Advantage Through Knowledge and Experience
Home › ISO 31000 Consulting
ISO 31000 · DACH Region & International · 2026

ISO 31000 Risk Management –
Identify Risks. Create Value. Build Resilience.

CONSUVATION GmbH guides you in building an effective risk management system according to ISO 31000:2018 – from the initial assessment through to full integration into your existing management systems. With more than 25 years of consulting experience, our own correlation matrix, and 100% senior consultants. For the DACH region and international clients.

25+Years of Consulting Experience
11Principles per ISO 31000:2018
3Pillars: Principles, Framework, Process
Free Initial Consultation → View ISO 31000 Overview
ISO 31000:2018 compliant
Integration into ISMS, QMS & BCM
ISO 27001 · ISO 22301 · NIS2
100% senior consultants
DACH region & international
Proprietary correlation matrix

Quick Check

How Mature Is Your Risk Management?

Find out in 30 seconds where your company stands on risk management according to ISO 31000 – free & without registration.

ISO 31000 Maturity Check

Based on ISO 31000:2018 As of: June 2026 Reviewed by CONSUVATION experts

At a Glance

What Is ISO 31000?

ISO 31000 is the world's leading guideline for risk management. It defines how organisations systematically identify, assess, treat and monitor risks – in order to create and protect value.

The current version ISO 31000:2018 rests on three pillars: 11 principles, a framework for organisational integration, and a concrete risk management process. Certification to ISO 31000 is not provided for – the standard is intended as a guideline.

ISO 31000 is the foundation for risk assessments in other standards – ISO 27001, ISO 22301 and NIS2 require risk analyses without prescribing their own methodology.

🏆 CONSUVATION – Risk Management as a Cross-Cutting Discipline

Our consultants combine risk management expertise with practical experience from ISO 27001, BCM and NIS2 projects. This cross-cutting perspective makes us an experienced partner for integrating ISO 31000 into your existing management systems in the DACH region.

ISO 31000:2018 – Aufbau der Norm

The 3 Pillars of Risk Management

ISO 31000 is not a control catalogue like ISO 27001 Annex A, but a guideline with three interacting pillars: principles, framework and process.

Pillar 1

Principles

11 success criteria for effective risk management – including integrated, structured, customised, inclusive and dynamic. They form the foundation for the framework and process.

11 Principles

Pillar 2

Framework

Embeds risk management in leadership, strategy and organisational structure. Governs responsibilities, resources, communication, and the ongoing evaluation of effectiveness.

Leadership & Governance

Pillar 3

Process

The operational core: defining the scope & context, identifying, analysing, evaluating and treating risks – supported by communication, consultation and monitoring.

6 Process Steps

Important to Know

No Certification

ISO 31000 is designed as a guideline and – unlike ISO 27001 – does not provide for a certification procedure. Its effectiveness shows in genuine day-to-day integration, not in an audit certificate.

Guideline, Not a Requirements Standard
11
Principles
The 11 principles per ISO 31000:2018: Integrated, Structured & comprehensive, Customised, Inclusive, Dynamic, Best available information, Human & cultural factors, Continual improvement, Governance, Compliance, Value-creating.

Our Approach

From Initial Assessment to Lived Risk Management

Structured, predictable and without surprises – our proven approach follows the ISO 31000 risk management process and results in a framework that is genuinely used in everyday business.

01

Initial Consultation & Scoping

Free initial consultation, defining the scope and context, identifying stakeholders, creating a project plan.

02

Maturity Assessment

Current-state assessment of existing risk management, comparison against the 11 principles per ISO 31000:2018, identifying gaps.

03

Building the Framework

Defining governance, roles and responsibilities, setting risk criteria, embedding risk management in leadership and strategy.

04

Risk Assessment

Identifying, analysing and evaluating risks – including opportunities. Creating a risk register, prioritising the risk treatment plan.

05

Risk Treatment & Training

Implementing risk treatment measures, training responsible staff, establishing communication and escalation pathways.

06

Monitoring & Improvement

Continually monitoring effectiveness, regularly re-assessing the risk landscape, continually developing the framework further.

ISO 31000 & Other Standards

How ISO 31000 Relates to Other Standards

ISO 31000 provides the generic risk management methodology – many other standards require risk assessments without prescribing a methodology of their own. CONSUVATION integrates ISO 31000 seamlessly into your existing management systems.

ISO 31000 → ISO 27001

ISO 27001 requires a risk assessment for information security but does not prescribe a specific methodology. ISO 31000 provides the recognised framework for this – a consistent risk methodology across all management systems.

ISMSAnnex ARisk Assessment

ISO 31000 → ISO 22301 (BCM)

Business continuity management builds on a sound risk assessment. ISO 31000 provides the methodology for systematically identifying and assessing business disruption risks – the foundation for resilient contingency plans.

