Home | News | How to complete a risk assessment for ISO 27001?

News

How to complete a risk assessment for ISO 27001?

How To Complete A Risk Assessment For Iso 27001?

How to complete a risk assessment for ISO 27001?

Completing a risk assessment for ISO 27001 means identifying the information security risks that could affect your organisation, assessing how serious those risks are and deciding what action you need to take.

The process sits at the heart of an Information Security Management System, commonly called an ISMS. ISO/IEC 27001:2022 uses a risk-based approach rather than asking every organisation to implement an identical set of security measures. ISO describes the standard as enabling organisations to establish an ISMS and apply a risk management process adapted to their own needs.

A useful assessment should answer practical questions. What information and services need protection? What could go wrong? Why could it happen? How likely is the event? What harm could it cause? Which controls already reduce the risk? Does the remaining exposure fall within the organisation’s acceptance criteria? If it does not, what should the business do next?

UK Cyber Compliance supports organisations through this process using an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. Its platform supports risk assessment, control management, policy activity and progress towards audit readiness through guided workflows.

Risk assessment is the engine behind ISO 27001

ISO 27001 does not treat cyber security as a checklist of technical products. It asks the organisation to understand its circumstances and make informed decisions based on risk.

That distinction matters because organisations face different threats. A cloud software business may worry about customer database access, software vulnerabilities and service outages. A consultancy may focus more heavily on confidential client files, remote workers and cloud accounts. A manufacturer may depend on operational technology, suppliers and production systems.

The risk assessment gives the business a structured way to decide which issues deserve the most attention.

ISO/IEC 27005:2022 supports ISO 27001 by providing guidance across the information security risk management cycle, including assessment, treatment, communication, monitoring and review.

Your assessment should therefore support decisions rather than simply create paperwork for an auditor.

What is ISO 27001 Certification?

ISO 27001 certification provides independent assurance that an organisation operates an ISMS that meets the requirements of ISO/IEC 27001.

ISO describes ISO/IEC 27001 as the world’s best-known standard for information security management systems. The framework helps organisations protect information through a structured combination of people, policies, processes and technology.

The ISMS covers much more than technical security. It connects:

Risk management

Leadership

Information security objectives

Policies

Legal and contractual requirements

People

Suppliers

Technology

Physical security

Internal audit

Management review

Corrective action

Continual improvement

Risk assessment drives many of these activities. The organisation needs to understand its exposure before it can decide which controls, resources and actions make sense.

Certification does not prove that an organisation will never experience an incident. It demonstrates that the business has created and operates a structured system for understanding and managing information security risk.

what is iso 27001

ISO 27001 is the commonly used name for ISO/IEC 27001:2022, the international requirements standard for information security management systems.

The standard supports the protection of confidentiality, integrity and availability.

Confidentiality means information remains available only to authorised people and systems.

Integrity means information stays accurate, complete and trustworthy.

Availability means authorised users can reach information and services when needed.

A risk assessment should consider how events might affect each of these areas.

For example, stolen credentials could threaten confidentiality. An attacker changing financial records could damage integrity. Ransomware or a cloud outage could affect availability.

One event can affect several areas at the same time.

ISO 27001 allows organisations to adapt the risk management process to their own objectives, processes and structure rather than imposing one universal assessment model.

Start by defining what your ISMS covers

Before identifying risks, define the ISMS scope.

You cannot assess information security risk effectively if you do not know which services, information, systems, people and suppliers sit inside the boundary.

Your scope may cover the whole organisation or a clearly defined business service. Whatever boundary you choose, you need to identify the important dependencies that support it.

Consider:

Business services

Customer information

Employee information

Cloud services

Business applications

Staff devices

Servers

Networks

Remote working

Physical records

Office locations

External support providers

Software suppliers

Critical business processes

Third-party platforms

A narrow scope that ignores essential dependencies can create an inaccurate risk assessment.

For example, if your certified customer service relies on a cloud application, identity provider and managed IT company, you should consider the risks created by those dependencies.

Understand the business before listing threats

A strong assessment starts with context.

Ask what the organisation does, what customers expect and what would cause meaningful harm.

Important questions include:

Which services generate or support important business activity?

Which information would cause serious problems if exposed?

Which information must remain accurate?

Which systems need high availability?

Which suppliers could interrupt operations?

Which employees hold privileged access?

Which customer contracts include security obligations?

Which legal duties influence information handling?

Which business activities depend heavily on technology?

This step prevents the risk assessment from becoming an IT-only exercise.

Information security risk can come from employees, suppliers, physical events, poor processes, technology failures and malicious attackers.

Decide how you will measure risk

Before scoring individual risks, define a consistent methodology.

