A growing engineering and manufacturing business has a risk register. It lives in a spreadsheet, was last updated before the annual insurance renewal, contains about sixty risks rated with a colour-coded matrix and is reviewed by nobody in particular. Meanwhile, the real risk decisions happen elsewhere: a major customer now accounts for more than a third of revenue, a key supplier is visibly struggling, a large capital purchase was approved on the strength of an optimistic forecast and cyber security depends on one contractor. None of these appear in the register in a way that changed anything.
The problem is not a lack of risk management tools. It is the lack of a framework: the arrangements that connect risk thinking to the decisions a business actually makes, assign clear accountability, set consistent criteria and make sure someone acts. ISO 31000, the international guidance on risk management, adopted in Australia as AS ISO 31000:2018, offers a well-tested structure for building one. It is deliberately general, so it suits a 50-person business as much as a large corporation, provided it is applied in proportion.
This article explains what ISO 31000 is and is not, its principles, framework and process, how to design risk criteria and a policy, how to assign roles and report usefully, how to judge maturity and how a growing business can implement the essentials without creating bureaucracy. It is general information. Businesses in regulated sectors, or with specific obligations such as directors’ duties, financial services licensing or work health and safety, should take advice on how those requirements interact with their risk framework.
What ISO 31000 is and is not
ISO 31000 provides guidance, not requirements. It is not a certifiable management system standard, so there is no ISO 31000 certificate to obtain. It does not prescribe a particular risk matrix, scale or register format. It describes how risk management should work so that each organisation can design arrangements that fit its own objectives and context. Related guidance includes a standard vocabulary and IEC 31010, which describes risk assessment techniques.
Its definition of risk is short and useful: the effect of uncertainty on objectives. That definition has two consequences. Risk is always about objectives, so a business that has not stated its objectives cannot manage risk well. And the effect can be positive as well as negative, so risk management includes pursuing opportunities, not only avoiding losses. The standard states the purpose of risk management as the creation and protection of value.
Three layers: principles, framework and process
ISO 31000 is organised in three connected layers:
- Principles describe the qualities that effective risk management shows.
- The framework describes the organisational arrangements that support it: leadership, integration, design, implementation, evaluation and improvement.
- The process describes the repeatable cycle for managing specific risks.
Most businesses start and stop with the process, a register and a matrix, and wonder why nothing changes. The principles and framework are what make the process matter.
The principles as diagnostic questions
The standard describes effective risk management as having eight qualities. Each can be turned into a practical question:
| Principle | The question to ask |
|---|---|
| Integrated | Is risk considered in the decisions we actually make, such as budgets, investments, contracts and launches? |
| Structured and comprehensive | Do we approach risk consistently, so results can be compared? |
| Customised | Are our criteria and methods designed for our business, or copied from somewhere else? |
| Inclusive | Are the right people, including those closest to the work, involved? |
| Dynamic | Do we notice and respond when things change? |
| Best available information | Do we use real data and acknowledge its limits? |
| Human and cultural factors | Do we recognise how behaviour, incentives and culture shape risk-taking and reporting? |
| Continual improvement | Do we learn from incidents, near misses and reviews? |
If the business keeps a register but major decisions never refer to it, the integration principle is failing, however tidy the register looks.
The framework: making risk part of how the business runs
The framework has six elements:
- Leadership and commitment. Owners, the board and senior managers set the tone, approve the policy and appetite, allocate resources and model the behaviour they want, including welcoming bad news.
- Integration. Risk thinking is built into the business’s existing decision processes, such as strategic planning, capital approvals, project gates, tender decisions, new product launches and supplier selection, rather than run as a separate activity.
- Design. The business understands its context, sets its policy, defines roles and accountabilities, allocates resources and establishes communication and reporting.
- Implementation. The arrangements are put into practice with a plan, timelines and the people and tools needed.
- Evaluation. The business periodically checks whether the framework is working: are risks being managed, are decisions better informed?
- Improvement. The framework is adapted as the business, its environment and its experience change.
The process: a cycle tied to decisions
The process has several activities that repeat:
- Scope, context and criteria: what decision or objective the assessment supports, the boundaries, the internal and external environment and the criteria for judging risk.
