Skip to content
EUROTECH Certification logoEUROTECHCertification

Services / ISO 31000 assessment

ISO 31000 risk management assessment, from $800

ISO 31000 is a set of guidelines, not a certification standard. We assess how your risk management framework and process compare with it and give you a clear written report.

From $800Assessment by EUROTECH

Chess board mid-game on a wooden table by a window in soft light

What the ISO 31000 assessment covers

ISO 31000:2018 gives guidelines on managing risk. It applies to any organization and any type of risk, whether strategic, operational, financial, legal, reputational or related to safety, and it is used by companies, public bodies and not-for-profit organizations as the reference for how risk management should work.

The guidelines are built on three parts. The principles describe what effective risk management looks like, for example integrated, structured, customized, inclusive and based on the best available information. The framework describes how risk management is built into governance and decision making, with leadership commitment. The process describes the steps: establishing scope and context, risk assessment, risk treatment, monitoring and review, communication and recording.

Our assessment compares your organization with all three parts and reports where you are strong, where practice falls short of the guidelines and what would make the biggest difference.

  • Review of risk policy, governance and roles
  • Assessment of the risk process from context to treatment and monitoring
  • Sample review of risk registers and decisions informed by risk
  • Interviews with leadership and risk owners
  • Written assessment report with findings, maturity view and recommendations

The assessment is tailored to your size. A small company with a simple risk register is assessed against what is proportionate for it, while a large group is assessed on how risk management works across units and at board level.

Assessment, not certification: what that means for you

ISO 31000 states that it is not intended for certification, so we assess against it rather than certify. What we offer is an independent assessment, with a report and a statement of the result.

The assessment is still valuable. Boards, regulators, lenders and insurers often want an independent view of risk management, and a structured comparison with the international guidelines gives them one. Internally, the report gives you a prioritized improvement plan.

If you need a certifiable standard that uses risk-based thinking, consider the management system standards that build on it: ISO 22301 for business continuity, ISO/IEC 27001 for information security, ISO 37301 for compliance or ISO 9001 for quality. Many organizations use ISO 31000 as the common risk method across all of them.

The statement we issue describes exactly what was assessed, against which edition of the guidelines and with what result, so readers understand what it does and does not say.

What decides the price

An ISO 31000 assessment with EUROTECH starts at $800. Time depends on the breadth of risk management to be assessed.

  • Size of the organization and number of business units
  • Scope: enterprise-wide risk management or a specific area
  • Number of risk owners to interview
  • Depth: overview assessment or detailed sampling of risk files
  • Sites and whether interviews are online or in person

We confirm days and every fee in a written quote. A current risk register and recent board risk reports are the most useful documents to share in advance.

Organizations that want a deeper review of specific areas, such as project risk, supplier risk or information risk, can add them to the scope, which increases the days needed for sampling and interviews.

We can also assess a single business unit first and extend the scope later.

How ISO 31000 assessment works with us

  1. Scope and interviews

    Step 1

    Scope and interviews

    We agree the scope and the people to interview, and quote the assessment in writing.

  2. Evidence review

    Step 2

    Evidence review

    We review your risk policy, governance, registers and reports against the guidelines.

  3. Process walk-through

    Step 3

    Process walk-through

    We test how risk information is used in real decisions through interviews and samples.

  4. Findings and report

    Step 4

    Findings and report

    You receive a written report with findings, a maturity view and recommendations.

Risk expectations in different sectors and markets

We carry out ISO 31000 assessments for organizations in the USA, Europe, Asia and Africa. Expectations on risk management differ by sector and market: listed companies face corporate governance codes, banks and insurers face prudential rules, public bodies face public sector risk frameworks, and many supply chains now ask suppliers about their risk management.

The assessment takes your context into account. We ask which external requirements apply to you and check whether your risk framework supports them, without claiming that conformity with ISO 31000 meets any specific regulation.

For groups operating in several countries, we look at how risk information flows from local units to group level and back, which is often where practice breaks down.

Risk culture differs between organizations and countries as well. In some, risks are discussed openly; in others, bad news travels slowly. Interviews at several levels help us judge how freely risk information actually moves.

Public bodies often follow national risk management guidance as well, which we take into account when it applies.

What to expect during the assessment

We start with documents: risk policy, governance arrangements, risk appetite statements if you have them, risk registers and reports. Then we interview leaders and risk owners to see how risk information is actually used in decisions such as investments, new products, entering markets or choosing suppliers.

Expect questions such as: how are risks identified for a new project, who decides whether a risk is acceptable, how are risk treatments tracked, how do emerging risks reach the board, and how is the effectiveness of risk management reviewed.

We also look at how risk criteria are set: whether likelihood and impact scales are defined, whether they match the organization's objectives and risk appetite, and whether people apply them consistently. Inconsistent scoring is one of the most common findings.

The assessment can be carried out online, in person or as a mix, depending on your organization. At the end we present the findings in a closing meeting and send the written report.

The report grades findings by importance and includes a maturity view for the principles, framework and process, with practical recommendations.

After the assessment

Use the report to build an improvement plan with owners and dates, and take it to your board or risk committee. Many clients repeat the assessment after twelve to eighteen months to measure progress against the same criteria.

If you later decide to certify a management system, such as ISO 22301 or ISO 27001, the risk process work done here carries over directly.

Keep the risk process alive between assessments: review key risks at regular management meetings, update treatments when circumstances change and record the decisions taken. These records are the best evidence of progress at the next assessment.

Share the main findings with risk owners so improvement is owned across the organization.

Please note: ISO 31000 provides guidelines and is not intended for certification. EUROTECH carries out an independent assessment against the guidelines and issues an assessment report and statement, not a management system certificate.

Questions buyers ask

Can you certify us to ISO 31000?

No. ISO 31000 is a set of guidelines not intended for certification. We provide an independent assessment and report against it.

How much does an ISO 31000 assessment cost?

With EUROTECH it starts at $800. Size, scope, number of risk owners, depth and sites set the final price.

Which edition of ISO 31000 is current?

ISO 31000:2018.

What do we receive at the end?

A written assessment report with findings, a maturity view of principles, framework and process, recommendations and a statement of the result.

Which certifiable standards use ISO 31000?

Many organizations use it as the risk method for ISO 22301, ISO/IEC 27001, ISO 37301, ISO 9001 and other management system standards.

Can the assessment be done online?

Yes, fully or partly. Some organizations prefer in-person interviews with leadership.

Get a quote for ISO 31000 assessment

Tell us your company, sites and the standard you need. We reply with a written quote and the audit plan.

Prefer to talk? Call +1 307 205 1833
Monday to Friday, 09:00 to 18:00 (US Mountain Time)

We use your details only to reply to this request. See our privacy policy.