Training Outcomes Within Your Budget!
We ensure quality, budget-alignment, and timely delivery by our expert instructors.
Table of Content
- ISO 31000 Risk Assessment Process Explained Step by Step
- What Is the ISO 31000 Risk Assessment Process?
- ISO 31000 Structure, Clauses, and Assessment Boundary
- ISO 31000:2018 vs ISO 31000:2009
- Preparing Scope, Risk Criteria, and Evidence
- How to Conduct an ISO 31000 Risk Assessment
- Worked Example, Assessment Template, and Practical Execution
- Evidence, Treatment, Monitoring, and Common Mistakes
- Conclusion
Recent Blogs
Top Tech Certifications Driving IT Infrastructure Modernization
August 27th, 2026
Kanban vs Scrum: Which Agile Framework to Choose?
August 27th, 2026
Azure AZ-104 Exam Study Guide: Pass on First Attempt
August 27th, 2026
ISO 22301 Clauses Explained
August 27th, 2026
ISO 13485 Medical Devices QMS
August 27th, 2026
Sprint Planning Best Practices: Template & Common Mistakes
August 27th, 2026
How to Write User Stories: Format, Examples & Acceptance Criteria
August 27th, 2026
AWS SysOps Administrator Certification Guide
August 24th, 2026
Cloud Computing Salary Guide 2026: AWS, Azure & GCP
August 20th, 2026
CompTIA Cloud+ Certification: Complete Guide
August 20th, 2026
ISO 31000 vs ISO 27001
August 20th, 2026
CISM Certification Cost and Roadmap for Career Success
August 19th, 2026
CISSP Exam Format & Domains
August 19th, 2026
Closer Look at CISSP Requirements That Truly Matter Most
August 19th, 2026
CISSP Certification Path Steps For Aspiring Security Leaders
August 19th, 2026
The process sits within the wider ISO 31000 Risk Management Framework, which also includes risk treatment, communication, monitoring, and reporting. This guide breaks down the process, key requirements, assessment criteria, responsibilities, records, formulas, and a simple real-world example.
ISO 31000 Risk Assessment Process Explained Step by Step
Risk can show up in many parts of a business. A supplier could miss a delivery, a new service might not perform as expected, information could be exposed, or a project could fall behind schedule. The ISO 31000 Risk Assessment Process helps teams examine possible risks before making decisions. The process involves identifying what could go wrong, judging how likely it is, considering the possible impact, and deciding which risks require action first. The process sits within the wider ISO 31000 Risk Management Framework, which also includes risk treatment, communication, monitoring, and reporting. This guide breaks down the process, key requirements, assessment criteria, responsibilities, records, formulas, and a simple real-world example.
What Is the ISO 31000 Risk Assessment Process?
The process is the part of ISO 31000 used to identify, analyze, and evaluate uncertainty connected to organizational objectives. It turns concerns, incomplete information, previous incidents, and possible future events into structured information for decision-making.
The assessment contains three connected stages:
- 1. Identification: List the events or situations that could affect the objective.
- 2. Analysis: Look at what may cause each risk, what could happen, how likely it is, and what controls are already in place.
- 3. Evaluation: Check the results against the organization’s risk criteria and determine which risks require action.
These stages do not operate alone. An organization first defines the scope, context, and criteria for the assessment. Communication supports each stage, while the findings may later lead to treatment, acceptance, escalation, monitoring, or further analysis.
Risk can lead to problems, but it can also bring useful results. For instance, a new technology may cause setup issues at first, while also cutting costs or improving the quality of service.
Why Is Risk Assessment Important in ISO 31000?
A structured assessment helps organizations:
- Tie each risk to a specific business objective.
- Use one consistent method to rate and compare risks.
- Review existing controls to see if they are actually effective.
- Give priority to risks that could have the greatest impact.
- Record the reasoning behind important risk decisions.
- Consider opportunities that could benefit the business, not only potential threats.
- Reassess risks when circumstances change.
