Understanding the Controls for Risk Assessment requirements for ISO 27001?
Understanding the Controls for Risk Assessment requirements for ISO 27001? starts with an important distinction. ISO 27001 does not ask an organisation to select security controls first and then invent risks to justify them. The organisation should understand its information security risks, decide how to treat those risks and then determine which controls it needs.
ISO/IEC 27001:2022 separates these activities clearly. Clause 6.1.2 deals with information security risk assessment, while Clause 6.1.3 addresses information security risk treatment. During treatment, the organisation determines the controls needed to reduce information security risk to an acceptable level and then compares those controls with Annex A to check that it has not overlooked anything necessary.
This risk-led approach helps prevent ISO 27001 from becoming a simple compliance checklist. A control should exist because it addresses a genuine business, security, contractual or legal need.
ISO/IEC 27005:2022 provides further guidance for organisations managing information security risk. ISO describes it as a structured approach to identifying, assessing and treating information security risks in support of an ISO 27001 ISMS.
UK Cyber Compliance supports organisations through this process using an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. Its platform includes guided risk assessment, residual risk tracking, control management, real-time compliance visibility and audit-ready documentation.
Risk assessment tells you what needs protecting
Before selecting controls, the organisation needs to understand what could go wrong.
A useful risk assessment considers information, systems, services, employees, physical environments and suppliers within the ISMS scope.
For example, a business might identify a risk that an employee could respond to a phishing message and disclose their Microsoft 365 credentials. That could allow an attacker to access confidential emails, impersonate the employee or target customers.
Another business might identify a risk that its main cloud provider becomes unavailable for an extended period, preventing employees from delivering a critical service.
The risks differ, so the controls may differ.
The organisation dealing with account compromise may need stronger authentication, access management, awareness, monitoring and incident response.
The organisation concerned about service interruption may need backup arrangements, resilience, supplier assurance and tested recovery measures.
Risk assessment therefore creates the reasoning behind control selection.
What is ISO 27001 Certification?
ISO 27001 certification provides independent assurance that an organisation operates an Information Security Management System that meets ISO/IEC 27001 requirements.
ISO describes ISO/IEC 27001 as the best-known international standard for information security management systems. It enables an organisation to establish an ISMS and apply a risk management process suited to its own objectives, processes and organisational structure.
An ISMS connects business context, leadership, scope, risk management, objectives, controls, policies, people, suppliers, technology, internal audit, management review and continual improvement.
Controls form an important part of that system, but they do not operate independently.
The organisation needs to understand why each control exists.
An auditor may ask which risk a control addresses, whether the organisation actually operates it, who owns it and what evidence demonstrates that it works.
Certification therefore involves much more than ticking Annex A controls as complete.
what is iso 27001
ISO 27001 is the commonly used name for ISO/IEC 27001:2022, the international requirements standard for information security management systems.
The standard helps organisations manage risks relating to confidentiality, integrity and availability.
Confidentiality means that only authorised people and systems can access information.
Integrity means that information remains accurate, complete and trustworthy.
Availability means that authorised users can access information and services when required.
Risk assessment should consider how a security event could affect each of these areas.
A stolen account may affect confidentiality.
Unauthorised changes to customer records may affect integrity.
A ransomware attack may affect availability and integrity.
One event may affect all three.
Controls then help the organisation reduce the likelihood of those events or reduce their consequences.
ISO explains that an ISMS conforming to ISO/IEC 27001 protects confidentiality, integrity and availability through a risk management process and gives interested parties greater confidence that risks receive appropriate management.
Risk assessment and control selection are separate steps
Businesses sometimes begin ISO 27001 by opening Annex A and asking which controls they need.
That reverses the intended logic.
The organisation should first establish its risk assessment methodology, identify risks, analyse them and evaluate whether each risk falls within the agreed acceptance criteria.
Risks that exceed the organisation’s tolerance move into treatment.
During treatment, management determines the controls needed to reduce those risks.
ISO committee guidance explains that Clause 6.1.3 requires the organisation to determine its necessary controls and then compare them with Annex A to verify that no necessary control has been omitted.
That distinction makes ISO 27001 much more flexible.
