Back to Standards

    ISO 31000

    Risk Management Guidelines

    Guidance standard

    ISO 31000 is the international guidance standard for managing risk. It sets out principles, a framework and a process that any organisation can adapt, and it is expressly not intended for certification.

    Can you get certified to ISO 31000?

    ISO 31000 is a guidance standard. It offers recommendations rather than auditable requirements, so no accredited body can certify an organisation to ISO 31000. Any claim of "ISO 31000 certification" should be treated with caution.

    What is ISO 31000?

    ISO 31000 provides guidance on managing risk faced by organisations of any size, sector or maturity. It was first published in 2009 and revised in 2018. Unlike a management system standard, it contains recommendations rather than auditable requirements, and ISO states that it is not intended for certification purposes.

    What it covers

    • Principles. Eight principles describing what effective risk management looks like, including being integrated, structured, customised, inclusive and based on the best available information.
    • Framework. Leadership and commitment, integration, design, implementation, evaluation and improvement of risk management across the organisation.
    • Process. Scope and context, risk identification, analysis, evaluation and treatment, supported by continual communication, consultation, monitoring, review and recording.

    Who uses it

    Boards and executives use ISO 31000 to set risk appetite and governance expectations. Risk, compliance, finance, project and operations teams use it to bring a common vocabulary to risk discussions. It is frequently used alongside certifiable management system standards, because those standards require risk-based thinking but do not prescribe how to do it.

    How to apply it

    1. Agree the scope, context and criteria for risk in your organisation.
    2. Map ISO 31000 principles onto the governance and decision-making you already have, rather than building a parallel process.
    3. Establish a single risk register and a consistent method for analysing and evaluating risk.
    4. Define treatment options, owners and review points, and record the rationale for each decision.
    5. Review effectiveness periodically and feed the outcome back into strategy and objectives.

    Related standards

    ISO 31000 is commonly applied together with ISO 9001, ISO 27001, ISO 45001 and ISO 22301, all of which are certifiable and all of which expect a risk-based approach. IEC 31010 provides risk assessment techniques that support ISO 31000.

    Applying ISO 31000 in your organisation

    There is no certification to pursue, but an experienced consultant can help you apply ISO 31000 alongside the management system standards you are certified to. Reading the published document is the best starting point.

    Authoritative source

    This page summarises ISO 31000 (current published edition). Always confirm the detail against the published document.

    View the official record for ISO 31000Last verified: 08 August 2026