Risk Management

Frameworks we cover and how ActiveERM helps you manage risk and stay audit-ready.

ISO 31000:2018 is the international standard for risk management and provides principles, framework, and process for managing risk. It supports consistent risk assessment, risk treatment, and risk monitoring. Many organizations align their risk register with ISO 31000 and use it to feed ISO 27001 risk assessments and operational risk reporting. ActiveERM links risk to controls and audit findings so you have one risk register, heat maps, KRIs, and treatment plans. See our Risk Management page for the risk register, heat maps, and key risk indicators.

Enterprise risk management (ERM), operational risk, strategic risk, and compliance risk all benefit from a unified risk taxonomy and assessment criteria. ActiveERM supports 5x5 risk matrices, risk appetite, and dashboards so the board and risk owners see a single source of truth.

Key regulations & official links

Explore Risk Management

ISO 31000 in Practice

ISO 31000 is a guidance standard, not a certifiable one. There is no ISO 31000 certificate, and any vendor offering you one is selling something else. What the standard provides is a common structure — principles, framework, and process — that most enterprise risk programmes and regulators now assume.

Its process runs: establish the scope, context and criteria; then risk identification, risk analysis, risk evaluation, and risk treatment; with communication and consultation, monitoring and review, and recording and reporting running throughout rather than as phases.

The step organisations skip is the first one. Risk criteria — the thresholds against which you evaluate whether a risk is acceptable — have to be agreed before anything is scored. Skipping straight to a risk workshop produces a register that has to be re-scored once the criteria eventually get written down.

Establishing Risk Criteria

Risk criteria translate the organisation's objectives and risk appetite into something an assessor can apply consistently. They should specify:

  • The nature and type of consequences to be considered — financial, regulatory, reputational, safety, operational, strategic — and how each is measured.
  • Impact scales with real anchors. "Major" means nothing; "€250k–1m, or enforcement action, or core service degraded for multiple weeks" can be applied by two people independently and produce the same answer.
  • Likelihood scales with frequency or probability bands, and an explicit time horizon. "Likely" over ten years and "likely" this quarter are different risks.
  • How to combine multiple consequence dimensions — take the maximum across dimensions, never the average, or a severe regulatory exposure with negligible financial cost will average itself into invisibility.
  • Thresholds for escalation — what must be reported, to whom, and by when.

Building the Risk Register

The risk register is the record ISO 31000 calls for under "recording and reporting". A register aligned to the standard carries, for each risk:

FieldWhy it is there
Scenario descriptionCause, event and consequence — "cyber risk" cannot be scored, a specific scenario can
CategoryEnables roll-up and comparison across the organisation
Inherent assessmentLikelihood and impact before controls
ControlsWhat currently modifies the risk, with owners
Residual assessmentLikelihood and impact after controls — this is what you compare to appetite
Treatment optionTreat, tolerate, transfer or terminate, with rationale
OwnerA named person, not a department
Review dateThe cadence that keeps the entry honest
Linked indicators and incidentsWhat tells you the assessment has changed

The single most common register defect is the unowned risk. A red risk with no owner is not being managed; it is being displayed.

Risk Categories

A workable taxonomy usually has six to ten top-level categories with one level of sub-categories beneath. Common top-level sets include strategic, financial, operational, compliance and regulatory, technology and cyber, people, and increasingly climate and sustainability.

Two rules save trouble later. Keep categories mutually exclusive enough that assessors do not agonise over placement — if a risk plausibly belongs in three categories, the taxonomy is too fine. And keep them stable: re-categorising a register mid-year destroys trend comparison, which is often the most valuable thing the register produces.

Risk Treatment Options

ISO 31000 frames treatment as selecting among options, which in practice are:

  • Treat — add or strengthen controls to reduce likelihood or impact, then reassess residual risk. The reassessment is the part that gets skipped.
  • Tolerate — accept the risk within appetite, with documented rationale and an approval at a level appropriate to the exposure.
  • Transfer — insure it, or shift it contractually. Note that transfer moves financial consequence, rarely reputational or regulatory consequence. See insurance and risk.
  • Terminate — stop the activity or exit the exposure.

Every treatment needs an owner, a target date, and a defined residual position. A treatment plan with no target residual score cannot be evaluated as successful or otherwise.

Monitoring, Review and Indicators

Static registers decay. ISO 31000's monitoring and review step is what keeps assessments connected to reality, and it works through three channels:

  • Scheduled review on a cadence proportionate to the risk level — reds more often than greens.
  • Event-driven review when an incident occurs, a control fails, or the business changes materially.
  • Indicator-driven review when a key risk indicator breaches its threshold, which is the only one of the three that gives you warning rather than hindsight.

How ActiveERM Supports ISO 31000

The Risk Management module implements this structure directly: configurable likelihood and impact scales with your own criteria, inherent and residual scoring, a live heat map generated from the register rather than maintained beside it, treatment plans with owners and target dates, and indicators wired to thresholds that trigger review.

Because the register sits alongside the GRC control library, business continuity and audit, a control tested once counts everywhere it is mapped, and an audit finding lands against the risk it relates to without re-keying.

For the assessment method itself, see our guide to risk matrices and ISO 31000 scoring.

One platform for all your frameworks.

View all regulationsRequest Demo