ISO 31000 – Risk management

ISO 31000 describes how an organisation deals with uncertainty. It applies to every sector and every size. And it is something different from the standards next to it: a set of guidelines, not a requirements standard. You cannot be certified to ISO 31000. There is no certificate and no body that issues one.

That is not a drawback, it is the point. The standard gives you a framework to work to. The framework can be demonstrated where it is called for anyway: in the management system standards that require a risk assessment. Set up the ISO 31000 methodology properly and you serve ISO 9001, ISO/IEC 27001 and ISO 22301 at the same time. That is exactly where the practical value lies. More on our service page Risk management.

Who it applies to

Where it usually goes wrong

The standard is assumed to be certifiable

That is the most common misconception. A customer demands “risk management to ISO 31000”, the company looks for a certification body – and finds none. Some providers then sell personal certificates or seals of approval of their own. Neither is evidence for your company.

The route is a different one. You build the methodology to ISO 31000 and demonstrate it through the management system standards. In the ISO 9001 or ISO/IEC 27001 audit you show your risk assessment. There the auditor sees a sound method instead of an improvised spreadsheet. As a rule that also satisfies the customer who asked in the first place.

Risk management runs alongside the management system

In many companies there are two worlds. Management keeps a risk list for the bank, the shareholders or the insurer. Alongside it sits the risk assessment from clause 6.1 of ISO 9001, usually held in quality management.

Both mean the same thing. Both are maintained twice, with different scales and different review dates. Sooner or later they contradict each other. The same matter appears once as critical and once as under control. That comes out in the audit at the latest. The effort is doubled and the result is worse than a single shared list.

Rating scales without a shared understanding

Almost every business rates by likelihood and impact. But every department reads “high” and “medium” differently. For production, one day of downtime is high; for sales it takes losing a major customer.

The sum of it is a list that cannot be prioritised. The numbers look comparable but are not. The remedy is a short, binding definition for each level, with amounts, periods or quantities instead of adjectives. That is a single workshop, and afterwards nobody argues about gut feeling any more.

How we support you

We start with what is already there. Usually we find two or three lists in the business. Out of them comes one method: one context, one scale, one review cycle, one owner per risk.

We then tie that into your management system so it does not drift off to one side again. More on this under Building a management system. Whether the method holds up day to day shows in the first cycle. This is where Internal audits & gap analyses helps.

Who handles this at our end

Marion Rammé – IRCA certified and registered QMS / EMS / OHSMS Lead Auditor #01194927

Rüdiger Rammé – IRCA certified and registered QMS / OHSMS Lead Auditor #01192806

The team in detail

Frequently asked questions

Can you be certified to ISO 31000?

No. ISO 31000 is written as a set of guidelines and contains no auditable requirements. There is therefore no accredited body that issues a company certificate for it. What you find on the market are personal qualifications or providers' own seals. In practice, the evidence runs through the management system standards that require a risk assessment.

How does this relate to clause 6.1 of ISO 9001?

ISO 9001 requires you to determine and address risks and opportunities. But it does not say how. That is exactly the gap ISO 31000 fills, with an approach, terms and process steps. In practice that means one method, one register – and clause 6.1 is dealt with.

What does it cost to set up?

Considerably less than a management system project. A manageable start is usually enough: one workshop with the leadership team, building the method and tying it into your existing routines. There are no certification fees, because there is no certification.

How many risks make sense?

Fewer than most people record. In our experience a medium-sized business can sensibly steer ten to twenty risks at top level. Anything beyond that is no longer discussed, only administered. Individual areas may keep their own, more detailed assessments below that.

Who in the business needs to be involved?

The management, otherwise it becomes an exercise in quality management. Alongside them the people responsible for the main areas, because they know the real risks. For particular topics you bring in specialists, IT or health and safety for example. Being involved means assessing and deciding – not just signing off a list.

Let us talk about it

The first conversation is free and without obligation.

Get in touch