How to complete a risk assessment for ISO 27001?
Completing a risk assessment for ISO 27001 means identifying the information security risks that could affect your organisation, assessing how serious those risks are and deciding what action you need to take.
The process sits at the heart of an Information Security Management System, commonly called an ISMS. ISO/IEC 27001:2022 uses a risk-based approach rather than asking every organisation to implement an identical set of security measures. ISO describes the standard as enabling organisations to establish an ISMS and apply a risk management process adapted to their own needs.
A useful assessment should answer practical questions. What information and services need protection? What could go wrong? Why could it happen? How likely is the event? What harm could it cause? Which controls already reduce the risk? Does the remaining exposure fall within the organisation’s acceptance criteria? If it does not, what should the business do next?
UK Cyber Compliance supports organisations through this process using an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. Its platform supports risk assessment, control management, policy activity and progress towards audit readiness through guided workflows.
Risk assessment is the engine behind ISO 27001
ISO 27001 does not treat cyber security as a checklist of technical products. It asks the organisation to understand its circumstances and make informed decisions based on risk.
That distinction matters because organisations face different threats. A cloud software business may worry about customer database access, software vulnerabilities and service outages. A consultancy may focus more heavily on confidential client files, remote workers and cloud accounts. A manufacturer may depend on operational technology, suppliers and production systems.
The risk assessment gives the business a structured way to decide which issues deserve the most attention.
ISO/IEC 27005:2022 supports ISO 27001 by providing guidance across the information security risk management cycle, including assessment, treatment, communication, monitoring and review.
Your assessment should therefore support decisions rather than simply create paperwork for an auditor.
What is ISO 27001 Certification?
ISO 27001 certification provides independent assurance that an organisation operates an ISMS that meets the requirements of ISO/IEC 27001.
ISO describes ISO/IEC 27001 as the world’s best-known standard for information security management systems. The framework helps organisations protect information through a structured combination of people, policies, processes and technology.
The ISMS covers much more than technical security. It connects:
Risk management
Leadership
Information security objectives
Policies
Legal and contractual requirements
People
Suppliers
Technology
Physical security
Internal audit
Management review
Corrective action
Continual improvement
Risk assessment drives many of these activities. The organisation needs to understand its exposure before it can decide which controls, resources and actions make sense.
Certification does not prove that an organisation will never experience an incident. It demonstrates that the business has created and operates a structured system for understanding and managing information security risk.
what is iso 27001
ISO 27001 is the commonly used name for ISO/IEC 27001:2022, the international requirements standard for information security management systems.
The standard supports the protection of confidentiality, integrity and availability.
Confidentiality means information remains available only to authorised people and systems.
Integrity means information stays accurate, complete and trustworthy.
Availability means authorised users can reach information and services when needed.
A risk assessment should consider how events might affect each of these areas.
For example, stolen credentials could threaten confidentiality. An attacker changing financial records could damage integrity. Ransomware or a cloud outage could affect availability.
One event can affect several areas at the same time.
ISO 27001 allows organisations to adapt the risk management process to their own objectives, processes and structure rather than imposing one universal assessment model.
Start by defining what your ISMS covers
Before identifying risks, define the ISMS scope.
You cannot assess information security risk effectively if you do not know which services, information, systems, people and suppliers sit inside the boundary.
Your scope may cover the whole organisation or a clearly defined business service. Whatever boundary you choose, you need to identify the important dependencies that support it.
Consider:
Business services
Customer information
Employee information
Cloud services
Business applications
Staff devices
Servers
Networks
Remote working
Physical records
Office locations
External support providers
Software suppliers
Critical business processes
Third-party platforms
A narrow scope that ignores essential dependencies can create an inaccurate risk assessment.
For example, if your certified customer service relies on a cloud application, identity provider and managed IT company, you should consider the risks created by those dependencies.
Understand the business before listing threats
A strong assessment starts with context.
Ask what the organisation does, what customers expect and what would cause meaningful harm.
Important questions include:
Which services generate or support important business activity?
Which information would cause serious problems if exposed?
Which information must remain accurate?
Which systems need high availability?
Which suppliers could interrupt operations?
Which employees hold privileged access?
Which customer contracts include security obligations?
Which legal duties influence information handling?
Which business activities depend heavily on technology?
This step prevents the risk assessment from becoming an IT-only exercise.
Information security risk can come from employees, suppliers, physical events, poor processes, technology failures and malicious attackers.
Decide how you will measure risk
Before scoring individual risks, define a consistent methodology.
The assessment method should explain how the organisation evaluates likelihood and impact, calculates the overall risk level and decides whether the result remains acceptable.