A small professional firm and a cloud software provider do not need identical control environments simply because they both want the same certification.
Their controls should reflect their own risks and requirements.
Annex A is a reference set
Annex A contains a reference set of information security controls.
ISO/IEC 27002:2022 provides supporting guidance for these controls. The current standard contains 93 controls grouped across four themes: organisational, people, physical and technological.
Those 93 controls provide a valuable cross-check, but the presence of a control in Annex A does not automatically mean that every organisation must implement it exactly as written.
ISO committee guidance explains that Annex A supports the organisation’s decision-making process rather than replacing it.
This is one of the most important points to understand when completing ISO 27001.
Your organisation determines what controls it needs.
Annex A helps you check those decisions.
Necessary controls come from risk and other requirements
Risk treatment provides a major source of necessary controls, but it is not the only possible source.
A control may also become necessary because of:
A legal requirement
A regulator
A customer contract
A supplier commitment
An internal policy
An information security objective
An industry obligation
Management expectations
For example, your numerical risk rating may suggest that a particular data transfer risk remains moderate.
However, a customer contract may specifically require encryption.
Encryption then becomes necessary regardless of whether the organisation would have selected it solely from the numerical score.
The ISMS should record this reasoning.
Organisational controls support governance
The organisational theme contains controls dealing with areas such as policies, responsibilities, information security governance, suppliers, cloud services, asset management and incident management.
These controls often address risks that cannot receive effective treatment through technology alone.
Imagine that several employees use different cloud platforms without any central oversight.
Installing endpoint security will not solve the whole problem.
The organisation may need supplier governance, acceptable use requirements, information classification, access processes and cloud service management.
Risk assessment should therefore look at organisational weaknesses as well as technical vulnerabilities.
ISO/IEC 27002 provides supporting guidance that organisations can use when implementing information security controls alongside ISO 27001.
People controls address human risk
Employees and contractors can create security risk through mistakes, inappropriate access, poor awareness or deliberate misuse.
The people theme includes measures covering areas such as screening, employment responsibilities, awareness, confidentiality and responsibilities when someone changes role or leaves.
Consider a risk involving an employee who leaves the business while retaining access to cloud services.
Technology can disable the account, but the organisation also needs a process that ensures somebody tells IT when the employee leaves.
The control environment therefore connects human resources, management and technology.
A good risk assessment looks at the complete scenario rather than assuming that one technical safeguard solves every problem.
Physical controls still matter
Information security does not apply only to cloud platforms and computers.
Physical access can affect sensitive information and equipment.
A business might identify risks involving unauthorised entry to an office, theft of laptops, insecure paper records or equipment damage.
Suitable controls may involve access restrictions, secure areas, visitor management, equipment protection and secure disposal.
The right approach depends on the ISMS scope and working environment.
A remote-first company may place more emphasis on home working and portable equipment, while an organisation operating secure facilities may need much stronger physical controls.
Again, risk should determine the level of attention.
Technological controls address digital exposure
Technological controls cover many familiar cyber security areas.
They include access management, authentication, malware protection, vulnerability management, configuration, logging, monitoring, backup, network security and development-related measures.
Suppose the risk assessment identifies a significant threat from account compromise.
The organisation might determine that it needs controls addressing strong authentication, privileged access, access reviews, logging and security monitoring.
Another risk involving ransomware may lead to controls supporting malware protection, security updates, backup and recovery.
The objective is not to deploy every technical measure available.
The objective is to select enough protection to reduce risk to an acceptable level.
Start with clear risk scenarios
Good control selection depends on good risk statements.
Avoid entries such as:
“Ransomware.”
“Phishing.”
“Cloud.”
“Supplier.”
These labels provide little useful information.
Instead, describe what could happen and why it matters.
For example:
“An attacker could exploit an unpatched vulnerability on an internet-facing system and gain unauthorised access to customer information.”
That statement helps you identify relevant controls.
They may include vulnerability monitoring, security update management, secure configuration, logging and incident response.
Another scenario could say:
“A critical supplier could suffer a prolonged service failure that prevents the organisation from accessing customer records.”
That might lead to supplier assurance, continuity arrangements, backup and recovery measures.
Clear risk statements lead to clearer control decisions.
