ISO 31000: The New International Risk Management Standard
In a world of risk management, many companies juggling on the framework that suitable to their environment for implementing risk management.
On November 2009, the International Organization for Standardization (ISO) published ISO 31000:2009, Risk Management — Principles and Guidelines, a new management standard intended to help organizations of all types and sizes across the silos/domains of risk scattered across the enterprise. It is just as relevant to areas not only for financial risk but also for also non-financial risk such as legal risk management as it is to information security, quality, or environmental, health & safety.
THE PORTRAIT OF ISO 31000
ISO 31000:2009 is the new international standard on risk management and largely foundation on AS/NZS 4360:2004, the Australian standard originally published in 1995. ISO 31000 provides a generic framework for establishing the context of, identifying, analyzing, evaluating, treating, monitoring and communicating risk. It is the first document published in the ISO 31000 Risk Management series, which also includes the following:
- ISO Guide 73:2009, Risk management — Vocabulary: Provides the definitions of generic terms related to risk management and aims to encourage a consistent understanding of, and a coherent approach to, the description of activities relating to the management of risk, as well as uniform risk management terminology.
- ISO/IEC 31010, Risk management — Risk assessment techniques: A supporting standard for ISO 31000 offering guidance on the selection and application of systematic techniques for risk assessment.
THE COMPATIBILITY OF ISO 31000 vs COSO ERM
The good news is that ISO 31000 is compatible with COSO ERM. It is considered an update to COSO ERM that reflects current risk management thinking internationally. In general, ISO 31000 has some significant advantages over COSO:
- More practical and less theoretical with detail provided and explicitly defined
- A concise 24 pages, ISO 31000:2009 is noteworthy for its simplicity and adaptability used by public and private companies, organizations and individuals also applied to a range of activities, from operations and processes to services and assets
- Plainly written, the document is accessible to Boards (CEOs, CIOs, CROs, Commissioners, Audit Committee, Risk Oversight Committee), risk practitioners, also controllers, to understand how to managing risk whilst exploit opportunity
- The information in the standard can be adapted to develop guidelines to assess existing risk management methodologies
The essential difference between ISO 31000 and COSO ERM is in the focus of assessing and managing risk.
- ISO 31000 is focused on consequences provides a framework to help consider the ‘flow on’ consequences of an event occurring. It shown through risk definition as the “effect of uncertainty on objectives”
- COSO ERM is focused more on the events rather the consequences of events. It shown through risk definition as “the possibility that an event will occur and adversely affect the achievement of objectives.”
THE ANATOMY OF ISO 31000
The ISO 31000 has three interrelated building block of general principles, framework, and process risk management to be effective implemented.
The First Building Block of ISO 31000 states that risk management should contain the following principles:
- Creates value
- Integral part of organizational processes
- Part of decision-making
- Explicitly addresses uncertainty
- Systematic, structured and timely
- Based on the best available information
- Takes human and cultural factors into account
- Transparent and inclusive
- Dynamic, iterative and responsive to change
- Facilitates continual improvement of the organization
The Second Building Block of ISO 31000 is having the right risk framework through Boards’ commitment. Once commitment is established, there is a loop of actions that include: 1) design the framework, 2) implement risk management, 3) monitor and review the framework, and 4) continual improvement of the framework.
The Third Building Block of ISO 31000 is adopted originally from AS/NZS 4360:2004 that assure the communication and monitoring is doing through the process of establishing the context, risk assessment, until risk treatment.
ISO 31000 is concise and well-written standard that reflect current international thinking as a very positive development in the risk management standards landscape. It defines risk as the “effect of uncertainty on objectives,” acknowledging both the positive opportunities and negative consequences associated with it.
In my point of view, as a risk practitioner we should discover on the application of new ISO 31000 standard in the organization to streamlining risk management on a global scale based on 3-prerequsite pillars of effective risk management as illustrated below since “not pursuing an opportunity” is a risk identified in ISO 31000.
3pillars vs iso31000framework