Standards
ISO 31000:2018ISO

Risk management — Guidelines

The common foundation for every risk discipline: principles, framework and process. Its strength is its economy — eight principles, a five-part framework, a six-step process — applying equally to operational, project and strategic risk.

Official text

Who it applies to

  • Risk functions
  • Internal audit
  • Any function formalising a risk assessment

Structuring points

  • Risk is the effect of uncertainty on objectives — it can therefore be positive
  • Identification, analysis and evaluation are three distinct steps
  • The risk management framework is a governance matter, not a methodological one
  • Communication and consultation run through the whole process rather than forming a step

Any type of risk, at any level of the organisation.

Requirements 3