A simple model might use a five-point likelihood scale and a five-point impact scale.
Likelihood could range from rare to highly likely.
Impact could range from minor to severe.
The organisation may then combine the values to determine a risk score.
ISO 27001 does not require one specific formula. ISO/IEC 27005 provides structured risk management guidance while leaving organisations flexibility to choose a method appropriate to their circumstances.
Consistency matters more than unnecessary complexity.
If two managers assess similar risks, the method should help them reach reasonably comparable results.
Define likelihood in plain language
Likelihood asks how realistically the event could occur.
Your criteria should explain what each score means.
Factors that can influence likelihood include:
Previous incidents
Current threat activity
Exposure to the internet
Known vulnerabilities
Staff behaviour
Supplier dependency
Frequency of the activity
Existing security controls
Access privileges
The value of the information to an attacker
Avoid scoring solely on instinct.
Use evidence where possible. Security alerts, vulnerability reports, incident history, supplier information and threat intelligence can all support the assessment.
A system with strong access control and multi-factor authentication may face lower account compromise likelihood than a poorly protected system using weak authentication.
The reasoning behind the score matters as much as the number.
Measure impact as a business problem
Impact asks what would happen if the risk event occurred.
Do not limit the assessment to technical inconvenience.
Consider potential effects on:
Customers
Operations
Legal obligations
Contracts
Confidential information
Personal information
Revenue
Reputation
Staff productivity
Service availability
Business continuity
Management time
Supplier relationships
A database failure may create little concern if the business can restore it immediately. The same failure becomes much more serious when no reliable backup exists and customers lose access to essential records.
Process owners should help assess impact. They often understand operational consequences better than the security team alone.
Set risk acceptance criteria before you need them
Risk acceptance criteria determine which risk levels the organisation can tolerate.
Without them, different managers may make inconsistent decisions.
For example, your rules might state that lower risks can receive acceptance from the risk owner, moderate risks require review, high risks require treatment and severe risks require senior management attention.
You should also consider exceptions.
A numerical score should not automatically allow acceptance when the risk would breach a legal obligation or an important customer requirement.
Record who has authority to accept each level of risk.
Clear acceptance criteria make the assessment easier to explain during audit and help management direct resources towards the areas that matter most.
Identify realistic risk scenarios
Now you can begin identifying risks.
Avoid writing single-word entries such as:
Phishing
Ransomware
Supplier
Laptop
Password
These labels do not describe the actual business risk.
Instead, write scenarios that explain what could happen and the resulting consequence.
For example:
“An employee could respond to a convincing phishing email and disclose their credentials, allowing an unauthorised person to access customer correspondence.”
Another example could say:
“A prolonged cloud service outage could prevent staff from accessing the customer platform and lead to missed contractual commitments.”
A useful structure is:
Cause or weakness
Event
Business consequence
This makes each risk easier to score, treat and explain.
Look beyond cyber criminals
Attackers create important risks, but your assessment should cover more than deliberate cyber attacks.
Relevant scenarios may involve:
Human error
Lost equipment
Incorrect permissions
Supplier failure
Power interruption
Fire or flooding
Cloud outages
Unsupported software
Poor change control
Data sent to the wrong recipient
Failure to remove former employee access
Misconfiguration
Missing backups
Inadequate recovery arrangements
Software defects
Contractual failures
Internal misuse
Weak physical security
The assessment should reflect your real organisation rather than a generic list copied from another company’s register.
Identify the assets and processes at risk
Each scenario should connect with something the organisation values.
That may include information, a service, system or business process.
Examples include:
Customer information
Employee records
Finance data
Intellectual property
Customer portals
Cloud storage
Finance platforms
Business websites
Staff laptops
Backup systems
Authentication services
Source code
Physical documents
Supplier platforms
You do not necessarily need an enormous asset register before risk assessment begins. However, you do need enough understanding to know what requires protection and why.
Assign a risk owner
Every significant risk should have an accountable owner.
The risk owner should understand the business consequence and have enough authority to make or escalate treatment decisions.
A technical employee does not automatically make the best risk owner.
For example, the IT team may maintain a finance system, but the Finance Director may own the business risk because they understand the operational and customer consequences of failure.
The risk owner should:
Review the risk description
Agree the impact assessment
Review existing controls
Approve treatment activity
Monitor progress
Review residual risk
Approve or seek acceptance
Escalate serious exposure
Use role titles where practical so the record remains useful when employees change.
Record the controls you already have
Before deciding what further treatment you need, identify the controls that already reduce the risk.
