Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Category: Risk Management

ISO 31000

Also known as: ISO 31000:2018, ISO 31000 Risk Management, Risk management — Guidelines
Simply put

ISO 31000 is an international standard published by the International Organization for Standardization that offers principles and guidelines for managing risk within an organization. It provides a general approach to identifying, assessing, and handling risks that can be adapted to organizations of any type or size. Because it is guidance rather than a set of certifiable requirements, it is intended to inform and improve risk management practices rather than to be formally audited against.

Formal definition

ISO 31000 is a voluntary international standard providing principles and guidelines for the management of risk, with the current edition being ISO 31000:2018 (a second edition superseding the original 2009 version). It sets out guidance that can be customized to any organization and its context, addressing the identification, analysis, evaluation, and treatment of risk. Notably, ISO 31000 is framed as guidance and is not intended for certification purposes, distinguishing it from certifiable management-system standards; its adoption is a matter of organizational best practice rather than a legal or regulatory obligation. Application to a specific organizational context, and integration with jurisdiction-specific compliance requirements, generally warrants tailored professional judgment and is outside the scope of the standard itself.

Why it matters

Risk management practices vary widely across organizations, and without a common reference point, teams often develop inconsistent or ad hoc approaches to identifying and treating risk. ISO 31000 matters because it offers an internationally recognized set of principles and guidelines that can be customized to any organization regardless of type or size, giving compliance and risk functions a shared vocabulary and a structured way to think about risk. Its uniform guidance can support more consistent risk management practices and procedures across an enterprise.

It is important to understand what ISO 31000 is and is not. It is voluntary guidance rather than a set of certifiable requirements, and adopting it is a matter of organizational best practice rather than a legal or regulatory obligation. This distinguishes it from certifiable management-system standards: organizations generally cannot be formally audited or certified against ISO 31000 in the way they might be against a certifiable standard. Compliance teams should treat it as a tool to inform and improve risk management rather than as evidence of meeting any specific legal duty.

Because it is high-level guidance, ISO 31000 does not by itself satisfy jurisdiction-specific compliance requirements. Applying it to a particular organizational context, and integrating it with the regulatory obligations that apply in a given jurisdiction, generally warrants tailored professional judgment and typically falls outside the scope of the standard itself.

Who it's relevant to

Risk Managers
Risk managers can use ISO 31000 as a reference framework of principles and guidelines to structure how the organization identifies, analyzes, evaluates, and treats risk. Because the guidance is designed to be customized to any organization and its context, it can help establish more consistent risk management practices and procedures.
Compliance Officers
Compliance officers should recognize that ISO 31000 is voluntary guidance and not a certifiable standard or a legal obligation. It can inform how risk is managed but does not by itself demonstrate compliance with jurisdiction-specific regulatory requirements, which generally must be addressed separately.
Internal Audit Functions
Internal auditors may find ISO 31000 useful as a benchmark for evaluating the maturity and consistency of an organization's risk management practices. However, because the standard is guidance rather than a set of certifiable requirements, it is not intended to be formally audited against in the manner of a certifiable management-system standard.
Senior Leadership and Boards
Executives and boards responsible for organizational governance can draw on ISO 31000's principles to promote a uniform, enterprise-wide approach to risk. Adoption is a matter of organizational best practice, and leadership generally needs tailored professional judgment to integrate the guidance with the specific legal and regulatory context in which the organization operates.

Inside ISO 31000

Principles
ISO 31000 sets out a set of guiding principles intended to make risk management effective, such as being integrated into organizational activities, structured and comprehensive, customized to context, and based on the best available information. These principles are guidance rather than certifiable requirements.
Framework
The standard describes a framework for integrating risk management into an organization's governance, leadership, and overall management. It emphasizes leadership commitment and the ongoing integration, design, implementation, evaluation, and improvement of risk management across the entity.
Process
ISO 31000 outlines a risk management process that generally includes elements such as communication and consultation, establishing scope and context, risk assessment (identification, analysis, and evaluation), risk treatment, and monitoring and review. The process is intended to be iterative rather than strictly linear.
Guidance nature
ISO 31000 is published as a guidance standard by the International Organization for Standardization. It provides voluntary guidelines and is generally not intended for certification purposes, unlike some other ISO management system standards.

Common questions

Answers to the questions practitioners most commonly ask about ISO 31000.

