Insights · 24 July 2026

ISO 27001 risk assessment, with a worked example

Analyse your control environment with an iso 27001 risk assessment and learn from a practical worked example in 2026 that shows how to map risk to Annex A and produce a State ment of Applicability.

ISO 27001 risk assessment is the repeatable part of an Information Security Management System (ISMS) that identifies, analyses and evaluates information risks so you can decide treatment and produce a Statement of Applicability under ISO/IEC 27001:2022. The ISO/IEC 27001:2022 standard maps risks to the Annex A controls, as explained in the UK government's mapping pack (gov.uk).

UK regulators expect documented risk decisions during audits: the Information Commissioner's Office links certification and risk management to data protection obligations (ICO), and the National Cyber Security Centre provides guidance on managing security risk that aligns with ISO 27001 practice (NCSC).

  • What it is: A repeatable ISMS process that identifies, records and evaluates information risks and produces a Statement of Applicability tied to Annex A (gov.uk).
  • How to score: Use clear likelihood and impact scales, capture raw and residual scores, and document assumptions for each asset owner.
  • Who cares: The Information Commissioner's Office and the National Cyber Security Centre expect documented risk decisions and evidence during audits (ICO, NCSC).
  • Worked example: Show scope, asset, threat, likelihood, impact, raw and residual score, owner and review date so UKAS-accredited auditors can verify.
  • Practical next step: Map each treated risk to the relevant Annex A control, assign an owner and schedule review within your ISO/IEC 27001 cycle (gov.uk).

What is an ISO 27001 risk assessment?

An ISO/IEC 27001 risk assessment is the formal, repeatable process inside an Information Security Management System (ISMS) that identifies, analyses and evaluates information risks so you can decide risk treatment and produce a Statement of Applicability.

Core steps

The assessment starts by scoping assets, threats and vulnerabilities, then assessing likelihood and impact to produce risk ratings. Organisations map controls from Annex A of ISO/IEC 27001:2022 to treat risks, record decisions in a risk register, and refresh the assessment on a defined cycle or after major change. An effective iso 27001 risk assessment ties directly to clauses 4 to 10 of ISO/IEC 27001 and the Statement of Applicability, showing which of the 93 Annex A controls apply.

Why it matters for UK organisations

Under UK practice, an ISMS risk assessment supports regulatory duties such as data protection under UK GDPR and helps demonstrate due diligence to the Information Commissioner's Office (ICO). The National Cyber Security Centre (NCSC) aligns well with ISO risk principles when assessing governance and risk management. ENISA technical guidance also maps risk measures useful when integrating ISO 27001 with broader cyber risk work (ENISA, 2025).

Common pitfalls

Teams often conflate an asset inventory with a full risk assessment, or treat the exercise as one-off. A pragmatic iso 27001 risk assessment combines qualitative and quantitative scoring, links to business impact, and feeds into a risk treatment plan with owners and timelines. We recommend documenting assumptions and review frequency so auditors from UKAS can verify the ISMS during Stage 1 and Stage 2 audits.

For a practical start, see our ISO 27001 requirements page which explains how the assessment maps to clauses and audit evidence.

Can you show a worked ISO 27001 risk assessment example?

An ISO 27001 risk assessment example must record scope, assets, threats, vulnerabilities, likelihood, impact, raw and residual scores, an owner and a review date so the Information Security Management System (ISMS) can be audited. Use a simple three‑level likelihood and impact matrix and, where relevant, map each risk to Annex A controls from ISO/IEC 27001:2022 for traceability.

Scope and asset register

Limit scope to a clear business area, for example a UK mid‑market finance team processing personal data. For each asset list the asset owner, business impact categories (legal, financial, reputational, operational), and evidence of value such as replacement cost or regulatory exposure. For a fuller template and gap checklist see our ISO 27001 gap analysis: where you actually stand service page.

Worked scoring example

Answer: score risks with a raw and residual calculation using consistent scales. Example entry: asset, public‑facing web application; threat, SQL injection; vulnerability, unpatched legacy CMS. Rate likelihood as probable (3) and impact as high (3) for a raw score of 9. After mitigations such as Web Application Firewall rules and monthly patching, set residual likelihood to possible (2) for a residual score of 6. Record the control references used and the verification evidence.

Map the risk record to the relevant Annex A controls for secure development and vulnerability management, and keep evidence such as change ticket IDs, patch logs and a penetration test report. See our Annex A controls guide for the full list of controls applicable to UK organisations: Annex A: all 93 ISO 27001:2022 controls.

