Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Setting risk criteria under ISO 31000

Risk Criteria: A Clear Guide to Setting Them Under ISO 31000

Risk criteria are where a risk management framework either becomes usable or quietly stops working. They are the terms of reference against which the significance of a risk is evaluated — the scales, the thresholds, and the point at which something stops being tolerable. ISO 31000 puts them in clause 6.3, alongside scope and context, and before any risk is assessed.

That placement is the whole argument. Criteria set before assessment produce comparable results; criteria invented afterwards produce a heat map that reflects whoever scored last.

Risk criteria: what ISO 31000 asks you to decide before assessing risk
Six decisions that have to be made before the first risk is scored.

What risk criteria have to specify

ISO 31000 expects the organization to specify the amount and type of risk it may or may not take, relative to its objectives, and to define criteria for evaluating the significance of risk. In practice that means writing down six things:

  1. The nature and type of consequences you will measure — financial, safety, regulatory, reputational, service continuity — and how they will be measured.
  2. The likelihood scale, expressed in terms people can apply consistently: a frequency, a probability band, or a plain-language definition anchored to a period.
  3. How time affects it — a consequence that arrives in a week is not the same as one that arrives over five years.
  4. How combinations of risks are treated. Several individually tolerable risks in one process can be jointly intolerable, and nothing in a scoring grid catches that unless you say so.
  5. The level at which risk becomes unacceptable, and the level at which it must be escalated — two different thresholds that are frequently conflated into one.
  6. The organization’s capacity — what it can actually absorb, which is a different question from what it is willing to accept.

Criteria should be dynamic. ISO 31000’s own position is that they are reviewed and amended as circumstances change, which means a criteria set that has not been touched since the framework was written is evidence the framework is not being used.

Risk criteria, risk appetite and risk tolerance

These three get used interchangeably and they are not the same:

  • Risk appetite is the amount and type of risk the organization is willing to pursue or retain. It is a statement of intent, set by the board.
  • Risk criteria are the operational expression of that intent — the scales and thresholds that let someone decide whether a specific risk is inside it.
  • Risk tolerance is the readiness to bear a risk after treatment, within the appetite. It is where exceptions live.

An appetite statement without criteria cannot be applied by anyone below the board. Criteria without an appetite statement produce consistent scoring in the service of no stated intent. You need both, and the criteria are the half that gets skipped.

Writing a scale people can actually apply

The failure mode is a five-by-five grid with undefined labels. “Moderate impact” means whatever the scorer thinks it means, so two people score the same risk differently and the register stops being comparable across departments.

Three fixes, in order of value:

Anchor every point on the scale to something measurable. Not “major financial impact” but “loss above X% of annual revenue, or above Y in absolute terms”. Not “likely” but “expected more than once in three years”. If a number is politically difficult to agree, that difficulty is the real finding — it means the organization has never stated what it can absorb.

Use several consequence types with one shared severity scale. A safety consequence and a financial consequence are not comparable in their own units, but both can be mapped onto the same five levels, and that is what lets a portfolio be ranked.

Write the criteria where the scorers will see them. On the register sheet, not in a framework document nobody opens. The single cheapest improvement to most risk registers is putting the definitions next to the scoring columns.

Where risk criteria go wrong in practice

Four failure patterns account for most unusable risk criteria.

The mid-table cluster. When most entries land in the middle of the grid, nobody is making a judgement — usually because the scale’s endpoints are so extreme that nothing real reaches them. Calibrate against risks you have actually experienced.

Criteria that ignore capacity. Appetite says what you want; capacity says what you can survive. A criteria set that permits accepting a risk the balance sheet cannot absorb is not a criteria set, it is optimism.

One scale for the whole organization, no matter the scale of the unit. A threshold calibrated for group level makes every risk in a small subsidiary look trivial. Either set unit-level criteria that roll up, or state the level the criteria apply at.

Never revisiting them. Growth, acquisition, a new regulator or a bad year all change what is tolerable. Criteria are meant to be amended; the register’s history should show it happening.

How this connects to certifiable standards

ISO 31000 is guidance and is not certifiable, but the standards that are certifiable lean on the same idea. ISO 27001 requires information security risk criteria — including risk acceptance criteria — to be established and maintained before assessment, and management-system standards generally expect the basis for evaluating significance to be defined rather than improvised. Setting criteria once, properly, satisfies several regimes at once. Our guide to ISO 31000 and its three components covers the framework the criteria sit inside.

Frequently asked questions

Where are risk criteria defined in ISO 31000?
In clause 6.3, scope, context and criteria — before risk assessment in clause 6.4, which is the point.

Are risk criteria the same as risk appetite?
No. Appetite is the amount and type of risk the organization is willing to pursue or retain; criteria are the scales and thresholds that let a specific risk be evaluated against it.

Who sets them?
The board or top management sets appetite and approves the criteria; risk and business owners apply them. Criteria written entirely by a risk function tend not to survive contact with a business decision.

How often should they be reviewed?
Whenever the organization’s objectives, capacity or environment change, and at least as part of the periodic framework review. ISO 31000 expects them to be dynamic.

Can we use qualitative criteria?
Yes, provided each level is defined well enough that two people apply it the same way. Qualitative does not mean undefined.

Where this leaves you

Write the risk criteria before the first assessment, anchor every level to something measurable, and keep the definitions in front of whoever is scoring. State appetite and criteria separately so the board’s intent and the operational thresholds are both visible, include capacity as well as willingness, and review the criteria when the business changes. A register scored against undefined labels cannot be aggregated, compared or defended — and that is a criteria problem, not a scoring one.

References

  • ISO 31000:2018 — Risk management guidelines, including clause 6.3 on scope, context and criteria.
  • ISO 31073:2022 — Risk management vocabulary, the source of the defined terms.

More on risk management

Criteria sets, scoring scales and the register they feed are in the ISO 31000 Risk Management Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.