ISO/IEC 27001 · Clause 6.1.2 and 6.1.3
ISO 27001 Risk Assessment Template
A working guide to the three documents a risk assessment actually needs: what each has to say, the 4 clauses people get wrong with real wording, what an auditor checks, and the failure modes that turn a register into a finding.
Rather not write them yourself? Have these documents generated in your branding instead - the signup credits cover the first one. Card required; no charge today.
The guide
How to write an ISO 27001 risk assessment
- 14
- sections the document needs
- 4
- wordings people reliably get wrong
- 7
- things an auditor asks to see
- a week
- to write it yourself
An ISO 27001 risk assessment is not one document. It is three that have to agree with each other: a Risk Management Policy that sets the commitment and the risk appetite, a Risk Assessment and Treatment Methodology that defines the repeatable method, and an Information Security Risk Register that records what the method found and what was done about it.
Clauses 6.1.2 and 6.1.3 require the method and the treatment; clauses 8.2 and 8.3 require the records that show you ran it. The method is the document this guide teaches, because it is the one that decides whether the other two hold together: the policy states an appetite, the register applies it, and the methodology is where those numbers are defined.
Write it in this order - all 14 sections - because the scales, the matrix and the acceptance criteria have to agree with each other before a single risk is rated. The 4 clauses that fail under pressure carry real wording, and why it holds up.
Get these as editable documents - your first document is free Card required; no charge today.
-
Purpose and scope
What it must contain
What the method covers, and its place among the three risk documents: this is the method, the policy is the commitment, the register is the record.
What the auditor checks
Whether the three documents describe the same process. A methodology that contradicts the policy it sits under is the fastest way to turn a document review into a deep audit.
-
Roles and responsibilities
What it must contain
Who owns the method, who owns each risk, and who approves the criteria and accepts residual risk - by role, not by person.
What the auditor checks
That approval sits with someone senior enough to accept the consequence, and not with the person who performed the assessment. Separation here is the point.
Wording that works Approval of this methodology and of the risk acceptance criteria rests with [approver role], who also formally accepts any residual risk that remains above appetite. Approval sits with a role senior enough to accept the consequence, and not with the person who performed the assessment.
It names the separation explicitly rather than leaving it implied, which is what an auditor is looking for when they ask who signed off.
-
The likelihood scale
What it must contain
Five levels, each with a definition rather than a bare number, rated over a stated time horizon and against the controls actually in place.
What the auditor checks
Whether two people would rate the same risk the same way. A scale of 1 to 5 with no definitions is the most common reason two assessors disagree.
-
The consequence scale
What it must contain
Five levels defined in terms of real harm - cost, disruption, regulatory exposure and harm to individuals - not adjectives alone.
What the auditor checks
That the scale covers harm to people and not only harm to the business. An assessment that only counts cost misses the consequences a regulator cares about.
-
The risk matrix and score bands
What it must contain
How likelihood and consequence combine into a score, the matrix that maps every combination to a band, and the score range each band covers.
What the auditor checks
Internal consistency, cell by cell. Every cell's label has to agree with the bands the document itself defines, and a matrix that contradicts its own bands is a finding an auditor can see in seconds.
Wording that works Multiply likelihood by consequence, both rated 1 to 5. Read the band off the matrix below. The same matrix is used for the inherent risk, before any control, and again for the residual risk after the chosen treatment is in place.
One sentence fixes the two things people get wrong: how the score is produced, and that the same scale is applied twice rather than once.
-
Risk acceptance criteria
What it must contain
What each band obliges you to do: which risks must be treated, which are monitored, which may be accepted, and who may accept them.
What the auditor checks
This is the clause 6.1.2 a) requirement, and it is checked directly. Criteria that exist but are not applied consistently in the register are worse than no criteria at all.
-
Risk identification
What it must contain
Where risks come from, and the requirement to write each one as a cause, an event and an effect rather than a one-word label.
What the auditor checks
Whether the risks are specific enough to treat. "Phishing" cannot be assessed or treated; a named event with a named effect on a named system can.
