Back to library
Enterprise · Issued by International Organization for Standardization

ISO 31000

ISO 31000:2018 — Risk Management Guidelines

ISOGenericPrinciplesEnterprise
Compare ISO 31000 with

The international gold-standard for risk management. Principles, framework, and process that work across any industry and any risk type.

ISO 31000 provides high-level guidelines, principles, and a generic process for managing any type of risk. It is not certifiable but is widely used as the foundation on which more specific frameworks (COSO ERM, NIST RMF) sit. Best when you want a portable, industry-neutral language to talk about risk.

At a glance

Complexity
Medium
Certification
No (guideline)
Time to implement
3–6 months
Issued by
International Organization for Standardization

Fits

Industries
bankinghealthcaremanufacturingitconstructiongovernmentother
Risk types
operationalstrategiccompliancefinancial
Frequently asked

Questions risk leaders ask

ISO 31000:2018 is an international standard providing principles, a framework, and a process for managing risk across any organization, industry, or risk type.
Related on RiskPedia

Frameworks & regulations frequently referenced together

See if it fits you

Run the Finder to get a personalised match score for ISO 31000.

Made with Emergent