ISO 31000 Risk Management

· About ISO 31000 Risk Management

Key Takeaways

  • ISO 31000 is a voluntary international guideline, not a certification standard, and it applies to any organization seeking a structured approach to risk management rather than a legal compliance regime.[1][4]
  • ISO 31000:2018 remains the current published edition in 2026, while ISO has an active revision project in progress; no new edition has been published yet and no 2025–2026 amendment is in force.[1][2][6]
  • ISO 31000 does not create direct fines or statutory penalties, but organizations can face contractual, audit, governance, or supervisory consequences if they claim conformance without implementing a defensible risk-management framework.[1][4][6]
  • The standard requires integration of risk management into governance, strategy, planning, reporting, policies, values, and culture, with leadership accountable for embedding it across the organization.[1][12]
  • Because ISO 31000 is generic and cross-sectoral, it maps most cleanly to enterprise risk management programs and to management systems that already use ISO 27001, NIST CSF 2.0, or ISO 42001 controls for risk treatment and monitoring.[1][12]

What It Is

ISO 31000:2018, Risk management — Guidelines, is an international standard that sets out principles and generic guidance for managing risk across organizations of any size, sector, or activity.[1][4] It is published by the International Organization for Standardization (ISO) and maintained through ISO’s committee process, with the official ISO page showing the standard as Published and noting that standards are reviewed every five years.[1]

The current edition is ISO 31000:2018, which replaced ISO 31000:2009.[1][14] The 2018 edition was published in February 2018 and remains the current valid edition as of 2026, with ISO’s public catalogue still listing it as the active standard.[1][4] ISO also shows a separate project for ISO/CD 31000 at committee-draft stage, confirming that a revision is underway, but that draft is not yet a published standard and does not change the current compliance baseline.[2][6]

There is no published 2025 or 2026 amendment to ISO 31000 in force. The practical legal status in 2026 is therefore simple: organizations may choose to align to ISO 31000:2018 today, while monitoring the ongoing revision process for a future edition.[1][2][6]

Who Must Comply

ISO 31000 does not impose mandatory compliance by law unless a regulator, contract, procurement specification, or internal policy adopts it by reference.[1][4] In that sense, the standard is broadly applicable but not legally compulsory on its own.[1]

The standard is designed for any organization and is intentionally industry-neutral, so there are no formal sector thresholds, employee-count triggers, revenue thresholds, or geographic scope tests in the standard text as publicly described by ISO.[1][12] It can be used by private companies, public bodies, nonprofits, and project-based organizations.[1][12]

ISO 31000 also has no extraterritorial enforcement mechanism of its own.[1][4] Cross-border relevance arises only where a contract, regulator, insurer, or parent-company policy requires alignment with the standard.

There are no exemptions in the usual legal sense because the document is not a statute or regulation.[1][4] However, the standard’s generic design means organizations can tailor implementation to their size, objectives, and risk profile, which is part of its core utility.[1][12]

Core Requirements

  1. Establish governance and leadership commitment. Senior management should ensure risk management is integrated into governance, decision-making, strategy, and organizational culture, rather than treated as a standalone control exercise.[1][12]
  1. Adopt the ISO 31000 principles. The organization should apply the standard’s principles, including being integrated, structured and comprehensive, customized, inclusive, dynamic, based on the best available information, responsive to change, and considering human and cultural factors.[12]
  1. Build a risk management framework. The framework should be embedded into planning, policy, resourcing, accountability, and reporting so that risk management is part of normal management practice.[1][12]
  1. Run a risk management process. Organizations should systematically identify, analyze, evaluate, and treat risks, then monitor and review outcomes and communicate and consult with stakeholders throughout the process.[12]
  1. Define risk criteria and appetite. The organization should set criteria for evaluating risk and determine how much risk it is prepared to accept in pursuit of objectives.[12]
  1. Maintain monitoring, review, and improvement. The framework and process should be regularly reviewed and improved as the organization, its context, and its risk profile change.[12]

Deadlines and Penalties

| Milestone | Date | What applies | |---|---:|---| | ISO 31000:2018 published | 14 February 2018 | Second edition issued and replaced ISO 31000:2009.[1][14] | | Systematic review confirmation | October 2023 | ISO 31000:2018 was confirmed as current without replacement.[3] | | Current public catalogue status | 25 June 2026 | ISO still lists ISO 31000:2018 as published and active.[1] | | Revision underway | 2025–2026 | ISO/CD 31000 is under development, but no published replacement is in force.[2][6] |

