ISO 31000
ISO 31000 is an international standard that offers general guidelines for managing risk, providing a set of principles, a framework, and a process that organizations can use regardless of their size, sector, or activity. According to the evidence, it is intended to support decision-making and activities across all levels of an organization. Note that the standard is published by ISO alone (not jointly with IEC), and per one source it is described as not certifiable.
ISO 31000 (current edition ISO 31000:2018, 'Risk management — Guidelines') is a voluntary international standard issued by the International Organization for Standardization that provides principles, a framework, and a process for managing risk. Per the evidence, the guidelines are designed to be customizable to any organization and its context, and to support all activities including decision-making across organizational levels. The evidence indicates the standard was developed in November 2009 and is described in one source as not certifiable. It is important to designate this standard correctly as ISO 31000 (published by ISO) rather than as a joint 'ISO/IEC 31000'; the evidence does not support an IEC co-designation. This entry is scoped to enterprise/organizational risk management as reflected in the provided sources; it does not address AI-specific application, sector-specific interpretations, or how ISO 31000 relates to other frameworks, as such details are outside the evidence packet.
Why it matters
ISO 31000 matters because it provides a common vocabulary and a structured approach to risk management that organizations can apply regardless of size, sector, or activity. As a voluntary international standard published by the International Organization for Standardization, it offers principles, a framework, and a process that can be customized to an organization's specific context, helping to bring consistency and discipline to how risks are identified, assessed, and treated. For professionals working in governance and risk functions, this shared reference point can support clearer communication about risk across organizational levels.
A point of particular practical significance is that, according to one source in the evidence, ISO 31000 is described as not certifiable. This distinguishes it from management system standards against which organizations can be formally audited and certified. Professionals should be careful not to treat adherence to ISO 31000 as something that yields a certificate; rather, it functions as guidance that organizations may adopt and adapt. Misrepresenting the standard as certifiable, or conflating it with certifiable standards, can create compliance and communication risks.
Correct designation also matters. The standard is ISO 31000, published solely by ISO, and it should not be referred to as a joint 'ISO/IEC 31000'. Precise naming avoids confusion with jointly issued ISO/IEC standards and helps ensure that references in policies, audit documentation, and contracts point to the correct instrument.
Who it's relevant to
Inside ISO 31000
Common questions
Answers to the questions practitioners most commonly ask about ISO 31000.