Risk management is not regulated by a single law for most companies, but it does have widely recognized reference standards. Boards, auditors, lenders and insurers often ask whether a company's approach is aligned with ISO 31000 or the COSO Enterprise Risk Management framework. Knowing what these documents say helps you build a program that is credible without becoming bureaucratic.
ISO 31000:2018 Risk management: Guidelines
ISO 31000 is published by the International Organization for Standardization. The current text is the second edition, published in 2018, and ISO lists it as reviewed and confirmed in 2023. It is written for any organization, of any size or sector, and for any type of risk. ISO 31000 has three building blocks:
- Principles. Eight characteristics of effective risk management: it should be integrated, structured and comprehensive, customized, inclusive, dynamic, based on the best available information, attentive to human and cultural factors, and continually improved.
- Framework. The governance arrangements that embed risk management in the organization: leadership and commitment, integration, design, implementation, evaluation and improvement.
- Process. Communication and consultation; scope, context and criteria; risk assessment (identification, analysis, evaluation); risk treatment; monitoring and review; and recording and reporting.
An important point: ISO 31000 is a set of guidelines, not requirements. ISO states that it cannot be used for certification. A company can align its practices with ISO 31000 and have them audited, but a claim of being "ISO 31000 certified" is a misunderstanding of the standard.
Related ISO and IEC documents
- IEC 31010:2019 describes risk assessment techniques, from brainstorming and checklists to bow-tie analysis, fault trees and Monte Carlo simulation.
- ISO Guide 73:2009 provides risk management vocabulary.
- Certifiable management system standards such as ISO/IEC 27001 (information security) and ISO 22301 (business continuity) contain risk-based requirements and are often used alongside ISO 31000.
COSO Enterprise Risk Management: Integrating with Strategy and Performance (2017)
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) is a U.S. private-sector initiative best known for its internal control framework, which is widely used for financial reporting controls. Its ERM framework was first issued in 2004 and substantially updated in 2017. The 2017 version replaced the earlier cube model with five interrelated components and 20 principles:
| Component | Examples of principles |
|---|---|
| Governance and Culture | Board risk oversight, operating structures, desired culture, core values, capable people |
| Strategy and Objective-Setting | Business context, risk appetite, alternative strategies, business objectives |
| Performance | Identify risk, assess severity, prioritize, implement responses, portfolio view |
| Review and Revision | Assess substantial change, review risk and performance, pursue improvement |
| Information, Communication, and Reporting | Leverage information and technology, communicate risk information, report on risk, culture and performance |
COSO's main message is that risk should be considered when strategy is set, not only when it is executed. Risk appetite, the amount of risk an organization is willing to accept in pursuit of value, is central to the framework.
How ISO 31000 and COSO ERM differ
- Audience. ISO 31000 is short, generic and international. COSO ERM is more detailed and is often favored by U.S. public companies, boards and internal auditors.
- Focus. ISO 31000 centers on a practical process applied at every level. COSO ERM centers on governance, strategy and performance at the enterprise level.
- Compatibility. The two are not competing rule books. Many organizations use ISO 31000 for the day-to-day process and COSO for board reporting and links to internal control.
How the insurance industry uses similar ideas
Insurers themselves are subject to risk management requirements. In the United States, states have adopted the NAIC Risk Management and Own Risk and Solvency Assessment (ORSA) Model Act, which requires insurers and groups above certain size thresholds to maintain a risk management framework and file a confidential ORSA summary report with their regulator. In the European Union, Solvency II also requires an own risk and solvency assessment. These rules reflect the same ideas found in ISO 31000 and COSO: identify material risks, assess them against capital and appetite, and report to the board.
Other frameworks worth knowing
For cyber risk, the NIST Cybersecurity Framework 2.0, released in February 2024, organizes activity into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Insurers writing cyber coverage often ask about controls that map to it.
Making standards practical
A small company does not need a large ERM department. Start with a risk register and heat map, name risk owners, agree on what level of risk is acceptable, and review the list regularly. Then decide which risks to reduce and which to transfer through insurance. Polis Re can help you compare coverage for the risks you choose to transfer; request a quote to get started.