ISO 27001 Risk Assessment Template: A Step-by-Step Guide for UK SMBs
By Brian Crocker · Published 9 August 2026
The ISO 27001 risk assessment is the foundation of your entire ISMS. Get it wrong and you will select the wrong controls, miss genuine threats, and fail Stage 2. Get it right and every other part of the standard — from your Statement of Applicability to your management review inputs — has a defensible basis.
Clause 6.1 of ISO 27001:2022 is the requirement. This guide translates it into a practical template and process for a UK SMB with 10–100 employees.
What Clause 6.1 requires
ISO 27001:2022 Clause 6.1.2 requires you to:
- Define and apply an information security risk assessment process
- Identify information security risks associated with the loss of confidentiality, integrity, and availability of information within the ISMS scope
- Analyse and evaluate the risks against defined criteria
- Prioritise risks for treatment
Clause 6.1.3 requires you to:
- Identify risk treatment options
- Determine which Annex A controls are necessary and applicable
- Produce a Statement of Applicability (SoA) listing all 93 Annex A controls with justifications for inclusion or exclusion
- Produce a risk treatment plan
Clause 7.5.1 requires you to retain documented information as evidence — so the risk assessment must be a living, maintained document, not a one-off exercise.
The standard does not prescribe a methodology. You choose. What matters is: your methodology is documented, consistently applied, and produces results you can defend.
Step 1: Document your methodology first
Before you identify a single risk, write down how you will assess them. Your methodology document (1–2 pages) should cover:
Scope: Which information, systems, processes, sites, and people are in scope? Reference your ISMS scope definition (Clause 4.3).
Risk identification approach: How will you identify assets and the threats and vulnerabilities associated with them? (Asset-based approach — most common for SMBs.)
Risk criteria: What scale will you use for likelihood and impact? 3x3 (1-3 each) is simpler; 5x5 gives more granularity. Define what each level means. For a UK SMB, impact levels might be:
- 1 = Minimal: brief disruption, no data loss, no regulatory exposure
- 2 = Moderate: operational disruption >4 hours, potential data breach (ICO notification unlikely)
- 3 = Significant: major disruption, confirmed data breach requiring ICO notification, reputational damage, contract loss
Risk score: Likelihood x Impact = Risk Score (1–9 on a 3x3). Define your acceptance threshold: risks scoring ≤3 = acceptable; 4–6 = treat; 7–9 = priority treatment.
Risk acceptance criteria: Who can authorise accepting a risk? For most SMBs, this is a director or owner.
Document this once. Apply it consistently to every risk. Your certification auditor will look for methodology consistency across the risk register.
Step 2: Build your asset inventory
An asset-based risk assessment starts with identifying what you need to protect. For an ISO 27001 ISMS, information assets include:
Information assets: Client data (contracts, financial records, PII), employee records, intellectual property, business plans, pricing data, system access credentials.
Software assets: Business applications (CRM, ERP, accounting), email and collaboration platforms, security tools, bespoke software.
Hardware assets: Laptops, servers, mobile devices, printers, network equipment, removable media.
Service assets: Cloud services (AWS, Azure, Microsoft 365, Google Workspace), ISP, managed service providers, CCTV systems.
People: Employees, contractors, third-party service providers with system access.
Premises: Office locations, server rooms, client sites where work is conducted.
For each asset, record: asset name, description, owner (named individual), classification (confidential / internal / public). 30–80 assets is typical for a 10–100 person SMB. Do not over-engineer: focus on assets that, if compromised, would cause real harm.
Step 3: Identify threats and vulnerabilities
For each asset (or logical group of assets), identify relevant threats and the vulnerabilities that make those threats exploitable.
Common threat categories for UK SMBs:
| Threat | Example |
|---|---|
| Malware / ransomware | Phishing email triggers file encryption |
| Unauthorised access | Former employee retains system credentials |
| Data breach | Client PII emailed to wrong recipient |
| Physical theft | Unencrypted laptop stolen from vehicle |
| Supplier compromise | SaaS provider suffers breach; data exposed |
| Human error | Database misconfiguration exposes records publicly |
| Business disruption | Cloud outage prevents access to client data |
| Regulatory failure | GDPR / UK GDPR breach reportable to ICO |
Match threats to assets. Not every threat applies to every asset — a paper document cannot be compromised by ransomware, but it can be stolen or lost.