For an email account compromise risk, current controls might include:
Multi-factor authentication
Email filtering
Staff awareness
Restricted administrator access
Logging
Security monitoring
Incident reporting
Account lockout measures
The assessment should only give credit for controls that actually operate.
A policy saying that multi-factor authentication should be enabled does not provide the same protection as evidence showing that the organisation has enabled it across the relevant accounts.
This difference becomes particularly important during an external audit.
Assess the current risk
Once you understand the scenario and current controls, apply your likelihood and impact criteria.
Suppose an organisation uses a five-point scale.
A phishing-related account compromise might receive:
Likelihood: four
Impact: four
Combined score: sixteen
If the organisation defines sixteen as high, the risk may require treatment.
Do not let the numerical calculation replace judgement.
A low-likelihood event with extremely serious consequences may still deserve strong treatment.
Likewise, legal or customer obligations may require a control even when the calculated score appears relatively low.
Record your reasoning
An auditor or manager should be able to understand why the risk received its rating.
Add a short explanation.
For example:
“Phishing remains common across UK organisations, employees use email heavily and the account contains customer correspondence. Multi-factor authentication reduces the likelihood of successful account takeover, but targeted social engineering remains credible.”
This gives the score context.
Current UK Government research reinforces the relevance of phishing risk. The Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months, while 38 per cent experienced phishing.
These statistics do not mean every organisation should assign the same phishing score. They provide useful background evidence that businesses can consider alongside their own circumstances.
Decide what to do with each risk
After evaluating the risk, decide how to treat it.
Common options include reducing the risk, avoiding the activity, sharing part of the exposure or accepting the remaining risk.
Reduce the risk
Introduce or strengthen controls.
Examples include enabling multi-factor authentication, improving backups, restricting access or strengthening supplier oversight.
Avoid the risk
Stop the activity that creates the exposure.
For example, a business may decide not to store particularly sensitive information when it has no genuine need for it.
Share the risk
Contracts, external providers or insurance may transfer part of the potential consequence.
The organisation still needs to understand what responsibility remains.
Accept the risk
Management may accept the exposure when it falls within the approved criteria.
Acceptance should represent an informed decision rather than inactivity.
Build a clear risk treatment plan
When a risk needs further action, create a treatment plan.
Each action should state:
What needs to happen
Who owns the action
When it should finish
Which control it supports
What evidence will demonstrate completion
What risk reduction the organisation expects
Avoid vague actions such as “improve security.”
A stronger action might say:
“Enable multi-factor authentication for all users of the finance platform, review administrator access and retain the completed access report.”
This gives the owner a measurable outcome.
The risk register and treatment plan should work together rather than becoming disconnected records.
Compare selected controls with Annex A
Once you determine the controls needed to treat risk, compare them with Annex A.
ISO/IEC 27001:2022 contains a reference set of 93 Annex A controls. ISO/IEC 27002 provides supporting guidance for information security controls.
The Annex A controls cover organisational, people, physical and technological security areas.
The purpose of the comparison is to help ensure that your treatment decisions have not overlooked relevant controls.
Do not begin by automatically applying all 93 controls.
Risk treatment comes first.
Annex A then acts as an important cross-check.
Your organisation can also use additional controls outside Annex A when its risks require them.
Connect the assessment with the Statement of Applicability
The Statement of Applicability, often shortened to SoA, records your control decisions.
It should align closely with the risk assessment and risk treatment process.
When the risk assessment identifies serious account compromise exposure, the SoA should reflect relevant authentication, access and monitoring controls.
When supplier risk matters, the SoA should show the appropriate supplier-related controls.
Your risk register, risk treatment plan and SoA should tell one coherent story.
Contradictions often create audit questions.
If the risk register says a control remains planned but the SoA says fully implemented, the organisation should correct the inconsistency.
Assess residual risk after treatment
Treatment does not normally remove all risk.
Residual risk is what remains after the chosen controls operate.
Reassess likelihood and impact once implementation has genuinely happened.
Do not reduce the risk rating simply because you created an action.
For example, writing “enable MFA” in a treatment plan does not reduce account compromise risk. The reduction occurs when the organisation deploys MFA successfully and verifies coverage.
The risk owner should review the remaining exposure and decide whether it now meets the acceptance criteria.
If it remains too high, additional treatment may be necessary.
Document risk acceptance
When management accepts residual risk, keep a clear record.
Useful information includes:
Risk reference
Residual rating
Reason for acceptance
Approver
Approval date
Conditions
Review date
Any temporary measures
The level of approval should reflect the seriousness of the exposure.
A department manager might approve a low operational risk. A serious risk involving major customer information may need director or board oversight.
