Risk Assessment
Risk Treatment
ISO 27001 Clause 6 Internal Audit: How to Review Risk Assessment and Risk Treatment Evidence
Learn how to audit ISO 27001 Clause 6 risk assessment and risk treatment evidence, including risk methodology, risk register, treatment plans, SoA alignment, risk owners, risk acceptance, management review, and certification readiness.
Quick Answer
What should an ISO 27001 Clause 6 internal audit review?
An ISO 27001 Clause 6 internal audit should review whether the organization has a defined risk assessment methodology, current risk register, assigned risk owners, consistent scoring, documented treatment decisions, and approved risk acceptance.
It should also test whether the risk treatment plan aligns with the Statement of Applicability, security objectives, evidence matrix, management review, and corrective action tracker.
The goal is simple: prove that the ISMS is risk-based, current, owner-driven, and supported by real evidence.
Clause 6 Is Where ISO 27001 Becomes Real
Clause 6 is the planning engine of the ISMS.
It shows whether information security decisions are based on real risk, or only on templates and copied policies.
Many organizations have a risk register. However, a risk register alone is not enough.
Internal audit must test whether risks are identified, scored, owned, treated, reviewed, accepted, and connected to evidence.
Practical rule: Clause 6 should prove that the organization understands its information security risks and is actively treating them.
Clause 6 Internal Audit Snapshot
| Clause 6 Area | What Internal Audit Should Test |
|---|---|
| Risk Methodology | Is the risk assessment approach defined, approved, and consistently used? |
| Risk Register | Are risks current, owned, rated, reviewed, and linked to business reality? |
| Risk Treatment | Are treatment decisions documented, assigned, tracked, and evidenced? |
| Statement of Applicability | Does the SoA match risks, treatment decisions, controls, owners, and evidence? |
| Risk Acceptance | Are accepted risks approved, justified, and reviewed? |
| Change Review | Are new systems, vendors, cloud tools, AI tools, and incidents reflected in risk review? |
The Main Clause 6 Audit Question
The strongest audit question is not, “Do you have a risk register?”
A better question is:
Can the organization prove that risks are assessed consistently, owned by the right people, treated through selected controls, reviewed by management, and supported by evidence?
Why Clause 6 Matters for Certification Readiness
A weak Clause 6 process can affect the entire ISMS.
If risks are outdated, the selected controls may be wrong.
If treatment actions are vague, the SoA may be misleading.
If risk acceptance is informal, leadership evidence may be weak.
1. Review the Risk Assessment Methodology
Start with the methodology.
The auditor should understand how the organization identifies, scores, reviews, treats, and accepts risk.
Audit Questions
- Is there a documented risk assessment methodology?
- How are likelihood and impact defined?
- What are the criteria for high, medium, and low risk?
- Who can accept risk?
- What triggers risk reassessment?
Common finding: the organization has a risk register, but no clear method for scoring, review, treatment, or acceptance.
2. Test Risk Identification
Risk identification should reflect the organization’s real operating environment.
It should not be limited to generic IT risks.
Audit test: compare the risk register against system inventory, vendor register, cloud inventory, AI tool inventory, incidents, audit findings, and client requirements.
Need to Review Clause 6 Before Certification?
Canadian Cyber helps organizations review ISO 27001 Clause 6 risk assessment and risk treatment evidence before certification, surveillance audits, and client security reviews.
We test risk registers, treatment plans, SoA alignment, risk acceptance, evidence ownership, SharePoint ISMS dashboards, and management readiness.
3. Review Risk Analysis and Evaluation
Risk scoring should be consistent.
The auditor should select a sample of risks and test whether each one follows the approved methodology.
| Sample Field | What to Verify |
|---|---|
| Risk description | Is the risk clear and specific? |
| Likelihood and impact | Are scores consistent with the methodology? |
| Current controls | Are existing controls documented? |
| Residual risk | Is residual risk explained? |
| Treatment decision | Is the decision documented and reasonable? |
Common finding: similar risks are scored differently because risk owners use different scoring logic.
4. Review Risk Owners
Every meaningful risk needs an owner.
The ISMS Manager may coordinate the register, but risk ownership should sit with the person who can manage the risk.
- Is each risk assigned to an owner?
- Does the owner understand the risk?
- Can the owner explain the treatment plan?
- Does the owner have authority to act?
- Are overdue treatment actions escalated?
Practical rule: the person who maintains the risk register is not always the person who owns the risk.
5. Review Risk Acceptance
Risk acceptance should be formal.
A risk marked “accepted” without approval is weak audit evidence.
- Which risks are accepted?
- Who approved acceptance?
- Is the acceptance rationale documented?
- Is there a review date?
- Are accepted high risks reviewed by management?
Practical rule: accepted risk should be a documented management decision.
6. Review Risk Treatment Decisions
Risk treatment explains what the organization will do about each risk.
The decision should be clear, assigned, tracked, and supported by evidence.
| Treatment Area | Audit Test |
|---|---|
| Treatment decision | Reduce, avoid, transfer, share, or accept. |
| Owner | Named person accountable for action. |
| Due date | Realistic target date with escalation path. |
| Evidence | Proof that treatment actions are complete or operating. |
Common finding: treatment actions say “mitigate” or “monitor,” but no owner, control, due date, or evidence is defined.
