Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 risk review cycle diagram

ISO 27001 Risk Review: The Essential 2026 Guide to Keeping Assessments Current

An ISO 27001 risk review is the recurring check that your risk assessment and treatment decisions still reflect reality, and the standard expects it to happen at planned intervals and whenever significant changes are proposed or occur. Without it, a risk register becomes a snapshot of the day it was written.

This guide explains what the standard asks for, how to set a review calendar, which events should trigger an early review, and what evidence to keep. It connects to your risk assessment methodology and your risk treatment plan.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

What the standard requires from an ISO 27001 risk review

Clause 6.1.2 requires you to perform information security risk assessments at planned intervals or when significant changes are proposed or occur, and to retain documented information of the results. Clause 8.2 repeats the point for the operation phase. Clause 9.3 then requires management review to consider changes in risks and the status of risk treatment.

Free ISO 27001 risk assessment

Which of your risks sit above your appetite line?

Set your own risk criteria, pick from 61 information security risk scenarios, rate likelihood and impact, and decide how to treat each one. You get a heat map, a process score and the findings an auditor would raise, free.

Run the free risk assessment →  or  View premium report sample

Together these mean the review is not optional housekeeping. You can confirm the wording in your licensed copy of the standard, listed at ISO/IEC 27001:2022 on iso.org.

Whatever you choose, make the reasoning visible: a sentence in the procedure explaining why the interval suits your pace of change is enough for most auditors.

Setting planned intervals for the review

The standard does not fix a frequency, so you decide and justify it. Annual full reviews are common, with shorter cycles for high-scoring risks. Base the choice on how fast your environment changes: a cloud-native firm releasing weekly needs tighter cycles than a stable manufacturer.

Write the intervals into your procedure and the calendar, and assign a named owner for each so that reviews do not depend on memory.

Change triggers that require an early ISO 27001 risk review

Some events should never wait for the annual cycle. Typical triggers include a new system or supplier, a merger, a major incident, a significant vulnerability in a core technology, a change in legislation, and changes to scope or business strategy.

Hook the trigger into change management and incident response so the review is requested automatically, rather than relying on someone to notice. Record which trigger started the review.

Review typeFrequencyOwnerOutput
Full risk assessment reviewAnnuallyInformation security managerUpdated register and plan
High risk checkQuarterlyRisk ownersConfirmed or revised scores
Trigger reviewOn change or incidentChange or incident ownerTargeted reassessment
Management review inputAt least annuallyTop managementDecisions and actions

What to check in each ISO 27001 risk review

Work through a fixed list so no review is skipped or thin. Confirm that assets and owners are current, that threats and vulnerabilities still fit the picture, that likelihood and impact scores remain valid, and that criteria have not drifted from appetite.

Then check treatment: are controls implemented, operating and effective, and do the residual scores still hold? Our guide to risk criteria helps you test whether the scales need updating.

Reviewing threats and vulnerabilities

Threat conditions change faster than most other inputs. Revisit your sources, such as threat intelligence, vulnerability scans, penetration tests and incident data, and adjust likelihoods accordingly.

See the companion guide on threats and vulnerabilities for how to structure that catalogue.

Documenting decisions from the ISO 27001 risk review

Every review should end with decisions written down: which scores changed and why, which risks were added or closed, which treatments were re-prioritized, and which exceptions were granted or renewed. Include the reasoning in a sentence or two so that someone reading the record a year later understands the logic. Store the decision log next to the register, and link each entry to the relevant treatment action so progress is easy to follow. Clear records also make handovers smoother when the security lead or a risk owner changes role.

Where a decision needs budget or resources, capture the request and its outcome as well, since unfunded treatments are a recurring reason for scores staying high.

Reviewing treatment progress and residual risk

Open actions in the treatment plan are a common blind spot. Check dates, owners and blockers, and escalate anything overdue. Where controls are complete, test that they work before lowering scores.

The article on residual risk explains how to rescore consistently and when to seek fresh owner approval.

