What is ISO 31000?
ISO 31000 is the international standard that provides guidelines for risk management: eight principles, a framework and a process that any organisation, whatever its size or sector, can use to manage risks to its objectives systematically. The current edition is ISO 31000:2018, developed by ISO/TC 262. The standard defines risk as the effect of uncertainty on objectives and is deliberately generic: it applies just as well to financial risk as to a cyberattack on a production line. For OT, ISO 31000 is above all the common language in which security, safety and business risks can be compared.
ποΈ Which editions of ISO 31000 exist?
| Year | Edition | Characteristics |
|---|---|---|
| 2009 | ISO 31000:2009 (1st edition) | First international standard, based on the Australian/New Zealand AS/NZS 4360; eleven principles |
| 2018 | ISO 31000:2018 (2nd edition) | Shorter text, eight principles, emphasis on leadership and integration into governance |
| 2025βpresent | ISO/CD 31000 (3rd edition) | Revision by working group 10 of ISO/TC 262, at committee draft stage; no publication date set yet |
The 2018 edition defines only eight terms, compared with 29 in 2009. The shared vocabulary has lived in ISO 31073:2022 since 2022, which replaced ISO Guide 73:2009. Practical techniques for assessing risk are described in IEC 31010:2019, the second edition of the joint IEC/ISO standard. It covers dozens of methods, from brainstorming and HAZOP to FMEA, fault tree analysis, bow-tie analysis and Monte Carlo simulation.
π How is ISO 31000 structured?
The standard has three interlocking parts: principles (clause 4), framework (clause 5) and process (clause 6).
The eight principles describe what effective risk management looks like: it is integrated into all activities, structured and comprehensive, customised, inclusive (stakeholders have a voice), dynamic, based on the best available information, takes human and cultural factors into account and is subject to continual improvement. Its stated purpose is the creation and protection of value.
The framework centres on leadership and commitment from top management, surrounded by a cycle of integration, design, implementation, evaluation and improvement.
The process is the operational core:
| Clause | Step | What you do |
|---|---|---|
| 6.2 | Communication and consultation | Involve stakeholders throughout the whole process |
| 6.3 | Scope, context and criteria | Define boundaries, internal and external context, risk criteria and risk appetite |
| 6.4.2 | Risk identification | Find sources, events, causes and consequences |
| 6.4.3 | Risk analysis | Determine likelihood and consequence, taking existing controls into account |
| 6.4.4 | Risk evaluation | Compare results with the criteria and decide what needs attention |
| 6.5 | Risk treatment | Select and implement options: avoid, take on risk to pursue an opportunity, remove the source, change likelihood or consequence, share or retain |
| 6.6 | Monitoring and review | Check that risks and controls are still valid |
| 6.7 | Recording and reporting | Document the results, for example in a risk register |
Identification, analysis and evaluation together make up the risk assessment.
π Can you get certified against ISO 31000?
No. ISO 31000 is a set of guidelines containing recommendations, not a requirements standard with shall clauses. An organisation therefore cannot be certified against it, unlike ISO 27001, where an auditor checks whether the ISMS meets the requirements. Training bodies do offer personal certificates such as ISO 31000 Risk Manager, and auditors use the standard as a reference when judging the maturity of risk management.
π How does ISO 31000 relate to other standards?
ISO 31000 is the umbrella; more specific standards fill in the process for a single domain.
| Framework | Domain | Relationship with ISO 31000 |
|---|---|---|
| ISO 31000:2018 | All risks, whole organisation | Generic principles, framework and process |
| ISO 27005:2022 | Information security | Follows the ISO 31000 process and terminology, linked to ISO 27001:2022 |
| IEC 62443-3-2:2020 | Industrial automation security | Risk assessment per zone and conduit, producing a target security level (SL-T) |
| NIST SP 800-30 Rev. 1 (2012) | Information systems, US federal government | Detailed threat-oriented model in four steps: prepare, conduct, communicate, maintain |
| COSO ERM (2017) | Enterprise risk management, financial oversight | Five components and twenty principles, strongly focused on strategy and performance |
In practice you use ISO 31000 to set risk criteria and risk appetite at board level, and IEC 62443 or ISO 27005 for the technical detail. That way an OT risk and a financial risk end up on the same scale.
