ISO 31000 helps organizations develop a risk management strategy to effectively identify and mitigate risks, thereby enhancing the likelihood of achieving their objectives and increasing the protection of their assets. Its overarching goal is to develop a risk management culture where employees and stakeholders are aware of the importance of monitoring and managing risk. Risk is a necessary part of doing business, and in a world where enormous amounts of data are being processed at increasingly rapid rates, identifying and mitigating risks is a challenge for any company. In order to keep ISO 31000 relevant in the changing environment the technical committee created a revision. This new version is available from the middle of February 2018. Each section of the standard was reviewed in the spirit of clarity, using simpler language to facilitate understanding and make it accessible to all stakeholders. The 2018 version places a greater focus on creating and protecting value as the key driver of risk management and features other related principles such as continual improvement, the inclusion of stakeholders, being customized to the organization and consideration of human and cultural factors.The risk management team has gained a comprehensive knowledge of the risk types that can be faced by the organization and the principles of risk management; they can start designing an appropriate risk management framework with the support and leadership of the organization’s top management. ISO 31000 can be applied throughout the life of an organization, and to a wide range of activities, including strategies and decisions, operations, processes, functions, projects, products, services and assets. The design and implementation of risk management plans and frameworks will need to take into account the varying needs of a specific organization, its particular objectives, context, structure, operations, processes, functions, projects, products, services, or assets and specific practices employed. Review of the principles of risk management, which are the key criteria for its success. Focus on leadership by top management who should ensure that risk management is integrated into all organizational activities, starting with the governance of the organization. Streamlining of the content with greater focus on sustaining an open systems model that regularly exchanges feedback with its external environment to fit multiple needs and contexts. Greater emphasis on the iterative nature of risk management, drawing on new experiences, knowledge and analysis for the revision of process elements, actions and controls at each stage of the process. The revised version of ISO 31000 focuses on the integration with the organization and the role of leaders and their responsibility.
User questions & answers