Involving risk owners in the review

Owners must be part of the conversation, not recipients of a finished spreadsheet. Give them their risks in advance, ask for changes, and record their confirmation. The guide to the risk owner role covers what they should be accountable for.

A short structured meeting per business area works better than one long workshop for the whole company.

Feeding the review into management review

Clause 9.3 lists inputs including changes in external and internal issues, feedback on performance and the results of risk assessment and treatment status. Summarize your ISO 27001 risk review outcomes for that meeting: new risks, changed scores, overdue treatments and accepted exceptions.

Minutes should show that leaders discussed the material and decided something, since that is the evidence auditors sample.

A sample ISO 27001 risk review agenda

A tight agenda keeps each session productive. Open with a summary of changes since the last review: new systems, suppliers, incidents and audit findings. Move to the top ten risks and confirm whether each score still stands. Review treatment actions that are overdue or blocked, then discuss new or emerging risks raised by owners. Close by recording decisions, actions, owners and dates. Ninety minutes is usually enough per business area when owners receive their risks a week before, and the record of that meeting becomes core evidence for the review.

Rotate a second reviewer from a different team into some sessions. A fresh perspective often catches optimistic scoring that the risk owner has stopped noticing.

Keeping evidence of the ISO 27001 risk review

Retain the review agenda, the updated register with version history, owner confirmations, trigger records and meeting minutes. Date everything and keep previous versions so a reader can see what changed.

A register that shows a last-reviewed date and a changelog answers most audit questions before they are asked.

Reviewing scope and context in the ISO 27001 risk review

Risk is always measured against something, so check that the scope of the management system, the interested parties and the internal and external issues still describe the business. A new office, a cloud migration or a customer contract with new security terms can all change what belongs in the register. If the scope has moved, the assessment must move with it, otherwise whole areas of exposure go unassessed. Note the scope check in the review record even when nothing changed, because an explicit confirmation is stronger evidence than silence.

Common weaknesses auditors find

Frequent findings are easy to prevent when you know them.

  • A register with no review date or a date years old.
  • Reviews that only refresh the paperwork and change no scores.
  • No link between incidents and reassessment.
  • Overdue treatment actions with no escalation.
  • Owner approvals that predate the latest scores.

Measuring whether the review works

Track a few simple measures to see if your review process has real effect. Useful ones include the percentage of risks reviewed on time, the number of scores changed per cycle, the average age of open treatment actions and the number of incidents that occurred in areas rated low. If scores never change across several reviews, the process is probably a formality. If incidents keep hitting low-rated risks, the scoring needs recalibration. These measures also give management a compact summary for the review meeting.

Using risk heat maps to show change

Plotting the previous and current positions of top risks on a risk heat map shows movement at a glance and makes management conversations faster.

Aligning the review with internal audit

Internal audit and the risk review support each other but should stay separate. Audit tests whether the process is followed and effective, while the review keeps the content current. Share findings between them: an audit finding on access control should prompt a review of related risks, and an unusual movement in scores is a good candidate for an audit sample. Agree the calendar so the two activities do not collide with the same people in the same fortnight.

Speeding up the review with a structured workbook

If you would prefer not to build the register and review log yourself, the ISO 27001 Risk Assessment Report and Workbook provides a structured report and workbook covering scoring, treatment and approvals. Whatever tool you use, keep one consistent format across reviews so year-on-year comparison is straightforward.

ISO 27001 risk review FAQ

How often must an ISO 27001 risk review happen?

The standard says at planned intervals or when significant changes occur. You choose the interval, document it and follow it.

Is an annual review enough?

Often, for stable environments, provided you also review after significant changes and incidents. Higher risks may need quarterly checks.

Who performs the review?

The information security lead coordinates it, while risk owners confirm their own risks and top management considers the results.

Does every review require a full reassessment?

No. Targeted reviews for triggers are acceptable if the scope is recorded and a full review still occurs at the planned interval.

What evidence do auditors want?

Dated registers, owner confirmations, trigger records, treatment status and management review minutes showing decisions.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.