Updated: 5 July 2026
What is a risk assessment in the context of ISO 27001? A risk assessment is a structured process of identifying, evaluating, and treating information security risks – required by ISO/IEC 27001:2022 Clause 6.1. It is the foundation of the entire ISMS: without a documented and board-approved risk assessment, it is not possible to determine what controls the organisation needs, or to plan the security budget in a meaningful way. For the board, a risk assessment translates technical threats into the language of business decisions.
ISO 27001 risk assessment – at a glance:
- ISO/IEC 27001:2022 requires a formal risk assessment at least annually and after every significant change – this is a mandatory requirement of Clause 6.1.2
- The risk assessment methodology must be documented and approved by the board before the assessment is conducted – not afterwards
- The risk register must contain: risk identification, owner, probability and impact assessment, treatment plan, and status
- The board approves the level of acceptable risk (risk appetite) – this is a business decision, not a technical one
- The ISO 27001 risk assessment must cover the entire ISMS scope – not only IT systems
- Patronusec supports organisations in building and maintaining risk registers in the vCISO model – from methodology to annual updates and board-ready materials
Table of Contents
What is the difference between risk identification and risk evaluation in ISO 27001?
This distinction matters – ISO/IEC 27001:2022 takes the organisation through three distinct stages.
Stage 1: Risk identification (Clause 6.1.2 a-b)
Objective: enumerate all information security risks that could affect the confidentiality, integrity, or availability of information within the ISMS scope. Identification should cover technical threats (malware, insider threat, system failure), process threats (human error, absent procedures, supplier change), and environmental threats (fire, flood, power outage).
Stage 2: Risk evaluation (Clause 6.1.2 c)
Objective: assign each risk a probability and potential impact rating to establish priorities. The standard does not prescribe a specific scale – the organisation defines its own methodology (1 to 3, 1 to 5, a risk matrix, qualitative or quantitative approaches).
Stage 3: Risk treatment (Clause 6.1.3)
Objective: for each risk, select a treatment option – avoidance, modification (implementing controls), transfer (insurance, outsourcing), or acceptance. Selected treatment options must be linked to specific Annex A controls or other chosen controls.
Typical risk register structure for ISO 27001:
| Column | Content | Notes |
|---|---|---|
| Risk ID | Unique identifier | e.g. RISK-001 |
| Risk description | Threat scenario | What could happen and why |
| Assets | Affected information assets | Server, customer data, process |
| Owner | Accountable person | Must be a named individual |
| Probability | Scale 1-5 or low/medium/high | Per approved methodology |
| Impact | Scale 1-5 or low/medium/high | Financial, reputational, operational |
| Gross risk rating | P × I or matrix value | Before controls are applied |
| Treatment | Avoidance/Modification/Transfer/Acceptance | Board or owner decision |
| Controls | Reference to Annex A | e.g. A.8.7, A.5.23 |
| Net risk rating | After controls applied | Residual risk |
| Status | In progress/Closed/Accepted | Date last updated |
Patronusec Insight: The most common mistake in a first ISO 27001 risk assessment is recording controls rather than risks. A client writes “no disk encryption” in the register – that is a control gap, not a risk. The risk reads: “Loss of an unencrypted laptop may result in unauthorised disclosure of customer data.” The distinction matters, because a correctly framed risk enables the board to decide: accept it, implement encryption, or transfer it to an insurer. We help clients build risk registers from scratch as part of our ISO 27001 and vCISO services.
How do you choose a risk assessment methodology – and what does ISO 27001 require?
ISO/IEC 27001:2022 does not mandate a specific methodology – it requires only that the organisation has a documented, repeatable, and board-approved methodology (Clause 6.1.2).
Three common approaches:
Qualitative (most common):
Descriptive scales: low/medium/high for probability and impact. A 3×3 or 5×5 matrix. Simple, fast, and accessible to a board without a technical background. Drawback: subjectivity of assessments between different analysts.
Semi-quantitative:
Numerical scales of 1 to 5; score = probability × impact; result 1 to 25, with acceptance thresholds (for example, 1 to 5 acceptable, 6 to 15 monitor, 16 to 25 requires immediate treatment). A compromise between simplicity and measurability.
Quantitative (FAIR, ALE):
Annualised Loss Expectancy = probability of incident × financial value of loss. Requires historical data and advanced analysis. Used by large financial institutions. Drawback: complexity and difficulty obtaining reliable data.
Recommendation for most organisations: a semi-quantitative approach with a 1 to 5 scale and a risk matrix. Sufficiently rigorous for an ISO 27001 auditor and sufficiently accessible for the board.
Planning an ISO 27001 implementation or facing a surveillance audit in three months and needing an updated risk register?
Patronusec conducts risk assessment workshops and builds risk registers compliant with ISO/IEC 27001:2022 – in a format ready for presentation to the board and the auditor. Delivered within 2 to 4 weeks.
What is the board’s role in the ISO 27001 risk assessment process?
The board in ISO 27001 is not a passive recipient of the risk assessment report – it is an active participant that takes specific decisions.
