MyPMPlearn live
← All templates
☁️
Free to try β€” your work auto-saves in this browser.
Saving to the cloud (sync across devices) is a paid feature. Unlock IT Risk Assessment for $1/mo, or get everything with membership ($9/mo or $99/yr).
All apps + QMS Β· $9/mo or $99/yr β†’
⚠️ Risk & Change
Risk & Change

IT Risk Assessment

MyPMP
QMS Template
RefRisk / eventLikelihoodImpactResponseOwnerStatus

Notes

Part of My QMS β€” the MyPMP Quality Management System. Template MYPMP-TMPLT-0199 Β· Β© MyPMP β€” mypmp.in. QMS content copyright MyPMP.

Auto-saved in your browser Β· β˜… members can white-label & sync across devices

About the IT Risk Assessment template

An IT Risk Assessment is a structured evaluation of threats to your information systems, data, and infrastructure, scoring each by likelihood and impact so you can prioritize mitigation. It underpins compliance frameworks like ISO 27001, NIST, and SOC 2, and gives stakeholders a defensible record of how technology risk is being managed.

It's part of My QMS, MyPMP's Quality Management System: fill it in online, personalize it with your name and logo, then export a clean, branded PDF. Your work auto-saves in your browser.

When to use a IT Risk Assessment

  • β–ΈBefore deploying new systems, cloud migrations, or major infrastructure changes
  • β–ΈDuring annual security reviews or ISO 27001 / SOC 2 audit preparation
  • β–ΈAfter a security incident or discovered vulnerability to reassess exposure
  • β–ΈWhen onboarding third-party vendors or evaluating supply-chain dependencies

What a good IT Risk Assessment includes

  • βœ“Asset or system inventory with owner and data classification
  • βœ“Threat and vulnerability description (e.g. ransomware, misconfiguration, insider access)
  • βœ“Likelihood and impact ratings with a calculated risk score or heat-map position
  • βœ“Existing controls and their assessed effectiveness
  • βœ“Treatment decision: accept, mitigate, transfer, or avoid, with residual risk
  • βœ“Action owner, remediation deadline, and review date

What's inside this template

The interactive form above gives you:

A table of Ref, Risk / event, Likelihood, Impact, Response, Owner, StatusNotes

Tips & common mistakes

  • πŸ’‘Rate risk on the residual level after existing controls, not the raw inherent threat, or you'll over-prioritize already-mitigated items
  • πŸ’‘Use a consistent scoring scale across all entries so the register stays comparable and defensible at audit
  • πŸ’‘Assign a named owner and date to every treatment action; unowned risks are the ones that stall

How it works

  1. 1. Fill it in β€” type directly into the fields, tables and sections above.
  2. 2. Brand it β€” add your organization name and logo with the Branding button.
  3. 3. Export β€” print to PDF, or become a member to white-label and sync across devices.

FAQ

What's the difference between inherent and residual risk?οΌ‹

Inherent risk is the exposure before any controls are applied; residual risk is what remains after your existing safeguards. Treatment decisions should be based on residual risk against your appetite threshold.

How do I calculate an IT risk score?οΌ‹

Multiply the likelihood rating by the impact rating (commonly on 1-5 scales) to produce a score, then map it onto a heat-map or tiered band such as low, medium, high, or critical.

How often should an IT risk assessment be updated?οΌ‹

Review it at least annually and additionally after major changes such as new systems, incidents, vendor changes, or regulatory updates. Frameworks like ISO 27001 expect ongoing, documented reassessment rather than a one-off exercise.

Make it yours β€” $9/mo or $99/yr

Membership unlocks white-label export (remove the MyPMP footer), cloud sync across devices, plus all apps & ScheduleX.

See membership
IT Risk Assessment Template β€” Free & Interactive | MyPMP Β· MyPMP