What Is ISO 31000?

Photo of author
Written By Chris Ekai
ISO 31000: Key Takeaways
ISO 31000:2018 is the current international risk management standard: eight principles, a leadership framework, and a six-step process in sixteen pages.
Organizations cannot be certified against ISO 31000. ISO itself says the standard holds guidelines, not auditable requirements; individual credentials do exist.
Only 35% of 273 US organizations run complete ERM processes, and just 11% get strategic advantage from risk management (NC State/AICPA, 2025).
The US adopted the standard verbatim as ANSI/ASSP/ISO 31000-2018; COSO ERM 2017 remains the governance-facing framework most US boards know.
A third edition of ISO 31000 is coming: committee draft registered December 19, 2025, comments closed March 1, 2026, publication unlikely before late 2027.
A mid-size company can reach a working register, tested criteria, and a first board risk report in 90 days with one deliverable per month.

ISO 31000 is the international risk management standard published by the International Organization for Standardization, last revised in 2018. It gives any organization eight principles, a leadership framework, and a six-step process for identifying, analyzing, evaluating, and treating risk. It is a guidance document: no company can be certified against it.

Only 35% of the 273 US organizations surveyed by the NC State ERM Initiative and AICPA in Spring 2025 run complete enterprise risk management processes, according to the 16th State of Risk Oversight report. Just 11% say risk management gives them a real strategic advantage.

Professor Mark Beasley’s team at NC State has tracked that maturity gap for sixteen years, and the needle barely moves. We meet the same pattern in advisory work: leaders want structured risk oversight and stall at the starting line. ISO 31000 was written for exactly that moment.

What ISO 31000 Actually Covers, and What It Does Not

ISO 31000:2018, formally titled Risk management Guidelines, is a sixteen-page document that defines risk as the effect of uncertainty on objectives. That definition includes upside as well as downside, which is why the standard keeps returning to the creation and protection of value.

The United States adopted the text word for word as ANSI/ASSP/ISO 31000-2018, with the American Society of Safety Professionals acting as secretariat. RIMS, the US risk management society, publicly urged every national standards body to adopt the 2018 edition the year it appeared.

The boundary matters just as much: ISO states plainly that ISO 31000 provides guidelines rather than auditable requirements, so no accredited body can certify an organization against it. Any vendor selling company-level ISO 31000 certification is selling paper that ISO itself says does not exist.

Part of ISO 31000:2018What it gives youRole
Eight principles (clause 4)The character of effective risk management: integrated, structured, customized, inclusive, dynamic, evidence-based, human-aware, improvingDesign brief
Framework (clause 5)Leadership and commitment driving a Plan-Do-Check-Act loop: integration, design, implementation, evaluation, improvementGovernance layer
Process (clause 6)Scope and criteria, risk assessment, treatment, recording and reporting, with communication and monitoring running throughoutOperating layer
ISO 31000 principles framework and process architecture diagram
Figure 1. ISO 31000:2018 in one view: principles shape a framework that runs a repeatable process.

Because it is guidance, sector programs adapt it freely. The US Army folded its old composite risk management doctrine into plain risk management aligned with this shape, and specialized standards from supply chain security to business continuity borrow its vocabulary today.

Why the Standard Matters: The US Risk Oversight Gap

A guidance document with no certificate attached still deserves attention because the maturity data says most programs need one. Beyond the 35% figure, only 32% of NC State’s respondents rate their risk oversight as mature, and 64% see minimal or no competitive advantage from their current process.

US risk oversight gap statistics that ISO 31000 adoption addresses
Figure 2. Three numbers from the 2025 State of Risk Oversight survey of 273 US organizations.

PwC’s 2025 Global Digital Trust Insights survey shows what that gap costs in one domain. Sixty-six percent of executives rank cyber as a top business concern, yet only 2% have implemented resilience across the whole firm, while the average data breach now runs past $3 million.

PwC 2025 statistics on cyber risk awareness versus implemented resilience
Figure 3. PwC’s 2025 findings: awareness of risk runs high while structured resilience stays rare.

The symptoms of risk work without a standard behind it repeat across companies and sectors, and they are recognizable within one meeting. Watch for these signals in your own organization before deciding your current approach is good enough for the next board cycle:

A risk register that lives in one analyst’s spreadsheet and has not changed since the last audit

Risk conversations that happen once a year, on the audit calendar, far from live decisions

No written risk appetite, so every escalation argument starts from zero

Key risk indicators that nobody reviews between quarterly reporting cycles

The Eight Principles and the 2018 Redesign

Those symptoms are what the 2018 revision was engineered against. ISO’s technical committee TC 262 cut the 2009 edition’s eleven principles to eight, moved value creation and protection to the center of the model, and trimmed the whole standard to a document a board member can actually read.

