ISO 31000 is intended to be a family of standards relating to risk management but my question is, beyond being another risk management standard - there are many already - how important is it to businesses and what types of organisations and in what circumstances is it likely to be applied?
|
0
|
ISO 31000 was published in 2009 as an internationally agreed standard for the implementation of risk management principles, and provides generic guidelines for the design, implementation and maintenance of risk management processes throughout an organisation. ISO 31000 also describes the components of a risk management implementation framework. It includes the essential steps in the implementation and ongoing support of the risk management process. The initial component of the ISO 31000 framework is ‘mandate and commitment’ by the Board and this is followed by:
ISO 31000 is to be applied within existing management systems, formalising and improving risk management processes as opposed to replacing existing risk management practices. As a result, attention is to be given to integrating existing risk management processes addressed in the standard. The focus of many ISO 31000 programmes have centred on:
|
||
|
|