ISO 31000

framework · governance and compliance · regulatory-standard

International standard providing principles and generic guidelines on risk management.

ISO 31000 is the principal international standard providing generic guidelines on risk management, applicable across organizations of any size and any sector. Unlike ISO 9001 or ISO/IEC 27001, ISO 31000 is explicitly non-certifiable: it provides principles, a framework for managing risk, and a process, but is intended as guidance rather than as a basis for third-party conformity assessment. The 2018 revision substantially simplified the structure of the 2009 original, condensing principles to eight, clarifying the framework's leadership role, and emphasizing integration with organizational governance and decision-making rather than treating risk management as a parallel process. ISO Guide 73 provides the related risk management vocabulary.

Originators

International Organization for Standardization Technical Committee 262 (ISO/TC 262) high

Year / Decade

2009 (first edition); 2018 (current revision) high

Primary sources

ISO (2018). ISO 31000:2018 Risk management — Guidelines, ISO Guide 73:2009 Risk management — Vocabulary high

Core components

Primary use case

General-purpose risk management guidance applicable across sectors; reference framework cited in sector-specific risk regimes; basis for organizational ERM programs alongside or instead of COSO ERM.

Common criticisms

Lineage

Siblings
COSO ERM, COSO Internal Control-Integrated Framework, Three Lines Model