What Clause 8.3 Actually Requires
Clause 8.3 of ISO 27001:2022 is short. It reads, in essence, that the organisation shall implement the information security risk treatment plan. That is it. No elaborate sub-clauses, no long list of requirements. But do not let the brevity fool you. This is where the rubber meets the road in any information security management system, and it is where auditors spend a significant portion of their time during a certification or surveillance audit.
On this page
The risk treatment plan is the output of Clause 6.1.3, where the organisation selects controls, justifies exclusions, and documents everything in the Statement of Applicability. Clause 8.3 picks up from there and asks a straightforward question: did you actually do what you said you would do? That question turns out to be surprisingly difficult for many organisations to answer with confidence.
To understand why, it helps to look at what implementing a risk treatment plan actually involves in practice, what evidence auditors expect to see, and where organisations consistently fall short.
The Link Between Planning and Operation
ISO 27001 follows the harmonised structure shared by most modern ISO standards. Clause 6 covers planning, and Clause 8 covers operation. The two are deliberately connected. You plan the treatment in Clause 6, and you execute it in Clause 8. If there is a gap between what was planned and what was done, that gap is a nonconformity.
This sounds simple, but in practice the gap appears in several common forms:
- Controls are listed in the Statement of Applicability as applicable and implemented, but there is no evidence they are operating
- The risk treatment plan was completed during the initial certification push and has not been updated since
- Ownership of specific treatment actions is unclear, so nobody follows through
- The plan was implemented in one part of the organisation but not others within the defined scope
Each of these is a failure of Clause 8.3, even though the planning documentation may look perfectly complete. Auditors are trained to follow the evidence trail from the plan into actual operations, and gaps become visible quickly once you start pulling on that thread.
Exemplar Global Recognised Training ProviderRTP No. 310970What the Risk Treatment Plan Should Contain
Before you can implement a risk treatment plan, you need one that is actually implementable. Many organisations produce a risk treatment plan that reads more like a risk register than an action document. The two are related but different.
A workable risk treatment plan should identify, for each accepted treatment action:
- The specific risk being treated
- The treatment option selected (modify, retain, avoid, or share)
- The controls from Annex A or elsewhere that will be applied
- The person or role responsible for implementation
- A target completion date or, for ongoing controls, a review frequency
- The residual risk level expected once controls are in place
Without these elements, the plan cannot be effectively implemented or audited. An auditor reviewing a plan that lists controls without owners and dates will immediately flag the gap, because there is no mechanism to drive implementation and no way to verify it happened.
If your plan currently looks like a spreadsheet of risks with control references but no ownership or timelines, that is the first thing to fix before your next audit.
Retained Documented Information
Clause 8.3 explicitly requires retained documented information about the risk treatment plan. This is not optional. The organisation must be able to show an auditor the plan itself, and it must be able to demonstrate that the plan reflects current circumstances.
The documented information requirement has two practical implications. First, the plan must exist in a form that can be retrieved and reviewed. A plan that lives only in someone's head, or in a series of email threads, does not satisfy the requirement. Second, the plan must be controlled documented information under Clause 7.5, which means it needs version control, an owner, and a review process.
Auditors will ask to see the current version of the risk treatment plan early in an ISMS audit. They will check whether it has been reviewed and updated since the last audit cycle, whether it aligns with the current Statement of Applicability, and whether the residual risk levels have been accepted by the risk owner or top management as required under Clause 6.1.3.
For more on how the Statement of Applicability connects to the treatment plan, the article on checking the Statement of Applicability against the risk treatment plan covers the audit evidence trail in detail.
Implementing Controls: What Evidence Looks Like
The word “implement” in Clause 8.3 means the controls are actually operating, not just documented. This distinction matters enormously in an audit. A policy document is not implementation. A procedure is not implementation. Implementation is the control working in the real environment.
Here are some examples of what implementation evidence looks like for common Annex A controls:
Access Control
The risk treatment plan identifies access control as a treatment for the risk of unauthorised access to sensitive systems. Implementation evidence includes active user access reviews, records of joiners and leavers being processed through the access management procedure, and system-generated logs showing access is restricted to authorised users. A policy document on access control, without these operational records, is not sufficient.
Information Security Awareness Training
The plan identifies human error as a risk and selects awareness training as a control. Implementation evidence includes training records showing completion rates across the workforce within the defined scope, assessment results where applicable, and records of new starters completing induction training before accessing systems. A training module sitting on a server that nobody has been required to complete does not constitute implementation.
Supplier Security Assessments
The plan identifies third party risk and selects supplier assessment as a control. Implementation evidence includes completed assessment records for suppliers within scope, contracts with security clauses, and records of periodic reviews. A template assessment form that has never been used for an actual supplier does not count.
The pattern is consistent across every control type. Auditors look for records of the control operating, not just the control being described. If you can show the policy but not the records, expect a finding.
Common Nonconformities Against Clause 8.3
Having conducted and reviewed a significant number of ISMS audits, the nonconformities that appear most often against Clause 8.3 follow recognisable patterns. Understanding these patterns helps organisations prepare more effectively.
The Plan Was Never Updated After Certification
This is probably the most common finding. The organisation worked hard to get certified, produced a thorough risk treatment plan, implemented the controls, and then effectively froze the plan. By the first surveillance audit, the organisation has changed, new risks have emerged, some planned controls were not implemented as expected, and the plan no longer reflects reality. The plan is out of date, and Clause 8.3 requires that the current plan be implemented, not the plan that existed two years ago.