π How do you apply ISO 31000 in OT?
Risk management in OT differs from IT in three ways:
- Consequences are physical β an attack can cause lost production, environmental damage or injury. Include safety, environment and production as separate consequence categories in your risk matrix.
- Safety and security overlap β a HAZOP assesses process hazards caused by failure, while a security risk assessment looks at deliberate manipulation. ISO 31000 provides one framework to put both side by side, so a cyberattack that disables a safety function does not fall between two stools.
- Risk appetite belongs to the board β under NIS2, and in the Netherlands under the Dutch Cybersecurity Act (Cbw) in force since 15 August 2026, management bodies must approve cybersecurity risk-management measures and complete training on cyber risks. ISO 31000 clause 6.3 is where that risk appetite is written down in concrete terms.
A common approach is a 5Γ5 risk matrix: likelihood from 1 (rare) to 5 (almost certain) multiplied by consequence from 1 (negligible) to 5 (catastrophic). A typical banding: scores of 15 or more are high and require treatment, scores of 6 or less are acceptable within the risk appetite, and in between the risk owner decides whether to treat or knowingly accept. You set those thresholds yourself; ISO 31000 does not prescribe a scale or matrix.
π οΈ Worked example: ransomware on a packaging line
A food manufacturer assesses the risk of ransomware spreading from the office network to its packaging line.
- Context and criteria β the line accounts for 30 per cent of revenue; in this example one hour of downtime costs around β¬15,000. The board accepts at most one shift (eight hours) of unplanned downtime per quarter.
- Identification β the lineβs HMI station and engineering workstation run Windows and share a network with the office systems.
- Analysis β likelihood 3 (possible, given the current threat landscape), consequence 5 (days of downtime, missed deliveries): score 15, high.
- Evaluation β above the risk appetite, so treatment is required.
- Treatment β network segmentation with a DMZ between IT and OT, immutable backups of PLC programs and HMI images, and a rehearsed recovery plan. Likelihood drops to 2 and consequence to 3 (recovery within one shift): residual risk 6, acceptable.
- Monitoring and reporting β the risk goes into the risk register with a named owner, and the recovery procedure is tested every year.
A business impact analysis (BIA) often supplies the figures for step 1.
β Frequently asked questions
Is ISO 31000 mandatory?
No, ISO 31000 is a voluntary guideline, not a legal obligation. Laws such as NIS2 and standards such as ISO 27001 do require a risk-based approach, however, and ISO 31000 is the usual foundation for organising that approach in a demonstrable way.
What is the difference between ISO 31000 and ISO 27001?
ISO 31000 provides guidelines for managing every type of risk and cannot be certified. ISO 27001 sets requirements for an information security management system and can be certified. For the risk assessment within ISO 27001, ISO 27005 follows the ISO 31000 process.
What are the eight principles of ISO 31000?
The eight principles of ISO 31000:2018 are: integrated, structured and comprehensive, customised, inclusive, dynamic, best available information, human and cultural factors, and continual improvement. Together they serve the purpose of risk management under ISO 31000: creating and protecting value.
Is a new version of ISO 31000 coming?
Yes, ISO/TC 262 is working on a third edition of ISO 31000, which is at committee draft stage. No publication date has been set yet, so ISO 31000:2018 remains the valid version for now.
Is ISO 31000 suitable for OT security?
ISO 31000 works well as an overarching framework for OT risks, because it puts security, safety and production risks on a single scale. For the technical assessment of zones and conduits you use IEC 62443-3-2 alongside it.
How does ISO 31000 relate to the NIST risk assessment guide?
ISO 31000 describes the overall risk management process in general terms, while NIST SP 800-30 Rev. 1 gives a detailed method for conducting information security risk assessments. Many organisations use ISO 31000 for governance and criteria and borrow threat modelling from NIST SP 800-30.
π In summary
ISO 31000:2018 is the generic, non-certifiable guideline for risk management, with eight principles, a framework and a process running from context to reporting. In OT, ISO 31000 is the shared language in which the board sets its risk appetite, while IEC 62443-3-2 and ISO 27005 handle the technical risk assessment. See also ISO 55000 for risk in asset management.
