Skip to main content
Rules Mate

ISO 31000 risk management: applying the standard to an Australian compliance program

Rules Mate Editorial7 min read

ISO 31000 is guidance, not a certifiable standard. How to apply its principles, framework and process to an Australian compliance program that regulators will accept.

ISO 31000:2018 provides guidelines for managing risk. It is the reference most Australian risk frameworks quietly sit on, it is adopted locally as AS ISO 31000:2018, and it is the one standard in this series that you cannot be certified against.

That last point shapes everything else. Because there is no certificate, ISO 31000 earns its place purely by making your compliance program defensible — to a board, to an internal auditor, and to a regulator asking how you decided what to control.

You cannot be certified to ISO 31000

ISO 31000 is guidance. It is not written as a requirements standard, and no accredited certification body can certify an organisation to it.

The catalogue entry is ISO 31000:2018, and the Australian adoption is AS ISO 31000:2018. Anyone offering "ISO 31000 certification" for your organisation is selling something that does not exist — individual training certificates are a different thing, and should not be represented as organisational certification.

What ISO 31000 is genuinely useful for:

  • Providing a common vocabulary so risk, control, consequence, likelihood and residual risk mean the same thing across compliance, operations, security and finance.
  • Supplying the methodology that certifiable standards require but do not prescribe. ISO 27001 requires an information security risk assessment process; ISO 31000 is a common choice for it.
  • Giving a board a defensible structure when it has to explain how risk decisions were made.

The three parts: principles, framework, process

ISO 31000 is organised into principles, framework and process, and the framework is the part organisations skip.

Principles describe what good risk management looks like: integrated, structured and comprehensive, customised, inclusive, dynamic, based on the best available information, accounting for human and cultural factors, and subject to continual improvement. The 2018 revision made "creating and protecting value" the central purpose.

Framework is the organisational plumbing — leadership and commitment, integration into governance and decision-making, design, implementation, evaluation and improvement of the arrangements. This is where most Australian compliance programs are weakest. A risk register without a framework is a spreadsheet nobody acts on.

Process is the operating cycle: scope, context and criteria; risk identification; risk analysis; risk evaluation; risk treatment; with communication and consultation, and monitoring and review, running throughout and recording and reporting at every step.

The framework matters most because it determines whether the process output changes any decision. If risk assessments do not feed capital allocation, project approval, product design or supplier selection, the framework is missing regardless of how good the register looks.

Turning the process into a compliance risk assessment

A compliance risk assessment applies the ISO 31000 process to the risk of failing to meet an obligation. The sequence:

  1. Scope, context and criteria. Define which entities, jurisdictions and activities are in scope, then define your criteria — how you will measure consequence and likelihood, and what level of risk requires treatment.
  2. Identify the obligations. You cannot assess compliance risk without an obligations inventory. This is the input step most programs get wrong: the register lists risks in the abstract ("regulatory breach") rather than being built up from actual obligations. Start from the obligation checker to establish which Australian obligations apply to your operations and entity type.
  3. Identify the risks against each obligation. For each obligation: what could cause us to fail it, in what circumstances, and through what mechanism.
  4. Analyse. Assess consequence and likelihood against your criteria, considering existing controls and their effectiveness. Consequence in a compliance setting is multi-dimensional — penalty exposure, licence impact, remediation cost, reporting obligations triggered, and reputational effect. The penalty estimator helps quantify the first of those.
  5. Evaluate. Compare the analysed risk against your criteria and decide: accept, treat, avoid, share, or take more risk to pursue an opportunity.
  6. Treat. Design controls, assign owners and dates, then reassess residual risk and record acceptance.
  7. Monitor, review, report. Set a review cadence per risk tier and report to the accountable body.

The step that separates a real program from a decorative one is step 2. An obligations-led register is auditable; a brainstormed register is not.

Risk criteria, appetite and tolerance in a compliance setting

Compliance risk appetite is different from financial risk appetite, and boards routinely conflate them.

For most obligations, the appetite for deliberate non-compliance is zero — you do not have an appetite for breaching a criminal provision. What you do have is a tolerance for the residual risk that remains after proportionate controls, and a set of decisions about how much control investment a given obligation warrants. Stating that distinction clearly is what makes a compliance appetite statement usable.

ElementWhat it should stateFailure mode
Consequence scaleDefined bands covering penalty, licence, remediation, notification and reputationFinancial-only scales that cannot rate a criminal exposure
Likelihood scaleDefined frequency or probability bands with time horizonDescriptive words with no shared meaning
Risk criteriaThe level at which treatment is mandatory and who may accept residual riskNo named acceptor, so nothing is ever accepted
Appetite statementZero appetite categories named explicitly; tolerance expressed for residual riskA single sentence saying the organisation is "risk averse"
Escalation triggersQuantified thresholds that force reporting upwardEscalation left to judgement

Whoever may accept residual risk must be named and must be senior enough to bear it. Under Australian law, some acceptances cannot practically be delegated: directors' duties of care and diligence, discussed in directors' duties and the business judgment rule, sit with the board.

