Guidelines · Risk management · Global

ISO 31000 risk management: principles, framework and process

ISO 31000 risk management is the international guideline for managing any kind of risk, from strategic to operational. ISO 31000:2018 sets out eight principles, a framework led by top management and a six-step process. It cannot be certified, but it gives one risk method that ISO 27001, ISO 22301 and other programmes can share.

Key takeaways

What you need to know about ISO 31000

Any riskIt covers every kind of risk, not only information security.
Not certifiableISO 31000 is guidance; there is no ISO 31000 certificate.
Leadership firstTop management owns the framework and the risk policy.
One methodUse it as the shared risk method behind ISO 27001, 22301 and others.
Companion standardsISO/IEC 31010 gives the assessment techniques; ISO 31073 the vocabulary.

Who uses ISO 31000?

Any organisation that wants a consistent way to manage risk across its activities.

Boards and risk committeesSetting risk policy, appetite and oversight.
Enterprise risk teamsRunning ERM across business units.
ISO 27001 and 22301 programmesUsing one risk method for several management systems.
Public bodiesMany governments adopt it as their risk standard.
AuditorsAssessing risk management maturity.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the guideline covers

What does ISO 31000 recommend?

ISO 31000 recommends managing risk through eight principles, a framework that integrates risk management into governance and decisions, and a repeatable process to identify, analyse, evaluate, treat, monitor and report risk.

4 Principles

Eight principles

Integrated, structured, customised, inclusive, dynamic, informed, human, improving.

In QULDEX: Principles as a maturity check
5 Framework

Six framework components

Leadership, integration, design, implementation, evaluation, improvement.

In QULDEX: Framework mapped to evidence
6 Process

Risk management process

Context, assessment, treatment, monitoring, reporting.

In QULDEX: Risk register workflow
6.3 Criteria

Risk criteria and appetite

How much risk the organisation will take.

In QULDEX: Criteria stored with the register
6.5 Treat

Treatment options

Avoid, take, remove, change, share or retain.

In QULDEX: Treatment plans as actions
Guideline explorer

What are the ISO 31000 principles, framework and process steps?

All 8 principles, 6 framework components, 8 process elements and 3 companion standards. Select any one to see what it means, typical evidence and how QULDEX handles it.

2018current edition
8principles
6framework components
6process steps

Showing up to 6 per group. Search, filter, or open a group to see all 25.

Principles 8

  1. 4(a)Integrated

    Risk management is part of all organisational activities, not a separate exercise.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

  2. 4(b)Structured and comprehensive

    A structured, comprehensive approach gives consistent and comparable results.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

  3. 4(c)Customized

    The framework and process are tailored to the organisation's context and objectives.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

  4. 4(d)Inclusive

    Stakeholders are involved in time, so their knowledge and views are considered.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

  5. 4(e)Dynamic

    Risks change; risk management anticipates, detects and responds to change in time.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

  6. 4(f)Best available information

    Inputs are based on historical and current information and future expectations, with their limits recognised.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

  7. 4(g)Human and cultural factors

    Behaviour and culture influence every aspect of risk management.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

  8. 4(h)Continual improvement

    Risk management improves through learning and experience.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

Framework 6

  1. 5.2Leadership and commitment

    Top management and oversight bodies make risk management part of governance, issue a policy and provide resources.

    In QULDEXPolicy approval and resourcing are recorded.

    Typical evidence
    Risk policy, board minutes
    Maps to
    ISO 27001 5.1

  2. 5.3Integration

    Risk management is built into the organisation's structure, processes and decisions.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

    Typical evidence
    Process maps

  3. 5.4Design

    Understand context, articulate commitment, assign roles and accountability, allocate resources and set up communication.

    In QULDEXRoles and risk owners are recorded per risk.

    Typical evidence
    Risk management framework document
    Maps to
    ISO 27001 6.1

  4. 5.5Implementation

    Plan the timing and resources, decide where decisions are made and make sure the arrangements are understood.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

    Typical evidence
    Implementation plan

  5. 5.6Evaluation

    Measure framework performance against its purpose, plans and indicators.

    In QULDEXIndicators are tracked on the dashboard.

    Typical evidence
    Framework performance review

  6. 5.7Improvement

    Adapt and continually improve the framework's suitability, adequacy and effectiveness.

    In QULDEXImprovement actions are tracked as CAPA items.

