If ISO 31000 feels like another set of documents to complete, begin with the decisions your organisation needs to make. Its principles, framework and process provide guidance for managing uncertainty; they do not prescribe a single register or report format.

It’s guidance, not a certification standard
That distinction matters practically, not just semantically. A vendor or partner asking you to prove “ISO 31000 compliance” is asking for something that doesn’t formally exist, and pointing that out early avoids an audit that measures your organisation against a benchmark nobody can actually certify to.
Unlike ISO 27001, you cannot be “certified to ISO 31000.” It sets out principles and a generic process for managing risk of any kind — not just security risk — and leaves the detail of implementation to the organisation. This is a feature, not a gap: it means the standard applies as well to a mining company’s project risk as to a council’s cyber risk, without prescribing specific controls or maturity levels for either. If someone tells you their organisation is “ISO 31000 certified,” they’ve misunderstood what the standard is.
The three parts
ISO 31000:2018 is structured around three things that work together, not three sequential steps.
Principles describe what good risk management looks like in character, not in procedure — integrated into the organisation’s activities, structured, tailored to context, inclusive of stakeholders, dynamic, and based on the best information available, among others. They’re a test you apply to a risk management arrangement, not a form you fill in.
Framework is the organisational scaffolding that makes the process possible and repeatable: leadership and commitment, how risk management is integrated into governance, how it’s designed for the organisation’s context, how it’s implemented, evaluated, and improved over time. Without a framework, risk assessments happen as one-off events instead of an ongoing capability.
Process is the part practitioners spend the most time in, and the part most useful to draw as a single picture.
ISO 31000 explained: the process, step by step
The ISO 31000 process runs left to right, with three activities running continuously alongside it rather than as steps in the sequence.
- Scope, context and criteria — define what you’re assessing, the internal and external environment it sits in, and the criteria you’ll use to judge significance (this is where your consequence and likelihood scales get set).
- Risk identification — find what could happen: the risks, their sources, and the events that would trigger them.
- Risk analysis — understand each risk’s causes, consequences and likelihood, including how existing controls affect it. This is where you establish the level of risk as it stands now — the current risk with existing controls taken into account.
- Risk evaluation — compare the analysed level of risk against your criteria to decide whether it needs treatment, and if so, how urgently.
- Risk treatment — select and implement options to modify the risk: avoid it, remove the source, change likelihood or consequence, share it, or retain it by informed decision.
Running throughout, not after the fact:
- Recording and reporting — the process and its outcomes are documented and communicated through appropriate mechanisms, so decisions are traceable and the same ground doesn’t get re-covered at the next review.
- Monitoring and review — the assessment is checked against reality on a planned or triggered basis, because a risk rating from eighteen months ago describes an organisation that may no longer exist.
- Communication and consultation — stakeholders are engaged throughout, not briefed once at the end, so the criteria and judgements reflect more than one point of view.
Worked example
A mid-size water utility is assessing the risk of unauthorised access to a remote pumping station. Walking it through the process:
| Step | What happens |
|---|---|
| Context | Remote site, unstaffed, on the utility’s own risk criteria for critical infrastructure |
| Identification | Unauthorised entry leading to tampering with dosing equipment |
| Analysis | Existing controls: perimeter fence, padlocked gate, no monitoring. Consequence rated Major (public health impact), likelihood rated Possible given weak detection |
| Evaluation | Against the utility’s criteria, this exceeds tolerance and requires treatment |
| Treatment | Add intruder detection with a monitored alarm response, reassess likelihood once installed |
Recording and monitoring don’t wait until the end of this table — the context, the analysis judgement, and the treatment decision are each logged as they’re made, and a review date is set so the “Possible” likelihood rating gets checked once the alarm is actually operating, not assumed to have improved.
Where it sits alongside ISO 27001 and NIST CSF
ISO 31000 is often confused with the standards that sit on top of it, because most practitioners meet risk management through one of those rather than through ISO 31000 directly. ISO 27001 is a management system standard for information security, and it has its own risk assessment requirement — one that draws on the same generic thinking ISO 31000 describes, but is scoped specifically to information security risk within a certifiable management system. NIST CSF, now at version 2.0, organises cybersecurity risk activity into functions — Identify, Protect, Detect, Respond and Recover, with Govern added as a sixth function in the 2.0 update — which is a different organising structure again, built for communicating cybersecurity posture rather than running a generic risk process.
None of these compete with each other. A security team can run ISO 27001’s risk assessment using ISO 31000’s process as the underlying method, and report the resulting posture through the NIST CSF functions for an audience that finds that structure more familiar. Treat ISO 31000 as the process engine and the others as the scoping and reporting layers built for particular audiences, and the standards stop looking like alternatives you have to choose between.
Common mistakes
- Treating the process as one-off, run for an audit and then left untouched until the next one, instead of monitored and reviewed on a cycle.
- Rating consequence and likelihood before defining criteria, so ratings from different assessors mean different things on the same scale.
- Skipping communication and consultation and running the assessment as a desk exercise, producing a technically complete register that the people who own the risks don’t recognise.
- Confusing the framework with the process — building an elaborate risk policy document while the actual risk assessments underneath it are still ad hoc.
- Analysing risk against controls that don’t yet exist, inflating confidence in a treatment that hasn’t been implemented.
Get the one-page version
If you need something to hand a new risk owner or put on the wall next to the register, SRMBOK’s free ISO31000 Risk Management Process — One-Page Guide sets out the process visually, from context and current-state risk through to treatment, alongside the continuous activities of communication, documentation and monitoring — jargon-free, on a single page. Once you’re rating risk, see Before and After: Recording Pre- and Post-Mitigation Risk for how to record the shift a treatment actually produces. If your current register is the reason nobody trusts the ratings, read Why Your Risk Spreadsheet Confuses Everyone Who Opens It next, and if part of your context-setting now involves records that pass through an AI tool, see Anonymising a Prompt Without Destroying the Answer.
