ISO 27001 risk assessment, explained step by step: how to find what could go wrong, score it, and turn it into the control decisions the rest of your ISMS depends on.
TL;DR
The risk assessment is the engine of ISO 27001. You identify what could go wrong with the information you hold, score each risk by likelihood and impact, and record it all in a risk register. Those results decide which Annex A controls you implement.
Get it right and everything downstream, the Statement of Applicability, the controls, the audit, follows logically. Skip it or fake it, and the whole ISMS rests on nothing.
On this page
ISO 27001 risk assessment: why it is the engine of the whole standard
Almost every other part of ISO 27001 flows from the risk assessment. It decides which controls you need, justifies your Statement of Applicability, and gives the auditor the logic behind your entire security programme. A risk assessment is the process of working out what could go wrong with the information you hold, how likely it is, and how much it would hurt.
The five-step process
A sound risk assessment follows a repeatable sequence. You do not need enterprise software to run it, but you do need to run it honestly.
Identify assets
- What information and systems you hold
- Customer data, code, infrastructure
Identify threats
- What could compromise each asset
- Breach, loss, misuse, outage
Score likelihood and impact
- How probable, how damaging
- A simple scale is fine
Prioritise
- Rank by combined risk score
- Focus effort where it matters
The risk register
The output of the assessment is a risk register: a living record of each identified risk, its score, its owner, and what you plan to do about it. The register is what you carry into the risk treatment stage and what the auditor will review to see that your process is real and maintained.
From risk to treatment
Identifying risk is only half the job. For each risk you decide how to treat it: reduce it by applying a control, accept it, avoid it by stopping the activity, or transfer it, for example through insurance. Those decisions become your risk treatment plan, which in turn drives your Statement of Applicability.
Mistakes to avoid
- Using a generic template unchanged. A risk assessment that does not reflect your actual business convinces no one.
- Over-engineering the scoring. A clear, simple scale beats an elaborate model nobody maintains.
- Assessing once and forgetting. A stale register fails at the surveillance audit.
- Skipping asset identification. You cannot assess risk to assets you have not listed.
The lean-team path to a real risk assessment
The assessment itself is analytical work, but treating the risks depends on controls that actually run, and evaluating them depends on visibility into your systems. When your security is scattered across tools, seeing your real risk picture and proving you have treated it is far harder.
Turn your risk register into controls that run.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Treat the risks you identify with controls that actually operate, evidenced from one platform and mapped to ISO 27001. No security team required.
Frequently asked questions
What is an ISO 27001 risk assessment?
It is the process of identifying what could go wrong with the information you hold, scoring each risk by likelihood and impact, and recording the results in a risk register. Those results decide which Annex A controls you implement.
How do I run an ISO 27001 risk assessment?
Identify your assets, identify the threats to each, score likelihood and impact, prioritise by combined risk, and record everything in a risk register. Then decide how to treat each risk, which drives your Statement of Applicability.
What is a risk register?
A living record of each identified risk, its score, its owner, and the planned treatment. It is the main output of the risk assessment and a document auditors review to confirm your process is real and maintained.
How is risk assessment linked to control selection?
Directly. Annex A is a menu of 93 controls; the risk assessment tells you which to select. Every control you include should trace back to a risk, and that logic is recorded in the Statement of Applicability.
How often should I redo the risk assessment?
Revisit it on a schedule and whenever something material changes, a new system, new data types, or a new threat. A stale assessment and register are common causes of findings at the surveillance audit.

