This article covers 8 points on how to create an ISO 27001 risk assessment:

  1. What ISO 27001 requires for risk assessment, clause 6.1.2
  2. Recommended methodology: ISO 27005 and good practice
  3. Step by step process to create the assessment
  4. How to document and maintain the assessment
  5. Common mistakes
  6. How PrivaLex can help
  7. How to turn the assessment into a practical management tool
  8. Frequently asked questions

Creating a risk assessment under ISO 27001 is one of the cornerstones of a solid information security management system, or ISMS. The standard does not prescribe a single method, but it does require the process to be consistent, documented, and reviewed periodically.

This guide explains how to create an ISO 27001 risk assessment in practice: what clause 6.1.2 requires, which methodology to use, and how to document it.

PrivaLex Partners helps organisations design and implement the risk assessment process efficiently, from methodology to risk treatment and the documentation required for certification. If you are preparing to obtain ISO 27001 certification or want to align your ISMS with the standard, this guide gives you the roadmap.

What ISO 27001 requires for risk assessment

Requirements of clause 6.1.2

Clause 6.1.2 of ISO 27001 requires the organisation to identify, assess, and treat information security risks systematically. Listing threats is not enough: you must define criteria for risk assessment and acceptance, ensure assessments are consistent and comparable over time, and assign responsibilities.

What the assessment must cover

The standard requires you to identify risks that threaten the confidentiality, integrity, and availability of information within the scope of the ISMS; to assess consequences, likelihood, and risk level; and to prioritise according to the criteria defined. A coherent risk assessment is the compass of your security: without it, you are navigating blind.

The process must be capable of producing consistent and comparable results. Organisations should retain documented information about the results of their information security risk assessments and risk treatment decisions, including who accepted any residual risk.

For the official description of the ISMS standard, see ISO/IEC 27001:2022.

Recommended methodology: ISO 27005 and good practice

The ISO 27005 cycle

Although ISO 27001 sets out what must be achieved, ISO 27005 provides more concrete guidance on how. This standard proposes a continuous cycle with clear stages: establish the context of risk, identify risks, analyse and assess likelihood and impact, treat risks, accept residual risks in a documented way, and communicate, review, and monitor.

Practical application

ISO 27005 turns ISO 27001 risk theory into real action. You can adapt the scales and criteria to your size and sector; what matters is that the methodology is documented and applied consistently.

The current guidance is ISO/IEC 27005:2022. It supports the full risk management cycle, including assessment, treatment, communication, monitoring, and review. It is guidance rather than a mandatory method, so the organisation can use another suitable methodology if it meets ISO 27001 requirements consistently.

Cybersecurity and risk management are the foundation, especially when aligned with the EU Artificial Intelligence Act in AI driven environments.

7 steps to create an ISO 27001 risk assessment

Although the approach should adapt to your organisation, this process serves as a general guide for how to create an ISO 27001 risk assessment:

  1. Define the methodology: assessment and acceptance criteria, scales for likelihood and impact, roles, approval authority, and planned review intervals. Document the method in an internal procedure or guide.
  2. Identify information and supporting assets within the ISMS scope, or use risk scenarios based on relevant processes. Consider the threats, vulnerabilities, suppliers, people, systems, and business dependencies that could affect them.
  3. Assess the likelihood and impact of each risk, by asset, process, or scenario, depending on your approach.
  4. Calculate and evaluate the risk level using the predefined criteria, then prioritise treatment according to the organisation’s risk tolerance. A simple likelihood and impact score can work when its definitions are clear and applied consistently.
  5. Prepare a treatment plan: decide whether to modify, retain, avoid, or share each risk; identify the necessary controls; assign an owner; and set a target date. When selecting controls, compare the necessary controls with Annex A so that no relevant control is omitted.
  6. Document the results in the risk register or risk assessment report, link actions to the treatment plan, and reflect the necessary controls in the Statement of Applicability.
  7. Review the assessment at planned intervals and whenever significant changes occur, such as a new system, material supplier, incident, acquisition, product launch, legal change, or major organisational change.

How to document and maintain the assessment

What the documentation should include

The risk assessment must be recorded in a report, or set of documents, that includes: scope, methodology used, assessment and acceptance criteria, list of risks identified with level and treatment, treatment plan with owners and dates, and approval by management or the ISMS owner.

