Resources / From Record-keeping to Resilience

ISO 31000 · Risk Management

From risk registration to resilience: what ISO 31000 requires but which many organisations still fail to do

Keeping a record of risks is the starting point, not the end goal. ISO 31000 sets out a more demanding requirement: to link each identified risk to the organisation’s risk appetite, decision-making and strategy — on an ongoing basis, not just once a year.

The problem of risk records that are frozen in time

Most organisations already have a risk register. The problem is not its existence, but how it is used: a document reviewed once a year ahead of an audit, listing generic risks (‘reputational risk’, ‘operational risk’) with no clear link to specific decisions. ISO 31000 does not require another document — it requires risk management to be a dynamic process, integrated into the way the organisation makes decisions, not a separate compliance exercise.

The three missing elements between registration and resilience

Defined risk appetite. Without clear criteria on how much risk the organisation is prepared to accept in each category, each risk in the register lacks a decision-making context — it is merely a list.

Indicators that predict, not just record. KRIs (key risk indicators) linked to alert thresholds enable action to be taken before a risk materialises, rather than simply documenting it after the event.

Actionable executive report. Management needs to view risk and decision-making as a single entity — not a 40-row table, but a clear overview of what falls outside the defined risk appetite and what to do about it.

How ISO 31000 structures this process

The standard organises risk management into three mutually reinforcing components: principles (risk management creates and protects value, is integrated into all processes, and is tailored to the organisation’s context); a framework that assigns clear leadership and responsibility to senior management; and an iterative process for identifying, analysing, assessing and addressing risk, with ongoing communication and monitoring.

In practice, this means that risk management is not the responsibility of a single department — senior management sets the risk appetite and tone, and each business area applies the process within its own context.

From theory to practice: where to start

A risk maturity assessment quickly identifies what is already in place (risk register, committees, policies) and the most critical gaps: typically, the absence of a formalised risk appetite and KRIs linked to that appetite. From there, designing the framework, defining indicators and establishing a regular executive report transform the risk register into a decision-making tool — and risk management into a genuine source of organisational resilience.

Where do we stand in terms of risk maturity?

A rapid assessment reveals what is already in place and the most critical gaps between the current risk register and a risk-based decision-making system.

Frequently Asked Questions

Common questions about risk management and ISO 31000

Isn’t a risk register enough?

No, if it is limited to a static list reviewed once a year. ISO 31000 calls for continuous management, linked to decision-making and integrated into governance.

What does ‘risk appetite’ mean in practice?

The level of risk that the organisation is prepared to accept in order to achieve its objectives, expressed in specific and measurable terms — not a generic statement.

How do you start implementing ISO 31000?

With a maturity assessment that identifies current capabilities and the most critical gaps: risk appetite, KRIs and actionable executive reporting.

Build resilience. Make better decisions.

Let’s assess your priorities and draw up a practical plan — together.