Risk management: one process under many names
Every management-system standard on this site asks you to manage risk, and every sector has its own standard for how. ISO 9001 and AQAP 2110 call it risk-based thinking. Information security has ISO/IEC 27005 and the NIST Risk Management Framework. Medical devices have ISO 14971, pharma has ICH Q9, corporate governance has COSO, and the safety disciplines have functional safety and process hazard analysis. They are one process wearing different names, and the standard that describes the process itself is ISO 31000. This page explains that process, the techniques it draws on, what each sector adds, and where the documents come from. The explorer below then finds the ones that apply to you.
ISO 31000: the process everyone shares
ISO 31000, in its 2018 edition, is guidance on managing risk of any kind. It sets out principles, a framework for putting risk management into an organisation's governance, and the process itself: establish the scope, the context and the criteria; identify what can happen and how; analyse likelihood and consequence; evaluate against the criteria; treat the risk by avoiding, reducing, sharing or accepting it; and monitor, review, record and report. It cannot be certified against, deliberately. What an auditor or an inspector looks for is the process running and its records, and every sector standard below is that process with its own vocabulary and its own required outputs. See ISO 31000.
IEC 31010: the techniques
IEC 31010 is the companion catalogue of techniques, around forty of them, with a table of which suit which step. Some elicit views: brainstorming, structured interviews, the Delphi method. Some identify: checklists, hazard and operability studies, structured what-if analysis, scenario analysis. Some analyse: failure modes and effects analysis with or without criticality, fault tree and event tree analysis, bow-tie analysis, Bayesian networks, Markov analysis, Monte Carlo simulation. Some evaluate: as low as reasonably practicable, cost-benefit analysis, risk matrices. The most used ones have method standards of their own. IEC 60812 is the standard for FMEA and FMECA, the technique behind design and process reliability work. IEC 61882 is the standard for HAZOP, the structured team study of deviations in a process design that the chemical and pharmaceutical industries run. IEC 61508 is functional safety, the safety life cycle and the safety integrity levels that the sector standards for machinery, rail, automotive and process plants derive from.
What each sector calls it
In quality management, ISO 9001 asks for risk-based thinking in planning the system and its processes, and AQAP 2110 makes it a requirement: a defence supplier identifies and manages risk across the contract and the customer may ask to see the analysis. In information security, ISO/IEC 27005 describes the assessment and treatment ISO/IEC 27001 requires, NIST SP 800-30 describes an assessment and SP 800-37 the seven-step framework that ties categorisation, control selection, assessment and authorisation together, and FAIR quantifies cyber risk in loss frequency and loss magnitude instead of colours. For medical devices, ISO 14971 runs the process over hazards, hazardous situations and harm, requires risk control and a benefit-risk judgement, and continues through production and post-production; every design decision in the technical file traces back to it. In pharma, ICH Q9 is quality risk management, revised in 2023 to say how formal the process should be and how to keep subjectivity out of it, and its annex lists the same techniques IEC 31010 does. In corporate governance, the COSO framework integrates enterprise risk with strategy and performance and is what a board and an external auditor recognise. Business continuity, ISO 22301, is the same process pointed at disruption, with a business impact analysis in place of the hazard list. And the newest name is AI: ISO/IEC 23894 and the NIST AI Risk Management Framework apply the process to artificial intelligence systems, and the EU AI Act makes a risk management system mandatory for the high-risk ones. See ISO/IEC 27005, and the defence, cybersecurity and pharma and medical device pages for the sector standards themselves.
The register is the evidence
Whatever the sector calls it, the process ends in a record, and the record is what an auditor, an inspector, a notified body or a customer reads. A risk register holds each risk, its owner, the analysis in whatever scale the standard prescribes, the treatment chosen, the residual risk after it, and when it was last reviewed. A medical device's risk management file, an information security risk treatment plan, a defence contract's risk analysis and a pharmaceutical quality risk assessment are the same register with different columns. The review history matters as much as the entries: a register that was written once and never touched shows a process that ran once.
Where the documents come from
ISO 31000, IEC 31010, ISO 14971 and ISO/IEC 27005 are bought from ISO, IEC or your national standards body, and the IEC method standards likewise. Every NIST publication, including SP 800-30, SP 800-37 and the AI Risk Management Framework, is free from NIST. ICH Q9 is free from ICH, the Open FAIR standard from The Open Group with registration, and the COSO framework is bought from COSO. Every entry in the explorer below links to its source.
Who decides what applies to you
Not this page, and not us. The management-system standard you hold names the risk process it expects, the contract names the standard, and the regulation names the file. What the explorer can do is show you the whole map: search it by name, browse it by family, or answer four questions about where your requirement comes from and see which standards and techniques companies like you are commonly asked about. Each entry links to its source, to its ComplyTrain page where one exists, and otherwise to a request. ComplyTrain holds a standard as a requirement tree with the evidence against each requirement, and a risk register is one of the records it keeps.