Start a free trial
Menu

Standards · Risk management

Which risk management standard are you being asked for?

ISO 31000 and the IEC 31010 techniques, and what each sector calls the same process: ISO/IEC 27005, ISO 14971, ICH Q9, NIST, COSO, FMEA and HAZOP. Explained in plain words, in one catalogue, with every entry linked to its source.

Overview

One process, many names

Four things to know before the detail. The sector standards differ in vocabulary and in the record they require, not in the process.

  1. ISO 31000 is the process

    Context, identification, analysis, evaluation, treatment, monitoring and review. Guidance, not a certificate: an auditor looks for the process running and its records.

  2. IEC 31010 holds the techniques

    FMEA, HAZOP, bow-tie, fault and event trees, Monte Carlo and FAIR, with a table of which fits which step. The most used ones have method standards of their own.

  3. Your sector names it

    ISO/IEC 27005 for security, ISO 14971 for devices, ICH Q9 for pharma, NIST RMF and COSO for systems and the enterprise, risk-based thinking for ISO 9001 and AQAP 2110.

  4. The register is the evidence

    Every one of them ends in a record: the risk, its owner, the analysis, the treatment, the residual risk and the review date. Search the catalogue below for yours.

WHAT YOUR SECTOR CALLS IT AQAP 2110 · ISO 9001 risk-based thinking, defence ISO/IEC 27005 information security ISO 14971 medical devices ICH Q9 pharmaceutical quality NIST RMF · COSO US federal systems · enterprise ISO 31000: one risk management process, whatever the sector calls it Establish context scope, criteria, appetite Identify what can happen, and how Analyse and evaluate likelihood and consequence Treat avoid, reduce, share, accept Monitor and review record, report, repeat Guidance, not a certificate: nobody is certified against ISO 31000. Auditors look for the process and its records. THE TECHNIQUES (IEC 31010) FMEA / FMECA IEC 60812 · failure modes of a design HAZOP IEC 61882 · deviations in a process Bow-tie · fault and event trees causes, barriers, consequences Quantitative: FAIR · Monte Carlo loss in numbers, not colours A risk register is the record every one of these standards ends in: the risk, its owner, the treatment and when it was last reviewed. Functional safety (IEC 61508) and business continuity (ISO 22301) are the same process pointed at safety and at disruption. ONE PROCESS, MANY NAMES · COMPLYTRAIN BY SKYLEN
One process, many names: the sector standards above all ask for the ISO 31000 process in the middle; the techniques below come from IEC 31010.

Risk management: one process under many names

Every management-system standard on this site asks you to manage risk, and every sector has its own standard for how. ISO 9001 and AQAP 2110 call it risk-based thinking. Information security has ISO/IEC 27005 and the NIST Risk Management Framework. Medical devices have ISO 14971, pharma has ICH Q9, corporate governance has COSO, and the safety disciplines have functional safety and process hazard analysis. They are one process wearing different names, and the standard that describes the process itself is ISO 31000. This page explains that process, the techniques it draws on, what each sector adds, and where the documents come from. The explorer below then finds the ones that apply to you.

ISO 31000: the process everyone shares

ISO 31000, in its 2018 edition, is guidance on managing risk of any kind. It sets out principles, a framework for putting risk management into an organisation's governance, and the process itself: establish the scope, the context and the criteria; identify what can happen and how; analyse likelihood and consequence; evaluate against the criteria; treat the risk by avoiding, reducing, sharing or accepting it; and monitor, review, record and report. It cannot be certified against, deliberately. What an auditor or an inspector looks for is the process running and its records, and every sector standard below is that process with its own vocabulary and its own required outputs. See ISO 31000.

IEC 31010: the techniques

IEC 31010 is the companion catalogue of techniques, around forty of them, with a table of which suit which step. Some elicit views: brainstorming, structured interviews, the Delphi method. Some identify: checklists, hazard and operability studies, structured what-if analysis, scenario analysis. Some analyse: failure modes and effects analysis with or without criticality, fault tree and event tree analysis, bow-tie analysis, Bayesian networks, Markov analysis, Monte Carlo simulation. Some evaluate: as low as reasonably practicable, cost-benefit analysis, risk matrices. The most used ones have method standards of their own. IEC 60812 is the standard for FMEA and FMECA, the technique behind design and process reliability work. IEC 61882 is the standard for HAZOP, the structured team study of deviations in a process design that the chemical and pharmaceutical industries run. IEC 61508 is functional safety, the safety life cycle and the safety integrity levels that the sector standards for machinery, rail, automotive and process plants derive from.

