Guest Post by Greg Hutchins (first posted on CERM ® RISK INSIGHTS – reposted here with permission)
ISO 31000 is organized around 11 risk management principles. A management principle refers to a fundamental idea, rule, or truth about a subject. ISO 31000 risk principles serve as the guideline, method, logic, design, and implementation for the risk management framework and its process.
ISO 31000 does not specify how the principles can be used to design, implement, and assure a risk management process. ISO 31000 believes an organization should apply and tailor these principles to the organizational context. ISO 31000 as a guidance document is applicable to all organizations and may be used with any product or service.
The eleven risk management principles are:
- Risk management establishes and sustains value.
- Risk management is an integral part of all organizational processes.
- Risk management is part of decision making.
- Risk management explicitly addresses uncertainty.
- Risk management is systematic, structured, and timely.
- Risk management is based on the best available information.
- Risk management is tailored.
- Risk management takes human and cultural factors into account.
- Risk management is transparent and inclusive.
- Risk management is dynamic, iterative, and responsive to change.
- Risk management facilitates continual improvement of the organization.
Many of us still think about ‘shall’ clauses as the basis for the design of a process or to demonstrate compliance. ISO 31000 is different. It is more principles based. It is more discretionary. It requires deep knowledge of risk management and context.
The successful implementation of these risk management principles will determine the design, implementation, and assurance of an effective ISO 31000 risk management process.