| ISO 31000: Key Takeaways |
|---|
| ISO 31000:2018 is the current international risk management standard: eight principles, a leadership framework, and a six-step process in sixteen pages. |
| Organizations cannot be certified against ISO 31000. ISO itself says the standard holds guidelines, not auditable requirements; individual credentials do exist. |
| Only 35% of 273 US organizations run complete ERM processes, and just 11% get strategic advantage from risk management (NC State/AICPA, 2025). |
| The US adopted the standard verbatim as ANSI/ASSP/ISO 31000-2018; COSO ERM 2017 remains the governance-facing framework most US boards know. |
| A third edition of ISO 31000 is coming: committee draft registered December 19, 2025, comments closed March 1, 2026, publication unlikely before late 2027. |
| A mid-size company can reach a working register, tested criteria, and a first board risk report in 90 days with one deliverable per month. |
ISO 31000 is the international risk management standard published by the International Organization for Standardization, last revised in 2018. It gives any organization eight principles, a leadership framework, and a six-step process for identifying, analyzing, evaluating, and treating risk. It is a guidance document: no company can be certified against it.
Only 35% of the 273 US organizations surveyed by the NC State ERM Initiative and AICPA in Spring 2025 run complete enterprise risk management processes, according to the 16th State of Risk Oversight report. Just 11% say risk management gives them a real strategic advantage.
Professor Mark Beasley’s team at NC State has tracked that maturity gap for sixteen years, and the needle barely moves. We meet the same pattern in advisory work: leaders want structured risk oversight and stall at the starting line. ISO 31000 was written for exactly that moment.
What ISO 31000 Actually Covers, and What It Does Not
ISO 31000:2018, formally titled Risk management Guidelines, is a sixteen-page document that defines risk as the effect of uncertainty on objectives. That definition includes upside as well as downside, which is why the standard keeps returning to the creation and protection of value.
The United States adopted the text word for word as ANSI/ASSP/ISO 31000-2018, with the American Society of Safety Professionals acting as secretariat. RIMS, the US risk management society, publicly urged every national standards body to adopt the 2018 edition the year it appeared.
The boundary matters just as much: ISO states plainly that ISO 31000 provides guidelines rather than auditable requirements, so no accredited body can certify an organization against it. Any vendor selling company-level ISO 31000 certification is selling paper that ISO itself says does not exist.
| Part of ISO 31000:2018 | What it gives you | Role |
|---|---|---|
| Eight principles (clause 4) | The character of effective risk management: integrated, structured, customized, inclusive, dynamic, evidence-based, human-aware, improving | Design brief |
| Framework (clause 5) | Leadership and commitment driving a Plan-Do-Check-Act loop: integration, design, implementation, evaluation, improvement | Governance layer |
| Process (clause 6) | Scope and criteria, risk assessment, treatment, recording and reporting, with communication and monitoring running throughout | Operating layer |

Because it is guidance, sector programs adapt it freely. The US Army folded its old composite risk management doctrine into plain risk management aligned with this shape, and specialized standards from supply chain security to business continuity borrow its vocabulary today.
Why the Standard Matters: The US Risk Oversight Gap
A guidance document with no certificate attached still deserves attention because the maturity data says most programs need one. Beyond the 35% figure, only 32% of NC State’s respondents rate their risk oversight as mature, and 64% see minimal or no competitive advantage from their current process.

PwC’s 2025 Global Digital Trust Insights survey shows what that gap costs in one domain. Sixty-six percent of executives rank cyber as a top business concern, yet only 2% have implemented resilience across the whole firm, while the average data breach now runs past $3 million.

The symptoms of risk work without a standard behind it repeat across companies and sectors, and they are recognizable within one meeting. Watch for these signals in your own organization before deciding your current approach is good enough for the next board cycle:
A risk register that lives in one analyst’s spreadsheet and has not changed since the last audit
Risk conversations that happen once a year, on the audit calendar, far from live decisions
No written risk appetite, so every escalation argument starts from zero
Key risk indicators that nobody reviews between quarterly reporting cycles
The Eight Principles and the 2018 Redesign
Those symptoms are what the 2018 revision was engineered against. ISO’s technical committee TC 262 cut the 2009 edition’s eleven principles to eight, moved value creation and protection to the center of the model, and trimmed the whole standard to a document a board member can actually read.
| What changed | 2009 edition | 2018 edition |
|---|---|---|
| Principles | Eleven, listed as attributes | Eight, anchored on value creation and protection |
| Center of the framework | Management commitment | Leadership and commitment at board level |
| Tone | Process manual | Design brief for risk-aware decision making |
| Risk definition in use | Threat-leaning practice | Effect of uncertainty on objectives, upside included |
| Length and readability | Longer, more clauses | Sixteen pages, plain language |
The eight principles read as short phrases in the standard, and each one carries a practical test. The table below is the version we use in workshops when a leadership team asks what adopting the standard would change about Monday morning.
