Understanding the Risk Assessment requirements for ISO 27001?
Understanding the Risk Assessment requirements for ISO 27001 starts with one simple principle: your organisation needs a consistent way to identify what could threaten its information, understand the potential consequences and decide what action to take.
Risk assessment sits at the heart of an Information Security Management System, commonly called an ISMS. ISO/IEC 27001:2022 requires organisations to establish an information security risk assessment process, define suitable risk criteria, identify information security risks, analyse those risks and evaluate the results against agreed criteria.
The process must produce consistent, valid and comparable results. That requirement matters because risk management becomes unreliable when one department describes a problem as serious while another treats an equivalent problem as insignificant.
ISO/IEC 27001 also requires organisations to perform information security risk assessments at planned intervals and when significant changes occur or are proposed. ISO committee guidance specifically links Clause 8.2 with the criteria established under Clause 6.1.2.
ISO/IEC 27005:2022 provides additional guidance for organisations managing information security risks. ISO describes it as supporting ISO 27001 through a structured approach to identifying, assessing and treating information security risk.
UK Cyber Compliance supports organisations through this process using an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. Its platform provides guided risk assessment, residual risk tracking, control management, real-time progress visibility and audit-ready documentation.
Why risk assessment matters to ISO 27001
ISO 27001 does not ask an organisation to implement security controls without first considering why it needs them.
A small professional consultancy faces different risks from a cloud software provider. A manufacturer may depend on production systems and suppliers, while a managed service provider may hold privileged access to customer environments.
Risk assessment allows each organisation to focus on the security issues that actually matter.
A good assessment helps management answer questions such as:
What information do we need to protect?
Which services are critical?
What could cause loss, disclosure or unauthorised change?
How realistic is each scenario?
What would happen to customers or operations?
Which controls already reduce the exposure?
Does the remaining risk meet our acceptance criteria?
Do we need additional treatment?
Who owns the decision?
When should we review it again?
These questions move cyber security away from guesswork and towards structured management.
What is ISO 27001 Certification?
ISO 27001 certification provides independent assurance that an organisation operates an Information Security Management System that meets the requirements of ISO/IEC 27001.
An ISMS brings information security into the wider management of the organisation. It connects business context, leadership, scope, risk assessment, objectives, policies, controls, people, suppliers, technology, internal audit, management review and continual improvement.
ISO describes ISO/IEC 27001 as the best-known international standard for information security management systems. It helps organisations establish, implement, maintain and continually improve their approach to protecting information.
Certification does not promise that an organisation will never experience a cyber incident.
Instead, it demonstrates that the business has a structured approach to recognising information security risks, making treatment decisions and reviewing whether controls remain effective.
Risk assessment gives the ISMS much of its direction.
Without it, an organisation may implement controls because somebody recommended them rather than because they address a documented business need.
what is iso 27001
ISO 27001 is the commonly used name for ISO/IEC 27001:2022, the international requirements standard for information security management systems.
The standard focuses strongly on confidentiality, integrity and availability.
Confidentiality means that only authorised people and systems can access information.
Integrity means that information remains accurate, complete and trustworthy.
Availability means that authorised users can access information and services when needed.
Risk assessment should consider how security events could affect all three.
For example, stolen administrator credentials could threaten confidentiality and integrity.
A ransomware incident could affect availability and integrity.
An accidental email containing sensitive information could affect confidentiality.
A cloud outage could affect availability.
The organisation should look beyond technical failure and consider the real business consequences.
Start with a defined ISMS scope
A risk assessment cannot work properly until the organisation understands what sits within the ISMS.
The scope defines the boundary.
It may cover the whole organisation or a clearly defined service, legal entity, business operation or location.
Within that boundary, identify the people, information, processes, systems, cloud services, suppliers and physical environments that support the organisation.
For example, a customer-facing platform may depend on:
Developers
Support staff
Cloud hosting
Identity services
Backup services
Third-party software
Customer information
Administrator accounts
Monitoring
A risk assessment that only considers the web application while ignoring these dependencies will provide an incomplete picture.
Establish the risk assessment method first
ISO 27001 expects a repeatable method.