The process cannot predict every event. Its purpose is to help decision-makers work with uncertainty in a more consistent and informed manner.
ISO 31000 Structure, Clauses, and Assessment Boundary
The ISO 31000 Standard is built around three main elements: principles, a framework, and a process. Each element serves a different purpose.
|
ISO 31000 element |
Main purpose |
|---|---|
|
Principles |
Describe the qualities of effective risk practices |
|
Framework |
Integrate risk practices into leadership, governance, and operations |
|
Process |
Provide activities for understanding and responding to uncertainty |
The ISO 31000 Risk Management Principles state that effective risk practices should be integrated, structured, tailored, inclusive, adaptable, informed by reliable evidence, mindful of people and cultural differences, and regularly improved.
Clauses Related to Risk Assessment
|
Clause |
Subject |
Relevance to assessment |
|---|---|---|
|
Clause 1 |
Scope |
Explains how the guidance may be applied |
|
Clause 2 |
Normative references |
States that there are no normative references |
|
Clause 3 |
Terms and definitions |
Establishes important terminology |
|
Clause 4 |
Principles |
Describes effective risk practices |
|
Clause 5 |
Framework |
Supports integration across the organization |
|
Clause 6 |
Process |
Contains the activities used to manage risk |
|
Clause 6.3 |
Scope, context, and criteria |
Sets boundaries and decision rules |
|
Clause 6.4 |
Risk assessment |
Covers identification, analysis, and evaluation |
|
Clause 6.4.2 |
Identification |
Finds and describes uncertainties |
|
Clause 6.4.3 |
Analysis |
Examines their nature and level |
|
Clause 6.4.4 |
Evaluation |
Compares findings with approved criteria |
Risk Management vs Risk Assessment
Risk assessment identifies, analyzes, and evaluates risk. Risk management is broader because it also includes context, communication, treatment, monitoring, recording, and reporting.
|
Area |
Risk assessment |
Risk management |
|---|---|---|
|
Purpose |
Understand and prioritize risk |
Direct and control risk |
|
Main activities |
Identification, analysis, and evaluation |
Context, assessment, treatment, monitoring, and reporting |
|
Output |
Evaluated risk information |
Decisions, controls, actions, and oversight |
|
Boundary |
Ends with evaluation and prioritization |
Continues into action and review |
How Does ISO 31000 Help Manage Risk? It connects objectives, uncertainty, evidence, decisions, ownership, and review through a consistent process.
ISO 31000:2018 vs ISO 31000:2009
ISO 31000 came out in 2009 and was revised in 2018. Older references may still use the 2009 version, so the way the standard is presented can vary between articles, guides, and diagrams.
|
Area |
ISO 31000:2009 |
ISO 31000:2018 |
|---|---|---|
|
Status |
Withdrawn edition |
Current published edition |
|
Principles |
11 principles |
8 principles |
|
Framework |
Clause 4 |
Clause 5 |
|
Process |
Clause 5 |
Clause 6 |
The three assessment activities remain identification, analysis, and evaluation. The main changes concern the structure, terminology, principles, leadership involvement, and integration of risk considerations into organizational decisions.
Current articles should use the 2018 clause references. The official ISO page shows that a future replacement is under development. Until that replacement is published, ISO 31000:2018 remains the current published edition.
Is ISO 31000 Certifiable?
The ISO 31000 Standard offers guidance for managing risk rather than requirements for certification, so organizations do not receive an accredited ISO 31000 management system certificate.
Professional courses based on the standard are available for individuals, but completing such training does not mean the organization itself is ISO 31000 certified.
During ISO 31000 Implementation, the approach can be adjusted to suit the organization, its goals, industry, size, available information, and working environment, with no fixed requirement for a particular risk matrix, scoring method, risk register, or set of documents.
Preparing Scope, Risk Criteria, and Evidence
First, decide what the assessment will cover and its goal. Then understand the current situation, involve the right people, agree on how risks will be judged, and collect the needed information before identifying risks.
