ISO 31000
Risk management guidelines and principles
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (7)
Framework
| Code | Title |
|---|---|
| ISO31000-5.2 | Leadership and commitment |
| ISO31000-5.3 | Integration into the organisation |
| ISO31000-5.4 | Design of framework |
| ISO31000-5.5 | Implementation |
| ISO31000-5.6 | Evaluation |
| ISO31000-5.7 | Improvement |
ISO 31000: Risk Assessment
Identifying and analyzing risks (ISO 31000)
| Code | Title |
|---|---|
| ISO31000-06 | Risk identification methods |
| ISO31000-07 | Risk analysis and evaluation |
| ISO31000-08 | Risk criteria and thresholds |
| ISO31000-09 | Risk scenario development |
| ISO31000-10 | Risk interdependency analysis |
ISO 31000: Risk Framework & Governance
Establishing risk management framework (ISO 31000)
| Code | Title |
|---|---|
| ISO31000-01 | Risk management policy and scope |
| ISO31000-02 | Risk governance structure |
| ISO31000-03 | Risk culture and communication |
| ISO31000-04 | Stakeholder requirements for risk |
| ISO31000-05 | Risk management integration |
ISO 31000: Risk Monitoring & Review
Ongoing monitoring and review of risks (ISO 31000)
| Code | Title |
|---|---|
| ISO31000-16 | Risk monitoring procedures |
| ISO31000-17 | Risk reporting and communication |
| ISO31000-18 | Risk register maintenance |
| ISO31000-19 | Continuous improvement of risk processes |
| ISO31000-20 | Management review of risk program |
ISO 31000: Risk Treatment
Treating and managing identified risks (ISO 31000)
| Code | Title |
|---|---|
| ISO31000-11 | Risk treatment options and selection |
| ISO31000-12 | Risk treatment plan development |
| ISO31000-13 | Residual risk acceptance |
| ISO31000-14 | Risk transfer and insurance |
| ISO31000-15 | Control implementation and monitoring |
Principles
| Code | Title |
|---|---|
| ISO31000-4.1 | Risk management principles overview |
| ISO31000-4.2 | Integrated principle |
| ISO31000-4.3 | Structured and comprehensive principle |
| ISO31000-4.4 | Customised principle |
| ISO31000-4.5 | Inclusive principle |
| ISO31000-4.6 | Dynamic principle |
| ISO31000-4.7 | Best available information principle |
| ISO31000-4.8 | Human and cultural factors principle |
| ISO31000-4.9 | Continual improvement principle |
Process
| Code | Title |
|---|---|
| ISO31000-6.2 | Communication and consultation |
| ISO31000-6.3 | Scope, context and criteria |
| ISO31000-6.4.1 | Risk identification |
| ISO31000-6.4.2 | Risk analysis |
| ISO31000-6.4.3 | Risk evaluation |
| ISO31000-6.5 | Risk treatment |
| ISO31000-6.6 | Monitoring and review |
| ISO31000-6.7 | Recording and reporting |
Your Compliance Coverage
If you comply with ISO 31000, you already cover:
German Supply Chain Due Diligence Act (LkSG)
16%
7 controls mapped
Compare →EASA Part-IS - Information Security in Aviation
16%
7 controls mapped
Compare →ISO 27005
16%
7 controls mapped
Compare →+ 221 more: NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (16%), South Korea ISMS-P (16%)
See all 224 mapped frameworks ↓Maps to 224 other frameworks
Frequently Asked Questions
What is ISO 31000?
ISO 31000 is a compliance framework from International with 7 domains and 43 controls. Risk management guidelines and principles It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO 31000 have?
ISO 31000 has 43 controls organised across 7 domains. The largest domains are Principles (9 controls), Process (8 controls), Framework (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO 31000 map to?
ISO 31000 maps to 224 other compliance frameworks. The top mapping partners are German Supply Chain Due Diligence Act (LkSG) (16% coverage), EASA Part-IS - Information Security in Aviation (16% coverage), ISO 27005 (16% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO 31000 compliance?
Start your ISO 31000 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 31000 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 43 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required