Maximum fines: None are set by ISO 31000 itself because it is not a statute, regulation, or certification regime.[1][4] Other sanctions: The standard itself does not prescribe penalties; consequences arise indirectly through contractual breach, failed audits, procurement disqualification, insurer scrutiny, governance findings, or regulatory criticism if a regulated entity represented compliance inaccurately.[1][4][6]

How to Comply

  1. Confirm the version in use. Treat ISO 31000:2018 as the operative edition in 2026 and document that the organization is monitoring the revision project, not claiming a future edition that does not yet exist.[1][2]
  1. Map enterprise risk ownership. Assign board, executive, and business-unit responsibilities for risk oversight and escalation, using governance structures that mirror ISO 31000’s emphasis on integration.[1][12]
  1. Set risk criteria and appetite. Define materiality thresholds, likelihood/impact scales, and decision tolerances so risk decisions are consistent and auditable.[12]
  1. Integrate with existing control frameworks. Where cybersecurity risks are involved, map ISO 31000 to ISO 27001 controls and governance; where organizational governance is broader, use NIST CSF 2.0 to organize identification, protection, detection, response, and recovery; where AI systems are in scope, align the risk process with ISO 42001 for AI management-system governance.
  1. Create a repeatable risk process. Standardize identification, analysis, evaluation, treatment, and review so business units use the same method and reporting format.[12]
  1. Document decisions and exceptions. Keep evidence of risk acceptance, treatment plans, residual-risk approvals, and follow-up actions to support internal audit and external assurance.
  1. Train leadership and operators. Ensure managers understand how risk criteria, escalation paths, and reporting obligations work so risk management becomes part of day-to-day decisions.[1][12]
  1. Review against change triggers. Reassess the framework after acquisitions, major incidents, regulatory change, strategic pivots, or significant technology deployment, then update as needed.

Related Regulations

  • ISO 27001 overlaps with ISO 31000 because it provides a certifiable information-security management system, while ISO 31000 gives broader risk-management principles that can support security governance.
  • ISO 42001 overlaps where AI governance is relevant, because AI management systems need risk controls that can be organized using ISO 31000’s generic framework.
  • NIST CSF 2.0 overlaps operationally because it offers a cybersecurity risk framework, but it is a guidance framework rather than a legal obligation.
  • COSO ERM overlaps conceptually because both focus on enterprise risk management, but COSO is a framework and ISO 31000 is an international guideline.
  • Sector-specific regulations such as banking, critical infrastructure, or privacy laws may conflict only if they impose prescriptive controls that go beyond ISO 31000’s flexible, principles-based approach.

FAQ

Does ISO 31000 apply to companies outside the country where it was published?

Yes. ISO 31000 is an international standard and is not limited to one jurisdiction.[1][4] Its applicability depends on whether an organization chooses it voluntarily or is required to use it by contract, regulator, or policy.

Is ISO 31000 certifiable?

No. ISO 31000 is a guideline standard, not a certifiable management-system standard.[1][4] Organizations can be assessed against it informally or through audits, but ISO does not run a certification scheme for ISO 31000 itself.

Is there a new ISO 31000 edition in 2026?

No published new edition is in force as of 2026.[1][2][6] ISO’s public catalogue still shows ISO 31000:2018 as the current published standard, while a revision project is under development.[1][2]

What changed in ISO 31000:2018 compared with the 2009 edition?

The 2018 edition was described by ISO as more strategic, with greater emphasis on senior management involvement and integration of risk management into the organization.[12][14] The current edition also reduced and clarified the principles and updated the framework language.

Are there legal penalties for not following ISO 31000?

Not directly from ISO 31000 itself.[1][4] Penalties only arise if the standard is incorporated into a legal requirement, contract, procurement rule, or other enforceable obligation.

How should a company prepare for the next revision?

Maintain a version-controlled risk framework aligned to ISO 31000:2018, track ISO’s revision process, and avoid hard-coding implementation details that would become obsolete if the new edition changes terminology or structure.[2][6] Organizations with mature programs should be able to update mapping tables and governance documents quickly once ISO publishes the next edition.

Sources

Put it into practice

More compliance guides