Define the Objective
Risk makes sense only when there is a clear goal. The goal should state what the project, team, process, or organization needs to achieve
For example, “assess technology risk” is too general. A clearer goal would be:
Keep the online examination platform available for all scheduled exams over the next six months
Set the Assessment Scope
The scope should define:
- Activities included in the assessment
- Locations, systems, and assets covered
- Departments and suppliers involved
- Time period being examined
- Important exclusions
- Assumptions and limitations
- Intended users of the findings
Understand the Context
Internal and external context may include:
- Business plans
- Legal requirements
- Market changes
- Technology in use
- Staff skills
- Supplier performance
- Financial position
- Stakeholder needs
- Past problems
Establish Risk Assessment Criteria
Risk assessment criteria help decide how serious a risk is and whether it needs action, consider the chance of it happening, its impact, risk limits, when to escalate it, legal requirements, review periods, and how effective the existing controls are.
Example Likelihood Scale
|
Rating |
Level |
Example meaning |
|---|---|---|
|
1 |
Rare |
Expected only in exceptional circumstances |
|
2 |
Unlikely |
Could occur but is not normally expected |
|
3 |
Possible |
May occur under normal conditions |
|
4 |
Likely |
Expected in many circumstances |
|
5 |
Almost certain |
Expected frequently or repeatedly |
Example Consequence Scale
|
Rating |
Level |
Example operational effect |
|---|---|---|
|
1 |
Insignificant |
Small interruption with no missed commitment |
|
2 |
Minor |
Short disruption managed through routine action |
|
3 |
Moderate |
Noticeable delay requiring management attention |
|
4 |
Major |
Serious interruption affecting important commitments |
|
5 |
Severe |
Long interruption with major legal, financial, or safety effects |
The Risk Assessment Methodology should clearly set out how each scale is used and interpreted, with the criteria agreed and approved before the assessment starts. Changing the thresholds after seeing the results can affect the ranking of risks and lead to the wrong priorities.
Gather Supporting Evidence
Useful information for a risk assessment can come from several sources, including:
- Company policies and objectives.
- Process flowcharts and maps.
- Past incident reports.
- Internal and external audit results.
- Supplier information and reports.
- Records showing how controls are working.
- Performance and operational data.
- Applicable laws and regulations.
- Notes from interviews and team discussions.
Missing information should be recorded as uncertainty instead of being hidden or replaced with an unsupported assumption.
How to Conduct an ISO 31000 Risk Assessment
The ISO 31000 Risk Assessment Process is carried out in three related stages, with each one covering a specific part of the assessment. The process should identify what is needed, what needs to be done, who is responsible, and what records are kept at each stage.
Step 1: Risk Identification
Risk Identification is the process of spotting anything that could affect an objective, whether it creates a problem or an opportunity. It looks at possible causes, events, consequences, threats, existing controls, weak points, and areas where information is missing.
Main Inputs
Risk identification can draw on information such as:
- Objectives and scope.
- Internal and external factors.
- Process documents.
- Details of key assets.
- Previous incidents.
- Audit findings.
- Input from relevant stakeholders.
- Details of controls already in place.
Practical Activities
Common ways to identify risks include:
- Team discussions and workshops.
- One-to-one interviews.
- Reviewing processes step by step.
- Using checklists.
- Looking at possible scenarios.
- Examining past incidents.
- Reviewing audit findings.
- Applying lessons from previous projects.
A useful statement format is:
Because of [source or cause], [uncertain event] may occur, resulting in [effect on the objective].
If the examination platform’s only hosting region becomes unavailable, scheduled assessments may be disrupted and course completion could be delayed.
Output, Owner, and Evidence
The output is an initial list of clearly described risks, causes, consequences, controls, assumptions, and knowledge gaps. This information is usually documented in a Risk Register.
The person responsible for the process or risk still owns the responsibility. Facilitators can run the session, and subject experts can explain how the work is carried out.
Useful records may include workshop notes, interview notes, process maps, audit results, incident reports, and approved risk statements.
