Free policy template ISO 27001

Risk Management Policy

How you identify, assess, treat, and accept information security risks on a recurring basis, and who owns each decision.

Download the Markdown

Free and ungated, no email required. The full template is below and in the download. Authored in Keel's own words and mapped to ISO 27001 by clause; replace the {{PLACEHOLDER}} tokens with your details.

How to use it

  1. Download the template. Grab the Markdown file, or copy the full text from this page.
  2. Fill in the placeholders. Replace every {{PLACEHOLDER}} token (company name, owner, approver, dates, version) with your details.
  3. Tailor it to how you operate. Adjust the statements so they describe what your organization actually does. A policy you do not follow is worse than none.
  4. Approve and publish. Have an accountable owner approve it, set an effective date and a review date, and share it where staff can find it.
  5. Keep it current. Review on the schedule you set (or when things change), and keep evidence that it is followed. In Keel this is tracked for you.

Related

Risk Management

Organization: {{COMPANY_LEGAL_NAME}} Document owner: {{POLICY_OWNER_ROLE}} Approved by: {{APPROVER_NAME}}, {{APPROVER_TITLE}} Version: {{VERSION}} · Effective: {{EFFECTIVE_DATE}} · Next review: {{REVIEW_DATE}} Classification: Internal


1. Purpose

This policy gives {{COMPANY_LEGAL_NAME}} a simple, repeatable way to find, rank, and act on the risks that matter, with particular attention to protecting {{DATA_TYPES}} held in {{CRITICAL_SYSTEMS}} and to obligations across {{GEO_SCOPE}}. The goal is a living picture of risk that stays lightweight enough to actually maintain.

2. Scope

This policy covers strategic, operational, technical, vendor, legal, and financial risks that could affect the organization. It applies to the {{LOCATION}} workforce and to any {{DEVICE_TYPES}} or workloads that connect to {{CRITICAL_SYSTEMS}}.

3. Policy statements

3.1 Risk register

We keep a single, current risk register. Each entry names the risk and records its impact, likelihood, owner, chosen treatment, and status. The register is never left empty.

3.2 Keeping the register current

We add or revise entries when launching a new service, taking on a vendor, changing {{CRITICAL_SYSTEMS}}, or learning of a relevant threat. Risks to {{DATA_TYPES}} and any cross-border considerations in {{GEO_SCOPE}} are captured explicitly.

3.3 Scoring and prioritization

Impact and likelihood are each scored on a simple one-to-five scale. Every quarter we surface the three highest-scoring risks for attention and record the reasoning behind any change in score.

3.4 Risk treatment

For each prioritized risk we choose to mitigate, transfer, avoid, or accept. Any choice other than acceptance produces at least one owned task with a due date. Accepted risks are recorded with the date and the approving manager.

3.5 Threat intelligence

We follow reputable, freely available advisories (such as national cyber agencies and the vendors behind {{CRITICAL_SYSTEMS}}) and share relevant items internally. Where available, we fold in bulletins specific to {{INDUSTRY}} and open new risks or actions when warranted.

3.6 Measuring the program

The program is working when the register exists, the top three risks are flagged, and no mitigation task is more than 30 days overdue. Larger teams (over {{EMPLOYEE_COUNT}} people) widen quarterly sampling to cover more of {{CRITICAL_SYSTEMS}} and {{DATA_TYPES}}.

3.7 Continual improvement

Closed or obsolete risks are pruned during the quarterly review so the list stays useful, and scoring guidance is adjusted after incidents or material changes to {{CRITICAL_SYSTEMS}} or to obligations affecting {{GEO_SCOPE}}.

4. Roles and responsibilities

Role Responsibility
Executive sponsor Accountable for the program; approves this policy
{{POLICY_OWNER_ROLE}} Maintains this policy and the risk register
Managers Own assigned risks and drive treatment within their teams
All personnel Report new or changed risks promptly

5. Compliance and exceptions

A register that is empty or stale (older than 90 days) is raised at the next management meeting until resolved. Accepting any high-impact risk requires documented senior-management approval that names the residual risk to {{DATA_TYPES}}. Exceptions require documented risk acceptance by {{APPROVER_TITLE}} and are time-limited and reviewed.

6. Review

This policy is reviewed at least annually and when significant change occurs.


Aligned to ISO/IEC 27001:2022. {{COMPANY_LEGAL_NAME}} is not affiliated with or endorsed by the relevant standards body; full standard text is copyrighted and is not reproduced here.

This template is authored by Keel in its own words. Clause references to ISO 27001 are factual identifiers; Keel is not affiliated with or endorsed by the standards bodies named. It is a starting point, not legal advice, review and adapt it for your organization.

Manage this policy in Keel

Keel ships this template in-product, fills the placeholders, maps it to your controls, and tracks approvals and reviews, so the policy stays live evidence, not a file in a drive. Start free.

Start free Browse all templates