Compliance · Guidance standard
One way to talk about risk across the whole business.
ISO 31000 gives you principles and a framework for managing risk of any kind — strategic, operational, financial, security. Unlike most standards on this page, it is guidance and explicitly not intended for certification. Its value is coherence, not a certificate.
Guidance
Not certifiable
All risk
Scope
Principles
+ framework + process
A common language and method so risk decisions are comparable across the organization.
Risk management should be integrated, structured, customized, inclusive, and dynamic — not a quarterly spreadsheet ritual disconnected from decisions.
Leadership commitment, integration into governance, and the design/implement/evaluate/improve loop that keeps it alive.
Establish context and risk criteria, then identify, analyze, evaluate, treat, monitor, and communicate — consistently, so risks can actually be compared.
Organizations where every function measures risk differently and none of it adds up.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We define likelihood and impact scales that mean the same thing in every department — the step most programs skip.
We build an assessment method that's rigorous enough to defend and light enough that people use it.
We stand up a risk register with owners, treatments, and dates that actually move.
We wire risk into your ISO 27001 ISMS and real decisions, not a parallel universe.
We build board and management reporting that supports decisions instead of decorating them.
We set the cadence for reviewing risk as the business changes.
Establish scope, objectives, and consistent risk criteria.
Define how risks are identified, analyzed, and evaluated.
Run assessments and build the register.
Assign owners, treatments, and dates.
Review, report, and improve on a set cadence.
No — and be cautious of anyone selling it. ISO 31000 is guidance, and the standard itself states it is not intended for certification purposes. You can align to it, be audited against your own framework, and certify individuals in risk practice, but there is no organizational ISO 31000 certificate.
Because it makes risk comparable. When security, finance, and operations all rate risk differently, leadership can't prioritize. ISO 31000 gives one language and method — and it supplies the risk discipline ISO 27001 requires but doesn't fully define.
27001 mandates a risk assessment and treatment process but leaves the methodology to you. ISO 31000 is the most common way to fill that gap, which also means your security risks land in the same register as everything else.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.