Step 2: Risk Analysis
Risk analysis looks at a known risk and works out how serious it could be. It considers what could cause the risk, how likely it is to happen, what the outcome might be, and how well the existing controls work.
Main Activities
The analysis should examine:
- What could cause the risk.
- How likely it is to happen.
- What could go wrong.
- When and how badly it could affect the organization.
- Controls already in place.
- How well those controls are designed and working.
- Links between different risks.
- Information that is not available.
- Assumptions and areas of uncertainty.
Risk Likelihood and Impact may be expressed through descriptions, numerical ratings, probabilities, financial estimates, or a combination of methods.
Basic Risk Formula
A common semi-quantitative formula is:
ISO 31000 does not require this formula. The result provides a starting point for discussion, not an automatic decision.
Types of Assessment Methods
|
Method |
Approach |
Suitable use |
|---|---|---|
|
Qualitative |
Uses descriptions such as low, medium, and high |
Rapid screening or limited data |
|
Semi-quantitative |
Uses numerical scores connected to defined scales |
Consistent comparison and ranking |
|
Quantitative |
Uses probabilities, costs, frequencies, or statistical models |
Data-rich or high-value decisions |
The selected Risk Assessment Methodology should fit the objective, available evidence, complexity, and importance of the decision.
Inherent, Residual, and Target Risk
- Inherent risk: The amount of risk present when no safeguards are applied.
- Residual risk: The amount left after existing safeguards are taken into account.
- Target risk: The acceptable level expected once the planned changes are completed.
The assessment may use earlier incident reports, control test findings, cost details, performance data, calculations, and practical input from staff who carry out the work.
Step 3: Risk Evaluation
Risk Evaluation checks the analyzed risk against the agreed limits and priorities agreed on before the assessment starts.
The evaluator should:
- 1. Review what the risk analysis found.
- 2. Compare the risk with the agreed limits.
- 3. Check relevant legal and contract obligations.
- 4. Consider concerns raised by stakeholders.
- 5. Identify effects that may reach other parts of the organization.
- 6. Decide whether the risk needs another review.
- 7. Choose whether to accept the risk, escalate it, or treat it as a higher priority.
- 8. Record the reason behind the decision.
The correct decision-maker depends on the nature of the risk. Process managers may approve routine operational exposure. Senior leaders may need to approve strategic, legal, safety-related, or high-value risks.
Why Scores Are Not Enough
A risk score does not always show the full picture, for example:
- Likelihood 5 × consequence 2 = 10
- Likelihood 2 × consequence 5 = 10
Both risks have the same score, but the situations are quite different. The second case may be less likely to occur, but its impact on safety, legal compliance, or daily operations could be much more serious, so the score should be used as a guide rather than the final basis for a decision, with the actual situation, possible impact, and professional judgment also taken into account.
Inputs, Activities, Outputs, Owners, and Evidence
|
Stage |
Input |
Activity |
Output |
Owner |
Evidence |
|---|---|---|---|---|---|
|
Preparation |
Objectives and context |
Define scope and criteria |
Assessment plan |
Sponsor |
Approved scope and scales |
|
Identification |
Process and incident data |
Find causes, events, and consequences |
Initial risk list |
Process or risk owner |
Notes, reports, and statements |
|
Analysis |
Risks and control data |
Assess likelihood, effects, and controls |
Risk levels |
Risk owner |
Calculations and control tests |
|
Evaluation |
Analysis results and criteria |
Compare, prioritize, and decide |
Evaluated risk list |
Authorized decision-maker |
Approvals and escalation records |
|
Handover |
Evaluation decisions |
Recommend acceptance or action |
Decision record |
Risk owner |
Approved recommendation |
Worked Example, Assessment Template, and Practical Execution
A practical example shows how the different assessment stages fit together
Assessment Objective
Maintain access to an online examination platform during scheduled assessments.
