Start a free trial
Menu

ISO 31000

ISO 31000 risk management software

Organisations building an enterprise risk management framework - including regulated and defence suppliers.

ISO 31000 is the international guidance for managing risk. ComplyTrain’s risk management is structured around its process, so risk is a living framework across the organisation, not a spreadsheet reviewed once a year.

ComplyTrain fully supports this standard

What ISO 31000 is

ISO 31000 is the international standard that provides guidance on managing risk. It is not a set of requirements to be certified against - it is a set of principles, a framework for embedding risk management in an organisation, and a process for doing the work. It applies to any kind of risk (strategic, operational, financial, security, project) and to any organisation, which is why it is the common reference point whenever people talk about “enterprise risk management”.

Where a standard like ISO 27001 tells you what an information-security management system must contain, ISO 31000 tells you how to think about and run risk management itself - the discipline that sits underneath every management system that asks you to “identify and treat your risks”.

Why ISO 31000 exists

Most organisations manage risk in fragments: a register a department refreshes before a board meeting, a separate security assessment, a project’s own risk log - none of them talking to each other, and none of them driving decisions. ISO 31000 exists to make risk management a coherent, organisation-wide discipline that actually informs decisions, rather than a compliance ritual. Its message is that risk management should be integrated, structured and continually improved - part of how you run the organisation, not a document you produce.

Who uses ISO 31000

Any organisation that wants to manage risk deliberately - but it is especially valuable where risk is contractual or regulatory. Defence suppliers must manage risk to contract performance (AQAP 2110); ISO 27001 requires an information-security risk process; NIS2 and sector regulators increasingly expect demonstrable risk management. ISO 31000 gives all of these a common language and method, so one risk framework can serve the whole organisation rather than each standard spawning its own.

How the standard is structured

ISO 31000 is organised in three parts that build on each other:

  • Principles: what good risk management looks like - integrated, structured, tailored, inclusive, dynamic, and based on the best available information.
  • Framework: how leadership embeds risk management in the organisation - its purpose, integration, design, implementation, evaluation and improvement.
  • Process: the working cycle - establish the scope and context, then identify, analyse and evaluate risks, treat them, and continually monitor, review and communicate throughout.

It is deliberately not prescriptive: there is no mandated risk matrix or scale. The point is a consistent, evidenced method that fits your organisation, not a form to fill in.

Certification: there isn’t one

You cannot be “certified to ISO 31000”, and any supplier offering to certify you against it is misreading the standard. ISO 31000 is guidance. Organisations adopt it to structure and improve their risk management, and they evidence that through their risk framework and records - which is exactly what an ISO 9001, ISO 27001 or AQAP 2110 assessor examines when they look at how you manage risk.

How ComplyTrain helps you apply it

ComplyTrain’s risk management is structured around the ISO 31000 process, so risk is a living framework rather than a spreadsheet:

  • One risk register across the organisation - strategic, operational, security and contract risk in a single place - Risk Management
  • The ISO 31000 cycle built in: identify, analyse, evaluate, treat and monitor, with owners and review dates
  • Risks linked to the requirements, documents and suppliers they relate to, so a risk is connected to the work rather than stranded in a tab
  • Risk as an input to management review and reporting, collated automatically rather than assembled by hand

Because the same register serves your ISO 9001, ISO 27001 and AQAP 2110 obligations, you run one risk framework instead of one per standard.

Questions

Can an organisation be certified to ISO 31000?

No. ISO 31000 is guidance, not a certifiable management-system standard - there is no accredited certification against it. Organisations adopt it to structure their risk management and evidence it through their risk framework and records, which assessors of standards like ISO 9001 and ISO 27001 will examine.

How does ISO 31000 relate to ISO 27001’s risk assessment?

ISO 27001 requires an information-security risk process but does not dictate the method; ISO 31000 provides one. Many organisations run their ISO 27001 risk assessment as a specific application of an ISO 31000-based framework, so information-security risk sits in the same register and method as the rest of their risk.

What is the ISO 31000 risk management process?

Establish the scope, context and criteria; then identify risks, analyse them, and evaluate them against your criteria; treat the ones that warrant it; and monitor, review and communicate throughout. It is a continuous cycle, not a one-off assessment - the register is meant to live and change with the organisation.

The process

The ISO 31000 risk management process

ISO 31000 describes risk management as a continuous cycle. These are its core steps, run over and over rather than once.

  1. Scope, context and criteria

    Decide what the assessment covers, understand the internal and external context, and set the criteria you will judge risks against.

  2. Identify, analyse, evaluate

    Find the risks, understand their causes, consequences and likelihood, then evaluate each against your criteria to decide which need action.

  3. Treat the risk

    Choose how to treat each risk that warrants it - avoid, reduce, share or accept - assign an owner, and record the decision and the controls.

  4. Monitor, review, communicate

    Keep the register live: review risks and treatments on a cadence, track changes, and communicate risk to the people who decide on it.

Manage your ISO 31000 compliance in one system

See how ComplyTrain maps to your framework on a 30-minute demo, walked through on your own processes. Or start a trial and we will set up a workspace to match what you are working on.