What is the Risk Assessment for in ISO 27001?
Risk assessment in ISO 27001 is used to identify, understand, evaluate, and manage information security risks that could affect an organisation. It helps a business decide what could go wrong, how serious the impact could be, how likely it is to happen, and what action should be taken to reduce the risk to an acceptable level.
For any organisation working towards ISO 27001 certification, risk assessment is one of the most important parts of the Information Security Management System, often called the ISMS. It is the process that turns information security from a broad concern into a clear set of business decisions. Instead of guessing which controls are needed, the organisation uses risk assessment to decide where effort, attention, and resources should go.
UK Cyber Compliance provides ISO 27001 certification support through an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. The platform helps organisations manage risks, controls, policies, evidence, actions, owners, and audit readiness in one place.
The purpose of risk assessment is not to create paperwork for the sake of it. It is to protect information, support business resilience, meet customer expectations, satisfy legal and regulatory duties, and give senior leaders a clear view of security priorities.
Why risk assessment matters in ISO 27001
ISO 27001 is a risk-based standard. That means the organisation is expected to understand its own risks and apply controls that are suitable for its business. The standard does not expect every business to copy the same control set without thought. It expects decisions to be based on context, scope, threats, vulnerabilities, business impact, legal duties, customer needs, and risk appetite.
Risk assessment matters because no organisation has unlimited time or resources. A business must decide which risks need urgent action, which risks can be monitored, which risks can be accepted, and which controls will provide the most value.
Without risk assessment, security decisions can become reactive. A business may buy tools it does not need, miss important weaknesses, over-focus on low-risk areas, or fail to protect the information that matters most.
A good ISO 27001 risk assessment helps prevent that. It creates a clear, evidence-based route from business risk to security action.
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 reported that 43 percent of UK businesses identified a cyber breach or attack in the previous 12 months. This shows why structured risk management remains important for UK organisations. Cyber risk is not limited to large companies. Small and medium organisations also need a practical way to understand and manage threats.
What is ISO 27001 Certification?
ISO 27001 certification is formal recognition that an organisation has implemented an ISMS that meets the requirements of ISO 27001. Certification is awarded after an independent audit confirms that the organisation has established, implemented, maintained, reviewed, and improved its ISMS.
An ISMS is a structured system for managing information security. It includes scope, leadership, policies, risk assessment, risk treatment, information security objectives, legal and regulatory requirements, supplier management, incident response, internal audit, management review, corrective action, and continual improvement.
Risk assessment sits at the heart of this system. It helps the organisation decide which risks affect confidentiality, integrity, and availability. Confidentiality means information is only available to authorised people. Integrity means information remains accurate and reliable. Availability means information and systems can be accessed when needed.
Certification does not prove that a business has removed every risk. That would not be realistic. What it does prove is that the business has a structured and independently assessed process for identifying, evaluating, treating, and reviewing information security risk.
For customers and partners, this can be valuable. It shows that the organisation is not relying on informal judgement alone. It has a recognised management system and a clear approach to risk.
what is iso 27001
ISO 27001 is an international standard for information security management. It sets out the requirements for creating, operating, maintaining, and continually improving an ISMS.
The standard helps organisations protect information by using a structured, risk-based approach. It covers business context, interested parties, scope, leadership, planning, support, operation, performance evaluation, and improvement.
ISO 27001 is not only about technology. It also covers people, processes, suppliers, governance, contracts, legal duties, physical security, incident response, business continuity, awareness, and leadership involvement.
Risk assessment is what connects these areas together. It helps the business understand which threats matter, which assets need protection, which controls are needed, and which areas require management attention.
For example, a company that stores customer data in cloud systems may identify risks around unauthorised access, supplier failure, misconfiguration, phishing, weak authentication, and data loss. A different organisation may identify risks around physical records, staff error, legacy systems, or service downtime.
ISO 27001 gives both organisations a framework, but risk assessment helps each business make it relevant to its own situation.
What risk assessment is really for
Risk assessment is for making better security decisions. It helps the organisation move from uncertainty to clarity.
A strong risk assessment helps answer several practical questions:
What information do we need to protect?
Which systems, suppliers, and processes support that information?
What could go wrong?
How likely is it to happen?
How serious would the impact be?
Which risks are acceptable?
Which risks need treatment?
Who owns each risk?
Which controls should be selected?
What evidence will show that risks are being managed?
This makes risk assessment useful for business leaders, not just technical teams. It gives management a clearer view of where the organisation is exposed and what should be done about it.
Risk assessment also supports audit readiness. An ISO 27001 auditor will expect to see that risks have been identified, assessed, treated, reviewed, and linked to suitable controls.
