Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 31000

Risk Management Guidelines

Governance & Social Published: 2018

ISO 31000:2018 at a glance

Current edition
ISO 31000:2018 - Risk management — Guidelines
Published
2018
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Previous edition
ISO 31000:2009
Official ISO page
View ISO 31000:2018 on iso.org
Last verified

Overview

Guidelines providing principles, a framework and a process for managing risk of any kind; guidance only, not intended for certification

ISO 31000:2018 provides guidelines on managing risk faced by organizations. It is deliberately generic: it can be applied to any type of risk, at any level of an organization, throughout its life, and to any activity, including decision-making at the highest levels. It is not specific to an industry or sector. The second edition replaced ISO 31000:2009 and was confirmed by systematic review in 2023; a further revision is currently in progress within ISO/TC 262.

ISO explicitly states that ISO 31000 is not intended for the purpose of certification. There is no such thing as an accredited ISO 31000 certificate for an organization. Training providers do offer personal qualifications based on the standard, but these certify individuals, not management systems. Organizations that want a certifiable framework use a management system standard (such as ISO 9001, ISO 14001, ISO 27001 or ISO 22301) and apply ISO 31000's thinking inside it.

The standard is built on three connected elements. The principles describe what effective risk management should be: integrated, structured and comprehensive, customized, inclusive, dynamic, based on the best available information, taking human and cultural factors into account, and subject to continual improvement — all serving the central purpose of creating and protecting value.

The framework is about embedding risk management into the organization's governance, strategy, planning and culture. It comprises leadership and commitment (which the 2018 edition places at the centre, as a responsibility of top management and oversight bodies), followed by integration, design, implementation, evaluation and improvement of the framework itself.

The process applies the principles and framework to actual decisions. It consists of establishing scope, context and risk criteria; risk assessment, made up of risk identification, risk analysis and risk evaluation; and risk treatment. Running alongside these are communication and consultation, monitoring and review, and recording and reporting. The 2018 edition is markedly shorter and more principles-based than the 2009 edition, with more emphasis on integration into decision-making and less prescriptive process detail.

ISO 31000 is supported by IEC 31010 (risk assessment techniques), which catalogues methods such as bow-tie analysis, FMEA, scenario analysis and Monte Carlo simulation, and by ISO 31073 (risk management vocabulary), which replaced ISO Guide 73. Sector and topic adaptations of the same architecture appear in ISO/IEC 27005 for information security risk, ISO/IEC 23894 for AI risk, and the risk clauses of every ISO management system standard.

Purpose

To provide a common, sector-neutral set of principles, an organizational framework and a repeatable process for managing risk, so that risk considerations are integrated into governance, strategy and day-to-day decision-making.

Key Benefits

  • Gives a single, common risk vocabulary and process that can be applied across all risk types and business units
  • Integrates risk management into decision-making rather than treating it as a separate compliance exercise
  • Clarifies the accountability of top management and oversight bodies for risk
  • Scales to organizations of any size and to any activity, from strategic planning to individual projects
  • Provides the underlying architecture used by the risk clauses of ISO management system standards
  • Improves consistency of risk reporting and comparability of risk information across an organization
  • Encourages explicit consideration of human, cultural and behavioural factors
  • Supports better use of the best available information, including its limitations and uncertainty
  • Works alongside IEC 31010 so that technique selection is deliberate rather than habitual
  • Adaptable to sector-specific risk standards without needing to change the underlying model

Key Requirements

  • Note: ISO 31000 is a guidance document — its clauses are recommendations, not auditable requirements
  • Apply the risk management principles, with value creation and protection as the central purpose
  • Secure leadership and commitment from top management and oversight bodies
  • Integrate risk management into the organization's governance, structure and decision-making
  • Design the framework: understand the organization and its context, articulate commitment, assign roles and authorities, allocate resources, establish communication and consultation
  • Implement, evaluate and continually improve the framework
  • Establish the scope, context and risk criteria for each application of the process
  • Identify risks, including sources, events, causes and potential consequences
  • Analyse risks, considering likelihood, consequences, controls and their effectiveness
  • Evaluate risks against criteria to decide on further action
  • Select and implement risk treatment options and prepare and implement treatment plans
  • Communicate and consult with stakeholders throughout the process
  • Monitor and review risks, controls and the process itself
  • Record and report the process and its outcomes

Who Needs This Standard?

Any organization, of any size or sector, that wants a consistent basis for managing risk — including boards and executives setting risk appetite, risk and audit functions, project and programme managers, and specialists building sector-specific risk frameworks on a recognised foundation.

Where to get ISO 31000

The full text of ISO 31000 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 31000 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 31000, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Related Standards