← Insights

Information security

An ISO 27001 risk assessment that holds up to audit

July 2026 · 6 min read

A generic risk register will not survive an ISO 27001 audit, and the reason is structural. A general risk list starts with risks. An information security risk assessment starts with assets - the information and the systems that hold it - and works outward from there. Assessors know the difference on sight, and a register that skips the asset step is the fastest way to a nonconformity.

The good news is that the method is entirely learnable, and once the shape is right the work becomes mechanical. Here is the shape.

Start from assets, not risks

List the information assets in scope: customer databases, source code, the finance system, employee records, the laptops and cloud services that hold them. For each, rate its confidentiality, integrity and availability - the CIA triad. A public marketing brochure scores low on confidentiality; a payroll database scores high on all three. Those ratings give each asset a value, and the value tells you where to spend your attention. You cannot assess a risk to something you have not first identified as worth protecting.

Describe risk as a threat against a vulnerability

This is the phrasing that reads as competent. A risk is not "the database". A risk is a threat exploiting a vulnerability against a named asset. "An attacker (threat) exploits an unpatched server (vulnerability) to access the customer database (asset)." Written this way, the risk is specific enough to score and specific enough to treat. Vague risks produce vague controls; precise risks produce precise ones.

Score it twice: inherent, then residual

Here is the step that separates a real assessment from a checkbox. You score each risk on a 5x5 grid of likelihood against impact - twice.

The gap between the two numbers is the visible value of your security programme. A risk that drops from a red 20 inherent to a green 4 residual proves the control is earning its keep. A risk that barely moves tells you the control is weak or absent. Scoring once hides all of this; scoring twice makes the effectiveness of your controls a number a board and an assessor can both read.

Inherent risk shows the size of the problem. Residual risk shows what your controls actually bought you. An auditor wants to see both.

Choose one of four treatment options

For every risk, you make a decision, and there are only four options - often taught as the four Ts.

The decision is not the assessor's business to second-guess, but the record of the decision very much is. An accepted risk with no owner and no rationale is a finding waiting to happen.

Map every risk to an Annex A control and the SoA

The final connection is what ties the assessment into the wider management system. Each risk you decide to treat should point to the Annex A control that treats it - access control, cryptography, supplier security, and so on. Those same controls are the ones you have marked as applicable on your Statement of Applicability. So the chain runs: asset, to risk, to treatment decision, to Annex A control, to the SoA, to the policy that implements it. When an auditor picks any risk and asks "so what are you doing about this?", you can walk them along that chain without pausing. That traceability, more than any single score, is what makes a risk assessment hold up.

Run it as a live document, not a launch-day artefact. Re-score when a control changes, when a new asset appears, or after an incident - and the residual column keeps telling you the truth about where you stand.

The ISO 27001 way, built in

Assets with CIA ratings, risks as threat plus vulnerability, scored 5x5 inherent and residual, Annex A mapping and the four treatment options - with a live residual heatmap and top-risk list. A framework to organise your own assessment, not legal advice or certification.

Get the ISO 27001 Risk Register on Etsy

Never miss a guide

New articles and templates, straight to your inbox. Plus a free tool to start.

By subscribing you consent to receive emails from Axiom. Your address is stored with Kit, our email provider, and never shared. Unsubscribe any time via the link in every email. Privacy policy.