ISO 27001

ISO 27001 risk assessment: how to do it properly

9 August 2026 · 8 min read · CertAssist

The risk assessment is the analytical heart of ISO 27001. Here is the method auditors expect, step by step.

An ISO 27001 risk assessment is the process of identifying the information security risks to your organisation, analysing how likely they are and how much they would hurt, and deciding how to treat each one. It is a mandatory requirement of ISO 27001 under Clause 6.1.2, and its output drives your risk treatment plan and your Statement of Applicability, the document that records which Annex A controls you apply and why. A good risk assessment is repeatable: define a method, identify risks, analyse and evaluate them against your criteria, then treat them. Here is how to run one that your auditor will accept.

Timeline of the ISO 27001 risk assessment process: set method, identify, analyse, evaluate, treat

What is an ISO 27001 risk assessment?

An ISO 27001 risk assessment is a structured evaluation of what could go wrong for your information security and what you will do about it. It identifies risks to the confidentiality, integrity and availability of your information, estimates their likelihood and impact using a consistent method, and ranks them so you can focus on what matters. It is not a one-off document but a living process you repeat and keep current. The assessment is the analytical heart of an information security management system, because every control you implement should trace back to a risk it addresses.

Is a risk assessment mandatory for ISO 27001?

Yes, a risk assessment is mandatory for ISO 27001. Clause 6.1.2 requires you to define and apply an information security risk assessment process, and Clause 6.1.3 requires a risk treatment process that selects controls to address the risks you found. You cannot certify to ISO 27001 without them, because they justify your Statement of Applicability. An auditor will check not only that you have a risk assessment but that it is based on a defined, repeatable method and that your chosen controls clearly follow from it.

Asset-based or scenario-based: which method?

ISO 27001 lets you choose your risk assessment method, and the two common approaches are asset-based and scenario-based. An asset-based assessment lists your information assets, then identifies threats and vulnerabilities for each, which is thorough but can be heavy for a large asset inventory. A scenario-based assessment starts from realistic risk scenarios, such as a phishing-led account takeover, which is often faster and more meaningful for smaller organisations. Either is acceptable as long as it is consistent and repeatable. Many small teams find a scenario-based method reaches useful results with less overhead.

How do you run an ISO 27001 risk assessment?

To run an ISO 27001 risk assessment, first define your method and criteria: how you will score likelihood and impact, and the level of risk you are willing to accept. Then identify risks, either asset by asset or scenario by scenario, and assign an owner to each. Analyse each risk by rating its likelihood and impact to produce a risk level, and evaluate those levels against your acceptance criteria to decide which need treatment. Finally, choose a treatment for each risk above the line. Record the whole thing, because the documented method and results are what the auditor examines.

How does risk treatment connect to the Statement of Applicability?

Risk treatment is where you decide how to handle each unacceptable risk, and it connects directly to the Statement of Applicability. For most risks you will treat them by applying controls, drawn largely from ISO 27001 Annex A, and for others you may accept, avoid or transfer the risk. The Statement of Applicability then records, for every Annex A control, whether it applies, the justification, and its implementation status. Because each applied control should trace back to a risk, a clean risk assessment makes the Statement of Applicability straightforward, and a weak one makes it impossible to justify.

What mistakes should you avoid?

The most common risk assessment mistakes are making it a one-time exercise, using an inconsistent method that cannot be repeated, and choosing controls first and reverse-engineering risks to fit. Avoid rating everything the same, which hides your real priorities, and avoid leaving risks without an owner, since ownerless risks never get treated. Keep the assessment proportionate too: a small company does not need hundreds of granular entries, it needs a genuine, consistent view of its real exposures that it revisits at planned intervals and after significant change.

How CertAssist helps

CertAssist lays out the ISO 27001:2022 requirements, including the risk assessment and treatment steps, with editable templates and the Statement of Applicability handled, so your risks, treatments and controls stay linked in one place rather than scattered across spreadsheets. You record each risk, its analysis and its chosen treatment, and the applied Annex A controls flow through to your Statement of Applicability. CertAssist does not connect to your systems, so your risk data stays with you, and the price is a published US$225 per month during its launch.

Frequently asked questions

What is an ISO 27001 risk assessment?

An ISO 27001 risk assessment is a structured evaluation that identifies information security risks, analyses their likelihood and impact using a consistent method, and ranks them so you can decide how to treat each one. It is a living process, not a one-off document, and every control you apply should trace back to a risk it addresses.

Is a risk assessment mandatory for ISO 27001?

Yes. Clause 6.1.2 requires a defined information security risk assessment process, and Clause 6.1.3 requires a risk treatment process that selects controls. You cannot certify to ISO 27001 without them, because they justify your Statement of Applicability. Auditors check that the method is defined, repeatable, and clearly drives your chosen controls.

What is the difference between asset-based and scenario-based risk assessment?

An asset-based assessment lists information assets and identifies threats and vulnerabilities for each, which is thorough but heavy for large inventories. A scenario-based assessment starts from realistic risk scenarios, which is often faster and more meaningful for smaller teams. ISO 27001 accepts either, provided the method is consistent and repeatable.

How does the risk assessment relate to the Statement of Applicability?

Risk treatment decides how to handle each unacceptable risk, usually by applying Annex A controls. The Statement of Applicability then records, for every Annex A control, whether it applies, the justification and its status. Because each applied control should trace back to a risk, a clean risk assessment makes the Statement of Applicability straightforward to justify.

How often should you do an ISO 27001 risk assessment?

Review your risk assessment at planned intervals, commonly at least annually, and whenever there is significant change, such as a new product, a major system, an incident or a shift in the threat landscape. ISO 27001 treats risk assessment as an ongoing process, so keeping it current, not just producing it once for the audit, is part of the requirement.

Related guides

Keep risks, treatments and controls linked in one place

CertAssist lays out ISO 27001:2022 with risk treatment and the Statement of Applicability handled, for a published $225 a month during the launch.

See pricing Frameworks

← Back to the blog

Powerful in its simplicity.

Flat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.