ISO 27001
Risk Criteria
Internal Audit
Certification Readiness

Risk Criteria Audit Guide: How to Test Impact, Likelihood, Acceptance, and Ownership

Learn how to audit ISO 27001 risk criteria, including impact, likelihood, scoring consistency, risk acceptance, ownership, treatment decisions, management oversight, and certification readiness evidence.

Quick Answer

How should internal auditors test ISO 27001 risk criteria?

Internal auditors should review whether the organization has clearly defined impact, likelihood, risk levels, acceptance thresholds, ownership rules, treatment decisions, and approval authority.

They should also test whether risks are scored consistently, high risks are escalated, accepted risks are approved, and risk owners understand their responsibilities.

The goal is simple: prove that the risk register is not just filled in. It must be based on clear criteria, real ownership, and evidence-backed decisions.

A Complete Risk Register Can Still Be Weak

A risk register can look complete and still be weak.

Rows may be filled. Risks may be scored. Owners may be listed. Treatment actions may be added.

However, during an ISO 27001 internal audit, the real question is not whether the register has content.

The real question is whether the risk criteria make sense.

Practical rule: ISO 27001 risk criteria make the risk assessment auditable.

The Main Risk Criteria Audit Question

The strongest audit question is not, “Do we have risk scores?”

A better question is:

Can the organization explain how risk scores were calculated, why they are reasonable, who owns the risk, and who approved the decision?

Risk Criteria Audit Snapshot

Audit Area What Internal Audit Should Test
Risk Criteria Whether the organization has defined how risks are evaluated.
Impact Whether impact reflects business, legal, client, operational, security, and reputational consequences.
Likelihood Whether likelihood levels are realistic, evidence-based, and consistently applied.
Acceptance Criteria Whether risk acceptance thresholds, authority, rationale, and review dates are defined.
Risk Ownership Whether each risk has a real owner with authority to act.
Management Oversight Whether leadership reviews high risks, accepted risks, and treatment progress.

Why ISO 27001 Risk Criteria Matter

Risk criteria are the rules behind the risk register.

They explain what low, medium, high, and critical risk mean.

They also explain who can accept risk, what requires treatment, and when leadership must review a decision.

Without clear criteria, the risk register becomes opinion-based.

One owner rates vendor outage as low.
Another owner rates the same risk as high.
Leadership accepts risk without clear authority.
Residual risk is lowered without evidence.

What Strong Risk Criteria Should Include

Strong ISO 27001 risk criteria should define the rules for risk-based decisions.

Impact levels.
Likelihood levels.
Risk calculation method.
Inherent and residual risk.
Acceptance thresholds.
Ownership expectations.
Approval authority.
Review frequency.

1. Test the Risk Assessment Methodology

Start with the risk methodology.

Before testing individual risks, the auditor should understand the rules used to create the register.

Audit Questions

  • Is the risk assessment methodology documented?
  • Who approved it?
  • How is impact defined?
  • How is likelihood defined?
  • What risk level requires treatment?
  • Who can accept risk?

Common finding: the organization has a risk register, but the methodology does not define scoring criteria, acceptance thresholds, or approval authority.

2. Test Impact Criteria

Impact criteria explain how serious the result of a risk could be.

Impact should reflect business reality, not only technical damage.

Impact Level Example Meaning
Low Limited internal inconvenience with no client impact or sensitive data exposure.
Medium Service disruption, limited sensitive data exposure, or delayed operations.
High Major client impact, sensitive data exposure, critical system outage, or contractual issue.
Critical Severe business disruption, major breach, regulatory exposure, or loss of key client trust.

Practical rule: impact should describe what the business would actually suffer if the risk occurred.

Need to Test Risk Criteria Before Certification?

Canadian Cyber helps organizations review ISO 27001 risk criteria, risk scoring, ownership, treatment decisions, and risk acceptance before certification audits.

We help test impact, likelihood, acceptance thresholds, risk owner accountability, SoA alignment, SharePoint risk dashboards, and management review readiness.

3. Test Likelihood Criteria

Likelihood criteria explain how probable a risk event is.

A weak likelihood score can make serious risks look less important.

Likelihood Level Example Meaning
Rare Unlikely based on strong controls, low exposure, and no relevant history.
Possible Could occur because some exposure, manual process, or known weakness exists.
Likely Reasonable chance due to recurring activity, known gaps, or weak controls.
Almost Certain Expected because controls are missing, ineffective, or repeatedly failing.

Common finding: likelihood ratings are assigned without evidence, exposure, incident history, control weakness, or audit finding support.

4. Test Risk Rating Consistency

Once impact and likelihood are defined, internal audit should test whether scoring is consistent.

A sample test helps reveal whether risk owners are using the same logic.

Sample Areas to Compare

  • Access control risks.
  • Vendor risks.
  • Backup and recovery risks.
  • Cloud security risks.
  • AI tool risks.
  • Privacy or client data risks.

Practical rule: risk scoring should be repeatable enough that two trained reviewers reach similar conclusions.

5. Test Inherent Risk and Residual Risk

Some organizations confuse inherent and residual risk.

This can weaken the entire risk register.

Inherent Risk

The level of risk before considering current controls.

Residual Risk

The level of risk after current controls are considered.

Common finding: residual risk is reduced without evidence that controls are implemented or operating effectively.

6. Test Risk Acceptance Criteria

Risk acceptance criteria define when risk can be accepted.

This is one of the most important internal audit areas.

Audit Questions

  • Which risk levels can be accepted?
  • Who can accept low, medium, high, or critical risks?
  • Is acceptance based on residual risk?
  • Is a rationale required?
  • Are accepted risks reviewed by management?

Practical rule: risk acceptance should be a formal decision, not a status label.