Wording that works Risks are written as a cause, an event and an effect, so that they can be assessed and treated rather than merely named. "Phishing" is not a risk; "an employee is deceived by a phishing email, exposing customer records held in [system], leading to a notifiable breach" is.
It gives the reader a worked contrast rather than an instruction, which is the difference between a register of labels and a register that can be acted on.
-
Risk analysis and evaluation
What it must contain
Rating each risk for likelihood and consequence, recording the reasoning behind the rating, and comparing the result against the acceptance criteria.
What the auditor checks
That the reasoning is recorded, not just the score. A rating with no reasoning cannot be reviewed and cannot be defended once the assessor has left.
-
Risk treatment options
What it must contain
The four options - modify, avoid, share, retain - and the requirement to record which was chosen and why.
What the auditor checks
That sharing a risk is not being treated as transferring accountability. A contract or an insurance policy moves consequence, never responsibility for the information.
-
Determining controls and the Statement of Applicability
What it must contain
That controls are chosen because they treat an identified risk, then compared against Annex A to confirm nothing necessary was left out.
What the auditor checks
The direction of travel. Controls chosen from a list and reverse-justified read differently from controls chosen from risk, and clause 6.1.3 c) expects the latter.
Wording that works Controls are chosen because they treat an identified risk, not because they appear on a list. Once the necessary controls are determined, they are compared against Annex A of ISO/IEC 27001:2022 to confirm that nothing necessary has been left out.
It states the order explicitly, which is the single sentence that separates a real methodology from a template that assumes the control set came first.
-
Residual risk and approval
What it must contain
Re-rating the risk after treatment using the same scales, and recording both the risk owner's approval of the plan and the acceptance of what remains.
What the auditor checks
Both approvals, because clause 6.1.3 f) requires both. A treatment plan approved with no residual acceptance recorded is an incomplete record.
-
The risk register
What it must contain
That every risk, treated or accepted, is recorded in one place with its whole lifecycle in a single row.
What the auditor checks
That the register and the methodology agree. A register scored on a scale the methodology does not define is the contradiction most often found in practice.
-
When the assessment is repeated
What it must contain
The scheduled cycle, plus the change triggers that require a risk to be reassessed before the next cycle comes around.
What the auditor checks
Evidence it was actually repeated. A register whose last change predates a migration, a restructure or an incident has stopped describing the organization.
-
Records and review
What it must contain
What the process produces, how long it is kept, and when the method itself is reviewed and re-approved.
What the auditor checks
That changes to the scales or the acceptance criteria were approved before they were used, not afterwards.
Two documents sit either side of this one. The Risk Management Policy above it carries the commitment, the risk appetite and who may accept a risk; it is short, and it is approved at a level above the person running the assessment. The Information Security Risk Register below it is the record: one row per risk, carrying the whole lifecycle from the inherent rating through to the residual one. Neither is worth writing before the method they depend on exists.
Get these as editable documents - your first document is free Card required; no charge today.
At audit
What an auditor actually checks
Nobody is asked to demonstrate that they take risk seriously. You are asked how a rating was arrived at, who accepted what, and when it last changed. These 7 requests cover most of what the risk section of an audit consists of.
- Show me your risk assessment methodology.
-
Satisfies One current, approved document defining scales, a matrix, acceptance criteria and the process - the same one the register was actually scored against.
Fails A spreadsheet of risks with no method behind it, or a method nobody can say is approved.
- How did you arrive at this rating?
-
Satisfies The likelihood and consequence definitions applied to the facts of that risk, with the reasoning recorded on the row.
Fails A number with no reasoning, or an answer that only the person who wrote it could give.
- What are your risk acceptance criteria, and who approved them?
-
Satisfies Bands with score ranges, what each obliges you to do, and a named approving role with a date.
Fails Criteria that exist in the methodology but are not followed in the register.
- Show me a risk you accepted, and who accepted it.
-
Satisfies A recorded acceptance by a role with authority to accept that consequence, with the reason and the date.
Fails An accepted risk with no named acceptor, or acceptance by the person who performed the assessment.
- How does this register relate to your Statement of Applicability?
-
Satisfies Treatments citing Annex A references, and the same decisions reflected in the Statement of Applicability.