Identification Findings
|
Field |
Finding |
|---|---|
|
Risk source |
Dependence on one cloud region |
|
Possible event |
Regional service interruption |
|
Main cause |
Cloud infrastructure or network failure |
|
Consequence |
Learners cannot access scheduled examinations |
|
Existing controls |
Monitoring and automated data backups |
|
Objective affected |
Continuous examination availability |
Backups protect stored information, but they do not restore immediate platform availability when the active region becomes unavailable.
Evaluation Decision
The expected downtime is above the approved limit, so the risk should not be left unchanged. A serious outage could interrupt exams, cause problems for learners, delay services, and damage the organization’s reputation.
The assessment recommends:
- Adding service capacity in another region
- Testing regional failover
- Assigning an infrastructure manager as owner
- Reviewing the findings after major platform changes
These actions belong to Risk Treatment, which begins after the assessment decision.
Practical Assessment Template
|
Field |
Information to record |
|---|---|
|
Objective |
What must be achieved? |
|
Scope |
What is included and excluded? |
|
Risk source |
Where does the uncertainty originate? |
|
Cause |
Why might the event happen? |
|
Event |
What uncertain event could occur? |
|
Consequence |
How could the objective be affected? |
|
Existing controls |
What currently changes the exposure? |
|
Likelihood |
How probable or frequent is the event? |
|
Consequence rating |
How serious could the effect be? |
|
Inherent exposure |
What exists before controls? |
|
Control effectiveness |
Are current controls dependable? |
|
Residual exposure |
What remains after controls? |
|
Decision |
Accept, escalate, analyze further, or treat? |
|
Owner |
Who is accountable? |
|
Evidence |
What supports the findings? |
|
Review trigger |
What change requires reassessment? |
Professionals responsible for conducting assessments also need to understand how risk criteria, evidence, ownership, and treatment decisions work together. ISO 31000 Risk Manager training can provide structured practice in applying these activities across projects, operations, compliance, and organizational decision-making.
Roles in Practical Execution
- Assessment sponsor: Approves the purpose and scope
- Facilitator: Organizes meetings and guides the method
- Process owner: Supplies operational knowledge
- Risk owner: Remains accountable for the exposure
- Control owner: Explains and tests controls
- Decision-maker: Approves acceptance or escalation
- Subject specialist: Provides technical, legal, financial, or safety knowledge
Who Should Use the ISO 31000 Risk Management Framework? It can support businesses, government bodies, nonprofit organizations, project teams, healthcare providers, financial institutions, manufacturers, technology teams, and educational organizations. The assessment should be scaled according to the complexity and importance of the decision.
Evidence, Treatment, Monitoring, and Common Mistakes
Assessment record should show what evidence was reviewed, how each rating was decided, who approved the result, and when the risk will be reviewed again.
Evidence Checklist
The records can include:
- Why the assessment was performed.
- What the assessment covers.
- The scales used to rate likelihood and impact.
- Names of those who took part.
- Important points discussed.
- Details of earlier incidents.
- Past performance information.
- Controls already in place.
- Control test results.
- Reasons for the ratings.
- Any calculations used.
- Assumptions made.
- Missing or uncertain information.
- Approval and escalation decisions.
- The next review date.
ISO 31000 does not ask every organization to keep identical records, level of detail should match the size, difficulty, and possible impact of the risk.
Moving From Assessment to Action
Assessment findings may lead to acceptance, escalation, further study, or Risk Treatment. Possible treatment decisions include:
- Avoiding the activity
- Removing the source
- Changing the likelihood
- Reducing the consequences
- Sharing the exposure
- Retaining it through an informed decision
- Increasing exposure to pursue an opportunity
Treatment is connected to assessment but remains outside its three core stages.
Monitoring and Reassessment
Risk Monitoring and Review checks whether anything has changed that could affect the risk, such as the operating context, assumptions, controls, or level of exposure.
A new assessment may be needed after:
- An incident occurs
- A control stops working as expected
- A new legal or regulatory requirement takes effect
- A supplier or service provider changes
- A major system update
- A change in objectives
- A new project stage
- Significant new information
This connection supports consistent ISO 31000 Implementation without reducing the assessment to an annual paperwork exercise.
