ISOQuality Systems MaturityStandard
ISO 31000:2018

Risk Management — Guidelines

Provides principles, a framework and a process for managing risk of any kind at any level of an organisation. It is guidance rather than a certifiable requirements standard, and it is the enterprise-level counterpart to the product-and-patient scope of ICH Q9(R1).

LAST REVISED
February 2018
PRODUCT AREAS
Solid DoseSterileBiotechApiDevicesDistributionClinical
SOURCE & PROVENANCE
ISSUING BODY
International Organization for Standardization
JURISDICTION
International
DOCUMENT ID
ISO 31000:2018
Official site — International Organization for Standardization

Always verify against the current published text before relying on it for a submission or inspection.

Scope & applicability

All risk an organisation faces — strategic, financial, operational, reputational — and how risk management is integrated into governance and decision-making. It does not replace quality risk management: ICH Q9(R1) governs risk to product quality and patient safety with a defined regulatory expectation behind it, while ISO 31000 gives the frame in which that sits alongside every other risk the organisation carries.

Key requirements

  • Principles — risk management as integrated, structured, customised, inclusive, dynamic and based on best available information
  • Framework — leadership commitment, integration into organisational structure, design, implementation, evaluation and improvement
  • Process — scope and context, risk assessment (identification, analysis, evaluation), treatment, monitoring, recording and reporting
  • Explicit treatment of risk appetite and of the criteria by which risk significance is judged
  • Second edition (2018) replaced ISO 31000:2009; confirmed by ISO review in 2023, with a revision at committee draft stage

Implementation tips

  • Do not merge it with quality risk management: the two have different scopes and different consequences for being wrong, and a merged register in practice means the weaker treatment wins on both
  • The clause practitioners most often skip is recording and reporting — a risk accepted without a record of who accepted it, on what basis and until when, is an acceptance nobody can review
CHECKING ACCESS

Checking your Professional access…

Where this control fails

live FDA enforcement
See all FDA enforcement →

Live FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.

ISO 31000:2018: frequently asked questions

Quick answers to common questions about ISO 31000:2018.

What is ISO 31000:2018?

ISO 31000:2018 — Risk Management — Guidelines — is a standard issued by the International Organization for Standardization. Provides principles, a framework and a process for managing risk of any kind at any level of an organisation. It is guidance rather than a certifiable requirements standard, and it is the enterprise-level counterpart to the product-and-patient scope of ICH Q9(R1).

Who does ISO 31000:2018 apply to?

All risk an organisation faces — strategic, financial, operational, reputational — and how risk management is integrated into governance and decision-making. It does not replace quality risk management: ICH Q9(R1) governs risk to product quality and patient safety with a defined regulatory expectation behind it, while ISO 31000 gives the frame in which that sits alongside every other risk the organisation carries.

What are the key requirements of ISO 31000:2018?

ISO 31000:2018 requires, among other things: Principles — risk management as integrated, structured, customised, inclusive, dynamic and based on best available information; Framework — leadership commitment, integration into organisational structure, design, implementation, evaluation and improvement; Process — scope and context, risk assessment (identification, analysis, evaluation), treatment, monitoring, recording and reporting; Explicit treatment of risk appetite and of the criteria by which risk significance is judged.

When was ISO 31000:2018 last updated?

The current version of ISO 31000:2018 dates from February 2018.