Risk methodology
One consistent method for both frameworks, so a single way of working produces evidence for ISO 27001 certification and a SOC 2 examination.
1. Establish context and scope
Define which entity, services, systems and locations the register covers, and agree a risk appetite threshold with leadership. Scope is recorded on each register so it appears on your export.
ISO 27001 cl. 4 & 6.1.1 · SOC 2 CC3.1
2. Identify risks
For every asset or process, describe what could go wrong as an event: a threat exploiting a vulnerability, with a consequence. One risk per row — resist bundling several concerns together.
ISO 27001 cl. 6.1.2 · SOC 2 CC3.2
3. Analyse and score
Score likelihood and impact 1-5 using the scales below, based on the controls you have today. ISOSOC multiplies them into an inherent risk score and bands it Low to Critical automatically.
ISO 27001 cl. 6.1.2 · SOC 2 CC3.2
4. Decide treatment
Choose reduce, avoid, transfer or accept, write a specific plan, name an accountable owner and set a target date. Anything above your appetite needs a plan, not just a comment.
ISO 27001 cl. 6.1.3 · SOC 2 CC9.1
5. Record residual risk
Re-score likelihood and impact assuming the plan is fully implemented. The residual level is what the risk owner is formally accepting.
ISO 27001 cl. 6.1.3 e) · SOC 2 CC3.4
6. Map to controls
Tag each risk with the Annex A controls or Trust Services Criteria it relates to. This is what turns a register into evidence — and for ISO 27001 it feeds your Statement of Applicability.
ISO 27001 Annex A / SoA · SOC 2 CC-series
7. Review and log changes
Review at least quarterly and after any significant change, incident or new system. Record every material edit in the change log so auditors can see the register is live.
ISO 27001 cl. 8.2, 9.3 · SOC 2 CC3.4, CC4.1
Scoring scales
Likelihood (1-5)
- 1 — Rare. Unlikely to occur (once every 5+ years)
- 2 — Unlikely. Could occur occasionally (every 2-5 years)
- 3 — Possible. May occur at some point (annually)
- 4 — Likely. Will probably occur (multiple times/year)
- 5 — Almost certain. Expected to occur (frequently/continuously)
Impact (1-5)
- 1 — Negligible. Minimal disruption, no data/financial/reputational loss
- 2 — Minor. Limited disruption, small localised data or financial loss
- 3 — Moderate. Noticeable disruption, contained breach, moderate cost
- 4 — Major. Significant disruption, regulatory/breach notification triggered
- 5 — Severe. Critical failure, large-scale breach, major regulatory/financial/reputational damage
SOC 2 registers use the same 1-5 shape, worded around service commitments and customer impact.
Risk matrix and bands
Risk score = likelihood x impact. ISOSOC bands the result as follows:
| L ↓ / I → | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 1 | 1 | 2 | 3 | 4 | 5 |
| 2 | 2 | 4 | 6 | 8 | 10 |
| 3 | 3 | 6 | 9 | 12 | 15 |
| 4 | 4 | 8 | 12 | 16 | 20 |
| 5 | 5 | 10 | 15 | 20 | 25 |
Treatment options
- Reduce (mitigate)
- Avoid
- Transfer (share)
- Accept (retain)
Definitions for each option are in the glossary.