Guidelines · Risk management · Global
ISO 31000 risk management is the international guideline for managing any kind of risk, from strategic to operational. ISO 31000:2018 sets out eight principles, a framework led by top management and a six-step process. It cannot be certified, but it gives one risk method that ISO 27001, ISO 22301 and other programmes can share.
Any organisation that wants a consistent way to manage risk across its activities.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
ISO 31000 recommends managing risk through eight principles, a framework that integrates risk management into governance and decisions, and a repeatable process to identify, analyse, evaluate, treat, monitor and report risk.
Integrated, structured, customised, inclusive, dynamic, informed, human, improving.
In QULDEX: Principles as a maturity checkLeadership, integration, design, implementation, evaluation, improvement.
In QULDEX: Framework mapped to evidenceContext, assessment, treatment, monitoring, reporting.
In QULDEX: Risk register workflowHow much risk the organisation will take.
In QULDEX: Criteria stored with the registerAvoid, take, remove, change, share or retain.
In QULDEX: Treatment plans as actionsAll 8 principles, 6 framework components, 8 process elements and 3 companion standards. Select any one to see what it means, typical evidence and how QULDEX handles it.
Showing up to 6 per group. Search, filter, or open a group to see all 25.
4(a)IntegratedRisk management is part of all organisational activities, not a separate exercise.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
4(b)Structured and comprehensiveA structured, comprehensive approach gives consistent and comparable results.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
4(c)CustomizedThe framework and process are tailored to the organisation's context and objectives.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
4(d)InclusiveStakeholders are involved in time, so their knowledge and views are considered.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
4(e)DynamicRisks change; risk management anticipates, detects and responds to change in time.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
4(f)Best available informationInputs are based on historical and current information and future expectations, with their limits recognised.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
4(g)Human and cultural factorsBehaviour and culture influence every aspect of risk management.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
4(h)Continual improvementRisk management improves through learning and experience.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
5.2Leadership and commitmentTop management and oversight bodies make risk management part of governance, issue a policy and provide resources.
In QULDEXPolicy approval and resourcing are recorded.
5.3IntegrationRisk management is built into the organisation's structure, processes and decisions.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
5.4DesignUnderstand context, articulate commitment, assign roles and accountability, allocate resources and set up communication.
In QULDEXRoles and risk owners are recorded per risk.
5.5ImplementationPlan the timing and resources, decide where decisions are made and make sure the arrangements are understood.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
5.6EvaluationMeasure framework performance against its purpose, plans and indicators.
In QULDEXIndicators are tracked on the dashboard.
5.7ImprovementAdapt and continually improve the framework's suitability, adequacy and effectiveness.
In QULDEXImprovement actions are tracked as CAPA items.
6.2Communication and consultationHelp stakeholders understand risk and the basis for decisions, throughout the process.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
6.3Scope, context and criteriaOften missedDefine the scope, the internal and external context, and the criteria used to evaluate risk.
In QULDEXRisk criteria and appetite are stored with the register.
6.4.2Risk identificationFind, recognise and describe risks that could help or prevent the achievement of objectives.
In QULDEXRisks are logged with sources, events and consequences.
6.4.3Risk analysisUnderstand the nature of risk, its likelihood and consequences, and existing controls.
In QULDEXLikelihood and consequence ratings use one scale across programmes.
6.4.4Risk evaluationCompare analysis results with the risk criteria to decide where action is needed.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
6.5Risk treatmentOften missedSelect and implement options: avoid, take or increase, remove the source, change likelihood or consequences, share, or retain.
In QULDEXTreatment plans become owned actions with due dates.
6.6Monitoring and reviewMonitor and review the process and its outcomes as a planned part of risk management.
In QULDEXReview dates and status changes are tracked per risk.
6.7Recording and reportingDocument and report the process and outcomes to support decisions and oversight.
In QULDEXReports draw on live register data.
31010ISO/IEC 31010:2019Risk assessment techniques, from interviews and checklists to bow-tie analysis and Monte Carlo simulation.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
31073ISO 31073:2022Risk management vocabulary, replacing ISO Guide 73.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
27005ISO/IEC 27005:2022Information security risk management guidance aligned with ISO 31000, used for ISO 27001.
In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.
Nothing matches that search.