Evaluate existing controls before adding more
Before creating new controls, identify what already operates.
Many businesses already have substantial security capability through Microsoft 365, Google Workspace, endpoint management, cloud services, managed IT providers and existing policies.
The risk assessment should consider those current safeguards.
For example, a company assessing account compromise may already use multi-factor authentication, restricted administrator accounts and login monitoring.
Those measures may reduce the current exposure.
Management can then decide whether the remaining risk meets the acceptance criteria.
Avoid introducing another control simply because Annex A contains something similar.
The organisation should understand whether the current arrangements already address the underlying need.
Control effectiveness matters more than the control name
Writing a control into the Statement of Applicability does not make it effective.
A policy may state that user access receives regular review.
The real question is whether somebody performs those reviews.
Evidence could include completed access reports, management approvals and records showing removal of unnecessary permissions.
Likewise, a backup control does not become effective because a backup application exists.
The organisation should know whether backups complete successfully and whether it can restore the information.
Risk assessment therefore needs to consider both the existence and effectiveness of controls.
An ineffective control may leave the risk much higher than management assumes.
Assess residual risk after controls operate
Controls should change risk.
Residual risk represents the exposure remaining after treatment.
Suppose an organisation initially rates an account compromise risk as high.
It introduces multi-factor authentication, stronger administrator restrictions, employee awareness and monitoring.
The organisation can then reassess likelihood and impact.
If the residual risk falls within the approved acceptance criteria, the authorised risk owner may accept it.
If it remains too high, management needs further treatment or escalation.
Do not reduce the residual rating merely because an action appears in a treatment plan.
The control should actually operate before the organisation claims the benefit.
The Statement of Applicability creates traceability
The Statement of Applicability, commonly called the SoA, brings the organisation’s necessary controls together.
ISO committee guidance explains that the SoA should identify necessary information security controls, explain why they are necessary, show whether they have been implemented and justify why any Annex A controls considered unnecessary have not been selected.
The SoA should therefore align with the risk assessment and treatment plan.
If the risk assessment identifies major supplier exposure, the SoA should show relevant supplier controls.
If the organisation faces significant privileged access risk, the SoA should reflect appropriate access measures.
The documents should tell one consistent story.
You can use controls outside Annex A
ISO 27001 does not limit organisations to Annex A.
ISO committee guidance confirms that organisations can create their own controls or select measures from other recognised sources when needed.
This flexibility matters for organisations with specialist risks.
A highly specialised technology business may need measures that Annex A does not describe in enough detail.
A regulated organisation may also need controls arising from sector requirements.
When a necessary control falls outside Annex A, include it within the SoA so the control environment remains complete and traceable.
Mapping controls improves audit readiness
Control mapping helps demonstrate why controls exist.
A useful relationship looks like this:
Risk identifies the problem.
Risk treatment defines what needs to change.
Controls address the exposure.
The SoA records the control decision.
Evidence demonstrates implementation.
Residual risk shows what remains.
Management acceptance records the decision.
An auditor can then trace a risk from identification through to the final management decision.
This approach creates stronger assurance than an isolated spreadsheet containing 93 rows marked complete.
Evidence should support every important control claim
Good evidence depends on the control.
Access control evidence might include completed access reviews.
Vulnerability management evidence could include scanning results and remediation records.
Supplier controls may use supplier assessments, contracts and assurance reports.
Awareness controls may use training records.
Backup controls may use recovery test results.
Logging controls may use monitoring records.
Incident controls may use incident records and response exercises.
The evidence should demonstrate actual operation.
A document stating what the organisation intends to do provides weaker assurance than a record showing that the process happened.
Control ownership keeps the system working
Every important control needs somebody who understands and maintains it.
A control owner may differ from the risk owner.
The risk owner remains accountable for the business exposure.
The control owner manages a particular safeguard.
For example, an Operations Director may own the risk of customer service disruption, while an IT Manager owns backup and recovery controls.
Clear ownership helps prevent controls from becoming forgotten after certification.
It also gives auditors a logical person to speak with when testing effectiveness.
Controls should support business priorities
Good ISO 27001 controls protect the organisation rather than create unnecessary obstacles.
