Overview
IWA 31:2020 - Risk management - Guidelines on using ISO 31000 in management systems (ISO, 2020) provides practical guidance for integrating ISO 31000:2018 risk management principles and processes into organizations that have implemented, or plan to implement, one or more ISO or IEC Management System Standards (MSS). This International Workshop Agreement (IWA) explains the relationship between the clauses of ISO 31000 and the High Level Structure (HLS) used by MSS, and offers tools (e.g., correspondence table, case study) to help embed risk-based thinking across an integrated management system (IMS). It is guidance only - it does not set MSS requirements or replace other sector-specific standards.
Key technical topics and guidance
- Relationship to ISO 31000 and the HLS: maps ISO 31000 clauses (principles, framework, process) to HLS clauses used across MSS (leadership, planning, support, operation, performance evaluation, improvement).
- Risk management framework and process: guidance on tailoring the ISO 31000 framework to an organization’s external/internal context and objectives; emphasizes proportionate and iterative application.
- Principles and value creation: promotes the eight ISO 31000 principles as foundations for creating and protecting value and improving decision-making.
- Integration techniques: recommends gap analysis, merging ISO 31000 with the process approach of a management system to avoid duplication and conflict.
- Operational links: shows how risk activities relate to leadership, objectives and planning, resources, competence, communication, documented information, monitoring, internal audit, management review, corrective action and continual improvement (see Annex A correspondence table).
- Practical example: Annex B provides a multidiscipline case study illustrating integration across QMS and other MSS processes.
Practical applications and target users
- Who benefits: management system implementers, IMS coordinators, risk managers, auditors, consultants, and executives seeking to align ISO 31000 with ISO/IEC MSS such as ISO 9001, ISO 14001, ISO 45001 and other sector standards.
- Typical uses:
- Integrating enterprise risk management into operational and strategic decision-making.
- Performing a gap analysis to incorporate ISO 31000 components into existing MSS.
- Designing risk-based processes that align with HLS clauses for audits and management review.
- Enhancing resilience, continual improvement and assurance that management systems achieve intended outcomes.
Related standards and references
- ISO 31000:2018 - Risk management - Guidelines (primary guidance referenced).
- ISO/IEC Directives, Part 1 - explains the HLS for MSS.
- ISO handbook on Integrated Use of Management System Standards (IUMSS) - recommended for detailed IMS integration steps.
Keywords: IWA 31:2020, ISO 31000, risk management, management system standards, HLS, integrated management system, risk-based thinking, ISO guidance.