What changed2009 edition2018 edition
PrinciplesEleven, listed as attributesEight, anchored on value creation and protection
Center of the frameworkManagement commitmentLeadership and commitment at board level
ToneProcess manualDesign brief for risk-aware decision making
Risk definition in useThreat-leaning practiceEffect of uncertainty on objectives, upside included
Length and readabilityLonger, more clausesSixteen pages, plain language

The eight principles read as short phrases in the standard, and each one carries a practical test. The table below is the version we use in workshops when a leadership team asks what adopting the standard would change about Monday morning.

PrincipleWhat it demands in practice
IntegratedRisk analysis inside planning, budgeting, and change decisions, never a parallel exercise
Structured and comprehensiveOne method and one risk language across departments
CustomizedCriteria sized to your objectives and context, never copied from a template
InclusiveStakeholders help identify and evaluate the risks that touch them
DynamicThe register moves when the business or the environment moves
Best available informationAssessments name their data sources and their blind spots
Human and cultural factorsIncentives, workload, and culture appear in the analysis
Continual improvementThe framework itself gets evaluated and redesigned on a schedule

Two of the eight do the heaviest lifting. Integration kills the standalone risk silo, and the human factors principle forces honest conversations about incentives. In our reviews, that is where ERM dashboards and key risk indicator sets usually show their first gaps.

How to Run the ISO 31000 Risk Management Process

Principles set expectations; the process turns them into work. Clause 6 walks through six connected activities, and the risk management process it describes maps cleanly onto what a risk assessment already does in most organizations, which makes adoption less disruptive than teams fear.

StepWhat happensEvidence it happened
Communication and consultationStakeholders shape criteria and share intelligence throughoutMeeting record naming who was consulted
Scope, context, criteriaDefine what is assessed and how much risk is acceptableWritten criteria tied to risk appetite
Risk assessmentIdentify, analyze, and evaluate risks against the criteriaA prioritized, owned risk register
Risk treatmentSelect and implement options that change likelihood or consequenceTreatment plan with owners and dates
Monitoring and reviewTrack risks, treatments, and the process itselfKRI dashboard and review calendar
Recording and reportingDocument results for decision makers and oversight bodiesBoard risk report

Treatment is where new programs most often go vague, so the standard names seven distinct options in place of a generic mitigate. A written treatment plan should state which of the seven it is applying to each priority risk, and why:

Avoid the risk by not starting or continuing the activity

Take or increase the risk to pursue an opportunity

Remove the risk source

Change the likelihood

Change the consequences

Share the risk through contracts or insurance

Retain the risk by informed decision

Register quality decides whether any of this sticks. Build yours around the key elements of a risk register, score entries against criteria drawn from sector-matched risk appetite statements, and use a full register template so treatment owners and review dates never go missing.

ISO 31000 vs COSO ERM and the Wider Standards Family

The first question US practitioners ask is how this differs from COSO. Our full ISO 31000 vs COSO ERM comparison covers the detail; the short version is that COSO’s 2017 framework speaks the language of boards and auditors while ISO 31000 speaks to anyone who runs operations.

DimensionISO 31000:2018COSO ERM 2017
PublisherISO technical committee TC 262COSO, five US professional bodies
Structure8 principles, framework, process5 components, 20 principles
Length16 pagesOver 100 pages
CertifiableNo, guidance onlyNo, framework only
Natural audienceOperations, any sector or sizeBoards, audit committees, US filers
Strategy linkRisk inside every decisionStrategy-setting explicitly central

COSO’s five components and twenty principles reward organizations that already publish audited financials, and the two frameworks combine well in practice. Cyber teams usually add a control catalog on top, which is where the NIST Cybersecurity Framework enters most US programs.

StandardPublishedWhat it adds to ISO 31000
IEC 310102019A toolbox of risk assessment techniques, from bow-tie analysis to Monte Carlo simulation
ISO 310732022The shared vocabulary for risk management terms
ISO 310222020Guidance for legal risk management
ISO 310302021Travel risk management for workforces abroad
ANSI/ASSP Z310.12026US-developed risk assessment and management standard for laboratory environments

Technique selection has its own companion standard, IEC 31010:2019, and the terminology lives in ISO 31073:2022. Where management systems already exist, ISO 22301 continuity programs, ISO 28000 supply chain security, and third-party risk frameworks reference the same vocabulary, so an ISO 31000 process becomes connective tissue instead of another silo. Delivery organizations add PMI’s standard for risk management in portfolios, programs, and projects for the project tiers.

Getting Started: A 90-Day Implementation Plan

Standing the process up does not require a consulting army; it requires sequence. Ninety days is enough for a mid-size US company to reach a working register, tested criteria, and a first board report, provided each month has one job and one deliverable.

