Risk management

ISO 31000

ISO 31000:2018 sets out how to design, implement and review an organisation's risk management. It is not a certifiable management system: it is the framework behind the risk-based approach required by ISO 9001, ISO 14001, ISO 45001 and ISO/IEC 27001.

StandardISO 31000:2018
NatureGuideline, not certifiable
ScopeAny organisation, any type of risk

Every business manages risk, whether it realises it or not: the client who pays late, the single supplier who lets you down, the production manager off sick, the IT failure that brings invoicing to a halt. ISO 31000:2018 does not add paperwork to that work; it gives it structure. The standard sets out principles, a governance framework and a repeatable process, so identifying and treating risk stops depending on one person's memory and becomes a system that outlives whoever built it.

The standard organises itself into three parts that feed into each other: the principles, which explain what risk management is for (protecting and creating value, not just avoiding losses); the framework, which sets the governance an organisation needs so risk management does not rest on a single person; and the process, which repeats in every review cycle. We break these down in the section below. None of the three works alone: a risk map with no governance framework behind it is just a document nobody updates.

ISO 31000 is deliberately a guideline, not a certifiable requirement. It carries none of the mandatory 'shall' clauses that ISO 9001 or ISO/IEC 27001 do, and no ENAC-accredited body issues a certificate called ISO 31000. What can be certified are the management systems that build on its approach: clause 6.1 of ISO 9001, ISO 14001, ISO 45001 and ISO/IEC 27001 requires risks and opportunities to be identified within the system, and ISO 31000 is the framework that gives that clause its shape.

The risk family does not stop at ISO 31000. IEC 31010:2019 (EN IEC 31010:2019) supplies the catalogue of techniques (root cause analysis, scenario analysis, FMEA, probability/impact matrices) used to carry out the identification and analysis stage of the process. Some management systems carry that framework into a specific domain: ISO/IEC 27005 guides the information security risk assessment required by clause 6.1.2 of ISO/IEC 27001, without its use being mandatory; and ISO 22301 applies an equivalent logic, the business impact analysis, to business continuity.

At Summum Calidad we do not hand over a risk matrix filled in with another client's generic entries. We build the map with the people who actually run each process, set criteria for probability and impact that belong to your business, and leave a live risk register, with an owner and a review date, integrated into whatever management system you already run. Certification, where it applies, is issued by an accredited third party; our job is to make sure that third party finds a real system, not an exam exercise.

The three pillars of ISO 31000: principles, framework and process

ISO 31000:2018 is not a checklist audited item by item; it is a model built from three parts that feed each other. The principles explain what risk management is for: creating and protecting value, not just avoiding losses. The framework is the governance scaffolding that embeds that management into everyday operations: leadership, risk policy, allocated resources and communication. And the process is the operational part, the one that repeats in every cycle.

The stages of the process

  • Scope, context and criteria: what is being analysed, and on what scale of probability and impact.
  • Identification: what could happen, and who in the organisation is consulted to find out.
  • Analysis: why it might happen and what the consequences would be.
  • Evaluation: comparing against the acceptance criteria and deciding what gets treated first.
  • Treatment: avoid, reduce, transfer or accept, with an owner and a deadline.
  • Monitoring, recording and communication: run across every stage, not a final step.

Risk matrix for an industrial SME: a worked example

A risk matrix is only useful if it comes from the company's real processes, not a generic list from a manual. Here is an example matrix for an industrial manufacturing SME with 40-60 employees, built with probability and impact on three levels (low, medium, high) and an extra level (very high) for risks that combine high probability with high impact.

RiskProbabilityImpactLevelTreatment
Dependence on a single supplier for critical raw materialMediumHighHighQualify a second approved supplier and hold four weeks of safety stock.
Unplanned stoppage of the main production lineMediumHighHighPreventive maintenance plan and an availability contract for critical spare parts.
Ransomware attack on the ERP and production systemsLowVery highHighDaily offline back-up, network segmentation and a continuity plan.
Long-term absence of a key person with no trained backupMediumMediumMediumDocument critical procedures and train a second person for every sensitive role.
Revenue concentrated in one or two customersLowHighMedium-highPortfolio diversification plan and credit insurance on the accounts with the highest exposure.
Sudden regulatory change affecting product markingMediumMediumMediumRegular regulatory watch and an annual review of the technical file.

The level of each risk does not come from an automatic formula: probability and impact are set using the company's own criteria, approved by the board, not a scale copied from another organisation.

ISO 31000 and clause 6.1: what each management system requires

The harmonised structure (formerly known as the high-level structure, or Annex SL) common to the ISO management-system standards includes a clause 6.1 dedicated to risks and opportunities. ISO 31000 is not cited by name in that text, but it is the framework consultants and auditors use to resolve it properly, rather than with a token table nobody looks at again.

StandardClauseWhat it requires on risk
ISO 9001:20156.1Determine the risks and opportunities that affect product or service conformity and customer satisfaction.
ISO 14001:20156.1.1 to 6.1.4Identify risks and opportunities linked to environmental aspects and applicable legal requirements.
ISO 45001:20186.1.2Identify hazards and assess occupational health and safety risks and opportunities, with worker participation.
ISO/IEC 27001:20226.1.2 and 6.1.3Assess and treat information security risk before selecting the Annex A controls.
ISO 22301:20196.1 and the business impact analysisIdentify disruption risks and supplement them with the standard's own business impact analysis (BIA).

When a company certifies several of these systems at once, a single risk register built on ISO 31000 methodology avoids repeating the same analysis with different criteria for every audit.