Before assessing individual risks, document how the organisation will carry out the assessment.
The methodology should explain:
How risks are identified
How likelihood receives assessment
How impact receives assessment
How the organisation determines the overall risk level
Which risk criteria apply
How acceptance works
Who owns risks
Who can approve acceptance
How treatment gets prioritised
When reassessment takes place
How records remain current
The method does not need unnecessary complexity.
A clear method that employees understand provides more value than a complicated scoring model that only one person can explain.
Define risk criteria clearly
Risk criteria tell staff how to assess and compare information security exposure.
ISO 27001 requires organisations to establish criteria for performing information security risk assessments and criteria for risk acceptance.
These two ideas work together but answer different questions.
Assessment criteria explain how you measure a risk.
Acceptance criteria explain whether the resulting level remains tolerable.
For example, the organisation may use likelihood and impact scores to determine a risk rating.
It may then decide that lower risks can remain under normal monitoring, while high risks need treatment and management approval.
The organisation should approve these rules before teams start making individual risk decisions.
Decide how likelihood works
Likelihood represents how realistically a risk event could occur.
Avoid using labels without definitions.
Terms such as unlikely, possible and likely only help when employees know what each one means.
Factors that may influence likelihood include:
Previous incidents
Known vulnerabilities
Internet exposure
Employee behaviour
Threat activity
Ease of exploitation
Supplier dependency
Strength of current controls
Frequency of the relevant activity
Number of users with access
For example, an administrator account with weak authentication and internet exposure may create a greater likelihood of compromise than an account protected by strong authentication, restricted access and active monitoring.
Evidence should support the judgement where practical.
Assess impact through business consequences
Impact represents the harm the organisation could suffer if the event happened.
This assessment should move beyond technical inconvenience.
Consider effects on:
Customers
Critical services
Confidential information
Personal information
Contracts
Legal responsibilities
Revenue
Reputation
Business operations
Staff productivity
Supplier relationships
Management attention
Service availability
Information accuracy
The same technical event can produce very different business consequences.
A one-hour outage affecting an internal convenience tool may cause limited disruption.
A one-hour outage affecting a customer platform with strict service commitments may create significant harm.
Process owners often provide valuable input here because they understand the operational consequences better than the security team alone.
Use consistent impact criteria
Define what each impact level means.
For example, a lower impact may represent a short disruption with no customer effect and straightforward recovery.
A higher impact might involve prolonged service disruption, sensitive information exposure, major contractual consequences or substantial customer harm.
Do not leave these definitions entirely open to personal interpretation.
Consistency helps the organisation compare risks across different departments and services.
It also helps auditors understand why management reached a particular rating.
Identify realistic risk scenarios
A risk register becomes far more useful when entries describe complete scenarios rather than isolated words.
“Phishing” is not a complete risk statement.
A stronger entry might say:
“An employee may respond to a convincing phishing message and disclose their credentials, allowing an unauthorised person to access business email and customer correspondence.”
This identifies:
The cause
The event
The affected service
The potential consequence
Another example could say:
“A prolonged outage at the organisation’s primary cloud provider may make the customer platform unavailable and prevent the business from meeting service commitments.”
Clear scenarios improve scoring because people understand exactly what they are assessing.
Consider threats beyond cyber criminals
Risk assessment should cover deliberate attacks, but it should not stop there.
Information security problems can result from:
Human error
Equipment loss
Incorrect permissions
Supplier failure
Software faults
Cloud outages
Unsupported applications
Accidental disclosure
Hardware failure
Poor change management
Natural events
Power disruption
Internal misuse
Inadequate backup
Weak physical protection
Loss of key personnel
Misconfiguration
The right scenarios depend on your business.
Avoid copying a generic risk list and assuming that every entry applies.
Understand which information and services matter
Risk assessment works best when the organisation understands what it values.
Important information may include:
Customer records
Employee information
Financial data
Contracts
Source code
Authentication information
Intellectual property
Security records
Supplier information
Business plans
Management information
Important services may include email, customer platforms, cloud storage, finance systems, identity services and operational applications.
