
ISO 27001 Risk Assessment Review
Your ISO 27001 risk assessment should be more than a document created for certification
It should help your organisation understand where information security risks exist, how serious those risks are, which controls are needed, and what actions should be taken to reduce unacceptable risk.
In practice, many ISO 27001 risk assessments become static. They are created during implementation, reviewed briefly before audits, and then left largely unchanged while the business moves on. Systems change, suppliers change, staff change, services change, customers ask new questions, and the threat environment continues to develop.
ID Risk and Compliance provides ISO 27001 risk assessment reviews to help organisations check whether their information security risk assessment remains current, useful and audit-ready.
Why the ISO 27001 risk assessment matters
Risk assessment is central to ISO 27001.
It informs the risk treatment plan, the Statement of Applicability, the selection of Annex A controls, management review discussions, internal audit priorities and continual improvement activity.
If the risk assessment is weak, outdated or poorly connected to the rest of the ISMS, the whole management system can become less effective.
For example, the business may have selected controls that no longer match its actual risks. Risk treatment actions may remain open for too long. New cloud services may have been introduced without being assessed. Supplier risks may have changed. Access control risks may have increased because of staff turnover or remote working. Incident trends may not have been reflected in the risk register.
A risk assessment review helps identify these issues before they become audit findings or real operational problems.
Common problems with ISO 27001 risk assessments
A common problem is that the risk assessment is too generic.
It may use standard risks copied from a template, but not properly reflect the organisation’s services, systems, people, suppliers, data, customers or working practices.
Another issue is that risks are not clearly linked to treatment decisions. A risk may be recorded as high, but the actions needed to reduce it are unclear. Alternatively, a control may appear in the Statement of Applicability without a clear link back to the risk assessment.
Some risk assessments are also too complicated. They contain too many low-value risks, unclear scoring rules, duplicated entries, vague controls and action plans that are difficult to manage.
Other common issues include outdated risk scores, missing risk owners, weak treatment plans, no review of completed actions, no consideration of supplier or cloud risks, and no clear link between incidents, changes and risk updates.
An independent review can help make the risk assessment more practical and reliable.
What an ISO 27001 risk assessment review includes
An ISO 27001 risk assessment review can be tailored around the maturity of your ISMS and the type of audit or review you are preparing for.
The review may include checking your risk assessment methodology, reviewing how risks are identified and scored, assessing whether risk owners are clear, checking whether risk treatment actions are defined, reviewing links to the Statement of Applicability, checking whether Annex A controls have been selected logically, and identifying whether the risk register reflects current business activity.
It can also include a review of whether recent changes have been considered. This may include new systems, new suppliers, new locations, new services, new customers, staff changes, incidents, vulnerabilities, audit findings or changes in legal, contractual or regulatory expectations.
The aim is to check whether the risk assessment supports real decision-making, not just whether it exists.
Reviewing the risk assessment methodology
ISO 27001 expects the organisation to define and apply an information security risk assessment process.
That process should include clear criteria for assessing risks, evaluating risk levels and deciding what needs to be treated.
If the methodology is unclear, inconsistent or too complex, the risk assessment can become difficult to apply. Different people may score risks differently, risk treatment decisions may be hard to justify, and the business may struggle to explain its approach during an audit.
A risk assessment review can check whether your methodology is clear, proportionate and consistently applied.
This includes reviewing how likelihood and impact are defined, how risk levels are calculated, how acceptance criteria are set, how treatment decisions are made, and how reviews are triggered when the business changes.
Checking risk treatment actions
The risk treatment plan should show how unacceptable risks are being addressed.
This may involve applying controls, improving existing controls, transferring risk, avoiding risk or accepting risk where justified.
A common issue is that risk treatment actions are vague. For example, an action may say “improve access control” without explaining what needs to happen, who owns the action, when it is due, or how completion will be evidenced.
Another common issue is that treatment actions remain open for long periods without review.
ID Risk and Compliance can review whether your risk treatment actions are clear, realistic, assigned, tracked and supported by evidence. This helps make the risk assessment more useful and improves audit readiness.
Linking risk assessment to the Statement of Applicability
The Statement of Applicability should not sit separately from the risk assessment.
It should reflect the controls selected as part of risk treatment, along with any controls required by legal, contractual, business or interested party requirements.
If the risk assessment and SoA are not aligned, auditors may question how control decisions were made.
A risk assessment review can check whether this link is clear. It can identify where risks suggest a control should apply, where controls are included without a clear reason, or where exclusions may need stronger justification.
This is particularly important for ISO 27001:2022, where organisations need to demonstrate a clear and considered approach to Annex A control applicability.
Keeping risk assessment current
Information security risks change as the business changes.
A risk assessment should be reviewed when significant changes occur, not just once a year before an audit.
Relevant changes might include new software, new cloud platforms, new suppliers, outsourcing, changes in remote working, new types of data, new customer requirements, business growth, staff turnover, security incidents, vulnerability findings, new legal obligations or changes in operational processes.
A review can help determine whether your current risk assessment reflects these changes properly.
This is especially useful for organisations that have grown quickly, inherited an ISO 27001 system, changed IT providers, or introduced new services since certification.
Supporting ISO 27001 audit readiness
External auditors often review the risk assessment closely because it drives the rest of the ISMS.
They may ask how risks were identified, how likelihood and impact were assessed, how treatment decisions were made, how actions are tracked, how controls were selected, and how the risk assessment is kept up to date.
If the risk assessment is unclear or poorly maintained, this can create problems during certification, surveillance or recertification audits.
An independent risk assessment review helps identify weaknesses before the audit. It gives the organisation time to update the risk register, clarify treatment actions, strengthen evidence and improve links to the Statement of Applicability.
Who this service is for
An ISO 27001 risk assessment review is suitable for organisations preparing for certification, organisations already certified to ISO 27001, and businesses that want an independent view of whether their ISMS risk process is still suitable.
It is particularly useful if your risk assessment has not been reviewed recently, if your business has changed since certification, if risk treatment actions are unclear, if your Statement of Applicability does not clearly link to your risks, or if your next external audit is approaching.
It may also be useful where the original ISO 27001 implementation was template-led and the organisation now wants to make the system more practical and specific.
How ID Risk and Compliance can help
ID Risk and Compliance provides practical ISO 27001 risk assessment review support for organisations that need clarity, challenge and audit readiness.
We can review your methodology, risk register, scoring approach, treatment actions, ownership, evidence and links to the Statement of Applicability.
Our approach is proportionate and commercially realistic. We focus on helping you maintain a risk assessment that reflects your actual business, supports better decisions and stands up to audit scrutiny.
Call to action
Need an independent review of your ISO 27001 risk assessment?
ID Risk and Compliance can help you check whether your risk register, treatment actions and control links are current, clear and audit-ready.
Contact us to discuss an ISO 27001 risk assessment review for your organisation.
