Book an Appointment
GRC · Risk Management

ISO 31000 Risk as a leadership discipline

ISO 31000:2018 is the international guideline for enterprise risk management. We embed cyber risk into your organisation's overarching risk framework – auditable, decision-ready and effective.

2018Current edition (2nd, reconfirmed 2023)
GuidanceGuideline, not a requirements standard
Not certifiableNo certification – framework & process
ERM umbrellaBasis for ISO/IEC 27005, links to NIS2 & DORA

Why ISO 31000 is the umbrella over your cyber risk

ISO 31000:2018 provides principles and guidelines for managing risk of any kind – across all industries and risk types, from strategic and operational to cyber and compliance risk. The standard is deliberately not a requirements standard and therefore not certifiable; it describes how risk management is designed, led and continually improved.

For security leaders, ISO 31000 closes the gap between technical risk analysis and enterprise steering. ISO/IEC 27005 builds methodologically on this umbrella framework, and regulatory obligations under NIS2 and DORA explicitly require a risk-based approach. Implement ISO 31000 well and you speak the language of the board and the regulator at once.

The core building blocks

ISO 31000 rests on three pillars: principles, framework and process.

01

8 Principles

Value creation and protection, integration, structured approach, customisation to context, inclusion of stakeholders, dynamic response, best available information, plus human and cultural factors – the purpose is to create and protect value.

02

Framework

Leadership and commitment at the centre, surrounded by the cycle of integration, design, implementation, evaluation and improvement.

03

Context & communication

External and internal context, risk criteria and continuous communication and consultation form the basis of every risk decision.

04

Risk assessment

Identification, analysis and evaluation of risk – the methodological core on which ISO/IEC 27005 builds for information security.

05

Risk treatment

Selecting and implementing options to modify risk – avoid, reduce, share or accept – including the evaluation of residual risk.

06

Monitoring & reporting

Continuous monitoring and review, plus recording and reporting, secure traceability and drive improvement.

The bridge to your obligations

ISO 31000 is the common denominator linking cyber risk to regulation.

NIS2 & DORA

Both demand a risk-based approach and risk management at management-body level. ISO 31000 provides the governance structure to demonstrably meet those accountability duties.

ISO/IEC 27005 & ISO 27001

ISO/IEC 27005 tailors ISO 31000 to information security risk and feeds the ISMS under ISO/IEC 27001, turning the umbrella framework into an auditable security process.

CRA & product risk

The Cyber Resilience Act requires risk assessments across the product lifecycle. ISO 31000 offers the uniform methodology to assess product, supply-chain and enterprise risk consistently.

Enterprise risk management

ISO 31000 integrates cyber risk into the enterprise-wide risk register and strategic steering – the prerequisite for sound decisions at board level.

How we work with you

From maturity snapshot to a lived risk framework in four steps.

01

1 · Context & maturity

We capture internal and external context, existing risk processes and risk criteria, and benchmark your maturity against the principles of ISO 31000.

02

2 · Design the framework

We define governance, roles, risk appetite and criteria, and anchor leadership and commitment at management-body level.

03

3 · Implement the process

We operationalise risk assessment and treatment, link them to ISO/IEC 27005 and your regulatory duties, and build the risk register.

04

4 · Monitor & improve

We establish monitoring, reporting lines to the management body and a continual improvement cycle – audit-ready for regulators.

Frequently asked questions about ISO 31000

What security and risk leaders ask most often.

Can an organisation be certified against ISO 31000?

No. ISO 31000 is guidance, not a requirements standard, so there is no accredited certification of an organisation against it. What is certifiable is your information security management system under ISO/IEC 27001, which can build methodologically on ISO 31000.

How does ISO 31000 differ from ISO/IEC 27005?

ISO 31000 is the overarching framework for risk management of any kind. ISO/IEC 27005 tailors this methodology specifically to information security risk and connects it to the ISMS under ISO/IEC 27001.

Does ISO 31000 help with NIS2 and DORA?

Yes. Both frameworks require a risk-based approach and accountability at management-body level. ISO 31000 provides the governance structure and a consistent risk process to meet these requirements demonstrably.

Which edition is current?

ISO 31000:2018 is the current, second edition; it has been reviewed and confirmed by ISO and remains valid. A revision is being prepared in technical committees but has not yet been published as a new edition.

Which organisations is ISO 31000 suited to?

Any organisation, regardless of size, industry or sector. The guidelines are adapted to context and risk profile and apply to strategic, operational, financial and cyber risks alike.

Make risk the basis for decisions

We anchor ISO 31000 as a living framework – from the board to technical risk analysis.