The assessment method should explain how the organisation evaluates likelihood and impact, calculates the overall risk level and decides whether the result remains acceptable.

A simple model might use a five-point likelihood scale and a five-point impact scale.

Likelihood could range from rare to highly likely.

Impact could range from minor to severe.

The organisation may then combine the values to determine a risk score.

ISO 27001 does not require one specific formula. ISO/IEC 27005 provides structured risk management guidance while leaving organisations flexibility to choose a method appropriate to their circumstances.

Consistency matters more than unnecessary complexity.

If two managers assess similar risks, the method should help them reach reasonably comparable results.

Define likelihood in plain language

Likelihood asks how realistically the event could occur.

Your criteria should explain what each score means.

Factors that can influence likelihood include:

Previous incidents

Current threat activity

Exposure to the internet

Known vulnerabilities

Staff behaviour

Supplier dependency

Frequency of the activity

Existing security controls

Access privileges

The value of the information to an attacker

Avoid scoring solely on instinct.

Use evidence where possible. Security alerts, vulnerability reports, incident history, supplier information and threat intelligence can all support the assessment.

A system with strong access control and multi-factor authentication may face lower account compromise likelihood than a poorly protected system using weak authentication.

The reasoning behind the score matters as much as the number.

Measure impact as a business problem

Impact asks what would happen if the risk event occurred.

Do not limit the assessment to technical inconvenience.

Consider potential effects on:

Customers

Operations

Legal obligations

Contracts

Confidential information

Personal information

Revenue

Reputation

Staff productivity

Service availability

Business continuity

Management time

Supplier relationships

A database failure may create little concern if the business can restore it immediately. The same failure becomes much more serious when no reliable backup exists and customers lose access to essential records.

Process owners should help assess impact. They often understand operational consequences better than the security team alone.

Set risk acceptance criteria before you need them

Risk acceptance criteria determine which risk levels the organisation can tolerate.

Without them, different managers may make inconsistent decisions.

For example, your rules might state that lower risks can receive acceptance from the risk owner, moderate risks require review, high risks require treatment and severe risks require senior management attention.

You should also consider exceptions.

A numerical score should not automatically allow acceptance when the risk would breach a legal obligation or an important customer requirement.

Record who has authority to accept each level of risk.

Clear acceptance criteria make the assessment easier to explain during audit and help management direct resources towards the areas that matter most.

Identify realistic risk scenarios

Now you can begin identifying risks.

Avoid writing single-word entries such as:

Phishing

Ransomware

Supplier

Laptop

Password

These labels do not describe the actual business risk.

Instead, write scenarios that explain what could happen and the resulting consequence.

For example:

“An employee could respond to a convincing phishing email and disclose their credentials, allowing an unauthorised person to access customer correspondence.”

Another example could say:

“A prolonged cloud service outage could prevent staff from accessing the customer platform and lead to missed contractual commitments.”

A useful structure is:

Cause or weakness

Event

Business consequence

This makes each risk easier to score, treat and explain.

Look beyond cyber criminals

Attackers create important risks, but your assessment should cover more than deliberate cyber attacks.

Relevant scenarios may involve:

Human error

Lost equipment

Incorrect permissions

Supplier failure

Power interruption

Fire or flooding

Cloud outages

Unsupported software

Poor change control

Data sent to the wrong recipient

Failure to remove former employee access

Misconfiguration

Missing backups

Inadequate recovery arrangements

Software defects

Contractual failures

Internal misuse

Weak physical security

The assessment should reflect your real organisation rather than a generic list copied from another company’s register.

Identify the assets and processes at risk

Each scenario should connect with something the organisation values.

That may include information, a service, system or business process.

Examples include:

Customer information

Employee records

Finance data

Intellectual property

Email

Customer portals

Cloud storage

Finance platforms

Business websites

Staff laptops

Backup systems

Authentication services

Source code

Physical documents

Supplier platforms

You do not necessarily need an enormous asset register before risk assessment begins. However, you do need enough understanding to know what requires protection and why.

Assign a risk owner

Every significant risk should have an accountable owner.

The risk owner should understand the business consequence and have enough authority to make or escalate treatment decisions.

A technical employee does not automatically make the best risk owner.

For example, the IT team may maintain a finance system, but the Finance Director may own the business risk because they understand the operational and customer consequences of failure.

The risk owner should:

Review the risk description

Agree the impact assessment

Review existing controls

Approve treatment activity

Monitor progress

Review residual risk

Approve or seek acceptance

Escalate serious exposure

Use role titles where practical so the record remains useful when employees change.

Record the controls you already have

Before deciding what further treatment you need, identify the controls that already reduce the risk.

