ISO 31000
Risk management guidelines and principles
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
ISO 31000: Risk Assessment
Identifying and analyzing risks (ISO 31000)
| Code | Title |
|---|---|
| ISO31000-06 | Risk identification methods |
| ISO31000-07 | Risk analysis and evaluation |
| ISO31000-08 | Risk criteria and thresholds |
| ISO31000-09 | Risk scenario development |
| ISO31000-10 | Risk interdependency analysis |
ISO 31000: Risk Framework & Governance
Establishing risk management framework (ISO 31000)
| Code | Title |
|---|---|
| ISO31000-01 | Risk management policy and scope |
| ISO31000-02 | Risk governance structure |
| ISO31000-03 | Risk culture and communication |
| ISO31000-04 | Stakeholder requirements for risk |
| ISO31000-05 | Risk management integration |
ISO 31000: Risk Monitoring & Review
Ongoing monitoring and review of risks (ISO 31000)
| Code | Title |
|---|---|
| ISO31000-16 | Risk monitoring procedures |
| ISO31000-17 | Risk reporting and communication |
| ISO31000-18 | Risk register maintenance |
| ISO31000-19 | Continuous improvement of risk processes |
| ISO31000-20 | Management review of risk program |
ISO 31000: Risk Treatment
Treating and managing identified risks (ISO 31000)
| Code | Title |
|---|---|
| ISO31000-11 | Risk treatment options and selection |
| ISO31000-12 | Risk treatment plan development |
| ISO31000-13 | Residual risk acceptance |
| ISO31000-14 | Risk transfer and insurance |
| ISO31000-15 | Control implementation and monitoring |
Maps to 419 other frameworks
Frequently Asked Questions
What is ISO 31000?
ISO 31000 is a compliance framework from International with 4 domains and 20 controls. Risk management guidelines and principles It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO 31000 have?
ISO 31000 has 20 controls organised across 4 domains. The largest domains are ISO 31000: Risk Assessment (5 controls), ISO 31000: Risk Framework & Governance (5 controls), ISO 31000: Risk Monitoring & Review (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO 31000 map to?
ISO 31000 maps to 419 other compliance frameworks. The top mapping partners are EASA Part-IS — Information Security in Aviation (35% coverage), COSO ERM (35% coverage), ISO 27005 (35% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO 31000 compliance?
Start your ISO 31000 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 31000 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 20 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required