7. Test Risk Ownership

Risk ownership is often weak.

Many organizations assign every risk to the ISMS Manager because that person maintains the register. That is not enough.

What a Risk Owner Should Do

  • Understand the risk.
  • Review the rating.
  • Monitor treatment progress.
  • Provide evidence.
  • Escalate delays.

Practical rule: the risk owner should be close enough to the risk to manage it and senior enough to make action happen.

8. Test Risk Treatment Decisions

Risk criteria should lead to treatment decisions.

If the risk is above the acceptance threshold, treatment should be clear.

Treatment Option Meaning
Reduce Implement or improve controls to reduce risk.
Avoid Stop or change the activity that creates the risk.
Transfer or Share Use insurance, contracts, or third-party support where appropriate.
Accept Approve residual risk through the correct authority.

Common finding: treatment decisions say “monitor” or “mitigate” without owner, deadline, control, or evidence.

9. Test Management Review of Risk Criteria

Leadership should understand high risks, accepted risks, and treatment progress.

Risk criteria are not only technical scoring rules. They support management decisions.

Audit Questions

  • Does management review high risks?
  • Does management review accepted risks?
  • Does management review overdue treatment actions?
  • Are risk decisions documented?
  • Are action owners assigned?

Risk Criteria Evidence Matrix

Risk Criteria Area Strong Evidence Weak Evidence
Methodology Approved method with scoring rules. Informal spreadsheet.
Impact Business-based definitions. Vague high, medium, low labels.
Likelihood Evidence-based guidance. Subjective guesses.
Acceptance Approved criteria and authority. Accepted with no rationale.
Ownership Named accountable risk owners. All risks assigned to ISMS Manager.

Sample Internal Audit Finding

Weak Finding

Risk criteria are not clear.

Stronger Finding

The risk assessment methodology defines high, medium, and low risk levels, but does not define impact and likelihood criteria in a way that supports consistent scoring. In a sample of eight risks, similar vendor and access-related risks were scored differently by different owners without documented rationale. The methodology also does not define approval authority for accepting residual high risks. This may result in inconsistent treatment decisions and weak management oversight of accepted risks.

How SharePoint Can Help Manage Risk Criteria

A SharePoint ISMS workspace can make risk criteria easier to audit.

It can connect risk methodology, risk owners, scoring, evidence, treatment actions, SoA links, corrective actions, and management review decisions.

Risk Methodology
Track scoring rules and approvals.
Risk Register
Track owners, ratings, and treatment decisions.
Risk Acceptance Register
Track approval, rationale, and review dates.
Risk Owner Matrix
Track accountable owners and evidence owners.
Corrective Action Tracker
Track remediation for risk criteria gaps.
Management Review Dashboard
Show high risks and accepted risks.

When Your Risk Criteria Need Support

Organizations may need professional support when these problems appear:

Risk scoring is inconsistent.
Impact and likelihood criteria are unclear.
Accepted risks are not formally approved.
Risk owners are not engaged.
Residual risk scores lack evidence.
Certification audit is coming soon.

How Canadian Cyber Helps

Canadian Cyber helps organizations audit ISO 27001 risk criteria, impact, likelihood, acceptance, and ownership before certification and surveillance audits.

We help turn risk registers from subjective spreadsheets into evidence-backed risk management systems.

Our support includes risk methodology review, impact and likelihood scoring review, risk acceptance review, risk owner mapping, risk treatment review, SoA alignment, SharePoint dashboards, management review preparation, and certification readiness reporting.

Senior Advisory Support

Canadian Cyber also provides senior advisory support for ISO 27001 risk reviews, risk criteria testing, SharePoint ISMS dashboards, corrective action tracking, management review preparation, and vCISO guidance.

View Waqar Mehboob’s Profile

Frequently Asked Questions

What are ISO 27001 risk criteria?

ISO 27001 risk criteria are the rules an organization uses to assess and evaluate information security risks. They define impact, likelihood, risk levels, acceptance thresholds, ownership, and treatment expectations.

Why are impact and likelihood important in ISO 27001?

Impact and likelihood determine how risks are scored. When they are unclear, the risk register may not support reliable treatment decisions.

What is risk acceptance criteria?

Risk acceptance criteria define which risks can be accepted, who can approve acceptance, what rationale is required, and how often accepted risks should be reviewed.

Who should own ISO 27001 risks?

Risks should be owned by appropriate business or control owners. The ISMS Manager may coordinate the register, but should not own every risk.

Can SharePoint help track ISO 27001 risk criteria?

Yes. SharePoint can track risk methodology, scoring matrix, risk register, risk owners, treatment actions, accepted risks, evidence links, SoA mapping, and management review dashboards.

Takeaway

Risk criteria are the foundation of a useful ISO 27001 risk assessment.

Without clear criteria, the risk register becomes subjective.

With clear criteria, the organization can explain why a risk is high, why a risk is acceptable, who owns the risk, and what evidence supports residual risk.

A strong internal audit should test more than the risk register. It should test the logic behind the risk register.

Make Your ISO 27001 Risk Criteria Audit-Ready

Canadian Cyber can help your organization test risk criteria, impact, likelihood, acceptance, ownership, treatment decisions, SoA alignment, and management review evidence.

We support ISO 27001 internal audits, certification readiness, SharePoint ISMS dashboards, corrective action tracking, vCISO support, SOC 2 readiness, ISO 42001, ISO 27017, ISO 27018, and cybersecurity assessments.

Stay Connected With Canadian Cyber

Follow Canadian Cyber for practical guidance on ISO 27001 internal audits, risk criteria, risk assessment, risk treatment, certification readiness, SharePoint ISMS, SOC 2 readiness, AI governance, and vCISO services.