ISO 31000 gives organizations a common approach to managing risk of any kind. Our compliance certification independently audits how your organization applies the ISO 31000 principles, framework and process, and issues a USGSR Certificate of Compliance where the evidence shows alignment.
ISO 31000 is a guidance standard. This is a compliance certification issued by US Global Standards Registrars confirming alignment with ISO 31000 guidelines at the time of audit. It is not an accredited management system certification. If stakeholders require accredited certification of a risk-based system, consider ISO 9001, ISO/IEC 27001, ISO 22301 or ISO 37001.
What We Audit
| Element | What the auditor looks for |
|---|---|
| Principles | Integrated, structured, customized, inclusive, dynamic risk management based on the best available information |
| Framework | Leadership commitment, integration into governance and decisions, evaluation and improvement |
| Process | Context and criteria; risk identification, analysis and evaluation; treatment; monitoring; reporting |
Who It Suits
Boards and executive teams, organizations building enterprise risk management, public-sector bodies and project-based organizations.
The Certification Process
- Application: share your scope, sites and headcount; we confirm the route and audit time.
- Proposal and agreement: written proposal and certification agreement.
- Stage 1 audit: documentation and readiness review.
- Stage 2 audit: on-site evaluation of implementation and effectiveness.
- Certification decision: made by a competent reviewer who was not on the audit.
- Surveillance and recertification: annual surveillance, recertification every three years.
FAQs
Can my organization be certified to ISO 31000?
Accredited certification is not available because ISO 31000 contains guidelines rather than requirements. We offer ISO 31000 compliance certification confirming your risk management aligns with the guidelines.
What is the difference between ISO 31000 and IEC 31010?
ISO 31000 sets out principles, framework and process. IEC 31010 describes risk assessment techniques.