ISO 31000:2018
Process – ISO 31000:2018

ISO 31000:2018 6.1: General

Guidance: the risk management process applies policies, procedures and practices systematically to each activity from communication and consultation and setting the scope, context and criteria, through the assessment and treatment of risk, to its monitoring and review and its recording and reporting. The process belongs inside management and decision-making, not beside them, and should be built into the organization's structure, operations and processes; it can run at the level of strategy, operations, programmes or projects, and there can be many applications of it at once, each customized to its objectives and context. Because people and culture change and vary, their influence should be kept in view at every step. The process is usually drawn as a sequence and in practice is iterative.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 7 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 4 controls

ISO 13485:2016 · 1 control

  • 4.1 General requirements

ISO 14004:2016 · 1 control

  • 8.1.1 General guidance: Operational control
  • 6.1 General concepts

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Process – ISO 31000:2018

Query this from an agent

The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.