You do not need to create unnecessary administration, but you do need enough understanding to identify what a security event could damage.
Consider confidentiality, integrity and availability separately
A single asset may face different consequences depending on what goes wrong.
Take a customer database.
Loss of confidentiality could expose customer records.
Loss of integrity could allow unauthorised changes.
Loss of availability could stop employees accessing customer information.
These outcomes may have different impacts and may require different controls.
Separating these considerations can make risk identification much clearer.
It also supports better control selection later.
Assign a risk owner
Every meaningful risk needs an accountable owner.
The owner should understand the business consequences and have enough authority to make or escalate decisions.
The technical employee who manages a system does not always make the best risk owner.
A finance platform may have technical support from IT, but a senior finance leader may better understand what disruption or incorrect financial information would mean for the organisation.
Risk owners should:
Review the scenario
Confirm the business impact
Understand existing controls
Review treatment proposals
Monitor actions
Assess the remaining exposure
Approve or escalate acceptance
Review the risk after significant change
Clear ownership prevents risks from becoming anonymous entries that nobody actively manages.
Record existing controls accurately
Before determining the current risk level, identify controls that already operate.
A phishing scenario might have controls such as:
Multi-factor authentication
Email filtering
Staff awareness
Restricted administrator permissions
Security monitoring
Incident reporting
Account access reviews
Only give credit for controls that genuinely operate.
A written plan to enable multi-factor authentication does not reduce risk in the same way as an active control protecting all relevant accounts.
The same principle applies throughout the risk assessment.
Planned work belongs in risk treatment, not in the list of existing controls.
Calculate or categorise the current risk
Once you understand likelihood, impact and existing controls, use the approved methodology to determine the current risk level.
Some organisations multiply numerical likelihood and impact values.
Others use a defined matrix.
Either method can work.
ISO 27001 does not require one specific calculation.
The important requirement involves producing consistent, valid and comparable results.
After calculating the rating, check whether it makes sense.
Numbers should support management judgement, not replace it.
A low-probability event with extreme consequences may still deserve attention.
Legal or contractual requirements can also require treatment even when a general score appears acceptable.
Record why you chose the rating
A number by itself provides limited insight.
Include enough reasoning for another person to understand the decision.
For example:
“Account compromise remains plausible because employees receive regular external email and targeted phishing remains common. Multi-factor authentication reduces the likelihood of successful access, but the potential impact remains significant because email contains customer and commercial information.”
This explanation gives the score context.
It also helps future reviews because managers can see whether the assumptions still remain valid.
Compare the result with risk acceptance criteria
The next step asks whether management can tolerate the risk.
The organisation should already have established acceptance criteria.
These rules may say that:
Lower risks can receive acceptance from the risk owner.
Moderate risks require additional review.
High risks require treatment.
Very serious risks need senior management escalation.
The exact approach should reflect the organisation’s business context.
Some requirements should override a normal numerical threshold.
For example, management may decide that it will not knowingly accept a situation that breaches a legal obligation or critical customer commitment.
Decide how to treat unacceptable risks
When a risk exceeds the agreed criteria, the organisation needs a treatment decision.
Common options include reducing the risk, avoiding the activity, sharing part of the exposure or retaining the remaining risk after informed approval.
Reduce
Apply or improve controls.
For example, strengthen authentication, improve backup arrangements or restrict administrator access.
Avoid
Stop the activity that creates the exposure.
For example, the organisation may stop retaining information that it no longer needs.
Share
Move part of the exposure through agreements, specialist services or other arrangements while recognising that responsibility may still remain.
Retain
Accept the remaining exposure when it meets the agreed criteria and the right person approves the decision.
Risk treatment should follow business reasoning rather than habit.
Build a practical risk treatment plan
The treatment plan should turn decisions into action.
Each activity should identify:
What needs to happen
Who owns the action
When it needs completion
Which risk it addresses
Which control it supports
What evidence will demonstrate completion
What improvement the organisation expects
Avoid vague actions such as “improve cyber security.”
A stronger action could say:
“Enable multi-factor authentication for every user of the finance cloud service and verify coverage through the administrator report.”
