Most risk frameworks are written for auditors. They are long, jargon-heavy, and designed to satisfy a compliance checklist rather than help a team actually manage risk. ISO 31000 is different. It is a practical standard built for anyone who manages risk — regardless of organisation size, sector, or how mature their risk function is. And it is the lens KinetiRisk was designed around from day one.
What is ISO 31000:2018?
ISO 31000:2018 — formally titled "Risk management — Guidelines" — is an international standard published by the International Organisation for Standardisation. Unlike ISO 27001 or SOC 2, it is not a certification scheme. There is no audit, no badge, no accreditation body. It is a set of principles and guidelines that organisations of any size or sector can use to build a coherent, consistent approach to managing risk.
That distinction matters. Because ISO 31000 is not about passing an assessment — it is about embedding better thinking into how your organisation works. A construction firm and a fintech startup can both use it. A team of five and a team of five thousand can both apply it. The standard is deliberately technology-agnostic and sector-agnostic, which is what makes it genuinely universal.
The 2018 edition replaced the original 2009 version with a sharper focus on leadership, integration, and making risk management part of how decisions are actually made — not a separate process that runs alongside the business and gets consulted once a quarter. The revision also placed greater emphasis on the human side of risk: that culture, behaviour, and accountability are not soft considerations but foundational ones.
Who Uses ISO 31000?
Because it is sector-agnostic, ISO 31000 shows up wherever there is a project or a decision worth managing systematically: construction firms use it to structure site and supply-chain risk, financial services teams reference it alongside their regulatory obligations, government and public-sector programmes adopt it as the default risk vocabulary for major projects, and IT and software teams use it to bring consistency to delivery risk. If your project involves an industry field on sign-up — the way KinetiRisk asks what sector your organisation operates in — that context exists specifically so AI-assisted scoring reflects the risk patterns of your industry rather than a generic checklist.
At its core, ISO 31000 rests on 8 principles. Get those principles right and everything else — the framework, the process, the risk register software — follows naturally.
The 8 Principles
The standard defines 8 attributes that effective risk management must have. These are not steps in a process — they are qualities that should be present at every stage, in every decision. Each one is expanded below with a project example and how KinetiRisk enforces it, then summarised in the table that follows.
1. Integrated
Risk management is not a separate function — it is woven into every organisational process, decision, and level of governance. Risk thinking happens alongside planning and delivery, not after. A programme manager applying this principle would review open risks as a standing item in the same meeting where schedule and budget are discussed, rather than in a separate quarterly risk board that nobody else attends. KinetiRisk enforces it structurally: the Portfolio → Programme → Project hierarchy means a risk logged at project level rolls up automatically, so it is never siloed from the decisions it should inform.
2. Structured & Comprehensive
A consistent, repeatable approach that produces comparable and reliable results across every part of the organisation. The same scoring means the same thing whether applied in one project or fifty. A finance-sector PM and a construction-sector PM working for the same organisation should be able to compare a P×I of 12 on their respective registers and trust it means the same level of exposure. KinetiRisk applies one standardised probability-times-impact model across every project in every programme, so that comparison is always valid.
3. Customised
The framework is adapted to the organisation's specific context, objectives, and risk appetite — not a one-size-fits-all template applied blindly regardless of industry or scale. A five-person consultancy and a five-hundred-person infrastructure client should not be filling in the same generic risk form. KinetiRisk grounds every AI analysis in the specific project description and the organisation's industry before it suggests a score, so the output reflects the actual domain rather than a template.
4. Inclusive
Stakeholders at every level are appropriately involved, informed, and heard. Risk is not identified by one person in a silo — the people closest to the work surface it, and the people responsible for decisions own it. A construction PM applying the Inclusive principle would invite the site safety officer into the risk review, not just the project board, since the safety officer sees hazards the board never will. KinetiRisk supports this with role-based project membership and named mitigation owners, so every risk has a specific accountable person rather than a shared inbox.
5. Dynamic
Risk management anticipates and responds as context, information, and circumstances change. A risk register that was accurate six months ago and has not been touched since is not risk management — it is documentation. A PM applying this principle re-scores a supplier risk the moment a supplier issues a profit warning, rather than waiting for the next scheduled review. KinetiRisk's escalation logic fires the instant a P×I reaches the project's threshold, and review reminders surface risks that are overdue for a fresh look.
