The international guidance standard for risk management. Not certifiable, but the methodology every certifiable framework depends on.
ISO 31000 sets out principles and a process for managing risk of any kind — strategic, operational, financial, security, safety. It is the methodology that sits beneath the risk requirements of every certifiable management system standard.
One point up front: ISO 31000 is a guidance standard and is not intended for certification. Organisations cannot be certified against it, and any provider offering you an ISO 31000 certificate is selling something the standard does not support. This is worth knowing before you are quoted for one.
What it is genuinely useful for is giving an organisation one coherent, defensible way of identifying, analysing, evaluating and treating risk, instead of three or four incompatible approaches maintained by different teams and reported separately to the same board.
The process is familiar — establish context, identify, analyse, evaluate, treat, monitor, communicate. The value is in the discipline: defined criteria for likelihood and consequence, an explicit statement of how much risk the organisation will accept, named risk owners, and treatment decisions that are recorded and reviewed rather than assumed.
Any organisation implementing one or more management system standards, and any organisation whose risk reporting has stopped being useful.
Where separate, inconsistent risk registers have accumulated and cannot be reconciled for the board, because each uses different scales.
Receiving risk reporting they do not trust or cannot act on. Where every risk is amber and nothing ever moves, the methodology is the problem.
Getting the risk methodology right at the outset avoids rework across every standard that follows. This is the most common reason we are engaged on it.
Under APRA or SOCI obligations, where a documented and consistently applied risk process is an expectation rather than a nicety.
A risk methodology can also support a CIRMP, where a responsible entity must document and maintain its critical infrastructure risk programme under the SOCI rules.
Three to six weeks as a standalone engagement. More commonly delivered as the foundation stage of a certification programme.
Establish what risk processes exist across the organisation and where they conflict. Most organisations have several, built at different times for different audiences, producing ratings that cannot be compared.
Define likelihood and consequence scales that mean something in your context, set risk acceptance criteria, and agree escalation thresholds with the executive. Generic five-by-five matrices borrowed from a template are where this usually goes wrong.
A single register holding security, privacy, AI, quality and continuity risk side by side, with named owners and review dates, constructed inside your existing systems.
Run the methodology against real risks with the people who own them, then adjust the scales where they produce results the business does not believe. Calibration is what separates a usable methodology from a theoretical one.
So the register is maintained through normal operation rather than reconstructed in the fortnight before an audit.
Soveriq builds one risk methodology and one register that serves every framework in scope, inside the systems you already run. Where a certification programme is planned, this is the foundation laid before any risk is assessed — getting it right at the outset avoids rework across every subsequent standard.
We will not sell you an ISO 31000 certificate, because no legitimate body issues one.
What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise assessment outcomes.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
Most often this is delivered as the foundation stage of a certification programme rather than on its own.
No. It is explicitly a guidance standard, not designed for certification purposes. If a consultancy or certification body offers you an ISO 31000 certificate, that should change your view of them rather than your view of the standard. Individuals can hold training certificates in it; organisations cannot be certified against it.
Because every certifiable management system standard requires a risk process, and most organisations have three or four incompatible ones. ISO 31000 gives you a single defensible methodology that serves all of them, which saves rework across every subsequent certification.
ISO 27001 requires you to have a risk process and tells you what it must achieve. ISO 31000 describes how to build a good one. They operate at different levels and are complementary rather than alternatives.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope