Nobody can certify your organisation to ISO 31000. It is guidance, it uses should rather than shall, and ISO states plainly that it is not intended for certification purposes. Any body selling your organisation an ISO 31000 certificate is selling something ISO does not recognise.
This is a maturity assessment, not a conformity one. It scores 53 questions across the eight principles, the framework and the process, measuring how far risk management actually changes decisions rather than whether a document exists. It is free, it saves as you go, and you can stop and come back to it.
What this is
ISO 31000:2018 is the second edition, published 14 February 2018. It sits at ISO stage 90.92, International Standard to be revised, and ISO/CD 31000 — the intended third edition — reached committee stage 30.60 on 1 March 2026. No draft international standard has been registered and no publication date is published, so the 2018 structure is safe to work to for now.
Two things in the wider family have changed and are still widely miscited. ISO Guide 73:2009 was withdrawn on 2 November 2023 and replaced by ISO 31073:2022 as the vocabulary standard. And ISO/TR 31004:2013, the implementation guidance, was withdrawn on 28 November 2022 — it should not appear in a current reference list. IEC 31010:2019 remains the reference for assessment techniques.
The background is elsewhere — the standard explained, against COSO ERM, the techniques standard, risk appetite and risk criteria. Come here when you want a score.
What it covers
53 questions, about 35 minutes.
| Section | Questions |
|---|---|
| Clause 4 – Principles | 8 |
| Clause 5 – Framework: leadership and integration | 7 |
| Clause 5.4 – Framework: design | 11 |
| Clause 5.5-5.7 – Framework: implementation, evaluation and improvement | 6 |
| Clause 6.2-6.3 – Process: communication, scope and criteria | 6 |
| Clause 6.4 – Process: risk assessment | 5 |
| Clause 6.5 – Process: risk treatment | 4 |
| Clause 6.6-6.7 – Process: monitoring, recording and reporting | 6 |
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
The wording throughout avoids comply, conform, nonconformity and shall on purpose. There is nothing to conform to. What is being measured is distance from good practice, and the only authority it carries is your own decision to adopt it.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by section, a prioritised gap list — as a PDF and a working Excel file.
How long does it take?
About 35 minutes. Clause 5.4, the design of the framework, carries the most questions because it is where most organisations are thinnest.
What to do with your score
Below 40% — start with leadership and accountability. A framework without a mandate, named risk owners and stated criteria produces a register, not risk management.
40–70% — the usual shape. The process runs, the register exists, and the framework questions — integration, resourcing, evaluation of the framework itself — are where the score drops.
Above 70% — test the honesty of the reporting. Where every risk that reaches the board is amber and none is red, the reporting is being managed rather than the risk.
Frequently asked questions
Is this assessment really free?
Yes. All 53 questions, the breakdown by clause and your overall score cost nothing. The $39 report is optional.
So how are organisations actually assessed against ISO 31000?
Through internal audit, self-assessment, second-party review by an investor, insurer or parent, and indirectly through the risk clauses of certifiable standards such as ISO 9001, ISO/IEC 27001, ISO 22301 and ISO 14001 — where an accredited auditor does test them.
What about ISO 31000 lead risk manager certificates?
Those certify a person, not an organisation, and they are real. The thing that does not exist is organisational certification. Questionnaires routinely conflate the two.
Why eight principles rather than eleven?
Clause 4 lists eight principles as a lettered list from a) to h), with no numbered sub-clauses. Writing clause 4.3 in a report is a small tell that the writer has not read clause 4.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.