A free SOC 2 risk register template with real rows
A blank grid teaches nothing, so this one comes with six rows already written. Copy the columns, replace the rows, keep it current.
Here is a SOC 2 risk register template you can copy for free, with the rows already filled in. Every risk sits on one line with a score, one owner, a decision, and the control that deals with it. Swap our six sample rows for your own and you have a working register.
Why SOC 2 wants this table
The 2017 Trust Services Criteria carry the COSO framework into the common criteria, and a block of them is about risk.1 CC3.1 wants objectives clear enough to attach risks to. CC3.2 wants risks identified and analyzed as the basis for deciding how to manage them. CC3.3 asks you to think about fraud on purpose. CC3.4 wants significant changes reassessed, and CC9.1 covers planning for business disruption.
Read CC3.2 twice. It is about decisions. A register with scores but no treatment column does not meet it.
The columns
Ten columns carry the load. The owner and the control link matter most, because those two turn a list of worries into something someone does and something an auditor can check.
| Column | Contents | Why keep it |
|---|---|---|
| ID | R-01 and up, never recycled | Controls and evidence point back to it |
| Risk | One sentence: what could happen, to what | “Access” is a topic, not a risk |
| Category | Access, change, vendor, people, fraud, continuity | Shows you which area has no rows |
| Owner | A single person | A team owner means nobody acts |
| L and I | Likelihood and impact, one to five each | Kept apart so people can argue each one |
| Score | L times I | Sets the order of work |
| Treatment | Mitigate, transfer, avoid or accept | The decision CC3.2 asks for |
| Control and evidence | Your control ID and where its proof lives | Makes the row testable |
| Residual score | Score after treatment | Shows the work changed something |
| Dates | Found, last reviewed, next review | Proves the register is alive |
Six sample rows for a small SaaS team
These are written for a fifteen person company on Google Cloud. They are concrete on purpose, because “unauthorized access” as a row tells you nothing about what to fix. L is likelihood and I is impact.
| ID | Risk | Owner | L | I | Score | Treatment | Control |
|---|---|---|---|---|---|---|---|
| R-01 | A leaver keeps cloud and code access because offboarding is informal | CTO | 3 | 5 | 15 | Mitigate | AC-03, offboarding checklist |
| R-02 | The cloud organization admin account has no hardware key and a shared password | Platform lead | 2 | 5 | 10 | Mitigate | AC-01, MFA enforcement report |
| R-03 | Engineers can merge their own changes to main without review | CTO | 4 | 3 | 12 | Mitigate | CM-01, branch protection export |
| R-04 | Database backups run nightly and no restore has ever been tried | Platform lead | 2 | 5 | 10 | Mitigate | BC-02, quarterly restore test |
| R-05 | One finance user can both issue credits and change the invoice they apply to | CEO | 2 | 4 | 8 | Mitigate | FR-01, monthly credit report sign off |
| R-06 | The support chat vendor stores customer emails and has no SOC 2 report | Head of support | 3 | 3 | 9 | Accept (CEO, revisit at renewal) | VM-02, acceptance memo |
R-05 is the fraud row CC3.3 asks you to think about. R-04 still belongs here under a Security only scope, since recovering from a security event is part of the common criteria, though how deeply it is tested depends on scope. The scoping tool helps with that choice.
A scale anyone can reuse
One to five for likelihood, one to five for impact, multiply. A three point scale is just as valid. What matters is a written meaning for each number, so the same four means the same thing in January and in June. Skip weighted asset models and loss formulas. At fifteen people they produce numbers nobody can explain six months later, and the time is better spent fixing R-01.
Four ways to treat a risk
Every row ends in one of four decisions. “Still looking into it” is not one of them, and a row left there has no treatment.
- Mitigate
- Add or tighten a control and point the row at it. Five of the six rows above.
- Transfer
- Shift the cost to someone else through insurance or a contract. The event can still happen.
- Avoid
- Stop the activity: drop the vendor, the feature or the data you did not need.
- Accept
- Carry the risk knowingly. This is the only treatment that needs a signature from someone with authority, a date, and a date to look again. The person who found the risk does not sign. On a small team that is a founder or officer, as SOC 2 for a small team explains.
When to review it
Yearly at minimum, quarterly if you ship often. Under CC3.4, a big change triggers a review whatever the calendar says: a new critical vendor, a first enterprise deal, an incident, a new region.1 For a Type 2, check the dates. A review finished before your window opened is a good habit but not evidence for that window.2 The shortest window is a 3-month observation window, so plan at least one review inside it.
Link every row to proof
Test your register with one walk. Pick a row, open the control it names, then open the evidence that control produced. If any step fails, the row is a claim, not a control. Use your own control IDs, not criterion numbers: CC6.2 is a criterion, AC-03 is something you run. Most of that evidence also appears on the PBC list, and the matching documents are in the SOC 2 policy list.
What a risk review costs if you buy one
Filling in this template yourself costs a few hours. Firms that sell professional readiness work publish figures like these for an assessment:
- Secureframe states that a professional SOC 2 readiness assessment typically costs between $10-17,000, and that cost depends on the size of your organization and the scope of your audit. Source, checked 2026-09-01.
- IS Partners, an audit and advisory firm, states that a professional SOC 2 readiness assessment can cost anywhere between $10,000 to $17,000, and that the assessment itself can take anywhere from a few weeks to a few months. Source, checked 2026-09-01.
The cybersoftware readiness assessment is free: readiness assessment, score, gap list and one AI sample policy. Take the free readiness assessment in about 15 minutes. If you want the register kept for you, the software generates it and tracks reviews at $199 a month, cancel any time. All options are on pricing.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
What is a risk register in SOC 2?
Which columns should the register have?
How should risks be scored?
Is it acceptable to accept a risk rather than fix it?
How often must the register be reviewed?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.