Evidence
A risk assessment method you can actually repeat next year
The standard asks for a defined method applied consistently. Most first attempts are elaborate, one-off, and impossible to reproduce twelve months later.
Facts checked — 2026-09-11
What makes a risk assessment method repeatable?
Write down the method before you use it: what you assess, the scales for likelihood and impact and what each point on them means, how you combine them, and what threshold triggers treatment. Then the second run produces comparable numbers rather than a different person’s intuition.
Simple beats clever. A five-by-five matrix that everyone applies the same way is more useful than a weighted model only its author understands, because the value is in comparing this year to last and in defending a decision to an auditor who will ask why that risk scored what it did.
The bottom line
If a different person could not reproduce your scores from your written method, the method is not written yet.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.