What each sector calls it

In quality management, ISO 9001 asks for risk-based thinking in planning the system and its processes, and AQAP 2110 makes it a requirement: a defence supplier identifies and manages risk across the contract and the customer may ask to see the analysis. In information security, ISO/IEC 27005 describes the assessment and treatment ISO/IEC 27001 requires, NIST SP 800-30 describes an assessment and SP 800-37 the seven-step framework that ties categorisation, control selection, assessment and authorisation together, and FAIR quantifies cyber risk in loss frequency and loss magnitude instead of colours. For medical devices, ISO 14971 runs the process over hazards, hazardous situations and harm, requires risk control and a benefit-risk judgement, and continues through production and post-production; every design decision in the technical file traces back to it. In pharma, ICH Q9 is quality risk management, revised in 2023 to say how formal the process should be and how to keep subjectivity out of it, and its annex lists the same techniques IEC 31010 does. In corporate governance, the COSO framework integrates enterprise risk with strategy and performance and is what a board and an external auditor recognise. Business continuity, ISO 22301, is the same process pointed at disruption, with a business impact analysis in place of the hazard list. And the newest name is AI: ISO/IEC 23894 and the NIST AI Risk Management Framework apply the process to artificial intelligence systems, and the EU AI Act makes a risk management system mandatory for the high-risk ones. See ISO/IEC 27005, and the defence, cybersecurity and pharma and medical device pages for the sector standards themselves.

The register is the evidence

Whatever the sector calls it, the process ends in a record, and the record is what an auditor, an inspector, a notified body or a customer reads. A risk register holds each risk, its owner, the analysis in whatever scale the standard prescribes, the treatment chosen, the residual risk after it, and when it was last reviewed. A medical device's risk management file, an information security risk treatment plan, a defence contract's risk analysis and a pharmaceutical quality risk assessment are the same register with different columns. The review history matters as much as the entries: a register that was written once and never touched shows a process that ran once.

Where the documents come from

ISO 31000, IEC 31010, ISO 14971 and ISO/IEC 27005 are bought from ISO, IEC or your national standards body, and the IEC method standards likewise. Every NIST publication, including SP 800-30, SP 800-37 and the AI Risk Management Framework, is free from NIST. ICH Q9 is free from ICH, the Open FAIR standard from The Open Group with registration, and the COSO framework is bought from COSO. Every entry in the explorer below links to its source.

Who decides what applies to you

Not this page, and not us. The management-system standard you hold names the risk process it expects, the contract names the standard, and the regulation names the file. What the explorer can do is show you the whole map: search it by name, browse it by family, or answer four questions about where your requirement comes from and see which standards and techniques companies like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement, and a risk register is one of the records it keeps.

Standards explorer

Find your risk management standards

Search ISO 31000 and IEC 31010, the method standards, the sector risk standards and the frameworks together, browse them by family, or answer four questions about where your requirement comes from.

29 standards in the catalogue

Not sure where to start?

Four questions, pick everything that applies. Nothing is stored.

