PRIMO is leaving ISO 31000 behind

PRIMO Res Publica | August 2026

The new draft ISO 31000 (2026) is moving further away from PRIMO’s approach to the issue of public values (and their associated risks). The framework remains too organisation-centred, fails to focus on the public domain and lacks the tools for systemic thinking with regard to public values. The framework was launched in 2009 and updated in 2018 in an attempt to give ‘risk’ a central place in the guidelines amidst the many other ISO frameworks. In the public sector, due to its lack of integration with core processes, it has never really taken root in the world of politics and governance. Furthermore, because of its general nature, it is a framework that cannot be certified, unlike other more specialised and specific frameworks, and partly for this reason it is not really usable.

With the new 2026 update on the horizon and the framework appearing to become increasingly isolated within its own world of risk management, it is time for some reflection. The conclusion:

PRIMO Res Publica advises against the use of the ISO 31000 framework for public organisations.

The complexity of the public sector is too great for ISO 31000

Public organisations, such as local authorities, counties, regions, federal states, countries and even Europe, with their high level of political dynamism, their external focus on cities and society, the intensive coordination between many levels of government and numerous partnerships with businesses, NGOs, civil society organisations and citizens’ groups, require far more than a framework written primarily with an internal focus in mind – and even then, only for part of the organisations’ administrative sphere, with little or no attention paid to executive boards, the composite councils of elected representatives, and even less to the surrounding political arena.

Our experience in Europe shows that only a handful of public organisations regard this ISO framework as useful, let alone actually use it. The framework has proved incapable of acting as a unifying link between the many specific methods and techniques within public administration to deliver bespoke solutions for specific policies or projects. The interfaces with the public sector are lacking.

The incomprehensible ISO 31000 definition of risk

The ISO definition itself – that ‘risk is an effect of uncertainty on objectives’ – remains inscrutable and linguistically incomprehensible, certainly in the context of public affairs. The definition is a pleonasm in itself: it is not uncertainty that causes an effect; a risk is, by its very nature, uncertain.

In its general form, the conceptual framework contains many elements and concepts from the worlds of finance, stock exchanges/markets and insurance, which are far less common and useful in the worlds of politics, governance and management within the public sector.

Moreover, what happens if there are no objectives? Does the framework then cease to apply?

Positive and negative risks?

The ISO framework adds the notion that a risk can be both positive and negative. If an objective is achieved, it cannot be more positive than its intended purpose, can it? The objective is either met or missed. It’s either a hit or a miss. The possibility of missing the mark can only be negative.

It cannot be more positive than a ‘hit’, but a ‘miss’ is indeed a ‘miss’ and can be regarded as a risk (damage to an intended value). Citizens not reached, the impact is disappointing, the policy plan is not working, the outcome is disastrous, the process was appalling, trust is lost, a major pollution incident occurs, a director may have to resign.

The introduction into the ISO framework of risks as positive or negative effects muddies the waters and renders the proposed management approach vague. Public values do not benefit from this. They require skilled archers who hit the mark, not collectors of missed arrows. A missed arrow is not positive. The dart players amongst us know a thing or two about this.

It is a question of either relying on uncertainty or knowing your certainties

PRIMO takes the view that we live in a world full of certainties. We know virtually everything, are aware of relevant trends and developments, recognise the patterns and cycles of policy, budgeting and accountability, and know what scenarios lie ahead for us, and so on. The so-called world of VUCA is often touted, including within this framework. However, PRIMO is convinced that this world has only a very limited presence in everyday life. Certainly given the state of knowledge and science – which is now being driven forward by artificial intelligence – this remains a strange, somewhat outdated concept, originating from military circles in the 1980s. If you fly too low, there is some merit to it, but at the correct altitude, the concept is non-existent. This ISO framework, as it were, gets bogged down in this somewhat demagogic-sounding VUCA world. It is not our world.

The problem with the emergence of tomorrow’s risks is that many of the certainties, familiar patterns and existing insights are obscured, denied or ignored. There are very few uncertainties. Surely we know where we’re heading? Surely we’re familiar with all the detailed scenarios that lie ahead, which have been meticulously worked out by many reputable institutions and described in a scientifically sound manner? Surely we read the countless surveys and reports from think tanks?

In hindsight, certainties are often revealed through investigations by external consultants, audit offices or inquiry commissions. More often than not, these reveal that there were many certainties at the time of decision-making. Numerous reports show that, for effective management, it is not uncertainty that leads to risks, but the failure to address certainties. This ISO framework continues to bang the drum about uncertainty as the driving factor behind risks. We are convinced that this is not the right approach and that it fails to recognise the extensive body of knowledge available.

PRIMO opts for a value-based definition

“Risk = potential damage to a value”. This is PRIMO’s definition, based on Renn and Klinke (2002). This definition guided the development of the concept in 2005 in Strasbourg and was further elaborated upon when the organisation was established as a European association in Dublin, later ratified in its articles of association in Brussels. See ‘About “Public Risk”’ (2007). This definition differs significantly from that of ISO 31000.

This choice was made on the basis of the archer, a metaphor for a director or manager who aims to hit the mark, who seeks to be effective in achieving the public values they have promised to their constituents. It is the definition that has been adopted by the Association of European Municipal Secretaries to support their (18,000) councils of mayors and aldermen in delivering high-quality governance that reaches out to citizens and businesses, and to society in villages and towns. The present ISO framework operates in a world quite distinct from that of public values.

Conclusion

The vague definition of risk within this ISO framework, its inward-looking organisational focus, the failure to address – or the extremely inadequate addressing of – forces in the public domain, the tenuous distinction between external trends and developments on the one hand and internal strengths and weaknesses on the other, and the associated conceptual framework of opportunities and threats, the blurred perception that risks are equated with threats – and thus a failure to recognise the distinction between the world of today and the world of tomorrow – mean that, in PRIMO’s view, it is unsuitable for public organisations where politics and governance take centre stage.

Moreover, and this is the real problem with this framework, it does not link it to concrete tools and techniques for actually getting down to work. It aims very high – too high. PRIMO Res Publica advises against the use of the ISO 31000 framework for public organisations.

Bibliography

Renn, O., & Klinke, A. ( 2002). A New Approach to Risk Evaluation and Management: Risk-Based, Precaution-Based and Discourse-Based Management. Risk Analysis, Vol. 22, No. 6 (December), 1071-1994.