For an email account compromise risk, current controls might include:

Multi-factor authentication

Email filtering

Staff awareness

Restricted administrator access

Logging

Security monitoring

Incident reporting

Account lockout measures

The assessment should only give credit for controls that actually operate.

A policy saying that multi-factor authentication should be enabled does not provide the same protection as evidence showing that the organisation has enabled it across the relevant accounts.

This difference becomes particularly important during an external audit.

Assess the current risk

Once you understand the scenario and current controls, apply your likelihood and impact criteria.

Suppose an organisation uses a five-point scale.

A phishing-related account compromise might receive:

Likelihood: four

Impact: four

Combined score: sixteen

If the organisation defines sixteen as high, the risk may require treatment.

Do not let the numerical calculation replace judgement.

A low-likelihood event with extremely serious consequences may still deserve strong treatment.

Likewise, legal or customer obligations may require a control even when the calculated score appears relatively low.

Record your reasoning

An auditor or manager should be able to understand why the risk received its rating.

Add a short explanation.

For example:

“Phishing remains common across UK organisations, employees use email heavily and the account contains customer correspondence. Multi-factor authentication reduces the likelihood of successful account takeover, but targeted social engineering remains credible.”

This gives the score context.

Current UK Government research reinforces the relevance of phishing risk. The Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months, while 38 per cent experienced phishing.

These statistics do not mean every organisation should assign the same phishing score. They provide useful background evidence that businesses can consider alongside their own circumstances.

Decide what to do with each risk

After evaluating the risk, decide how to treat it.

Common options include reducing the risk, avoiding the activity, sharing part of the exposure or accepting the remaining risk.

Reduce the risk

Introduce or strengthen controls.

Examples include enabling multi-factor authentication, improving backups, restricting access or strengthening supplier oversight.

Avoid the risk

Stop the activity that creates the exposure.

For example, a business may decide not to store particularly sensitive information when it has no genuine need for it.

Share the risk

Contracts, external providers or insurance may transfer part of the potential consequence.

The organisation still needs to understand what responsibility remains.

Accept the risk

Management may accept the exposure when it falls within the approved criteria.

Acceptance should represent an informed decision rather than inactivity.

Build a clear risk treatment plan

When a risk needs further action, create a treatment plan.

Each action should state:

What needs to happen

Who owns the action

When it should finish

Which control it supports

What evidence will demonstrate completion

What risk reduction the organisation expects

Avoid vague actions such as “improve security.”

A stronger action might say:

“Enable multi-factor authentication for all users of the finance platform, review administrator access and retain the completed access report.”

This gives the owner a measurable outcome.

The risk register and treatment plan should work together rather than becoming disconnected records.

Compare selected controls with Annex A

Once you determine the controls needed to treat risk, compare them with Annex A.

ISO/IEC 27001:2022 contains a reference set of 93 Annex A controls. ISO/IEC 27002 provides supporting guidance for information security controls.

The Annex A controls cover organisational, people, physical and technological security areas.

The purpose of the comparison is to help ensure that your treatment decisions have not overlooked relevant controls.

Do not begin by automatically applying all 93 controls.

Risk treatment comes first.

Annex A then acts as an important cross-check.

Your organisation can also use additional controls outside Annex A when its risks require them.

Connect the assessment with the Statement of Applicability

The Statement of Applicability, often shortened to SoA, records your control decisions.

It should align closely with the risk assessment and risk treatment process.

When the risk assessment identifies serious account compromise exposure, the SoA should reflect relevant authentication, access and monitoring controls.

When supplier risk matters, the SoA should show the appropriate supplier-related controls.

Your risk register, risk treatment plan and SoA should tell one coherent story.

Contradictions often create audit questions.

If the risk register says a control remains planned but the SoA says fully implemented, the organisation should correct the inconsistency.

Assess residual risk after treatment

Treatment does not normally remove all risk.

Residual risk is what remains after the chosen controls operate.

Reassess likelihood and impact once implementation has genuinely happened.

Do not reduce the risk rating simply because you created an action.

For example, writing “enable MFA” in a treatment plan does not reduce account compromise risk. The reduction occurs when the organisation deploys MFA successfully and verifies coverage.

The risk owner should review the remaining exposure and decide whether it now meets the acceptance criteria.

If it remains too high, additional treatment may be necessary.

Document risk acceptance

When management accepts residual risk, keep a clear record.

Useful information includes:

Risk reference

Residual rating

Reason for acceptance

Approver

Approval date

Conditions

Review date

Any temporary measures

The level of approval should reflect the seriousness of the exposure.

