Quick Answer:

ISO 31000 is the international standard for risk management, published by ISO and used worldwide. It gives any organisation a common set of principles, a framework and a process for managing risk of any kind. It is guidance, not a certifiable requirement, so you align your risk management to it rather than get audited against it. Its roots are Australian: ISO 31000 grew out of AS/NZS 4360, the world’s first risk-management standard, published in 1995.

ISO 31000 is the standard almost everyone in risk management points to and almost nobody explains simply.

This guide fixes that. It covers what ISO 31000 is, what it actually contains, whether you can be certified against it, and a fact most people miss: the world’s most widely used risk standard began in Australia and New Zealand.

Sentrient is an Australian-built GRC platform for compliance, risk and HR. See our risk management system and workplace compliance system, built for Australian and New Zealand workplaces.

What Is ISO 31000?

ISO 31000 is the international standard for risk management, published by the International Organization for Standardization.

It sets out a shared way for any organisation, of any size and in any sector, to manage risk of any kind, not just financial or safety risk. The current version is the 2018 revision.

As the world’s reference risk management standard, its purpose is to make risk management consistent and deliberate rather than ad hoc.

The standard does not tell you what your risks are or how much risk to accept. It gives you the principles, structure and process to work that out and manage it well, and it connects naturally to broader governance, risk and compliance practice.

That consistency is rarer than you might think. In the AICPA and CIMA and NC State State of Risk Oversight study, only around 37% of organisations reported having a complete, formal risk management process in place, and fewer than a third rated their risk oversight as mature.

A shared standard like ISO 31000 is how a business moves from managing risk in scattered, one-off ways to a single approach it can repeat and defend.

What ISO 31000 Covers: Principles, Framework and Process

The standard is built around three connected parts. Understanding them is the whole standard in a nutshell.

Part What it means
Principles The qualities of good risk management: it should be integrated, structured, tailored, inclusive, dynamic and based on the best available information, and it should create and protect value
Framework How risk management is led and embedded across the organisation, through leadership, integration, design, implementation, evaluation and improvement
Process The practical steps: set the scope and context, assess risk (identify, analyse, evaluate), treat it, then monitor, review, record and communicate throughout

The process at the centre is the part most people recognise, and it is the same discipline behind a good workplace risk assessment, scaled to the whole organisation.

How ISO 31000 Defines Risk

The standard defines risk as the effect of uncertainty on objectives. That wording is deliberate and worth pausing on. Risk is not only the chance of something bad.

It is any way uncertainty can move you away from what you are trying to achieve, which can include missed opportunities as well as threats.

Anchoring risk to objectives is what keeps risk work connected to the business rather than sitting in a separate register nobody reads.

Can You Be Certified to ISO 31000?

No, and this trips people up. It is guidance, not a set of auditable requirements, so you cannot be certified against it the way you can with a management-system standard.

You align your risk management to it and can say you follow it, but there is no ISO 31000 certificate.

That is by design. The standard is meant to be adapted to your context, not passed as a test. If a vendor claims to be certified to it, treat that as a red flag about how well they understand the standard.

ISO 31000 vs ISO 27001 and ISO 45001

This is the difference that matters in practice. ISO 27001 (information security) and ISO 45001 (work health and safety) are management-system standards with specific requirements you can be independently certified against. The risk standard is not.

It is the overarching risk-management guidance that sits beneath and alongside them.

In short: you get certified to ISO 27001 or ISO 45001, and you apply the risk standard to how you manage risk across all of it.

The Australian Roots: From AS/NZS 4360 to ISO 31000

Here is the part that should make Australian businesses sit up. In 1995, Standards Australia and Standards New Zealand published AS/NZS 4360, the first formal risk-management standard published anywhere in the world. That first standard was revised in 1999 and 2004.

In 2005 the International Organization for Standardization began work on a global risk standard and used AS/NZS 4360:2004 as its starting draft.

That became ISO 31000, published in 2009 and revised in 2018. So the risk-management vocabulary now used worldwide, and sold back to Australian businesses by global vendors, was written here first. ISO 31000 is not a foreign import. It is a homegrown idea that went global.

How to Use ISO 31000 in a Small or Mid Business

You do not need to adopt the whole standard formally to benefit from it. For most small and mid-sized Australian organisations, using it well means three things:

  • Tie risks to objectives. Ask what could stop you achieving each goal, rather than listing generic risks
  • Run one consistent process. Identify, analyse, evaluate, treat, then monitor and review, the same way every time
  • Keep it living. Record risks with owners and review dates, and revisit them when things change, so the register reflects reality

Done this way, the standard is not bureaucracy. It is a simple, defensible habit that makes your risk management consistent and your decisions easier to justify.

Where Sentrient Fits

Sentrient gives Australian businesses a practical way to run the standard’s process without enterprise complexity, so the standard becomes a habit rather than a project. It holds a risk register with owners and review dates, links risks to the incidents and controls that test them, and keeps the records retrievable for audits and reporting, so risk management is consistent, current and provable.

Being straight about scope: aligning to the standard is about how you work, not a piece of software. What Sentrient does is make that way of working easy to sustain and evidence, alongside the rest of your governance, risk and compliance.

See ISO 31000 risk management running in one place.

The Short Version

ISO 31000 is the world’s reference standard for risk management: principles, a framework and a process for managing the effect of uncertainty on your objectives. You align to it rather than get certified against it, it works at any size, and it started in Australia and New Zealand. Use it as a simple, consistent habit, and it will make your risk decisions clearer and easier to defend.

General information for Australian businesses, not professional risk advice. How you apply ISO 31000 depends on your industry, size and circumstances. Confirm current requirements with a qualified adviser before relying on this. Correct as at August 2026.

Frequently Asked Questions

1. What is ISO 31000?

ISO 31000 is the international standard for risk management, published by ISO. It provides principles, a framework and a process that any organisation can use to manage risk of any kind. The current version is the 2018 revision, and it applies to businesses of any size and sector.

2. Can you be certified to ISO 31000?

No. It is guidance, not an auditable management-system standard, so there is no certification against it. You align your risk management to it and can say you follow it, but there is no certificate. A claim of certification against it is a red flag.

3. What are the three parts of ISO 31000?

Principles, framework and process. The principles describe good risk management, the framework covers how it is led and embedded across the organisation, and the process sets out the practical steps: scope and context, risk assessment, treatment, and ongoing monitoring, review, recording and communication.

4. How does ISO 31000 define risk?

As the effect of uncertainty on objectives. This includes both threats and missed opportunities, and it ties risk to what the organisation is trying to achieve rather than treating it as a separate exercise.

5. What is the difference between ISO 31000 and ISO 27001?

ISO 27001 (information security) is a management-system standard with specific requirements you can be certified against. It is overarching risk-management guidance you cannot be certified against. You apply it to how you manage risk, including the risks that standards like ISO 27001 and ISO 45001 address.

6. Where did ISO 31000 come from?

It grew out of AS/NZS 4360, the world’s first risk-management standard, published by Standards Australia and Standards New Zealand in 1995. AS/NZS 4360:2004 was used as the first draft for the international standard, which became ISO 31000 in 2009 and was revised in 2018.

7. Do small businesses need ISO 31000?

Not formally, but the ideas are valuable at any size. Tie risks to your objectives, run one consistent identify-analyse-evaluate-treat-monitor process, and keep a living risk register with owners and review dates. That is the standard in practice, without the bureaucracy.

Sources