ISO 27001 Risk Assessment: The Test Your Assessment Has to Pass
Pick any control marked applicable in your Statement of Applicability. Ask which risk it treats.
If the answer is a risk identifier from your assessment, your ISO 27001 risk assessment is doing its job. If the answer is “because it’s in Annex A”, you have a compliance artefact rather than a management system — and an experienced certification auditor establishes which one you have within about twenty minutes.
That single test matters more than the methodology debate that occupies most published guidance. Asset-based or scenario-based, qualitative or quantitative, five-by-five or three-by-three: those are choices, and the standard lets you make any of them. Getting the direction of travel wrong is not a choice, and it is the most common structural failure in ISO 27001 implementations.

Building this from scratch? The ISO 27001 Compliance Suite includes the risk management procedure with the criteria and scales as configurable annexes, plus the risk register and treatment plan as a working file with the risk-to-control traceability built in. €590 excl. VAT.
The direction of travel
Clause 6.1.2 and 6.1.3 set out a sequence, and the order is not decorative.
Identify the risks to confidentiality, integrity and availability within your scope. Analyse them: consequence, likelihood, resulting level. Evaluate them against the criteria you defined beforehand, and prioritise. Choose treatment options. Determine the controls necessary to implement those treatments. Then, and only then, compare that set against Annex A to verify nothing necessary has been overlooked, and produce the Statement of Applicability to record the outcome.
Read clause 6.1.3(c) carefully, because it is the one people invert. Its purpose is verification of completeness. Annex A is a checklist you compare your own list against, not a menu you order from.
The standard even permits controls that are not in Annex A at all, if your risk assessment produced them. Almost nobody exercises this, and an auditor who sees one takes the whole system more seriously, because it can only exist if the assessment was genuinely upstream.
What running it backwards looks like: the team opens Annex A, decides which of the 93 controls they can plausibly implement, marks the rest not applicable, and then writes risks to explain the choices. The output looks identical to a correct assessment. It fails the test in the first paragraph.
What clause 6.1.2 actually requires
Five things. Everything else in your methodology is your decision.
A documented process that is applied consistently.
Risk acceptance criteria, defined before assessing anything. What level of residual risk the organisation is prepared to live with, decided by someone with the authority to accept it.
Criteria for performing assessments, so that the process is repeatable.
Results that are consistent, valid and comparable. This is the requirement people skip, and it has a specific consequence discussed below.
Risk owners. Each risk has one person accountable for it, and the same person approves the treatment plan and accepts the residual risk. Not a department — a person.
That is the whole obligation. There is no required scale, no required method, no required tool, and no required number of risks.
The word that constrains you: comparable
“Consistent, valid and comparable results” is the phrase that rules out the most common working practice, which is re-scoring everything by feel each year.
If the same risk, unchanged, scores 12 this year and 8 next year because a different person filled the sheet, the results are not comparable and the process is not repeatable. That is a clause 6.1.2 nonconformity even if every individual score looks reasonable.
What makes results comparable in practice:
- Scale definitions written in words, not just numbers. “Consequence 4 = regulatory notification required or material contractual breach”, not “4 = high”.
- Likelihood anchored to something observable. “Has happened to us or to a comparable organisation in the last two years” beats “likely”.
- The same person or panel scoring within one cycle, with the reasoning recorded when a score changes.
Two organisations with different scales can both be compliant. One organisation with two different scales in the same register cannot.
Asset-based or scenario-based
This decision absorbs more discussion than it deserves. The 2022 edition prescribes neither, and both are used successfully.
| Asset-based | Scenario-based | |
|---|---|---|
| Starts from | The asset inventory | Things that could happen |
| Strength | Systematic coverage; nothing in scope is missed | Finds cross-cutting risks a per-asset view fragments |
| Weakness | Produces volume — hundreds of near-identical rows | Coverage depends on the imagination in the room |
| Suits | Organisations with a real asset inventory already | Service organisations whose value is process, not kit |
The practical answer for most organisations is a hybrid, and it is not a compromise. Use the asset inventory for coverage, so that nothing in scope goes unconsidered, then write scenarios for the things that cut across assets — a supplier failing, a key person leaving, a credential set being reused.
The failure mode of asset-based is worth naming because it is so common: four hundred rows, one per asset per threat, most of them variations of the same exposure. A register nobody can read is a register nobody reviews, and an unreviewed register is worse than a shorter one.
If your register has more than about eighty rows for a mid-sized organisation, you are probably recording the same risk repeatedly with different asset names attached.
Where risk assessments actually break
Six failures, in the order an auditor tends to encounter them.
Risks written as asset names. “Customer database” is not a risk. A risk has a source, an event and a consequence: an administrator credential is reused externally, allowing unauthorised access to the customer database, resulting in disclosure of personal data. If your register column reads like an inventory, the analysis has not been done.
Criteria written after scoring. People score first, look at the distribution, then set the acceptance threshold so that the results fall where they want. This is invisible in the document and obvious in the dates.
Risk owners who are roles, not people. “IT” cannot approve a treatment plan or accept residual risk. When something is accepted, one person accepted it.
