• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » ISO 31000

ISO 31000

Definition

ISO 31000

ISO 31000 is the international guidance on risk management, describing principles, a framework and a process for handling uncertainty. It is deliberately non-certifiable, so a provider claiming an ISO 31000 certificate is offering something the standard does not.

That last sentence is the most commercially useful fact about the standard.

Certificates get claimed anyway — some providers mean their staff hold a training qualification, others have simply misunderstood what they bought. Either way it is a question worth asking in a first meeting.

What the standard genuinely offers is a common method: a way to describe how risk gets identified, assessed and treated, so two organisations can compare notes without inventing vocabulary.

Key takeaways

  • ISO 31000:2018 is guidance on risk management, not an auditable requirements standard.
  • DNV states plainly that it is a non-certifiable standard.
  • An organisation can align to it, apply it, or train staff in it, but cannot be certified against it.
  • Its value in outsourcing is a shared method for describing risk, not a badge.

How it works

ISO 31000 sets out three components: principles that describe what good risk management looks like, a framework for embedding it, and a process for carrying it out. DNV describes it as guidelines and principles for identifying, assessing and managing risks.

The certification point is explicit. DNV states that ISO 31000 is a non-certifiable standard and that it provides a reference framework behind the requirements of other standards.

That places it alongside other voluntary structures rather than alongside auditable ones. The United States cybersecurity framework works the same way: a shared organising structure that nobody certifies against, published and maintained by NIST.

So the comparison a buyer should make is not “does this provider have ISO 31000” but “can this provider describe its risk process in terms I recognise”.

Individuals can hold risk-management qualifications that reference the standard. That is a training record, and it belongs in a different column from an organisational certificate.

Claim you may hearWhat it can legitimately mean
“We are ISO 31000 certified”Nothing — no such certification exists
“We are aligned to ISO 31000”The risk process follows the standard’s structure
“Our risk team is ISO 31000 trained”Individuals hold a training qualification
“We apply ISO 31000 principles”A claim you can test by asking for the risk register
“Our ISO 9001 audit covers risk”Risk-based thinking was audited under a different standard

The bottom row is where genuine assurance usually lives. Auditable standards embed risk thinking — ISO 31000 explains it.

Examples

Risk vocabulary travels badly between organisations, which is exactly the problem this standard was written to solve. What follows are live deployments, with the awkward parts deliberately left in.

A buyer asks three providers how they manage delivery risk and receives three incompatible answers. A shared method would have made the responses comparable, which is the practical argument for risk outsourcing frameworks generally.

A provider’s tender response claims ISO 31000 certification. The buyer asks which body issued it and the claim quietly disappears from the revised submission.

A financial services client requires its provider to maintain a risk register in a defined format. That is the standard’s substance without the certificate, and it is enforceable because it sits in the contract.

A manufacturer uses the standard’s process to structure supplier reviews, so its own business risk reporting and its suppliers’ reporting use the same categories.

Related terms

Risk terminology spans a standard, a role, a service line and a contractual instrument, and the four get used interchangeably. The entries here are kept small, because a generous definition is a useless one.

FAQ

Can a company be ISO 31000 certified?

No. It is guidance rather than a requirements standard, and DNV describes it directly as non-certifiable. Any certificate claim should be questioned.

What can a provider legitimately claim?

That it is aligned to the standard, applies its principles, or has trained staff. Each of those is testable by asking to see the risk process.

Which edition is current?

ISO 31000:2018, which replaced the 2009 original and restructured the guidance around principles, framework and process.

How does it differ from ISO 27001?

ISO 27001 is an auditable specification for information security. ISO 31000 is general risk guidance that other standards draw on.

Is it useful in outsourcing at all?

Yes, as a shared method. It lets a buyer and provider describe risk in the same terms, which makes supplier comparisons meaningful.

What should I ask for instead of a certificate?

The risk register, the assessment criteria, and how often the register is reviewed. Those show whether the method is actually running.

Compare source partners in the Outsource Accelerator hubs directory and treat a risk framework as a method, not a credential.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image