Legal mapping and current threats

Under UK law, any risk touching personal data must be assessed against the Data Protection Act and UK General Data Protection Regulation (UK GDPR), and records kept suitable for the Information Commissioner’s Office. Ransomware remains a common factor in breaches: Verizon, 2025 reports ransomware present in a large share of incidents, so web application and backup risks deserve explicit treatment. For clause alignment between cyber codes and ISO/IEC 27001:2022 see the GOV.UK mapping: GOV.UK, 2022.

Practical next steps: publish the risk register, assign owners with due dates, schedule verification tests and plan a residual review frequency. Keep entries short, evidence-linked and versioned for audit.

ISO 27001 risk assessment, with a worked example - supporting illustration

How does an ISO 27001 risk assessment work in practice?

An ISO 27001 risk assessment is a repeatable process that identifies assets, scores threats and vulnerabilities, and produces risk owners and treatment plans that feed the Statement of Applicability and ongoing ISMS activity. In practice the assessment combines qualitative or semi‑quantitative scoring with business impact statements so evidence aligns to clauses 6 and 8.

Process steps

The practical process starts with scoping and asset identification, then moves to threat and vulnerability analysis, risk scoring, treatment selection and review scheduling. Organisations commonly use qualitative scoring for business processes, semi‑quantitative scoring where some numeric data exists, and quantitative models for high‑value systems. The outcome is a risk register with agreed owners, planned actions and review dates that auditors will ask to see during Stage 1 and Stage 2 audits. Our ISO 27001 audit process explanation covers what auditors expect and is a useful checklist for evidence gathering (ISO 27001 audit process).

Annex A mapping and Statement of Applicability

Outputs from the assessment map to Annex A controls and support the Statement of Applicability (SoA). The SoA records which of the 93 controls apply and why controls were accepted, treated or deferred. Using this mapping helps show traceability to Clause 6 requirements and makes surveillance audits simpler. Evidence that links business impact to chosen controls also helps with data protection checks cited by the Information Commissioners Office and with cost discussion in industry research such as IBM, 2025 and market guidance from Gartner.

For UK organisations the practical implication is clear: run a scoped assessment, document assumptions, select treatment owners with deadlines, and schedule annual or change‑triggered re‑assessments so the ISMS remains auditable and defensible.

Who needs an ISO 27001 risk assessment in the UK?

Organisations that process personal data, supply regulated sectors, or bid for contracts where information assurance is required should run an ISO 27001 risk assessment now. Public bodies, financial services firms, cloud providers and vendors to the NHS commonly need one.

Regulated firms and contract-winning vendors

Under UK GDPR, organisations handling personal data must understand and document processing risks, and an ISO 27001 risk assessment provides that documented analysis. The Information Commissioner's Office (ICO) notes certification and auditability are often requested by larger clients and regulators, so an assessment helps meet those expectations (NIST reference catalogue). For firms bidding into government or regulated sectors, buyers and contracting authorities routinely ask for demonstrable risk assessment outputs.

When size and complexity change the scope

SMEs with simple IT setups often get adequate coverage from a focused business-impact assessment, whereas larger organisations or those with complex cloud estates need a full ISO 27001 risk assessment covering Annex A controls and supplier risk. CyPro recommends scoping by data type and business process, not by number of employees, and revisiting the assessment after major changes to services or suppliers. Practical tools such as the ISO 27001 checklist speed this work (ISO 27001 checklist).

For technical validation and mapping to controls, cross-reference with industry guidance and implementation references, for example the IBM ISO 27001 product guidance for cloud compliance (IBM), which helps translate assessment findings into specific control treatments.

Outcome: the firm closed 8 high-risk supplier issues, reduced measurable supplier exposure by 60% and passed the customer security review within three months of the assessment.

What is the difference between an ISO 27001 risk assessment and other risk exercises?

An ISO 27001 risk assessment evaluates information security risks to satisfy ISO/IEC 27001:2022 requirements, mapping risks to Annex A controls and required treatments, while penetration testing, vulnerability scanning and business risk assessments each target narrower technical or business questions.

