ISO 31000:2018
Process – ISO 31000:2018

ISO 31000:2018 6.7: Recording and reporting

Guidance: the process and what it produces should be recorded and reported by suitable means, in order to communicate risk activity and results throughout the organization, inform decisions, improve risk management, and support interaction with stakeholders including those accountable for risk management. Decisions about creating, retaining and handling documented information should consider its use, its sensitivity and the context. Reporting is part of governance and should raise how well the organization talks with its stakeholders and help top management and oversight bodies meet their responsibilities; it should consider the different stakeholders and their information needs, the cost, frequency and timeliness of reporting, the method, and the relevance of the information to objectives and decisions.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 9 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 19011:2018 · 5 controls

  • 5.7 Reviewing and improving audit programme
  • 6.4.10 Conducting closing meeting
  • 6.5 Preparing and distributing audit report
  • 6.5.1 Preparing audit report
  • 6.5.2 Distributing audit report

ISO/IEC 23894:2023 · 3 controls

  • 23894-6.7 Recording and Reporting
  • ISO23894-6.6 Recording and Reporting
  • 6.7 Recording and reporting
  • 27557-6.6 Recording and reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Process – ISO 31000:2018

Query this from an agent

The graph holds this control, the 9 it maps to, and the evidence behind each claim, over MCP and REST.