Controls Are Marked as Implemented in the SoA But Are Not Operating
The Statement of Applicability lists a control as applicable and implemented. The auditor asks for evidence. The evidence does not exist, or the control was implemented briefly and then abandoned. This is a direct nonconformity against Clause 8.3 because the implementation has not been sustained.
No Clear Ownership of Treatment Actions
The plan exists but treatment actions are not assigned to specific individuals. When the auditor asks who is responsible for a particular control, nobody can give a clear answer. This points to a systemic failure in how the plan was structured and is likely to result in multiple controls being partially or not implemented.
Residual Risk Not Accepted by the Appropriate Authority
Clause 6.1.3 requires that the risk owner accept residual risk. If the risk treatment plan shows residual risk levels but there is no record of formal acceptance, the auditor will raise this as a finding. It is technically a Clause 6.1.3 issue, but it surfaces during the Clause 8.3 review because the plan cannot be properly closed out without that acceptance.
Integrating Risk Treatment Into Daily Operations
One of the most practical shifts an organisation can make is to stop treating the risk treatment plan as a certification document and start treating it as an operational tool. This means:
- Assigning control owners who are responsible for ongoing operation, not just initial implementation
- Including control effectiveness reviews in the internal audit programme
- Connecting the risk treatment plan to the management review agenda so leadership sees progress and gaps
- Using the plan as the basis for corrective actions when controls fail
When the plan is embedded in operations rather than stored in a compliance folder, the evidence of implementation becomes a natural byproduct of normal work rather than something that has to be assembled before an audit.
The article on risks and opportunities under Clause 6.1.1 provides useful context on how the planning phase feeds into the operational requirements of Clause 8.3.
How Auditors Approach Clause 8.3
When an auditor arrives at Clause 8.3 during an ISMS audit, they are not just checking that a document exists. They are tracing a chain of evidence from the risk assessment through the treatment plan and into actual operations. The audit approach typically involves:
- Requesting the current risk treatment plan and Statement of Applicability
- Selecting a sample of treatment actions, particularly those associated with higher risks or those that were open at the previous audit
- Asking the responsible person to demonstrate that the control is operating
- Reviewing records that evidence the control has been consistently applied
- Checking whether the plan has been updated to reflect any changes in the organisation or its risk environment
The auditor is essentially asking: for each treatment action in this plan, show me that it happened. If the evidence chain breaks at any point, that becomes an audit finding. The severity depends on the nature of the gap and the risk it leaves unaddressed.
Auditors will also check alignment between the risk treatment plan and the internal audit programme. If the internal audit programme has not covered the controls in the plan, that is a separate finding under Clause 9.2, but it also raises questions about how the organisation knows whether its treatment is working.
The Role of the Internal Audit in Verifying Treatment
Internal audits are one of the primary mechanisms for verifying that the risk treatment plan is being implemented. This is not just good practice. It is the logical connection between Clause 8.3 and Clause 9.2. The internal audit programme should be designed, at least in part, around the controls in the risk treatment plan, particularly those associated with significant risks.
An internal auditor reviewing Clause 8.3 should be checking the same things an external auditor would check: is the plan current, are controls operating, is there evidence, and are gaps being addressed through corrective action? If the internal audit has been rubber-stamping conformity without actually verifying control operation, the certification audit will expose that gap.
For those building or reviewing their ISMS internal audit capability, the article on ISMS internal audits under Clause 9.2 covers the requirements and common pitfalls in detail.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Steps to Strengthen Clause 8.3 Conformity
If you are preparing for a certification or surveillance audit, or simply want to make sure your risk treatment implementation is genuinely solid, the following steps will help:
- Review the plan for currency. Check that every treatment action reflects the current state of the organisation and its risks. If the organisation has changed significantly since the plan was last updated, update the plan before the audit, not during it.
- Confirm ownership for every action. Every treatment action should have a named owner who can be interviewed by an auditor and who can produce evidence of implementation.
- Collect implementation evidence systematically. Do not wait for an audit to gather evidence. Build evidence collection into the normal operation of each control. Access review records, training completion reports, supplier assessment files, and incident logs should all be maintained as a matter of course.
- Check the SoA against reality. Walk through the Statement of Applicability and verify that every control marked as implemented can actually be evidenced. If a control cannot be evidenced, either implement it properly or update the SoA to reflect its actual status and document the justification.
- Close out open treatment actions. If the plan shows treatment actions that are still open from previous periods, either complete them or formally reassess the risk and update the plan. Open actions with no progress are a reliable source of nonconformities.
- Connect the plan to management review. Ensure that the status of the risk treatment plan is a standing agenda item at management review. This creates a governance trail showing that leadership is monitoring implementation progress.
Training for ISMS Auditors and Implementers
Understanding how Clause 8.3 works in practice is one thing. Being able to audit it effectively, or implement it in a way that will hold up under audit scrutiny, requires hands-on training that goes beyond reading the standard.
Audit Workshop offers ISO 27001 auditor training at internal and lead auditor levels, delivered by practitioners who have conducted real ISMS audits across a range of industries. The training covers the full audit process, including how to trace implementation evidence from the risk treatment plan through to operational controls, how to frame findings when evidence is absent, and how to structure an internal audit programme that genuinely supports Clause 8.3 conformity.
Whether you are an information security manager preparing your organisation for certification, an internal auditor building your ISMS audit skills, or a quality professional expanding into the information security space, the practical grounding you get from working through real audit scenarios makes a significant difference to how confidently you can handle Clause 8.3 in practice.













