ISO 31022:2020
ISO 31022:2020 gives guidelines for managing legal risk, the risk related to legal, regulatory and contractual matters and to non-contractual rights and obligations (illegal conduct, duty of care, intellectual property), as a complement to ISO 31000 for any organization. Clause 4 recasts the ISO 31000 principles for legal risk (integration into governance and decision-making, a structured and customised approach reflecting the legal environment and conflict of laws, inclusion that preserves legal privilege, dynamic monitoring of legal change, the best available legal information, human and cultural factors, continual improvement) and adds equity. Clause 5 runs the ISO 31000 process for legal risk: external context (laws by jurisdiction, extraterritoriality, third parties, regulators and media) and internal context (entity structure, contracts, rights, duty of care, transaction liabilities, dispute history); legal risk criteria agreed with management and never so narrow that legal is engaged only in a crisis; identification through a methodology, a register and a process for new and changed laws; analysis of causes, likelihood and consequences with the correlation to other risks; evaluation against the criteria including reputation, values, maturity and negotiating leverage; treatment options with key risk indicators (contract liability against value, executed contracts against deals, sales against compliance training), residual-risk acceptance and a plan of policies, standard practices, contract templates, notifications and training; and communication that preserves privilege, learning, monitoring with early warning and pattern analysis, and record-keeping under privilege, retention, chain-of-evidence and access rules. Clause 6 embeds the discipline: a policy, assigned roles and functions with counsel available to risk owners, integration into all activities, resources and awareness. Annexes give an identification matrix, a register, likelihood and consequence approaches and key contract clauses.
ISO 31022:2020 is a compliance framework from International with 3 domains and 24 controls. The largest domains are Clause 5: Legal risk management process – ISO 31022:2020 (17 controls), Clause 6: Implementation of the management of legal risk – ISO 31022:2020 (6 controls), Clause 4: Principles – ISO 31022:2020 (1 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (3)
Clause 4: Principles – ISO 31022:2020
| Code | Title |
|---|---|
| iso-31022-2020::4 | Principles: the eight ISO 31000 principles applied to legal risk, plus equity |
Clause 5: Legal risk management process – ISO 31022:2020
| Code | Title |
|---|---|
| iso-31022-2020::5.1 | General: the legal risk management process |
| iso-31022-2020::5.2.1 | General: context and criteria beyond ISO 31000 |
| iso-31022-2020::5.2.2 | External context of legal risk |
| iso-31022-2020::5.2.3 | Internal context of legal risk |
| iso-31022-2020::5.2.4 | Defining the legal risk criteria |
| iso-31022-2020::5.3.1 | General: assessment of legal risk |
| iso-31022-2020::5.3.2 | Identification of legal risk |
| iso-31022-2020::5.3.3 | Analysis of legal risk |
| iso-31022-2020::5.3.4 | Evaluation of legal risk |
| iso-31022-2020::5.4.1 | General: treatment of legal risk |
| iso-31022-2020::5.4.2 | Choosing options for the treatment of legal risk |
| iso-31022-2020::5.4.3 | Evaluation of the current practices for the treatment of legal risk |
| iso-31022-2020::5.4.4 | Development and implementation of the risk treatment plan |
| iso-31022-2020::5.5.1 | General: communication and reporting mechanisms |
| iso-31022-2020::5.5.2 | Communication, consultation and learning |
| iso-31022-2020::5.5.3 | Monitoring and review |
| iso-31022-2020::5.5.4 | Recording and reporting |
Clause 6: Implementation of the management of legal risk – ISO 31022:2020
| Code | Title |
|---|---|
| iso-31022-2020::6.1 | General: embedding the management of legal risk |
| iso-31022-2020::6.2 | Policy for the management of legal risk |
| iso-31022-2020::6.3 | Roles and functions for the management of legal risk |
| iso-31022-2020::6.4 | Integrating the management of legal risk |
| iso-31022-2020::6.5 | Resource allocation for the management of legal risk |
| iso-31022-2020::6.6 | Awareness of legal risk |
What is ISO 31022:2020 and who does it apply to?
ISO 31022:2020 is a compliance framework from International with 3 domains and 24 controls. ISO 31022:2020 gives guidelines for managing legal risk, the risk related to legal, regulatory and contractual matters and to non-contractual rights and obligations (illegal conduct, duty of care, intellectual property), as a complement to ISO 31000 for any organization. Clause 4 recasts the ISO 31000 principles for legal risk (integration into governance and decision-making, a structured and customised approach reflecting the legal environment and conflict of laws, inclusion that preserves legal privilege, dynamic monitoring of legal change, the best available legal information, human and cultural factors, continual improvement) and adds equity. Clause 5 runs the ISO 31000 process for legal risk: external context (laws by jurisdiction, extraterritoriality, third parties, regulators and media) and internal context (entity structure, contracts, rights, duty of care, transaction liabilities, dispute history); legal risk criteria agreed with management and never so narrow that legal is engaged only in a crisis; identification through a methodology, a register and a process for new and changed laws; analysis of causes, likelihood and consequences with the correlation to other risks; evaluation against the criteria including reputation, values, maturity and negotiating leverage; treatment options with key risk indicators (contract liability against value, executed contracts against deals, sales against compliance training), residual-risk acceptance and a plan of policies, standard practices, contract templates, notifications and training; and communication that preserves privilege, learning, monitoring with early warning and pattern analysis, and record-keeping under privilege, retention, chain-of-evidence and access rules. Clause 6 embeds the discipline: a policy, assigned roles and functions with counsel available to risk owners, integration into all activities, resources and awareness. Annexes give an identification matrix, a register, likelihood and consequence approaches and key contract clauses. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 31022:2020 actually require?
ISO 31022:2020 has 24 controls organised across 3 domains. The largest domains are Clause 5: Legal risk management process – ISO 31022:2020 (17 controls), Clause 6: Implementation of the management of legal risk – ISO 31022:2020 (6 controls), Clause 4: Principles – ISO 31022:2020 (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 31022:2020 do I already cover?
ISO 31022:2020 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO 31022:2020?
Start your ISO 31022:2020 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 31022:2020 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required