Expertise · ISO 31000

Risk Management as a Governance Discipline

ISO 31000:2018 provides the principles, framework and process enabling any organisation to manage risk in a coherent, structured way — integrated into governance rather than treated as a standalone function.

ISO 31000 — Universal Guidelines

Published by ISO in 2018, ISO 31000 provides guidelines for risk management applicable to any organisation, regardless of size, sector or nature — private, public or non-profit. Unlike management system standards such as ISO/IEC 27001 or ISO 22301, ISO 31000 does not lead to organisational certification: it serves as a reference framework for professionals responsible for designing, implementing, leading or improving risk management practices within their organisation.

Key concept · Universality of the framework

ISO 31000 applies to all types of risk, whatever their nature — strategic, operational, financial, regulatory, environmental, information security, business continuity. It does not replace sector-specific standards: it provides their shared reference framework, ensuring coherence and articulation across risk management activities within an organisation.

The standard is built around three interdependent components: principles, which define the characteristics of effective risk management; the framework, which organises the integration of risk management into organisational governance; and the process, which describes the operational steps — communication and consultation, establishing the context, risk assessment (identification, analysis, evaluation), risk treatment, monitoring and review.

The PECB ISO 31000 Lead Risk Manager personal certification validates the ability to design and implement a risk management programme based on ISO 31000, to lead its continuous improvement, and to report results to senior management.

My Teaching Approach

ISO 31000 cannot be taught in isolation. Its operational value lies precisely in its ability to structure and unify risk management activities conducted across very different contexts. My approach anchors ISO 31000 in its normative and regulatory ecosystem, connects its components to recognised risk assessment methods, and grounds each concept in situations drawn from field experience.

ISO 31000:2018

Risk Management — Guidelines · Universal reference framework, applicable to any organisation and any type of risk

Companion standards — the ISO 31000 family

ISO 31073:2022

Risk Management — Vocabulary · International reference terminology

IEC 31010:2019

Risk Management — Risk Assessment Techniques · Catalogue of 41 methods and tools

Sector-specific applications — instantiations of ISO 31000 principles

ISO/IEC 27005

Information security risk management

ISO 22301

Business continuity risk management

EBIOS Risk Manager

Cyber risk assessment — complex environments

ISO/IEC 42001

AI system risk management

Regulatory environment

NIS2

Cyber risk management — essential and important entities

DORA

ICT-related risk — financial sector

ISO/IEC 27001

Information Security Management System

ISO 19011

Auditing management systems

Principles — The foundations of effective risk management

ISO 31000 sets out eight principles characterising effective risk management: integrated, structured and comprehensive, customised, inclusive, dynamic, based on the best available information, accounting for human and cultural factors, and oriented toward continual improvement. These principles are not formal requirements: they form the critical reference point for assessing the maturity of a risk management programme and identifying areas for improvement.

Framework — Integration into governance

The framework describes how risk management should be integrated into organisational governance: leadership commitment, framework design (understanding the organisation's context, defining roles and responsibilities, allocating resources), implementation, evaluation and improvement. The central challenge is integrating risk management into decision-making at all levels — not treating it as an isolated function or a purely compliance-driven exercise.

Process — Risk assessment and treatment

The ISO 31000 process comprises: communication and consultation (continuous, at every stage); establishing the external, internal and risk management context; risk assessment (identification, analysis, evaluation); risk treatment (selecting and implementing options); monitoring and review; and recording and reporting. The process is iterative — it adapts to changes in context and to newly identified risks.

IEC 31010 — Risk assessment techniques

IEC 31010:2019 catalogues 41 risk assessment techniques — from structured interviews and SWOT analysis to probabilistic methods (fault trees, bow-tie diagrams, Monte Carlo simulation) — and specifies for each the appropriate application scenarios, advantages and limitations. Mastering this standard is essential for selecting and applying the methods best suited to each operational context.

Articulation with sector-specific standards

ISO 31000 constitutes the generic framework of which ISO/IEC 27005, ISO 22301 and other sector standards are specific applications. Understanding this relationship avoids duplication of effort, ensures coherence across the overall risk management programme, and enables organisations to leverage the synergies between different risk domains. This cross-cutting perspective is particularly valuable for organisations subject to multiple regulatory requirements (NIS2, DORA, etc.).

International Experience

This approach is grounded in operational experience gained with major international groups, defence sector organisations, critical entities within the meaning of NIS2 and DORA, higher education institutions, Big Four firms and international training organisations. It draws on field practice developed in France, Luxembourg and Scandinavia, with organisations subject to high standards of governance, risk management and compliance.

Risk management is often perceived as a technical discipline reserved for specialists. My approach aims to make it a competence accessible to any manager, auditor or executive — by grounding concepts in concrete operational situations and showing how ISO 31000 connects to governance decisions in practice.

ISO 31000 reaches its full value when integrated into organisational governance — not as one procedure among many, but as a discipline of thought that improves the quality of decisions at every level.

Dominique Bourra  ·  PECB Platinum Trainer

Training your teams or pursuing individual certification?
On-site or remote, instructor-led or self-paced.

Get in touch →