ISO 31000 Risk Management Standard: Time for an Update?

By Awad Loubani - Russell Price on
ISO 31000 Risk Management Standard: Time for an Update?

The idea of creating a dedicated Task Group to advance ISO 31000 arose from observations of the discussions taking place during the development of the ISO 31000 Guidance Handbook. 

The idea of creating a dedicated Task Group to advance ISO 31000 arose from observations of the discussions taking place during the development of the ISO 31000 Guidance Handbook. Canada, supported by the USA, recommended researching opportunities to enhance ISO 31000.

Mandate:
ISO Technical Committee 262 Risk Management created TG5 with the purpose to:

  • Identify ISO 31000's audience/market
  • Study the strengths, weaknesses, opportunities and threats to ISO 31000
  • Obtain independent factual data from stakeholder communities
  • Recommend ways to improve awareness and understanding of managing risk
  • Show how managing risk effectively adds value to organizations

 

The Task:

The group was tasked with reporting to the ISO TC262 Chair’s Advisor Group and was set to be completed with a target time frame of October 2023. Key activities included:

  • Analyzing and clarifying the audience, context, scope and purpose of ISO 31000
  • Conducting stakeholder analysis and surveys
  • Identifying how ISO 31000 fits with other risk standards
  • Conducting a SWOT analysis
  • Identifying opportunities to improve ISO 31000
  • Producing a final report with recommendations

The Study’s finding:

The TG5 study suggested it's time to revise and expand the ISO 31000 risk management standard. The group's final report outlines several recommendations to enhance the standard's usefulness and relevance. Key findings include:

  1. The principles section needs more guidance.
  2. The framework section should clarify how to implement risk management, gain support, link to other processes, and build a risk-aware culture.
  3. The process section requires updates on risk categories, appetite, metrics, and control effectiveness.
  4. The risk definition needs review.
  5. More guidance is needed on opportunities, emerging risks, and risk quantification.
  6. Practical examples and case studies would be helpful.
  7. An annex linking ISO 31000 to other risk standards is recommended.

 

The report also suggested:

  • Improving readability to a grade 8 level
  • Aligning with Annex SL and other ISO resources
  • Referencing relevant ISO guides
  • Updating related standards on emerging and travel risks

TG5 raised additional points for discussion:

  • Should TC262 broaden its scope beyond risk management?
  • Should ISO 31000 provide generic rather than organizational guidance?
  • How should "risk" and "opportunity" be defined?
  • Do the key principles need clarification, especially regarding sustainability and value creation?

This study highlighted the need to keep ISO 31000 current and practical. As risks evolve, so too must the standards that guide their management.

TG5 survey:

TG5 conducted a survey of end users which:

  • Aimed to gather input from a wide range of stakeholders on risk management practices and perceptions of ISO 31000 to inform potential updates to the standard.
  • Received 1,957 responses over 33 days from September 21 to October 23, from approximately 104 countries.
  • Reached a diverse range of respondents in terms of:
    • Organization types
    • Organization sizes
    • Geographical presence
    • Respondent roles/positions
    • Level of risk management experience
  • Based on our analysis, our survey had a 95% confidence interval with a 5% accepted error rate.
  • Received responses from:
    • ISO/IEC Technical Committees (35 sources, 804 responses) 41.08%
    • Associations (9 sources, 649 responses) - 33.16%
    • LinkedIn Groups (64 sources, 343 responses) - 17.53%
    • Liaisons (11 sources, 155 responses) - 7.92%
    • Unknown (1 source, 6 responses) - 0.31%
  • Covered topics like:
    • Use of risk management standards/frameworks
    • Experience implementing risk management
    • Challenges and advantages of risk management
    • Views on ISO 31000 specifically
    • Areas for potential improvement in ISO 31000

Membership and Countries:

  • TG5 had 60 active subject matter experts from 17 participating countries
  • Countries represented included: Argentina, Australia, Canada, Finland, France, Germany, India, Ireland, Italy, Japan, Jordan, Netherlands, New Zealand, South Africa, Sweden, Switzerland, United Kingdom, United States

Effort:

  • TG5 held 89 total meetings, including 51 core meetings
  • This amounted to 120 total meeting hours (72 core team meeting hours)
  • There were 2,007.75 total person-hours spent (1,609.25 core team person hours)
  • The group had 94 total participants, with 63 active participants
  • There was approximately 84.19% attendance rate for core sessions

TG5 was considered a resounding success, with extensive consultation with stakeholders and users, engaged members, and the effective delivery of its mandate.

DOWNLOAD SUMMARY REPORT