ISO 27001 Risk Assessment: Running a Risk Review Meeting That Stands Up to Audit

Most ISO 27001 risk assessment guidance focuses on the mechanics: identifying assets, scoring likelihood and impact, choosing treatments. But what actually gets examined at your certification audit is the evidence that real decisions were made by the right people — and that evidence lives in your risk review meeting minutes. A polished risk register with no record of management sign-off is a finding waiting to happen. This guide covers how to run the review meeting and document it so an auditor sees a living process, not a paperwork exercise.
Why the meeting matters more than the spreadsheet
Clause 6.1 of ISO 27001:2022 requires you to identify, analyse and evaluate information security risks — and clause 9.3 requires top management to review the ISMS, including the results of risk assessment and the status of risk treatment. Auditors test this by looking for two things:- A decision-making forum — evidence that risk owners and senior leadership actually discussed and accepted (or rejected) treatments.
- A paper trail — minutes, attendance records, and updated registers that show the discussion happened and produced outcomes.
When to hold the risk review
- At implementation. The first review approves your initial risk register, the risk acceptance criteria, and the Statement of Applicability rationale.
- At least annually. A full re-assessment with minuted management review — this is the cadence most certification bodies expect, and it should align with your management review cycle.
- On significant change. Mergers, new products, major system migrations, office moves, or a material incident should all trigger an out-of-cycle review, even a short one.
Who should be in the room
Keep it small enough to make decisions, broad enough to be credible:- The ISMS lead or CISO-equivalent — facilitates, presents the register, and captures the minutes.
- A member of top management — the person with authority to accept risk on behalf of the organisation and commit budget. Without them, risk acceptance decisions carry no weight.
- Risk owners — the operational managers accountable for the risks being discussed (IT, HR, facilities, finance, product as relevant).
- A scribe — ideally not the facilitator. Splitting presenting from minuting is the easiest way to get usable minutes.
Structuring the agenda
A tight agenda keeps the meeting to 60–90 minutes and produces minutes that map cleanly to audit requirements:
- Welcome and context — confirm the meeting's purpose, note attendees and apologies, and reference the risk assessment methodology being applied.
- Review of previous actions — status of treatments agreed last time: done, in progress, or overdue (and why).
- New and changed risks — anything identified through incidents, audits, change management, or the business environment since the last review.
- Risk register walk-through — re-validate scores for existing risks; challenge stale likelihood or impact ratings.
- Treatment decisions — for each risk above the acceptance threshold: treat, transfer, avoid, or accept — with a named owner and a target date for every treatment.
- Residual risk acceptance — explicit sign-off by management on the residual risk position. This is the moment auditors are looking for.
- Next review date and close — lock in the next scheduled review so the cycle is visible.
Running the discussion well
- Work from the register, not from memory. Screen-share the live document and update it in the meeting where possible — what you see changing is what the minutes record.
- Force explicit decisions. "We noted the risk" is not a decision. Each item should end with a treatment choice, an owner, and a date, or a conscious acceptance.
- Challenge scores out loud. If someone argues a likelihood down from "likely" to "possible", record the reasoning. The debate is the evidence that assessment actually occurred.
- Don't accept risk by default. If a risk above threshold gets no funded treatment, the minutes should show management consciously accepting it — with a review date, not indefinitely.
Writing minutes that serve as audit evidence
Minutes don't need to be long — two to four pages is typical — but they must be specific. For each risk discussed, capture:- The risk — a short identifier or description matching the register entry.
- The decision — treat / transfer / avoid / accept, in those words.
- The rationale — one or two sentences on why, especially for acceptances and score changes.
- The owner and due date — for every treatment action.
- Attendees, date, and approval — who was present, when the minutes were circulated, and when they were accepted (usually at the next meeting).
- Update the risk register the same day, so the register and minutes never disagree.
- Feed actions into your corrective action log so overdue treatments surface at internal audit.
- Reference the minutes in your management review inputs — clause 9.3 explicitly expects risk assessment results there.
Keeping the cycle alive
One good meeting doesn't make a process. Schedule the next review before everyone leaves the room, track treatment actions between meetings, and feed the outputs into your internal audit programme so an independent set of eyes tests whether treatments were implemented. If your team lacks the capacity to facilitate this, a virtual CISO can chair the review and keep the evidence trail clean.
Run the meeting like it will be read by a stranger — because it will be. Clear decisions, named owners, dated actions, and approved minutes turn a risk assessment from a spreadsheet into audit-proof evidence.
Assess your ISO 27001 readiness with our FREE ISO 27001 Gap Assessment Tool — instant results, no sign-up required.
Need Help With Your Security?
Our team of experts can guide you through implementation and certification. Start with a free assessment.
Start Free Assessment