- Risk assessment: identification of risks, analysis of their causes, consequences, likelihood and existing controls, and evaluation against criteria to decide what needs treatment.
- Risk treatment: selecting and implementing options to modify the risk, then assessing what remains.
- Monitoring and review: checking whether risks and controls are changing.
- Recording and reporting: documenting decisions and informing the people who need to know.
- Communication and consultation: involving stakeholders throughout.
The process works best at decision points: when choosing an option, approving a budget, entering a contract, releasing a design, launching a product or changing scope. A monthly review of a static register has its place, but risk management that is not present at decisions has little effect.
Design criteria before assessing risks
Risk criteria are the terms of reference used to judge how significant a risk is. Setting them before assessing risks stops people moving the thresholds to suit the answer they want. Criteria usually include:
- Consequence scales across the dimensions that matter: financial, safety, customer and service, legal and compliance, reputation, people and environment. Financial thresholds should be scaled to the business; a $200,000 loss means something very different to a business with $3 million profit than to one with $300 million.
- Likelihood scales, described in both frequency and probability terms so they can be applied consistently.
- How the two combine, usually in a matrix, and the tolerability zones that follow, with the response required in each: who must be informed, who can accept the risk and how quickly treatment must start.
- How multiple risks are considered together, because several moderate risks with a common cause can add up to a severe one.
The what a risk score cannot tell you article explains the limits of matrices and when other methods are needed.
A risk policy in a few pages
A risk policy sets out the business’s approach to risk. For a growing business, a few pages are enough:
- Purpose: why the business manages risk and what it expects.
- Definitions: risk, risk owner, appetite, tolerance and other terms used.
- Risk appetite statements: how much risk the business is willing to take in pursuit of its objectives, by category. For example, no appetite for serious harm to people or for knowingly breaking the law, but a moderate appetite for product development risk in pursuit of growth. The how much risk can the business carry article explains appetite, tolerance and capacity in practical terms.
- Roles and accountabilities.
- Criteria and escalation rules: which risks go to whom.
- Where risk management is required: the decisions and processes it must be part of.
- Reporting and review: what is reported, to whom and how often, and when the policy is reviewed.
Roles and accountability
Clear accountability matters more than detailed procedures:
- The owners or board approve the policy and appetite, oversee the most significant risks and satisfy themselves that the framework works.
- The executive team owns the framework, manages enterprise-level risks and makes sure risk is part of key decisions.
- Managers are risk owners for the risks in their area: they assess them, decide on treatment within their authority and escalate those beyond it.
- Everyone identifies and reports risks, incidents and near misses.
- Assurance, through internal review, external audit or independent advisers, provides an independent view of whether controls and the framework work.
Many organisations describe these responsibilities using the Institute of Internal Auditors’ Three Lines Model, which distinguishes those who own and manage risk, those who provide expertise and challenge, and independent assurance. A small business may combine roles, but it should still separate doing from checking where the stakes are high.
Report what changes decisions
Good risk reports are short and focused on decisions:
- The top risks, with their trend, owners and the status of treatments.
- Changes since the last report: new risks, risks that have grown and risks that have materialised.
- Treatments that are overdue.
- Appetite breaches and decisions needed.
- Emerging issues that are not yet assessed.
Avoid reports that consist only of a heat map. A matrix shows where risks sit, not what anyone should do.
Judge maturity honestly
Risk maturity models describe a progression, commonly in about four levels: from ad hoc, where risk management happens only when someone happens to think of it; through initial and defined, where processes exist and are followed in places; to embedded, where risk thinking is a normal part of decisions throughout the business. Assess maturity against several dimensions, such as leadership, culture, process, information, tools, competence and learning, using evidence of behaviour, not the existence of documents. A business with a beautifully written policy and no change in decisions is less mature than one with a one-page policy that managers actually use.
Improve one or two dimensions at a time, starting with integration into the decisions that matter most.
Keep it proportionate
For a growing business, a practical minimum might be:
- A one to three page policy with appetite statements, roles and criteria.
