+421 917 743 382
Free consultation

Risk analysis and risk management

Risk analysis: the input to your audit, not an appendix to it

A risk analysis is not something you attach to an audit — it is what the audit starts from. We build it with you, and the risk register stays with you in a form you can keep working with.

Where your risk analysis stands

Four questions. The result shows what is missing for a usable analysis and in what order to deal with it.

Go through the four questions yourself. Next to each is what your answer tells you.

  1. Why do you need a risk analysis? The framework decides the scope, the form of the output and who approves it. If you are not sure, that is the first thing to settle.
  2. What state is your risk analysis in today? If it is not current and formally approved, that is the first gap an auditor sees — and usually the quickest to close.
  3. Do you have an asset inventory? Without an inventory with owners there is nothing to assess, and nobody answers for treating the risk.
  4. What should the analysis cover? An undefined scope means completeness cannot be shown, and leaving operational technology out leaves the gap in the most visible place.

Two ways to continue

The method is not prescribed

In practice, most organisations manage with a qualitative approach — a likelihood × impact matrix — as long as they can defend it. A semi-quantitative approach works with indices, a quantitative one with financial modelling. The choice depends on the requirements that apply to you, on the standards you already use and on what the organisation needs.

If you want a reference process, ISO/IEC 27005 describes one: establishing the context, identifying, analysing and evaluating risks, treating them, and monitoring and reviewing the result. It is written to fit ISO/IEC 27001. If you already have a methodology in place — because of ISO/IEC 27001 or group rules, for example — there is no point in replacing it.

One risk register, several frameworks

More than one framework asks you for a risk analysis at the same time.

  • ISO/IEC 27001. Clause 6.1.2 asks for a defined information security risk assessment process, and clause 8.2 for the assessment to be repeated — on a schedule you set and whenever something significant changes. Alongside it, clause 6.1.3 expects a risk treatment plan and a Statement of Applicability, and the three have to tell the same story.
  • GDPR. Article 32 requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the risk of varying likelihood and severity for the rights and freedoms of natural persons. The risk that counts is the risk to people, not to the organisation — the same assets, seen from the other side.
  • DORA. Financial entities must have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system (Article 6(1)). As part of that framework they have to identify, classify and adequately document all ICT supported business functions, roles and responsibilities, the information assets and ICT assets supporting those functions, and their roles and dependencies in relation to ICT risk (Article 8(1)). The framework has to be reviewed at least once a year (Article 6(5)); microenterprises review it periodically.

What follows in practice. If you face ISO/IEC 27001 certification and also answer to GDPR or DORA, do not build two analyses. One risk register with two views of the output is usually cheaper, stays consistent and is easier to defend at audit than two documents that rate the same asset differently.

Five reasons a risk analysis does not hold up at audit

In our audits these recur across sectors — and all five can be fixed before the audit.

  1. A one-off document. The analysis was written once and has not been updated since. The date on the document gives it away at once.
  2. A borrowed catalogue, not adapted. A generic list of threats that fits any company — and therefore none. The auditor asks about one specific asset and the connection falls apart.
  3. Assets without owners. If nobody is responsible for an asset, nobody is responsible for treating its risk. It is a common reason why measures stay in the document and never reach operations.
  4. Operational technology left out. Control systems, production lines and building technology are missing from the scope.
  5. Risks with no measures attached. A list of risks that leads to no measure does not show that anything is being done about them.

Three levels — start with the one you need

  • Developing the risk analysis. Identifying and valuing assets, including their owners; threats and vulnerabilities tailored to your environment; evaluating risks with the method you choose; and a proposal for accepting residual risk — plus the source risk register you can keep working with.
  • Ongoing risk management. Reviewing risks and re-assessing accepted ones, updating after a significant change or incident, tracking how measures are implemented, and material for management in a form it can read and approve.
  • Anrix — a risk management system. If you want to run it yourself: an asset register with owners, a risk register and a measure catalogue linked together, change history and an approval step. See what Anrix does.

Why a tool, when a spreadsheet will do

For a first analysis a spreadsheet really is enough, and we will not claim otherwise. It stops being enough when someone has to show, a year later, what changed and who approved it.

  • A spreadsheet has no history. It cannot show when and why a rating changed.
  • A spreadsheet has no links. Asset, risk, measure and owner sit next to each other, not together.
  • A spreadsheet has no approval. It does not show who signed off the acceptance of residual risk.

That is what Anrix is for: the same register, with the history, the links and the approval step.

Where our role ends

We do the analysis with an auditor’s eye: the difference between an analysis that looks good and one that holds up is visible only from the other side of the table.

Neither a tool nor a consultant can decide for you which asset is critical and whether residual risk is acceptable. That is a decision management signs — and that is how it should be.

If you would rather run the analysis yourself, start with Anrix. If you want to talk it through first, the form below reaches us.

Status verified as of 10 October 2026.

Tell us what you are dealing with.

Thirty minutes with a consultant who knows your industry. The output is a one-page summary with a recommended approach and an indicative scope — we send it to you even if we do not reach an agreement.

info@iosec.eu
+421 917 743 382

Please fill in your name.
Please fill in your organisation.
Please give an address we can reply to.
Please choose a topic.
Please confirm you have read the privacy notice.

No newsletter, no sales sequence — we answer the question you asked.

Call us Free consultation