Lifecycle of Risk in a diagram
Simple is better
In the diagram above you can see the UML diagram I use to manage the lifecycle of risks. Obviously when you assign a risk to an owner, you have to communicate it. Otherwise it is unlikely the owner will do something about it.
I find it simpler than the ISO27005 flow view:
Unfortunately, risks are often immortal and resist attempts to move them to the Closed status…