Get Your ISO 31000 Quote
ISO 31000 Risk Management a risk framework that holds
Credit, operational, cyber, supplier and strategic risk are usually managed by different teams on different scales, and nothing adds up at board level. ISO 31000 gives one framework and one process for all of them. It is guidance rather than a certifiable standard, and SIS assesses organisations against it independently.
You need ISO 31000 if…
- !Each function scores risk on its own scale and the board cannot compare one against another.
- !A regulator or auditor has questioned how risk appetite is set and who owns each material risk.
- !The risk register is updated for the audit committee and ignored for the rest of the quarter.
- !An incident happened in a risk everyone knew about and nobody had been made accountable for.
- !You are implementing ISO 22301, ISO/IEC 27001 or ISO 37301 and need one risk method underneath them.
- !An investor or acquirer is testing whether enterprise risk management exists beyond a spreadsheet.
Guidance on managing risk of any kind. It sets out principles, a framework for embedding risk work in governance, and a process running from establishing context through identification, analysis, evaluation and treatment to monitoring and reporting.
ISO 31000 is guidance and carries no accredited certification. SIS provides an independent assessment against its principles, framework and process, issuing an assessment report and statement of conformance.
There is no certificate to expire. The assessment reports a point in time, and organisations typically repeat it annually alongside their certified management system audits.
Banks, insurers, utilities, healthcare groups, public bodies and any organisation whose board is asked to state that risk is being managed.
Where this certification is demanded
ISO 31000 is applicable across 1 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What ISO 31000 Actually Requires
The backbone an implementer has to build, in the order it usually gets built.
Board and executive commitment that puts risk work inside planning, budgeting and decision-making rather than into a parallel process owned by one department.
A stated internal and external context, defined risk criteria and an articulated appetite, so that severity means the same thing in treasury and in operations.
Systematic identification across strategic, financial, operational, legal, technology and supply chain sources, including the risks nobody currently owns and the opportunities the same process reveals.
Consistent analysis of likelihood and consequence using stated methods, then evaluation against the criteria to decide what is tolerated, treated, transferred or avoided.
Treatment plans with named owners, funding, deadlines and residual risk accepted at the level with authority to accept it, not by the person who wrote the register.
Regular review of whether treatments work, recording of risk information as a decision trail, and reporting that reaches the board in a form it can act on.
How ISO 31000 Assessment Works
No black box. A defined, time-bound route from first call to statement of conformance.
Scoping & Proposal
We agree what is assessed: which entities, which risk categories and which decision forums, and whether the output is a gap report, a maturity rating or both.
2–3 daysFramework & Document Review
The board and committee papers are read off site before anyone visits, because they show whether risk information reached the people deciding or stopped at the risk function.
1–2 weeksInterviews & Evidence Testing
Risk owners, function heads and executives are interviewed, and specific decisions are traced backwards to test whether the framework shaped them or merely recorded them afterwards.
3–5 days on siteAssessment Report & Statement
The deliverable is a written assessment against the principles, framework and process, with a maturity view by function and a statement of conformance you can hand to a regulator or an acquirer.
1–2 weeksIndustries That Need ISO 31000
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Is the register a control or a chore?
ISO 31000 has no certificate and we will not pretend otherwise. What you get is a maturity view and a conformance statement the audit committee can question line by line.
Get My Free Quote →What ISO 31000 Changes for Your Business
Certification is not a certificate on the wall. It is a working system that pays for itself.
One risk language
A single set of criteria lets credit, operational and technology risks be compared and ranked, so capital and attention go to the largest exposures.
Board reporting improves
Directors receive an aggregated picture with owners and treatment status attached, rather than a register that grows every quarter and never closes anything.
Feeds certified systems
ISO 22301, ISO/IEC 27001 and ISO 37301 all demand risk assessment. One method underneath them removes duplicate registers and contradictory scores.
Evidence for regulators
An independent assessment gives supervisors and auditors something better than a self-assessment when they ask how risk governance actually operates day to day.
Decisions get tested
Applying the process at the point of investment, market entry or supplier selection changes decisions. Risk work that never changes a decision has not paid for itself.
Appetite becomes usable
Expressing appetite as measurable limits lets managers act without escalating everything, and makes escalation meaningful when a limit is genuinely breached.
Knowledge Base - Downloads
Practical documents prepared by our auditors. Fill the short form once and every download on the page unlocks.
From risk register to board decision
How aggregation, ownership and reporting turn a list of risks into something a board can act on before an incident.
Risk criteria and appetite statement template
A format expressing appetite as measurable limits by category, with escalation thresholds managers can apply without further interpretation.
ISO 31000 framework maturity checklist
Principle-by-principle self-assessment covering integration, design, implementation, evaluation and improvement, with the evidence each one usually needs to be credible.
Why risk registers stop influencing decisions
The failure patterns behind registers that are maintained diligently and then consulted by nobody making the real choices.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to ISO 31000.
Can we be certified to ISO 31000?
What is the difference between ISO 31000 and IEC 31010?
Does it replace our existing framework, such as COSO?
Who should own the framework?
How long does an assessment take?
Will SIS help us design the framework?
Have your risk framework independently assessed
An audit committee treats an outside opinion differently from one written in-house. That is most of the value here. Ask what the assessment would cover at your size.
Get My Free Quote → WhatsApp Us