A practical risk register should also identify the relevant asset or process, risk owner, existing controls, planned treatment actions, target date, residual risk, risk acceptance decision, and review date. This makes it possible to trace a risk from identification through to action, approval, and review.

How the risk assessment connects to the Statement of Applicability

The Statement of Applicability reflects which Annex A controls you apply and why, based on the risks; it must be aligned with the risk report.

The Statement of Applicability should show the necessary controls, whether they are implemented, and the justification for including or excluding them. It should also include necessary controls that are not taken from Annex A, where applicable.

When to review the assessment

Maintaining the assessment means reviewing it at least annually or when significant changes occur, such as new projects, incidents, or regulatory changes. Without periodic reviews, the ISMS becomes outdated and certification or internal audit may find deviations.

ISO 27001 does not impose one universal annual schedule. The organisation should define its own review intervals and ensure that the assessment is updated when relevant changes occur. An annual review is often a useful practical baseline, but it should not replace change triggered reviews.

The risk assessment under ISO 27001 is not an end in itself but a strategic tool that helps you anticipate, respond, and strengthen yourself against real vulnerabilities.

5 common mistakes in an ISO 27001 risk assessment

1. Using inconsistent criteria

If each assessment uses different scales or criteria, results are not comparable and the auditor will detect inconsistencies. Document the methodology and use it consistently.

2. Assessing once and never reviewing

ISO 27001 requires the assessment to be kept up to date. Not reviewing when things change or not scheduling periodic reviews weakens the ISMS and can lead to nonconformities.

3. Failing to link risks to treatment and the Statement of Applicability

Identified risks must translate into controls, whether from Annex A or another necessary source, and into the Statement of Applicability. If the risk report and the Statement of Applicability are not aligned, the auditor will notice.

4. Leaving responsibilities unclear

Assign owners for the assessment, for approval of residual risk, and for monitoring the treatment plan. Without a clear owner, the process drifts.

5. Relying on a numerical score without judgement

A numerical score can support prioritisation, but it does not replace management judgement. A risk can require treatment because of legal, contractual, customer, or business continuity consequences even when a simple score appears moderate. Record the reasoning behind significant risk treatment and acceptance decisions.

How PrivaLex can help create an ISO 27001 risk assessment

PrivaLex Partners helps organisations establish a risk assessment process that is practical for the business and credible in an ISO 27001 audit. It can support methodology design, risk criteria, scope definition, risk workshops, treatment planning, risk ownership, and the documentation needed to connect the risk register with the ISMS.

Its support also includes reviewing how risks map to the Statement of Applicability, helping teams identify evidence for implemented controls, and preparing the organisation for internal audit, management review, and independent certification. The focus is not on producing a generic register, but on creating a process that remains useful when systems, suppliers, products, and business priorities change.

Where the organisation also needs to address regulatory requirements, PrivaLex can connect risk management with NIS2 compliance and GDPR audit preparation. This can reduce duplicated work and give leadership a clearer view of risk across security, privacy, and operational resilience.

Schedule a strategic session with PrivaLex to turn the risk assessment into a practical foundation for certification and everyday security decisions.

Build a risk assessment that supports real decisions

An ISO 27001 risk assessment is not a one time spreadsheet exercise. It is the mechanism that explains why the ISMS has its scope, controls, treatment priorities, and improvement actions. When the methodology is clear, responsibilities are assigned, and changes trigger review, the assessment becomes useful for both certification and everyday decision making.

The most effective approach is proportionate to the organisation’s size, services, information, and risk appetite. What matters is not using the most complex model, but applying a clear method consistently and being able to explain the decisions it produces.

Frequently Asked Questions (FAQs)

No. ISO 27001 does not require one template or scoring model. The organisation must use a documented method that identifies, analyses, evaluates, and treats information security risks consistently.

Yes, if the definitions are clear, the method produces consistent results, and the organisation can explain how scores lead to treatment and risk acceptance decisions.

The organisation should define approval authority in its methodology. Significant residual risks are commonly accepted by a responsible manager or risk owner with sufficient authority to make that decision.

At the intervals defined by the organisation and whenever relevant change occurs. New systems, suppliers, incidents, products, markets, or legal requirements can all justify an earlier review.


Free checklist
Do you know what’s standing between you and ISO 27001 certification?
Download our readiness checklist and find out which controls you already have in place and where your real gaps lie, before you start the process.
Download Free Checklist