Clear actions make progress easier to monitor.
Compare selected controls with Annex A
After determining the controls needed for risk treatment, compare them with Annex A.
ISO/IEC 27001:2022 contains 93 Annex A controls organised across organisational, people, physical and technological areas.
The purpose is not to apply every control automatically.
Risk treatment determines which controls the organisation needs.
Annex A then provides a reference set that helps management check whether it overlooked something relevant.
An organisation can also use controls outside Annex A when its circumstances require them.
Connect the assessment with the Statement of Applicability
The Statement of Applicability, commonly shortened to SoA, records the organisation’s control decisions.
It should align with the risk assessment and treatment plan.
If the risk register identifies serious supplier exposure, the SoA should reflect relevant supplier controls.
If account compromise represents a major risk, the SoA should show suitable access and authentication measures.
The risk register, treatment plan and SoA should tell one consistent story.
Contradictions often create audit questions.
Assess residual risk after treatment
Controls rarely remove all exposure.
Residual risk represents what remains after the organisation applies treatment.
Reassess likelihood and impact once the planned controls genuinely operate.
Do not reduce a rating simply because an action appears on a project plan.
Suppose the treatment involves implementing stronger authentication.
The risk reduction becomes credible when the organisation has implemented the control, verified coverage and gathered evidence.
The risk owner can then compare the residual level against the acceptance criteria.
If the risk still exceeds tolerance, the organisation needs further treatment or escalation.
Document acceptance clearly
When the organisation accepts residual risk, record the decision.
Useful information includes:
Risk reference
Residual rating
Reason for acceptance
Risk owner
Approver
Approval date
Conditions
Review date
Temporary safeguards where relevant
Acceptance represents an informed management decision.
It should not mean that somebody ignored the issue.
Accepted risks still require monitoring and review.
Perform risk assessments at planned intervals
ISO 27001 requires organisations to perform information security risk assessments at planned intervals.
The organisation decides the frequency according to its circumstances.
A yearly formal review may suit some environments, while rapidly changing organisations may need more frequent assessment for certain services.
The schedule should support effective management rather than exist only for certification.
ISO committee guidance also emphasises reassessment when significant changes occur or are proposed.
Reassess after significant change
Do not wait for the next scheduled review when something important changes.
Useful triggers include:
Launching a new service
Changing a major supplier
Moving to another cloud platform
Acquiring a company
Opening a new location
Changing remote working arrangements
Introducing important software
Experiencing a security incident
Discovering a serious vulnerability
Changing customer requirements
Changing legal obligations
Receiving a major audit finding
A risk assessment should reflect the organisation that exists today rather than the organisation that existed when certification work first started.
Security incidents provide valuable risk information
An incident gives the organisation evidence about whether previous assumptions were accurate.
After a significant event, ask:
Did our register already identify this scenario?
Was the likelihood appropriate?
Did we understand the impact?
Did our controls work?
Did employees follow the process?
Do we need additional controls?
Has the residual risk changed?
Should we change the assessment criteria?
This feedback helps the ISMS improve.
Current UK statistics show why assessment matters
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 found that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months. That equates to approximately 612,000 UK businesses.
Reported exposure increased among larger organisations. The survey found breaches or attacks among 65 per cent of medium businesses and 69 per cent of large businesses.
Despite that exposure, only 30 per cent of businesses reported conducting a cyber security risk assessment during the previous year. Among small businesses, the proportion fell from 48 per cent in 2024 to 2025 to 41 per cent in 2025 to 2026.
The survey also found that only 15 per cent of businesses formally reviewed risks presented by immediate suppliers, while only 6 per cent reviewed the wider supply chain.
These figures demonstrate why structured risk assessment remains valuable.
Organisations face regular threats, yet many still lack a formal process for understanding where their most important exposure sits.
Include suppliers in the assessment
Modern organisations depend heavily on third parties.
Cloud providers, payroll companies, managed IT providers, software vendors and communications suppliers can all affect information security.
Ask:
What information does the supplier access?
What happens if the service becomes unavailable?
Could supplier compromise affect our customers?
Does the supplier hold privileged access?