The organisation should define this authority within its risk management process.
Review risks when the business changes
Risk assessment is not a one-time certification task.
ISO 27005 describes monitoring and review as part of the wider information security risk management cycle.
Review risks after significant events such as:
Launching a new service
Changing a critical supplier
Migrating systems
Opening a new location
Changing working arrangements
Winning a major contract
Experiencing a security incident
Discovering a serious vulnerability
Changing important software
Receiving an audit finding
Changes in legal requirements
You should also schedule regular reviews.
A risk that looked acceptable last year may become unacceptable when the organisation or threat environment changes.
Use incidents as risk information
Security incidents provide some of the best information for improving risk assessment.
When an incident occurs, ask:
Did the risk register already contain this scenario?
Was the likelihood accurate?
Was the impact assessment realistic?
Did existing controls operate?
What failed?
Which new controls do we need?
Should we change the acceptance criteria?
Does the residual risk need reassessment?
A strong ISMS learns from events instead of treating them as isolated technical problems.
Use internal audit to test the assessment
Internal audit should test whether the organisation follows its own risk management method.
An internal auditor might select several risks and ask:
Does the scenario make sense?
Does it sit within the ISMS scope?
Did the organisation score it consistently?
Is the owner appropriate?
Do the stated controls actually operate?
Does evidence support the control claims?
Did management treat unacceptable risk?
Does the residual rating make sense?
Does the SoA agree with the risk assessment?
This review gives the organisation an opportunity to correct weaknesses before the external certification audit.
Management review should see the major risks
Senior management needs visibility of significant information security exposure.
A risk register can support management review by showing:
Highest-rated risks
Overdue treatment
Recent changes
Accepted exposure
Control failures
Supplier concerns
Incidents
Emerging threats
Resource needs
Management does not need to discuss every minor entry at every meeting.
It should understand the risks that could affect business objectives, customers, contracts and legal responsibilities.
Who needs iso 27001 certification
ISO 27001 certification can benefit organisations that handle valuable information or need to demonstrate structured information security management.
Technology providers, software companies, managed service providers, professional firms, healthcare suppliers, manufacturers, charities, finance-related organisations and public sector contractors may all gain value from the framework.
ISO explains that the ISO/IEC 27000 family helps organisations manage information such as financial records, intellectual property, employee information and information entrusted by third parties.
Customer requirements often drive certification.
A client may want evidence that a supplier understands information security risks rather than simply owning security software.
Tender requirements, contractual obligations, board governance and supply-chain assurance can also influence the decision.
Small organisations can keep the process practical
A small business does not need an enormous risk model.
Start with the areas that matter:
Important services
Sensitive information
Cloud services
Staff access
Critical suppliers
Backups
Remote working
Customer obligations
Business continuity
Use clear language.
Keep the scoring model straightforward.
Assign owners who understand the business.
Focus on meaningful scenarios rather than creating hundreds of theoretical risks.
A smaller, well-maintained register provides much more value than a huge register that nobody reviews.
ISO 27001 Certification Levels
ISO 27001 does not award formal achievement bands such as bronze, silver or gold.
An organisation either meets the certification requirements for its stated ISMS scope or it does not.
Businesses do move through practical stages of readiness.
These stages commonly include:
Defining the ISMS scope
Understanding the business context
Assessing information security risk
Treating unacceptable risk
Selecting controls
Preparing the SoA
Operating the controls
Gathering evidence
Completing internal audit
Holding management review
Undergoing external assessment
Security maturity can continue improving after certification through stronger controls, better evidence, improved monitoring and more effective management processes.
That progress reflects continual improvement rather than a formal certification band.
How the Certification Works
The organisation begins by defining the ISMS scope and understanding the internal and external factors that affect information security.
It identifies interested parties and relevant obligations.
The business then establishes its risk assessment method and completes the information security risk assessment.
Unacceptable risks move into treatment.
The organisation determines the controls it needs, checks those choices against Annex A and records the control position in the Statement of Applicability.
Next, the organisation operates the ISMS and gathers evidence.
Internal audit checks whether the management system meets requirements and operates effectively.
Management review gives senior leaders an opportunity to assess risks, findings, objectives, resources and improvement needs.
The external certification process then assesses the ISMS against ISO/IEC 27001 requirements.
Certification depends on demonstrating that the ISMS operates rather than merely showing that documents exist.
Common mistakes when completing the assessment
One common mistake involves using a generic risk register downloaded from somewhere else.
Templates can help with structure, but your risks must reflect your business.
Another mistake involves listing threats instead of writing complete scenarios.