A department manager might approve a low operational risk. A serious risk involving major customer information may need director or board oversight.

The organisation should define this authority within its risk management process.

Review risks when the business changes

Risk assessment is not a one-time certification task.

ISO 27005 describes monitoring and review as part of the wider information security risk management cycle.

Review risks after significant events such as:

Launching a new service

Changing a critical supplier

Migrating systems

Opening a new location

Changing working arrangements

Winning a major contract

Experiencing a security incident

Discovering a serious vulnerability

Changing important software

Receiving an audit finding

Changes in legal requirements

You should also schedule regular reviews.

A risk that looked acceptable last year may become unacceptable when the organisation or threat environment changes.

Use incidents as risk information

Security incidents provide some of the best information for improving risk assessment.

When an incident occurs, ask:

Did the risk register already contain this scenario?

Was the likelihood accurate?

Was the impact assessment realistic?

Did existing controls operate?

What failed?

Which new controls do we need?

Should we change the acceptance criteria?

Does the residual risk need reassessment?

A strong ISMS learns from events instead of treating them as isolated technical problems.

Use internal audit to test the assessment

Internal audit should test whether the organisation follows its own risk management method.

An internal auditor might select several risks and ask:

Does the scenario make sense?

Does it sit within the ISMS scope?

Did the organisation score it consistently?

Is the owner appropriate?

Do the stated controls actually operate?

Does evidence support the control claims?

Did management treat unacceptable risk?

Does the residual rating make sense?

Does the SoA agree with the risk assessment?

This review gives the organisation an opportunity to correct weaknesses before the external certification audit.

Management review should see the major risks

Senior management needs visibility of significant information security exposure.

A risk register can support management review by showing:

Highest-rated risks

Overdue treatment

Recent changes

Accepted exposure

Control failures

Supplier concerns

Incidents

Emerging threats

Resource needs

Management does not need to discuss every minor entry at every meeting.

It should understand the risks that could affect business objectives, customers, contracts and legal responsibilities.

Who needs iso 27001 certification

ISO 27001 certification can benefit organisations that handle valuable information or need to demonstrate structured information security management.

Technology providers, software companies, managed service providers, professional firms, healthcare suppliers, manufacturers, charities, finance-related organisations and public sector contractors may all gain value from the framework.

ISO explains that the ISO/IEC 27000 family helps organisations manage information such as financial records, intellectual property, employee information and information entrusted by third parties.

Customer requirements often drive certification.

A client may want evidence that a supplier understands information security risks rather than simply owning security software.

Tender requirements, contractual obligations, board governance and supply-chain assurance can also influence the decision.

Small organisations can keep the process practical

A small business does not need an enormous risk model.

Start with the areas that matter:

Important services

Sensitive information

Cloud services

Staff access

Critical suppliers

Backups

Email

Remote working

Customer obligations

Business continuity

Use clear language.

Keep the scoring model straightforward.

Assign owners who understand the business.

Focus on meaningful scenarios rather than creating hundreds of theoretical risks.

A smaller, well-maintained register provides much more value than a huge register that nobody reviews.

ISO 27001 Certification Levels

ISO 27001 does not award formal achievement bands such as bronze, silver or gold.

An organisation either meets the certification requirements for its stated ISMS scope or it does not.

Businesses do move through practical stages of readiness.

These stages commonly include:

Defining the ISMS scope

Understanding the business context

Assessing information security risk

Treating unacceptable risk

Selecting controls

Preparing the SoA

Operating the controls

Gathering evidence

Completing internal audit

Holding management review

Undergoing external assessment

Security maturity can continue improving after certification through stronger controls, better evidence, improved monitoring and more effective management processes.

That progress reflects continual improvement rather than a formal certification band.

How the Certification Works

The organisation begins by defining the ISMS scope and understanding the internal and external factors that affect information security.

It identifies interested parties and relevant obligations.

The business then establishes its risk assessment method and completes the information security risk assessment.

Unacceptable risks move into treatment.

The organisation determines the controls it needs, checks those choices against Annex A and records the control position in the Statement of Applicability.

Next, the organisation operates the ISMS and gathers evidence.

Internal audit checks whether the management system meets requirements and operates effectively.

Management review gives senior leaders an opportunity to assess risks, findings, objectives, resources and improvement needs.

The external certification process then assesses the ISMS against ISO/IEC 27001 requirements.

Certification depends on demonstrating that the ISMS operates rather than merely showing that documents exist.

Common mistakes when completing the assessment

One common mistake involves using a generic risk register downloaded from somewhere else.

Templates can help with structure, but your risks must reflect your business.

Another mistake involves listing threats instead of writing complete scenarios.

“Ransomware” tells management very little.

