ISO 31000 Risk Management: The Essentials

ISO 31000 provides internationally recognised principles and guidance for managing risk across any organisation. This guide explains the purpose of the standard, its core principles and how it can be applied in practice to strengthen governance and decision-making. It offers a clear introduction for anyone looking to build or improve an enterprise risk management programme.
5 min read time

ISO 31000 is the international standard for risk management. Published by the International Organisation for Standardisation and most recently updated in 2018, it provides principles and guidelines that any organisation, regardless of size, sector, or geographic location, can use as the foundation for a structured approach to managing risk.

Despite its prominence in regulatory guidance, professional standards, and risk management literature across multiple sectors, the standard's actual content is frequently referenced without being well understood. Practitioners who know they should be working to ISO 31000 sometimes have only a general sense of what it says. This article sets out the substance of the standard clearly, covering what it requires, how its components fit together, how it compares to the COSO ERM Framework, and what applying it in practice actually looks like.

What ISO 31000 Is and Is Not

A Guidance Standard, Not a Certifiable One

ISO 31000 is a guidance standard, not a certifiable one. This is a significant and sometimes misunderstood distinction. Unlike ISO 27001 for information security management or ISO 9001 for quality management, organisations cannot be audited against ISO 31000 and awarded an ISO 31000 certificate. There is no accredited certification process for the standard.

ISO 31000 provides principles and a process model that organisations adopt and adapt to their own context. The absence of certification is intentional: the standard is designed to be applicable across all sectors and all sizes of organisation, which requires flexibility that a certifiable standard's specific requirements would constrain.

Broad Applicability

This flexibility is one of the standard's genuine strengths. The same principles apply to a multinational financial institution and a small not-for-profit, to an operational process risk assessment and a strategic board-level risk review. The implementation differs substantially across these contexts, but the underlying framework is consistent.

The FCA's systems and controls sourcebook references ISO 31000 principles in its guidance on risk management for regulated firms. The Central Bank of Ireland's guidance for credit unions similarly draws on ISO 31000 as a framework reference. The standard's application extends well beyond any single sector.

The 2018 Revision

The 2018 update to ISO 31000 was the first revision since the original 2009 publication. Key changes included a stronger emphasis on leadership commitment to risk management at the board and executive level, greater emphasis on the integration of risk management into the organisation's governance and decision-making structures rather than as a separate activity, the addition of human and cultural factors as an explicit principle, and a streamlined structure with cleaner separation between the principles, framework, and process components.

The Three Core Components

ISO 31000 is organised around three interrelated components. Understanding how they relate to each other is essential to understanding how the standard works as a whole.

Principles: What Effective Risk Management Looks Like

The 2018 standard sets out eight principles that characterise effective risk management. These are not procedural requirements or steps to follow. They are attributes: characteristics that an organisation's risk management should exhibit if it is genuinely effective.

Integrated. Risk management should not exist as a separate function alongside the organisation's governance and operations. It should be embedded in how the organisation is directed and controlled, informing decisions rather than reporting on them retrospectively.

Structured and comprehensive. Risk management should be applied through a consistent, systematic approach that produces comparable and reliable results across the organisation and over time.

Customised. The framework and process should be adapted to the organisation's specific context, including its external environment, its objectives, and its risk profile. A generic template applied uniformly is not a compliant interpretation of this principle.

Inclusive. Stakeholders whose knowledge, perspectives, and interests are relevant to risk assessment should be included in the process. Risk management that is conducted by the risk function without genuine engagement from the people who understand the operational realities will systematically miss important information.

Dynamic. Risk management should be responsive to changes in the internal and external environment. Risks change, and the management approach should change with them, rather than producing a static picture that is reviewed annually regardless of how much the environment has shifted.

Best available information. Decisions about risk should draw on historical data, stakeholder experience and input, current information, and expert judgment, with the limitations of each source explicitly acknowledged rather than treated as certainty.

Human and cultural factors. This principle, made more explicit in the 2018 revision, acknowledges that human behaviour, organisational culture, and individual perception of risk significantly influence how risk management works in practice. A technically sound risk framework operating in a culture that penalises the surfacing of problems will perform poorly regardless of its design.

Continual improvement. Risk management should improve over time as the organisation learns from experience, both from what has gone wrong and from the application of the risk management process itself.

The Framework: How Risk Management Is Integrated Into the Organisation

The ISO 31000 framework describes how risk management is integrated into and sustained within an organisation. It has five components.

Leadership and commitment. Risk management must be visibly championed at the board and executive level. This is not about signing off on a policy. It is about demonstrating through behaviour, resource allocation, and decision-making that risk management is genuinely valued. The 2018 standard placed stronger emphasis on this than its predecessor, reflecting the recognition that leadership behaviour is a more reliable predictor of risk culture than the quality of the risk framework documentation.

Integration. Risk management should be embedded in governance structures, strategic planning processes, and operational decision-making. When risk management is integrated in this sense, risk is a routine input to decisions rather than a parallel exercise that produces a report that decisions may or may not reflect.

Design. The framework should be designed to reflect the organisation's specific external environment, including its regulatory and legal context; its internal environment, including its values, structure, and capabilities; and its risk profile and objectives. A framework designed for one organisation's context is not necessarily appropriate for another's, even in the same sector.

