Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 31000 risk management — principles, framework and process

ISO 31000 Risk Management: The 3 Components Explained

ISO 31000 is the standard organisations most often cite and least often read. It is sixteen pages long, it contains no requirements, and nobody can certify you against it — three facts that between them explain most of the confusion around it.

Used properly it is the best available description of what risk management is supposed to look like when it works. Used badly it becomes a logo on a policy nobody follows.

What ISO 31000 actually is

ISO 31000:2018Risk management — Guidelines — is the second edition, published in February 2018 and confirmed on review in 2023. It is developed by ISO/TC 262 and runs to sixteen pages.

The word in the title is Guidelines, and it is doing real work. A requirements standard uses “shall” and can be audited. A guidelines standard uses “should” and cannot. That is why:

  • There is no certification. An organisation cannot be certified to the standard, and any certificate claiming otherwise is describing something else — usually a training course or a consultant’s own scheme.
  • There is no conformity to demonstrate. You align with it, you do not comply with it.
  • It is deliberately generic. It applies to any organisation, any sector and any kind of risk, which is why it says less about technique than people expect.

Techniques live in the companion standard, IEC 31010:2019Risk assessment techniques — which is where you go when you want to know how to actually run a bow-tie analysis or a Monte Carlo simulation. Vocabulary lives in ISO 31073.

The three components of ISO 31000

The three components of ISO 31000 — principles, framework and process

ISO 31000 is built from three parts, and the relationship between them is the whole design.

Principles describe what effective risk management looks like: integrated, structured and comprehensive, customised, inclusive, dynamic, based on the best available information, alive to human and cultural factors, and continually improving. They are characteristics to test yourself against, not steps to follow.

Framework is how risk management gets embedded in the organisation — leadership and commitment at the centre, surrounded by design, implementation, evaluation and improvement. This is the part organisations skip, and skipping it is why so many risk registers exist without changing any decision.

Process is the working cycle most people already recognise: establish scope, context and criteria; identify, analyse and evaluate risk; treat it; monitor and review; record and report. Communication and consultation run alongside all of it rather than at the end.

What the 2018 edition changed, and why it matters

The first edition dated from 2009. The revision cut the length roughly in half, simplified the language, and moved leadership from a supporting role to the centre of the framework.

The intent behind that reordering is the single most useful idea in the standard: risk management is meant to be part of governance and decision-making, not a parallel activity that produces its own documents. A risk process that runs monthly and never touches a strategy meeting is not what ISO 31000 describes, however well the register is maintained.

A third edition is being drafted

Worth knowing before you build anything durable on the current text: ISO has recorded the 2018 edition at stage 90.92 — International Standard to be revised, and a revision is genuinely under way. ISO/CD 31000 sits at stage 30.60, meaning a committee draft has been circulated and its comment period closed.

Two sensible conclusions. First, 2018 remains the current standard and will be for some time — a committee draft still has to pass DIS and FDIS stages before publication, and that is measured in years, not months. Second, do not architect a risk framework around specific clause numbers when the clause numbering is being revisited. Structure it around the three components, which are very unlikely to change.

Where ISO 31000 fits against certifiable standards

Standard Relationship
ISO 27001 Requires a risk assessment and treatment process but does not mandate a method. ISO 31000 is the most common answer to “which method?” — and clause 6.1.2 is written so that a 31000-aligned process satisfies it cleanly
ISO 9001 Uses risk-based thinking throughout without requiring a formal risk process. The guidelines give you one if you want it
ISO 22301 Business continuity sits downstream of risk assessment. A shared risk approach stops the continuity and security teams maintaining two incompatible registers
ISO 37301, ISO 45001, ISO 14001 Every modern management system standard has a risk clause. Running one method underneath all of them is the practical reason to adopt ISO 31000 at all

That last row is the real business case. The value is not in the standard itself — it is in having one definition of risk, one set of criteria and one register, rather than four teams grading the same exposure differently.

What implementing ISO 31000 actually involves

  • Risk criteria that mean something. Defined thresholds tied to real consequences — financial, regulatory, operational — rather than a five-by-five grid with unlabelled axes.
  • A defined scope and context covering the external and internal factors the organisation operates within.
  • A single register, with owners, treatments and dates, that decision-makers actually see.
  • Treatment plans that resolve — accepted, reduced, transferred or avoided, with the choice recorded and the residual position stated.
  • Monitoring and review on a defined cycle, plus a trigger for material change.
  • Reporting into governance, which is the framework component and the one most often missing.

None of that requires a tool, and none of it is what people expect ISO 31000 to be about. It requires agreement on criteria and somebody senior who reads the output.

Where to start

  1. Write the risk criteria first. Everything downstream inherits them, and a register built on undefined criteria cannot be aggregated or compared.
  2. Define scope and context and record it, so the register’s boundaries are a decision rather than an accident.
  3. Consolidate existing registers before creating another one. Most organisations already have three.
  4. Fix the framework, not just the process. Assign leadership accountability and a reporting route into governance.
  5. Use IEC 31010 when you need an actual assessment technique — the guidelines will not give you one.
  6. Review annually against the eight principles, honestly, as a health check rather than an audit.

This guide reflects the position on iso.org at 15 August 2026: ISO 31000:2018 published and current, and ISO/CD 31000 under development at stage 30.60. Check the standard’s page before citing a stage in anything formal.

The ISO 31000 Risk Management Toolkit provides 30 editable documents covering the risk management policy and framework, the criteria definitions, the register and treatment plans, and the review and reporting records — the artefacts that turn sixteen pages of guidance into a process a board can see.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.