If ISO 31000 feels like another set of documents to complete, begin with the decisions your organisation needs to make. Its principles, framework and process provide guidance for managing uncertainty; they do not prescribe a single register or report format.

Make the risk process support decisions: Clarify context and criteria; Assess and treat risk; Monitor, review and communicate.
Keep the evidence proportionate to the decision.

It's guidance, not a certification standard

That distinction matters practically, not just semantically. A vendor or partner asking you to prove "ISO 31000 compliance" is asking for something that doesn't formally exist, and pointing that out early avoids an audit that measures your organisation against a benchmark nobody can actually certify to.

Unlike ISO 27001, you cannot be "certified to ISO 31000." It sets out principles and a generic process for managing risk of any kind — not just security risk — and leaves the detail of implementation to the organisation. This is a feature, not a gap: it means the standard applies as well to a mining company's project risk as to a council's cyber risk, without prescribing specific controls or maturity levels for either. If someone tells you their organisation is "ISO 31000 certified," they've misunderstood what the standard is.

The three parts

ISO 31000:2018 is structured around three things that work together, not three sequential steps.

Principles describe what good risk management looks like in character, not in procedure — integrated into the organisation's activities, structured, tailored to context, inclusive of stakeholders, dynamic, and based on the best information available, among others. They're a test you apply to a risk management arrangement, not a form you fill in.

Framework is the organisational scaffolding that makes the process possible and repeatable: leadership and commitment, how risk management is integrated into governance, how it's designed for the organisation's context, how it's implemented, evaluated, and improved over time. Without a framework, risk assessments happen as one-off events instead of an ongoing capability.

Process is the part practitioners spend the most time in, and the part most useful to draw as a single picture.

ISO 31000 explained: the process, step by step

The ISO 31000 process runs left to right, with two activities running continuously alongside it rather than as steps in the sequence.

  1. Scope, context and criteria — define what you're assessing, the internal and external environment it sits in, and the criteria you'll use to judge significance (this is where your consequence and likelihood scales get set).
  2. Risk identification — find what could happen: the risks, their sources, and the events that would trigger them.
  3. Risk analysis — understand each risk's causes, consequences and likelihood, including how existing controls affect it. This is where you establish the level of risk as it stands now — the inherent picture with current controls factored in.
  4. Risk evaluation — compare the analysed level of risk against your criteria to decide whether it needs treatment, and if so, how urgently.
  5. Risk treatment — select and implement options to modify the risk: avoid it, remove the source, change likelihood or consequence, share it, or retain it by informed decision.

Running throughout, not after the fact:

Worked example

A mid-size water utility is assessing the risk of unauthorised access to a remote pumping station. Walking it through the process:

Step What happens
Context Remote site, unstaffed, on the utility's own risk criteria for critical infrastructure
Identification Unauthorised entry leading to tampering with dosing equipment
Analysis Existing controls: perimeter fence, padlocked gate, no monitoring. Consequence rated Major (public health impact), likelihood rated Possible given weak detection
Evaluation Against the utility's criteria, this exceeds tolerance and requires treatment
Treatment Add intruder detection with a monitored alarm response, reassess likelihood once installed

Recording and monitoring don't wait until the end of this table — the context, the analysis judgement, and the treatment decision are each logged as they're made, and a review date is set so the "Possible" likelihood rating gets checked once the alarm is actually operating, not assumed to have improved.

Where it sits alongside ISO 27001 and NIST CSF

ISO 31000 is often confused with the standards that sit on top of it, because most practitioners meet risk management through one of those rather than through ISO 31000 directly. ISO 27001 is a management system standard for information security, and it has its own risk assessment requirement — one that draws on the same generic thinking ISO 31000 describes, but is scoped specifically to information security risk within a certifiable management system. NIST CSF, now at version 2.0, organises cybersecurity risk activity into functions — Identify, Protect, Detect, Respond and Recover, with Govern added as a sixth function in the 2.0 update — which is a different organising structure again, built for communicating cybersecurity posture rather than running a generic risk process.

None of these compete with each other. A security team can run ISO 27001's risk assessment using ISO 31000's process as the underlying method, and report the resulting posture through the NIST CSF functions for an audience that finds that structure more familiar. Treat ISO 31000 as the process engine and the others as the scoping and reporting layers built for particular audiences, and the standards stop looking like alternatives you have to choose between.

Common mistakes

Get the one-page version

If you need something to hand a new risk owner or put on the wall next to the register, SRMBOK's free ISO31000 Risk Management Process — One-Page Guide sets out the process visually, from context and current-state risk through to treatment, alongside the continuous activities of communication, documentation and monitoring — jargon-free, on a single page. Once you're rating risk, see Before and After: Recording Pre- and Post-Mitigation Risk for how to record the shift a treatment actually produces. If your current register is the reason nobody trusts the ratings, read Why Your Risk Spreadsheet Confuses Everyone Who Opens It next, and if part of your context-setting now involves records that pass through an AI tool, see Anonymising a Prompt Without Destroying the Answer.