Implementation. Putting the framework into practice: deploying the risk management process across the organisation, building risk literacy among the people responsible for applying it, and establishing the reporting structures that connect risk information to governance decisions.

Evaluation and improvement. The framework itself, not just the individual risks within it, should be reviewed periodically against performance criteria and improved based on what is and is not working. This closes the governance loop: the organisation is not just managing risks, it is managing the quality of the risk management programme.

The Process: How Individual Risks Are Managed

The ISO 31000 process is the operational sequence through which risk is identified, assessed, treated, and monitored. It runs through six stages.

Communication and consultation. This is not a one-off step at the beginning or end of the process. It runs throughout. Stakeholders relevant to each stage of the process should be engaged at that stage, with their perspectives genuinely influencing assessments and decisions rather than being acknowledged and set aside.

Scope, context, and criteria. Before identifying any risks, the scope of the assessment must be defined, the internal and external context understood, and the criteria for evaluating risk established. This includes the organisation's risk appetite and tolerance, the time horizon for the assessment, and the objectives being protected.

Risk identification. What could happen that would affect the achievement of objectives? Identification should be systematic rather than relying on memory or past experience alone, should include both threats and opportunities, and should draw on multiple techniques and multiple sources of input.

Risk analysis. For each identified risk, understanding its nature, sources, likelihood, potential consequences, and existing controls. Analysis produces the input for evaluation but is not itself the evaluation: the output of analysis is a characterisation of the risk, not a decision about whether it is acceptable.

Risk evaluation. Comparing the output of analysis against the risk criteria established in the scope and context stage. This produces a conclusion about whether the risk requires treatment and, if so, what priority it should be given. Risks within appetite and adequately controlled may be accepted. Risks outside appetite require treatment.

Risk treatment. Selecting and implementing responses. ISO 31000 identifies five broad treatment options: avoiding the risk by not undertaking the activity that creates it; removing the source of the risk; changing the likelihood or consequence through controls; sharing the risk through contracts or insurance; and retaining the risk as a deliberate, informed decision that the current level is acceptable. Treatment decisions should be documented and their implementation verified.

Monitoring and review. Continuous monitoring of risks, controls, and the treatment plan, with periodic review to confirm that the risk picture remains current and that treatments are delivering the expected reduction in exposure.

Recording and reporting. Documenting risk management activities and communicating outcomes to relevant stakeholders through structures appropriate to each audience.

How ISO 31000 Compares to COSO ERM

The two most widely referenced enterprise risk management frameworks internationally are ISO 31000 and the COSO ERM Framework. Understanding how they differ helps organisations decide how to position each within their approach.

Scope and Purpose

ISO 31000 is a broad, principles-based guidance standard applicable to risk management at any level, from individual project risks to enterprise-wide strategic risks. It provides the philosophical and process foundation without prescribing specific governance structures or reporting formats.

COSO ERM is specifically focused on enterprise-level risk management and its integration with organisational strategy and performance. It is more structured and more prescriptive than ISO 31000, with detailed components and principles specifically designed for board-level governance of risk.

Strategic Emphasis

The 2017 update to COSO ERM placed substantial emphasis on the relationship between risk and strategy: how organisations identify risks in the context of their strategic objectives, how risk appetite informs strategic choices, and how risk management contributes to sustainable value creation. This strategic framing is more explicit in COSO than in ISO 31000.

ISO 31000 addresses the connection between risk and objectives but is less specifically focused on strategy-setting as the primary context for risk management. It is equally applicable to an operational process risk assessment as to a board-level strategic risk review.

Sector and Jurisdictional Use

ISO 31000 is widely referenced in European regulatory contexts, including the FCA and Central Bank of Ireland guidance referenced earlier. It tends to predominate as the primary framework reference in public sector, healthcare, and not-for-profit contexts. COSO ERM is particularly prominent in North American financial services and among public companies subject to US securities regulation, where COSO's specific application to internal control over financial reporting gives it additional relevance.

Many organisations draw on both frameworks, using ISO 31000 as the philosophical foundation and methodological process, and COSO for more detailed governance structure and the specific connection to financial reporting and controls.

Applying ISO 31000 in Practice

ISO 31000 provides the what and the why of risk management. The how is determined by the organisation applying it.

Translation Into a Working Programme

Translating the standard into a working ERM programme means developing a risk management policy that reflects its principles, establishing governance structures with clear accountability at board, executive, and operational levels, defining a risk taxonomy and assessment methodology appropriate to the organisation's context, building the reporting infrastructure that connects risk information to governance decisions, and investing in the cultural conditions that make the framework genuinely operational rather than nominal.

Technology as an Enabler

ISO 31000 makes no specific technology requirements. The standard is technology-agnostic: its principles and process can in theory be implemented without any specific platform. In practice, implementing the ISO 31000 process at any meaningful scale, across multiple risk categories, multiple business units, and with the continuous monitoring and dynamic updating the standard envisions, requires ERM software. Manual approaches cannot deliver the consistency, currency, and board-quality reporting that the standard implicitly expects at the level of rigour that modern governance demands.

References and Further Reading

Next Steps

Ready to elevate your enterprise risk management?

Join 150+ organisations who’ve already made calQrisk their competitive edge.