ISO 31000 · Risk Management
Most organisations already have a risk register. The problem is not its existence, but how it is used: a document reviewed once a year ahead of an audit, listing generic risks (‘reputational risk’, ‘operational risk’) with no clear link to specific decisions. ISO 31000 does not require another document — it requires risk management to be a dynamic process, integrated into the way the organisation makes decisions, not a separate compliance exercise.
Defined risk appetite. Without clear criteria on how much risk the organisation is prepared to accept in each category, each risk in the register lacks a decision-making context — it is merely a list.
Indicators that predict, not just record. KRIs (key risk indicators) linked to alert thresholds enable action to be taken before a risk materialises, rather than simply documenting it after the event.
Actionable executive report. Management needs to view risk and decision-making as a single entity — not a 40-row table, but a clear overview of what falls outside the defined risk appetite and what to do about it.
The standard organises risk management into three mutually reinforcing components: principles (risk management creates and protects value, is integrated into all processes, and is tailored to the organisation’s context); a framework that assigns clear leadership and responsibility to senior management; and an iterative process for identifying, analysing, assessing and addressing risk, with ongoing communication and monitoring.
In practice, this means that risk management is not the responsibility of a single department — senior management sets the risk appetite and tone, and each business area applies the process within its own context.
A risk maturity assessment quickly identifies what is already in place (risk register, committees, policies) and the most critical gaps: typically, the absence of a formalised risk appetite and KRIs linked to that appetite. From there, designing the framework, defining indicators and establishing a regular executive report transform the risk register into a decision-making tool — and risk management into a genuine source of organisational resilience.
Frequently Asked Questions