Can we obtain suitable security assurance?
How quickly must the supplier report incidents?
What happens when the relationship ends?
Supplier risk should appear in the assessment when the relationship could materially affect the ISMS.
A contract does not remove the underlying risk.
Use evidence rather than assumptions
Evidence makes risk assessment stronger.
Useful sources can include:
Incident records
Access reviews
Security monitoring
Vulnerability reports
Supplier assessments
Audit findings
Backup testing
Customer requirements
Contract obligations
Control test results
Threat information
For example, a manager might believe that administrator access presents low risk.
An access review showing unnecessary administrator accounts may challenge that belief.
Risk assessment should respond to what the evidence shows.
Internal audit should test the process
Internal audit provides an opportunity to check whether the organisation follows its own methodology.
An internal auditor may select several risks and ask:
Does each scenario fall within the ISMS scope?
Did staff use the correct likelihood criteria?
Does the impact rating make sense?
Does each risk have an owner?
Do the existing controls really operate?
Does evidence support the rating?
Did the organisation treat risks above its acceptance threshold?
Does the residual rating reflect completed controls?
Does the SoA agree with the treatment decisions?
This testing can reveal inconsistency before the external certification assessment.
Management review needs meaningful risk information
Senior leadership should have visibility of important information security exposure.
Management review can examine:
Highest-rated risks
Recently changed risks
Accepted high exposure
Overdue treatment actions
Control failures
Supplier concerns
Security incidents
Resource shortages
Emerging threats
Management does not need to discuss every minor entry in detail.
It should understand the risks that could materially affect customers, business objectives and information security.
Who needs iso 27001 certification
ISO 27001 certification can benefit organisations that manage valuable information or need to demonstrate structured security governance.
Technology providers, software companies, managed service providers, professional firms, manufacturers, healthcare suppliers, financial organisations, charities and public-sector suppliers may all gain value.
Customers often drive the requirement.
A larger organisation may ask a supplier to demonstrate that it manages information security through a recognised framework.
Tender requirements, contracts and supply-chain assurance can also create demand.
Risk assessment matters particularly in these relationships because certification should show that the organisation understands its own exposure instead of merely operating a collection of security tools.
Small businesses can keep risk assessment practical
A smaller organisation does not need hundreds of risk entries.
Focus on what matters.
Start with:
Critical customer services
Important information
Cloud applications
Employee access
Key suppliers
Backups
Remote working
Business continuity
Legal and contractual responsibilities
Write realistic scenarios.
Use a straightforward likelihood and impact method.
Assign clear owners.
Keep the register current.
A smaller, well-managed register gives management more value than a huge collection of generic entries that nobody reviews.
ISO 27001 Certification Levels
ISO 27001 does not provide official certification bands such as bronze, silver or gold.
An organisation either achieves certification for its stated ISMS scope or it does not.
Businesses still move through practical stages while preparing for certification.
They define scope, identify interested parties, establish the risk methodology, perform risk assessment, determine treatment, select controls, prepare the Statement of Applicability, operate the ISMS, complete internal audit and hold management review.
The organisation can improve its security maturity after certification through better monitoring, stronger evidence, improved risk analysis and more effective governance.
That progress represents continual improvement rather than another official certification band.
How the Certification Works
The organisation begins by understanding its context and defining the ISMS scope.
It identifies interested parties and relevant information security requirements.
Management establishes the risk assessment method, including likelihood, impact and acceptance criteria.
The organisation identifies risks and assigns owners.
It assesses current exposure and compares each result with the agreed criteria.
Risks that exceed tolerance move into treatment.
The organisation determines necessary controls and compares them against Annex A.
It records control decisions in the Statement of Applicability.
Control owners implement the chosen measures and gather evidence.
Risk owners reassess residual exposure once treatment operates.
The organisation completes internal audit and management review.
An independent certification body then assesses whether the ISMS meets ISO/IEC 27001 requirements.
Risk assessment remains active after certification through scheduled reviews and reassessment when significant changes occur.
Common mistakes to avoid
One common mistake involves copying risks from a generic template without adapting them to the organisation.
