The International Organization for Standardization | November 2009
The International Organization for Standardization (ISO) in Genève started in 2005 the development of a guidance standard on risk management. An ISO working group was established to develop a Committee Draft called ISO CD31000. The standard “gives generic guidelines for the principles and the adequate implementation of risk management. It is not intended to be used for the purposes of certification.”
ISO 31000 seeks to provide a universally recognised paradigm for practitioners and companies employing risk management processes, replacing the myriad of existing standards, methodologies, and paradigms that differ between industries, subject matters, and regions. For this purpose, the recommendations provided in ISO 31000 can be customized to any organisation and its context.
In some respects, ISO 31000 is similar to ISO 9000 and other broad-based international standards. Though it is not certifiable, it is a concise and comprehensive statement which can, in a practical sense, contribute to the awareness and implementation of risk management.

