ISO 27001 Internal Audit

ISO 27001 Risk Assessment: How to Find What Actually Puts You at Risk


Published 07/30/2026

Every ISO 27001 certification starts in the same place, not with policies or controls, but with risk. Before an organization can decide how to protect its information, it has to understand what could go wrong, how likely it is, and how much damage it could cause. That's the entire purpose of a risk assessment, and it's arguably the most important step in the whole certification process.

View Information Security Management System

What Is an ISO 27001 Risk Assessment?

An ISO 27001 risk assessment is a structured process for identifying, analyzing, and evaluating the risks to an organization's information assets. It answers three core questions: what could threaten your data, how likely is that threat, and what would the impact be if it happened.

The standard doesn't dictate a single method for conducting this process. Instead, it requires organizations to define a consistent, repeatable approach and apply it across the business. The results directly shape which security controls get implemented, making this one of the few requirements that touches nearly every other part of the ISMS.

Skip this step, or rush through it, and the rest of the certification effort tends to fall apart. Controls end up misaligned with actual risk, resources get wasted on low-priority issues, and real vulnerabilities go unaddressed.

Why It's So Central to ISO 27001

Nearly everything else in an ISMS traces back to the risk assessment.

It drives control selection. Annex A of ISO 27001 lists over 90 possible controls, but organizations aren't expected to implement all of them. The risk assessment determines which ones are actually necessary.

It justifies your Statement of Applicability. Auditors expect a clear link between identified risks and the controls chosen to address them. Without a solid risk assessment, that justification falls apart.

It focuses limited resources. No organization has unlimited budget or staff. A proper risk assessment ensures effort goes toward the risks that matter most, not just the ones that are easiest to fix.

It demonstrates due diligence. Regulators, customers, and auditors all want evidence that security decisions are based on actual analysis, not guesswork.

It supports ongoing improvement. Risk isn't static. Revisiting the assessment regularly keeps the ISMS aligned with a changing threat landscape.

The Risk Assessment Process, Step by Step

While specific methodologies vary, most organizations follow a similar sequence when conducting this process under ISO 27001.

1. Establish the Risk Assessment Methodology
Define how risks will be identified, scored, and prioritized. This includes setting criteria for likelihood and impact, along with a consistent scale for measuring risk levels.

2. Identify Information Assets
Create an inventory of the data, systems, applications, and infrastructure that need protection. You can't assess risk to something you haven't identified.

3. Identify Threats and Vulnerabilities
For each asset, determine what could go wrong. This might include cyberattacks, insider threats, system failures, or physical risks like theft or natural disasters.

4. Assess Likelihood and Impact
Evaluate how probable each threat is and what the consequences would be if it occurred, whether financial, operational, legal, or reputational.

5. Calculate Risk Levels
Combine likelihood and impact scores to determine an overall risk rating for each identified threat. This helps prioritize which risks need immediate attention.

6. Determine Risk Treatment
Decide how to handle each risk: reduce it with controls, transfer it through insurance or contracts, avoid it by changing a process, or accept it if the risk falls within tolerable limits.

7. Document Everything
Maintain clear records of the methodology, findings, and decisions made. This documentation is essential for audits and for tracking how risk evolves over time.

Common Risk Treatment Options

Once risks are identified and scored, organizations generally choose from four treatment strategies:

Mitigate: Implement controls to reduce the likelihood or impact of the risk, such as encryption, access controls, or employee training.

Transfer: Shift responsibility for the risk to a third party, often through cyber insurance or outsourcing arrangements.

Avoid: Eliminate the risk entirely by discontinuing the process, system, or activity that creates it.

Accept: Acknowledge the risk and choose not to take further action, typically reserved for low-impact or low-likelihood risks that fall within the organization's defined risk appetite.

Common Mistakes to Avoid

Organizations often run into the same pitfalls when conducting a risk assessment for the first time.

Treating it as a one-time exercise. Risk changes constantly. An assessment done once during initial certification quickly becomes outdated.

Using vague or inconsistent scoring. Without clear criteria for likelihood and impact, results become subjective and difficult to defend during an audit.

Focusing only on technical risks. Human error, physical security, and third-party vendors are often overlooked, even though they represent significant sources of risk.

Failing to involve the right people. Risk assessment shouldn't sit solely with IT. Input from legal, HR, operations, and leadership leads to a far more accurate picture.

Not linking risks to controls clearly. Auditors expect to see a direct, documented connection between identified risks and the controls chosen to address them.

Tips for a Stronger Risk Assessment

Use a consistent methodology. Whether qualitative, quantitative, or a hybrid approach, consistency makes results easier to compare and defend.

Involve cross-functional stakeholders. Different departments see different risks. Broader input leads to a more complete assessment.

Review it at planned intervals. Set a schedule, such as annually or after major changes, to keep the assessment current.

Prioritize based on business impact. Not every risk deserves the same level of investment. Focus resources where the potential damage is greatest.

Keep documentation audit-ready. Maintain clear records that show your reasoning, not just your conclusions.

Take the Next Step

An ISO 27001 risk assessment sets the direction for your entire information security program. Getting it right from the start saves time, reduces wasted effort, and makes certification far smoother.

Sign up today and get access to risk assessment templates and expert guidance built specifically for ISO 27001, so you can identify what matters most and build your security program on solid ground. Discover our ISO Risk Management Tool


View ISMS Templates, Forms and Examples


Get Started Free
Create your first Incident Report form or choose from our form templates and start recording incidents in the field