Another involves assessing only technical infrastructure and overlooking people, suppliers and business processes.
Some organisations use scoring scales without defining what the numbers mean.
Others have no clear acceptance criteria.
Additional weaknesses include:
Missing risk owners
Planned controls counted as operational
No evidence behind ratings
Residual risks reduced too early
Supplier exposure ignored
No review dates
No connection with the SoA
Legal requirements overlooked
Old risks left unchanged for years
Too many low-value entries
A good methodology should help management make decisions, not create unnecessary administration.
Which UK-based firms offer ISO 27001 consultancy services?
UK organisations can obtain ISO 27001 assistance from information security consultancies, compliance specialists, managed service providers, internal audit professionals and platform-led providers.
UK Cyber Compliance provides ISO 27001 support through an automated and AI-driven platform.
Its current platform includes guided risk assessment, residual risk tracking, real-time compliance visibility, control management, AI-powered policy generation and audit-ready evidence reporting.
A capable provider should help the organisation understand its own risks rather than simply fill a register with generic entries.
Useful support may include:
Defining the methodology
Setting likelihood and impact criteria
Creating acceptance criteria
Identifying meaningful risk scenarios
Assigning owners
Planning treatment
Connecting controls with Annex A
Building the Statement of Applicability
Preparing evidence
Supporting internal audit readiness
The organisation should keep ownership of its decisions.
Consultants and technology can support the process, but management still decides what risk it can accept.
How UK Cyber Compliance can simplify risk assessment
Traditional risk registers often spread information across spreadsheets, documents and email messages.
That can make it difficult to see the relationship between risk, controls, actions and evidence.
UK Cyber Compliance brings these activities into a central compliance environment.
The platform describes an intelligent risk assessment capability that helps organisations identify, evaluate and manage information security risks across assets, including residual risk tracking.
It also provides real-time progress tracking and can generate audit-ready evidence packs, risk reports and Statement of Applicability documents.
This can help organisations see:
Which risks need treatment
Who owns the action
Which controls support the treatment
Whether residual exposure remains acceptable
Where evidence exists
Which areas need management attention
Automation can reduce repetitive administration, but human judgement remains essential.
A practical ISO 27001 risk assessment checklist
Before your certification assessment, ask:
Have we clearly defined the ISMS scope?
Have we documented our risk assessment methodology?
Do our likelihood criteria have clear definitions?
Do our impact criteria reflect real business consequences?
Have we established risk acceptance criteria?
Do we identify realistic risk scenarios?
Do we consider confidentiality, integrity and availability?
Have we included people, suppliers and business processes?
Does every meaningful risk have an owner?
Have we recorded existing controls accurately?
Can we explain why each important risk received its rating?
Do we compare results with approved acceptance criteria?
Do unacceptable risks have treatment plans?
Do treatment actions have owners and dates?
Have we compared selected controls against Annex A?
Does the Statement of Applicability agree with our decisions?
Have we reassessed residual risk after controls started operating?
Has the right authority approved accepted exposure?
Do risks have appropriate review dates?
Do we reassess after significant change?
Can we provide evidence supporting important decisions?
If several answers remain unclear, improve the process before the external audit.
Make risk assessment a working management process
Understanding the Risk Assessment requirements for ISO 27001 means recognising that risk management is not a one-time spreadsheet exercise.
The organisation needs a defined method, clear criteria and meaningful risk scenarios.
It needs accountable owners.
It needs reliable information about existing controls.
It needs treatment for risks that exceed tolerance.
It needs evidence that planned controls actually operate.
It needs residual risk decisions that management can explain.
It also needs regular reassessment as systems, suppliers, customers and threats change.
ISO/IEC 27005 provides additional structured guidance for organisations that want to strengthen information security risk management alongside ISO 27001.
UK Cyber Compliance supports this work through an automated and AI-driven platform that connects risk assessment, residual risk, controls, policies, progress monitoring and audit documentation.
When risk assessment works properly, it gives management something more valuable than an audit record. It gives the organisation a practical way to decide where security effort matters most, which exposure requires action and how to protect the information and services that support the business.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

