Back to Frameworks

ISO 31022:2020

International
v2020 (first edition)
3 domains
24 controls

ISO 31022:2020 gives guidelines for managing legal risk, the risk related to legal, regulatory and contractual matters and to non-contractual rights and obligations (illegal conduct, duty of care, intellectual property), as a complement to ISO 31000 for any organization. Clause 4 recasts the ISO 31000 principles for legal risk (integration into governance and decision-making, a structured and customised approach reflecting the legal environment and conflict of laws, inclusion that preserves legal privilege, dynamic monitoring of legal change, the best available legal information, human and cultural factors, continual improvement) and adds equity. Clause 5 runs the ISO 31000 process for legal risk: external context (laws by jurisdiction, extraterritoriality, third parties, regulators and media) and internal context (entity structure, contracts, rights, duty of care, transaction liabilities, dispute history); legal risk criteria agreed with management and never so narrow that legal is engaged only in a crisis; identification through a methodology, a register and a process for new and changed laws; analysis of causes, likelihood and consequences with the correlation to other risks; evaluation against the criteria including reputation, values, maturity and negotiating leverage; treatment options with key risk indicators (contract liability against value, executed contracts against deals, sales against compliance training), residual-risk acceptance and a plan of policies, standard practices, contract templates, notifications and training; and communication that preserves privilege, learning, monitoring with early warning and pattern analysis, and record-keeping under privilege, retention, chain-of-evidence and access rules. Clause 6 embeds the discipline: a policy, assigned roles and functions with counsel available to risk owners, integration into all activities, resources and awareness. Annexes give an identification matrix, a register, likelihood and consequence approaches and key contract clauses.

Verified

ISO 31022:2020 is a compliance framework from International with 3 domains and 24 controls. The largest domains are Clause 5: Legal risk management process – ISO 31022:2020 (17 controls), Clause 6: Implementation of the management of legal risk – ISO 31022:2020 (6 controls), Clause 4: Principles – ISO 31022:2020 (1 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (3)

Clause 4: Principles – ISO 31022:2020

1 controls
Controls in the Clause 4: Principles – ISO 31022:2020 domain of ISO 31022:20201 controls
CodeTitle
iso-31022-2020::4Principles: the eight ISO 31000 principles applied to legal risk, plus equity

Clause 5: Legal risk management process – ISO 31022:2020

17 controls
Controls in the Clause 5: Legal risk management process – ISO 31022:2020 domain of ISO 31022:202017 controls
CodeTitle
iso-31022-2020::5.1General: the legal risk management process
iso-31022-2020::5.2.1General: context and criteria beyond ISO 31000
iso-31022-2020::5.2.2External context of legal risk
iso-31022-2020::5.2.3Internal context of legal risk
iso-31022-2020::5.2.4Defining the legal risk criteria
iso-31022-2020::5.3.1General: assessment of legal risk
iso-31022-2020::5.3.2Identification of legal risk
iso-31022-2020::5.3.3Analysis of legal risk
iso-31022-2020::5.3.4Evaluation of legal risk
iso-31022-2020::5.4.1General: treatment of legal risk
iso-31022-2020::5.4.2Choosing options for the treatment of legal risk
iso-31022-2020::5.4.3Evaluation of the current practices for the treatment of legal risk
iso-31022-2020::5.4.4Development and implementation of the risk treatment plan
iso-31022-2020::5.5.1General: communication and reporting mechanisms
iso-31022-2020::5.5.2Communication, consultation and learning
iso-31022-2020::5.5.3Monitoring and review
iso-31022-2020::5.5.4Recording and reporting

Clause 6: Implementation of the management of legal risk – ISO 31022:2020

6 controls
Controls in the Clause 6: Implementation of the management of legal risk – ISO 31022:2020 domain of ISO 31022:20206 controls
CodeTitle
iso-31022-2020::6.1General: embedding the management of legal risk
iso-31022-2020::6.2Policy for the management of legal risk
iso-31022-2020::6.3Roles and functions for the management of legal risk
iso-31022-2020::6.4Integrating the management of legal risk
iso-31022-2020::6.5Resource allocation for the management of legal risk
iso-31022-2020::6.6Awareness of legal risk

What is ISO 31022:2020 and who does it apply to?

ISO 31022:2020 is a compliance framework from International with 3 domains and 24 controls. ISO 31022:2020 gives guidelines for managing legal risk, the risk related to legal, regulatory and contractual matters and to non-contractual rights and obligations (illegal conduct, duty of care, intellectual property), as a complement to ISO 31000 for any organization. Clause 4 recasts the ISO 31000 principles for legal risk (integration into governance and decision-making, a structured and customised approach reflecting the legal environment and conflict of laws, inclusion that preserves legal privilege, dynamic monitoring of legal change, the best available legal information, human and cultural factors, continual improvement) and adds equity. Clause 5 runs the ISO 31000 process for legal risk: external context (laws by jurisdiction, extraterritoriality, third parties, regulators and media) and internal context (entity structure, contracts, rights, duty of care, transaction liabilities, dispute history); legal risk criteria agreed with management and never so narrow that legal is engaged only in a crisis; identification through a methodology, a register and a process for new and changed laws; analysis of causes, likelihood and consequences with the correlation to other risks; evaluation against the criteria including reputation, values, maturity and negotiating leverage; treatment options with key risk indicators (contract liability against value, executed contracts against deals, sales against compliance training), residual-risk acceptance and a plan of policies, standard practices, contract templates, notifications and training; and communication that preserves privilege, learning, monitoring with early warning and pattern analysis, and record-keeping under privilege, retention, chain-of-evidence and access rules. Clause 6 embeds the discipline: a policy, assigned roles and functions with counsel available to risk owners, integration into all activities, resources and awareness. Annexes give an identification matrix, a register, likelihood and consequence approaches and key contract clauses. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO 31022:2020 actually require?

ISO 31022:2020 has 24 controls organised across 3 domains. The largest domains are Clause 5: Legal risk management process – ISO 31022:2020 (17 controls), Clause 6: Implementation of the management of legal risk – ISO 31022:2020 (6 controls), Clause 4: Principles – ISO 31022:2020 (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO 31022:2020 do I already cover?

ISO 31022:2020 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO 31022:2020?

Start your ISO 31022:2020 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 31022:2020 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required