Is ISO 31000 a certifiable standard that our organization can be audited against?
No. ISO 31000 is a guidance standard providing principles, a framework, and a process for managing risk; it is not written as a set of auditable requirements and is not intended for certification. Unlike standards that use conformity-oriented language (such as certain management system standards designed for third-party certification), ISO 31000 is advisory in nature. Organizations may adopt its guidance voluntarily and align their practices to it, but any claim of "ISO 31000 certification" should be treated with caution. Confirm the current scope and intended use directly with the published standard from ISO.
Does implementing ISO 31000 make our organization compliant with regulatory risk management obligations?
Not by itself. ISO 31000 is a voluntary best-practice framework, not a legal or regulatory instrument, so adopting it does not automatically satisfy any statutory or regulator-imposed risk management requirement. Specific obligations arise from the applicable laws, regulations, or supervisory expectations in your jurisdiction and sector, and these differ across regimes. ISO 31000 may support and structure your approach, but conformance to the standard and compliance with a given regulation are distinct concepts. Whether the two align in a particular case generally depends on the relevant regulatory requirements and may warrant professional advice.
How does ISO 31000 relate to the risk assessment process we already run?
ISO 31000 describes a risk management process that typically includes establishing context, risk identification, risk analysis, risk evaluation, risk treatment, and ongoing communication, consultation, monitoring, and review. Many organizations map their existing assessment activities to these process stages to check for gaps, such as insufficient context-setting or weak monitoring. Because the standard is guidance rather than a prescriptive checklist, how you operationalize each stage may depend on your organization's structure, risk appetite, and objectives.
Can we use ISO 31000 alongside other frameworks or standards we already apply?
Generally, yes. ISO 31000 is designed to be broad and framework-agnostic, so organizations often use it as an overarching reference for risk management principles while applying more specific or sector-focused frameworks for particular domains. Because it is guidance rather than a certifiable requirement, it is typically positioned to complement rather than replace existing controls, policies, or standards. How well it integrates in practice may depend on how your other frameworks are structured and governed.
Who within the organization should own the ISO 31000 framework?
ISO 31000 emphasizes that risk management should be integrated across the organization with leadership and governance involvement, rather than confined to a single function. In practice, ownership often reflects existing accountability structures, so responsibilities may be distributed across governing bodies, senior management, and functions such as risk management. It is important to keep role distinctions clear where they apply in your governance model, for example separating the function that manages and coordinates risk from any independent assurance function. The standard provides principles rather than a fixed allocation of roles, so specific assignments should be documented according to your own structure.
How do we demonstrate that our practices align with ISO 31000 if it is not certifiable?
Because ISO 31000 is not designed for certification, alignment is typically evidenced through internal documentation rather than an external certificate. Organizations commonly maintain records showing how their principles, framework, and process map to the standard's guidance, such as policy documents, risk registers, and evidence of monitoring and review. This can support internal governance and may inform discussions with stakeholders, but it should not be presented as formal proof of conformance in the way a certified standard would be. The appropriate form of evidence may depend on your internal governance expectations and any external stakeholder requirements.

Common misconceptions

Organizations can become 'certified' to ISO 31000.
ISO 31000 is generally intended as a guidance document rather than a certifiable management system standard. Because it provides guidelines rather than auditable requirements, it is typically not used as a basis for third-party certification. Organizations seeking certifiable risk-related standards should confirm which specific ISO documents support certification.
Adopting ISO 31000 by itself demonstrates regulatory compliance.
ISO 31000 is a voluntary standard, not a legal or regulatory obligation. Following its guidance does not by itself satisfy any statutory or regulatory requirement, and compliance obligations depend on the applicable jurisdiction and regime. Using the standard may support good risk management practice but does not substitute for meeting specific legal requirements.
ISO 31000 prescribes a fixed, one-size-fits-all risk process.
The standard is intended to be customized to an organization's context and is generally described as iterative rather than a rigid sequence. It provides principles and guidance to be adapted, not a mandatory step-by-step methodology that must be applied identically across all organizations.

Best practices

Treat ISO 31000 as guidance to be tailored to your organization's context, size, and objectives rather than applying its process elements mechanically.
Integrate risk management into existing governance and management activities, consistent with the framework's emphasis on leadership commitment and integration, rather than treating it as a standalone exercise.
Apply the risk management process iteratively, revisiting scope, assessment, treatment, and monitoring as circumstances change rather than assuming a single linear pass is sufficient.
Do not rely on ISO 31000 alone to demonstrate regulatory compliance; map your risk activities against the specific legal and regulatory obligations that apply in your jurisdiction and seek professional or legal advice where application is uncertain.
Clarify to stakeholders that ISO 31000 is a voluntary guidance standard and generally not a basis for certification, to avoid misrepresenting your risk management posture.
Base risk assessments on the best available information and document the communication and consultation carried out with relevant stakeholders throughout the process.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide