Skip to main content
Category: Risk Assessment & Analysis

ISO 31000

Also known as: ISO 31000:2018, ISO 31000 Risk Management Guidelines
Simply put

ISO 31000 is an international standard that offers general guidelines for managing risk, providing a set of principles, a framework, and a process that organizations can use regardless of their size, sector, or activity. According to the evidence, it is intended to support decision-making and activities across all levels of an organization. Note that the standard is published by ISO alone (not jointly with IEC), and per one source it is described as not certifiable.

Formal definition

ISO 31000 (current edition ISO 31000:2018, 'Risk management — Guidelines') is a voluntary international standard issued by the International Organization for Standardization that provides principles, a framework, and a process for managing risk. Per the evidence, the guidelines are designed to be customizable to any organization and its context, and to support all activities including decision-making across organizational levels. The evidence indicates the standard was developed in November 2009 and is described in one source as not certifiable. It is important to designate this standard correctly as ISO 31000 (published by ISO) rather than as a joint 'ISO/IEC 31000'; the evidence does not support an IEC co-designation. This entry is scoped to enterprise/organizational risk management as reflected in the provided sources; it does not address AI-specific application, sector-specific interpretations, or how ISO 31000 relates to other frameworks, as such details are outside the evidence packet.

Why it matters

ISO 31000 matters because it provides a common vocabulary and a structured approach to risk management that organizations can apply regardless of size, sector, or activity. As a voluntary international standard published by the International Organization for Standardization, it offers principles, a framework, and a process that can be customized to an organization's specific context, helping to bring consistency and discipline to how risks are identified, assessed, and treated. For professionals working in governance and risk functions, this shared reference point can support clearer communication about risk across organizational levels.

A point of particular practical significance is that, according to one source in the evidence, ISO 31000 is described as not certifiable. This distinguishes it from management system standards against which organizations can be formally audited and certified. Professionals should be careful not to treat adherence to ISO 31000 as something that yields a certificate; rather, it functions as guidance that organizations may adopt and adapt. Misrepresenting the standard as certifiable, or conflating it with certifiable standards, can create compliance and communication risks.

Correct designation also matters. The standard is ISO 31000, published solely by ISO, and it should not be referred to as a joint 'ISO/IEC 31000'. Precise naming avoids confusion with jointly issued ISO/IEC standards and helps ensure that references in policies, audit documentation, and contracts point to the correct instrument.

Who it's relevant to

Enterprise risk managers
Risk managers can use ISO 31000's principles, framework, and process as a reference for structuring how risk is identified, assessed, and treated across the organization. Because the guidelines are designed to be customized to an organization's context, they support tailoring rather than a one-size-fits-all approach.
Governance and oversight functions
Those responsible for organizational oversight may find value in the standard's emphasis on supporting decision-making across all levels of an organization, which can help embed risk considerations into governance activities. Note that ISO 31000 addresses organizational risk management generally and does not, within this evidence, speak to AI-specific governance.
Auditors and compliance professionals
Auditors and compliance staff should note that, per the evidence, ISO 31000 is described as not certifiable, so it functions as guidance rather than a standard against which formal certification is granted. Correct designation as ISO 31000 (published by ISO, not as a joint 'ISO/IEC 31000') is important when citing it in documentation.
Policy and standards specialists
Those drafting internal policies or mapping to external standards can reference ISO 31000 as a voluntary international standard providing general risk management guidelines. This entry is scoped to enterprise/organizational risk management as reflected in the sources and does not address how ISO 31000 relates to other frameworks.

Inside ISO 31000

Risk management principles
ISO 31000 sets out a set of principles intended to describe the characteristics of effective and efficient risk management, commonly framed around the idea that risk management should be integrated, structured, customized, and aimed at creating and protecting value. These are stated as guidance for how risk management ought to function rather than as prescriptive, auditable requirements.
Risk management framework
The standard describes a framework component intended to help organizations integrate risk management into governance, leadership, and organizational activities. It is typically described in terms of leadership commitment, integration, design, implementation, evaluation, and improvement, and is meant to be adapted to an organization's context rather than applied uniformly.
Risk management process
ISO 31000 outlines a process for managing risk that commonly includes establishing scope and context, risk assessment (identification, analysis, and evaluation), risk treatment, and supporting activities such as communication, consultation, monitoring, review, and recording and reporting. As commonly presented, these steps are iterative rather than strictly sequential.
Common vocabulary orientation
ISO 31000 is oriented around shared risk terminology. It is frequently used alongside a companion vocabulary resource, though the definitions of specific terms should be confirmed against the current published text rather than assumed.
Scope and applicability
The standard is written to be applicable across organizations of any size, sector, or activity and is not specific to AI systems. It provides general guidance on managing risk and does not by itself constitute a model risk management framework or an AI governance framework, though it can inform both.

Common questions

Answers to the questions practitioners most commonly ask about ISO 31000.