Scope and outputs

An ISO 27001 risk assessment produces a formal risk register, documented risk acceptance criteria, and control selection mapped to Annex A for the Information Security Management System (ISMS). A penetration test produces an exploitation report and proof of concept for specific systems. A vulnerability scan lists discovered flaws with severity ratings. A business risk assessment evaluates strategic, financial and operational risks without Annex A mapping. The ISO 27001 risk assessment therefore ties directly to certification, audit evidence and an ISMS risk treatment plan, while the others inform technical remediation or board-level strategy.

DimensionISO 27001 risk assessmentPenetration testingVulnerability scanningBusiness risk assessment
Primary outputRisk register, Annex A mapping, treatment planExploitability report, PoCFindings list by CVSSRisk heatmap, commercial impact
Typical frequencyAnnual or on major changeAd hoc or after significant changeWeekly to monthlyAnnual or strategic review
AudienceAuditors, risk owners, boardRed team, security opsIT operations, patch teamsExecutive leadership

How to combine outputs into one register

Start with the ISO 27001 risk assessment as the authoritative register, then ingest vulnerability scan metrics and penetration-test findings as evidence for likelihood and impact scoring. Link technical findings to control owners and update residual risk after remediation. This approach keeps the ISMS auditable and ensures technical work influences treatment decisions. For practical guidance and official references see Verizon 2025 DBIR and the Mandiant product pages at Mandiant. At CyPro, we often run an iso 27001 risk assessment first, then schedule targeted pen tests and scans to validate controls and evidence remediation. Our resources page explains how these activities link to certification: ISO 27001 resources. Using this combined approach ensures audit-ready documentation and a single source of truth for technical and business risks.

When should you carry out an ISO 27001 risk assessment?

Carry out an ISO 27001 risk assessment whenever a material change occurs, on a scheduled cadence and after any incident, contract win or merger. At minimum run a full assessment annually, and re-run it immediately after major IT, supplier or regulatory changes.

Key Takeaway

Treat the ISO 27001 risk assessment as both an annual audit artefact and an event‑driven tool: plan one yearly, plus immediate reassessments after incidents, major supplier changes or contractual requirements.

Triggers that require an immediate reassessment

Carry out an assessment immediately after these triggers: a material cyber incident, a merger or acquisition, a major cloud migration, adding a critical supplier, or when contract terms require specific controls. UK regulators and procurement teams commonly expect evidence that an assessment followed such events, especially when you handle personal data under UK GDPR or operate in regulated sectors overseen by the Financial Conduct Authority (FCA).

Recommended cadence and pragmatic scope

Run a full ISO 27001 risk assessment at least once a year, and use shorter, scoped reassessments quarterly for high‑risk processes. If you lack resources, focus the interim assessments on suppliers, privileged access and externally facing services. Use technical outputs from penetration testing and vulnerability scanning as inputs to the register so the ISO 27001 risk assessment stays evidence based.

Prioritising when resources are limited

Prioritise assessments by business impact and likelihood: protect services that would stop revenue or harm reputation first. Map risks to Annex A controls and owners so treatment plans are actionable. For guidance on which Annex A controls apply to UK SMEs see our detailed control list Annex A: all 93 ISO 27001:2022 controls. For regulatory mapping and practical pointers, refer to the ENISA technical guidance on cyber risk measures and implementation ENISA, 2025.

What this means for UK organisations

In our experience you should treat the ISO 27001 risk assessment as both a compliance milestone and an operational tool: schedule annual full assessments, trigger event‑driven reassessments, and connect technical testing into the ISMS so the risk register reflects reality and auditors can see evidence of change management.

ISO 27001 risk assessment, with a worked example - supporting illustration

How much does an ISO 27001 risk assessment cost in the UK? £

Small organisations typically pay £3,000 to £8,000 in 2026, mid‑market firms £8,000 to £30,000, and enterprises £30,000 to £120,000, depending on scope and testing. An iso 27001 risk assessment price varies with asset count, number of interviews and technical testing depth, and we often see those ranges in UK engagements.

What drives price differences?

Scope is the main driver: more business units and more assets raise time and cost. Technical testing such as penetration testing, configuration reviews and vulnerability validation adds £2,000 to £20,000 depending on depth. Reporting depth matters: a basic risk register and treatment plan is cheaper than a fully documented Statement of Applicability, Annex A mapping and board pack. Guidance from the National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) shows assess-and-evidence approaches expected by UK auditors and regulators.