Everything scored medium. A register where nothing is high and nothing is low has not prioritised anything, which is what clause 6.1.2 asks the evaluation step to do. Usually a symptom of scales that were never defined in words.
No link to the controls. The risk register and the Statement of Applicability exist as separate documents with no reference column between them. This is the failure the opening test detects, and it takes one column to fix.
The assessment that happens once. Clause 8.2 requires assessments at planned intervals and when significant changes are proposed or occur. An annual sweep with nothing in between means the changes that mattered were not assessed at the time they happened.
What a defensible risk register row contains
Six columns are enough. More is your choice; fewer will not survive an audit.
| Column | Content |
|---|---|
| Reference | R-014. Used by the SoA, the treatment plan and the audit trail |
| Risk description | Source, event and consequence in one sentence |
| Owner | A named person |
| Analysis | Consequence, likelihood, resulting level, against the scales in your criteria |
| Treatment decision | Modify, retain, avoid or share — with the controls named if modifying |
| Residual and acceptance | Level after treatment, and who accepted it, on what date |
The reference column is the one that turns a spreadsheet into evidence. It is what lets an auditor follow a control in the Statement of Applicability back to a risk, and a risk forward to a record showing the treatment was implemented.

Treatment: four options, and the two nobody records properly
The standard offers modify, retain, avoid and share. Everyone documents modify. The other three get skipped, and two of them are where auditors probe.
Retain — accepting the risk as it is. This is legitimate and common, and it requires a named person to have accepted it on a date. An accepted risk with no acceptance record is an untreated risk.
Avoid — stopping the activity that creates the risk. Rarely used, easy to evidence when it is.
Share — insurance, or transfer to a supplier. The trap: sharing changes the shape of your obligation, it does not remove it. You still assess and monitor the party you shared with, and that assessment is the evidence.
The residual risk after treatment is what gets accepted, and clause 6.1.3(f) requires the risk owners’ approval of both the treatment plan and the residual risk acceptance. Two approvals, often recorded as one.
Keeping it alive
The triggers are events, not the calendar. Reassess when the scope changes, when a significant change is proposed or occurs, after an incident, when a new supplier gains access, and when a control that was treating a risk stops working.
Two habits that cost little and prevent most drift:
Reconcile the register against the Statement of Applicability at every management review. Every applicable control should trace to at least one risk; every risk treated by modification should name its controls. Twenty minutes, and it catches the contradictions before an auditor does.
Once a year, take the ten thinnest rows — the ones where the description is vaguest or the reasoning shortest — and rewrite them properly. That is where the assessment decays, and it decays quietly.
Frequently asked questions
Does ISO 27001 require a specific risk assessment methodology? No. The 2022 edition prescribes neither asset-based nor scenario-based, and does not require a particular scale or tool. It requires a documented process, defined criteria including acceptance criteria, risk owners, and results that are consistent, valid and comparable.
Is the risk assessment mandatory documented information? The process itself must be available as documented information under clause 6.1.2. The results must be retained as evidence under clause 8.2, and the results of treatment under 8.3. Those are two different obligations — see documents versus records.
How many risks should the register contain? There is no target. For a mid-sized organisation, a register above roughly eighty rows usually indicates the same exposure recorded repeatedly with different asset names. What matters is that nothing in scope was left unconsidered and that the register is short enough to be reviewed.
Do we assess risks against Annex A controls? No, and this is the inversion to avoid. You identify and analyse risks, choose treatments, determine the necessary controls, and then compare that set against Annex A to check nothing was overlooked. Clause 6.1.3(c) is a completeness check.
Who can be a risk owner? A named individual with the authority to approve the treatment and accept the residual risk. A department name does not satisfy this.
How often must the risk assessment be repeated? At planned intervals that you define, and additionally when significant changes are proposed or occur — clause 8.2. Annual is the common planned interval and is not sufficient on its own.
What is the difference between the risk assessment and the risk treatment plan? The assessment identifies, analyses and evaluates. The treatment plan says what will be done, by whom and by when. The Statement of Applicability records which controls are necessary, why, and their implementation status. The standard requires all three and they are not interchangeable.
Where to go from here
If you take one thing from this, take the test at the top: pick a control, ask which risk it treats. Do it for five controls across different themes. The answers tell you in ten minutes what a gap analysis would take a week to establish.
When the assessment is genuinely upstream, everything downstream gets easier — the Statement of Applicability writes itself, the internal audit has something to test against, and the management review has something to decide about.
The ISO 27001 Compliance Suite contains the risk management procedure with the criteria, scales and risk source catalogue as configurable annexes, and the risk register and treatment plan as one working file with the reference columns that make the chain traceable in both directions. 43 files, €590 excl. VAT.
Downstream of this sit three documents worth reading next: the risk register template itself, with the nine columns that keep it auditable, the Statement of Applicability, which records what your assessment produced and is the first document a certification auditor opens, and the internal audit, which is where somebody tests whether the register describes reality. For the whole documented set, what a documentation toolkit should contain covers it.