What is ISO 31000?
ISO 31000 provides principles and generic guidelines on risk management, helping organisations of all types integrate risk-informed decision-making into governance, strategy and operations.
Benefits of Certification
- โEmbed structured risk-based decision-making
- โImprove resilience and opportunity capture
- โStrengthen governance and accountability
- โSupport strategic and operational planning
- โEnhance stakeholder confidence
Scope
Applicable to all organisations and can be applied to any activity, decision or function where risk needs to be managed.
Who it applies to
- โAll sectors and organisation types
- โFinancial & insurance
- โInfrastructure & utilities
- โPublic sector & governance
- โManufacturing & supply chain
- โProfessional services
What the scope covers
- โธRisk management framework and leadership
- โธIntegration into governance and processes
- โธRisk identification, analysis and evaluation
- โธRisk treatment and monitoring
- โธCommunication and consultation
- โธContinual improvement of the framework
Key Requirements
- โธRisk management framework and leadership
- โธIntegration into governance and processes
- โธRisk assessment: identification, analysis, evaluation
- โธRisk treatment and monitoring
- โธCommunication and consultation
- โธContinual improvement of the framework
Certification Process
- 1
Application & Quotation
Submit your details and receive a tailored, fixed-price quotation based on scope, sites and headcount.
- 2
Gap Analysis (Optional)
An optional pre-audit review identifies gaps between your current practices and the standard.
- 3
Stage 1 Audit
Documentation review to confirm your management system is designed and ready for assessment.
- 4
Stage 2 Audit
On-site (or remote) assessment of the implementation and effectiveness of your system.
- 5
Certification Decision
An independent technical review leads to the certification decision and issue of your certificate.
- 6
Surveillance & Renewal
Annual surveillance audits maintain your certification over the three-year cycle before recertification.
Documents Required
- ๐Company registration / incorporation details
- ๐Organisation chart and list of sites
- ๐Scope statement of activities
- ๐Management system manual / documented information
- ๐Key policies and procedures relevant to the standard
- ๐Records demonstrating implementation (audits, reviews, training)
Frequently Asked Questions
How long does ISO 31000 certification take?
Typical timelines range from 4 to 12 weeks depending on the size of your organisation, the number of sites and how mature your existing management system is.
How long is a ISO 31000 certificate valid?
Certificates are issued for a three-year cycle, subject to successful annual surveillance audits, after which recertification renews the cycle.
Can the audit be conducted remotely?
Yes. Where appropriate, UKCTL can conduct Stage 1 and parts of Stage 2 remotely, combined with on-site verification as required.
Is ISO 31000 certification accredited?
UKCTL issues accredited certificates recognised internationally, giving your customers and stakeholders confidence in the assessment.
Get ISO 31000 certified with UKCTL
Apply Now