A proper scenario explains how ransomware could affect a service, why the event could occur and what the business consequence would be.

Other common weaknesses include:

Assessing only IT systems

Ignoring suppliers

No risk owner

Unclear scoring criteria

No acceptance criteria

Treating planned controls as implemented

No residual risk assessment

No link with Annex A

No connection with the SoA

No review dates

Risk ratings that lack supporting reasoning

Old entries that no longer reflect the business

A good assessment remains specific, consistent and current.

Keep evidence behind your assessment

An auditor may ask why you assigned a particular score or why you believe a control reduces the risk.

Useful supporting records can include:

Incident history

Access reviews

Vulnerability reports

Security monitoring

Supplier assessments

Contract requirements

Backup tests

Cloud security records

Audit findings

Management approvals

Training records

Control test results

Evidence improves confidence in the assessment.

A rating supported by current information carries more value than one based only on opinion.

Use the risk assessment to decide where resources go

Risk assessment should help management prioritise.

If one risk could seriously interrupt customer services while another causes only minor inconvenience, the organisation should understand that difference.

Treatment decisions can then focus staff time and security investment on the most important problems.

ISO/IEC 27005 highlights prioritisation and informed decision-making as benefits of structured information security risk management.

This is why the assessment should not become a compliance exercise.

Its real purpose involves helping leaders make better decisions.

Which UK-based firms offer ISO 27001 consultancy services?

UK organisations can obtain ISO 27001 support from cyber security consultancies, information security specialists, compliance advisers, managed service providers and platform-led services.

UK Cyber Compliance provides an automated and AI-driven platform that supports the ISO 27001 journey from risk assessment through wider compliance activity. Its current website describes structured workflows designed to guide organisations through certification requirements.

A capable provider should help the organisation understand:

ISMS scope

Risk methodology

Likelihood and impact

Acceptance criteria

Risk identification

Treatment

Annex A controls

The Statement of Applicability

Evidence

Internal audit readiness

Management review

The business should remain responsible for its own decisions.

A consultant or platform can guide the process, but management and risk owners need to understand the risks they have accepted and the controls they rely on.

How UK Cyber Compliance supports risk assessment

Managing a risk assessment through disconnected spreadsheets can become difficult as the organisation adds owners, controls, actions, evidence and review dates.

UK Cyber Compliance provides a centralised approach to ISO 27001 compliance. Its platform describes support ranging from risk assessment to policy generation, with guided workflows that help users progress through certification requirements.

This helps teams connect:

Risks

Owners

Controls

Actions

Policies

Evidence

Audit preparation

Automation can reduce repeated administrative work, while AI-driven assistance can guide users through assessment activity.

Human judgement remains essential.

Management still sets risk criteria. Process owners still assess business impact. Risk owners still approve treatment. Senior leaders still accept significant residual exposure.

A practical ISO 27001 risk assessment checklist

Before your external audit, ask whether your organisation can answer the following questions clearly:

Have we defined the ISMS scope?

Do we understand which information and services matter most?

Have we documented our risk assessment method?

Are likelihood criteria clear?

Are impact criteria clear?

Have we defined risk acceptance criteria?

Do our risk scenarios describe realistic events and consequences?

Does every important risk have an owner?

Have we recorded existing controls accurately?

Have we scored risks consistently?

Can we explain the reasoning behind the ratings?

Have we identified unacceptable risks?

Does every unacceptable risk have treatment?

Do treatment actions have owners and target dates?

Have we compared necessary controls with Annex A?

Does our SoA agree with our treatment decisions?

Have we assessed residual risk after controls became operational?

Has the correct authority accepted residual exposure?

Do risks have review dates?

Do we reassess risks after significant change?

Can we provide evidence supporting our decisions?

If several answers remain unclear, strengthen the assessment before the external audit.

Make risk assessment useful beyond certification

The strongest ISO 27001 risk assessment does much more than help an organisation prepare for an auditor.

It gives management a clear picture of what could harm the business and where security effort will have the greatest value.

Start by defining your scope and assessment method. Identify realistic scenarios, evaluate likelihood and business impact, assign owners and document current controls.

Compare each risk with your acceptance criteria. Treat exposure that remains too high. Select appropriate controls, check them against Annex A and record the resulting decisions in the Statement of Applicability.

Reassess the remaining risk after treatment and keep reviewing the register as your business changes.

UK Cyber Compliance helps organisations organise this work through an automated and AI-driven platform that connects risk assessment with the wider ISO 27001 certification journey.

A clear, evidence-based risk assessment gives your organisation more than audit readiness. It provides a practical foundation for protecting customers, information, services and the future operation of the business.