ISO 27001 Risk Assessment Template: A Step-by-Step Guide for UK SMBs

By Brian Crocker · Published 9 August 2026

The ISO 27001 risk assessment is the foundation of your entire ISMS. Get it wrong and you will select the wrong controls, miss genuine threats, and fail Stage 2. Get it right and every other part of the standard — from your Statement of Applicability to your management review inputs — has a defensible basis.

Clause 6.1 of ISO 27001:2022 is the requirement. This guide translates it into a practical template and process for a UK SMB with 10–100 employees.

What Clause 6.1 requires

ISO 27001:2022 Clause 6.1.2 requires you to:

  • Define and apply an information security risk assessment process
  • Identify information security risks associated with the loss of confidentiality, integrity, and availability of information within the ISMS scope
  • Analyse and evaluate the risks against defined criteria
  • Prioritise risks for treatment

Clause 6.1.3 requires you to:

  • Identify risk treatment options
  • Determine which Annex A controls are necessary and applicable
  • Produce a Statement of Applicability (SoA) listing all 93 Annex A controls with justifications for inclusion or exclusion
  • Produce a risk treatment plan

Clause 7.5.1 requires you to retain documented information as evidence — so the risk assessment must be a living, maintained document, not a one-off exercise.

The standard does not prescribe a methodology. You choose. What matters is: your methodology is documented, consistently applied, and produces results you can defend.

Step 1: Document your methodology first

Before you identify a single risk, write down how you will assess them. Your methodology document (1–2 pages) should cover:

Scope: Which information, systems, processes, sites, and people are in scope? Reference your ISMS scope definition (Clause 4.3).

Risk identification approach: How will you identify assets and the threats and vulnerabilities associated with them? (Asset-based approach — most common for SMBs.)

Risk criteria: What scale will you use for likelihood and impact? 3x3 (1-3 each) is simpler; 5x5 gives more granularity. Define what each level means. For a UK SMB, impact levels might be:

  • 1 = Minimal: brief disruption, no data loss, no regulatory exposure
  • 2 = Moderate: operational disruption >4 hours, potential data breach (ICO notification unlikely)
  • 3 = Significant: major disruption, confirmed data breach requiring ICO notification, reputational damage, contract loss

Risk score: Likelihood x Impact = Risk Score (1–9 on a 3x3). Define your acceptance threshold: risks scoring ≤3 = acceptable; 4–6 = treat; 7–9 = priority treatment.

Risk acceptance criteria: Who can authorise accepting a risk? For most SMBs, this is a director or owner.

Document this once. Apply it consistently to every risk. Your certification auditor will look for methodology consistency across the risk register.

Step 2: Build your asset inventory

An asset-based risk assessment starts with identifying what you need to protect. For an ISO 27001 ISMS, information assets include:

Information assets: Client data (contracts, financial records, PII), employee records, intellectual property, business plans, pricing data, system access credentials.

Software assets: Business applications (CRM, ERP, accounting), email and collaboration platforms, security tools, bespoke software.

Hardware assets: Laptops, servers, mobile devices, printers, network equipment, removable media.

Service assets: Cloud services (AWS, Azure, Microsoft 365, Google Workspace), ISP, managed service providers, CCTV systems.

People: Employees, contractors, third-party service providers with system access.

Premises: Office locations, server rooms, client sites where work is conducted.

For each asset, record: asset name, description, owner (named individual), classification (confidential / internal / public). 30–80 assets is typical for a 10–100 person SMB. Do not over-engineer: focus on assets that, if compromised, would cause real harm.

Step 3: Identify threats and vulnerabilities

For each asset (or logical group of assets), identify relevant threats and the vulnerabilities that make those threats exploitable.

Common threat categories for UK SMBs:

Threat Example
Malware / ransomware Phishing email triggers file encryption
Unauthorised access Former employee retains system credentials
Data breach Client PII emailed to wrong recipient
Physical theft Unencrypted laptop stolen from vehicle
Supplier compromise SaaS provider suffers breach; data exposed
Human error Database misconfiguration exposes records publicly
Business disruption Cloud outage prevents access to client data
Regulatory failure GDPR / UK GDPR breach reportable to ICO

Match threats to assets. Not every threat applies to every asset — a paper document cannot be compromised by ransomware, but it can be stolen or lost.

