ISO 27001 Risk Assessment: Methodology and Template

By July 25th, 2026ISO Audit And Certificate6 min read

ISO 27001 Risk Assessment: Methodology and Template

An ISO 27001 risk assessment is the systematic process of identifying, analysing, and evaluating information security risks to your organisation. It is the engine that drives your entire ISMS – without a robust risk assessment, you cannot select the right controls, justify exclusions, or pass certification audits. This guide covers the full methodology, step-by-step process, and includes a practical risk register template.

What Is an ISO 27001 Risk Assessment?

A risk assessment under ISO 27001 identifies threats to your information assets, evaluates the likelihood and impact of those threats, and prioritises risks for treatment. The output feeds directly into your risk treatment plan and Statement of Applicability.

The standard does not prescribe a specific methodology. This flexibility allows organisations to choose an approach that matches their size, complexity, and industry. However, the methodology must be defensible, repeatable, and documented.

ISO 27001 Requirements for Risk Assessment (Clause 6.1)

Clause 6.1 of ISO 27001 sets out specific requirements for risk assessment. Your process must:

  • Establish and maintain information security risk criteria
  • Ensure that repeated risk assessments produce consistent, valid, and comparable results
  • Identify risks associated with the confidentiality, integrity, and availability of information
  • Analyse the consequences and likelihood of identified risks
  • Evaluate risks against predefined acceptance criteria
  • Retain documented information about the risk assessment process

Risk Assessment Methodology: Qualitative vs Quantitative

There are two broad approaches to risk assessment methodology. Many organisations use a hybrid model.

AspectQualitativeQuantitative
ApproachDescriptive scales (High, Medium, Low)Numerical values (monetary loss, percentages)
Ease of useEasy to implement and understandComplex, requires data and expertise
ObjectivitySubjective, depends on assessor judgmentObjective, data-driven
Best forSMEs, first-time certifications, broad assessmentsLarge enterprises, regulated industries, financial quantification
OutputRisk matrix (e.g. 5×5 colour-coded grid)Annual Loss Expectancy (ALE), Return on Security Investment (ROSI)
Common toolsSpreadsheets, risk registers, workshop sessionsFAIR model, Monte Carlo simulation, specialised software

Step 1: Risk Identification

Identify threats, vulnerabilities, and assets that could be affected. Common sources of threats include:

  • Cyber threats: malware, phishing, ransomware, denial of service
  • Physical threats: fire, flood, power failure, theft
  • Human threats: insider threats, human error, social engineering
  • Technical threats: system failures, software bugs, network outages
  • Legal and regulatory: compliance breaches, contractual penalties

Create an asset inventory and identify which assets are in scope for your ISMS. For each asset, list the threats and existing controls.

Step 2: Risk Analysis

Analyse each risk by assessing its potential consequences and likelihood. You can assign numerical scores or use descriptive scales. A common approach is the 5×5 risk matrix:

Likelihood / ImpactInsignificant (1)Minor (2)Moderate (3)Major (4)Catastrophic (5)
Almost certain (5)510152025
Likely (4)48121620
Possible (3)3691215
Unlikely (2)246810
Rare (1)12345

Step 3: Risk Evaluation

Compare the risk level against your organisation’s risk acceptance criteria. Risks above the threshold require treatment. Define your thresholds clearly in your risk management policy:

  • Low risk (1–5): Acceptable; monitor periodically
  • Medium risk (6–12): Requires treatment within a defined timeframe
  • High risk (13–25): Immediate treatment required; may need escalation to management

Risk Treatment Options

Once risks are evaluated, you must decide how to treat them. The four options are:

OptionDescriptionExample
Risk mitigationImplement controls to reduce likelihood or impactDeploying multi-factor authentication to reduce unauthorised access risk
Risk acceptanceKnowingly accept the risk without further actionAccepting low-risk, low-impact events that are cheaper to tolerate than fix
Risk transferShift the risk to a third partyPurchasing cyber insurance or outsourcing to a managed security provider
Risk avoidanceEliminate the activity that generates the riskDiscontinuing a legacy system that cannot be secured

Risk Register Template

A risk register is the key output of your risk assessment. Below is a template structure you can adapt for your ISMS:

AssetThreatVulnerabilityExisting ControlsLikelihoodImpactRisk LevelTreatmentTarget Date
Customer databaseSQL injectionUnpatched web applicationWAF, network firewall3515 (High)Apply security patch; implement input validationQ2 2025
Email systemPhishing attackLow user awarenessSpam filter4312 (Medium)Security awareness training; deploy DMARCQ1 2025
Office server roomFireNo fire suppressionSmoke detector155 (Low)Accept (insurance covers loss)N/A
Employee laptopsTheftNo disk encryptionNone248 (Medium)Deploy full-disk encryption (BitLocker)Q1 2025
Cloud infrastructureMisconfigurationNo automated compliance checksManual review3412 (Medium)Deploy IaC scanning; implement CI/CD security gatesQ3 2025

Common Risks by Industry

The types of risks organisations face vary significantly by sector. The table below highlights prevalent risks across different industries.

IndustryCommon RisksTypical Controls
Financial servicesFraud, data breach, regulatory non-compliance, insider tradingSegregation of duties, transaction monitoring, encryption, audit logging
HealthcarePatient data breach, system availability, medical device vulnerabilitiesAccess control, backup and recovery, network segmentation
Technology / SaaSCloud misconfiguration, API abuse, supply chain compromiseVulnerability scanning, penetration testing, secure SDLC
ManufacturingOT/ICS compromise, IP theft, supply chain disruptionNetwork segmentation, physical security, vendor assessments
RetailPayment card fraud, POS malware, customer data theftPCI DSS compliance, encryption, access controls

Frequently Asked Questions

How often should I conduct an ISO 27001 risk assessment?

At least annually, or whenever significant changes occur to your organisation, systems, or threat landscape. Some organisations conduct rolling assessments quarterly for high-risk areas.

What is the difference between risk assessment and risk treatment?

Risk assessment identifies, analyses, and evaluates risks. Risk treatment is the subsequent process of selecting and implementing controls to modify the risk level. Both are required by ISO 27001 clause 6.1.

Can I use a spreadsheet for my risk assessment?

Yes. Many organisations successfully use spreadsheet-based risk registers, especially for initial certification. The key is ensuring the methodology is consistent, repeatable, and well-documented. Specialised tools become useful as the organisation grows.

Do I need to assess risks for every single asset?

Not necessarily. You can group assets into logical categories (e.g. all employee workstations, all cloud databases) and assess risks at the group level. The key is to justify your grouping approach and ensure no critical assets are overlooked.

What are risk acceptance criteria?

These are predefined thresholds that determine whether a risk requires treatment or can be accepted. They should be documented in your risk management policy and approved by top management.

Does the risk assessment need to cover third-party suppliers?

Yes, if suppliers process or access your information assets. Supplier-related risks must be included in your risk assessment scope, and controls such as supplier agreements, audits, and NDAs should be considered.

Start Your ISO 27001 Risk Assessment

A well-executed risk assessment is the foundation of a successful ISMS. Whether you are starting from scratch or refining an existing process, the key is to keep it practical, documented, and aligned with your business context.

Need help building your ISO 27001 risk assessment framework? Contact Bitrixme today or send us a message on WhatsApp to speak with an ISO 27001 specialist.