The link between scope and risk assessment
Before a useful risk assessment can take place, the organisation needs a clear ISMS scope. The scope defines what the ISMS covers. This may be the whole organisation, a particular service, a department, a software platform, a location, or a defined business function.
The risk assessment must match the scope. If the scope covers a customer-facing cloud platform, the risk assessment should consider the people, systems, suppliers, data, processes, and legal duties linked to that platform. If the scope covers the whole organisation, the risk assessment should be wider.
A common problem is creating a risk assessment that does not align with scope. If important systems or suppliers are missing, the assessment may be challenged during audit.
A strong scope gives risk assessment a clear boundary. It helps the business decide what must be assessed and prevents the process from becoming too vague or too broad.
UK Cyber Compliance helps organisations manage this by linking scope, risks, controls, and evidence through a more structured platform.
Who needs iso 27001 certification
ISO 27001 certification is useful for organisations that need to protect information and demonstrate that security is managed properly. It is especially relevant for businesses that handle client data, personal data, confidential records, financial information, intellectual property, supplier information, cloud services, regulated records, or sensitive operational information.
Technology providers, managed service providers, SaaS companies, cyber security firms, consultants, legal firms, finance-related organisations, healthcare suppliers, recruitment agencies, accountants, public sector suppliers, and professional services firms often benefit from certification.
Many organisations pursue ISO 27001 because customers request it during supplier due diligence. Others need it for tenders, contract requirements, board assurance, investor confidence, insurance discussions, or stronger internal governance.
Risk assessment is especially valuable for these organisations because customers want evidence that information security risk is understood and managed. Certification helps show that risks are assessed through a recognised framework rather than handled through informal assumptions.
Small and medium organisations can also gain value from ISO 27001. A smaller business may not have the same internal security resources as a large organisation, but a structured risk assessment helps focus effort where it matters most.
What should be included in an ISO 27001 risk assessment?
An ISO 27001 risk assessment should include the assets, threats, vulnerabilities, likelihood, impact, risk level, risk owner, existing controls, treatment decision, treatment actions, and review date.
Assets can include information, systems, applications, cloud platforms, devices, suppliers, services, business processes, physical locations, and people. The organisation should understand what supports the scoped service or business function.
Threats are events or actions that could cause harm. Examples include phishing, ransomware, unauthorised access, supplier failure, staff error, data loss, service outage, physical theft, misconfiguration, malware, or insider misuse.
Vulnerabilities are weaknesses that could be exploited. Examples include weak access controls, missing updates, poor supplier review, lack of staff awareness, poor backup testing, unclear incident reporting, or weak monitoring.
Likelihood considers how probable the risk is. Impact considers how serious the damage would be. The risk level combines these factors so the organisation can decide what needs action.
A strong risk assessment also records ownership. Someone must be responsible for reviewing and managing each risk.
Risk assessment criteria
ISO 27001 expects the organisation to define how risks will be assessed. This means the business should have clear criteria for likelihood, impact, risk levels, and risk acceptance.
Without criteria, risk scoring can become inconsistent. One person may rate a risk as high while another rates a similar risk as low. Clear criteria help people assess risks more consistently.
Impact criteria should reflect the business. They may include customer impact, legal exposure, reputational harm, financial loss, operational disruption, service downtime, data sensitivity, contractual failure, and harm to confidentiality, integrity, or availability.
Likelihood criteria should also be clear. They may consider threat activity, past incidents, known weaknesses, control maturity, exposure to the internet, supplier dependency, user behaviour, and sector risk.
The criteria should be approved and used across the ISMS. They should also be reviewed when the business changes.
Risk acceptance criteria
Risk acceptance criteria define when a risk is acceptable and when it needs further treatment. This is one of the most important outputs of the risk process.
A business may decide that low risks can be accepted by the risk owner, medium risks require a treatment plan, and high risks require senior management approval. Some risks may be too serious to accept without executive decision.
Risk acceptance does not mean ignoring a risk. It means the risk has been assessed, understood, approved, and recorded.
A risk may be accepted because it is low, because existing controls are enough, or because further treatment would not be proportionate. However, accepted risks should still have owners and review dates.
This is important for audit. An auditor may ask why a risk was accepted and who approved the decision. The business should be able to explain clearly.
Risk treatment
After risks are assessed, the organisation decides how to treat them. Risk treatment is the process of deciding what will be done about each risk.
There are usually four broad choices.
The business can reduce the risk by applying controls. This may include access control, training, monitoring, supplier review, encryption, backup, secure configuration, vulnerability management, or incident response.
The business can avoid the risk by stopping the activity that creates it. For example, the organisation may decide not to use a particular supplier or not to process certain information.
The business can transfer part of the risk through contracts, outsourcing, or insurance. This does not remove responsibility completely, but it may reduce exposure.