7. Review the Risk Treatment Plan
The risk treatment plan should translate risk decisions into action.
It should not be a static document.
8. Review SoA Alignment
The Statement of Applicability should align with risk treatment decisions.
This is one of the most important Clause 6 audit tests.
- Does the SoA reflect selected controls?
- Are applicable controls justified?
- Are non-applicable controls justified?
- Does each control have an owner and evidence?
- Was the SoA updated after risk changes?
Practical rule: the risk register, treatment plan, and SoA should tell the same story.
9. Review Information Security Objectives
Clause 6 also includes information security objectives.
Internal audit should test whether objectives are measurable, owned, risk-linked, and reviewed by management.
| Objective Example | Evidence |
|---|---|
| Complete quarterly access reviews. | Access review records and approval. |
| Review critical vendors annually. | Vendor review records and risk ratings. |
| Complete restore testing. | Restore test report and results. |
| Review AI tools before approved use. | AI tool register and approval records. |
10. Review Planning of Changes
When the business changes, risk should be reviewed.
The auditor should test whether changes leave a risk review trail.
Common finding: new systems, vendors, or AI tools were introduced without updating the risk register, SoA, or treatment plan.
Sample Clause 6 Finding Language
Weak Finding
Risk register needs improvement.
Stronger Finding
The risk register does not include current risks related to the new AI support drafting tool, the recently onboarded cloud monitoring vendor, or the customer support ticketing workflow that stores client information. The Risk Management Procedure requires new systems, vendors, and business processes to be reviewed for information security risk. Because these changes are missing from the risk register, the related treatment decisions, SoA mapping, and evidence requirements are incomplete.
How SharePoint Can Support Clause 6 Evidence
A SharePoint ISMS workspace can make Clause 6 easier to manage and audit.
It can connect risks, owners, treatment plans, controls, evidence, approvals, and management review actions.
Track risks, owners, ratings, and reviews.
Track treatment actions and deadlines.
Map controls, owners, and evidence.
Track approvals, rationale, and review dates.
Track metrics, owners, targets, and results.
Show overdue risks and missing evidence.
When Your Clause 6 Process Needs Help
Organizations may need professional support when these problems appear:
How Canadian Cyber Helps
Canadian Cyber helps organizations audit ISO 27001 Clause 6 risk assessment and risk treatment evidence before certification, surveillance audits, and client security reviews.
We help teams move from static risk registers to active risk-based ISMS management.
Our support includes risk methodology review, risk register testing, treatment plan review, SoA alignment, risk acceptance review, security objectives review, SharePoint dashboards, and certification readiness reporting.
Senior Advisory Support
Canadian Cyber also provides senior advisory support for ISO 27001 internal audits, risk evidence reviews, SoA alignment, SharePoint ISMS dashboards, corrective action tracking, and vCISO guidance.
Frequently Asked Questions
What is ISO 27001 Clause 6?
ISO 27001 Clause 6 focuses on planning. It includes risk assessment, risk treatment, information security objectives, and planning changes to the ISMS.
What evidence should auditors review for Clause 6?
Auditors should review the risk methodology, risk register, risk treatment plan, Statement of Applicability, risk acceptance records, security objectives, treatment evidence, management review minutes, and corrective action tracker.
How does the SoA connect to Clause 6?
The Statement of Applicability should reflect risk treatment decisions by identifying applicable controls, justifying exclusions, assigning owners, and linking controls to evidence.
Should AI tools be included in risk assessment?
Yes. AI tools should be included when they affect company data, customer data, source code, support workflows, vendor risk, decision-making, or regulated information.
Can Canadian Cyber help audit Clause 6?
Yes. Canadian Cyber helps organizations audit Clause 6, review risk assessment and treatment evidence, align the SoA, build SharePoint dashboards, prepare management review, and support certification readiness.
Takeaway
Clause 6 is where ISO 27001 proves that the ISMS is risk-based.
A strong internal audit should not only check whether a risk register exists.
It should test whether the methodology is defined, risks are current, owners are assigned, treatment decisions are documented, the SoA aligns with risks, and treatment evidence exists.
When Clause 6 is strong, the ISMS has direction. When Clause 6 is weak, the organization may have documents but no clear proof that those documents are connected to real risk.
Review Clause 6 Before Your ISO 27001 Audit
Canadian Cyber can help your organization review Clause 6 risk assessment and risk treatment evidence, align your SoA, build SharePoint ISMS dashboards, prepare management review, and close readiness gaps.
We support ISO 27001 internal audits, certification readiness, corrective action tracking, vCISO support, SOC 2 readiness, ISO 42001, ISO 27017, ISO 27018, and cybersecurity assessments.
Stay Connected With Canadian Cyber
Follow Canadian Cyber for practical guidance on ISO 27001 internal audits, Clause 6, risk assessment, risk treatment, certification readiness, SharePoint ISMS, SOC 2 readiness, AI governance, and vCISO services.