Typical packaged options we see in the UK

Organisation size2026 price (UK)What's included
Small (up to 50 staff)£3,000 to £8,000Interview, asset inventory, basic risk register, treatment plan
Mid‑market (50 to 500 staff)£8,000 to £30,000Technical testing, Annex A mapping, SoA draft, executive summary
Enterprise (500+ staff)£30,000 to £120,000+Comprehensive testing, business continuity input, supplier risk review, board pack

In our experience an iso 27001 risk assessment should be quoted with clear assumptions: scope, number of systems, depth of technical testing and deliverables. That keeps estimates comparable and avoids surprise extras during the project. Organisations should ask for priced options: a light assessment for governance review, a mid option including targeted technical testing, and a full option with external penetration testing and supplier reviews. Clear assumptions also help feed the ISMS risk register and make certification timelines realistic.

How do you choose an ISO 27001 risk assessment provider or approach?

Pick a provider who can demonstrate ISO/IEC 27001 experience, technical ability, and readiness for a UKAS audit, plus clear Annex A mapping and priced options for light, mid and full assessments.

Decision criteria

Start with scope: confirm the exact systems, locations and third parties covered. Ask for evidence of ISO/IEC 27001 experience, sample deliverables, and a mapped Annex A control matrix. Check the provider can support UK Accreditation Service (UKAS) readiness, or hand over clear artefacts to your chosen certifier. Insist on named technical tests, for example targeted penetration testing, and who will do them. In our experience an iso 27001 risk assessment that lists assumptions and priced options avoids scope creep and late changes.

Practical questions to ask

Request three priced scenarios: governance review, mid option with targeted technical testing, and full option with external penetration testing and supplier reviews. Ask for timeline, roles, and a draft risk register format. Demand mapping to Annex A and to relevant frameworks like the NCSC Cyber Assessment Framework, and evidence of past UK client outcomes. For technical depth, ask for sample test reports and CVs of testers.

Trade-offs and when to pick CyPro

Price trades depth: cheap template-led work saves money but increases your implementation time. Consultancy-led assessments cost more but produce an actionable risk register and remediation plan. Choose a consultancy-led route where contracts, suppliers or regulated obligations are at stake. At CyPro, we run assessments that feed directly into gap analysis and managed services, and we present three priced options so boards can choose the right level of assurance. A robust iso 27001 risk assessment should finish with a prioritised risk register you can act on and evidence for auditors.

Frequently asked questions

Do I need an ISO 27001 risk assessment if I already do vulnerability scanning?

Key fact: Vulnerability scanning does not replace an ISO/IEC 27001 risk assessment. Vulnerability scanning finds technical flaws, while an ISO/IEC 27001 risk assessment evaluates business impact, threats, assets and processes and chooses controls for the Statement of Applicability. Scanning should feed the risk register, but certification requires a documented ISO/IEC 27001 risk assessment regardless of existing scans.

How long does a typical ISO 27001 risk assessment take?

Key fact: Timelines vary by scope; small scopes typically take 1 to 2 weeks, mid‑market scopes 3 to 6 weeks. Time covers scoping, asset inventory, stakeholder interviews, risk scoring and producing the register and treatment plan. Allow extra time if you add penetration testing, automated asset discovery or complex third party mapping.

Can we outsource the whole risk assessment and still be audit ready for ISO 27001?

Key fact: Yes, you can outsource the ISO/IEC 27001 risk assessment and still be audit ready, but the organisation must own decisions and accept the Statement of Applicability. At CyPro, we run outsourced assessments, map findings to Annex A controls and hand over UKAS and BSI friendly artefacts while ensuring your executives sign off the final risk treatment plan.

What templates or artefacts should a vendor deliver with the assessment?

Key fact: Vendors should deliver an editable risk register, risk scoring matrix, draft Statement of Applicability, risk treatment plan and an executive summary. Good deliverables include Annex A control mappings and a prioritised remediation roadmap. Ensure artefacts are editable so you can import them into your Information Security Management System and produce audit evidence.

What is the ROI of doing an ISO 27001 risk assessment?

Key fact: ROI from an ISO/IEC 27001 risk assessment is realised through avoided incidents, smoother audits and new contracts, not immediate revenue. Quantify ROI by linking high risk assets to business process impacts and modelling reduction in incident cost after treatments. Prioritise low‑cost, high‑impact controls to get faster payback and visible savings.

3D rocket illustration for booking a free ISO 27001 scoping call

Take the first step

Get to ISO 27001 without the guesswork

Book a free 45 minute scoping call: where your ISMS stands today, what the UKAS audit will demand, and one fixed fee for getting there. No obligation, no hard sell.