Enquire Us

ISO 22301 vs ISO 31000

ISO 22301 and ISO 31000 are both published by the International Organization for Standardization (ISO), but they are different kinds of document and they are not interchangeable. ISO 22301:2019 is a certifiable management system standard for business continuity, developed by ISO technical committee ISO/TC 292 on security and resilience. ISO 31000:2018 is a guidance document on risk management from ISO/TC 262, and ISO states that it is not intended for certification purposes. This page sets out what each document actually requires and how to decide which one your organisation needs.

What is ISO 22301?

ISO 22301:2019 carries the full title Security and resilience: Business continuity management systems: Requirements. It is a requirements standard, which means every shall statement in it is auditable and an accredited certification body can issue a certificate against it. ISO published Amendment 1 in 2024 to add climate action considerations, in line with the joint ISO and IAF communique issued in February 2024 that applied the same change across the management system standards.

A conforming business continuity management system typically covers:

  • A defined scope, a business continuity policy and top management commitment.
  • Business impact analysis, which identifies prioritised activities and the recovery time objectives and recovery point objectives that go with them.
  • Risk assessment for the disruption scenarios that could affect those activities.
  • Business continuity strategies and solutions, including resourcing, alternate sites and supplier arrangements.
  • Documented business continuity plans and incident response structures.
  • Exercising and testing of those plans, plus evaluation of the results.
  • Internal audit, management review and continual improvement.

ISO 22301 follows the harmonised high level structure shared by ISO management system standards, so it integrates cleanly with ISO 9001, ISO 14001, ISO 45001 and ISO/IEC 27001. An accredited ISO 22301 certificate is valid for three years, subject to annual surveillance audits, with a recertification audit at the end of the cycle. The companion guidance document is ISO 22313, and ISO 22300 holds the vocabulary for the security and resilience family.

What is ISO 31000?

ISO 31000:2018 carries the title Risk management: Guidelines. It is the second edition, published in February 2018 by ISO/TC 262. It is a guidance document, not a requirements standard, and ISO is explicit that it is not a certifiable risk management standard. No accredited certification body can issue an organisation an ISO 31000 certificate. Personal training certificates in ISO 31000 exist, but they certify the individual, not the organisation.

The document is built around three linked parts:

  • Principles. The characteristics that make risk management effective, including that it is integrated, structured, customised, inclusive, dynamic and based on the best available information.
  • Framework. How leadership integrates risk management into governance, strategy, roles, resources and communication, then evaluates and improves it.
  • Process. Scope and context setting, risk identification, risk analysis, risk evaluation, risk treatment, plus monitoring, review, recording and reporting throughout.

ISO 31000 is deliberately generic. It applies to every category of risk an organisation faces, including strategic, financial, operational, safety, environmental and security risk, not only disruption risk. The companion documents are IEC 31010:2019, which catalogues risk assessment techniques, and ISO 31073:2022, which holds the risk management vocabulary that previously sat in ISO Guide 73.

ISO 22301 vs ISO 31000: side by side

AttributeISO 22301:2019ISO 31000:2018
Full titleSecurity and resilience: Business continuity management systems: RequirementsRisk management: Guidelines
Issuing bodyInternational Organization for Standardization (ISO)International Organization for Standardization (ISO)
Technical committeeISO/TC 292, Security and resilienceISO/TC 262, Risk management
Document typeRequirements standard, written with shall statementsGuidance document, written with should statements
Certifiable?Yes. Accredited certification bodies issue certificates against it.No. ISO states it is not intended for certification purposes.
Subject matterContinuity of prioritised activities through and after a disruptionManagement of risk of any type, across the whole organisation
Core analytical methodBusiness impact analysis plus risk assessment for disruption scenariosRisk identification, analysis, evaluation and treatment
Key outputsRecovery time objectives, recovery point objectives, continuity strategies, plans, exercise recordsRisk criteria, risk register, treatment plans, integrated governance arrangements
Assurance modelStage 1 and Stage 2 certification audit, annual surveillance, three year cycleSelf assessment, internal audit or a second party review against the guidance
StructureHarmonised high level structure shared with other ISO management system standardsPrinciples, framework and process. Not a management system structure.
Recent changeAmendment 1:2024 added climate action considerationsConfirmed on review in 2023 and listed by ISO as under revision
Typical ownerBusiness continuity manager, resilience or operations functionChief risk officer, risk and governance function, board risk committee

Which one do you need?

The decision usually comes down to whether you have to prove something to a third party.

  • Choose ISO 22301 if a client, tender, regulator or insurer has asked for evidence of business continuity capability. A certificate is the only artefact of the two that an external party can verify through an accreditation body.
  • Choose ISO 31000 if you are building or repairing enterprise risk governance and want a recognised reference model. It gives you a common vocabulary and a framework the board can be held to, without an audit programme attached.
  • Use both if you want the risk framework to feed the continuity system. In practice the ISO 31000 process supplies the risk criteria and appetite that make the ISO 22301 risk assessment meaningful, and the business impact analysis feeds prioritised activities back into the enterprise risk register.

They are not alternatives competing for the same budget line. ISO 31000 tells you how to think about risk. ISO 22301 tells you what you must have in place, and lets you prove it. If someone offers you an accredited ISO 31000 certificate for your organisation, treat that as a warning sign about the provider.

Frequently asked questions

Can an organisation be certified to ISO 31000?

No. ISO 31000:2018 is published as a guidance document and ISO states that it is not intended for certification purposes. There is no accredited certification scheme for it. Individuals can hold ISO 31000 training or lead risk manager certificates, but those certify a person’s competence, not an organisation’s risk management system.

Is ISO 22301 certification accredited?

Yes. ISO 22301:2019 is a requirements standard, so certification bodies accredited by a national accreditation body that is a signatory to the IAF Multilateral Recognition Arrangement can audit and certify against it. The certificate is valid for three years, with annual surveillance audits and a recertification audit at the end of the cycle.

Does ISO 22301 replace ISO 31000?

No. They cover different ground. ISO 22301 is limited to business continuity, which is one part of the risk landscape. ISO 31000 covers risk management as a whole, including strategic, financial, compliance and operational risk that has nothing to do with disruption. Implementing one does not satisfy the other.

Which standard should come first?

If you have no formal risk framework at all, starting with ISO 31000 gives you the vocabulary, risk criteria and governance structure that the ISO 22301 risk assessment will otherwise have to invent. If you have a fixed deadline from a client or tender, start with ISO 22301 and align the risk framework as you go.

What is the relationship between ISO 22301 and ISO 22313?

ISO 22301 states the requirements. ISO 22313 is the guidance document that explains how to meet them and gives worked examples. You are audited against ISO 22301, not ISO 22313.

Do ISO 22301 and ISO 31000 use the same definition of risk?

Broadly yes. The risk management vocabulary now sits in ISO 31073:2022, which replaced ISO Guide 73, and the security and resilience family uses ISO 22300 for its own terms. Both treat risk as the effect of uncertainty on objectives, so the two documents can be used together without a terminology clash.

Univate Solutions supports business continuity management system implementation and ISO 22301 certification readiness, and helps risk functions align their framework with ISO 31000. Book a consultation to talk through which route fits your obligations.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.