ISO 31000: The Risk Management Framework That Underpins Everything
Most compliance frameworks tell you to “manage risk” — but they don’t tell you how. That’s what ISO 31000 is for. It’s the international standard for managing risk of any kind — cyber, financial, operational, strategic — and it gives every risk-based obligation you have a common backbone. You can’t certify to it, and that’s the point: it’s guidance, not an auditable checklist.
Three parts: principles, framework, process
| Component | What it covers |
|---|---|
| Principles | What good risk management looks like — integrated, structured, tailored, inclusive, dynamic, and focused on creating and protecting value. |
| Framework | How risk management is embedded and governed: leadership commitment, integration, design, implementation, evaluation and improvement. |
| Process | The repeatable cycle: scope & context → risk assessment (identify, analyse, evaluate) → risk treatment → monitoring, review, communication and recording. |
Why it matters even though you can’t certify
ISO 27001, DORA, APRA CPS 234, NIST and virtually every governance framework demand a risk assessment and a risk-treatment decision. If each of those uses a different method and register, you end up with fragmented, incomparable risk data. Adopt ISO 31000 as your house method and every framework’s risk requirement is satisfied from one consistent process — with one risk register, one scoring approach, one language the board understands.
The process, in practice
- Establish scope and context — what you’re assessing, your criteria, and your risk appetite/tolerance.
- Identify risks — sources, events, causes and potential consequences, not just IT threats.
- Analyse — likelihood and impact, using consistent criteria so risks are comparable.
- Evaluate — compare against criteria and appetite to decide which risks need treatment and in what order.
- Treat — choose to avoid, reduce, share/transfer or accept; record owners and actions (this is your risk-treatment plan).
- Monitor, review, communicate and record — keep it living, and keep the evidence.
Common pitfalls
- A risk register that’s a graveyard — created for an audit, never reviewed. ISO 31000 is explicit that the process must be dynamic.
- Scoring theatre — elaborate heat maps with no defined criteria behind the numbers, so “high” means nothing consistent.
- Treating risk as an IT-only exercise — ISO 31000 is deliberately all-hazards; strategic and operational risks belong too.
- No link to appetite — risks get analysed but there’s no stated tolerance to evaluate them against, so prioritisation is arbitrary.
The bottom line
ISO 31000 won’t appear on a certificate, but it’s the connective tissue beneath every framework that asks you to manage risk. Adopt it as your single method and your ISO 27001, DORA, and enterprise risk work all draw from one living register — consistent, comparable, and board-ready.
One risk register, every framework
Cyber Horizon’s risk module runs an ISO 31000-aligned process — one register, consistent scoring, and treatment plans that feed straight into your ISO 27001 SoA, DORA and board reporting.
Book a Demo