PhaseFocusDeliverable
Days 1-30Mandate, scope, context, criteriaBoard-approved charter and draft risk criteria
Days 31-60Identification and analysis workshopsPrioritized risk register with named owners
Days 61-90Treatment, reporting, first reviewTreatment plans plus the first board risk report

The first thirty days decide the program’s credibility, and five moves carry most of the weight there. Do these before any software decision and before anyone builds a heat map, because each one removes an argument that will otherwise resurface in month three:

Name an executive sponsor and put risk on the leadership agenda

Write scope in one page: which objectives, units, and decisions are covered

Draft risk criteria against a stated appetite before any workshop

Inventory what already exists: registers, audits, insurance schedules, incident logs

Book the identification workshops now, with attendee names, not job titles

One budgeting note from our own practice: organizations cannot certify to the standard, but individuals can earn credentials such as ISO 31000 Lead Risk Manager. PwC’s 2025 Global Compliance Survey shows compliance loads growing, which argues for building that expertise in-house early.

Tooling comes last for a reason. A spreadsheet register survives the first two quarters; once volume grows, evaluate platforms on our enterprise risk management software shortlist and confirm any GRC suite maps its fields to the six process steps described above before you sign.

Seven Traps That Derail New Risk Programs

Sixteen years of NC State survey data plus our own reviews point to the same short list of program killers. None of them is exotic, and every one shows up in month two or three wearing the costume of good intentions.

TrapWhy it happensFix
Certification shoppingVendor marketing implies a company certificate existsRedirect the budget to training and criteria design
Copy-pasted risk criteriaTemplates feel faster than context analysisDerive criteria from your objectives and appetite
Register as archiveRegister built for auditors, then abandonedReview dates and owners on every entry
Annual-only assessmentRisk work timed to the audit cycleTrigger reassessment on change events
Heat map worshipColor grids substitute for analysisRecord assumptions and data sources per risk
Silo frameworkThe risk team owns everythingPush identification into line functions
No treatment follow-throughPlans stop at a generic mitigateSeven named options, owners, and dates

The ISO 31000 Questions Boards and Executives Keep Asking

Is ISO 31000 certifiable for organizations?

No: ISO 31000 is a guidance standard containing recommendations, and ISO itself states it is not intended for certification. Accredited certification exists for requirements standards such as ISO 9001 or ISO/IEC 27001. Individuals, though, can earn ISO 31000 training credentials such as lead risk manager designations.

What are the three parts of ISO 31000?

ISO 31000:2018 is built from eight principles, a framework, and a process. The principles define what good risk management looks like, the framework embeds it in governance through leadership and continual improvement, and the process runs assessment, treatment, monitoring, and reporting day to day.

What is the current version of ISO 31000?

ISO 31000:2018 is the current edition, published in February 2018 as a sixteen-page revision of the 2009 original. The United States adopted it unchanged as ANSI/ASSP/ISO 31000-2018. A third edition is in development, with a committee draft registered in December 2025.

When will ISO 31000 be updated next?

ISO approved the revision project in October 2024, and the committee draft consultation closed on March 1, 2026. Standards typically take two to four years from committee draft to publication, so a new ISO 31000 edition before late 2027 is unlikely. Adopt the 2018 edition now.

How does ISO 31000 compare with COSO ERM?

ISO 31000 is shorter, sector-neutral, and built for any organization; COSO ERM 2017 runs five components and twenty principles aimed at boards, audit committees, and US public filers. Many US programs use both: COSO for governance reporting language, ISO 31000 for the operating process.

What is the difference between ISO 31000 and IEC 31010?

ISO 31000 sets the principles, framework, and process; IEC 31010:2019 is its companion toolbox, describing dozens of assessment techniques from bow-tie analysis to Monte Carlo simulation. Use 31000 to design the program and 31010 to choose the technique that fits each risk.

How long does ISO 31000 implementation take?

A focused mid-size organization can stand up a working ISO 31000 process in about ninety days: mandate and criteria in month one, register and analysis in month two, treatment plans and board reporting in month three. Full cultural integration is a multi-year effort measured by the NC State maturity markers.

Looking Ahead: The Next Edition and Your First Move

The standard is mid-revision as we write. ISO technical committee TC 262 registered the committee draft of the third edition on December 19, 2025, closed comments on March 1, 2026, and now works through them; the project record is public on the ISO site.

Timeline of ISO 31000 editions from 2009 to the revision in progress
Figure 4. Sixteen years between editions: where the third edition of ISO 31000 stands in August 2026.

Waiting for the third edition would be the wrong lesson from that timeline. Committee drafts change substantially before publication, ISO revisions preserve their predecessor’s architecture far more often than they break it, and a program built on the 2018 edition will migrate with light edits when the new text lands. The public project record suggests no structural rebuild.

Expect the pressure on US organizations to keep rising in the meantime. Sixteen consecutive NC State surveys show boards asking more risk questions each year, and AICPA’s 2025 release put the strategic-advantage figure at 11%, a number no competitor wants printed about them.

If you own this problem for a US company, whether as COO, CFO, or a newly named head of risk, the fastest route is a ninety-day build with an experienced guide. See how our services fit that build and contact us to scope a first register and board report you can defend.

Leave a Comment