The business can accept the risk if it falls within the agreed risk acceptance criteria.
The treatment decision should be recorded. If action is needed, the risk treatment plan should show what will be done, who owns it, and when it should be completed.
The risk treatment plan
The risk treatment plan turns risk decisions into practical action. It should show how risks will be managed and who is responsible.
A good risk treatment plan should include the risk, the treatment decision, the selected controls, the action owner, target date, progress status, and any evidence needed to confirm the action is complete.
The plan helps the organisation avoid leaving risks as static records. It creates movement and accountability.
For example, if the risk assessment identifies weak access review as a risk, the treatment plan may include creating a formal access review process, assigning an owner, setting review frequency, recording evidence, and reporting results to management.
UK Cyber Compliance can help track this activity so risk treatment does not become scattered across emails, spreadsheets, and individual notes.
The Statement of Applicability
The Statement of Applicability, often called the SoA, is closely linked to risk assessment. It records which Annex A controls apply, why they apply, whether they are implemented, and why any controls have been excluded.
Risk assessment helps explain why controls are selected. If the business identifies a risk around unauthorised access to client data, access control and authentication controls may be selected. If the business identifies supplier risk, supplier relationship controls may be selected. If the business identifies service disruption risk, business continuity controls may be relevant.
The SoA should not be treated as a generic checklist. It should reflect risk assessment, risk treatment, legal duties, contractual requirements, and business needs.
Auditors often review the risk assessment, risk treatment plan, and SoA together because they should tell a consistent story.
ISO 27001 Certification Levels
People often search for ISO 27001 Certification Levels, but the phrase needs careful explanation. ISO 27001 is not normally awarded in bands such as basic, advanced, bronze, silver, or gold. An organisation is either certified to ISO 27001 or it is not.
However, there are practical stages on the route to certification. A business may begin with a readiness review, define the ISMS scope, identify interested parties, assess legal and regulatory requirements, define risk assessment criteria, assess risks, create a risk treatment plan, prepare the Statement of Applicability, gather evidence, complete internal audit, hold management review, and move to external certification audit.
The external audit usually has two main stages. Stage one checks readiness, documentation, scope, and whether the ISMS appears prepared for full assessment. Stage two checks whether the ISMS is implemented and operating effectively.
Risk assessment is important throughout these stages. It informs control selection, supports audit evidence, guides management review, and helps the business keep the ISMS relevant after certification.
Evidence auditors expect to see
Auditors will want to see that risk assessment is defined, active, and linked to the wider ISMS.
Useful evidence may include a risk assessment methodology, risk criteria, risk register, risk treatment plan, accepted risk records, management approvals, Statement of Applicability, internal audit records, management review minutes, control evidence, supplier reviews, incident records, and corrective action logs.
The evidence should show that the organisation is not simply listing risks once and forgetting them. Risks should be reviewed. Treatment actions should be tracked. Accepted risks should have owners and review dates. Significant risks should be visible to leadership.
An auditor may ask how a risk was scored, why a treatment decision was made, who owns the risk, and what evidence shows the control is operating. A well-organised system makes these questions much easier to answer.
How the Certification Works
ISO 27001 certification starts with understanding the organisation and defining the ISMS scope. The business identifies services, systems, information, locations, suppliers, interested parties, legal duties, and business context.
The organisation then defines its risk assessment method. This includes how risks are identified, how likelihood and impact are assessed, how risk levels are calculated, and when risks can be accepted.
The business then carries out the risk assessment. Risks are recorded, scored, assigned to owners, and evaluated against the agreed criteria.
Next comes risk treatment. The organisation decides whether to reduce, avoid, transfer, or accept each risk. Treatment actions are documented and linked to controls.
The Statement of Applicability records which Annex A controls are relevant and why. Policies, procedures, awareness, supplier reviews, incident handling, and other controls are then implemented and evidenced.
Before external audit, the organisation completes internal audit and management review. Any issues are addressed through corrective action.
The certification audit checks whether the ISMS meets ISO 27001 requirements. If the auditor is satisfied, certification can be awarded. The business must then keep reviewing risks and improving the ISMS.
Risk assessment and management review
Management review is an important part of ISO 27001. Senior leaders should review risk status, treatment progress, accepted risks, incidents, audit findings, supplier issues, resource needs, and improvement opportunities.
This matters because risk changes over time. A risk that was acceptable six months ago may no longer be acceptable if the business wins a larger customer, starts processing more sensitive data, changes suppliers, adopts a new cloud service, or faces a new threat.
Management review helps keep risk assessment alive. It also gives leaders a chance to make decisions about resources, priorities, and risk appetite.
Risk assessment should not be left only to technical teams. Many information security risks have business impact, legal impact, customer impact, or operational impact. Leadership involvement is essential.