Question 1 of 4Where does the requirement come from?
Question 2 of 4What do you need to produce?
Question 3 of 4Which techniques do you use, or have been asked for?
Question 4 of 4What do you have today?
ISO management systems14 standards
  1. EN 9100Quality Management Systems - Requirements for Aviation, Space and Defence OrganizationsEd. 2018How ComplyTrain supports itISO 9001 plus the aerospace and defence supply chain's additional requirements (AS9100 in the Americas).
  2. ISO 10007Quality management - Guidelines for configuration managementEd. 2017Configuration management guidance, the civil counterpart to ACMP-2000 series.
  3. ISO 14001Environmental management systems - Requirements with guidance for useEd. 2015Environmental management: how an organisation controls its environmental impact and obligations.
  4. ISO 19443Quality management systems - Specific requirements for the application of ISO 9001:2015 by organizations in the supply chain of the nuclear energy sector supplying products and services important to nuclear safety (ITNS)Ed. 2018ISO 9001 with the additional requirements of the nuclear supply chain.
  5. ISO 28000Security and resilience - Security management systems - RequirementsEd. 2022Security management across the supply chain.
  6. ISO 37001Anti-bribery management systems - Requirements with guidance for useEd. 2016Anti-bribery controls, often asked for in public procurement and export markets.
  7. ISO 37301Compliance management systems - Requirements with guidance for useEd. 2021A management system for meeting legal and contractual compliance obligations.
  8. ISO 45001Occupational health and safety management systems - Requirements with guidance for useEd. 2018Occupational health and safety management, the successor to OHSAS 18001.
  9. ISO 50001Energy management systems - Requirements with guidance for useEd. 2018Energy management: measuring and improving energy performance.
  10. ISO 55001Asset management - Management systems - RequirementsEd. 2014Managing physical assets over their life cycle.
  11. ISO 9001Quality management systems - RequirementsEd. 2015How ComplyTrain supports itThe general-purpose quality management system standard most defence and industrial contracts start from.
  12. ISO/IEC 17025General requirements for the competence of testing and calibration laboratoriesEd. 2017Competence requirements for test and calibration laboratories.
  13. ISO/IEC 20000-1Information technology - Service management - Part 1: Service management system requirementsEd. 2018IT service management, the certifiable counterpart to ITIL.
  14. ISO/IEC 42001Information technology - Artificial intelligence - Management systemEd. 2023The first management system standard for organisations that build or use AI.
Information security management (ISO/IEC 27000 family)1 standards
  1. ISO/IEC 27005Information security, cybersecurity and privacy protection - Guidance on managing information security risksEd. 2022How ComplyTrain supports itThe risk assessment and treatment that ISO/IEC 27001 requires but does not describe.
ICH guidelines1 standards
  1. ICH Q9ICH Q9(R1): Quality Risk ManagementEd. 2023The pharmaceutical quality risk management process and its tools, revised in 2023 for formality and subjectivity.
Medical devices and health software1 standards
  1. ISO 14971Medical devices - Application of risk management to medical devicesEd. 2019The risk management process every medical device file is built on: hazard identification, estimation, control and residual risk.
Risk management standards and methods12 standards
  1. ISO 22301Security and resilience - Business continuity management systems - RequirementsEd. 2019Business continuity management: keeping the organisation running through disruption.
  2. ISO 31000Risk management - GuidelinesEd. 2018How ComplyTrain supports itPrinciples and a framework for managing risk. Guidance, not a certifiable requirement set.
  3. ISO/IEC 23894Information technology - Artificial intelligence - Guidance on risk managementEd. 2023ISO 31000 applied to AI systems: the sources of risk particular to them and how to manage them across the life cycle.
  4. FAIROpen FAIR Risk Analysis Standard (O-RA)Ed. 2021Factor Analysis of Information Risk: quantifying cyber risk in loss event frequency and magnitude rather than colours.
  5. IEC 31010Risk management - Risk assessment techniquesEd. 2019The catalogue of risk assessment techniques, from brainstorming and checklists to FMEA, HAZOP, bow-tie and Monte Carlo, and when each fits.
  6. IEC 60812Failure modes and effects analysis (FMEA and FMECA)Ed. 2018The method standard for FMEA and FMECA, used in reliability, safety and process risk work.
  7. IEC 61508Functional safety of electrical/electronic/programmable electronic safety-related systemsEd. 2010The umbrella functional safety standard: safety integrity levels and the safety life cycle that sector standards derive from.
  8. IEC 61882Hazard and operability studies (HAZOP studies) - Application guideEd. 2016The structured team study that finds deviations in a process design and their consequences.
  9. NIST AI RMFArtificial Intelligence Risk Management Framework (AI RMF 1.0)Ed. 2023Four functions, Govern, Map, Measure and Manage, for the risks of AI systems, voluntary and sector-neutral.
  10. NIST SP 800-30Guide for Conducting Risk Assessments (Rev. 1)Ed. 2012How to run an information security risk assessment: threat sources, events, vulnerabilities, likelihood and impact.
  11. NIST SP 800-37Risk Management Framework for Information Systems and Organizations (Rev. 2)Ed. 2018The seven-step framework, Prepare to Monitor, that ties categorisation, control selection, assessment and authorisation together.
  12. COSO ERMEnterprise Risk Management - Integrating with Strategy and PerformanceEd. 2017The enterprise risk management framework used in corporate governance and financial reporting.

