ISO 31000
Definition
ISO 31000
ISO 31000 is the international guidance on risk management, describing principles, a framework and a process for handling uncertainty. It is deliberately non-certifiable, so a provider claiming an ISO 31000 certificate is offering something the standard does not.
That last sentence is the most commercially useful fact about the standard.
Certificates get claimed anyway — some providers mean their staff hold a training qualification, others have simply misunderstood what they bought. Either way it is a question worth asking in a first meeting.
What the standard genuinely offers is a common method: a way to describe how risk gets identified, assessed and treated, so two organisations can compare notes without inventing vocabulary.
Key takeaways
- ISO 31000:2018 is guidance on risk management, not an auditable requirements standard.
- DNV states plainly that it is a non-certifiable standard.
- An organisation can align to it, apply it, or train staff in it, but cannot be certified against it.
- Its value in outsourcing is a shared method for describing risk, not a badge.
How it works
ISO 31000 sets out three components: principles that describe what good risk management looks like, a framework for embedding it, and a process for carrying it out. DNV describes it as guidelines and principles for identifying, assessing and managing risks.
The certification point is explicit. DNV states that ISO 31000 is a non-certifiable standard and that it provides a reference framework behind the requirements of other standards.
That places it alongside other voluntary structures rather than alongside auditable ones. The United States cybersecurity framework works the same way: a shared organising structure that nobody certifies against, published and maintained by NIST.
So the comparison a buyer should make is not “does this provider have ISO 31000” but “can this provider describe its risk process in terms I recognise”.
Individuals can hold risk-management qualifications that reference the standard. That is a training record, and it belongs in a different column from an organisational certificate.
| Claim you may hear | What it can legitimately mean |
|---|---|
| “We are ISO 31000 certified” | Nothing — no such certification exists |
| “We are aligned to ISO 31000” | The risk process follows the standard’s structure |
| “Our risk team is ISO 31000 trained” | Individuals hold a training qualification |
| “We apply ISO 31000 principles” | A claim you can test by asking for the risk register |
| “Our ISO 9001 audit covers risk” | Risk-based thinking was audited under a different standard |
The bottom row is where genuine assurance usually lives. Auditable standards embed risk thinking — ISO 31000 explains it.
Examples
Risk vocabulary travels badly between organisations, which is exactly the problem this standard was written to solve. What follows are live deployments, with the awkward parts deliberately left in.
A buyer asks three providers how they manage delivery risk and receives three incompatible answers. A shared method would have made the responses comparable, which is the practical argument for risk outsourcing frameworks generally.
A provider’s tender response claims ISO 31000 certification. The buyer asks which body issued it and the claim quietly disappears from the revised submission.
A financial services client requires its provider to maintain a risk register in a defined format. That is the standard’s substance without the certificate, and it is enforceable because it sits in the contract.
A manufacturer uses the standard’s process to structure supplier reviews, so its own business risk reporting and its suppliers’ reporting use the same categories.
Related terms
Risk terminology spans a standard, a role, a service line and a contractual instrument, and the four get used interchangeably. The entries here are kept small, because a generous definition is a useless one.
- Risk outsourcing: transferring exposure to a third party, which is a commercial act rather than a method.
- Business risk: the underlying category of threats to objectives that the method addresses.
- Risk analyst: the role performing the assessment work, whatever framework the employer uses.
- Compliance outsourcing: buying regulatory capability, which is narrower than managing risk.
- ISO certification: the audit mechanism that this particular standard sits outside.
- Business continuity plan (BCP): planning for one specific risk category, disruption.
- Vendor management outsourcing: running supplier assurance, where this method is most often applied.
FAQ
Can a company be ISO 31000 certified?
No. It is guidance rather than a requirements standard, and DNV describes it directly as non-certifiable. Any certificate claim should be questioned.
What can a provider legitimately claim?
That it is aligned to the standard, applies its principles, or has trained staff. Each of those is testable by asking to see the risk process.
Which edition is current?
ISO 31000:2018, which replaced the 2009 original and restructured the guidance around principles, framework and process.
How does it differ from ISO 27001?
ISO 27001 is an auditable specification for information security. ISO 31000 is general risk guidance that other standards draw on.
Is it useful in outsourcing at all?
Yes, as a shared method. It lets a buyer and provider describe risk in the same terms, which makes supplier comparisons meaningful.
What should I ask for instead of a certificate?
The risk register, the assessment criteria, and how often the register is reviewed. Those show whether the method is actually running.
Compare source partners in the Outsource Accelerator hubs directory and treat a risk framework as a method, not a credential.







Independent