| Principle | What it demands in practice |
|---|---|
| Integrated | Risk analysis inside planning, budgeting, and change decisions, never a parallel exercise |
| Structured and comprehensive | One method and one risk language across departments |
| Customized | Criteria sized to your objectives and context, never copied from a template |
| Inclusive | Stakeholders help identify and evaluate the risks that touch them |
| Dynamic | The register moves when the business or the environment moves |
| Best available information | Assessments name their data sources and their blind spots |
| Human and cultural factors | Incentives, workload, and culture appear in the analysis |
| Continual improvement | The framework itself gets evaluated and redesigned on a schedule |
Two of the eight do the heaviest lifting. Integration kills the standalone risk silo, and the human factors principle forces honest conversations about incentives. In our reviews, that is where ERM dashboards and key risk indicator sets usually show their first gaps.
How to Run the ISO 31000 Risk Management Process
Principles set expectations; the process turns them into work. Clause 6 walks through six connected activities, and the risk management process it describes maps cleanly onto what a risk assessment already does in most organizations, which makes adoption less disruptive than teams fear.
| Step | What happens | Evidence it happened |
|---|---|---|
| Communication and consultation | Stakeholders shape criteria and share intelligence throughout | Meeting record naming who was consulted |
| Scope, context, criteria | Define what is assessed and how much risk is acceptable | Written criteria tied to risk appetite |
| Risk assessment | Identify, analyze, and evaluate risks against the criteria | A prioritized, owned risk register |
| Risk treatment | Select and implement options that change likelihood or consequence | Treatment plan with owners and dates |
| Monitoring and review | Track risks, treatments, and the process itself | KRI dashboard and review calendar |
| Recording and reporting | Document results for decision makers and oversight bodies | Board risk report |
Treatment is where new programs most often go vague, so the standard names seven distinct options in place of a generic mitigate. A written treatment plan should state which of the seven it is applying to each priority risk, and why:
Avoid the risk by not starting or continuing the activity
Take or increase the risk to pursue an opportunity
Remove the risk source
Change the likelihood
Change the consequences
Share the risk through contracts or insurance
Retain the risk by informed decision
Register quality decides whether any of this sticks. Build yours around the key elements of a risk register, score entries against criteria drawn from sector-matched risk appetite statements, and use a full register template so treatment owners and review dates never go missing.
ISO 31000 vs COSO ERM and the Wider Standards Family
The first question US practitioners ask is how this differs from COSO. Our full ISO 31000 vs COSO ERM comparison covers the detail; the short version is that COSO’s 2017 framework speaks the language of boards and auditors while ISO 31000 speaks to anyone who runs operations.
| Dimension | ISO 31000:2018 | COSO ERM 2017 |
|---|---|---|
| Publisher | ISO technical committee TC 262 | COSO, five US professional bodies |
| Structure | 8 principles, framework, process | 5 components, 20 principles |
| Length | 16 pages | Over 100 pages |
| Certifiable | No, guidance only | No, framework only |
| Natural audience | Operations, any sector or size | Boards, audit committees, US filers |
| Strategy link | Risk inside every decision | Strategy-setting explicitly central |
COSO’s five components and twenty principles reward organizations that already publish audited financials, and the two frameworks combine well in practice. Cyber teams usually add a control catalog on top, which is where the NIST Cybersecurity Framework enters most US programs.
| Standard | Published | What it adds to ISO 31000 |
|---|---|---|
| IEC 31010 | 2019 | A toolbox of risk assessment techniques, from bow-tie analysis to Monte Carlo simulation |
| ISO 31073 | 2022 | The shared vocabulary for risk management terms |
| ISO 31022 | 2020 | Guidance for legal risk management |
| ISO 31030 | 2021 | Travel risk management for workforces abroad |
| ANSI/ASSP Z310.1 | 2026 | US-developed risk assessment and management standard for laboratory environments |
Technique selection has its own companion standard, IEC 31010:2019, and the terminology lives in ISO 31073:2022. Where management systems already exist, ISO 22301 continuity programs, ISO 28000 supply chain security, and third-party risk frameworks reference the same vocabulary, so an ISO 31000 process becomes connective tissue instead of another silo. Delivery organizations add PMI’s standard for risk management in portfolios, programs, and projects for the project tiers.
