Risk methodology

One consistent method for both frameworks, so a single way of working produces evidence for ISO 27001 certification and a SOC 2 examination.

  1. 1. Establish context and scope

    Define which entity, services, systems and locations the register covers, and agree a risk appetite threshold with leadership. Scope is recorded on each register so it appears on your export.

    ISO 27001 cl. 4 & 6.1.1 · SOC 2 CC3.1

  2. 2. Identify risks

    For every asset or process, describe what could go wrong as an event: a threat exploiting a vulnerability, with a consequence. One risk per row — resist bundling several concerns together.

    ISO 27001 cl. 6.1.2 · SOC 2 CC3.2

  3. 3. Analyse and score

    Score likelihood and impact 1-5 using the scales below, based on the controls you have today. ISOSOC multiplies them into an inherent risk score and bands it Low to Critical automatically.

    ISO 27001 cl. 6.1.2 · SOC 2 CC3.2

  4. 4. Decide treatment

    Choose reduce, avoid, transfer or accept, write a specific plan, name an accountable owner and set a target date. Anything above your appetite needs a plan, not just a comment.

    ISO 27001 cl. 6.1.3 · SOC 2 CC9.1

  5. 5. Record residual risk

    Re-score likelihood and impact assuming the plan is fully implemented. The residual level is what the risk owner is formally accepting.

    ISO 27001 cl. 6.1.3 e) · SOC 2 CC3.4

  6. 6. Map to controls

    Tag each risk with the Annex A controls or Trust Services Criteria it relates to. This is what turns a register into evidence — and for ISO 27001 it feeds your Statement of Applicability.

    ISO 27001 Annex A / SoA · SOC 2 CC-series

  7. 7. Review and log changes

    Review at least quarterly and after any significant change, incident or new system. Record every material edit in the change log so auditors can see the register is live.

    ISO 27001 cl. 8.2, 9.3 · SOC 2 CC3.4, CC4.1

Scoring scales

Likelihood (1-5)

  • 1 — Rare. Unlikely to occur (once every 5+ years)
  • 2 — Unlikely. Could occur occasionally (every 2-5 years)
  • 3 — Possible. May occur at some point (annually)
  • 4 — Likely. Will probably occur (multiple times/year)
  • 5 — Almost certain. Expected to occur (frequently/continuously)

Impact (1-5)

  • 1 — Negligible. Minimal disruption, no data/financial/reputational loss
  • 2 — Minor. Limited disruption, small localised data or financial loss
  • 3 — Moderate. Noticeable disruption, contained breach, moderate cost
  • 4 — Major. Significant disruption, regulatory/breach notification triggered
  • 5 — Severe. Critical failure, large-scale breach, major regulatory/financial/reputational damage

SOC 2 registers use the same 1-5 shape, worded around service commitments and customer impact.

Risk matrix and bands

Risk score = likelihood x impact. ISOSOC bands the result as follows:

Low · 1-4Medium · 5-9High · 10-14Critical · 15-25
L ↓ / I →12345
112345
2246810
33691215
448121620
5510152025

Treatment options

  • Reduce (mitigate)
  • Avoid
  • Transfer (share)
  • Accept (retain)

Definitions for each option are in the glossary.