Fails A control treated in the register but excluded in the Statement of Applicability, or the reverse.
- When did you last reassess, and what changed?
-
Satisfies A dated cycle at least annually, plus reassessments triggered by incidents, new systems or scope changes.
Fails A register unchanged since certification while the business demonstrably moved.
- Show me the treatment for this high risk being carried out.
-
Satisfies The evidence the control produces: a ticket, a completed review, a configuration, a record.
Fails A treatment marked complete with nothing showing that it happened.
Failure modes
Where risk assessments go wrong
Almost none of these are about risk. They are about three documents that were written separately and never reconciled, and a matrix nobody checked against its own bands.
-
A matrix that contradicts its own score bands
The most common defect in a downloaded methodology, and the easiest to spot. If your bands say 5 to 9 is Medium, then every cell scoring 9 has to read Medium. Check all twenty-five cells by hand after any change to the scales, because a single wrong cell undermines every rating derived from it.
-
Scales that are numbers without definitions
A 1 to 5 scale with no meaning attached produces a different answer for every assessor, which is the one thing a methodology exists to prevent. Define each level in terms someone outside security can apply, and state the time horizon likelihood is judged over.
-
Rating the risk you wish you had
Likelihood is judged against the controls actually in place today, not the ones in the treatment plan. Rating the intended state produces a register where nothing looks urgent and the treatment plan has no reason to exist.
-
Choosing controls first and finding risks to justify them
Clause 6.1.3 expects controls to be determined from risk, then compared against Annex A to check nothing was missed. A register that reads as a reverse-engineered justification of a control set you already bought is visible to an experienced auditor within a few rows.
-
Treating "share" as making the risk someone else's problem
Insurance and contracts move consequence. They never move accountability for your information. A shared risk still needs an owner, a residual rating and a monitoring arrangement.
-
Never recording residual risk
Recording the inherent rating and the treatment but not re-rating afterwards leaves no evidence the treatment worked, and no basis for the acceptance clause 6.1.3 f) requires. Rate it twice with the same scale, and the effect of the treatment becomes visible.
-
A register that stops moving
The risk assessment is the ISMS document most sensitive to change. Reviewed only before an audit, it stops being a management tool and becomes a snapshot of the year you were certified. Reassess on the triggers, not just on the calendar.
From template to audit-ready
Where the risk assessment fits in ISO 27001
The risk assessment is not one clause among many; it is the engine the rest of the standard runs on. Clause 6.1.2 requires a defined process with risk criteria you set in advance, applied consistently. Clause 6.1.3 requires you to determine the controls needed to treat what you found, then compare that set against Annex A to confirm nothing necessary was left out - and that comparison is what produces the Statement of Applicability. Clauses 8.2 and 8.3 then require the records showing the process was actually performed and the treatment actually carried out.
That direction matters more than any other detail on this page. Controls chosen from risk, then checked against Annex A, is what the standard asks for. A control set chosen first and reverse-justified reads differently, and an experienced auditor sees it within a few rows of the register.
Three documents, however good, are still three documents. Certification needs a whole consistent set: a Statement of Applicability recording a decision for every control, and the topic policies your controls require, each mapped to what it satisfies. See what a certifiable ISO 27001 documentation set contains, and the information security policy template that sits above all of it.
See the real output
What PolicyMint generates
Same structure as the guide, with none of the decisions left to you: scales defined in your terms, a matrix whose every cell agrees with the bands beneath it, acceptance criteria set to your appetite, and a register laid out to carry each risk from inherent rating to residual. It cites the clauses it satisfies, carries your branding, and exports to Word, PDF or Excel. The cover in the hero and the body page below are exactly that output, generated for an example company.
Side by side
Writing them yourself vs generating them
Both routes end with the same three documents. What differs is how many of the decisions inside them you make alone, how much reconciling you do between them, and who checks the result before an auditor does.
