Most risk frameworks are written for auditors. They are long, jargon-heavy, and designed to satisfy a compliance checklist rather than help a team actually manage risk. ISO 31000 is different. It is a practical standard built for anyone who manages risk — regardless of organisation size, sector, or how mature their risk function is. And it is the lens KinetiRisk was designed around from day one.
What is ISO 31000:2018?
ISO 31000:2018 — formally titled "Risk management — Guidelines" — is an international standard published by the International Organisation for Standardisation. Unlike ISO 27001 or SOC 2, it is not a certification scheme. There is no audit, no badge, no accreditation body. It is a set of principles and guidelines that organisations of any size or sector can use to build a coherent, consistent approach to managing risk.
That distinction matters. Because ISO 31000 is not about passing an assessment — it is about embedding better thinking into how your organisation works. A construction firm and a fintech startup can both use it. A team of five and a team of five thousand can both apply it. The standard is deliberately technology-agnostic and sector-agnostic, which is what makes it genuinely universal.
The 2018 edition replaced the original 2009 version with a sharper focus on leadership, integration, and making risk management part of how decisions are actually made — not a separate process that runs alongside the business and gets consulted once a quarter. The revision also placed greater emphasis on the human side of risk: that culture, behaviour, and accountability are not soft considerations but foundational ones.
At its core, ISO 31000 rests on 8 principles. Get those principles right and everything else — the framework, the process, the risk register software — follows naturally.
The 8 Principles
The standard defines 8 attributes that effective risk management must have. These are not steps in a process — they are qualities that should be present at every stage, in every decision. Here is each one in plain English:
- Integrated
- Risk management is not a separate function — it is woven into every organisational process, decision, and level of governance. Risk thinking happens alongside planning and delivery, not after.
- Structured & Comprehensive
- A consistent, repeatable approach that produces comparable and reliable results across every part of the organisation. The same scoring means the same thing whether applied in one project or fifty.
- Customised
- The framework is adapted to the organisation's specific context, objectives, and risk appetite — not a one-size-fits-all template applied blindly regardless of industry or scale.
- Inclusive
- Stakeholders at every level are appropriately involved, informed, and heard. Risk is not identified by one person in a silo — the people closest to the work surface it, and the people responsible for decisions own it.
- Dynamic
- Risk management anticipates and responds as context, information, and circumstances change. A risk register that was accurate six months ago and has not been touched since is not risk management — it is documentation.
- Best Available Information
- Decisions are based on explicit, timely, and well-reasoned evidence. Crucially, the standard also requires that the limitations and uncertainties of that evidence are acknowledged — not hidden.
- Human & Cultural Factors
- People, behaviour, and accountability are central. The standard recognises that risk is owned by humans, not systems, and that cultural norms inside an organisation will shape how honestly risk is surfaced.
- Continual Improvement
- The organisation learns from experience, reviews its approach, and improves its risk management capability over time. This requires records — you cannot improve what you cannot measure.
How KinetiRisk Maps to Each Principle
When we built KinetiRisk, we used these 8 principles as design constraints — not marketing language to apply retrospectively. Each one shaped a specific product decision:
- Integrated
- The three-level Portfolio → Programme → Project hierarchy means risk management is embedded at every layer of the organisation. A risk logged at project level automatically rolls up to programme and portfolio views — it is never siloed.
- Structured & Comprehensive
- A standardised P×I scoring model (probability 1–5, impact 1–5) is applied consistently across every project in every programme. A score of 12 means the same thing in a technology project as it does in a regulatory one.
- Customised
- AI analysis is grounded in the project's description, the user's industry, and the organisation's name before a single score is suggested. The output reflects the specific domain, not a generic template.
- Inclusive
- Role-based project membership controls who can see and act on each risk. Every mitigation action is assigned to a named owner. Email notifications go directly to the person responsible — not into a shared inbox.
- Dynamic
- Automated escalation triggers when P×I reaches 15 or above, immediately. Risks move through a defined lifecycle — open, AI review, human review, closed — and the system acts at each transition rather than waiting for a quarterly review. The formal reviewer queue, where escalated risks require sign-off before closing, is available on the Team plan (£25/month).
- Best Available Information
- The AI uses chain-of-thought reasoning to explain why it has assigned a given probability and impact score. Users see the reasoning in plain English alongside the number — and they can override it with their own judgment, which is also recorded.
- Human & Cultural Factors
- KinetiRisk is human-in-the-loop by design. The AI recommends; humans decide. No risk is confirmed escalated without a reviewer's deliberate approval. The system makes accountability explicit and unavoidable.
- Continual Improvement
- Every change to a risk — score, status, ownership, notes — is recorded with a timestamp and the identity of who made the change. Teams can see how their risk posture has evolved and where their process breaks down. Full compliance audit logging is available on the Team plan (£25/month).
KinetiRisk is designed around the ISO 31000 principles — not bolted on after. Start free →
Start free See how it worksWhy This Matters for Busy Teams
Enterprise GRC platforms will tell you they are ISO 31000 aligned too. And technically, they are. But alignment in an enterprise tool means the capability is present somewhere inside a configuration layer that takes six months and an implementation consultant to surface. The principles are there — they are just not the product. They are a destination you configure towards. For a busy team without a dedicated risk function, that is not a usable tool.
KinetiRisk is built so that the principles are the product, not the configuration. The hierarchy is the default structure. The scoring model is the only scoring model. The escalation logic runs automatically. Risk version tracking starts from the first risk logged; full compliance audit logging is available on the Team plan (£25/month). A project manager with no GRC experience can start on day one and be operating inside a fully ISO 31000-aligned framework without ever reading the standard. That is the point: good risk management should feel like good project management, not like compliance work.
Frequently Asked Questions
What is ISO 31000 and who is it for?
ISO 31000:2018 is an international standard for risk management — a set of principles and guidelines that organisations of any size or sector can use to build a coherent approach to managing risk. Unlike ISO 27001 or SOC 2, it is not a certification scheme and there is no audit body. It is a framework for thinking about risk systematically, applicable whether you run a five-person consultancy or a five-thousand-person enterprise.
What are the 8 principles of ISO 31000?
The 8 principles are: Integrated, Structured and Comprehensive, Customised, Inclusive, Dynamic, Best Available Information, Human and Cultural Factors, and Continual Improvement. These are not steps in a process — they are qualities that should be present at every stage of risk management, in every decision, across the whole organisation.
Does ISO 31000 require specific software or AI?
No. ISO 31000 is deliberately technology-agnostic. The standard sets principles for how organisations should think about and manage risk; it does not mandate specific tools. What it does require is that decisions are based on the best available information, that accountability is clearly assigned to named individuals, and that the process is documented well enough to support continual improvement.
How do you know if your risk management process is ISO 31000 aligned?
A well-aligned process has consistent risk scoring applied across all levels of the organisation, clear named ownership for every risk, automated or prompt escalation when risk thresholds are crossed, a full audit trail of decisions and changes, and regular reviews that treat risk as dynamic rather than a one-time assessment at project kick-off. If any of those are missing, there is a gap.
ISO 31000 is not a box-ticking exercise. It is a way of thinking about risk — systematically, consistently, and with clear human accountability at every step. The organisations that get the most value from it are not the ones that can produce a certificate. They are the ones that have genuinely internationalised the 8 principles into how they plan, decide, and act. KinetiRisk is built to make that the default — so your team does it automatically, not manually, and without needing a dedicated risk professional to hold the framework together.
If you want to understand how AI-assisted scoring sits within an ISO 31000-aligned governance structure — with named reviewers, override recording, and a full audit trail — read our post on AI risk scoring and governance.