What can and can't be certified, and when to formalise risk management

No ENAC-accredited body issues a certificate called ISO 31000: the standard describes itself as a guide. What a certification body can audit and certify is whether a company's management system resolves its risk clause with a coherent process and real evidence. Confusing the two is a common mistake: nobody can promise an "ISO 31000 certification" because that certification does not exist.

In practice, it pays to formalise risk management with ISO 31000 before, rather than after, these moments:

  • Before implementing ISO 22301 or ISO/IEC 27001, since both require a mature risk analysis as a starting point.
  • When a company moves into public procurement and needs to show how it manages contract risk.
  • After an incident reveals that nobody had been given responsibility for watching that risk.

The ISO 31000 process.

The process · four stages
01

Diagnosis and context

We analyse the organisation's internal and external context, identify the relevant interested parties and set the risk criteria: what counts as high probability or severe impact in your business, not in a generic manual. This is also where the risk appetite the board signs off on comes from.

02

Identification and analysis

We run workshops with the people responsible for each area to build the risk catalogue process by process, using whichever IEC 31010 techniques suit each case best: scenarios, FMEA or probability/impact matrices.

03

Evaluation and treatment

We prioritise risks against the criteria set in the diagnosis stage and define the treatment for each one: avoid, reduce, transfer or accept. Every treatment is assigned to an owner with a deadline.

04

Monitoring, records and integration

We put a monitoring dashboard and a review calendar in place, and connect the risk register to clause 6.1 of the company's certifiable management system, where one exists, so both documents say the same thing.

What is included

What ISO 31000 includes.

The operational detail: what we deliver as part of the work and what we keep alive afterwards.

  • Context and stakeholder map

    The organisation's internal and external context, with the relevant interested parties and their expectations around risk.

  • Risk catalogue by process

    Risk inventory identified in workshops with the people responsible for each area, not copied from a sector list.

  • Probability x impact matrix with your own criteria

    Assessment scale defined with the company, not from a manual, applied to every risk in the catalogue.

  • Treatment plan with owner and deadline

    For each prioritised risk: treatment action, owner and review date.

  • Live risk register

    A single document, updated at every review, that replaces the spreadsheet nobody opens again.

  • Integration with clause 6.1 of the management system

    Connection between the risk register and clause 6.1 of ISO 9001, ISO 14001, ISO 45001 or ISO/IEC 27001, when the company certifies one of those systems.

Marco normativo

The regulatory framework

Normas y reglamentos verificados que aplican a este servicio: ISO 31000:2018, IEC 31010:2019 (EN IEC 31010:2019), Clause 6.1 of ISO 9001:2015 and ISO 14001:2015….

ISO ISO 31000:2018 International, non-certifiable guideline for designing, implementing and reviewing risk management in any organisation, built on principles, a governance framework and a repeatable application process.
IEC IEC 31010:2019 (EN IEC 31010:2019) Catalogue of risk identification and assessment techniques (FMEA, scenario analysis, Monte Carlo simulation) applied within the ISO 31000 process.
CLAUSE Clause 6.1 of ISO 9001:2015 and ISO… Determine the management system's risks and opportunities, with planned actions and an evaluation of their effectiveness; a structure common to the ISO management-system standards.
ISO Clause 6.1 of ISO/IEC 27001:2022 Assess (6.1.2) and treat (6.1.3) information security risk before selecting the Annex A controls; it does not impose a specific methodology.

Frequently asked questions about ISO 31000.

Can ISO 31000 be certified?

No. It is a guideline, not a system with requirements you can audit one by one, and no accredited body issues a certificate under that name. What is certified are the management systems that build in its risk approach, such as ISO 9001, ISO 14001 or ISO/IEC 27001, within clause 6.1. Working with ISO 31000 strengthens the risk evidence those audits ask for, even though another standard issues the certificate.

What is the difference between ISO 31000 and ISO/IEC 31010?

ISO 31000 sets the principles, the governance framework and the stages of the risk management process. ISO/IEC 31010:2019 is the catalogue of techniques for carrying out those stages: which method to use to identify, analyse or evaluate a risk, depending on the kind of decision at hand. The two are used together: the first says what to do, the second says how to do it.

My company already has ISO 9001 or ISO 27001; why do I also need ISO 31000?

Those systems already require risk to be managed under their clause 6.1, but they don't say how to do it rigorously. ISO 31000 supplies the methodology: your own criteria, a repeatable process and an auditable register. Without it, many companies fill in clause 6.1 with a generic table that doesn't hold up under a demanding audit.

What is risk appetite, and who decides it?

It is the level of risk an organisation accepts in pursuit of its objectives, before treatment measures kick in. It is set by the board, not the technical team: it is a strategic decision that later translates into the acceptance criteria on the matrix.

Is ISO 31000 for SMEs, or only for large companies?

The standard declares itself applicable to any organisation, regardless of size or sector. In an SME the process is simpler: fewer approval levels, and identification workshops run with the same people who already manage each area, with no dedicated risk committee.

How does ISO 31000 relate to ISO 22301 (business continuity)?

ISO 22301 applies the logic of ISO 31000 to one specific type of risk: disruption to the business. Its business impact analysis (BIA) is, in essence, the identification-and-analysis stage of ISO 31000, focused on which processes cannot stop, and for how long.

How long does it take a company to have its first working risk map?

It depends on how many processes are involved and whether it is integrated into an already-certified system. Building the first catalogue, matrix and register is usually a few weeks of joint work; keeping it alive through regular reviews is an ongoing process, not a project with a closing date.

Who audits whether our ISO 31000 risk management is adequate?

There is no certification audit for ISO 31000 on its own. What gets audited, as part of certifying a management system, is whether clause 6.1 is resolved with a coherent risk process. An internal audit beforehand is how you check that before the external auditor arrives.