6. Best Available Information
Decisions are based on explicit, timely, and well-reasoned evidence. Crucially, the standard also requires that the limitations and uncertainties of that evidence are acknowledged — not hidden. A PM applying this principle would note in the risk description that a probability estimate is based on early supplier feedback rather than a confirmed schedule, so reviewers know how much weight to give it. KinetiRisk's AI scoring always comes with a plain-English rationale attached, so the reasoning behind a number is visible, not buried.
7. Human & Cultural Factors
People, behaviour, and accountability are central. The standard recognises that risk is owned by humans, not systems, and that cultural norms inside an organisation will shape how honestly risk is surfaced. A PM applying this principle actively encourages junior team members to log risks without fear that doing so reflects badly on them. KinetiRisk is human-in-the-loop by design: the AI proposes, but no risk is confirmed or escalated without a named reviewer's deliberate approval.
8. Continual Improvement
The organisation learns from experience, reviews its approach, and improves its risk management capability over time. This requires records — you cannot improve what you cannot measure. A PM applying this principle would look back at closed risks at the end of a project to see which mitigation strategies actually worked, rather than starting the next project's register from a blank sheet. KinetiRisk records every change to every risk with a timestamp and the identity of who made it, so that review is a query, not an archaeology exercise.
| Principle | In practice | KinetiRisk feature |
|---|---|---|
| Integrated | Risk reviewed alongside schedule and budget, not in a separate meeting | Portfolio → Programme → Project hierarchy, automatic roll-up |
| Structured & Comprehensive | The same score means the same exposure in every project | One standardised P×I model applied everywhere |
| Customised | Risk process reflects the organisation's own context and scale | AI analysis grounded in project description and industry |
| Inclusive | People closest to the work surface risks, named owners act on them | Role-based membership, named mitigation owners |
| Dynamic | Risks are re-scored as circumstances change, not left static | Automatic escalation, review reminders |
| Best Available Information | Evidence and its limitations are stated explicitly | AI reasoning shown in plain English with every score |
| Human & Cultural Factors | Accountability sits with a named person, not a system | Human-in-the-loop review before any risk is confirmed |
| Continual Improvement | Past decisions are reviewable, not lost after the project closes | Full risk change history with timestamp and author |
The ISO 31000 Framework
The principles say what good risk management looks like. The framework is how you build the thing that delivers it. This is the part most summaries skip, and it is the part auditors ask about, because it is where responsibility actually sits.
- Leadership and commitment
- The standard puts this at the centre deliberately. Risk management that is not visibly owned at the top becomes an administrative exercise, and ISO 31000 treats that as a failure of the framework rather than of the people running it.
- Integration
- Risk management belongs inside how decisions are made, not alongside them. If your risk process runs in parallel with the real work and is consulted quarterly, it is not integrated.
- Design
- Understanding the organisation and its context, articulating commitment, assigning roles and authority, and allocating the resources to make it work.
- Implementation
- Turning the design into an actual plan: who does what, when, and by what mechanism. The standard expects this to be deliberate rather than assumed.
- Evaluation
- Periodically measuring the framework against its own purpose. Not whether risks were logged, but whether the framework is achieving what it was designed to achieve.
- Improvement
- Continually adapting the framework as the organisation and its context change. This closes the loop back to the Dynamic and Continual Improvement principles.
The ISO 31000 Risk Management Process
This is the operational core of the standard and the part a project or programme manager works through week to week. It is a cycle rather than a checklist: six core activities plus two continuous activities that run alongside all of them rather than appearing once in sequence.
1. Communication and Consultation
Runs throughout, not at the end. Bringing in the people who understand the risk and the people who will live with the consequences. This is the activity most often skipped, and the reason registers end up owned by one person rather than reflecting the whole team's view of exposure. It is one of the two continuous activities in the process, alongside monitoring and review.
2. Scope, Context and Criteria
Defining what is in scope, what external and internal factors apply, and crucially what your risk criteria are. Criteria set before scoring starts are the difference between a comparable portfolio and a collection of opinions. A project that skips this step ends up rescoring risks halfway through once someone finally asks what a 4 actually means.
3. Risk Identification
Finding and describing risks, including those with no obvious owner. The standard is explicit that you should look for risks whether or not their sources are under your control — a key supplier's financial health is a legitimate project risk even though nobody on the project can directly manage it.
