ISO 31073 Risk management — Vocabulary

 

 

This document provides basic vocabulary to develop common understanding on risk management concepts and terms among organizations and functions, and across different applications and types. Risk management is application specific. In some circumstances, it can therefore be necessary to supplement the vocabulary in this document. The terminology in this document may need to be displaced by disciplinary-specific terminology where appropriate. In addition to managing threats to the achievement of their objectives, organizations are increasingly applying risk management processes and developing an integrated approach to risk management in order to improve the management of potential opportunities. The terms and definitions in this document are, therefore, broader in concept and application than those contained in other documents

This vocabulary document represents the current focus of ISO/TC 262 on the management of risks faced by organizations. This document encourages a mutual and consistent understanding of, and a coherent approach to, the description of activities related to the management of risk, and the use of a uniform risk management terminology in processes and frameworks dealing with the management of the risks faced by organizations.


This document is intended to be used by:
— those engaged in managing risks;
— those who are involved in activities of the ISO and IEC;
— developers of national or sector-specific standards, guides, procedures and codes of practice related
to the management of risk.


For principles and guidelines on risk management, see ISO 31000:2018.