- A tailored consequence and likelihood matrix.
- An enterprise register of perhaps 10 to 20 significant risks, owned by executives, plus project and operational registers where needed.
- Risk sections in capital approval forms, tender reviews and project gate reviews.
- A monthly review of top risks at the management meeting, and a quarterly report to the owners or board.
- An annual review of the framework itself.
A worked example
This is an illustrative example. A 150-person engineering services and manufacturing business has annual revenue of about $40 million and profit of about $3 million. Its risk register has 60 items and influences little.
Policy and appetite. The board approves a three-page policy. Appetite statements include no appetite for serious harm to people or knowing non-compliance with law, low appetite for losing a major customer or a cyber incident that stops operations, and moderate appetite for product development risk in pursuit of growth.
Criteria. Consequence scales are tailored to the business. Financial consequences, for instance, range from insignificant (under $20,000) through minor ($20,000 to $100,000), moderate ($100,000 to $500,000) and major ($500,000 to $2 million) to severe (over $2 million, roughly two-thirds of a year’s profit). Similar scales are set for safety, customers, compliance and reputation. Risks in the highest zone must be reported to the board within a week; risks in the next zone need an executive owner and a treatment plan within a month.
Integration. The capital approval form gains a risk section, tender reviews include a structured risk discussion, and new product projects must present their top risks at each gate.
The enterprise register. The 60 items are consolidated into 15 enterprise risks with executive owners. The review surfaces two risks the old register had missed: the largest customer now accounts for 35% of revenue, and production planning depends on one aging server administered by a single contractor.
Treatment. A customer diversification plan sets targets for new accounts in two adjacent sectors. The planning system is moved to a supported platform with multi-factor authentication, tested backups and documented recovery. A struggling supplier is identified early through monthly supplier risk reviews, and a second source is qualified before the supplier enters administration.
After 18 months. The board receives a two-page quarterly risk report focused on changes and decisions. The largest customer’s share has fallen to 28%, and the supplier failure caused a one-week delay rather than a major disruption. The annual framework review finds that managers use the criteria consistently, and that the next improvement should be in sharing lessons from near misses.
Applying this in an Australian business
- State objectives clearly, because risk is the effect of uncertainty on them.
- Use ISO 31000 as guidance, tailored, not as a certification target.
- Integrate risk into real decisions: capital approvals, tenders, project gates and launches.
- Write a short policy with appetite statements, roles and criteria.
- Tailor consequence scales to the size of the business.
- Assign owners and escalation rules.
- Report changes and decisions, not just heat maps.
- Assess maturity by behaviour, and improve in steps.
- Take advice where regulatory obligations apply.
Where risk frameworks go wrong
- A register with no link to decisions.
- Criteria copied from a larger organisation and meaningless at your scale.
- Assessing risks before setting criteria, so ratings drift to suit.
- Ownership by a risk officer rather than by the managers who can act.
- Heat-map reports that prompt no action.
- Ignoring opportunities.
- A framework that never changes as the business grows.
Questions for owners and directors
- Which of our major decisions in the last year considered risk explicitly?
- What are our appetite statements, and do managers know them?
- Are our consequence scales meaningful for a business of our size?
- Who owns each of our top risks, and what are they doing about them?
- What did our last risk report lead anyone to decide?
- How would we know if our risk framework had stopped working?
Bringing it together
A risk register is a record; a framework is a way of running the business. ISO 31000 provides a sound structure: principles that describe what good risk management looks like, a framework that connects it to leadership and decisions, and a process that repeats at the points where decisions are made. Start from clear objectives, write a short policy with appetite statements and tailored criteria, assign ownership to the people who can act, build risk into capital approvals, tenders, project gates and launches, and report what changes decisions. Judge maturity by behaviour and improve in steps. Applied in proportion, the framework helps a growing business take the risks worth taking and avoid the ones that could sink it.
Source: KEVOS editorial notes, drawing on earlier KEVOS risk management handbooks on ISO 31000 for project risk management, establishing risk context and criteria, risk policy, governance and accountability, and risk maturity assessment. The worked example is illustrative. This article is general information and does not constitute legal or governance advice.