Step 4: Score and prioritise risks

For each threat-asset combination, apply your likelihood x impact scoring:

Risk ID Asset Threat Vulnerability Likelihood (1-3) Impact (1-3) Risk Score Risk Owner
R001 Client PII (CRM) Ransomware Weak endpoint protection; no offline backup 3 3 9 IT Manager
R002 Employee laptops Physical theft Laptops unencrypted 2 3 6 Operations
R003 Email (M365) Phishing / credential theft No MFA enforced 2 3 6 IT Manager
R004 Paper client files Unauthorised access Filing cabinet not locked 1 2 2 Office Manager

Work through your full asset inventory. A typical SMB risk register has 40–80 entries. Focus analysis effort on high-scoring risks — these drive control selection.

Step 5: Risk treatment decisions

For each risk, you have four treatment options:

Modify (mitigate): Implement controls to reduce likelihood or impact. Most risks are treated this way — select applicable Annex A controls and assign to an owner.

Retain (accept): The risk is within your acceptance criteria, or treatment cost exceeds the potential loss. Document the decision and who authorised it. Every accepted risk must be formally documented — "we chose not to treat this" is valid; "we never looked at it" is not.

Avoid: Change the activity that creates the risk. Stop holding certain categories of data, outsource a high-risk process, exit a market.

Share / transfer: Insurance, contractual liability transfer to a supplier, outsourcing to a managed security provider.

For each treated risk, record: treatment decision, control(s) selected (reference Annex A), implementation owner, target implementation date, residual risk after treatment.

Step 6: Map to Annex A and produce your SoA

Every risk treatment that involves implementing a control requires a corresponding Annex A control reference. The 93 controls in ISO 27001:2022 Annex A are grouped into four categories:

  • A.5 Organisational controls (37 controls): policies, roles, supplier management, incident response
  • A.6 People controls (8 controls): screening, terms of employment, awareness, remote working
  • A.7 Physical controls (14 controls): physical security perimeters, clear desk, equipment disposal
  • A.8 Technological controls (34 controls): access control, cryptography, malware protection, backup, patch management

Not all 93 controls apply to every organisation. Your SoA must list all 93 and state, for each: applicable or not applicable, and the justification. Controls identified as applicable must link back to a specific risk or legal/contractual requirement.

Our ISO 27001 Annex A Controls Checklist maps all 93 controls with applicability prompts and links to your risk register entries.

Step 7: Risk treatment plan

Your risk treatment plan is a separate document that lists:

Risk ID Treatment option Control (Annex A ref) Owner Target date Status Residual risk score
R001 Modify A.8.7 (malware protection), A.8.13 (backup) IT Manager 2026-09-01 In progress 3
R002 Modify A.7.9 (equipment security), A.8.5 (access control) Operations 2026-08-15 Planned 3
R003 Modify A.8.5 (authentication), A.6.3 (awareness training) IT Manager 2026-08-01 Complete 2
R004 Retain Director 2026-07-01 Accepted 2

The risk treatment plan is a live document — update it as controls are implemented and residual risks are re-scored.

UK-specific considerations

UK GDPR: Your ISMS risk assessment should identify risks related to personal data processing. Where a risk involves processing that is likely to result in high risk to individuals, a Data Protection Impact Assessment (DPIA) may be required under UK GDPR Article 35. The ICO publishes guidance at ico.org.uk.

Cyber Essentials: If you hold Cyber Essentials, several Annex A technological controls are partially addressed: boundary firewalls (A.8.20), secure configuration (A.8.9), access control (A.8.2–8.5), malware protection (A.8.7), and patch management (A.8.8). Map your CE evidence against Annex A before building from scratch.

Sector-specific threats: Financial services, healthcare, and public sector supply chain businesses face additional threats (FCA requirements, NHS DSP Toolkit, MOD supplier requirements). Ensure your threat identification reflects your sector context.

Maintaining the risk assessment

The risk assessment is not a one-time document. Review triggers under ISO 27001:2022:

  • At least annually, as part of management review (Clause 9.3)
  • When significant changes occur: new systems, new processes, new offices, acquisitions, key staff changes
  • After an information security incident or near-miss
  • When new threats emerge (new ransomware variant, supplier breach disclosed)

Document each review. Record what was reviewed, whether any risks changed, and whether new risks were identified. Even a review that concludes "no changes needed" should be documented — the evidence of regular review is what auditors look for.

Your risk assessment results feed directly into your ISO 27001 gap analysis, which maps your current control implementation against the risks you have identified.

This article is for general informational purposes only and does not constitute legal, regulatory, or professional compliance advice. ISO certification requirements vary by scope, sector, and certification body. Always verify requirements with your UKAS-accredited certification body or a qualified consultant before making compliance decisions.

ClauseWise is coming soon

Generate your ISO 9001 and ISO 27001 documentation without consultant fees.