    Typical evidence
    Improvement log

Process 8

  1. 6.2Communication and consultation

    Help stakeholders understand risk and the basis for decisions, throughout the process.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

    Typical evidence
    Stakeholder communication records

  2. 6.3Scope, context and criteriaOften missed

    Define the scope, the internal and external context, and the criteria used to evaluate risk.

    In QULDEXRisk criteria and appetite are stored with the register.

    Typical evidence
    Risk criteria, appetite statement

  3. 6.4.2Risk identification

    Find, recognise and describe risks that could help or prevent the achievement of objectives.

    In QULDEXRisks are logged with sources, events and consequences.

    Typical evidence
    Risk register entries
    Maps to
    ISO 27001 6.1.2

  4. 6.4.3Risk analysis

    Understand the nature of risk, its likelihood and consequences, and existing controls.

    In QULDEXLikelihood and consequence ratings use one scale across programmes.

    Typical evidence
    Analysis records
    Maps to
    ISO/IEC 31010

  5. 6.4.4Risk evaluation

    Compare analysis results with the risk criteria to decide where action is needed.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

    Typical evidence
    Evaluation decisions

  6. 6.5Risk treatmentOften missed

    Select and implement options: avoid, take or increase, remove the source, change likelihood or consequences, share, or retain.

    In QULDEXTreatment plans become owned actions with due dates.

    Typical evidence
    Treatment plans
    Maps to
    ISO 27001 6.1.3

  7. 6.6Monitoring and review

    Monitor and review the process and its outcomes as a planned part of risk management.

    In QULDEXReview dates and status changes are tracked per risk.

    Typical evidence
    Review records

  8. 6.7Recording and reporting

    Document and report the process and outcomes to support decisions and oversight.

    In QULDEXReports draw on live register data.

    Typical evidence
    Risk reports

Related standards 3

  1. 31010ISO/IEC 31010:2019

    Risk assessment techniques, from interviews and checklists to bow-tie analysis and Monte Carlo simulation.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

    Maps to
    ISO 31000 6.4

  2. 31073ISO 31073:2022

    Risk management vocabulary, replacing ISO Guide 73.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

  3. 27005ISO/IEC 27005:2022

    Information security risk management guidance aligned with ISO 31000, used for ISO 27001.

    In QULDEXQULDEX records this element with an owner, evidence and a review date, and links it to the risk register so ISO 27001, ISO 22301 and other programmes share one risk method.

    Maps to
    ISO 27001 6.1

Clause numbers follow ISO 31000:2018. Summaries are QULDEX paraphrases; the standard is the authority.

Adoption path

How do you adopt ISO 31000?

Get leadership commitment and a risk policy, design the framework for your context, set risk criteria, run the process and review it. Most organisations need 3 to 6 months for a first cycle.

  1. Leadership commitment and policy

    Top management approves a risk management policy and resources.

  2. Design the framework

    Context, roles, accountability, risk owners and reporting lines.

  3. Set risk criteria and appetite

    Likelihood and consequence scales, appetite and tolerance.

  4. Run the first risk cycle

    Identify, analyse and evaluate risks; agree treatment plans.

  5. Review framework performance

    Measure against indicators and improve.

  6. Keep the cycle running

    QuarterlyRisk review by owners
    YearlyFramework evaluation
    On changeRe-assess affected risks

Durations are QULDEX planning ranges. ISO 31000 has no certification audit.

Records to keep

Which documents support ISO 31000?

ISO 31000 is guidance, so it names no mandatory documents. These records show the framework and process work.

RecordClauseWhere it lives in QULDEX
Risk management policy5.2Policy library
Framework description and roles5.4Policy library
Risk criteria and appetite statement6.3Risk register
Risk register6.4Risk register
Treatment plans6.5CAPA automation
Monitoring and review records6.6Evidence vault
Risk reports to leadership6.7Evidence vault
Framework performance review5.6Audit workspace

Record names are QULDEX recommendations.

Time and cost

How long does ISO 31000 adoption take?

A first full cycle typically takes 3 to 6 months. Agreeing risk criteria and appetite with leadership, and the number of business units, drive the effort.

Where the time goes

Policy and leadership2–4 wk
Framework design3–6 wk
Criteria and appetite2–4 wk
First risk cycle1–2 mo
Review2–4 wk

Bars show the upper end of each range on one scale (6 months = full width).

What changes the effort

  • Business units: each needs owners and a risk cycle
  • Appetite agreement: boards take time to agree tolerances
  • Existing registers: merging several registers into one
  • Regulatory overlay: sector rules may add requirements
  • ISO 27001 in place: its risk process maps directly
Readiness check · 2 minutes

How mature is your risk management?

