ISO 31000:2018
Process – ISO 31000:2018

ISO 31000:2018 6.3.2: Defining the scope

Guidance: the organization should set out what its risk management activities cover. Because the process can run at strategic, operational, programme, project or other levels, it should be clear which scope is under consideration, which objectives are relevant and how they align with the organization's objectives. Planning the approach should consider the objectives and decisions to be made; the outcomes expected from the steps; time, location and specific inclusions and exclusions; the assessment tools and techniques that fit; the resources needed, the responsibilities and the records to keep; and the links to other projects, processes and activities.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 10 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 9 controls

  • 5.4.4 Determining audit programme resources
  • 5.5.2 Defining the objectives, scope and criteria for an individual audit
  • 5.5.5 Assigning responsibility for an individual audit to the audit team leader
  • 6.3.3 Assigning work to audit team
  • 6.4.9 Determining audit conclusions
  • 6.5.2 Distributing audit report
  • 7.2 Determining auditor competence
  • 7.2.4 Achieving auditor competence
  • 7.6 Maintaining and improving auditor competence

ISO/IEC 23894:2023 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Process – ISO 31000:2018

Query this from an agent

The graph holds this control, the 10 it maps to, and the evidence behind each claim, over MCP and REST.