[email protected]
Accredited Certification Body · IAS & IAF Member · Certificates Verifiable Online
HomeStandardsISO 31000

Get Your ISO 31000 Quote

Takes 30 seconds · a specialist responds within 2 business hours
Step 1 of 2
CertificationTrainingCompliance Audits
Not sure - guide me
ISO 31000
No spam. No obligation. A clear quote.
15,000+Certified Clients
30+Countries Served
IAS · IAFAccredited
ISO 31000:2018 · Risk Management (guidance)

ISO 31000 Risk Management a risk framework that holds

Credit, operational, cyber, supplier and strategic risk are usually managed by different teams on different scales, and nothing adds up at board level. ISO 31000 gives one framework and one process for all of them. It is guidance rather than a certifiable standard, and SIS assesses organisations against it independently.

You need ISO 31000 if…

  • !Each function scores risk on its own scale and the board cannot compare one against another.
  • !A regulator or auditor has questioned how risk appetite is set and who owns each material risk.
  • !The risk register is updated for the audit committee and ignored for the rest of the quarter.
  • !An incident happened in a risk everyone knew about and nobody had been made accountable for.
  • !You are implementing ISO 22301, ISO/IEC 27001 or ISO 37301 and need one risk method underneath them.
  • !An investor or acquirer is testing whether enterprise risk management exists beyond a spreadsheet.
What it is

Guidance on managing risk of any kind. It sets out principles, a framework for embedding risk work in governance, and a process running from establishing context through identification, analysis, evaluation and treatment to monitoring and reporting.

Who issues it

ISO 31000 is guidance and carries no accredited certification. SIS provides an independent assessment against its principles, framework and process, issuing an assessment report and statement of conformance.

Validity

There is no certificate to expire. The assessment reports a point in time, and organisations typically repeat it annually alongside their certified management system audits.

Who gets asked for it

Banks, insurers, utilities, healthcare groups, public bodies and any organisation whose board is asked to state that risk is being managed.

1of 25 industries

Where this certification is demanded

ISO 31000 is applicable across 1 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.

Banking and Finance

What ISO 31000 Actually Requires

The backbone an implementer has to build, in the order it usually gets built.

1
Mandate and integration

Board and executive commitment that puts risk work inside planning, budgeting and decision-making rather than into a parallel process owned by one department.

2
Context and criteria

A stated internal and external context, defined risk criteria and an articulated appetite, so that severity means the same thing in treasury and in operations.

3
Risk identification

Systematic identification across strategic, financial, operational, legal, technology and supply chain sources, including the risks nobody currently owns and the opportunities the same process reveals.

4
Analysis and evaluation

Consistent analysis of likelihood and consequence using stated methods, then evaluation against the criteria to decide what is tolerated, treated, transferred or avoided.

5
Treatment and ownership

Treatment plans with named owners, funding, deadlines and residual risk accepted at the level with authority to accept it, not by the person who wrote the register.

6
Monitoring and reporting

Regular review of whether treatments work, recording of risk information as a decision trail, and reporting that reaches the board in a form it can act on.

How ISO 31000 Assessment Works

No black box. A defined, time-bound route from first call to statement of conformance.

Scoping & Proposal

We agree what is assessed: which entities, which risk categories and which decision forums, and whether the output is a gap report, a maturity rating or both.

2–3 days

Framework & Document Review

The board and committee papers are read off site before anyone visits, because they show whether risk information reached the people deciding or stopped at the risk function.

1–2 weeks

Interviews & Evidence Testing

Risk owners, function heads and executives are interviewed, and specific decisions are traced backwards to test whether the framework shaped them or merely recorded them afterwards.

3–5 days on site

Assessment Report & Statement

The deliverable is a written assessment against the principles, framework and process, with a maturity view by function and a statement of conformance you can hand to a regulator or an acquirer.

1–2 weeks
A single-entity assessment usually runs four to six weeks end to end - the fieldwork compresses where an audit committee date is already fixed - and groups with several regulated subsidiaries should allow longer.

Not Sure Which Certification You Need?

Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.