Is ISO 31000 the same as a model risk management framework like SR 11-7?
No. ISO 31000 is a general, organization-wide risk management standard issued by the International Organization for Standardization (ISO). It provides principles and a generic process for managing risk of any kind and is not specific to models. Model risk management guidance—such as the U.S. supervisory guidance commonly referenced as SR 11-7 / OCC 2011-12—addresses the identification, measurement, monitoring, and control of risks arising specifically from the use of models. The two operate at different levels of specificity and origin, and while an organization may align its model risk practices with ISO 31000's principles, the standard does not itself prescribe model validation, benchmarking, or the model-specific controls that model risk management guidance addresses.
Does certifying to ISO 31000 make an organization compliant and its AI risks controlled?
ISO 31000 is generally treated as a guidance standard providing principles and a process rather than a certifiable requirements specification, so it is not typically the basis for certification in the way a management system standard is. Adopting its guidance does not by itself establish legal compliance with any particular regulatory regime, nor does it eliminate risk. Risk management measures described in the standard are intended to help an organization reduce and manage risk, not remove it. Readers should confirm which binding laws, sector guidance, or voluntary standards actually apply to their context, as ISO 31000 does not substitute for those.
How does ISO 31000 relate to AI-specific frameworks an organization may already use?
ISO 31000 offers a general risk management vocabulary and process that can sit above or alongside more AI-specific instruments. Organizations often use it to provide a consistent overarching approach into which narrower AI governance or model risk activities are mapped. Because it is deliberately generic, it does not supply AI-specific controls, terminology, or lifecycle expectations; where such detail is needed, organizations typically supplement it with instruments scoped to AI. The exact way it integrates depends on the frameworks already in place, so the mapping should be established explicitly rather than assumed.
Where does ISO 31000 fit relative to an organization's lines of defense?
ISO 31000 describes risk management principles and process at an organizational level and does not itself dictate a specific three-lines-of-defense structure. In practice, organizations often use its guidance to inform how risk ownership, oversight, and independent assurance are arranged, but the standard should not be read as prescribing who occupies the first, second, or third line. Assigning those roles, and distinguishing operational risk ownership from independent oversight and assurance, remains an organizational design decision that ISO 31000 informs rather than determines.
Can ISO 31000 be used to define inherent versus residual risk in an AI risk assessment?
The standard's process—covering risk identification, analysis, evaluation, and treatment—provides a general structure within which an organization can reason about risk before and after controls are applied. However, precise definitions and calculations of inherent versus residual risk are typically specified within an organization's own methodology rather than fixed by ISO 31000. When implementing, teams should document their definitions explicitly and avoid assuming the standard supplies a single authoritative formulation for these terms.
What are the practical limitations to be aware of when applying ISO 31000 to AI systems?
Because ISO 31000 is intentionally generic and applicable to risk of any type, it does not address AI-specific concerns such as data drift, model performance degradation, explainability, or bias and fairness considerations in a tailored way. Applying it to AI generally requires supplementing its high-level process with AI-specific controls, measurement approaches, and terminology. Organizations should also recognize that the standard's treatment is principle-based, so operational detail, thresholds, and evidence expectations must be developed internally or drawn from more specific instruments.

Common misconceptions

ISO 31000 is a certifiable standard against which organizations can be audited and certified for compliance.
ISO 31000 is commonly described as guidance rather than a requirements standard. It is generally not intended for certification. Organizations should not present alignment with ISO 31000 as a certified compliance status; where certification against a management system is sought, a different type of standard is typically required.
ISO 31000 is an AI-specific standard that provides direct AI governance or model risk management controls.
ISO 31000 is a general, all-hazards risk management guidance document and is not tailored to AI systems. It can inform AI risk practices, but it does not substitute for AI-specific governance structures or model risk management activities, and it does not by itself address concerns such as model performance degradation, bias, or explainability.
Following ISO 31000 eliminates or removes organizational risk.
The standard describes measures intended to help identify, assess, treat, and monitor risk; it is aimed at managing and reducing risk, not eliminating it. Residual risk typically remains after treatment, and the standard's principles are guidance rather than guarantees of any outcome.

Best practices

Use the correct official designation, ISO 31000, and avoid referring to it as a joint ISO/IEC standard in policies, procedures, and communications.
Adapt the framework and process to your organization's context rather than adopting the guidance verbatim, since ISO 31000 is intended to be customized rather than applied uniformly.
Treat ISO 31000 as complementary to, not a replacement for, dedicated AI governance structures and model risk management activities where those are relevant to your organization.
Confirm specific terminology and definitions against the current published text before relying on them, rather than assuming a fixed definition.
Do not represent alignment with ISO 31000 as a certified compliance status, and clarify internally that it functions as guidance rather than an auditable requirements standard.
Document the iterative nature of the risk process—communication and consultation, monitoring and review, and recording and reporting—so that risk management remains an ongoing activity rather than a one-time exercise.