ISO 31000 is the international standard for risk management. One of the most common questions we hear is “can you get ISO 31000 certified?” The short answer is no, and understanding why tells you a lot about how to use it well.
What is ISO 31000?
ISO 31000:2018 provides principles and guidelines for managing risk of any kind: strategic, operational, financial, safety, security. It’s deliberately generic so any organisation, in any sector, can apply it. It gives you a consistent way to identify, assess and treat risk and to build risk thinking into decision-making.
Can you get certified to ISO 31000?
No. ISO 31000 is a guidance standard, not a management-system standard with auditable requirements (the word “shall” doesn’t appear in it the way it does in ISO 9001). Because there’s nothing to certify against, there is no accredited certification for organisations, and you should be cautious of anyone selling “ISO 31000 certification” for a business. What you can do is adopt ISO 31000 and then be certified to standards that require risk management, such as ISO 9001 or ISO 27001.
Individuals are different. You can take ISO 31000 training and receive a certificate of completion. That’s a personal qualification, not certification of your organisation.
The ISO 31000 framework: principles, framework and process
ISO 31000 is built around three things: a set of principles (risk management should be integrated, structured, customised, inclusive and based on the best available information), a framework that embeds risk management into governance and leadership, and a process you apply day to day.
The ISO 31000 risk management process
- Communication and consultation with the people involved.
- Scope, context and criteria: what you’re assessing and how you’ll judge risk.
- Risk assessment: identify, analyse and evaluate the risks.
- Risk treatment: decide how to avoid, reduce, share or accept each risk.
- Monitoring and review: keep the picture current as things change.
- Recording and reporting: document decisions and keep stakeholders informed.
ISO 31000 and “risk-based thinking” in ISO 9001
ISO 9001:2015 requires “risk-based thinking” but doesn’t prescribe a method. ISO 31000 fills that gap perfectly: using its process gives your quality, environmental, safety or information-security system a credible, consistent way to handle risk that auditors recognise. In other words, ISO 31000 is the engine that makes risk-based thinking real.
How Streamline can help
We help businesses build practical risk management aligned with ISO 31000 and wire it into their certifiable management systems, so risk thinking actually informs decisions, and your ISO 9001 or ISO 27001 auditor sees a system that works.
ISO 31000: FAQs
Can a company be certified to ISO 31000?
No. It’s a guidance standard with no auditable requirements, so there’s no accredited organisational certification. You can align with it and be certified to standards that require risk management, such as ISO 9001 or ISO 27001.
Is there ISO 31000 certification for individuals?
Yes. Individuals can complete ISO 31000 training and receive a certificate: a personal qualification, distinct from certifying an organisation.
How does ISO 31000 relate to ISO 9001?
ISO 9001’s risk-based thinking aligns directly with ISO 31000. Using the ISO 31000 process is one of the cleanest ways to satisfy that requirement and strengthen your QMS.
Speak with an experienced ISO auditor
Email hello@streamline.business or call us. You’ll deal directly with an experienced ISO auditor who’ll tailor a practical approach to your business. You’re also welcome to get in touch via our contact page.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











