Standards › ISO 31000

Guidance standard — not certifiable

ISO 31000 — Risk Management

ISO 31000 is a guidance standard. This is a guidance standard. Organisations cannot hold accredited certification against it.

International guidance on risk management principles and process. It is a guidance standard: organisations cannot be certified against ISO 31000.

What it covers

Principles for effective risk management, a framework for integrating it into governance and decision-making, and a process for identifying, analysing, evaluating and treating risk.

Who it is for

Boards and managers who want one coherent way of handling risk across safety, commercial, programme and corporate decisions — and anyone building risk-based thinking into ISO 9001/14001/45001 systems.

Key requirement themes

  • Risk management integrated into decisions, not run beside them
  • A defined framework: mandate, integration, design, implementation, evaluation, improvement
  • A common process: scope, context, criteria; assessment; treatment; monitoring; recording
  • Communication and consultation throughout

Theme-level description in our own words — the standard itself defines the requirements, and no standard text is reproduced here.

Construction-sector relevance

Useful as the connective tissue between commercial risk registers, project risk reviews and H&S risk assessment — one vocabulary and one escalation route instead of three unconnected ones.

Benefits

  • Consistent risk language across the business
  • Better-informed bid and programme decisions
  • Strengthens the risk-based thinking your certifiable standards expect

Common gaps we find

  • Risk registers maintained for ceremony, not decisions
  • Safety and commercial risk never connected
  • No defined risk criteria or appetite

Typical documents

  • Risk management framework description
  • Risk criteria
  • Risk registers with owners and treatments
  • Review records

Typical evidence

  • Decisions recording the risk basis
  • Treatments completed and reviewed

Related standards

Certifiable standard

ISO 9001 — Quality Management

The international standard for quality management systems: consistent processes, controlled documents, measured performance and evidenced improvement.

Certifiable standard

ISO 45001 — Occupational Health & Safety

The international standard for occupational health and safety management systems. It replaced OHSAS 18001, which was withdrawn when migration ended in 2021.

Certifiable standard

ISO 22301 — Business Continuity

The international standard for business continuity management systems: keep priority activities running through disruption, and recover in a planned way.

Questions we are actually asked

Can we get ISO 31000 certified?

No. ISO 31000 is guidance — there is no accredited certification against it. Anyone offering "ISO 31000 certification" of an organisation should be treated with caution.

Then why use it?

Because the certifiable standards all expect risk-based thinking but none tells you how to run risk management as a discipline. ISO 31000 is the how.

How does it relate to project risk registers?

It gives the register a process around it: defined criteria, ownership, treatment and review, connected to decisions rather than filed beside them.

Professional disclaimer: this page is orientation, not advice on your specific circumstances, and not a reproduction of any standard. Implementation support, templates and platform tools do not confer certification or legal compliance; certification decisions rest solely with independent certification bodies, and legal duties apply regardless of certification.