Scroll the table sideways to compare both routes.
| Dimension | Writing them yourself | Generating them with PolicyMint |
|---|---|---|
| Getting the method | The structure on this page. Scales, a matrix and acceptance criteria are yours to define, and this guide says what each has to do. | The same method, with the scales and thresholds set from your business rather than left generic. |
| Keeping the matrix consistent | Twenty-five cells to check by hand every time you change a scale. | The matrix and the bands are generated together, so they cannot disagree. |
| Identifying your risks | Yours to do, and rightly so - nobody else knows your systems, suppliers and obligations. | Same. What it cannot know is flagged in the document rather than invented. |
| Three documents agreeing | Reconcile the policy, the method and the register by hand, every time any one of them moves. | Written as a set from one profile, so the appetite in the policy and the bands in the register are the same numbers. |
| Checking it | Nobody, until an auditor. That is the expensive place to find out. | Three independent verifiers before you see it, against the standard's requirements. |
| Time and cost | A week across the three documents, plus the rework when an auditor tests a rating nobody justified. | Minutes, and your first document is free. |
Card required; no charge today. Documents in bulk, and the whole ISO 27001 set, are both on the pricing page.
- ISO 27001 documents
-
36
ISO 27001 documents
tiered by what you actually need
- ISO 42001 documents
-
21
ISO 42001 documents
for AI management systems
- Clauses and controls mapped
-
182
Clauses and controls mapped
every document cites the ones it satisfies
- Verifiers per section
-
3
Verifiers per section
on a different model to the writer
ISO 27001 risk assessment FAQ
The questions people ask
Including whether a free template is enough, what belongs in the register, and how the matrix stays consistent.
What is an ISO 27001 risk assessment?
An ISO 27001 risk assessment is not one document. It is three that have to agree with each other: a Risk Management Policy that sets the commitment and the risk appetite, a Risk Assessment and Treatment Methodology that defines the repeatable method, and an Information Security Risk Register that records what the method found and what was done about it. Clauses 6.1.2 and 6.1.3 require the method and the treatment; clauses 8.2 and 8.3 require the records that show you ran it.
Is a free risk assessment template enough for certification?
A template is a real start, and this guide is written so you can produce one without us: every section in order, the clauses people get wrong, and what an auditor checks. What no template can do is identify your risks, set thresholds that match your business, or keep three documents consistent as they change. Certification looks at the whole set and at evidence the process is live: dated reassessments, recorded reasoning, approvals by the right role. Auditors flag generic risk documents that do not match how a business runs.
What should an ISO 27001 risk register contain?
One row per risk, carrying its whole lifecycle: an identifier, the date raised, the risk written as a cause, an event and an effect, the risk owner, the inherent rating before any control, the treatment option chosen, the controls applied with their Annex A references, a due date, the residual rating after treatment, the approvals, and the current status. The register is the record required by clauses 8.2 and 8.3.
How does a risk methodology stay consistent?
By defining each level of the likelihood and consequence scales in words rather than numbers alone, by checking that every cell of the matrix agrees with the score bands the document itself defines, and by recording the reasoning behind each rating alongside the rating. Consistency is the reason the methodology exists: a method that gives a different answer depending on who ran it cannot support a defensible treatment decision.
Does the risk assessment have to map to Annex A?
Yes, in one direction. Clause 6.1.3 expects you to determine the controls necessary to treat your risks, then compare that set against Annex A to confirm nothing necessary has been left out. The comparison produces the Statement of Applicability, and the register cites Annex A references against each treatment so the two documents can be checked against each other.
What does a full ISO 27001 document set cost?
The three risk documents are part of a set. A certifiable ISO 27001 set is around 36 documents. Toolkits sell blank templates: Advisera publicly lists about A$1,300 (US$897)US$897about £660 (US$897)about €780 (US$897) one-time and IT Governance about A$760 (£395)about US$530 (£395)£395about €460 (£395) for the first year, and you still write every document yourself. PolicyMint delivers the finished set, written for your business and checked before you see it, for A$350US$229£179€209 including GST, about A$8.75US$5.73£4.48€5.23 per finished document. Your first document is free.
Stop staring at an empty document set
Set up your business once. Get the documents you actually need, written for how you really operate, in your branding, checked before you see them.
Your first document is on us. We ask for a card to begin and you are not charged for it, and there is no sales call. See pricing