Fecha de registro: 13 may 2022

The goal of ISO 31000 is to provide guidance to practitioners for the development of a comprehensive and consistent set of risk management practices. ISO 31000 provides guidance to 'risk managers' and to people working within organisations engaged in risk management. ISO 31000:2018 supports the ISO 31000:2007 standard as a foundation on which to build a comprehensive set of risk management practices. It also builds on that foundation and extends it to include new sections on: Good practices in risk management, Risk assessment, Risk management and Information security. ISO 31000:2018 also brings together a number of complementary standards from other international and national standards organisations such as BS EN ISO/IEC Guide 73:2007 on risk analysis for non-life-critical products and systems, AIAG Risk Management (ISO/IEC 27002) Standard, NACE standard for the Risk Management of Quality Systems for Offshore Industries, ASTM standard for the Risk Analysis of Clinical Equipment and Good Laboratory Practice. Elements of ISO 31000 risk management ISO 31000:2018 provides guidance on: Standard requirements for risk management and requirements for an appropriate management system Risk assessment Risk analysis Risk response and risk management Risk communication and reporting Risk management Internal control Contingency planning Note: If the organisation is engaged in 'Quality Management', ISO/IEC Guide 73:2007 should be applied as a complementary standard. ISO 31000 identifies four key elements that must be in place to ensure that an organisation is managing its risk effectively. The four elements of risk management are: Risk Response Risk Assessment The first element of an effective risk management process is an understanding of the risks. This must be undertaken through risk assessment, to ensure that the risk is properly assessed and identified before a response is put in place. The risk must be assessed at a number of different levels within an organisation including: at strategic level at operational level at individual organisational unit level Risk assessment is a formal activity designed to identify the risk and assess the likelihood and consequences of the risk occurring. The risk assessment should be carried out as a continuous process which enables the organisation to adapt its management of risks to new information and changing circumstances. Risk Response The second element of risk management is risk response. This involves the selection, implementation and measurement of responses, to reduce or eliminate the identified risks. The response must be