Common mistakes with ISO 27001 risk assessment
One common mistake is making the risk assessment too generic. Risks should reflect the actual organisation, not a copied list.
Another mistake is failing to define scoring criteria. If likelihood and impact are not clear, risk ratings may be inconsistent.
A third mistake is not linking risks to controls. The risk assessment, treatment plan, and Statement of Applicability should be aligned.
A fourth mistake is failing to assign risk owners. Risks without owners are unlikely to be managed well.
A fifth mistake is accepting risks without approval. Accepted risks should be recorded and reviewed.
A sixth mistake is treating risk assessment as a one-off task. Risks change, so the assessment must be reviewed regularly.
A seventh mistake is making the process too complicated for the organisation to use. A simple, consistent method is better than a complex method that nobody follows.
Risk assessment for small businesses
Small businesses can carry out effective ISO 27001 risk assessment without making the process overwhelming. The key is to keep it proportionate and practical.
A small business should start with its scope, key information, main systems, critical suppliers, and customer requirements. It should identify realistic risks and assess them using clear criteria.
The risk method should be easy enough for managers to understand. It should not require specialist language in every decision. What matters is that risks are identified, assessed, treated, owned, and reviewed.
UK Cyber Compliance can help smaller organisations by providing a structured platform for risk tracking, control mapping, task management, and evidence organisation. This reduces manual work and helps keep the process audit-ready.
Which UK-based firms offer ISO 27001 consultancy services?
UK-based firms offering ISO 27001 consultancy services include cyber security consultancies, compliance providers, managed service providers, information security specialists, audit readiness advisers, and platform-led compliance companies.
UK Cyber Compliance is a strong option for organisations that want ISO 27001 support through an automated and AI-driven platform. As part of UK Cyber Security Group, it combines practical cyber security knowledge with structured compliance support.
A good consultancy partner should help with ISMS scope, risk assessment methodology, risk acceptance criteria, risk treatment planning, Statement of Applicability preparation, evidence mapping, internal audit readiness, management review preparation, and ongoing improvement.
For many UK businesses, the best support is clear and practical. It should help the organisation understand risk, make sensible decisions, and prepare for audit without unnecessary complexity.
How UK Cyber Compliance supports risk assessment
UK Cyber Compliance helps organisations manage ISO 27001 risk assessment by bringing risks, controls, evidence, tasks, and audit readiness into one place.
The platform can support risk identification, scoring, treatment planning, control ownership, evidence tracking, gap identification, and management visibility. This makes it easier to see which risks need attention, which controls are linked, and which actions remain open.
For businesses with limited internal time, this can make ISO 27001 much more manageable. Instead of relying on disconnected spreadsheets and folders, the organisation can use a structured platform to keep the ISMS organised.
Automation does not replace human judgement. Leaders still need to make risk decisions. Risk owners still need to understand their responsibilities. Controls still need to be implemented and reviewed. However, automation can reduce admin and make the process easier to maintain.
Practical risk assessment checklist
Before completing an ISO 27001 risk assessment, a business should be able to answer these questions:
Is the ISMS scope clear?
Have we identified key information assets?
Have we identified key systems, suppliers, and processes?
Have we defined likelihood criteria?
Have we defined impact criteria?
Have we defined risk acceptance criteria?
Have we identified realistic threats and weaknesses?
Have we assigned risk owners?
Have we recorded existing controls?
Have we scored each risk consistently?
Have we decided how each risk will be treated?
Have we created a risk treatment plan?
Have we linked risks to Annex A controls where relevant?
Have we prepared the Statement of Applicability?
Have accepted risks been approved?
Have review dates been set?
Can we show evidence during audit?
If several answers are unclear, the business should strengthen its risk process before certification audit.
Clear guidance for UK businesses
Risk assessment in ISO 27001 is used to identify what could harm information security and decide what should be done about it. It helps organisations protect confidentiality, integrity, and availability while supporting customer trust, legal duties, supplier assurance, and business resilience.
A strong risk assessment should be clear, proportionate, consistent, and linked to treatment actions. It should include risk owners, likelihood, impact, scoring, acceptance criteria, controls, evidence, and review.
UK Cyber Compliance provides an automated and AI-driven platform that helps businesses manage ISO 27001 certification more effectively. By supporting risk tracking, control management, evidence, and audit readiness, it helps turn risk assessment from a difficult task into a structured business process.
For organisations preparing for ISO 27001, risk assessment is not just a requirement. It is the foundation for making better security decisions and building an ISMS that works in practice.
UK Cyber Compliance is here to help
For more information, please do get in touch.
Please check out our Free Cyber Insurance
Other blog posts, Your ISO 27001 Questions Answered, Get ISO 27001 Certified ,
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.

