ISO 31000
ISO 31000 is an international standard published by the International Organization for Standardization that offers principles and guidelines for managing risk within an organization. It provides a general approach to identifying, assessing, and handling risks that can be adapted to organizations of any type or size. Because it is guidance rather than a set of certifiable requirements, it is intended to inform and improve risk management practices rather than to be formally audited against.
ISO 31000 is a voluntary international standard providing principles and guidelines for the management of risk, with the current edition being ISO 31000:2018 (a second edition superseding the original 2009 version). It sets out guidance that can be customized to any organization and its context, addressing the identification, analysis, evaluation, and treatment of risk. Notably, ISO 31000 is framed as guidance and is not intended for certification purposes, distinguishing it from certifiable management-system standards; its adoption is a matter of organizational best practice rather than a legal or regulatory obligation. Application to a specific organizational context, and integration with jurisdiction-specific compliance requirements, generally warrants tailored professional judgment and is outside the scope of the standard itself.
Why it matters
Risk management practices vary widely across organizations, and without a common reference point, teams often develop inconsistent or ad hoc approaches to identifying and treating risk. ISO 31000 matters because it offers an internationally recognized set of principles and guidelines that can be customized to any organization regardless of type or size, giving compliance and risk functions a shared vocabulary and a structured way to think about risk. Its uniform guidance can support more consistent risk management practices and procedures across an enterprise.
It is important to understand what ISO 31000 is and is not. It is voluntary guidance rather than a set of certifiable requirements, and adopting it is a matter of organizational best practice rather than a legal or regulatory obligation. This distinguishes it from certifiable management-system standards: organizations generally cannot be formally audited or certified against ISO 31000 in the way they might be against a certifiable standard. Compliance teams should treat it as a tool to inform and improve risk management rather than as evidence of meeting any specific legal duty.
Because it is high-level guidance, ISO 31000 does not by itself satisfy jurisdiction-specific compliance requirements. Applying it to a particular organizational context, and integrating it with the regulatory obligations that apply in a given jurisdiction, generally warrants tailored professional judgment and typically falls outside the scope of the standard itself.
Who it's relevant to
Inside ISO 31000
Common questions
Answers to the questions practitioners most commonly ask about ISO 31000.

