Knowledge base

ISO 27001 Risk Assessment: A Simple and Practical Approach

ISO 27001 requires a risk assessment, but you can choose your own method. This is a practical approach that auditors can accept.

Neha Dvivedi · August 16, 2026

ISO 27001 requires organisations to carry out a risk assessment, but it does not tell you exactly which method to use. This gives organisations flexibility to choose a method that suits their business.

The key is to have a clear, consistent and repeatable process that can also satisfy an auditor.

What Does ISO 27001 Require?

Your risk assessment process should:

• Identify risks related to the confidentiality, integrity and availability of information within the scope.

• Identify a person responsible for each risk.

• Analyse and evaluate risks using clearly defined criteria.

• Produce results that are consistent and comparable.

• Be repeatable whenever the assessment is carried out again.

Beyond these requirements, the organisation can choose the method that works best for its business.

Step 1: Define Your Risk Criteria First

Before identifying risks, decide and document two important things:

1. Risk Acceptance Criteria

Decide what level of risk the organisation is willing to accept without taking additional action.

This should be a business decision and approved by someone who has the authority to accept the risk.

2. Impact and Likelihood Scales

Clearly define what each level means for your organisation.

For example, instead of simply saying "High Impact = Significant," explain what high impact actually means. It could mean regulatory penalties, major financial loss or losing an important customer.

These criteria should be defined before the risk assessment starts. Otherwise, there is a possibility of changing the criteria later to match the results.

Step 2: Identify the Risks

There are two common ways to identify risks:

Asset-Based Approach

Start by listing the information assets within the scope. Then identify the threats and vulnerabilities related to each asset.

This approach can be detailed and thorough, but it can also take more time.

Scenario-Based Approach

Think about realistic situations that could negatively affect the organisation and then identify what could cause those situations.

For many organisations, this approach is easier because people naturally understand risks through real-life scenarios.

A practical approach is to use scenario-based risk assessment along with an asset inventory to make sure nothing important is missed.

Write Risks Clearly

A risk should explain both the cause and the possible consequence.

For example:

Good:

"A developer has permanent access to the production database and could extract customer information."

Too vague:

"Data breach."

The first example clearly explains what could happen and why.

Step 3: Assign a Risk Owner

Every identified risk should have a named risk owner.

The risk owner should be someone who has the authority to decide whether the risk should be treated or accepted.

It does not mean that the information security manager should own every risk. Ideally, the person responsible for the affected business area should own the risk.

This creates clear accountability and ensures that risks are discussed by the people who actually manage the business activity.

Step 4: Analyse and Evaluate the Risks

Now apply your predefined impact and likelihood criteria to each risk.

Then compare the result with your risk acceptance criteria.

If the risk is above the organisation's acceptable level, it should normally be treated.

Avoid marking every risk as "Medium."

If almost every risk receives the same rating, it becomes difficult to understand which risks actually require more attention. A good risk assessment should clearly differentiate between lower and higher risks.

Step 5: Decide How to Treat the Risk

There are four main options:

1. Modify the Risk

Introduce appropriate controls to reduce the likelihood or impact of the risk.

2. Avoid the Risk

Stop the activity that is creating the risk.

3. Share the Risk

Transfer or share part of the risk through insurance, contracts or other arrangements.

4. Accept the Risk

The organisation may decide to accept the risk if it is within the approved tolerance level.

Risk acceptance is a valid option. Organisations sometimes introduce unnecessary controls simply because accepting a risk feels uncomfortable.

A documented decision that is approved by the appropriate risk owner is a legitimate way to treat a risk.

Step 6: Connect the Risks to Annex A

Only after completing the risk assessment and deciding how to treat the risks should you review ISO 27001 Annex A.

Use Annex A to check whether the selected controls adequately address the identified risks and whether any important controls have been missed.

The results can then be used to develop the Statement of Applicability (SoA).

This sequence is important:

Identify risks → Assess risks → Decide treatment → Review Annex A → Prepare SoA

This helps ensure that controls are selected based on actual business risks rather than simply selecting controls first and then trying to justify them.

Keep the Risk Assessment Updated

Risk assessment should not be a one-time activity done only before certification.

Review it at planned intervals and whenever there is a significant change, such as:

• Introduction of a new system

• Appointment of a new supplier handling company data

• Expansion into a market with different regulatory requirements

• A security incident

• Major changes to business processes

Keep evidence of these reviews.

A risk assessment that has only one date and has not been reviewed for years can raise questions about how actively the organisation manages information security risks.

Common Problems Auditors May Find

Some common weaknesses include:

1. Risks are written too vaguely, such as using only "data breach" instead of explaining the cause and consequence.

2. Risk owners are not clearly identified, or the same person is assigned to every risk.

3. Risk criteria are created after the assessment, instead of being defined beforehand.

4. There is no evidence that risks have been reviewed after certification.

5. Risk treatment decisions are not clearly connected to the controls listed in the Statement of Applicability.

The Key Takeaway

A good ISO 27001 risk assessment does not need to be unnecessarily complicated.

What matters is having a clear, documented and repeatable process that identifies realistic risks, assigns accountability, evaluates risks consistently, and connects treatment decisions to appropriate controls.

The goal is not simply to create a risk register for the auditor. The goal is to create a risk assessment that helps the organisation understand and manage its information security risks.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 27001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles