A risk management policy is the document ISO 31000:2018 asks top management to issue as the first act of leadership and commitment: clause 5.2 says the organisation’s leaders should demonstrate commitment by “issuing a statement or policy that establishes a risk management approach, plan or course of action”, and the rest of the framework — integration, design, implementation, evaluation and improvement — hangs from it. The policy is not the process, the register or the appetite statement; it is the short, board-approved document that says why the organisation manages risk, who is accountable for it, what principles it follows, how risk will be assessed and against what criteria, how it will be reported and how the arrangements will be reviewed. Eight sections cover that in three to six pages. This guide sets out the eight sections a risk management policy needs, with what each has to say to satisfy ISO 31000 and to survive an auditor, the documents the policy points to rather than contains, the errors that make policies unusable, and a drafting sequence that produces one a board will sign.

What ISO 31000 asks of the risk management policy
Clause 5.2 lists what leadership and commitment involve: customising and implementing the framework; issuing the statement or policy; ensuring resources are allocated; and assigning authority, responsibility and accountability at appropriate levels. Clause 5.4 — design — adds what the policy has to reflect: understanding of the organisation and its context (5.4.1), articulating risk management commitment (5.4.2), assigning organisational roles, authorities, responsibilities and accountabilities (5.4.3), allocating resources (5.4.4) and establishing communication and consultation (5.4.5). Clause 5.4.2 is the one that speaks directly to the policy: the commitment should be expressed through a policy, statement or other form that conveys the organisation’s objectives and commitment to risk management, and it should address the organisation’s purpose for managing risk and links to objectives, the integration of risk management into culture, the way risk management is integrated into decision-making, the roles, the necessary resources, the way conflicting objectives are dealt with, performance measurement and reporting, and review and improvement. Our guide to ISO 31000 covers the framework the policy launches.
The eight sections of a risk management policy
| Section | ISO 31000 basis | What it has to say |
|---|---|---|
| 1. Purpose and commitment | 5.2, 5.4.2 | Why the organisation manages risk — to create and protect value in pursuit of its objectives — and the board’s commitment, signed and dated; the link to strategy and objectives; how conflicting objectives are resolved |
| 2. Scope and application | 5.4.1 | Which entities, activities, risk types and decisions the policy covers; relationship to other policies (health and safety, information security, financial) and to the ISO management systems the organisation runs |
| 3. Principles | Clause 4 | The eight ISO 31000 principles as the organisation adopts them — integrated, structured and comprehensive, customised, inclusive, dynamic, best available information, human and cultural factors, continual improvement — stated as commitments, not copied as a list |
| 4. Roles, responsibilities and accountability | 5.2, 5.4.3 | Board: oversight and appetite; executive: ownership of the framework; risk function: design, support, challenge and reporting; risk owners: assessment and treatment; internal audit: assurance. Who may accept risk at each level |
| 5. Risk appetite and criteria | 6.3 | The statement of the amount and type of risk the organisation will take, and where the detailed risk criteria — scales, thresholds, escalation levels — are set and approved |
| 6. The process | Clause 6 | That risk is managed through the ISO 31000 process — communication and consultation; scope, context and criteria; identification, analysis and evaluation; treatment; monitoring and review; recording and reporting — and where the procedure lives |
| 7. Reporting and communication | 5.4.5, 6.7 | What is reported to whom and how often: the register to the executive, the profile and appetite position to the board, escalation thresholds, and external reporting obligations |
| 8. Review and improvement | 5.6, 5.7 | How the framework’s effectiveness is evaluated, how often the policy is reviewed, who owns the review, and how improvement is captured |
What the policy points to, and does not contain
| Document | Relationship to the policy | Why it is separate |
|---|---|---|
| Risk management framework document | The policy commissions it; the framework document describes the design in detail | Changes more often than the policy |
| Risk criteria | Section 5 names the authority that sets them and where they are | Scales and thresholds are operational and reviewed with the assessments; our guide to risk criteria covers the content |
| Risk appetite statement | Section 5 states the appetite at the level of principle; the statement gives the metrics | Board-owned but more granular; our guide to risk appetite covers the terms |
| Risk assessment procedure | Section 6 commits to the process; the procedure says how each step is performed and with which IEC 31010 techniques | Method detail; our guide to IEC 31010 covers the techniques |
| Risk register | Section 7 names it as the record | A living record, not a policy |
| Role descriptions and committee charters | Section 4 assigns; the charters define | Governance instruments with their own approval |
A policy that tries to contain all of these becomes a manual nobody reads and a document that needs board approval every time a scale changes. The test is whether each section can be read in a minute and whether every claim in it can be pointed at a document that proves it.
Errors that make a risk management policy unusable
- The principles copied, not adopted. A list of the eight ISO 31000 principles with no statement of what the organisation will do differently because of them.
- Roles without accountability. “Everyone is responsible for managing risk” and no one named as able to accept a risk outside criteria.
- Appetite absent or buried. A policy that never says how much risk the organisation will take cannot be used to evaluate anything.
- Process described in full. Ten pages of method inside the policy, so that any change to the method becomes a policy change.
- No reporting commitments. If the policy does not say what the board sees and when, the board sees whatever the risk function chooses.
- Unsigned, undated, unreviewed. Clause 5.2 asks leadership to issue the policy; a policy without a visible approval and a review date does not evidence commitment.
- Cited standards never read. A policy “in accordance with ISO 31000 and COSO ERM” whose sections match neither; our guide to ISO 31000 vs COSO ERM covers what each expects.
Drafting the risk management policy
- Interview the board and the executive on purpose and appetite. Sections 1 and 5 are theirs; a risk function that drafts them alone produces a policy the board tolerates rather than owns.
- Map the existing governance. Committees, delegated authorities, the internal audit charter — section 4 assigns roles that already exist before it invents new ones.
- Write the principles as commitments. One sentence per principle stating what the organisation will do: “risk is assessed in every decision paper above the threshold in the criteria” for integrated; “assessments use the best available information and state its limitations” for best available information.
- Draft the eight sections in three to six pages. Point at the framework document, criteria, procedure and register rather than reproducing them.
- Test it against clause 5.4.2. Purpose and links to objectives, integration into culture and decision-making, roles, resources, conflicting objectives, performance measurement and reporting, review — each addressed somewhere in the eight sections.
- Approve, publish, date, and diarise the review. Board minute, version and date on the document, review within a stated period or on significant change.
Frequently asked questions
Does ISO 31000 require a risk management policy?
ISO 31000 is a guidelines standard and requires nothing, but clause 5.2 says leadership should demonstrate commitment by issuing a statement or policy establishing the risk management approach, and clause 5.4.2 lists what that commitment should address. ISO management system standards and most regulators expect a policy to exist.
What should a risk management policy contain?
Eight sections: purpose and commitment; scope and application; principles; roles, responsibilities and accountability; risk appetite and criteria; the process; reporting and communication; review and improvement — with the detailed framework, criteria, procedure and register held in separate documents the policy points to.
How long should it be?
Three to six pages. A policy long enough to contain the method needs board approval every time the method changes; a policy short enough to read in ten minutes is one the board will own.
Who approves it?
The board or its equivalent, because clause 5.2 places the commitment with top management and the policy carries the appetite the board sets; the executive owns the framework beneath it.
How often should it be reviewed?
The policy should say — commonly annually or on significant change to the organisation, its context or its strategy — and clause 5.6 expects the framework’s effectiveness to be evaluated periodically against its purpose.
Where this leaves you
Write the risk management policy as the board’s commitment rather than the risk function’s manual: eight sections in a few pages — purpose, scope, principles as commitments, accountable roles, appetite and where the criteria live, the ISO 31000 process and where the procedure lives, what the board sees and when, and how the arrangements are reviewed — signed, dated and pointing at the documents that carry the detail, because clause 5.2 asks leadership to issue it, and a policy nobody can read in ten minutes is not evidence of anything.
References
- ISO 31000:2018 — Risk management — Guidelines — Clauses 4, 5.2, 5.4, 5.6, 5.7 and 6.
- IEC 31010:2019 — Risk management — Risk assessment techniques — The techniques the procedure selects from.
More on ISO 31000
- The risk management policy — you are here
- ISO 31000: the three components
- Risk appetite: the three terms people confuse
- Risk criteria under ISO 31000
- ISO 31000 vs COSO ERM
- Inherent vs residual risk
The risk management policy template on the eight sections, the framework document, the risk appetite statement and criteria, the assessment procedure and the register are in the ISO 31000 Risk Management Toolkit, or start with the free templates.