“Ransomware” tells management very little.
A proper scenario explains how ransomware could affect a service, why the event could occur and what the business consequence would be.
Other common weaknesses include:
Assessing only IT systems
Ignoring suppliers
No risk owner
Unclear scoring criteria
No acceptance criteria
Treating planned controls as implemented
No residual risk assessment
No link with Annex A
No connection with the SoA
No review dates
Risk ratings that lack supporting reasoning
Old entries that no longer reflect the business
A good assessment remains specific, consistent and current.
Keep evidence behind your assessment
An auditor may ask why you assigned a particular score or why you believe a control reduces the risk.
Useful supporting records can include:
Incident history
Access reviews
Vulnerability reports
Security monitoring
Supplier assessments
Contract requirements
Backup tests
Cloud security records
Audit findings
Management approvals
Training records
Control test results
Evidence improves confidence in the assessment.
A rating supported by current information carries more value than one based only on opinion.
Use the risk assessment to decide where resources go
Risk assessment should help management prioritise.
If one risk could seriously interrupt customer services while another causes only minor inconvenience, the organisation should understand that difference.
Treatment decisions can then focus staff time and security investment on the most important problems.
ISO/IEC 27005 highlights prioritisation and informed decision-making as benefits of structured information security risk management.
This is why the assessment should not become a compliance exercise.
Its real purpose involves helping leaders make better decisions.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can obtain ISO 27001 support from cyber security consultancies, information security specialists, compliance advisers, managed service providers and platform-led services.
UK Cyber Compliance provides an automated and AI-driven platform that supports the ISO 27001 journey from risk assessment through wider compliance activity. Its current website describes structured workflows designed to guide organisations through certification requirements.
A capable provider should help the organisation understand:
ISMS scope
Risk methodology
Likelihood and impact
Acceptance criteria
Risk identification
Treatment
Annex A controls
The Statement of Applicability
Evidence
Internal audit readiness
Management review
The business should remain responsible for its own decisions.
A consultant or platform can guide the process, but management and risk owners need to understand the risks they have accepted and the controls they rely on.
How UK Cyber Compliance supports risk assessment
Managing a risk assessment through disconnected spreadsheets can become difficult as the organisation adds owners, controls, actions, evidence and review dates.
UK Cyber Compliance provides a centralised approach to ISO 27001 compliance. Its platform describes support ranging from risk assessment to policy generation, with guided workflows that help users progress through certification requirements.
This helps teams connect:
Risks
Owners
Controls
Actions
Policies
Evidence
Audit preparation
Automation can reduce repeated administrative work, while AI-driven assistance can guide users through assessment activity.
Human judgement remains essential.
Management still sets risk criteria. Process owners still assess business impact. Risk owners still approve treatment. Senior leaders still accept significant residual exposure.
A practical ISO 27001 risk assessment checklist
Before your external audit, ask whether your organisation can answer the following questions clearly:
Have we defined the ISMS scope?
Do we understand which information and services matter most?
Have we documented our risk assessment method?
Are likelihood criteria clear?
Are impact criteria clear?
Have we defined risk acceptance criteria?
Do our risk scenarios describe realistic events and consequences?
Does every important risk have an owner?
Have we recorded existing controls accurately?
Have we scored risks consistently?
Can we explain the reasoning behind the ratings?
Have we identified unacceptable risks?
Does every unacceptable risk have treatment?
Do treatment actions have owners and target dates?
Have we compared necessary controls with Annex A?
Does our SoA agree with our treatment decisions?
Have we assessed residual risk after controls became operational?
Has the correct authority accepted residual exposure?
Do risks have review dates?
Do we reassess risks after significant change?
Can we provide evidence supporting our decisions?
If several answers remain unclear, strengthen the assessment before the external audit.
Make risk assessment useful beyond certification
The strongest ISO 27001 risk assessment does much more than help an organisation prepare for an auditor.
It gives management a clear picture of what could harm the business and where security effort will have the greatest value.
Start by defining your scope and assessment method. Identify realistic scenarios, evaluate likelihood and business impact, assign owners and document current controls.
Compare each risk with your acceptance criteria. Treat exposure that remains too high. Select appropriate controls, check them against Annex A and record the resulting decisions in the Statement of Applicability.
Reassess the remaining risk after treatment and keep reviewing the register as your business changes.
UK Cyber Compliance helps organisations organise this work through an automated and AI-driven platform that connects risk assessment with the wider ISO 27001 certification journey.
A clear, evidence-based risk assessment gives your organisation more than audit readiness. It provides a practical foundation for protecting customers, information, services and the future operation of the business.

