A practical recap of CERRIX ISO 31000 risk treatment webinar
Risk leaders today face pressure from both sides. Regulators expect stronger oversight, better documentation, and stricter control testing. At the same time, the business wants to move faster, innovate freely, and reduce the cost of compliance.
This tension is exactly why we hosted our recent webinar on risk treatment and control assurance in ISO 31000. Rather than repeating the standard process diagram, we focused on the real-world question everyone struggles with:
What does effective risk treatment look like in an organisation that needs to stay both compliant and competitive?
Missed the webinar ? Watch the recording here: On-demand Webinar: ISO 31000 in Practice. Risk Treatment & Control Effectiveness Testing
ISO 31000 as a practical foundation
ISO 31000 continues to gain adoption across Europe because it is principle-based, practical and easy to translate into daily work. It gives risk and compliance teams a shared language for discussing how risks are identified, assessed and treated.
In the session, Paul (Founder, CERRIX) highlighted a valuable point: ISO 31000 is not another rule book. It isa way to build a consistent risk management framework across the entire organisation. You can then complement it with frameworks like DORA or ISO 27001if you need deeper guidance for specific domains.
At its core, ISO 31000helps you answer a simple question: what are we going to do with the risks we have identified?
Risk treatment as a leadership decision
Risk treatment is often shown as one small box in the ISO 31000 diagram, but in practice it is where the most important decisions are made. Once you have identified and analysed a risk, you need to choose whether to
- avoid
- mitigate it
- transfer or share it
- accept it
This is not a documentation task. It is a business decision. You are choosing which risks you are willing to carry forward, which risks deserve investment, and which risks are not worth the cost of control.
During the webinar we emphasised that the reasoning behind these decisions matters just as much as the decision itself. Environments change, systems evolve and people move roles. Clear decision reasoning prevents confusion later on.
Balancing expected loss with cost of control
One theme that resonated strongly was the need to understand the cost of control. ISO 31000 encourages risk leaders to compare the expected loss of a risk with the cost and effectiveness of the treatment.
This is where many organisations struggle. Controls often appear “free” because the cost is hidden in people’s time. In reality, a complex control test plan can consume dozens of hours each quarter.
As soon as you record control cost and compare it with residual risk reduction, the conversation with leadership becomes more constructive and more transparent.
Looking beyond individual controls
Not every risk can be solved by adding another control. Sometimes you need to zoom out and consider process design, automation opportunities and the speed at which risks can materialise.
We walked through two examples during the session
- A key person risk with high impact but slow velocity. Treatment focuses on succession planning and knowledge transfer.
- A continuity risk in a core system with very fast velocity. Treatment requires resilience, monitoring and recovery planning.
ISO 31000 supports this broader view. Treatment is not simply about adding controls but about choosing the right response for the nature of the risk.
Treatment actions in practice
Treatment options can include policies, automated controls, process redesign, training, contractual measures, analytics, audits or combinations of these. The key is to choose an action that truly modifies the risk and is proportionate to the exposure.
In CERRIX, these treatment decisions are captured and translated into measures of improvement, defined with owners, due dates and clear objectives. This keeps treatment plans actionable rather than theoretical.
Turning treatment into action with ownership
Risk treatment only works when ownership is clear. In the webinar we discussed the importance of:
- assigning risk owners and control owners
- defining who decides on treatment options
- linking treatment actions to accountability
- monitoring progress with clear due dates
Without ownership, treatment plans tend to age instead of evolve.
A modern approach to control assurance
Most organisations still rely heavily on effectiveness testing that takes place after the reporting period. This creates delays and results in repeated evidence collection.
We introduced a more complete and modern control assurance model that includes:
- Design and implementation checks to confirm that controls are well described, implemented and still relevant.
- Control execution to confirm that controls are performed on time with evidence captured at the moment of execution.
- Effectiveness testing that reuses the execution evidence already collected.
- Continuous control monitoring for controls that can be automated or linked to source systems.
This approach moves assurance closer to real time and reduces duplicate work for the first line and the auditors.
Test once. Comply to many.
A major benefit of an integrated GRC platform is the ability to map one control to multiple frameworks. If a single access review control satisfies ISO 27001, DORA ICT guidelines and a local supervisory expectation, you should not run three separate tests.
In the demo, we showed how CERRIX allows you to
- standardise a control description
- store evidence once
- automate ownership and workflow
- reuse execution results across multiple frameworks
This is how ISO31000’s principle of integrated risk management becomes practical.
What risk and compliance leaders should take away
“Good risk treatment is the difference between risk management as documentation and risk management as decision-making.”
Effective risk management is not about eliminating risk.
It is about taking the right risks with confidence and clarity.
A few practical takeaways for leaders
- Refresh your risk appetite and make it usable by teams.
- Build a standardised control library linked to your frameworks.
- Capture evidence during control execution instead of afterwards.
- Reduce duplicate testing by improving evidence instructions.
- Review treatment plans regularly so they stay relevant.
Want to explore ISO 31000 in your organisation?
If this webinar sparked new ideas or questions about your own risk treatment approach, we would be happy to continue the conversation.
We can walk through how CERRIX helps organisations structure their risk treatment, strengthen control assurance and reduce the cost of compliance. Book a demo here.
Spreadsheets vs. GRC Tools: Elevating Risk & Compliance Management
Accessible popup
Welcome to Finsweet's accessible modal component for Webflow Libraries. This modal uses custom code to open and close. It is accessible through custom attributes and custom JavaScript added in the embed block of the component. If you're interested in how this is built, check out the Attributes documentation page for this modal component.

.jpg)
%20(1).jpg)
.jpg)
.jpg)
.jpg)
.jpg)
%20(1).jpg)
.jpg)
%20(1).jpg)
.jpg)
.jpg)

.jpg)
.jpg)





.jpg)
%20(2).jpg)
















%20(1)%20(2).jpg)





.jpg)

.png)
.jpg)






%20(1).avif)



