Sentrix

ISO 27001 guide · Clause 8

8.2 — Information security risk assessment

Clause 8.2 requires you to repeat the risk assessment at planned intervals or when a significant change occurs, using the 6.1.2 criteria, and keep the results.

By Sentrix · Published 2026-07-16

A risk assessment done once, at certification, and never again is not a risk assessment—it is a snapshot of a moment that no longer exists.

Mandatory requirement · Documented information required: yes

In plain language

8.2 requires you to actually perform your risk assessment again—at planned intervals, or whenever a significant change is proposed or happens—using the criteria you established under clause 6.1.2, and to keep the results as evidence each time.

Why this requirement exists

Risk is not static. New systems get adopted, staff turn over, threat actors change tactics, and business priorities shift—a risk assessment from certification day describes an organization that, eighteen months later, may no longer exist in the same form. This requirement forces the assessment to keep pace with reality instead of becoming a historical artifact.

Scenario: a company certifies with a risk assessment built around an on-premises environment, then migrates most workloads to the cloud over the following year without ever reassessing risk against the new architecture. At the surveillance audit, the risk register still describes infrastructure that no longer exists—a direct 8.2 finding, independent of how good the cloud migration itself was.

What the standard expects

The standard expects the organization to perform information security risk assessments at planned intervals, or when significant changes are proposed or occur, taking account of the criteria established under 6.1.2 a). The organization must retain documented information of the results of each information security risk assessment.

In practice

  • Fix a planned interval (annually is common) for a full risk assessment refresh, independent of any changes.
  • Define what counts as a "significant change" for your organization (new system, new office, major reorg, new regulatory obligation) so the trigger is not left to judgment in the moment.
  • Reuse the exact criteria and scales from your 6.1.2 methodology each time, so results stay comparable year over year.

Evidence the auditor will ask for

  • A history of risk assessment results showing they were performed on the planned schedule.
  • Evidence that significant changes (system migrations, new offices, major reorgs) triggered an out-of-cycle reassessment.

Common pitfalls

  • A single risk assessment performed at certification, never repeated by the first surveillance audit.
  • A major infrastructure or organizational change that never triggered a fresh risk assessment.

Related requirements

Sources

Frequently asked questions

How often is "planned intervals" in practice?
The standard does not fix a number. Annually is the most common cadence, aligned with the certification cycle, though higher-risk organizations sometimes reassess semi-annually. What matters is fixing the interval in advance and keeping to it, independent of any changes, so the auditor sees a history of results rather than a single assessment.
Can the reassessment use a different method than the original?
It should use the same criteria established under 6.1.2 so results are comparable over time. Changing methodology between cycles makes it hard to show trends or prove consistency. Reuse the exact criteria and scales from your methodology each time, so results stay comparable year over year.
What counts as a significant change?
The standard does not define it for you: the organization sets it in advance—new system, new office, major reorg, new regulatory obligation—so the trigger is not left to judgment in the moment. A cloud migration that never triggered a reassessment is a direct 8.2 finding, however well the migration itself went.

Let's talk about your compliance program.

Last updated: 2026-09-17