Clause numbers follow ISO 31000:2018. Summaries are QULDEX paraphrases; the standard is the authority.
Get leadership commitment and a risk policy, design the framework for your context, set risk criteria, run the process and review it. Most organisations need 3 to 6 months for a first cycle.
Top management approves a risk management policy and resources.
Context, roles, accountability, risk owners and reporting lines.
Likelihood and consequence scales, appetite and tolerance.
Identify, analyse and evaluate risks; agree treatment plans.
Measure against indicators and improve.
Durations are QULDEX planning ranges. ISO 31000 has no certification audit.
ISO 31000 is guidance, so it names no mandatory documents. These records show the framework and process work.
| Record | Clause | Where it lives in QULDEX |
|---|---|---|
| Risk management policy | 5.2 | Policy library |
| Framework description and roles | 5.4 | Policy library |
| Risk criteria and appetite statement | 6.3 | Risk register |
| Risk register | 6.4 | Risk register |
| Treatment plans | 6.5 | CAPA automation |
| Monitoring and review records | 6.6 | Evidence vault |
| Risk reports to leadership | 6.7 | Evidence vault |
| Framework performance review | 5.6 | Audit workspace |
Record names are QULDEX recommendations.
A first full cycle typically takes 3 to 6 months. Agreeing risk criteria and appetite with leadership, and the number of business units, drive the effort.
Bars show the upper end of each range on one scale (6 months = full width).
Check these eight things first. Nothing you enter leaves this page.
ISO 31000 is the umbrella; ISO/IEC 27005 applies it to information security for ISO 27001, and COSO ERM is the main alternative framework.
| ISO 31000:2018 | COSO ERM (2017) | |
|---|---|---|
| Type | International guideline | Enterprise risk framework |
| Scope | Any risk, any organisation | Enterprise risk linked to strategy and performance |
| Structure | 8 principles, framework, process | 5 components, 20 principles |
| Certifiable | No | No |
| Common use | Global, public sector, ISO programmes | US, listed companies, internal audit |
| In QULDEX | QULDEX keeps one risk register that can be reported against either model. | |
| ISO 31000:2018 | ISO/IEC 27005:2022 | ISO 27001:2022 | ISO 22301 | Shared evidence |
|---|---|---|---|---|
| 5.2 Leadership | Clause 5 | 5.1 | 5.1 | Policy |
| 6.3 Context and criteria | Clause 6 | 4.1–4.2, 6.1.2 | 4.1, 8.2.3 | Risk criteria |
| 6.4 Assessment | Clauses 7–8 | 6.1.2, 8.2 | 8.2.3 | Risk register |
| 6.5 Treatment | Clause 9 | 6.1.3, 8.3 | 8.3 | Treatment plans |
| 6.6 Monitoring | Clause 10 | 9.1 | 9.1 | Reviews |
| 6.7 Reporting | Clause 10 | 9.3 | 9.3 | Reports |
Indicative mapping for planning. ISO 31000 vs ISO 27005 is compared in full on the blog.
QULDEX is risk management and audit software built from EGV Group's audit delivery, used by risk teams, their advisors and the auditors who review them. Pick your role to see who does what.
For enterprise risk and compliance teams.
For risk consultants and internal audit.
For internal and external auditors reviewing risk management.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →No. ISO 31000 is a guideline, not a requirements standard, so organisations cannot be certified against it. They can be assessed for alignment.
Integrated; structured and comprehensive; customized; inclusive; dynamic; best available information; human and cultural factors; and continual improvement, all serving the creation and protection of value.
Communication and consultation; scope, context and criteria; risk assessment (identification, analysis, evaluation); risk treatment; monitoring and review; and recording and reporting.
ISO 31000 is the general risk management guideline for any risk. ISO/IEC 27005 applies it to information security risk, to support the ISO 27001 risk assessment and treatment requirements.
Yes. A third edition is in development to replace ISO 31000:2018, but no publication date has been confirmed, so the 2018 edition remains current.
Each step of the process, with examples.
blog.quldex.comThe general guideline and its information security application.
blog.quldex.comHow to write appetite and tolerance statements.
blog.quldex.comRisk appetite, compensating controls and closing findings.
Reviewed by
Answer a short readiness check and get a gap summary by clause. No sales call needed to see the result.