How to answer
Do you perform regular security risk assessments?
The most enterprise-shaped question on the questionnaire, and the one small teams most often answer with an aspiration.
Yes. We maintain a risk register covering our production environment, our vendors and our internal systems. It is reviewed at least [annually] and after any material change to the product, and each risk carries an owner and a treatment decision.
Square brackets are yours to fill in. FillTrust grades an answer like this not in your documents when your documents support it.
- Answered from
- Your risk register if you keep one, and the governance section of your SOC 2 report.
- Evidence to attach
- Occasionally the register itself, usually with specific findings redacted.
- Where it is asked
- CAIQ v4.0 · GRC-02SIG LiteISO 27001 · Clause 6.1.2
This is the question that most clearly comes from ISO 27001, where risk assessment is the engine of the whole management system. Asked of a fifteen-person company it usually finds nothing, because risk decisions get made in conversations and never written down.
What it is actually asking. Whether somebody has sat down, listed what could go wrong, decided which of those things the company is going to do something about, and recorded the decision. That is it. It is not a methodology question and reviewers rarely ask which framework you used.
The smallest honest version is a real answer. A single sheet with ten rows: the risk, how likely, how bad, who owns it, and what you decided to do. Reviewed once a year and after anything significant changes. That is a risk register, it takes an afternoon to start, and it is defensible in a way that "we consider risk continuously as part of engineering" is not.
Do not confuse it with scanning. A vulnerability scanner tells you a dependency has a CVE. A risk assessment is where you decide that a single shared administrator account is a risk you are going to close this quarter and that the lack of a second region is one you are accepting for now. Reviewers ask about both separately, and answering this one with your scanner is a visible category error.
Accepting a risk is a legitimate outcome, and saying so helps. A register where every row is mitigated reads as fiction. One that records two accepted risks with a named owner and a reason reads as a company that makes decisions.
Where it interacts. Your answers about vendors, business continuity and access control all imply that someone weighed something. A register is where that weighing lives, which is why this question tends to appear early: it tells the reviewer how to read everything after it.
Expect this to come back as not in your documents, because it usually is not. Of all the gaps a questionnaire surfaces, this is among the more worthwhile ones to close, and the version worth closing it with is one page rather than a framework.
How this one goes wrong
Specific to this question, not general advice.
- Confusing this with vulnerability scanning. A scanner finds technical flaws; a risk assessment decides what the company is going to accept, mitigate or transfer.
- Describing an annual cadence you have never completed once. The follow-up is the date of the last assessment.
- Keeping a register with no owners and no decisions. A list of worries is not an assessment.