Every ISO 27001 certification starts in the same place, not with policies or controls, but with risk. Before an organization can decide how to protect its information, it has to understand what could go wrong, how likely it is, and how much damage it could cause. That's the entire purpose of a risk assessment, and it's arguably the most important step in the whole certification process.
Organizations often run into the same pitfalls when conducting a risk assessment for the first time.