MarketplaceGRCISO 31000
GRCStandard

ISO 31000

ISO 31000:2018 Risk management — Guidelines

ISO 31000:2018 is an international standard providing principles and guidelines for risk management across organizations. It outlines processes for identifying, analyzing, evaluating, monitoring, and communicating risks, helping entities manage uncertainty proactively.

Overview

ISO 31000:2018 serves as a comprehensive framework for risk management, applicable to any organization regardless of size or sector. The standard emphasizes embedding risk management into governance, strategy, and operations, fostering proactive identification and mitigation of risks. While it is not a certifiable standard, ISO 31000 provides valuable tools for benchmarking an organization's risk management practices, enhancing decision-making and stakeholder confidence. Key elements include guidance on the principles of risk management, criteria for monitoring and improvement, and frameworks for integrating risk management into organizational processes.

Related in GRC

GRCStandard

National Principles of Child Safe Organisations

The National Principles for Child Safe Organisations outline ten core principles aimed at creating a child-safe culture within organisations that work with children. They provide a nationally consistent approach to promoting child safety and wellbeing.

Australian Government • Australia • v2025

View details
GRCFramework

COBIT 5 — COBIT 5

COBIT 5 is a comprehensive framework for the governance and management of enterprise IT, designed to maximize the value organizations derive from their information systems. It incorporates principles, practices, and tools to align IT with business strategies and goals.

ISACA • Global • v5

View details
GRCLaw

Sex Discrimination Act 1984

A federal law enacted by the Australian Government to eliminate discrimination on the basis of sex, gender identity, sexual orientation, marital status, pregnancy, or family responsibilities. It also addresses sexual harassment and outlines protections in employment, education, goods and services, and public programs.

Attorney-General's Department • Australia • v1 January 2014

View details
GRCLaw

South Africa Electronic Communications and Transactions Act 25 of 2002

The Electronic Communications and Transactions Act 25 of 2002 establishes legal and policy frameworks for regulating electronic communications and transactions in South Africa. It aims to facilitate universal access to electronic services, prevent abuse of information systems, and promote the use of e-government services and small business technology adoption.

Government of South Africa • South Africa

View details

Ready to manage these frameworks?

6clicks maps regulations to controls, evidence and risks — automatically.

Book your strategy call