Question 1 of 3

Which sector best describes your organisation?

Is the register a control or a chore?

ISO 31000 has no certificate and we will not pretend otherwise. What you get is a maturity view and a conformance statement the audit committee can question line by line.

Get My Free Quote →

What ISO 31000 Changes for Your Business

Certification is not a certificate on the wall. It is a working system that pays for itself.

🧭

One risk language

A single set of criteria lets credit, operational and technology risks be compared and ranked, so capital and attention go to the largest exposures.

🪑

Board reporting improves

Directors receive an aggregated picture with owners and treatment status attached, rather than a register that grows every quarter and never closes anything.

🔗

Feeds certified systems

ISO 22301, ISO/IEC 27001 and ISO 37301 all demand risk assessment. One method underneath them removes duplicate registers and contradictory scores.

🧾

Evidence for regulators

An independent assessment gives supervisors and auditors something better than a self-assessment when they ask how risk governance actually operates day to day.

💡

Decisions get tested

Applying the process at the point of investment, market entry or supplier selection changes decisions. Risk work that never changes a decision has not paid for itself.

🎯

Appetite becomes usable

Expressing appetite as measurable limits lets managers act without escalating everything, and makes escalation meaningful when a limit is genuinely breached.

Knowledge Base - Downloads

Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.

PDF GUIDE

From risk register to board decision

How aggregation, ownership and reporting turn a list of risks into something a board can act on before an incident.

TEMPLATE

Risk criteria and appetite statement template

A format expressing appetite as measurable limits by category, with escalation thresholds managers can apply without further interpretation.

CHECKLIST

ISO 31000 framework maturity checklist

Principle-by-principle self-assessment covering integration, design, implementation, evaluation and improvement, with the evidence each one usually needs to be credible.

WHITEPAPER

Why risk registers stop influencing decisions

The failure patterns behind registers that are maintained diligently and then consulted by nobody making the real choices.

🔒 Documents are locked. Fill the form once to unlock every download.

Frequently Asked Questions

Straight answers to what buyers ask before they commit to ISO 31000.

Can we be certified to ISO 31000?
No. ISO 31000 is written as guidance, so there is no accredited certification against it, and any body offering an accredited ISO 31000 certificate is misrepresenting what it holds. What is available is an independent assessment against the principles, framework and process, resulting in a report and a statement of conformance. Where a certificate is genuinely needed, the certifiable neighbours are ISO 22301, ISO/IEC 27001 and ISO 37301.
What is the difference between ISO 31000 and IEC 31010?
ISO 31000 sets the framework and the process. IEC 31010 is the companion standard describing risk assessment techniques, from bow tie and failure mode analysis to scenario work and structured expert judgement, and it explains when each is appropriate. ISO 31000 tells you the process must analyse consequence and likelihood. IEC 31010 helps you choose how to do it.
Does it replace our existing framework, such as COSO?
Not necessarily. Many organisations run COSO or a sector framework and use ISO 31000 to test whether the principles hold: integration into decisions, a structured process, best available information, human and cultural factors, continual improvement. The two are compatible in practice. Our assessment looks at how risk actually works in your organisation, not at which framework document you adopted.
Who should own the framework?
The board or equivalent governing body owns accountability, executives own integration into planning and budgeting, and individual risks need named owners with authority to act and to accept residual risk. A risk function coordinates and challenges. Where the risk team owns the risks themselves, the framework has already failed, and interviews expose that within a day.
How long does an assessment take?
Four to six weeks for a single entity, longer for a group with regulated subsidiaries or several jurisdictions. Document review runs off site, fieldwork is typically three to five days of interviews, and the report follows within a fortnight. If an audit committee date or a regulatory submission is fixed, we work backwards from it and agree the fieldwork window.
Will SIS help us design the framework?
No. SIS assesses; it does not consult. That separation is what makes the assessment worth showing a regulator or a board, and accreditation rules require it for the certified standards SIS also audits. Risk consultants design frameworks and write appetite statements. SIS tests whether what exists actually functions the way ISO 31000 describes.
Email Us
✉ EmailGet Quote