Quick Answer: An ISO risk assessment is a structured process for identifying, analysing, and treating risks within your management system. To do it properly, you work through eight clear steps: define your scope, identify assets or activities, identify threats and vulnerabilities, score likelihood and impact, calculate risk ratings, choose treatment options, document everything in a risk register, and review regularly. A good template makes the whole process consistent and auditable.
Key Takeaways
- Every major ISO standard (ISO 9001, ISO 27001, ISO 45001, ISO 14001) requires some form of risk assessment
- The most widely used scoring method is likelihood × impact, typically on a 1–5 scale
- A 5×5 risk matrix produces scores from 1 to 25, giving you a clear, colour-coded picture of priority
- There are four treatment options for every risk: reduce, accept, avoid, or transfer
- Your template must capture both inherent risk (before controls) and residual risk (after controls)
- Risk owners must be named — "the company" is not an acceptable owner
- Assessments need reviewing at least annually, and after any significant change
- Auditors will check your risk register closely — vague entries will cost you
What Is an ISO Risk Assessment and Why Does It Matter?
An ISO risk assessment is a documented, repeatable process for identifying what could go wrong in your business, how likely it is, how bad it would be, and what you're going to do about it. It's not optional — it's a core requirement across virtually every ISO management system standard.
Here's why auditors take it seriously. Your risk assessment is the engine that drives your entire management system. If it's weak, everything built on top of it is weak too.
Which standards require it?
| Standard | Risk Assessment Requirement |
|---|---|
| ISO 9001 | Clause 6.1 — Actions to address risks and opportunities |
| ISO 27001 | Clause 6.1.2 — Information security risk assessment |
| ISO 45001 | Clause 6.1 — Hazard identification and risk assessment |
| ISO 14001 | Clause 6.1 — Risks and opportunities related to environmental aspects |
| ISO 22301 | Clause 6.1 — Business continuity risk assessment |
The depth and format varies by standard, but the core logic is the same.
How to Do an ISO Risk Assessment Properly: The Eight Steps
This is the part most guides skip over too quickly. Here's what actually happens, step by step.
Step 1: Define your scope
Decide what's included. Which processes, departments, locations, or assets does this assessment cover? Scope creep kills risk assessments. Be specific.
Step 2: Build your asset or activity inventory
For ISO 27001, this means information assets. For ISO 45001, it's activities and hazards. For ISO 9001, it's processes and quality-affecting activities. You can't assess risks you haven't identified yet.
Step 3: Identify threats and vulnerabilities
What could go wrong? For each asset or activity, list realistic threats (cyberattack, equipment failure, supplier collapse) and the vulnerabilities that make those threats possible (outdated software, single supplier dependency).
Step 4: Score likelihood
Rate the probability of each threat occurring on a 1–5 scale:
- 1 = Rare
- 2 = Unlikely
- 3 = Possible
- 4 = Likely
- 5 = Almost certain
Step 5: Score impact
Rate the consequence if the risk materialises, also 1–5:
- 1 = Negligible
- 2 = Minor
- 3 = Moderate
- 4 = Major
- 5 = Catastrophic
Step 6: Calculate your risk rating
Multiply likelihood × impact. This gives you a score between 1 and 25. Plot it on your 5×5 risk matrix. Anything scoring 15 or above typically needs immediate treatment.
Step 7: Choose your treatment option
For each risk above your acceptable threshold, decide:
- Reduce — implement controls to lower likelihood or impact
- Accept — document that you're knowingly living with it
- Avoid — stop the activity that creates the risk
- Transfer — use insurance or outsource the risk
Step 8: Document and review
Record everything in your risk register. Assign a named risk owner. Set a review date. Revisit at least annually and after any significant change to your business or operating environment.
What Should Your ISO Risk Assessment Template Include?
A solid template is what separates a defensible risk assessment from a document that falls apart under audit scrutiny. Here's what every good template must capture:
- Risk ID — a unique reference number
- Risk name and description — clear, specific, not vague
- Asset or process affected
- Threat and vulnerability
- Likelihood score (1–5)
- Impact score (1–5)
- Inherent risk rating (likelihood × impact, before controls)
- Existing controls — what's already in place
- Treatment option (reduce, accept, avoid, transfer)
- Proposed additional controls
- Residual risk rating (after controls are applied)
- Risk owner — a named individual, not a department
- Review date
The inherent vs residual risk distinction matters. Auditors want to see that your controls are actually reducing risk, not just being listed for show.