BCMContingency PlanningResilience

ISO 31000 → NIS2

NIS2 requires risk management for cybersecurity measures but does not prescribe its own methodology. Companies already applying ISO 31000 can use their established risk methodology directly for NIS2 requirements.

NIS2Cyber RiskBSI

ISO 31000 → COSO ERM

COSO ERM originates from US auditing practice and is more strongly focused on internal controls and governance. ISO 31000 is more broadly recognised internationally and easier to integrate with other ISO management systems – CONSUVATION is familiar with both approaches.

COSO ERMGovernanceInternational Recognition

ISO 31000 → GDPR

The GDPR requires a data protection impact assessment for high-risk processing activities. The risk methodology from ISO 31000 provides a structured, traceable assessment approach to demonstrate this to supervisory authorities.

GDPRImpact AssessmentData Protection

ISO 31000 → ISO 9001 (QMS)

ISO 9001:2015 already requires risk-based thinking in quality management. ISO 31000 provides the in-depth methodology for systematically integrating quality risks into the existing QMS.

QMSRisk-Based ThinkingIntegration

Core Elements

What Makes Effective Risk Management According to ISO 31000

ISO 31000 is not a rigid set of requirements – it's about principles that flow into an organisation's leadership, processes and culture.

Framework

Context of the Organisation

Understanding internal & external context, defining the scope and risk criteria, involving stakeholders and their expectations.

Process

Risk Identification & Analysis

Systematically identifying risks (and opportunities), analysing causes and effects, assessing likelihood of occurrence.

Process

Risk Evaluation & Treatment

Prioritising risks according to defined criteria, selecting suitable treatment options and creating a risk treatment plan.

Framework

Governance & Responsibilities

Defining clear roles and escalation pathways, providing resources, integrating risk management into the leadership structure.

Process

Communication & Consultation

Consistently involving stakeholders, fostering risk awareness across the organisation, making the basis for decisions transparent.

Framework

Monitoring & Continual Improvement

Regularly evaluating the effectiveness of risk management, adapting the risk landscape to changing conditions, incorporating lessons learned.

Implementation Checklist

ISO 31000 – What Belongs to Effective Risk Management?

📋 Organisational Measures

  • 🏛️Define and document the scope and risk criteria
  • 📜Adopt a risk management policy
  • 👤Define roles & responsibilities (risk owner, risk manager)
  • 🔍Create a risk register and risk treatment plan
  • 📋Define risk appetite and risk tolerance
  • 🎓Introduce a training and awareness programme
  • 🔄Establish regular risk reviews
  • 📊Conduct regular management reviews

🔧 Operational & Methodological Measures

  • 🔐Introduce a risk identification methodology
  • 🛡️Define assessment scales for likelihood & impact
  • 🔒Systematically review risk treatment options (avoid, mitigate, transfer, accept)
  • 💾Ensure documentation and tracking of risk measures
  • 📡Set up early-warning indicators (KRIs) for material risks
  • 🚨Define and test an escalation process for emerging risks
  • ☁️Check integration into existing management systems (ISMS, QMS, BCM)
  • 🔗Introduce a communication and consultation process with stakeholders

Services

ISO 31000 Risk Management Consulting From a Single Source

From maturity assessment to full integration into your management systems – everything from a single source, with senior consultants and our own correlation matrix.

01

ISO 31000 Maturity Assessment

Systematic comparison of current state vs. target state against the 11 principles per ISO 31000:2018: what exists, what's missing, what needs to be prioritised – clearly documented with a measures plan.

ISO 31000:2018Maturity

02

Risk Management Framework Setup

Complete build-up according to ISO 31000: governance, roles, risk criteria, risk register, risk treatment plan and documentation.

FrameworkRisk RegisterGovernance

03

Risk Identification & Assessment

Structured identification and assessment of risks and opportunities, prioritisation according to defined criteria, selection of suitable treatment options.

Risk AnalysisAssessment Methodology

04

Integration Into Existing Management Systems

Linking the ISO 31000 methodology with ISO 27001, ISO 22301, ISO 9001 and NIS2 – a consistent risk methodology instead of isolated point solutions.

ISMSBCMQMS

05

Risk Treatment Planning

Developing concrete treatment measures (avoid, mitigate, transfer, accept), assigning responsibilities, tracking implementation.

Risk TreatmentMeasures Plan

06

Risk Management for NIS2, BCM & QMS

ISO 31000 as a shared risk methodology for all other standards: NIS2, ISO 22301, ISO 9001 and ISO 27001 in one integrated project – maximum synergies.

NIS2BCMQMS

07

Training & Awareness

Risk management training for all levels: basics for employees, in-depth training for risk owners, management briefings on governance obligations.

AwarenessRisk Owner

08

Ongoing Support & Further Development

Ongoing support for risk management operations: regular risk reviews, updating risk registers, continual improvement of the framework.