A strong access control process should protect sensitive information while still allowing employees to do their jobs.
Supplier governance should identify meaningful risk rather than create unnecessary paperwork for every minor purchase.
Security monitoring should focus attention on useful information rather than producing alerts nobody reviews.
Risk assessment helps maintain this balance.
Controls should be proportionate to the exposure and business need.
Current UK cyber statistics show why this matters
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months, representing approximately 612,000 UK businesses.
Medium businesses reported 65 per cent, while large businesses reported 69 per cent.
Despite that exposure, only 30 per cent of businesses reported carrying out a cyber security risk assessment during the previous year.
Supplier risk management also remained limited. Only 15 per cent of businesses formally reviewed risks from immediate suppliers, while 6 per cent reviewed their wider supply chain.
These figures show why control selection should start with proper risk understanding.
Organisations may operate several security measures while still overlooking important business exposure.
Who needs iso 27001 certification
ISO 27001 certification can benefit organisations that handle important information or need to demonstrate structured security governance.
Technology companies, software providers, managed service providers, professional firms, manufacturers, healthcare suppliers, financial organisations, charities and public-sector suppliers may all find value in the framework.
ISO states that organisations across different sectors can use ISO/IEC 27001 and adapt the risk management process to their own circumstances.
Customer expectations often drive certification.
Clients may want evidence that suppliers understand security risk and operate appropriate controls.
Tender requirements, contractual commitments and supply-chain assurance can also create demand.
A risk-led control process gives customers stronger assurance because it shows that the organisation has selected safeguards for clear reasons.
Controls should respond to change
The control environment should not remain frozen after certification.
New services create new risks.
Suppliers change.
Employees work differently.
Cloud platforms evolve.
Attackers discover new vulnerabilities.
Customer requirements develop.
Review risk and controls when significant changes occur.
For example, moving a critical system to a cloud provider may change access, supplier, resilience and monitoring requirements.
A new customer contract might introduce stronger security obligations.
A serious incident may reveal that an existing control did not work as expected.
The ISMS should respond to that information.
Internal audit should test control effectiveness
Internal audit provides an important check.
The auditor can select a risk and follow it through the treatment process.
They may ask why the organisation selected a particular control.
They can examine whether the SoA records that control accurately.
They may inspect evidence to confirm implementation.
The auditor can also review whether the residual rating makes sense after considering the control’s actual effectiveness.
This process helps identify gaps before the external certification audit.
Management review should see control weaknesses
Senior leadership needs visibility of controls that are not working effectively.
Management review can consider high risks, failed controls, overdue actions, audit findings, incidents and resource shortages.
Suppose vulnerability remediation repeatedly misses agreed deadlines.
Management should not simply leave the control marked as implemented.
Leaders should understand why the process struggles and decide whether it needs additional people, technology, supplier support or another approach.
That is what an active management system looks like.
ISO 27001 Certification Levels
ISO 27001 does not use formal achievement bands such as bronze, silver or gold.
An organisation either achieves ISO 27001 certification for its stated ISMS scope or it does not.
Businesses still progress through practical stages.
They establish the ISMS scope, understand interested parties, assess information security risks, determine treatment, select controls, prepare the SoA, operate those controls, gather evidence, perform internal audit and hold management review.
Security maturity can improve substantially after initial certification.
The organisation may improve monitoring, strengthen evidence, automate processes or refine its risk methodology.
That represents continual improvement rather than another formal certification band.
How the Certification Works
The organisation begins by understanding its context and defining the ISMS scope.
Management identifies interested parties and information security requirements.
The organisation establishes its risk assessment methodology and defines criteria for likelihood, impact and acceptance.
It then identifies and evaluates information security risks.
Risks above tolerance move into treatment.
Management determines the necessary controls for those risks and compares them with Annex A to ensure it has not inadvertently missed something important.
The organisation records its control decisions in the Statement of Applicability.
Control owners implement and operate the measures.
Evidence demonstrates effectiveness.
Risk owners review residual exposure and make or escalate acceptance decisions.
Internal audit tests the ISMS.
Management review examines performance, risks, resources and improvement needs.
An independent certification body then assesses whether the ISMS meets ISO/IEC 27001 requirements.