Step 4: Score and prioritise risks
For each threat-asset combination, apply your likelihood x impact scoring:
| Risk ID | Asset | Threat | Vulnerability | Likelihood (1-3) | Impact (1-3) | Risk Score | Risk Owner |
|---|---|---|---|---|---|---|---|
| R001 | Client PII (CRM) | Ransomware | Weak endpoint protection; no offline backup | 3 | 3 | 9 | IT Manager |
| R002 | Employee laptops | Physical theft | Laptops unencrypted | 2 | 3 | 6 | Operations |
| R003 | Email (M365) | Phishing / credential theft | No MFA enforced | 2 | 3 | 6 | IT Manager |
| R004 | Paper client files | Unauthorised access | Filing cabinet not locked | 1 | 2 | 2 | Office Manager |
Work through your full asset inventory. A typical SMB risk register has 40–80 entries. Focus analysis effort on high-scoring risks — these drive control selection.
Step 5: Risk treatment decisions
For each risk, you have four treatment options:
Modify (mitigate): Implement controls to reduce likelihood or impact. Most risks are treated this way — select applicable Annex A controls and assign to an owner.
Retain (accept): The risk is within your acceptance criteria, or treatment cost exceeds the potential loss. Document the decision and who authorised it. Every accepted risk must be formally documented — "we chose not to treat this" is valid; "we never looked at it" is not.
Avoid: Change the activity that creates the risk. Stop holding certain categories of data, outsource a high-risk process, exit a market.
Share / transfer: Insurance, contractual liability transfer to a supplier, outsourcing to a managed security provider.
For each treated risk, record: treatment decision, control(s) selected (reference Annex A), implementation owner, target implementation date, residual risk after treatment.
Step 6: Map to Annex A and produce your SoA
Every risk treatment that involves implementing a control requires a corresponding Annex A control reference. The 93 controls in ISO 27001:2022 Annex A are grouped into four categories:
- A.5 Organisational controls (37 controls): policies, roles, supplier management, incident response
- A.6 People controls (8 controls): screening, terms of employment, awareness, remote working
- A.7 Physical controls (14 controls): physical security perimeters, clear desk, equipment disposal
- A.8 Technological controls (34 controls): access control, cryptography, malware protection, backup, patch management
Not all 93 controls apply to every organisation. Your SoA must list all 93 and state, for each: applicable or not applicable, and the justification. Controls identified as applicable must link back to a specific risk or legal/contractual requirement.
Our ISO 27001 Annex A Controls Checklist maps all 93 controls with applicability prompts and links to your risk register entries.
Step 7: Risk treatment plan
Your risk treatment plan is a separate document that lists:
| Risk ID | Treatment option | Control (Annex A ref) | Owner | Target date | Status | Residual risk score |
|---|---|---|---|---|---|---|
| R001 | Modify | A.8.7 (malware protection), A.8.13 (backup) | IT Manager | 2026-09-01 | In progress | 3 |
| R002 | Modify | A.7.9 (equipment security), A.8.5 (access control) | Operations | 2026-08-15 | Planned | 3 |
| R003 | Modify | A.8.5 (authentication), A.6.3 (awareness training) | IT Manager | 2026-08-01 | Complete | 2 |
| R004 | Retain | — | Director | 2026-07-01 | Accepted | 2 |
The risk treatment plan is a live document — update it as controls are implemented and residual risks are re-scored.
UK-specific considerations
UK GDPR: Your ISMS risk assessment should identify risks related to personal data processing. Where a risk involves processing that is likely to result in high risk to individuals, a Data Protection Impact Assessment (DPIA) may be required under UK GDPR Article 35. The ICO publishes guidance at ico.org.uk.
Cyber Essentials: If you hold Cyber Essentials, several Annex A technological controls are partially addressed: boundary firewalls (A.8.20), secure configuration (A.8.9), access control (A.8.2–8.5), malware protection (A.8.7), and patch management (A.8.8). Map your CE evidence against Annex A before building from scratch.
Sector-specific threats: Financial services, healthcare, and public sector supply chain businesses face additional threats (FCA requirements, NHS DSP Toolkit, MOD supplier requirements). Ensure your threat identification reflects your sector context.
Maintaining the risk assessment
The risk assessment is not a one-time document. Review triggers under ISO 27001:2022:
- At least annually, as part of management review (Clause 9.3)
- When significant changes occur: new systems, new processes, new offices, acquisitions, key staff changes
- After an information security incident or near-miss
- When new threats emerge (new ransomware variant, supplier breach disclosed)
Document each review. Record what was reviewed, whether any risks changed, and whether new risks were identified. Even a review that concludes "no changes needed" should be documented — the evidence of regular review is what auditors look for.
Your risk assessment results feed directly into your ISO 27001 gap analysis, which maps your current control implementation against the risks you have identified.
This article is for general informational purposes only and does not constitute legal, regulatory, or professional compliance advice. ISO certification requirements vary by scope, sector, and certification body. Always verify requirements with your UKAS-accredited certification body or a qualified consultant before making compliance decisions.
ClauseWise is coming soon
Generate your ISO 9001 and ISO 27001 documentation without consultant fees.