ISO 31000:2018
Process – ISO 31000:2018

ISO 31000:2018 6.3.3: External and internal context

Guidance: the internal and external context is the setting in which the organization defines and pursues its objectives. The context in which the process is applied should come from an understanding of that environment and should match the particular setting of the activity the process is applied to, because risk management happens against the organization's objectives and activities, organizational factors can themselves be a source of risk, and the purpose and scope of the process may be linked to the organization's overall objectives. The organization should set the context by considering the same external and internal factors listed for framework design in 5.4.1.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 1 control

  • 7.2.5 Achieving audit team leader competence

ISO/IEC 23894:2023 · 1 control

  • 6.3.3 External and internal context

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Process – ISO 31000:2018

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.