← ArticlesISO 31000 for Project Risk ManagementProject Delivery · RiskLesson 5/8← PrevNext →
GuidePublished 13 Aug 20267 min readBy Kevin JoginISO 31000risk frameworkrisk processrisk principles

Project Delivery · Project Risk Management

ISO 31000 for Project Risk Management

A current, project-oriented interpretation of ISO 31000:2018, its principles, framework and process, with clear limits on certification and numerical scoring.

7 min read Handbook guide Reviewed 2026-08-13 De-identified examples

Executive summary

A current, project-oriented interpretation of ISO 31000:2018, its principles, framework and process, with clear limits on certification and numerical scoring. The method is intended to improve decisions, not merely complete documentation. Apply it proportionately, preserve the evidence behind judgement and connect every action to an accountable owner.

Learning outcomes

  • Set scope, context and criteria
  • Identify uncertainty affecting objectives
  • Analyse and evaluate risk
  • Select and implement treatment
  • Monitor, communicate and record
  1. Set scope, context and criteria
  2. Identify uncertainty affecting objectives
  3. Analyse and evaluate risk
  4. Select and implement treatment
  5. Monitor, communicate and record

Purpose and status of the standard

ISO 31000:2018 provides guidance for managing risk in any organisation or activity, including projects. It is deliberately generic, principles-based and adaptable. It is not a certifiable management-system standard and it does not prescribe a single risk matrix, appetite scale, register layout or control threshold. A project must tailor the guidance to its objectives, delivery model, contractual setting, stakeholders and consequences.

The supplied source material described the 2009 edition. The current published edition at the review date is ISO 31000:2018. The vocabulary reference has also moved from the withdrawn 2009 guide to ISO 31073:2022, while IEC 31010:2019 provides guidance on selecting and applying assessment techniques. Historical lists from the earlier edition should therefore be treated as background, not represented as the current text of the standard.

The three connected layers

Principles: the qualities effective practice should display

The current model describes effective risk management as integrated, structured and comprehensive, customised, inclusive, dynamic, informed by the best available information, attentive to human and cultural factors, and continually improved. These qualities are diagnostic rather than ceremonial. If the project maintains a register but major decisions do not use it, practice is not integrated. If scales are copied from another project without calibration, practice is not customised. If dissenting technical views are suppressed, practice is not inclusive or attentive to human factors.

Framework: the organisational support around the project

The framework connects leadership and commitment with integration, design, implementation, evaluation and improvement. At project level this means the sponsor and governance body set expectations; the risk approach is linked to planning, cost, schedule, design, procurement and change control; roles and escalation paths are explicit; resources are available; performance is reviewed; and lessons change the way later decisions are made.

A framework is more than a procedure. It includes authority, accountabilities, competence, information flows, review mechanisms and the behaviours that determine whether people disclose uncertainty early. A technically sound process will fail if governance rewards optimistic reporting or if risk owners lack authority to implement treatment.

Process: the repeatable decision cycle

The process begins by defining scope, context and criteria. It then moves through risk assessment—identification, analysis and evaluation—before treatment is selected and implemented. Communication and consultation, monitoring and review, and recording and reporting operate throughout the cycle.

For a project, the cycle should align with decision points rather than run as an isolated monthly administration task. Apply it when selecting an option, approving a baseline, releasing design, entering a contract, authorising manufacture, accepting a test result, changing scope and closing or transferring residual exposure.

Applying the process to a project

Scope, context and criteria

State which decision or objective the assessment supports, the project boundary, the time horizon, assumptions, interfaces and stakeholders. Define consequence dimensions such as safety, performance, cost, schedule, environment, reputation and compliance. Set criteria before rating risks so the team does not move thresholds to obtain a preferred result.

Identification

Identify sources, events, causes, consequences and areas of uncertainty. Use more than one lens: objectives, work breakdown, schedule, interfaces, assumptions, stakeholders, supply chain, technical maturity and external environment. Include upside opportunities and systemic effects, not only discrete adverse events.

Analysis and evaluation

Analysis develops an understanding of likelihood, consequences, existing controls, uncertainty, dependencies and the potential effect on objectives. Evaluation compares that understanding with approved criteria to determine significance, priority, escalation and the need for further action. A probability–impact score is only one possible decision aid. Multiplying ordinal labels does not turn judgement into precise probability.