4. Risk Analysis
Understanding likelihood, consequence and the factors driving both. This is where probability and impact scoring sits, and where consistency matters most, since a score that means one thing to one reviewer and something else to another undermines everything downstream of it. We go into the mechanics of this scoring model in our probability × impact matrix post.
5. Risk Evaluation
Comparing the analysis against your criteria to decide what happens next: accept, treat, or escalate for a decision above your level. This is a distinct step from analysis — analysis produces a score, evaluation decides what the score means for action.
6. Risk Treatment
Selecting and implementing options, then assessing what is left. Residual risk is not an afterthought in ISO 31000, it is an explicit output of treatment: the standard expects you to know what exposure remains after mitigation, not just what it was before.
Continuous: Monitoring and Review
Checking that controls remain effective and that scores still reflect reality, rather than reflecting the day the risk was raised. This runs alongside every one of the six activities above, not after them, which is why a register updated once a quarter cannot genuinely claim to be monitoring anything.
Continuous: Recording and Reporting
Documenting the process and its outcomes so decisions can be explained later. This is where risk change history earns its keep: the standard expects traceability, not just a current snapshot. We show what that looks like end to end in a worked risk register example.
Read in sequence, the process explains why spreadsheets struggle with ISO 31000 alignment. Communication, monitoring and recording are all continuous activities, and a document that only changes when somebody remembers to open it cannot support any of the three.
How KinetiRisk Maps to Each Principle
When we built KinetiRisk, we used these 8 principles as design constraints — not marketing language to apply retrospectively. Each one shaped a specific product decision:
- Integrated
- The three-level Portfolio → Programme → Project hierarchy means risk management is embedded at every layer of the organisation. A risk logged at project level automatically rolls up to programme and portfolio views — it is never siloed.
- Structured & Comprehensive
- A standardised P×I scoring model (probability 1–5, impact 1–5) is applied consistently across every project in every programme. A score of 12 means the same thing in a technology project as it does in a regulatory one.
- Customised
- AI analysis is grounded in the project's description, the user's industry, and the organisation's name before a single score is suggested. The output reflects the specific domain, not a generic template.
- Inclusive
- Role-based project membership controls who can see and act on each risk. Every mitigation action is assigned to a named owner. Email notifications go directly to the person responsible — not into a shared inbox.
- Dynamic
- Automated escalation triggers when P×I reaches 15 or above, immediately. Risks move through a defined lifecycle — open, AI review, human review, closed — and the system acts at each transition rather than waiting for a quarterly review. The formal reviewer queue, where escalated risks require sign-off before closing, is available on the Team plan (£25/month).
- Best Available Information
- The AI uses chain-of-thought reasoning to explain why it has assigned a given probability and impact score. Users see the reasoning in plain English alongside the number — and they can override it with their own judgment, which is also recorded.
- Human & Cultural Factors
- KinetiRisk is human-in-the-loop by design. The AI recommends; humans decide. No risk is confirmed escalated without a reviewer's deliberate approval. The system makes accountability explicit and unavoidable.
- Continual Improvement
- Every change to a risk — score, status, ownership, notes — is recorded with a timestamp and the identity of who made the change. Teams can see how their risk posture has evolved and where their process breaks down. Full compliance audit logging is available on the Team plan (£25/month).
KinetiRisk is designed around the ISO 31000 principles — not bolted on after. Start free →
Start free See how it worksWhy This Matters for Busy Teams
Enterprise GRC platforms will tell you they are ISO 31000 aligned too. And technically, they are. But alignment in an enterprise tool means the capability is present somewhere inside a configuration layer that takes six months and an implementation consultant to surface. The principles are there — they are just not the product. They are a destination you configure towards. For a busy team without a dedicated risk function, that is not a usable tool.
KinetiRisk is built so that the principles are the product, not the configuration. The hierarchy is the default structure. The scoring model is the only scoring model. The escalation logic runs automatically. Risk version tracking starts from the first risk logged; full compliance audit logging is available on the Team plan (£25/month). A project manager with no GRC experience can start on day one and be operating inside a fully ISO 31000-aligned framework without ever reading the standard. That is the point: good risk management should feel like good project management, not like compliance work.
Frequently Asked Questions
What are the three components of ISO 31000?