Check these eight things first. Nothing you enter leaves this page.

5.2Has top management approved a risk management policy?
5.4Are risk owners named for every significant risk?
6.3Are risk criteria and appetite documented?
6.4Is there one risk register across the organisation?
6.5Does every high risk have a treatment plan with an owner and date?
6.6Are risks reviewed on a set schedule?
6.7Does leadership receive regular risk reports?
5.6Do you measure how well the framework works?
Crosswalk

How ISO 31000 maps to ISO 27005, ISO 27001 and COSO ERM

ISO 31000 is the umbrella; ISO/IEC 27005 applies it to information security for ISO 27001, and COSO ERM is the main alternative framework.

ISO 31000 vs COSO ERM at a glance

ISO 31000:2018COSO ERM (2017)
TypeInternational guidelineEnterprise risk framework
ScopeAny risk, any organisationEnterprise risk linked to strategy and performance
Structure8 principles, framework, process5 components, 20 principles
CertifiableNoNo
Common useGlobal, public sector, ISO programmesUS, listed companies, internal audit
In QULDEXQULDEX keeps one risk register that can be reported against either model.

Risk management crosswalk

ISO 31000:2018ISO/IEC 27005:2022ISO 27001:2022ISO 22301Shared evidence
5.2 LeadershipClause 55.15.1Policy
6.3 Context and criteriaClause 64.1–4.2, 6.1.24.1, 8.2.3Risk criteria
6.4 AssessmentClauses 7–86.1.2, 8.28.2.3Risk register
6.5 TreatmentClause 96.1.3, 8.38.3Treatment plans
6.6 MonitoringClause 109.19.1Reviews
6.7 ReportingClause 109.39.3Reports

Indicative mapping for planning. ISO 31000 vs ISO 27005 is compared in full on the blog.

Where QULDEX fits

How QULDEX runs ISO 31000 from policy to risk reporting

QULDEX is risk management and audit software built from EGV Group's audit delivery, used by risk teams, their advisors and the auditors who review them. Pick your role to see who does what.

For enterprise risk and compliance teams.

  1. PolicyApprove the policyPolicy and approvals recorded
  2. CriteriaSet criteria and appetiteCriteria stored with the register
  3. AssessIdentify and analyse risksOne register across programmes
  4. TreatOwn treatment plansPlans as actions with dates
  5. ReviewReview risksReview schedule per owner
  6. ReportReport to leadershipReports from live data
Without one systemWith QULDEX
A risk register per programmeOne register shared by ISO 27001, 22301 and ERM
Appetite agreed once and forgottenCriteria stored and reviewed with the register
Treatment tracked in emailPlans as owned actions with dates
Board reports built by handReports from live register data
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

ISO 31000 questions people ask

Is ISO 31000 certifiable?

No. ISO 31000 is a guideline, not a requirements standard, so organisations cannot be certified against it. They can be assessed for alignment.

What are the ISO 31000 principles?

Integrated; structured and comprehensive; customized; inclusive; dynamic; best available information; human and cultural factors; and continual improvement, all serving the creation and protection of value.

What is the ISO 31000 risk management process?

Communication and consultation; scope, context and criteria; risk assessment (identification, analysis, evaluation); risk treatment; monitoring and review; and recording and reporting.

What is the difference between ISO 31000 and ISO 27005?

ISO 31000 is the general risk management guideline for any risk. ISO/IEC 27005 applies it to information security risk, to support the ISO 27001 risk assessment and treatment requirements.

Is ISO 31000 being revised?

Yes. A third edition is in development to replace ISO 31000:2018, but no publication date has been confirmed, so the 2018 edition remains current.

Sources

References

  1. ISO 31000:2018 Risk management — Guidelines. iso.org/standard/65694.html
  2. ISO/CD 31000, Risk management — Guidelines (third edition in development). iso.org/standard/88574.html
  3. ISO news: The new ISO 31000 keeps risk management simple. iso.org/news/ref2263.html
  4. ISO/IEC 31010:2019 Risk assessment techniques. iso.org

Reviewed by

Manisha Dubey

Framework reviewer · QULDEX

Reviewed this page against ISO 31000:2018: principles, framework and process.

Page history
  • : Page first built: principles, framework and process explorer, adoption path and readiness check

Find the gaps in your risk management

Answer a short readiness check and get a gap summary by clause. No sales call needed to see the result.

Schedule
Book a Demo