The ISO 31000 standard
Risk management: principles and guidelines

The ISO 31000 risk management process

ISO 31000 is an international standard published in 2009 (and updated in 2018) that provides principles and guidelines for effective risk management. It outlines a generic approach to risk management, which can be applied to different types of risks (financial, safety, project risks) and used by any type of organization. The standard provides a uniform vocabulary and concepts for discussing risk management. It provides guidelines and principles that can help to undertake a critical review of your organization’s risk management process.

The standard does not provide detailed instructions or requirements on how to manage specific risks, nor any advice related to a specific application domain; it remains at a generic level.

Relative to older standards on risk management, the 31000 standard innovates in several areas:

Course material

The ISO 31000 standard

The risk management process outlined in the ISO 31000 standard includes the following activities:

The standard includes a number of principles that risk management should verify:

Note that the standards document is very expensive to purchase. The slides above suggest an alternative source of information that may be useful to some learners.

Other resources

We recommend the following sources of further information on this topic:

Published: 2017-07-31
Last updated: 2022-10-14