Controls remain part of an ongoing management process after certification rather than a one-off assessment exercise.
Common mistakes when choosing controls
One mistake involves starting with all 93 Annex A controls and assuming every one must apply.
Another involves excluding controls without connecting the decision to risk or another business requirement.
Some organisations record planned controls as though they already operate.
Others fail to test whether controls remain effective.
Further weaknesses include unclear ownership, missing evidence, poor links between the risk register and SoA, ignoring supplier exposure and failing to reassess residual risk.
Generic controls copied from another organisation can create another problem.
Your organisation should be able to explain why each necessary control matters within your own ISMS.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can obtain ISO 27001 support from information security consultancies, compliance specialists, managed service providers, internal audit professionals and platform-led services.
UK Cyber Compliance provides ISO 27001 support through an automated and AI-driven platform.
Its current platform offers guided risk assessment, residual risk tracking, control management, AI-powered policy generation, live compliance tracking and audit-ready documentation.
A capable provider should help the organisation understand the relationship between risk and controls rather than simply marking Annex A items as complete.
Useful support can include developing the risk methodology, identifying meaningful scenarios, determining treatment, mapping necessary controls to Annex A, preparing the SoA and organising evidence.
Management should still retain ownership of risk and control decisions.
How UK Cyber Compliance helps connect risk with controls
Managing the process through several spreadsheets can make traceability difficult.
A risk may appear in one file.
The treatment plan may sit somewhere else.
The SoA may live in another document.
Evidence may be spread throughout shared drives and email.
UK Cyber Compliance brings these relationships into one environment.
Its platform provides intelligent risk assessment covering asset risks and residual risk, alongside control management and real-time compliance tracking. It can also generate audit-ready evidence packs, risk reports and Statement of Applicability documentation.
This helps organisations see the chain from identified risk through treatment, control selection, evidence and residual acceptance.
Automation can make the administrative work easier, while management remains responsible for the decisions.
A practical control selection checklist
Before your external ISO 27001 audit, ask whether you can answer these questions clearly:
- Have we defined our risk assessment methodology and acceptance criteria?
- Have we identified realistic information security risks across the ISMS scope?
- Have we considered confidentiality, integrity and availability?
- Have we recorded the controls that already operate?
- Can we demonstrate that those controls work?
- Have we identified which risks exceed our acceptance criteria?
- Have we determined the controls needed to treat those risks?
- Have we considered legal, contractual and customer requirements?
- Have we compared our necessary controls with Annex A?
- Have we checked that no necessary control has been overlooked?
- Does our SoA contain every necessary control, including controls outside Annex A where relevant?
- Can we justify control inclusion and Annex A exclusions?
- Does every important control have an owner?
- Can we provide current evidence of implementation?
- Have we reassessed residual risk after treatment?
- Has the appropriate risk owner approved remaining exposure?
- Do internal audit and management review test whether controls remain effective?
- Do we reassess controls when systems, suppliers or risks change?
Clear answers indicate that the organisation has moved beyond a checklist approach and built a genuinely risk-based ISMS.
Make controls follow risk, not the other way around
Understanding the Controls for Risk Assessment requirements for ISO 27001? means understanding the relationship between assessment, treatment and controls.
Risk assessment identifies the exposure.
Risk evaluation determines whether management can tolerate it.
Risk treatment decides what needs to change.
Necessary controls reduce the exposure.
Annex A provides a reference set that helps the organisation check its choices.
The Statement of Applicability records those decisions.
Evidence demonstrates that the controls operate.
Residual risk shows what remains.
Management then decides whether that remaining risk can be accepted.
This sequence keeps the ISMS focused on real business security rather than paperwork.
ISO/IEC 27002:2022 provides guidance for implementing information security controls, while ISO/IEC 27005:2022 supports the wider information security risk management process.
UK Cyber Compliance helps organisations connect these activities through an automated and AI-driven platform that combines risk assessment, controls, residual risk, policies, evidence and audit preparation in one compliance environment.
When an organisation can clearly explain why each control exists, which risk it addresses, how it operates and whether it has reduced the remaining exposure, it has created something much more valuable than an Annex A checklist. It has created a practical, defensible and risk-led information security management system.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

