Risk Management Guidelines
ISO 31000 is the international guidance standard for managing risk. It sets out principles, a framework and a process that any organisation can adapt, and it is expressly not intended for certification.
ISO 31000 is a guidance standard. It offers recommendations rather than auditable requirements, so no accredited body can certify an organisation to ISO 31000. Any claim of "ISO 31000 certification" should be treated with caution.
ISO 31000 provides guidance on managing risk faced by organisations of any size, sector or maturity. It was first published in 2009 and revised in 2018. Unlike a management system standard, it contains recommendations rather than auditable requirements, and ISO states that it is not intended for certification purposes.
Boards and executives use ISO 31000 to set risk appetite and governance expectations. Risk, compliance, finance, project and operations teams use it to bring a common vocabulary to risk discussions. It is frequently used alongside certifiable management system standards, because those standards require risk-based thinking but do not prescribe how to do it.
ISO 31000 is commonly applied together with ISO 9001, ISO 27001, ISO 45001 and ISO 22301, all of which are certifiable and all of which expect a risk-based approach. IEC 31010 provides risk assessment techniques that support ISO 31000.
There is no certification to pursue, but an experienced consultant can help you apply ISO 31000 alongside the management system standards you are certified to. Reading the published document is the best starting point.
This page summarises ISO 31000 (current published edition). Always confirm the detail against the published document.