Risicomanagement

ISO 31000 Risk Management

ISO 31000:2018 (Risk management: Guidelines) is an international, non-certifiable guideline setting out principles, a framework and a process for risk management, applicable to any type of organisation and risk. It encompasses risk identification, evaluation, treatment, communication and monitoring, and emphasises value creation, integration into business activities, stakeholder engagement, human and cultural factors, and continual improvement. ISO 31000 is widely applied in audit, corporate governance and enterprise risk management systems, and offers guidance for audit and assurance programmes.

Source: ISO 31000:2018 Risk management: Guidelines

ISO 31000:2018 (Risk management: Guidelines) is an international, non-certifiable guideline for risk management, providing principles and guidance that enable any organisation to manage risks effectively, regardless of size, sector, or type of risk. The guideline sets out a coherent set of principles, a framework, and a process, and encompasses risk identification, evaluation, treatment, communication, and monitoring. ISO 31000 is widely applied in audit, corporate governance, and enterprise risk management systems.

For the board, the supervisory board, and the audit committee, ISO 31000 matters because it offers a recognisable, internationally accepted foundation for the organisation's risk management. It helps the board integrate risk management into decision-making rather than treating it as a separate exercise. For those charged with oversight, it provides a reference framework to assess whether the organisation approaches risk in a structured and consistent way.

In practice, ISO 31000 works with eight principles (including integration, a structured approach, customisation, and continual improvement), a framework that links leadership and governance to risk management, and an iterative process. That process runs from establishing context, through risk assessment (identifying, analysing, evaluating) and risk treatment, to communication, monitoring, and review. Unlike COSO ERM 2017, which is strongly strategy- and performance-oriented, ISO 31000 is deliberately generic and applicable to any type of risk.

At ONE Risk Advisory, we translate ISO 31000 into a workable risk management process that aligns with the organisation's governance. Unlike a certifiable standard, it is a framework that organisations tailor to their own context. We use the principles and the process to set up an approach that fits the nature and size of the organisation, without unnecessary bureaucracy.

Last updated:

Related service Governance & Control Design

Frequently asked questions

Can we be certified against ISO 31000?

No. ISO 31000:2018 is deliberately written as a guideline, not as a certifiable standard. Organisations can apply the principles and the process and have their risk management assessed, but there is no formal ISO 31000 certificate as there is for, say, ISO 9001.

What is the difference between ISO 31000 and COSO ERM 2017?

ISO 31000 is a generic guideline applicable to any type of risk and any organisation, emphasising a repeatable process. COSO ERM 2017 places stronger emphasis on the link between risk, strategy, and performance. The two are complementary and are often used together.

Which organisations is ISO 31000 suitable for?

ISO 31000 is suitable for any organisation, regardless of size or sector, because it is deliberately generic. The principles are scaled to the organisation's own context, so both a small entity and a large organisation can base a fitting risk management process on it.

← All terms