What the board must approve:
- The risk assessment methodology (before the assessment is conducted) – the auditor is interested in whether the methodology is approved, not whether the assessment produced a “good” result
- The risk appetite – which risks the organisation accepts without implementing additional controls
- The risk treatment plan (RTP) – what controls will be implemented, by when, and by whom
- The Statement of Applicability (SoA) – which Annex A controls are applied and why
How to report risk effectively to the board:
The board understands business risk, not technical risk. An effective board report translates risk into financial and operational language:
| Technical language | Board language |
|---|---|
| “No MFA on the AD administrator account” | “Risk of full IT infrastructure takeover – potential loss of customer data and operational downtime estimated at £1.5 to £4 million” |
| “Unpatched servers” | “Ransomware risk – comparable to the incident at [sector peer], which resulted in three months of data recovery” |
Patronusec Insight: Organisations that implement ISO 27001 without genuine board engagement in the risk assessment end up with a paper ISMS – the documents exist, but risk decisions are made by IT without board mandate. An ISO 27001 auditor detects this quickly: they ask the board whether it knows and understands its own risk register – and if the board cannot answer, that is a major nonconformity. In the vCISO model, we prepare decision-ready materials for the board in business language – and conduct annual management reviews as separate facilitated workshops.
How often must the ISO 27001 risk assessment be updated?
ISO/IEC 27001:2022 requires a risk assessment review at least annually (Clause 6.1.2 g) and following any significant change to the ISMS environment.
What qualifies as a “significant change” requiring a risk update:
- Deploying a new system that processes personal or sensitive data
- Migrating to the cloud or changing cloud provider
- Organisational restructuring that affects security accountabilities
- New legislation or regulatory requirements (DORA, NIS2, new FCA guidance)
- A security incident – even one that did not result in a breach
- A change in business model or entry into a new market
A practical ISO 27001 risk management cycle:
- January: Annual review – update the risk register, verify control status
- March: Board presentation – status of residual risks, acceptance of new risks
- On an ongoing basis: Update following every significant change
- Before the audit: Verify that the register is current and approved
How do you link the risk assessment to Annex A controls and the treatment plan?
Annex A of ISO/IEC 27001:2022 contains 93 security controls in four categories (organisational, people, physical, technological). The selection of controls to implement must be driven by the risk assessment – controls implemented “just in case” without a link to a specific risk are difficult to justify during the audit.
Risk-to-control mapping example:
Risk: “Unauthorised access to customer data by former employees”
- Treatment: Modification (implement controls)
- Annex A controls: A.5.18 (access rights), A.6.5 (responsibilities after termination), A.8.3 (restriction of access to information)
- Owner: HR Manager plus IT Security
- Target date: Q2 2026
- KPI: 100% of employee accounts deactivated within 24 hours of departure
FAQ – ISO 27001 risk assessment
Does ISO 27001 require a specific risk assessment methodology?
No – the standard only requires that the methodology is documented, board-approved, and repeatable. Organisations may use OCTAVE, FAIR, their own matrix, or another approach. The important thing is that the same methodology produces comparable results across successive reviews.
How many risks should the ISO 27001 register contain?
There is no minimum or maximum. Organisations often have 30 to 80 risks after a first assessment. Quality matters more than quantity – 30 well-described risks with named owners and treatment plans are more valuable than 200 vague entries without accountability.
Must the ISO 27001 risk assessment cover UK GDPR-related risks?
Yes, if personal data processing is within the ISMS scope. Privacy risks may be captured in the same register as information security risks, or in a separate register linked to a DPIA (Data Protection Impact Assessment). An ISO 27001 auditor will verify that personal data risks are addressed.
Who should own risks in the ISO 27001 register?
Risk owners should be people with genuine authority over the assets the risk relates to – not the CISO or Information Security Manager for every risk by default. A risk relating to an HR process should be owned within HR. A risk relating to a production server should be owned within IT. The risk owner is accountable for the treatment decision and monitoring of status.
How much does risk assessment support from Patronusec cost?
Scope and cost depend on the size of the organisation and the breadth of the ISMS. A risk assessment workshop for an organisation of 50 to 200 employees takes 2 to 4 working days, producing a complete risk register ready for presentation to the auditor. Patronusec provides a fixed-price quotation after a free initial call. In the vCISO model, we maintain the risk register and conduct annual reviews as an ongoing service.
How does ISO 27001 risk assessment differ from risk assessment required by DORA or NIS2?
ISO 27001 defines general information security risk management requirements. DORA (Digital Operational Resilience Act) imposes additional requirements on financial institutions for ICT risk management – with an emphasis on operational resilience and ICT supplier risk. NIS2 requires risk assessment for the cybersecurity of networks and information systems. A strong ISO 27001 risk assessment is often the foundation for DORA and NIS2 compliance, but requires extensions specific to those regulations.
ISO 27001 risk assessment – free consultation
Patronusec supports organisations in building and maintaining information security management systems compliant with ISO/IEC 27001:2022. In the vCISO model, we take responsibility for the risk register, management reviews, and auditor communication – the client focuses on the business.
In a free 30-minute consultation we will help you:
- Assess whether your current risk assessment methodology will satisfy an ISO 27001 auditor
- Identify gaps in the risk register before a surveillance or recertification audit
- Choose a methodology appropriate to the size and complexity of your organisation
- Plan the level of external support required (project versus ongoing vCISO model)
Free consultation | ISO 27001 implementation | vCISO – risk management | DORA compliance | NIS2