ISO 31000:2009 Risk management – Principles and Guidelines
While all organizations manage risk to some degree, this standard articulates a number of principles that need to be satisfied to make risk management effective. It informs the reader about how organizations should develop, implement and continuously improve a framework whose purpose is to integrate the process for managing risk into the organization’s overall values, culture, governance, strategy, planning and management.