Risk & remediation

The ISO 31000 risk management process, step by step

ISO 31000:2018 clause 6 sets out one process for any kind of risk. Here is what each step asks for, what it produces and how it looks in a real risk register.

Expert reviewedChecked against ISO 31000:2018 Risk management — Guidelines · by Aishwarya ·

Short answer

The ISO 31000 risk management process in clause 6 of ISO 31000:2018 has six parts: communication and consultation; scope, context and criteria; risk assessment (identification, analysis and evaluation); risk treatment; monitoring and review; and recording and reporting. The steps repeat rather than run once, and each produces a record an auditor or board can follow.

Key takeaways

  • ISO 31000 defines risk as the effect of uncertainty on objectives, so every risk ties back to an objective.
  • Set risk criteria before assessing anything; they decide which risks need treatment.
  • Risk assessment is three steps: identify, analyse, evaluate.
  • Communication, monitoring and recording run alongside every step, not after it.

Where the process sits in ISO 31000

ISO 31000:2018 has three parts: eight principles (clause 4), a framework that embeds risk management in governance (clause 5) and the process (clause 6). The process is the part teams run day to day. It is the same whether the risk is a supplier failure, a data breach or a missed strategic target.

ClauseStepMain output
6.2Communication and consultationStakeholder list, consultation records
6.3Scope, context and criteriaScope statement, risk criteria (likelihood and impact scales, appetite)
6.4.2Risk identificationRisk register entries with source, event and consequence
6.4.3Risk analysisLikelihood, consequence and level for each risk
6.4.4Risk evaluationDecision: treat, accept or monitor
6.5Risk treatmentTreatment plan with owner, action and due date
6.6Monitoring and reviewReview records, updated ratings
6.7Recording and reportingRisk reports to management and the board

1. Scope, context and criteria

Decide what the process covers (an organisation, a project, a product line) and which objectives are at stake. Then set risk criteria: the likelihood and consequence scales, how they combine into a risk level, and the level above which a risk must be treated. Writing criteria first stops each assessor from rating risks on a private scale.

2. Risk assessment: identify, analyse, evaluate

Identification finds risks that could help or prevent the achievement of objectives. A useful entry names the source (an ageing payment platform), the event (an outage at month end) and the consequence (missed settlements and regulatory notice). Analysis rates likelihood and consequence and notes existing controls. Evaluation compares the result with the criteria and decides what happens next.

IEC 31010:2019 describes dozens of assessment techniques, from structured interviews and bow-tie analysis to Monte Carlo simulation. Most organisations need two or three: workshops for identification, a 5×5 matrix for analysis, and scenario analysis for the few risks that matter most.

3. Risk treatment

ISO 31000 lists treatment options rather than the familiar four Ts: avoid the risk, take or increase it to pursue an opportunity, remove the source, change the likelihood, change the consequences, share it (for example through insurance or contracts) or retain it by informed decision. Each treatment needs an owner, a due date and a statement of the residual risk expected afterwards.

4. Monitoring, review, recording and reporting

Risks change, controls drift and treatments slip. Schedule reviews by risk level, record what changed and why, and report to the people who set the criteria. A risk register that shows its review history is the clearest evidence that the process runs.

Checklist

ISO 31000 process evidence

0 of 6 done

Put this into practice on QULDEX

Frequently asked questions

How many steps are in the ISO 31000 risk management process?

Six parts in clause 6: communication and consultation; scope, context and criteria; risk assessment (identification, analysis and evaluation); risk treatment; monitoring and review; and recording and reporting.

Is ISO 31000 certifiable?

No. ISO 31000 is a guideline, not a requirements standard, so organisations cannot be certified against it. They can be assessed for alignment with it.

Which risk assessment techniques does ISO 31000 recommend?

ISO 31000 does not prescribe techniques. It points to IEC 31010:2019, which describes dozens, including interviews, checklists, bow-tie analysis, risk matrices and Monte Carlo simulation.

Sources

  1. ISO 31000:2018 Risk management — Guidelines, ISO
  2. IEC 31010:2019 Risk management — Risk assessment techniques, ISO
  3. NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments, NIST