ISO 31000:2018 is built from three parts that work together: the 8 principles, which describe what effective risk management looks like; the framework, which is how an organisation builds and sustains the capability, covering leadership and commitment, integration, design, implementation, evaluation and improvement; and the process, which is the operational cycle people actually work through. Most summaries cover only the principles, which is why teams often understand the ideas but not what to do on Monday morning.
What is the ISO 31000 risk management process?
The process has six activities: communication and consultation; establishing scope, context and criteria; risk assessment, which breaks down into identification, analysis and evaluation; risk treatment; monitoring and review; and recording and reporting. Communication and monitoring run continuously rather than as sequential steps, which is the detail most often missed and the main reason a static spreadsheet struggles to support ISO 31000 alignment.
What is ISO 31000 and who is it for?
ISO 31000:2018 is an international standard for risk management — a set of principles and guidelines that organisations of any size or sector can use to build a coherent approach to managing risk. Unlike ISO 27001 or SOC 2, it is not a certification scheme and there is no audit body. It is a framework for thinking about risk systematically, applicable whether you run a five-person consultancy or a five-thousand-person enterprise.
What are the 8 principles of ISO 31000?
The 8 principles are: Integrated, Structured and Comprehensive, Customised, Inclusive, Dynamic, Best Available Information, Human and Cultural Factors, and Continual Improvement. These are not steps in a process — they are qualities that should be present at every stage of risk management, in every decision, across the whole organisation.
Does ISO 31000 require specific software or AI?
No. ISO 31000 is deliberately technology-agnostic. The standard sets principles for how organisations should think about and manage risk; it does not mandate specific tools. What it does require is that decisions are based on the best available information, that accountability is clearly assigned to named individuals, and that the process is documented well enough to support continual improvement.
How do you know if your risk management process is ISO 31000 aligned?
A well-aligned process has consistent risk scoring applied across all levels of the organisation, clear named ownership for every risk, automated or prompt escalation when risk thresholds are crossed, a full risk change history of decisions and changes, and regular reviews that treat risk as dynamic rather than a one-time assessment at project kick-off. If any of those are missing, there is a gap.
What is the difference between ISO 31000 and ISO 27001?
ISO 31000 is generic risk management guidance covering any type of risk to any organisation — schedule, financial, operational, reputational, and more. ISO 27001 is a certifiable standard scoped specifically to information security, with an accredited audit and certificate at the end of it. The two are complementary rather than competing: an organisation can run ISO 27001-certified information security management inside a broader ISO 31000-aligned approach to risk generally. If you only manage information security risk, ISO 27001 is the relevant standard. If you manage project or programme risk more broadly, ISO 31000 is the one that applies.
Can a small team be ISO 31000 aligned without a GRC platform?
Yes. ISO 31000 does not require specific software, let alone an enterprise GRC platform — it requires consistent scoring, named accountability, timely escalation, and a traceable record of decisions. A small team can meet all of that with a lightweight, purpose-built tool rather than a six-month GRC implementation. KinetiRisk's Free plan covers the core of this: one project, 25 AI analyses a month, automatic escalation, and risk change history, with no card required.
ISO 31000 is not a box-ticking exercise. It is a way of thinking about risk — systematically, consistently, and with clear human accountability at every step. The organisations that get the most value from it are not the ones that can produce a certificate. They are the ones that have genuinely internationalised the 8 principles into how they plan, decide, and act. KinetiRisk is built to make that the default — so your team does it automatically, not manually, and without needing a dedicated risk professional to hold the framework together.
The Dynamic principle is where this is easiest to see in practice: a risk score set at kick-off and never revisited is not dynamic, it is a snapshot. Re-scoring after mitigations are applied — your residual risk — is what keeps a register aligned with the standard rather than just referencing it.
If you want to understand how AI-assisted scoring sits within an ISO 31000-aligned governance structure — with named reviewers, override recording, and a full risk change history — read our post on AI risk scoring and governance.
ISO 31000 is deliberately method-agnostic — it describes what good risk management looks like, not a specific procedure to follow. If your organisation runs a more prescriptive methodology on top of it, the shape is still the same underneath. We have written a separate walkthrough of how KinetiRisk maps to PMBOK's risk knowledge area, which sits inside the same principles covered here.
If your organisation works to PRINCE2 instead, our PRINCE2 risk theme mapping covers proximity, threat and opportunity registers, and escalation to programme in the same ISO 31000-aligned way.