ISO 31000:2018
Framework – ISO 31000:2018

ISO 31000:2018 5.2: Leadership and commitment

Guidance: top management, and oversight bodies where they exist, should make sure risk management is integrated into every organizational activity and should show their commitment by customizing and implementing the whole framework, issuing a policy or statement that sets the approach, allocating the resources, and assigning authority, responsibility and accountability at the right levels. Doing so aligns risk management with objectives, strategy and culture; recognizes every obligation and voluntary commitment; establishes how much and what kind of risk may be taken so that risk criteria can be set and communicated; communicates the value of managing risk; promotes systematic monitoring; and keeps the framework fit for the organization's context. Accountability for managing risk rests with top management; oversight bodies are accountable for overseeing it, which usually means ensuring risks are considered when objectives are set, understanding the risks the organization faces, ensuring the systems for managing them work, judging whether those risks are appropriate to the objectives, and ensuring risk information is properly communicated.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 36 controls across 28 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 23894:2023 · 3 controls

  • 23894-5.2 Leadership and Commitment
  • ISO23894-5.1 Leadership and Commitment
  • 5.2 Leadership and commitment
  • ISO-37002-5.1 Leadership and commitment
  • ISO37002-5.1 Leadership and Commitment
  • ISO-39001-5.1 Leadership and commitment
  • ISO39001-5.1 Leadership and Commitment
  • ISO-41001-5.1 Leadership and commitment
  • ISO41001-5.1 Leadership and Commitment
  • ISO-50001-5.1 Leadership and commitment
  • 5.1 Leadership and commitment

ISO 56002 · 2 controls

  • ISO-56002-5.1 Leadership and commitment
  • ISO56002-5.1 Leadership and commitment

ISO/IEC 27003:2017 · 2 controls

  • 27003-5.1 Leadership and Commitment
  • ISO27003-5.1 Leadership and commitment
  • AS9100D-5.1 Leadership and Commitment
  • BS65000-5.1 Leadership Commitment

ISO 14001:2015 · 1 control

  • 5.1 Leadership and commitment

ISO 14004:2016 · 1 control

  • 5.1 Leadership and commitment

ISO 19011:2018 · 1 control

  • 7.2 Determining auditor competence
  • ISO-20400-5.1 Commitment from leadership

ISO 22000:2018 · 1 control

  • 5.1 Leadership and commitment

ISO 22301:2019 · 1 control

  • 5.1 Leadership and commitment
  • ISO-22313-5.1 Leadership and commitment

ISO 27005:2022 · 1 control

  • 10.2 Leadership and commitment

ISO 27701:2019 · 1 control

  • 5.3.1 Leadership and commitment

ISO 30401 · 1 control

  • ISO30401-5.1 Leadership and commitment

ISO 37001:2016 · 1 control

  • 5.1 5.1 Leadership and commitment

ISO 37301:2021 · 1 control

  • 5.1 Leadership and commitment

ISO 45001:2018 · 1 control

  • 5.1 Leadership and commitment

ISO 55001:2014 · 1 control

  • 5.1 Leadership and commitment

ISO 9001:2015 · 1 control

  • 5.1 Leadership and commitment
  • 27557-5.1 Leadership and commitment

ISO/IEC 42001:2023 · 1 control

  • 5.1 Leadership and commitment
  • NFPA1600-4.1 Leadership and Commitment
  • 0007 0007 Accountable Authority manages the entity's security risks

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Framework – ISO 31000:2018

Query this from an agent

The graph holds this control, the 36 it maps to, and the evidence behind each claim, over MCP and REST.