ISO 27001 clause 6.1.2 is where most audit findings on risk documentation originate. It requires a documented, repeatable process for identifying, scoring, and treating information security risks — and evidence that you ran it.
In plain English, your risk register needs to show:
The register doesn't need to be sophisticated. It needs to be current, traceable, and consistent. Auditors fail teams not because the tool is wrong but because the register was updated the week before the audit and everyone knows it.
The most common ISO 27001 finding on risk documentation isn't a missing field. It's a register that can't answer: "Show me the link between this risk and the work that mitigated it."
A Confluence page can't show that. A spreadsheet can't show that. A Jira board with risk labels can't show that either — not without manual assembly that takes hours and still looks unconvincing to an auditor.
The second common finding: no pre-mitigation score. Teams record the risk after treatment, with a single score, and have no evidence of what it looked like before. ISO 27001 wants both states. The delta between them is what justifies your treatment decision.
If your current process can produce all eight with a direct link to Jira work — you're audit-ready. If it requires manual assembly, you're one audit cycle away from a finding.
We built Risk Manager for Jira to cover this exactly. It covers the risk register requirements for ISO 14971, ISO 26262, ISO 27001, and SOC 2 — identification, automated scoring, pre and post mitigation tracking, residual risk calculation, and a traceability table your auditor can follow without a guided tour.
A colour-coded risk matrix with drill-down shows which issues sit in each risk band.
Format Rules flag unowned or overdue risks automatically.
Risk logic — probability and severity labels — is configurable to match your SOPs or your specific standard.
It won't complete your certification for you, but the data your auditor needs is in Jira, traceable, and current. Available for Jira Cloud and Atlassian Government Cloud. Zero external storage. Try Risk Manager for Jira →
Published by Optimizory
Mahima - Optimizory
0 comments