Every business manages risk, whether it realises it or not: the client who pays late, the single supplier who lets you down, the production manager off sick, the IT failure that brings invoicing to a halt. ISO 31000:2018 does not add paperwork to that work; it gives it structure. The standard sets out principles, a governance framework and a repeatable process, so identifying and treating risk stops depending on one person's memory and becomes a system that outlives whoever built it.
The standard organises itself into three parts that feed into each other: the principles, which explain what risk management is for (protecting and creating value, not just avoiding losses); the framework, which sets the governance an organisation needs so risk management does not rest on a single person; and the process, which repeats in every review cycle. We break these down in the section below. None of the three works alone: a risk map with no governance framework behind it is just a document nobody updates.
ISO 31000 is deliberately a guideline, not a certifiable requirement. It carries none of the mandatory 'shall' clauses that ISO 9001 or ISO/IEC 27001 do, and no ENAC-accredited body issues a certificate called ISO 31000. What can be certified are the management systems that build on its approach: clause 6.1 of ISO 9001, ISO 14001, ISO 45001 and ISO/IEC 27001 requires risks and opportunities to be identified within the system, and ISO 31000 is the framework that gives that clause its shape.
The risk family does not stop at ISO 31000. IEC 31010:2019 (EN IEC 31010:2019) supplies the catalogue of techniques (root cause analysis, scenario analysis, FMEA, probability/impact matrices) used to carry out the identification and analysis stage of the process. Some management systems carry that framework into a specific domain: ISO/IEC 27005 guides the information security risk assessment required by clause 6.1.2 of ISO/IEC 27001, without its use being mandatory; and ISO 22301 applies an equivalent logic, the business impact analysis, to business continuity.
At Summum Calidad we do not hand over a risk matrix filled in with another client's generic entries. We build the map with the people who actually run each process, set criteria for probability and impact that belong to your business, and leave a live risk register, with an owner and a review date, integrated into whatever management system you already run. Certification, where it applies, is issued by an accredited third party; our job is to make sure that third party finds a real system, not an exam exercise.