Edition 2026.09 · Desk research from public vendor pages, last reviewed 29 September 2026

Lesson 3 of 10 · Track A · · Updated

Risk assessment and risk treatment in ISO 27001

Short answer

ISO 27001 asks for a risk assessment method you can repeat and that produces comparable results, a record of the risks you found, and a treatment plan that says what you will do about each one and who owns it. The controls you choose flow into the Statement of Applicability.

G-01

What does a risk assessment need to include?

The standard does not prescribe a method. It asks that yours defines how risks are identified, who owns them, how likelihood and consequence are judged, and what level of risk is acceptable. Most companies use a simple scale and a register listing each risk, its owner, the current rating and the treatment. What auditors look for is consistency: the same method applied the same way, rerun when things change and at planned intervals.

G-02

What are the treatment options?

For each risk you choose what to do. You can reduce it with controls, avoid it by stopping the activity, share it, for example through a supplier contract or insurance, or accept it where it sits within your acceptance level. Accepted risks need a named owner who signs off. The treatment plan lists the chosen option, the controls, the owner and the date. Risk owners must approve the plan and the residual risk that remains.

G-03

How does the risk work connect to Annex A?

Once you know which controls treat your risks, you compare them with the controls in Annex A to check nothing necessary has been missed. The result is the Statement of Applicability: every Annex A control, whether it applies, why, and whether it is implemented. This is why a good risk assessment makes the rest of the ISMS easier. Controls without a risk behind them are hard to justify, and risks without controls are the first thing an auditor will find.

G-04

What should you look for in a platform's risk features?

Ask to see the risk register, the scoring method and how treatment links to controls and evidence. Among the vendors on this site, Secureframe and Sprinto list risk management on their entry plans, Vanta lists it on Professional, Drata lists Risk Management Pro on GRC Enterprise, and Scrut describes a Risk Analyst agent that works through MCP servers. We did not find a risk register workflow described on Scytale's public pages, although its dedicated compliance expert manages the audit-readiness process. In a demo, ask each vendor to show how a new risk is added, scored, treated and reviewed, and who does each step.

G-05

What mistakes are common?

Three come up often. Copying a generic risk list that does not match the business. Rating every risk as high, which makes treatment meaningless. And never rerunning the assessment after a major change such as a new product, a new cloud provider or an acquisition. A platform can remind you to rerun it; deciding what changed is still your job.