Where Australian regulators expect this rigour

No Australian law mandates ISO 31000 by name. Several regimes require a risk management framework whose expected content is materially the same.

APRA CPS 220. Regulated entities must maintain a risk management framework, a risk appetite statement, a risk management strategy and a business plan, with board oversight. See CPS 220 risk management and the obligation cps-220-risk-management, plus the CPS 220 glossary entry.

SOCI critical infrastructure. Responsible entities must adopt and maintain a critical infrastructure risk management program addressing cyber, personnel, supply chain and physical hazards, with an annual report. See the CIRMP requirements and the obligation soci-rmp.

AML/CTF. The regime is explicitly risk-based: a reporting entity must assess and document its money laundering and terrorism financing risk and apply controls proportionate to it. See the risk-based approach and the obligation aml-ctf-program.

Listed entity governance. The ASX Corporate Governance Council principles ask listed entities to have a risk management framework and to review it, and to disclose whether they do. See the ASX principles.

Across all four, regulators test the same things: is the framework owned at the right level, is it applied consistently, does it produce decisions, and can you evidence the review cycle.

Building a risk register that survives review

A register that survives scrutiny has these columns and nothing decorative:

  • Obligation reference — the specific requirement the risk relates to.
  • Risk description in cause-event-consequence form, not a one-word label.
  • Inherent assessment against the defined scales.
  • Existing controls, with a control owner and an assessed effectiveness rating supported by evidence.
  • Residual assessment, and where it sits against the criteria.
  • Treatment actions with owner and due date, tracked to completion.
  • Acceptance — who accepted the residual risk and when.
  • Review date and last review record.

Two disciplines make it credible. First, control effectiveness must be tested, not asserted — a control rated effective with no testing evidence collapses the residual rating built on it. Second, the register must be versioned, so you can show what the risk position was at a point in time. After an incident, the question is always what you knew and when.

Common mistakes

  • Buying "ISO 31000 certification." It does not exist for organisations. Do not put it on a tender response.
  • A register that starts from risks, not obligations. Without an obligations inventory you cannot demonstrate coverage.
  • Scales that cannot express regulatory consequence. If the only consequence axis is dollars, criminal and licence exposure gets under-rated.
  • Controls with no owner. "IT" and "Compliance" are not owners.
  • Assessment without treatment tracking. An action list with no completion evidence is an admission that the risk was identified and not managed.
  • An annual refresh with no trigger-based review. Material change — a new product, a new jurisdiction, a new law, an incident — must trigger reassessment between cycles.
  • Confusing risk management with compliance management. ISO 31000 tells you how to think about uncertainty; the standard written for the compliance function itself is ISO 37301, covered in ISO 37301 compliance management systems.

For the governance framing of all of this, see the directors and governance topic hub.

Frequently asked

Can an organisation be certified to ISO 31000?

No. ISO 31000 is written as guidance rather than as a requirements standard, and no accredited certification body can certify an organisation against it. Individual training certificates exist and are a different thing — presenting one as organisational certification is misleading.

Do Australian regulators require ISO 31000?

No Australian law mandates ISO 31000 by name. Several regimes — APRA CPS 220, the SOCI critical infrastructure risk management program, and the AML/CTF risk-based approach — require a risk management framework whose expected content closely matches what ISO 31000 describes, which is why it is so widely used as the underlying method.

What is the difference between ISO 31000 and ISO 37301?

ISO 31000 is guidance on managing risk of any kind and cannot be certified. ISO 37301 sets certifiable requirements for a compliance management system — the obligations register, the compliance function, culture, and the governance around it. Most organisations use ISO 31000 as the risk method inside an ISO 37301-shaped compliance program.

How should compliance risk appetite be expressed?

Separate zero-appetite categories from residual risk tolerance. There is no appetite for deliberate breach of a criminal provision, but there is a tolerance for residual risk after proportionate controls. State which categories are zero appetite, express tolerance for the rest, and name who may accept residual risk at each level.

What makes a compliance risk register defensible after an incident?

Version history and control testing evidence. The questions asked after an incident are what you knew, when you knew it, and what you did. A versioned register shows the risk position at a point in time, and tested control effectiveness ratings support the residual assessment you relied on.

How often should compliance risks be reviewed?

Set a cadence by risk tier and add trigger-based review. An annual refresh alone is insufficient: material change — a new product or jurisdiction, a legislative amendment, an incident, a regulator action against a peer — should force reassessment between scheduled cycles.

Related

Related reading