Purpose and status of the standard
ISO 31000:2018 provides guidance for managing risk in any organisation or activity, including projects. It is deliberately generic, principles-based and adaptable. It is not a certifiable management-system standard and it does not prescribe a single risk matrix, appetite scale, register layout or control threshold. A project must tailor the guidance to its objectives, delivery model, contractual setting, stakeholders and consequences.
The supplied source material described the 2009 edition. The current published edition at the review date is ISO 31000:2018. The vocabulary reference has also moved from the withdrawn 2009 guide to ISO 31073:2022, while IEC 31010:2019 provides guidance on selecting and applying assessment techniques. Historical lists from the earlier edition should therefore be treated as background, not represented as the current text of the standard.
The three connected layers
Principles: the qualities effective practice should display
The current model describes effective risk management as integrated, structured and comprehensive, customised, inclusive, dynamic, informed by the best available information, attentive to human and cultural factors, and continually improved. These qualities are diagnostic rather than ceremonial. If the project maintains a register but major decisions do not use it, practice is not integrated. If scales are copied from another project without calibration, practice is not customised. If dissenting technical views are suppressed, practice is not inclusive or attentive to human factors.
Framework: the organisational support around the project
The framework connects leadership and commitment with integration, design, implementation, evaluation and improvement. At project level this means the sponsor and governance body set expectations; the risk approach is linked to planning, cost, schedule, design, procurement and change control; roles and escalation paths are explicit; resources are available; performance is reviewed; and lessons change the way later decisions are made.
A framework is more than a procedure. It includes authority, accountabilities, competence, information flows, review mechanisms and the behaviours that determine whether people disclose uncertainty early. A technically sound process will fail if governance rewards optimistic reporting or if risk owners lack authority to implement treatment.
Process: the repeatable decision cycle
The process begins by defining scope, context and criteria. It then moves through risk assessment—identification, analysis and evaluation—before treatment is selected and implemented. Communication and consultation, monitoring and review, and recording and reporting operate throughout the cycle.
For a project, the cycle should align with decision points rather than run as an isolated monthly administration task. Apply it when selecting an option, approving a baseline, releasing design, entering a contract, authorising manufacture, accepting a test result, changing scope and closing or transferring residual exposure.
Applying the process to a project
Scope, context and criteria
State which decision or objective the assessment supports, the project boundary, the time horizon, assumptions, interfaces and stakeholders. Define consequence dimensions such as safety, performance, cost, schedule, environment, reputation and compliance. Set criteria before rating risks so the team does not move thresholds to obtain a preferred result.
Identification
Identify sources, events, causes, consequences and areas of uncertainty. Use more than one lens: objectives, work breakdown, schedule, interfaces, assumptions, stakeholders, supply chain, technical maturity and external environment. Include upside opportunities and systemic effects, not only discrete adverse events.
Analysis and evaluation
Analysis develops an understanding of likelihood, consequences, existing controls, uncertainty, dependencies and the potential effect on objectives. Evaluation compares that understanding with approved criteria to determine significance, priority, escalation and the need for further action. A probability–impact score is only one possible decision aid. Multiplying ordinal labels does not turn judgement into precise probability.
Treatment
Treatment changes exposure through avoidance, reduction, sharing or transfer, acceptance, opportunity capture, or a combination of actions. Specify an accountable owner, resources, due dates, trigger points, intended change in exposure and verification evidence. Analyse secondary risk introduced by the treatment itself.
Monitoring, communication and records
Monitor assumptions, controls, indicators, actions, context and emerging exposure. Communicate information in a form suited to each decision-maker. Preserve a proportionate audit trail showing inputs, judgement, challenge, approval, action and residual exposure. Retire a risk only when the basis is recorded and any remaining obligation has an owner.
Tailoring without weakening discipline
Tailoring changes effort and technique, not the need for a defensible decision. A low-complexity project may use a concise register and short facilitated reviews. A high-consequence project may need quantitative models, independent challenge, control assurance and formal escalation. The degree of evidence should reflect uncertainty, consequence, reversibility and stakeholder obligations.
Minimum project implementation set
A practical implementation normally needs a small connected set of controlled artefacts rather than one oversized register. The risk management plan defines the rules; the risk register provides the portfolio view; analysis worksheets retain deeper evidence for material risks; treatment plans convert decisions into action; and reports present the information required by a particular governance forum. Assumption, issue, change, schedule, cost and control records should reference the same identifiers where they describe the same uncertainty.
The project should also define a risk taxonomy, consequence and likelihood criteria, escalation thresholds, status definitions, review cadence, closure rules and record-retention expectations. These are local decisions. ISO 31000 does not supply universal colours, scores or acceptance levels.
Verifying effectiveness
Do not measure implementation only by counting risks or meetings. Test whether significant decisions considered uncertainty, high exposures have active treatment, controls have evidence, overdue actions are challenged, forecasts reflect risk, stakeholders receive useful information and lessons alter later work. A mature review asks whether the process changes choices and outcomes, not whether every field is populated.
Independent assurance can examine design adequacy, consistent application and control effectiveness. It should challenge optimism, omitted interfaces, stale assumptions and unjustified acceptance while preserving clear accountability with management. Findings need owners and closure evidence; an assurance report without implemented improvement adds little value.
Important limitations
ISO 31000 does not replace legislation, contractual duties, technical standards or specialist safety processes. It does not establish universal acceptance levels. It also cannot eliminate cognitive bias, poor data or political pressure. Treat the standard as an organising architecture, then apply competent domain judgement and current mandatory requirements.
