ISO 31000
International standard providing principles and generic guidelines on risk management.
ISO 31000 is the principal international standard providing generic guidelines on risk management, applicable across organizations of any size and any sector. Unlike ISO 9001 or ISO/IEC 27001, ISO 31000 is explicitly non-certifiable: it provides principles, a framework for managing risk, and a process, but is intended as guidance rather than as a basis for third-party conformity assessment. The 2018 revision substantially simplified the structure of the 2009 original, condensing principles to eight, clarifying the framework's leadership role, and emphasizing integration with organizational governance and decision-making rather than treating risk management as a parallel process. ISO Guide 73 provides the related risk management vocabulary.
Core components
- Eight principles (integrated, structured, customized, inclusive, dynamic, best-available-information, human-and-cultural-factors, continual-improvement)
- Framework (leadership and commitment, integration, design, implementation, evaluation, improvement)
- Process (scope-context-criteria, risk assessment, risk treatment, recording and reporting, monitoring and review, communication and consultation)
Primary use case
General-purpose risk management guidance applicable across sectors; reference framework cited in sector-specific risk regimes; basis for organizational ERM programs alongside or instead of COSO ERM.
Common criticisms
- Non-certifiable nature limits market signaling
- high-level abstraction provides limited operational specificity
- substantial overlap with COSO ERM creates redundant adoption decisions
- some practitioners argue principles-based approach is too generic to drive real change
- inconsistent terminology with sector-specific regimes despite Guide 73.
Lineage
- Siblings
- COSO ERM, COSO Internal Control-Integrated Framework, Three Lines Model