For ISO 27001 specifically, your template should also map controls to Annex A of ISO 27001:2022, so there's a clear audit trail from risk to control.
Common Mistakes That Fail Audits
Here's what we see time and again when reviewing risk assessments before certification audits.
Vague risk descriptions. "Data breach" is not a risk description. "Unauthorised access to customer financial records via phishing attack on finance team accounts" is. The more specific, the more credible.
No named risk owners. Every risk needs a real person responsible for monitoring and managing it. "IT department" doesn't count.
Inherent and residual risk rated identically. If your controls aren't reducing the risk score, either the controls aren't effective or you haven't thought them through. Auditors notice this immediately.
Treating the assessment as a one-off exercise. Your risk landscape changes. New regulations, new technology, new threats. An assessment from 2023 that's never been touched is a red flag.
Scoring everything as medium risk. This suggests you haven't genuinely assessed anything. Some risks should be high. Some should be low. A realistic spread shows genuine thought.
If you want expert eyes on your risk assessment before your audit, ISO Adviser's internal auditing service can review it properly and flag issues before your certification body does.
How Does ISO Risk Assessment Fit Into Certification?
Your risk assessment feeds directly into your Statement of Applicability (for ISO 27001), your objectives, your controls, and your management review. It's not a standalone document — it's the foundation everything else sits on.
If you're working through certification for the first time, the complete guide to ISO certification steps walks you through where risk assessment fits in the broader process. And if you're wondering about timelines, how long ISO 9001 certification takes gives you a realistic picture.
For businesses that need help building their risk assessment from scratch, ISO Adviser's implementation support covers exactly this — including the template, the methodology, and the documentation auditors expect to see.
Conclusion: Get Your Risk Assessment Right From the Start
A well-built ISO risk assessment isn't bureaucracy for its own sake. It's the document that shows your auditor — and your own leadership team — that you understand your business risks and have a credible plan for managing them.
Your next steps:
- Download or build a template that captures all the fields listed above
- Run a scoping session to define what's included
- Complete your asset or activity inventory before scoring anything
- Score honestly — a realistic spread of low, medium, and high risks is more credible than everything sitting at medium
- Assign named risk owners and set review dates before you finalise the document
- Get an independent review before your certification audit
If you'd like expert support building your risk assessment properly, get in touch with ISO Adviser — we've helped hundreds of businesses get this right first time.
FAQ
Do all ISO standards require a risk assessment?
Most do. ISO 9001, ISO 27001, ISO 45001, ISO 14001, and ISO 22301 all require documented risk assessment processes. The format and depth vary, but the requirement is consistent across modern ISO management system standards.
What's the difference between inherent risk and residual risk?
Inherent risk is the raw risk score before any controls are applied. Residual risk is what remains after your controls are in place. Both must be documented — auditors want to see that controls are actually making a difference.
How often should I review my risk assessment?
At minimum, annually. Also after any significant business change, security incident, regulatory update, or major process change. Treat it as a living document, not a one-time task.
Can I use a spreadsheet for my risk assessment?
Yes. A well-structured spreadsheet with the right columns is perfectly acceptable for most ISO standards. What matters is completeness and consistency, not the software you use.
What is a 5×5 risk matrix?
It's a grid that plots likelihood (1–5) against impact (1–5), producing risk scores from 1 to 25. Colour coding (green, amber, red) makes it easy to prioritise which risks need immediate attention.
Who should own the risk assessment process?
Typically the Quality Manager, Information Security Manager, or Operations Director — whoever is responsible for the management system. But individual risks need named owners throughout the business, not just one person owning everything.
What happens if my risk assessment is weak at audit?
At best, you'll receive a nonconformity that delays certification. At worst, you'll fail the Stage 2 audit and need to redo significant work. It's one of the areas auditors scrutinise most closely.
Is a risk assessment the same as a gap analysis?
No. A gap analysis identifies where your current systems fall short of ISO requirements. A risk assessment identifies and scores business risks. Both are needed for certification, but they serve different purposes.
