Risk Management — Guidelines
Provides principles, a framework and a process for managing risk of any kind at any level of an organisation. It is guidance rather than a certifiable requirements standard, and it is the enterprise-level counterpart to the product-and-patient scope of ICH Q9(R1).
Always verify against the current published text before relying on it for a submission or inspection.
Scope & applicability
All risk an organisation faces — strategic, financial, operational, reputational — and how risk management is integrated into governance and decision-making. It does not replace quality risk management: ICH Q9(R1) governs risk to product quality and patient safety with a defined regulatory expectation behind it, while ISO 31000 gives the frame in which that sits alongside every other risk the organisation carries.
Key requirements
- Principles — risk management as integrated, structured, customised, inclusive, dynamic and based on best available information
- Framework — leadership commitment, integration into organisational structure, design, implementation, evaluation and improvement
- Process — scope and context, risk assessment (identification, analysis, evaluation), treatment, monitoring, recording and reporting
- Explicit treatment of risk appetite and of the criteria by which risk significance is judged
- Second edition (2018) replaced ISO 31000:2009; confirmed by ISO review in 2023, with a revision at committee draft stage
Implementation tips
- Do not merge it with quality risk management: the two have different scopes and different consequences for being wrong, and a merged register in practice means the weaker treatment wins on both
- The clause practitioners most often skip is recording and reporting — a risk accepted without a record of who accepted it, on what basis and until when, is an acceptance nobody can review
Where this control fails
live FDA enforcementLive FDA recalls SPEQ maps to this standard’s topics — a SPEQ interpretation, not an FDA classification.
ISO 31000:2018: frequently asked questions
Quick answers to common questions about ISO 31000:2018.
What is ISO 31000:2018?
ISO 31000:2018 — Risk Management — Guidelines — is a standard issued by the International Organization for Standardization. Provides principles, a framework and a process for managing risk of any kind at any level of an organisation. It is guidance rather than a certifiable requirements standard, and it is the enterprise-level counterpart to the product-and-patient scope of ICH Q9(R1).
Who does ISO 31000:2018 apply to?
All risk an organisation faces — strategic, financial, operational, reputational — and how risk management is integrated into governance and decision-making. It does not replace quality risk management: ICH Q9(R1) governs risk to product quality and patient safety with a defined regulatory expectation behind it, while ISO 31000 gives the frame in which that sits alongside every other risk the organisation carries.
What are the key requirements of ISO 31000:2018?
ISO 31000:2018 requires, among other things: Principles — risk management as integrated, structured, customised, inclusive, dynamic and based on best available information; Framework — leadership commitment, integration into organisational structure, design, implementation, evaluation and improvement; Process — scope and context, risk assessment (identification, analysis, evaluation), treatment, monitoring, recording and reporting; Explicit treatment of risk appetite and of the criteria by which risk significance is judged.
When was ISO 31000:2018 last updated?
The current version of ISO 31000:2018 dates from February 2018.
This standard in practice
Recall domain is a SPEQ mapping of this standard’s topics, not an FDA classification.