Titles belong to their publishers. The one-line summaries are ours.

Request access to work with this standard in ComplyTrain

Shortlist

Risk standards with their own page

Each page sets out what the standard asks of you and how a ComplyTrain workspace is organised around it. The catalogue above holds far more than these, and any entry in it can be requested. Adding a standard to a workspace is usually a matter of days, not a project.

  • ISO 31000

    ISO 31000 risk management

    ISO 31000 is the international guidance for managing risk. ComplyTrain’s risk management is structured around its process, so risk is a living framework across the organisation, not a spreadsheet reviewed once a year.

  • ISO 27005

    ISO 27005 information security risk management

    ISO 27005 is the guidance for managing information security risk - the assessment and treatment that ISO 27001 requires but does not describe. ComplyTrain runs it as a living register, not an annual document.

If you need to get there and have no quality function

A standard usually arrives as a contract condition or a regulator's letter rather than a project anyone planned for, and often at a company with no quality manager. Software is half the answer. Skylen's consultants are the other half, and because they build on ComplyTrain from day one you keep a live system your team owns rather than a binder and a departed consultant.

  • Gap assessment

    A clause-by-clause read of where you stand against the standard your contract or your regulator cites, turned into a prioritised plan you could act on with us or alone.

    What an assessment covers
  • Guided implementation

    Our consultants build the system with your team - procedures, document control, the records you need to keep and the review cadence - and prepare you for the audit or the inspection.

    How an engagement works
  • Full-service quality function

    We run and maintain the system for you, so a small team can reach and hold a standard without hiring a quality manager.

    What full-service means

Questions people ask about risk management standards

Can we be certified against ISO 31000?

No. ISO 31000 is guidance, written so that it cannot be used for certification, and a certificate that claims otherwise is not worth the paper. What is certified is the management system that uses the process, ISO 9001, ISO/IEC 27001 or ISO 13485, and the auditor checks that the risk process the system requires is running and recorded. See ISO 31000.

Do we need one risk register or several?

One process, and as many views of it as your standards require. A company that holds ISO 9001 and ISO/IEC 27001 and makes a medical device has quality risks, information security risks and a device risk management file, each with the columns its standard prescribes, and an auditor for one will not want to read the others. Keeping them in one system with one method and one review cadence is what makes that manageable.

Which technique should we use?

The one that fits the question and that your standard or your customer expects. FMEA is for the failure modes of a design or a process and is what a reliability engineer or a device notified body expects to see. HAZOP is for deviations in a process design and is standard in chemical and pharmaceutical plants. Bow-tie is for showing barriers between causes and consequences and reads well for management. Quantitative methods such as FAIR and Monte Carlo are for when a number is needed, in cyber risk and in finance. IEC 31010 has the full table.

What is the difference between a hazard and a risk?

A hazard is a source of potential harm; a risk is the combination of how likely the harm is and how severe. ISO 14971 adds a third term, the hazardous situation, the circumstance in which people are exposed to the hazard, and asks you to estimate the risk of each one. Most of the vocabulary differences between sector standards are of this kind: the same process, with the steps named more or less finely.

Does ComplyTrain certify us against a standard?

No. Certification is issued by an accredited certification body, a licence by your authority, and government quality assurance is exercised by the acquisition authority. ComplyTrain is the system you build, run and evidence your compliance in, and Skylen's consultants can take you through the work. The certificate stays yours to earn.

Can I get a standard added to ComplyTrain?

Yes, and that is what the Request access button on every entry is for. Tell us which standard and where the requirement comes from, and we come back to you on what holding it in your workspace involves, usually within one business day. Adding a standard to a workspace is usually a matter of days, not a project. ComplyTrain holds a standard as a requirement tree with your evidence against each requirement, and the tree is what we build.

Request access to work with a standard or a method

Name the standard or the technique and where the requirement comes from, and we come back to you on what holding it in your workspace involves.

See a risk register in ComplyTrain

Book a 30-minute demo with your quality, security or compliance lead - the product organised around the standard you answer to, with the register inside it.