ISO 31000
is a generic risk management standard. It was developed by ISO Technical
Committee 262, Risk Management. ISO 31000: 2018 was published in February of
2018 and is the second edition of this ISO standard. It cancels and replaces
the ISO 31000: 2009 standard which is now obsolete. It was updated in order to
streamline the content and in order to respond to changing stakeholder needs
and expectations. It outlines a generic approach to risk management, which can
be applied to different types of risks (financial, safety, project risks) and
used by any type of organization. The standard provides a uniform vocabulary
and concepts for discussing risk management. ISO 31000:2018 Risk management –
Principles and guidelines has been revised to provide clear and concise
procedures to help organizations improve planning, and manage factors that
threaten their objectives. The ISO 31000:2018 version places an emphasis on
protecting value as the key driver of risk management. It also highlights other
principles such as continual improvement, the inclusion of stakeholders, and
human and cultural factors. “The revised version of ISO 31000 focuses on the integration with the organization
and the role of leaders and their responsibility,†he said in a press release.
“Risk practitioners are often at the margins of organizational management and
this emphasis will help them demonstrate that risk management is an integral
part of business.†The updated standard defines risk as “the effect of
uncertainty on objectivesâ€. It highlights the impact of incomplete knowledge of
circumstances on an organization’s decision making. It provides guidelines and
principles that can help to undertake a critical review of your organization’s
risk management process. ISO 31000 suggests that effective risk management is
characterized by principles, framework and process. The ISO 31000 guidelines
are centered on leadership and commitment. The effectiveness of risk management
will depend on its integration into all aspects of the organization, including decision-making.
The remaining components of the framework are design, implementation,
evaluation and improvement. This approach is often represented in management
literature as plan-do-check-act. The main changes to ISO 31000:2018 include:
*Review of
risk management principles.
*Focus on
top management – leaders must ensure that risk management underpins governance
and all other organizational activities.
*Greater
focus on the iterative nature of risk management, actions and controls at each
stage of the process.
*Simplify
content with more emphasis on sustaining an open systems model that exchanges
feedback with external stakeholders to fit multiple needs and contexts.
User questions & answers