KITE 2025 New Product Award — Local IT | SACEEC
Risk

ISO 31000:2018, implemented as a working process

ISO 31000 is a guideline rather than a certifiable standard, which is exactly why it is so often adopted in name and not in practice. Dimeri implements its three parts directly: the principles that shape the approach, the framework that embeds it, and the process that runs it cycle after cycle.

What ISO 31000 sets out

ISO 31000:2018 gives guidelines for managing risk faced by organisations of any size in any sector. It is deliberately not a management system standard, which means there is no certification against it. What it offers instead is a coherent way of thinking about risk that can be applied to strategy, operations, projects and programmes without being rewritten for each.

The standard has three parts that build on one another. The principles describe what good risk management looks like: it is integrated, structured and comprehensive, customised, inclusive, dynamic, based on the best available information, takes human and cultural factors into account, and improves continually. The framework is about embedding, and turns on leadership and commitment followed by design, implementation, evaluation and improvement. The process is the operational cycle: communication and consultation, establishing scope, context and criteria, risk assessment in its three steps of identification, analysis and evaluation, risk treatment, monitoring and review, and recording and reporting.

The 2018 revision made two changes that matter in practice. It put leadership and commitment at the centre of the framework rather than treating risk management as a specialist function operating to one side, and it made integration with the organisation's governance and decision making explicit. Both are hard to demonstrate when risk lives in a spreadsheet that the executive sees once a quarter.

The process Dimeri implements

Dimeri follows the clause structure of the standard directly, so a register built in the platform maps onto ISO 31000 without translation.

Clause 4

Principles

Risk management that is integrated, structured and comprehensive, customised, inclusive, dynamic, informed, human aware and continually improving.

  • Register structure customised to your context
  • Inclusive input from line functions rather than central drafting
  • Dynamic capture of emerging risk between cycles
  • Improvement actions tracked on the process itself
Clause 5

Framework and leadership

Leadership and commitment expressed through a mandate, policy, allocated resources and defined accountabilities, then designed, implemented, evaluated and improved.

  • Risk policy and mandate held with review dates
  • Accountabilities assigned to named individuals
  • Framework evaluation recorded against its own criteria
  • Improvement actions with owners and due dates
Clause 6.3

Scope, context and criteria

Defining the scope of each risk activity, understanding external and internal context, and setting the criteria that determine what is significant.

  • Scope statement held against each assessment
  • External and internal context factors recorded
  • Configurable likelihood and consequence criteria
  • Appetite and tolerance thresholds applied per category
Clause 6.4

Risk assessment

Identification, analysis and evaluation, treated as three distinct steps rather than a single scoring exercise.

  • Identification capturing sources, events and consequences
  • Analysis of likelihood, consequence and control effectiveness
  • Evaluation against criteria to decide what needs treatment
  • Inherent and residual positions held separately
Clause 6.5

Risk treatment

Selecting and implementing treatment options, then assessing the residual risk and deciding whether it is tolerable.

  • Treatment option recorded with its rationale
  • Treatment plans with owners, dates and cost
  • Residual assessment after implementation
  • Secondary risks introduced by treatment captured
Clauses 6.6 and 6.7

Monitoring, review, recording and reporting

Planned monitoring and review of the process and outcomes, with recording and reporting that reaches decision makers.

  • Review schedules per risk and per control
  • Key risk indicators with thresholds and trends
  • Complete audit trail of who changed what and when
  • Reporting tailored to board, committee and management

How Dimeri covers ISO 31000

The gap between adopting ISO 31000 and operating it is almost always clause 6.7, recording and reporting, and clause 5, leadership and integration. Dimeri closes both by construction.

Recording and reporting as a by-product

Clause 6.7 expects records that support reporting and preserve the basis of decisions. In Dimeri every assessment, rating change and treatment decision is recorded with its author and date automatically, so the record exists without anyone maintaining it.

Integrated with decisions, not parallel to them

Project risks, compliance obligations, audit findings and business continuity all sit in the same register with the same criteria. Risk stops being a separate exercise that runs alongside the organisation's decisions.

Customised without being bespoke

Criteria, scales, categories and appetite are configured to your context, which is what clause 4 asks for, while the underlying structure stays consistent enough to report across the organisation.

Shared with COSO ERM and the PSRMF

Organisations working to more than one risk framework map the control once. An assessment that satisfies ISO 31000 clause 6.4 also satisfies the corresponding PSRMF and COSO ERM expectations, with each scorecard reflecting it.

Implementing ISO 31000 in Dimeri

  1. 1

    Set the framework

    The risk policy, mandate and accountabilities are loaded, and the criteria that determine significance are configured to your context rather than to a default scale.

  2. 2

    Run the first assessment properly

    Identification, analysis and evaluation are run as three steps. Most registers inherited from spreadsheets collapse them into one, which is why they produce ratings nobody can explain six months later.

  3. 3

    Treat and track

    Treatment options are recorded with their rationale and turned into actions with owners and dates. Residual positions are reassessed after implementation rather than assumed.

  4. 4

    Monitor, review and improve

    Review schedules and indicators run continuously, and the improvement actions from clause 5.7 are tracked against the risk management framework itself, not only against individual risks.

ISO 31000 questions

Can we get certified against ISO 31000?

No. ISO 31000 provides guidelines rather than requirements, and it is not a certifiable management system standard in the way ISO 9001 or ISO 27001 are. Organisations demonstrate alignment through the quality of their framework and process, and through independent assessment such as internal audit, rather than through a certificate.

What changed in the 2018 edition?

The 2018 revision simplified the standard considerably and moved leadership and commitment to the centre of the framework, with a stronger emphasis on integrating risk management into governance and decision making. The process steps were also clarified, including making recording and reporting an explicit part of the process rather than an afterthought.

Should we use ISO 31000 or COSO ERM?

They answer slightly different questions. ISO 31000 is a concise, sector neutral guideline that works well as the operating method for a risk function. COSO ERM 2017 is more detailed and more explicitly tied to strategy and performance, which suits organisations whose board wants risk framed in those terms. Many organisations run both, and Dimeri maps controls once across the two.

Does Dimeri support our own risk scoring scales?

Yes. Likelihood and consequence criteria, the number of levels, the labels, appetite and tolerance thresholds and category specific scales are all configurable. Clause 4 explicitly asks for the framework to be customised to the organisation, so a fixed scale would work against the standard.

Is this a substitute for the standard itself?

No. This page describes how Dimeri implements the ISO 31000 process. The standard is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to work to it.

Put ISO 31000 on one register

Every requirement mapped to a control with a named owner, the evidence held against it, and one view of where you stand.