Treatment

Treatment changes exposure through avoidance, reduction, sharing or transfer, acceptance, opportunity capture, or a combination of actions. Specify an accountable owner, resources, due dates, trigger points, intended change in exposure and verification evidence. Analyse secondary risk introduced by the treatment itself.

Monitoring, communication and records

Monitor assumptions, controls, indicators, actions, context and emerging exposure. Communicate information in a form suited to each decision-maker. Preserve a proportionate audit trail showing inputs, judgement, challenge, approval, action and residual exposure. Retire a risk only when the basis is recorded and any remaining obligation has an owner.

Tailoring without weakening discipline

Tailoring changes effort and technique, not the need for a defensible decision. A low-complexity project may use a concise register and short facilitated reviews. A high-consequence project may need quantitative models, independent challenge, control assurance and formal escalation. The degree of evidence should reflect uncertainty, consequence, reversibility and stakeholder obligations.

Minimum project implementation set

A practical implementation normally needs a small connected set of controlled artefacts rather than one oversized register. The risk management plan defines the rules; the risk register provides the portfolio view; analysis worksheets retain deeper evidence for material risks; treatment plans convert decisions into action; and reports present the information required by a particular governance forum. Assumption, issue, change, schedule, cost and control records should reference the same identifiers where they describe the same uncertainty.

The project should also define a risk taxonomy, consequence and likelihood criteria, escalation thresholds, status definitions, review cadence, closure rules and record-retention expectations. These are local decisions. ISO 31000 does not supply universal colours, scores or acceptance levels.

Verifying effectiveness

Do not measure implementation only by counting risks or meetings. Test whether significant decisions considered uncertainty, high exposures have active treatment, controls have evidence, overdue actions are challenged, forecasts reflect risk, stakeholders receive useful information and lessons alter later work. A mature review asks whether the process changes choices and outcomes, not whether every field is populated.

Independent assurance can examine design adequacy, consistent application and control effectiveness. It should challenge optimism, omitted interfaces, stale assumptions and unjustified acceptance while preserving clear accountability with management. Findings need owners and closure evidence; an assurance report without implemented improvement adds little value.

Important limitations

ISO 31000 does not replace legislation, contractual duties, technical standards or specialist safety processes. It does not establish universal acceptance levels. It also cannot eliminate cognitive bias, poor data or political pressure. Treat the standard as an organising architecture, then apply competent domain judgement and current mandatory requirements.

Practitioner completion checks

Use these checks before closing the analysis or taking the decision forward. Scale the evidence to the consequence, uncertainty and reversibility of the decision.

Check 01Set scope, context and criteria is defined, owned, evidenced and linked to the relevant project decision.
Check 02Identify uncertainty affecting objectives is defined, owned, evidenced and linked to the relevant project decision.
Check 03Analyse and evaluate risk is defined, owned, evidenced and linked to the relevant project decision.
Check 04Select and implement treatment is defined, owned, evidenced and linked to the relevant project decision.
Check 05Monitor, communicate and record is defined, owned, evidenced and linked to the relevant project decision.
How much detail is enough?

Use the least complex method that can support a defensible decision. Increase rigour when consequences are high, uncertainty is material, interfaces are complex, evidence is weak or the decision is difficult to reverse.

What should the decision record contain?

Record the objective, scope, inputs, assumptions, method, uncertainties, options, judgement, owner, approval, actions, residual exposure and the trigger or date for review.

When should the work be repeated?

Repeat it when a key assumption changes, new evidence appears, exposure crosses a threshold, a response fails, scope or interfaces change, or the next governance decision requires refreshed information.

Current authoritative reference points

Use the current published documents and the requirements adopted for the project's jurisdiction and contract. Links below support currency checking; they do not reproduce copyrighted standards.

Continue learning

Project Risk and Enterprise RiskGuide · RiskNEXT LESSON →Comparing Project Risk MethodologiesGuide · RiskThe Evolution of Project Risk ManagementGuide · RiskThe Project Risk Management LifecycleGuide · Risk