Risk ReviewContinual Improvement

Frequently Asked Questions

ISO 31000 – Frequently Asked Questions

What is ISO 31000?
ISO 31000 is the international guideline for risk management. It describes principles, a framework and a process that enable organisations to systematically identify, assess, treat and monitor risks – regardless of industry or company size.
Can a company be certified to ISO 31000?
No. ISO 31000 is designed as a guideline and – unlike ISO 27001 – does not provide for a certification procedure. The standard offers principles and a framework that organisations can use as orientation and tailor individually. Its effectiveness shows in genuine day-to-day practice, not in a certificate.
How long does it take to build a risk management system according to ISO 31000?
Depending on maturity level and company size, building a basic framework typically takes 2 to 6 months. Full integration into all business processes is an ongoing, continuous process with no fixed end point.
How are ISO 31000 and ISO 27001 related?
ISO 27001 requires a risk assessment for information security but does not prescribe a specific methodology. ISO 31000 provides the recognised, generic framework for this. Anyone already applying ISO 31000 can use the risk methodology directly for ISO 27001.
What is the difference between ISO 31000 and COSO ERM?
Both address enterprise-wide risk management. COSO ERM originates from US auditing practice and is more strongly focused on internal controls and governance. ISO 31000 is more broadly recognised internationally, more concisely formulated, and easier to integrate with other ISO management systems.
Is ISO 31000 worthwhile even without ISO 27001 or ISO 22301?
Yes. ISO 31000 is independently applicable and helps every company manage risk systematically rather than intuitively – regardless of whether other management systems already exist. If ISO 27001, ISO 22301 or a QMS are already in place, the risk methodology can be integrated directly into them.

Our ISO 31000 Solutions

A Complete Solution for Every Company Size

Project plan, process models, training portal, dashboard and an external risk management officer – all from a single source. Scalable for small, medium and large enterprises.

The 5 Building Blocks of Our Complete ISO 31000 Solution

🏛️

Risk Management Framework

Foundation & Steering

📋

Process Model & Risk Register

All 11 Principles

🎓

Training Portal

DE & EN, with test

📊

Risk Dashboard

Operations & Steering

👤

External Risk Manager

Remote + optional on-site

Small Business · up to 50 Employees

ISO 31000 STARTER

Entry-level solution for small companies. Includes all essential building blocks for a first functioning risk management system – pragmatic, fast and cost-efficient.

  • Risk management framework
  • Process model & core policies
  • E-learning training portal
  • Maturity assessment & risk register
  • Remote guidance through to establishment
Request Package →
Large Enterprise · 250+ Employees

ISO 31000 ENTERPRISE

Maximum solution for complex organisations – with an individual project structure plan, on-site support, and integration with ISO 27001, ISO 22301 or NIS2.

  • All PROFESSIONAL services
  • Individual project structure plan
  • External risk management officer (remote + on-site)
  • Integration with ISO 27001 / ISO 22301 / NIS2
  • Correlation-matrix-supported maturity assessment
  • Continuous operation & ongoing development
Request Package →

All packages include an individual project plan tailored to your company. Remote guidance included – on-site appointments available on request. Schedule a Consultation Now →

Our Expertise

Risk Management as a Cross-Cutting Discipline – Experience That Counts

CONSUVATION exclusively employs senior consultants. With more than 25 years of consulting experience in information security, business continuity and compliance, we are among the most experienced risk management consultancies in the DACH region.

Our consultants bring risk management experience from numerous ISO 27001, ISO 22301 and NIS2 projects. They combine this practice-proven knowledge with the generic methodology of ISO 31000:2018 to develop a framework that is genuinely lived in everyday operations.

As active members of ISO working groups, we bring insider knowledge that flows directly into your risk management implementation.

Our Tool: ISO 31000 Correlation Matrix

CONSUVATION has developed its own correlation matrix for risk management requirements, mapping all relevant standards – ISO 31000, ISO 27001, ISO 22301, ISO 9001 and NIS2. This allows us to spot synergies immediately and produce a complete maturity assessment in the shortest possible time – without duplicate work, with maximum standard coverage.

25+
Years of Experience
11
Principles per ISO 31000
ISO
Working Group Members
100%
Senior Consultants

ISO 31000:2018

Experienced risk management consultants – from maturity assessment to complete framework integration

CISA · CISM · CRISC · CGEIT

The most renowned ISACA certifications – from IT audit to IT governance to risk management

ISO 27001 · ISO 22301 · NIS2

Integrated risk methodology for all related standards – in one project, without duplicate work

Cross-Cutting Experience for Over 25 Years

Risk management experience from information security, business continuity and compliance projects

Get Started Now

Ready for Risk Management According to ISO 31000?

Get advice from an experienced CONSUVATION consultant – free, non-binding and without empty phrases.

Download ISO 31000 Checklist (PDF) Request a Consultation
CONSUVATION GmbH · Tilsiter Str. 6 · D-71065 Sindelfingen, Germany · +49 (0) 7031.4181-860 · contact@consuvation.com