Getting Started: A 90-Day Implementation Plan
Standing the process up does not require a consulting army; it requires sequence. Ninety days is enough for a mid-size US company to reach a working register, tested criteria, and a first board report, provided each month has one job and one deliverable.
| Phase | Focus | Deliverable |
|---|---|---|
| Days 1-30 | Mandate, scope, context, criteria | Board-approved charter and draft risk criteria |
| Days 31-60 | Identification and analysis workshops | Prioritized risk register with named owners |
| Days 61-90 | Treatment, reporting, first review | Treatment plans plus the first board risk report |
The first thirty days decide the program’s credibility, and five moves carry most of the weight there. Do these before any software decision and before anyone builds a heat map, because each one removes an argument that will otherwise resurface in month three:
Name an executive sponsor and put risk on the leadership agenda
Write scope in one page: which objectives, units, and decisions are covered
Draft risk criteria against a stated appetite before any workshop
Inventory what already exists: registers, audits, insurance schedules, incident logs
Book the identification workshops now, with attendee names, not job titles
One budgeting note from our own practice: organizations cannot certify to the standard, but individuals can earn credentials such as ISO 31000 Lead Risk Manager. PwC’s 2025 Global Compliance Survey shows compliance loads growing, which argues for building that expertise in-house early.
Tooling comes last for a reason. A spreadsheet register survives the first two quarters; once volume grows, evaluate platforms on our enterprise risk management software shortlist and confirm any GRC suite maps its fields to the six process steps described above before you sign.
Seven Traps That Derail New Risk Programs
Sixteen years of NC State survey data plus our own reviews point to the same short list of program killers. None of them is exotic, and every one shows up in month two or three wearing the costume of good intentions.
| Trap | Why it happens | Fix |
|---|---|---|
| Certification shopping | Vendor marketing implies a company certificate exists | Redirect the budget to training and criteria design |
| Copy-pasted risk criteria | Templates feel faster than context analysis | Derive criteria from your objectives and appetite |
| Register as archive | Register built for auditors, then abandoned | Review dates and owners on every entry |
| Annual-only assessment | Risk work timed to the audit cycle | Trigger reassessment on change events |
| Heat map worship | Color grids substitute for analysis | Record assumptions and data sources per risk |
| Silo framework | The risk team owns everything | Push identification into line functions |
| No treatment follow-through | Plans stop at a generic mitigate | Seven named options, owners, and dates |
The ISO 31000 Questions Boards and Executives Keep Asking
Is ISO 31000 certifiable for organizations?
No: ISO 31000 is a guidance standard containing recommendations, and ISO itself states it is not intended for certification. Accredited certification exists for requirements standards such as ISO 9001 or ISO/IEC 27001. Individuals, though, can earn ISO 31000 training credentials such as lead risk manager designations.
What are the three parts of ISO 31000?
ISO 31000:2018 is built from eight principles, a framework, and a process. The principles define what good risk management looks like, the framework embeds it in governance through leadership and continual improvement, and the process runs assessment, treatment, monitoring, and reporting day to day.
What is the current version of ISO 31000?
ISO 31000:2018 is the current edition, published in February 2018 as a sixteen-page revision of the 2009 original. The United States adopted it unchanged as ANSI/ASSP/ISO 31000-2018. A third edition is in development, with a committee draft registered in December 2025.
When will ISO 31000 be updated next?
ISO approved the revision project in October 2024, and the committee draft consultation closed on March 1, 2026. Standards typically take two to four years from committee draft to publication, so a new ISO 31000 edition before late 2027 is unlikely. Adopt the 2018 edition now.
How does ISO 31000 compare with COSO ERM?
ISO 31000 is shorter, sector-neutral, and built for any organization; COSO ERM 2017 runs five components and twenty principles aimed at boards, audit committees, and US public filers. Many US programs use both: COSO for governance reporting language, ISO 31000 for the operating process.
What is the difference between ISO 31000 and IEC 31010?
ISO 31000 sets the principles, framework, and process; IEC 31010:2019 is its companion toolbox, describing dozens of assessment techniques from bow-tie analysis to Monte Carlo simulation. Use 31000 to design the program and 31010 to choose the technique that fits each risk.
How long does ISO 31000 implementation take?
A focused mid-size organization can stand up a working ISO 31000 process in about ninety days: mandate and criteria in month one, register and analysis in month two, treatment plans and board reporting in month three. Full cultural integration is a multi-year effort measured by the NC State maturity markers.
Looking Ahead: The Next Edition and Your First Move
The standard is mid-revision as we write. ISO technical committee TC 262 registered the committee draft of the third edition on December 19, 2025, closed comments on March 1, 2026, and now works through them; the project record is public on the ISO site.

Waiting for the third edition would be the wrong lesson from that timeline. Committee drafts change substantially before publication, ISO revisions preserve their predecessor’s architecture far more often than they break it, and a program built on the 2018 edition will migrate with light edits when the new text lands. The public project record suggests no structural rebuild.
Expect the pressure on US organizations to keep rising in the meantime. Sixteen consecutive NC State surveys show boards asking more risk questions each year, and AICPA’s 2025 release put the strategic-advantage figure at 11%, a number no competitor wants printed about them.
If you own this problem for a US company, whether as COO, CFO, or a newly named head of risk, the fastest route is a ninety-day build with an experienced guide. See how our services fit that build and contact us to scope a first register and board report you can defend.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.