Published by ISO in 2018, ISO 31000 provides guidelines for risk management applicable to any organisation, regardless of size, sector or nature — private, public or non-profit. Unlike management system standards such as ISO/IEC 27001 or ISO 22301, ISO 31000 does not lead to organisational certification: it serves as a reference framework for professionals responsible for designing, implementing, leading or improving risk management practices within their organisation.
Key concept · Universality of the framework
ISO 31000 applies to all types of risk, whatever their nature — strategic, operational, financial, regulatory, environmental, information security, business continuity. It does not replace sector-specific standards: it provides their shared reference framework, ensuring coherence and articulation across risk management activities within an organisation.
The standard is built around three interdependent components: principles, which define the characteristics of effective risk management; the framework, which organises the integration of risk management into organisational governance; and the process, which describes the operational steps — communication and consultation, establishing the context, risk assessment (identification, analysis, evaluation), risk treatment, monitoring and review.
The PECB ISO 31000 Lead Risk Manager personal certification validates the ability to design and implement a risk management programme based on ISO 31000, to lead its continuous improvement, and to report results to senior management.
ISO 31000 cannot be taught in isolation. Its operational value lies precisely in its ability to structure and unify risk management activities conducted across very different contexts. My approach anchors ISO 31000 in its normative and regulatory ecosystem, connects its components to recognised risk assessment methods, and grounds each concept in situations drawn from field experience.
ISO 31000:2018
Risk Management — Guidelines · Universal reference framework, applicable to any organisation and any type of risk
Companion standards — the ISO 31000 family
ISO 31073:2022
Risk Management — Vocabulary · International reference terminology
IEC 31010:2019
Risk Management — Risk Assessment Techniques · Catalogue of 41 methods and tools
Sector-specific applications — instantiations of ISO 31000 principles
ISO/IEC 27005
Information security risk management
ISO 22301
Business continuity risk management
EBIOS Risk Manager
Cyber risk assessment — complex environments
ISO/IEC 42001
AI system risk management
Regulatory environment
NIS2
Cyber risk management — essential and important entities
DORA
ICT-related risk — financial sector
ISO/IEC 27001
Information Security Management System
ISO 19011
Auditing management systems
Principles — The foundations of effective risk management
ISO 31000 sets out eight principles characterising effective risk management: integrated, structured and comprehensive, customised, inclusive, dynamic, based on the best available information, accounting for human and cultural factors, and oriented toward continual improvement. These principles are not formal requirements: they form the critical reference point for assessing the maturity of a risk management programme and identifying areas for improvement.
Framework — Integration into governance
The framework describes how risk management should be integrated into organisational governance: leadership commitment, framework design (understanding the organisation's context, defining roles and responsibilities, allocating resources), implementation, evaluation and improvement. The central challenge is integrating risk management into decision-making at all levels — not treating it as an isolated function or a purely compliance-driven exercise.
Process — Risk assessment and treatment
The ISO 31000 process comprises: communication and consultation (continuous, at every stage); establishing the external, internal and risk management context; risk assessment (identification, analysis, evaluation); risk treatment (selecting and implementing options); monitoring and review; and recording and reporting. The process is iterative — it adapts to changes in context and to newly identified risks.
IEC 31010 — Risk assessment techniques
IEC 31010:2019 catalogues 41 risk assessment techniques — from structured interviews and SWOT analysis to probabilistic methods (fault trees, bow-tie diagrams, Monte Carlo simulation) — and specifies for each the appropriate application scenarios, advantages and limitations. Mastering this standard is essential for selecting and applying the methods best suited to each operational context.
Articulation with sector-specific standards
ISO 31000 constitutes the generic framework of which ISO/IEC 27005, ISO 22301 and other sector standards are specific applications. Understanding this relationship avoids duplication of effort, ensures coherence across the overall risk management programme, and enables organisations to leverage the synergies between different risk domains. This cross-cutting perspective is particularly valuable for organisations subject to multiple regulatory requirements (NIS2, DORA, etc.).
This approach is grounded in operational experience gained with major international groups, defence sector organisations, critical entities within the meaning of NIS2 and DORA, higher education institutions, Big Four firms and international training organisations. It draws on field practice developed in France, Luxembourg and Scandinavia, with organisations subject to high standards of governance, risk management and compliance.
Risk management is often perceived as a technical discipline reserved for specialists. My approach aims to make it a competence accessible to any manager, auditor or executive — by grounding concepts in concrete operational situations and showing how ISO 31000 connects to governance decisions in practice.
ISO 31000 reaches its full value when integrated into organisational governance — not as one procedure among many, but as a discipline of thought that improves the quality of decisions at every level.