Enquire Us

What is ISO 31000?

ISO 31000 is the ISO guideline for risk management. ISO states plainly that it is not a certifiable standard, so no certification body issues an ISO 31000 certificate. This page explains what it contains and how organisations use it.

Definition and publisher

ISO 31000 is an international standard published by the International Organization for Standardization. Its full title is Risk management, Guidelines, and the current edition is ISO 31000:2018. As the title indicates, it is a guidance document. It gives principles, a framework and a process for managing risk of any type, in any organisation, at any scale.

The most important thing to understand about ISO 31000 is what it is not. ISO states in its own guidance on the standard that ISO 31000 is not a certifiable standard and is not intended for certification purposes. It contains recommendations, not auditable requirements, so there is nothing for a certification body to audit an organisation against. Any claim that a certification body issues an accredited ISO 31000 certificate after a Stage 1 and Stage 2 audit, with annual surveillance and a three year cycle, is factually wrong. That model applies to management system standards written as requirements, such as ISO/IEC 27001, ISO 22301 and ISO 9001, and ISO 31000 is not one of them.

The eight principles

ISO 31000:2018 opens with a set of principles that describe what effective risk management looks like. Risk management should be:

  • Integrated, forming part of all organisational activities rather than a separate exercise run by a risk team.
  • Structured and comprehensive, so that it produces consistent and comparable results.
  • Customised, proportionate to the organisation’s external and internal context and to its objectives.
  • Inclusive, drawing in stakeholders so that their knowledge, views and perceptions are considered.
  • Dynamic, anticipating and responding to change as risks emerge, alter and disappear.
  • Based on the best available information, taking account of the limitations and uncertainty of that information.
  • Attentive to human and cultural factors, which significantly influence how risk is perceived and managed.
  • Continually improved, through learning and experience.

The framework and the process

Beyond the principles, ISO 31000 describes two structural elements. The framework is about embedding risk management in the organisation: securing leadership commitment and accountability, understanding the organisation and its context, designing the arrangements, allocating roles and resources, implementing them, evaluating how well they work and improving them. Leadership commitment is treated as the pivot. The standard is explicit that the governing body and top management are responsible for ensuring risk management is integrated into all activities.

The process is the working sequence applied to actual risks:

  • Communication and consultation with stakeholders, which runs throughout rather than as a step.
  • Defining scope, context and criteria, which sets what is being assessed, the internal and external environment, and the criteria against which risk significance will be judged.
  • Risk assessment, comprising risk identification, risk analysis and risk evaluation.
  • Risk treatment, selecting and implementing options, which may include avoiding the risk, taking or increasing it to pursue an opportunity, removing the source, changing likelihood or consequence, sharing it, or retaining it by informed decision.
  • Monitoring and review of both risks and the arrangements themselves.
  • Recording and reporting, which turns the process into an auditable record and feeds decision making.

ISO 31000 defines risk as the effect of uncertainty on objectives, which is deliberately neutral. The effect can be positive as well as negative, which is why the treatment options include taking on risk in pursuit of an opportunity.

Related standards and how conformity is demonstrated

ISO 31000 does not stand alone. Two companion documents are commonly used with it:

  • IEC 31010:2019, Risk management, Risk assessment techniques, which describes a large catalogue of techniques for identifying and analysing risk, from structured interviews and checklists through to fault tree analysis and Bayesian methods.
  • ISO 31073:2022, Risk management, Vocabulary, which fixes the terminology used across the family.

Since certification is not available, organisations demonstrate alignment with ISO 31000 in other ways. The usual routes are an internal or independent gap assessment against the principles, framework and process, with the findings reported to the audit or risk committee; a documented risk management policy and framework that references ISO 31000 explicitly; a maintained risk register with owners, criteria, treatment plans and review dates; and, where an organisation wants a certified system, adopting a requirements standard that uses ISO 31000 concepts, such as ISO/IEC 27001 for information security risk or ISO 22301 for business continuity. Individuals can also hold risk management qualifications, but that is a personal credential and is not the same as organisational certification.

How Univate uses ISO 31000

Univate applies ISO 31000 as the underlying risk discipline in most of the management system work it delivers, because a credible risk assessment is what makes a certified system defensible. Typical work includes:

  • Designing a risk management framework and policy fitted to the organisation’s size, sector and governance structure, with defined risk appetite and risk criteria.
  • Running risk identification and analysis workshops using techniques drawn from IEC 31010 rather than a single generic template.
  • Building or rebuilding the risk register so that risks are stated as cause, event and consequence, with named owners and treatment plans that have dates.
  • Aligning the risk process so that the same method serves information security risk assessment under ISO/IEC 27001, business impact analysis and risk assessment under ISO 22301, and enterprise risk reporting to the board.
  • Gap assessment against ISO 31000 where a client or regulator has asked for evidence of alignment.

Univate does not offer ISO 31000 certification, because it does not exist. Where a client needs a certificate, the honest answer is to identify which certifiable standard actually meets the underlying requirement.

Frequently asked questions about ISO 31000

Can an organisation be certified to ISO 31000?

No. ISO states that ISO 31000 is not a certifiable standard and is not intended for certification purposes. It is written as guidance rather than as auditable requirements, so no accredited certification body issues an ISO 31000 certificate.

What is the current version of ISO 31000?

The current edition is ISO 31000:2018, Risk management, Guidelines, published by the International Organization for Standardization.

What are the eight principles of ISO 31000?

Risk management should be integrated, structured and comprehensive, customised, inclusive, dynamic, based on the best available information, attentive to human and cultural factors, and continually improved.

What is the ISO 31000 risk management process?

The process comprises communication and consultation, establishing scope, context and criteria, risk assessment made up of identification, analysis and evaluation, risk treatment, monitoring and review, and recording and reporting.

How does ISO 31000 relate to IEC 31010?

IEC 31010:2019 is the companion standard on risk assessment techniques. ISO 31000 tells you what the process is and IEC 31010 provides the catalogue of techniques you can apply within the identification and analysis steps.

If we cannot be certified, how do we prove we follow ISO 31000?

Organisations evidence alignment through a documented risk management framework and policy that reference the standard, a maintained risk register with owners and treatment plans, an internal or independent gap assessment reported to the audit or risk committee, and, where a certificate is genuinely required, certification to a requirements standard such as ISO/IEC 27001 or ISO 22301 that embeds the same risk approach.

Need a risk management framework that will stand up in an ISO audit or a board review? Talk to Univate about an ISO 31000 aligned risk programme.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.