how you decide to mitigate, accept, transfer, or avoid it, and who can sign off on accepting a risk. Accepted risks should have an owner and a review date.
Other ways buyers ask it
Every one of these wants the same answer:
- “Describe your risk treatment process.”
- “Who can accept a security risk?”
- “How are risk treatment plans tracked?”
Evidence to have ready
- Risk treatment plans in the risk register
- A signed risk acceptance
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.