ISO 31000 Risk Management
ISO 31000:2018 is the international standard for risk management providing principles and guidelines for all organisations to manage risks effectively. The framework encompasses risk identification, evaluation, treatment, communication and monitoring. ISO 31000 is widely applied in audit, corporate governance and enterprise risk management systems.
Source: ISO 31000:2018 (Risk Management, Principles and Guidelines)
ISO 31000:2018 is the international standard for risk management, providing principles and guidelines that enable any organization to manage risks effectively, regardless of size, sector, or type of risk. The standard sets out a coherent set of principles, a framework, and a process, and encompasses risk identification, evaluation, treatment, communication, and monitoring. ISO 31000 is widely applied in audit, corporate governance, and enterprise risk management systems.
For the board, the supervisory board, and the audit committee, ISO 31000 matters because it offers a recognizable, internationally accepted foundation for the organization's risk management. It helps the board integrate risk management into decision-making rather than treating it as a separate exercise. For those charged with oversight, it provides a reference framework to assess whether the organization approaches risk in a structured and consistent way.
In practice, ISO 31000 works with eight principles (including integration, a structured approach, customization, and continual improvement), a framework that links leadership and governance to risk management, and an iterative process. That process runs from establishing context, through risk assessment (identifying, analyzing, evaluating) and risk treatment, to communication, monitoring, and review. Unlike COSO ERM 2017, which is strongly strategy- and performance-oriented, ISO 31000 is deliberately generic and applicable to any type of risk.
At ONE Risk Advisory, we translate ISO 31000 into a workable risk management process that aligns with the organization's governance. Unlike a certifiable standard, it is a framework that organizations tailor to their own context. We use the principles and the process to set up an approach that fits the nature and size of the organization, without unnecessary bureaucracy.
Last updated:
Related service Governance & Control Design
Frequently asked questions
Can we be certified against ISO 31000?
No. ISO 31000:2018 is deliberately written as a guideline, not as a certifiable standard. Organizations can apply the principles and the process and have their risk management assessed, but there is no formal ISO 31000 certificate as there is for, say, ISO 9001.
What is the difference between ISO 31000 and COSO ERM 2017?
ISO 31000 is a generic guideline applicable to any type of risk and any organization, emphasizing a repeatable process. COSO ERM 2017 places stronger emphasis on the link between risk, strategy, and performance. The two are complementary and are often used together.
Which organizations is ISO 31000 suitable for?
ISO 31000 is suitable for any organization, regardless of size or sector, because it is deliberately generic. The principles are scaled to the organization's own context, so both a small entity and a large organization can base a fitting risk management process on it.