Short answer
The ISO 31000 risk management process in clause 6 of ISO 31000:2018 has six parts: communication and consultation; scope, context and criteria; risk assessment (identification, analysis and evaluation); risk treatment; monitoring and review; and recording and reporting. The steps repeat rather than run once, and each produces a record an auditor or board can follow.
Key takeaways
- ISO 31000 defines risk as the effect of uncertainty on objectives, so every risk ties back to an objective.
- Set risk criteria before assessing anything; they decide which risks need treatment.
- Risk assessment is three steps: identify, analyse, evaluate.
- Communication, monitoring and recording run alongside every step, not after it.
Where the process sits in ISO 31000
ISO 31000:2018 has three parts: eight principles (clause 4), a framework that embeds risk management in governance (clause 5) and the process (clause 6). The process is the part teams run day to day. It is the same whether the risk is a supplier failure, a data breach or a missed strategic target.
| Clause | Step | Main output |
|---|---|---|
| 6.2 | Communication and consultation | Stakeholder list, consultation records |
| 6.3 | Scope, context and criteria | Scope statement, risk criteria (likelihood and impact scales, appetite) |
| 6.4.2 | Risk identification | Risk register entries with source, event and consequence |
| 6.4.3 | Risk analysis | Likelihood, consequence and level for each risk |
| 6.4.4 | Risk evaluation | Decision: treat, accept or monitor |
| 6.5 | Risk treatment | Treatment plan with owner, action and due date |
| 6.6 | Monitoring and review | Review records, updated ratings |
| 6.7 | Recording and reporting | Risk reports to management and the board |
1. Scope, context and criteria
Decide what the process covers (an organisation, a project, a product line) and which objectives are at stake. Then set risk criteria: the likelihood and consequence scales, how they combine into a risk level, and the level above which a risk must be treated. Writing criteria first stops each assessor from rating risks on a private scale.
2. Risk assessment: identify, analyse, evaluate
Identification finds risks that could help or prevent the achievement of objectives. A useful entry names the source (an ageing payment platform), the event (an outage at month end) and the consequence (missed settlements and regulatory notice). Analysis rates likelihood and consequence and notes existing controls. Evaluation compares the result with the criteria and decides what happens next.
IEC 31010:2019 describes dozens of assessment techniques, from structured interviews and bow-tie analysis to Monte Carlo simulation. Most organisations need two or three: workshops for identification, a 5×5 matrix for analysis, and scenario analysis for the few risks that matter most.
3. Risk treatment
ISO 31000 lists treatment options rather than the familiar four Ts: avoid the risk, take or increase it to pursue an opportunity, remove the source, change the likelihood, change the consequences, share it (for example through insurance or contracts) or retain it by informed decision. Each treatment needs an owner, a due date and a statement of the residual risk expected afterwards.
4. Monitoring, review, recording and reporting
Risks change, controls drift and treatments slip. Schedule reviews by risk level, record what changed and why, and report to the people who set the criteria. A risk register that shows its review history is the clearest evidence that the process runs.
Checklist
ISO 31000 process evidence
0 of 6 done
Put this into practice on QULDEX
Frequently asked questions
How many steps are in the ISO 31000 risk management process?
Six parts in clause 6: communication and consultation; scope, context and criteria; risk assessment (identification, analysis and evaluation); risk treatment; monitoring and review; and recording and reporting.
Is ISO 31000 certifiable?
No. ISO 31000 is a guideline, not a requirements standard, so organisations cannot be certified against it. They can be assessed for alignment with it.
Which risk assessment techniques does ISO 31000 recommend?
ISO 31000 does not prescribe techniques. It points to IEC 31010:2019, which describes dozens, including interviews, checklists, bow-tie analysis, risk matrices and Monte Carlo simulation.