ISO 27001 Clause 6.1.2 Information Security Risk Assessment requires organisations to define and apply a formal risk assessment process. Documented criteria ensure teams identify threats, evaluate potential business impacts, and establish consistent, repeatable risk scores across the business.
Table of contents
Key Takeaways
- Establish a risk assessment framework: Create clear rules to identify, analyse, and evaluate information security risks systematically.
- Store methodologies centrally: Keep risk assessment policies, scoring tables, and criteria registers in a central document repository.
- Set explicit risk criteria: Define risk acceptance thresholds and impact scales before evaluating active operational threats.
- Ensure repeatable scoring: Apply consistent calculation formulas so different assessors produce comparable, reliable results over time.
- Identify risks to confidentiality, integrity, and availability: Spot potential threat events that could compromise critical business data and systems.
- Assign named risk owners: Designate specific operational managers with the formal authority to manage and own identified risks.
- Prioritise risks for treatment: Compare calculated risk levels against acceptance boundaries to determine which risks require treatment.
- Retain documented assessment proof: Maintain detailed assessment registers and meeting logs to prove compliance during audits.
How to Implement ISO 27001 Clause 6.1.2
- Draft a risk assessment methodology: Write a clear procedure detailing your risk scoring formulas, acceptance rules, and review cycles.
- Define likelihood and impact scales: Create simple, standardized rating grids, such as low, medium, and high, or numeric one-to-five scales.
- Set risk acceptance criteria: Establish the exact risk score above which risks must receive formal treatment safeguards.
- Identify threats and vulnerabilities: Map realistic threat scenarios and operational weaknesses across all critical information assets.
- Calculate raw risk scores: Multiply or combine likelihood and impact ratings to determine the initial risk level before safeguards.
- Engage operational risk owners: Involve business department heads to validate scores and take ownership of identified risks.
- Log findings in a central risk register: Record identified threat scenarios, asset links, assigned owners, and scores in a live tracker.
- Trigger assessments on major changes: Run ad-hoc risk assessments whenever introducing new systems, suppliers, or business locations.
- Feed results into risk treatment: Route all risks exceeding your acceptance threshold directly into the Clause 6.1.3 treatment workflow.
When you’re ready to bring compliance into one place

How to Audit ISO 27001 Clause 6.1.2
- Review risk methodology documentation: Inspect written procedures to verify explicit rules define how the business identifies and analyses risks.
- Audit risk acceptance criteria: Check that leadership defined and formally approved explicit risk acceptance thresholds.
- Sample active risk register entries: Check sampled risks to ensure scoring calculations match the defined likelihood and impact scales.
- Verify risk owner assignments: Confirm every logged risk links to an active, named individual with operational authority.
- Inspect scoring consistency: Cross-check risk evaluations completed by different teams to ensure uniform application of scoring rules.
- Check change-triggered assessments: Verify teams completed risk assessments before rolling out recent major operational or technical changes.
- Interview risk owners: Speak with operational leads to confirm they understand how their assigned risks were identified and evaluated.
- Confirm assessment intervals: Verify that management conducted scheduled risk assessments within planned calendar timeframes.
Audit Evidence Checklist
- Risk assessment methodology document: Maintain a documented policy defining scoring scales, impact matrices, and evaluation criteria.
- Approved risk criteria sign-off: Supply evidence showing top management reviewed and approved risk acceptance boundaries.
- Central information risk register: Provide an active register containing identified threats, vulnerabilities, scores, and named risk owners.
- Completed risk assessment reports: Provide summary reports and workshop notes from scheduled annual risk reviews.
- Change-driven risk evaluations: Maintain assessment records executed for new project launches or operational restructuring.
- Risk owner validation records: Supply approval logs showing risk owners verified and agreed with assigned risk ratings.
- Management review meeting minutes: Provide records proving executive leadership reviewed risk assessment findings.
What to Teach Employees
- Understand risk identification: Teach staff how to spot day-to-day security threats, weak controls, and data exposure points.
- Know your role in assessments: Encourage workers to participate openly in risk workshops and explain operational realities.
- Report new risks promptly: Instruct teams to notify risk managers whenever business processes or supplier arrangements change.
- Understand risk scoring basics: Educate team leads on how likelihood and business impact combine to produce overall risk ratings.
- Support assigned risk owners: Remind staff to help department leads manage and track operational risks effectively.
- Follow established safeguards: Reiterate that security controls exist directly to mitigate identified assessment risks.
Common Implementation Challenges
- Overly complex scoring algorithms: Creating complicated mathematical formulas alienates business managers. Use clean, accessible scoring matrices.
- Subjective and biased ratings: Assessors score risks based on personal feelings rather than criteria. Provide detailed criteria definitions with concrete examples.
- Assessing IT systems without business data: Focusing only on servers while ignoring core data workflows. Inventory information assets before evaluating risks.
- Treating assessments as one-off exercises: Reviewing risks once for certification and shelving the register. Embed risk reviews into regular change management workflows.
- Missing risk ownership: Logging risks without naming individual business owners. Mandate a specific named owner for every register entry.
- Disconnect from risk treatment: Assessing risks without linking high scores to treatment plans. Automate escalation from assessment to treatment.
How to Measure Effectiveness (KPIs)
- Assessment schedule completion rate: Track the percentage of scheduled departmental risk assessments completed on time.
- Change assessment coverage: Measure the proportion of major operational and technical changes assessed for risk prior to launch.
- Unidentified threat incident rate: Track the number of security incidents caused by threats not previously captured in the risk register.
- Risk owner validation percentage: Measure the proportion of risk register entries verified and signed off by assigned risk owners.
- Scoring consistency audit rate: Track the percentage of sampled risk assessments complying fully with approved corporate scoring criteria.
- Risk assessment audit finding count: Monitor the number of non-conformities raised against risk assessment execution during internal and external audits.
Related ISO 27001 Controls
ISO 27001 Clause 6.1.2 connects to several other ISO 27001 requirements:
Related ISO 27001 Controls
- ISO 27001 Clause 4.1 Context: Your internal and external issues provide the primary input for identifying risks.
Read the Clause 4.1 guide. - ISO 27001 Clause 4.2 Stakeholders: Stakeholder needs often dictate which risks are considered unacceptable.
Learn about Stakeholder Requirements. - ISO 27001 Clause 6.1.3 Risk Treatment: Once risks are assessed, you must decide how to handle them using this clause.
Explore Risk Treatment.
