Start a free trial
Menu

ISO 31000

ISO 31000 risk management

Organisations building an enterprise risk management framework - including regulated and defence suppliers.

ISO 31000 is the international guidance for managing risk. ComplyTrain’s risk management is structured around its process, so risk is a living framework across the organisation, not a spreadsheet reviewed once a year.

What it is

What ISO 31000 is

ISO 31000 is the international standard that provides guidance on managing risk. It is not a set of requirements to be certified against - it is a set of principles, a framework for embedding risk management in an organisation, and a process for doing the work. It applies to any kind of risk (strategic, operational, financial, security, project) and to any organisation, which is why it is the common reference point whenever people talk about “enterprise risk management”.

Where a standard like ISO 27001 tells you what an information-security management system must contain, ISO 31000 tells you how to think about and run risk management itself - the discipline that sits underneath every management system that asks you to “identify and treat your risks”.

Why ISO 31000 exists

Most organisations manage risk in fragments: a register a department refreshes before a board meeting, a separate security assessment, a project’s own risk log - none of them talking to each other, and none of them driving decisions. ISO 31000 exists to make risk management a coherent, organisation-wide discipline that actually informs decisions, rather than a compliance ritual. Its message is that risk management should be integrated, structured and continually improved - part of how you run the organisation, not a document you produce.

Who uses ISO 31000

Any organisation that wants to manage risk deliberately - but it is especially valuable where risk is contractual or regulatory. Defence suppliers must manage risk to contract performance (AQAP 2110); ISO 27001 requires an information-security risk process; NIS2 and sector regulators increasingly expect demonstrable risk management. ISO 31000 gives all of these a common language and method, so one risk framework can serve the whole organisation rather than each standard spawning its own.

How the standard is structured

ISO 31000 is organised in three parts that build on each other:

  • Principles: what good risk management looks like - integrated, structured, tailored, inclusive, dynamic, and based on the best available information.
  • Framework: how leadership embeds risk management in the organisation - its purpose, integration, design, implementation, evaluation and improvement.
  • Process: the working cycle - establish the scope and context, then identify, analyse and evaluate risks, treat them, and continually monitor, review and communicate throughout.

It is deliberately not prescriptive: there is no mandated risk matrix or scale. The point is a consistent, evidenced method that fits your organisation, not a form to fill in.

Certification: there isn’t one

You cannot be “certified to ISO 31000”, and any supplier offering to certify you against it is misreading the standard. ISO 31000 is guidance. Organisations adopt it to structure and improve their risk management, and they evidence that through their risk framework and records - which is exactly what an ISO 9001, ISO 27001 or AQAP 2110 assessor examines when they look at how you manage risk.

Put ISO 31000 on a system that keeps the evidence

Documents, training, risks and evidence in one place, with the trail an auditor asks for.

How we help

How ComplyTrain helps you apply it

ComplyTrain’s risk management is structured around the ISO 31000 process, so risk is a living framework rather than a spreadsheet:

  • One risk register across the organisation - strategic, operational, security and contract risk in a single place - Risk Management
  • The ISO 31000 cycle built in: identify, analyse, evaluate, treat and monitor, with owners and review dates
  • Risks linked to the requirements, documents and suppliers they relate to, so a risk is connected to the work rather than stranded in a tab
  • Risk as an input to management review and reporting, collated automatically rather than assembled by hand

Because the same register serves your ISO 9001, ISO 27001 and AQAP 2110 obligations, you run one risk framework instead of one per standard.

Request access to this standard

Tell us how you need to work with ISO 31000 and what you need from it. We will come back to you about what ComplyTrain can do.

Questions

Can an organisation be certified to ISO 31000?

No. ISO 31000 is guidance, not a certifiable management-system standard - there is no accredited certification against it. Organisations adopt it to structure their risk management and evidence it through their risk framework and records, which assessors of standards like ISO 9001 and ISO 27001 will examine.

How does ISO 31000 relate to ISO 27001’s risk assessment?

ISO 27001 requires an information-security risk process but does not dictate the method; ISO 31000 provides one. Many organisations run their ISO 27001 risk assessment as a specific application of an ISO 31000-based framework, so information-security risk sits in the same register and method as the rest of their risk.

What is the ISO 31000 risk management process?

Establish the scope, context and criteria; then identify risks, analyse them, and evaluate them against your criteria; treat the ones that warrant it; and monitor, review and communicate throughout. It is a continuous cycle, not a one-off assessment - the register is meant to live and change with the organisation.

The process

The ISO 31000 risk management process

ISO 31000 describes risk management as a continuous cycle. These are its core steps, run over and over rather than once.

  1. Scope, context and criteria

    Decide what the assessment covers, understand the internal and external context, and set the criteria you will judge risks against.

  2. Identify, analyse, evaluate

    Find the risks, understand their causes, consequences and likelihood, then evaluate each against your criteria to decide which need action.

  3. Treat the risk

    Choose how to treat each risk that warrants it - avoid, reduce, share or accept - assign an owner, and record the decision and the controls.

  4. Monitor, review, communicate

    Keep the register live: review risks and treatments on a cadence, track changes, and communicate risk to the people who decide on it.

If you need to get there and have no quality function

A standard usually arrives as a contract condition rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the certification audit.

    How an engagement works
  • Full-service quality function

    We run and maintain the quality system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Manage your ISO 31000 compliance in one system

See how ComplyTrain maps to your framework on a 30-minute demo, walked through on your own processes. Or start a trial and we will set up a workspace to match what you are working on.

What ComplyTrain does

One system for the whole compliance programme. Start with the module you need most.

  • Forms & Follow-up

    Collect information the same way every time, and decide in advance what happens next.

  • Controls & Assurance

    Know whether your controls are operating, not just whether a policy says they exist.

  • Project Planner

    Turn the compliance work you already know about into a plan with owners, dependencies and dates.

  • Product Compliance

    Know what you can offer, and hold the evidence behind every configuration you offer it in.

  • Reporting & Analytics

    Eight built-in reports across every module, scheduled, delivered, and filed where the evidence lives.

  • Media Monitoring

    The sector news that matters to your organisation - read and rated by AI, and delivered as a scheduled digest in your own language.

  • Grants & Tenders

    AI reads the tender pack and pulls out the requirements, deadlines and rules - then helps you draft the response from your own approved content, with you reviewing every step.

  • Stakeholder/Vendor Management

    One current register of the suppliers and partners you depend on - each risk-assessed, re-assessing itself on schedule, and wired straight into your risk register.

  • Requirements Management

    See every requirement you face - across every standard, plus your own contracts and policies - traced to the documents, evidence and processes that satisfy it.

  • Risk Management

    Identify, score, treat and review your risks in one place - with AI to help anyone run a proper assessment, and a defensible trail behind every decision.

  • Training Management

    Assign training, prove it was understood, and hold the competence records an auditor asks for.

  • Document Control

    Draft compliance documents with AI, keep every version under control, and export them beautifully branded - all in one place.

  • Quality Management

    Audits, corrective actions, processes and approvals in one quality system, organised around ISO 9001.

Latest from ComplyTrain

Other standards in Risk management standards and methods

  • NIST AI RMFNIST AI RMF, a framework for managing AI system risk
  • NIST SP 800-30NIST SP 800-30 information security risk assessments
  • NIST SP 800-37NIST SP 800-37 risk management framework for information systems

Compliance work does not have to live in documents and spreadsheets

See ComplyTrain on your own processes in a 30-minute demo, with your quality or compliance lead.