A consistent assessment process depends on clear criteria, reliable evidence, and regular review. SterlingNext risk management learning supports a broader understanding of risk across projects, operations, compliance, and organizational decisions.
Common Assessment Mistakes
- 1. Starting Without a Clear Objective: A risk assessment needs a defined purpose so the risk can be understood and judged against the right criteria.
- 2. Using Vague Statements: Terms such as “cyberattack” or “supplier issue” give little useful detail about what could happen, why it could happen, or what the result might be.
- 3. Copying Generic Criteria: A scoring scale taken from another organization may not fit the risks, priorities, or working conditions of the current organization.
- 4. Changing Criteria After Scoring: Adjusting thresholds after seeing the scores can affect the ranking and lead to the wrong priorities.
- 5. Treating Every Risk as Negative: Focusing only on threats can cause useful opportunities to be missed.
- 6. Assuming Controls Work: Having a control documented does not mean it works properly in practice or is applied consistently.
- 7. Depending Only on Scores: A number does not always show the full picture, especially when legal, safety, financial, or strategic issues are involved.
- 8. Ignoring Connected Risks: Risks can have common causes or trigger other problems, creating wider effects across the organization.
- 9. Hiding Uncertainty: Gaps in information, assumptions, and areas of doubt should be clearly noted rather than left unexplained.
- 10. Providing Findings Without Evidence: Ratings need supporting information so the reasoning can be checked, approved, and justified.
Conclusion
The ISO 31000 Risk Assessment Process helps organizations understand uncertainty and make better decisions by defining the purpose and scope, setting suitable criteria, involving people who know the work, and collecting reliable information. The process identifies what could happen, examines how likely it is and what effect it may have, then compares the result with the agreed criteria to decide whether the risk needs treatment, escalation, acceptance, or further review. Keeping the evidence, calculations, assumptions, and reasons for each decision clear also makes ISO 31000 Risk Management easier to apply in projects, routine operations, and business planning.
Get Certified With Industry Level Projects & Fast Track Your Career
Checkout Top 10 Highest Paying Jobs
Frequently Asked Questions
The three stages are risk identification, analysis, and evaluation, helping an organization understand what may happen, how likely it is to occur, what impact it could have, and whether action is needed.
Risk assessment covers the work of identifying, analyzing, and evaluating risks, whereas ISO 31000 Risk Management takes a wider view by also covering planning, communication, risk treatment, monitoring, reporting, leadership involvement, and using risk information when making decisions.
No, ISO 31000 does not prescribe one specific matrix, formula, or scoring system. An organization can use a qualitative method, a numerical approach, or a mix of both based on the type of decision, the information available, and the complexity of the risk.
Risk analysis considers the source of a risk, its chances of occurring, the damage it could cause, the safeguards already being used, and any information that is missing. Risk evaluation uses these findings to decide what happens next, such as accepting the risk, taking action, raising it to the right level, or gathering more information.
The assessment may draw on previous incidents, audit findings, control results, employee input, meeting records, legal requirements, calculations, and earlier approvals that match the risk and current conditions.
The risk owner is usually responsible for the assessed risk, while process owners, control owners, and specialists provide relevant information, and an authorized manager decides whether to accept, treat, monitor, or escalate it.
Residual risk is the risk left after current controls are applied, it shows whether the controls are doing enough or whether further action, monitoring, or escalation may be required.
No, ISO 31000 offers guidance for managing risk rather than requirements for certifying an organization, although professionals may take relevant courses or earn individual credentials to improve their knowledge.
A risk assessment should be reviewed according to the size and nature of the risk, as well as whenever an incident occurs, a control fails, a law changes, a supplier is replaced, a system is updated, or business objectives change.
An ISO 31000 Risk Assessment helps an organization understand what may affect its objectives by finding possible risks, considering how likely they are and what harm they could cause, then using agreed criteria to decide what should happen next.
Sachin Kumar 