ISO 31000 – Risk management
ISO 31000 describes how an organisation deals with uncertainty. It applies to every sector and every size. And it is something different from the standards next to it: a set of guidelines, not a requirements standard. You cannot be certified to ISO 31000. There is no certificate and no body that issues one.
That is not a drawback, it is the point. The standard gives you a framework to work to. The framework can be demonstrated where it is called for anyway: in the management system standards that require a risk assessment. Set up the ISO 31000 methodology properly and you serve ISO 9001, ISO/IEC 27001 and ISO 22301 at the same time. That is exactly where the practical value lies. More on our service page Risk management.
Who it applies to
- Businesses running several standards that do not want to assess the same risks three times over
- Organisations that have so far ticked off clause 6.1 of ISO 9001 as an obligatory exercise
- Companies where the management keeps a risk list of its own, separate from the management system
- Anyone facing certification to ISO/IEC 27001 or ISO 22301 – there the methodology is mandatory
Where it usually goes wrong
The standard is assumed to be certifiable
That is the most common misconception. A customer demands “risk management to ISO 31000”, the company looks for a certification body – and finds none. Some providers then sell personal certificates or seals of approval of their own. Neither is evidence for your company.
The route is a different one. You build the methodology to ISO 31000 and demonstrate it through the management system standards. In the ISO 9001 or ISO/IEC 27001 audit you show your risk assessment. There the auditor sees a sound method instead of an improvised spreadsheet. As a rule that also satisfies the customer who asked in the first place.
Risk management runs alongside the management system
In many companies there are two worlds. Management keeps a risk list for the bank, the shareholders or the insurer. Alongside it sits the risk assessment from clause 6.1 of ISO 9001, usually held in quality management.
Both mean the same thing. Both are maintained twice, with different scales and different review dates. Sooner or later they contradict each other. The same matter appears once as critical and once as under control. That comes out in the audit at the latest. The effort is doubled and the result is worse than a single shared list.
Rating scales without a shared understanding
Almost every business rates by likelihood and impact. But every department reads “high” and “medium” differently. For production, one day of downtime is high; for sales it takes losing a major customer.
The sum of it is a list that cannot be prioritised. The numbers look comparable but are not. The remedy is a short, binding definition for each level, with amounts, periods or quantities instead of adjectives. That is a single workshop, and afterwards nobody argues about gut feeling any more.
How we support you
We start with what is already there. Usually we find two or three lists in the business. Out of them comes one method: one context, one scale, one review cycle, one owner per risk.
We then tie that into your management system so it does not drift off to one side again. More on this under Building a management system. Whether the method holds up day to day shows in the first cycle. This is where Internal audits & gap analyses helps.
Who handles this at our end
Marion Rammé – IRCA certified and registered QMS / EMS / OHSMS Lead Auditor #01194927
Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806
Related standards
- ISO 9001 – quality management, requires risks and opportunities in clause 6.1
- ISO/IEC 27001 – information security, with its own risk methodology as a mandatory part
- ISO 22301 – business continuity, builds directly on the risk assessment
Frequently asked questions
Can you be certified to ISO 31000?
No. ISO 31000 is written as a set of guidelines and contains no auditable requirements. There is therefore no accredited body that issues a company certificate for it. What you find on the market are personal qualifications or providers' own seals. In practice, the evidence runs through the management system standards that require a risk assessment.
How does this relate to clause 6.1 of ISO 9001?
ISO 9001 requires you to determine and address risks and opportunities. But it does not say how. That is exactly the gap ISO 31000 fills, with an approach, terms and process steps. In practice that means one method, one register – and clause 6.1 is dealt with.
What does it cost to set up?
Considerably less than a management system project. A manageable start is usually enough: one workshop with the leadership team, building the method and tying it into your existing routines. There are no certification fees, because there is no certification.
How many risks make sense?
Fewer than most people record. In our experience a medium-sized business can sensibly steer ten to twenty risks at top level. Anything beyond that is no longer discussed, only administered. Individual areas may keep their own, more detailed assessments below that.
Who in the business needs to be involved?
The management, otherwise it becomes an exercise in quality management. Alongside them the people responsible for the main areas, because they know the real risks. For particular topics you bring in specialists, IT or health and safety for example. Being involved means assessing and deciding – not just signing off a list.
Let us talk about it
The first conversation is free and without obligation.