ISO 31000:2018 — Risk Management

The international guidance standard for risk management. Not certifiable, but the methodology every certifiable framework depends on.

ISO, through technical committee ISO/TC 262. Not a certification standard.

What it is

ISO 31000 sets out principles and a process for managing risk of any kind — strategic, operational, financial, security, safety. It is the methodology that sits beneath the risk requirements of every certifiable management system standard.

One point up front: ISO 31000 is a guidance standard and is not intended for certification. Organisations cannot be certified against it, and any provider offering you an ISO 31000 certificate is selling something the standard does not support. This is worth knowing before you are quoted for one.

What it is genuinely useful for is giving an organisation one coherent, defensible way of identifying, analysing, evaluating and treating risk, instead of three or four incompatible approaches maintained by different teams and reported separately to the same board.

The process is familiar — establish context, identify, analyse, evaluate, treat, monitor, communicate. The value is in the discipline: defined criteria for likelihood and consequence, an explicit statement of how much risk the organisation will accept, named risk owners, and treatment decisions that are recorded and reviewed rather than assumed.

Who it's for

Any organisation implementing one or more management system standards, and any organisation whose risk reporting has stopped being useful.

Organisations running multiple frameworks

Where separate, inconsistent risk registers have accumulated and cannot be reconciled for the board, because each uses different scales.

Boards and executives

Receiving risk reporting they do not trust or cannot act on. Where every risk is amber and nothing ever moves, the methodology is the problem.

Organisations starting a certification programme

Getting the risk methodology right at the outset avoids rework across every standard that follows. This is the most common reason we are engaged on it.

Regulated entities

Under APRA or SOCI obligations, where a documented and consistently applied risk process is an expectation rather than a nicety.

A risk methodology can also support a CIRMP, where a responsible entity must document and maintain its critical infrastructure risk programme under the SOCI rules.

Why implement it

  • It makes risk comparable. Without a common methodology, security risk, quality risk and financial risk cannot be ranked against each other, so the loudest voice wins rather than the largest exposure.
  • It satisfies multiple standards at once. ISO 27001, 27701, 42001, 9001, 20000-1 and 22301 all require a risk process. One methodology built properly serves all of them.
  • It improves board reporting. Consistent criteria mean reporting shows movement over time rather than a fresh set of subjective ratings each quarter.
  • It withstands audit scrutiny. Auditors probe how ratings were arrived at. A documented methodology with defined criteria answers that; a spreadsheet of colour-coded opinions does not.

How implementation works

Three to six weeks as a standalone engagement. More commonly delivered as the foundation stage of a certification programme.

1. Review current practice

Establish what risk processes exist across the organisation and where they conflict. Most organisations have several, built at different times for different audiences, producing ratings that cannot be compared.

2. Design the methodology

Define likelihood and consequence scales that mean something in your context, set risk acceptance criteria, and agree escalation thresholds with the executive. Generic five-by-five matrices borrowed from a template are where this usually goes wrong.

3. Build the register

A single register holding security, privacy, AI, quality and continuity risk side by side, with named owners and review dates, constructed inside your existing systems.

4. Populate and calibrate

Run the methodology against real risks with the people who own them, then adjust the scales where they produce results the business does not believe. Calibration is what separates a usable methodology from a theoretical one.

5. Embed the review cycle

So the register is maintained through normal operation rather than reconstructed in the fortnight before an audit.

How Soveriq helps

Soveriq builds one risk methodology and one register that serves every framework in scope, inside the systems you already run. Where a certification programme is planned, this is the foundation laid before any risk is assessed — getting it right at the outset avoids rework across every subsequent standard.

We will not sell you an ISO 31000 certificate, because no legitimate body issues one.

What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise assessment outcomes.

What the engagement looks like

  • Module 01 — Gap analysis of existing risk processes across the organisation.
  • Module 02 — Build. Methodology design, criteria and appetite, and a single register built inside your own environment.
  • Module 05 — Continuous compliance. Keeping the register maintained through normal operation rather than reconstructed before each audit.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Most often this is delivered as the foundation stage of a certification programme rather than on its own.

Common questions

Can we get certified to ISO 31000?

No. It is explicitly a guidance standard, not designed for certification purposes. If a consultancy or certification body offers you an ISO 31000 certificate, that should change your view of them rather than your view of the standard. Individuals can hold training certificates in it; organisations cannot be certified against it.

Then why bother with it?

Because every certifiable management system standard requires a risk process, and most organisations have three or four incompatible ones. ISO 31000 gives you a single defensible methodology that serves all of them, which saves rework across every subsequent certification.

How is it different from the risk requirements in ISO 27001?

ISO 27001 requires you to have a risk process and tells you what it must achieve. ISO 31000 describes how to build a good one. They operate at different levels and are complementary rather than alternatives.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope