What it is
What ISO 31000 is
ISO 31000 is the international standard that provides guidance on managing risk. It is not a set of requirements to be certified against - it is a set of principles, a framework for embedding risk management in an organisation, and a process for doing the work. It applies to any kind of risk (strategic, operational, financial, security, project) and to any organisation, which is why it is the common reference point whenever people talk about “enterprise risk management”.
Where a standard like ISO 27001 tells you what an information-security management system must contain, ISO 31000 tells you how to think about and run risk management itself - the discipline that sits underneath every management system that asks you to “identify and treat your risks”.
Why ISO 31000 exists
Most organisations manage risk in fragments: a register a department refreshes before a board meeting, a separate security assessment, a project’s own risk log - none of them talking to each other, and none of them driving decisions. ISO 31000 exists to make risk management a coherent, organisation-wide discipline that actually informs decisions, rather than a compliance ritual. Its message is that risk management should be integrated, structured and continually improved - part of how you run the organisation, not a document you produce.
Who uses ISO 31000
Any organisation that wants to manage risk deliberately - but it is especially valuable where risk is contractual or regulatory. Defence suppliers must manage risk to contract performance (AQAP 2110); ISO 27001 requires an information-security risk process; NIS2 and sector regulators increasingly expect demonstrable risk management. ISO 31000 gives all of these a common language and method, so one risk framework can serve the whole organisation rather than each standard spawning its own.
How the standard is structured
ISO 31000 is organised in three parts that build on each other:
- Principles: what good risk management looks like - integrated, structured, tailored, inclusive, dynamic, and based on the best available information.
- Framework: how leadership embeds risk management in the organisation - its purpose, integration, design, implementation, evaluation and improvement.
- Process: the working cycle - establish the scope and context, then identify, analyse and evaluate risks, treat them, and continually monitor, review and communicate throughout.
It is deliberately not prescriptive: there is no mandated risk matrix or scale. The point is a consistent, evidenced method that fits your organisation, not a form to fill in.
Certification: there isn’t one
You cannot be “certified to ISO 31000”, and any supplier offering to certify you against it is misreading the standard. ISO 31000 is guidance. Organisations adopt it to structure and improve their risk management, and they evidence that through their risk framework and records - which is exactly what an ISO 9001, ISO 27001 or AQAP 2110 assessor examines when they look at how you manage risk.