International guidelines for the principles, framework and process of managing risk across an organisation.
How enterprise risk is identified, analysed, evaluated, treated, monitored and reported — and how risk management is integrated into governance and decision-making rather than run as a separate exercise.
ISO 31000 is a guideline standard. Organisations cannot be certified against it — it informs how risk is managed, not a pass/fail outcome.