KITE 2025 New Product Award โ€” Local IT | SACEEC
Risk

ISO 31000 coverage that turns principles into practice

Principles, framework and process implemented as one operating cycle, with every assessment, treatment decision and review recorded automatically.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What ISO 31000 sets out

Three-step assessment built in

Identification, analysis and evaluation run as distinct steps rather than a single scoring exercise, capturing sources, events and consequences before likelihood and impact are applied.

Treatment that closes and is measured

Treatment options carry owners, dates and cost. Residual positions are reassessed after implementation rather than assumed.

Recording and reporting by default

Every assessment, rating change and treatment decision is recorded with its author and date automatically. The audit trail exists without anyone maintaining it.

Shared credit across risk frameworks

An assessment that satisfies ISO 31000 also satisfies PSRMF and COSO ERM expectations. Dimeri records it once and reflects it in each scorecard.

ISO 31000 compliance, covered by default

ISO 31000 is adopted more often than it is used. Dimeri closes the gap by implementing its three parts directly. The principles shape the approach, the framework embeds it, and the process runs cycle after cycle.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Aligned to the standard

The platform follows the structure of ISO 31000 directly, from scope, context and criteria through identification, analysis and evaluation to treatment, monitoring and reporting, so the register maps onto the standard without translation.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Three-step assessment

Identification, analysis and evaluation run as three distinct steps rather than a single scoring exercise, capturing sources, events and consequences before likelihood and impact are applied.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Leadership integration

Risk policy, mandate and accountabilities held with review dates, and risk information embedded in the same registers as strategy and operations, the integration the 2018 revision calls for.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Treatment tracking

Treatment options recorded with their rationale, turned into actions with owners and dates, and residual positions reassessed after implementation rather than assumed.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Recording and reporting by default

Every assessment, rating change and treatment decision recorded with its author and date automatically. Recording and reporting handled as a by-product, not a separate effort.

The process Dimeri implements

Dimeri follows the clause structure of the standard directly, so a register built in the platform maps onto ISO 31000 without translation.

Principles

Principles

Risk management that is integrated, structured and comprehensive, customised, inclusive, dynamic, informed, human aware and continually improving.

  • Register structure customised to your context
  • Inclusive input from line functions rather than central drafting
  • Dynamic capture of emerging risk between cycles
  • Improvement actions tracked on the process itself
Framework

Framework and leadership

Leadership and commitment expressed through a mandate, policy, allocated resources and defined accountabilities, then designed, implemented, evaluated and improved.

  • Risk policy and mandate held with review dates
  • Accountabilities assigned to named individuals
  • Framework evaluation recorded against its own criteria
  • Improvement actions with owners and due dates
Scope and context

Scope, context and criteria

Defining the scope of each risk activity, understanding external and internal context, and setting the criteria that determine what is significant.

  • Scope statement held against each assessment
  • External and internal context factors recorded
  • Configurable likelihood and consequence criteria
  • Appetite and tolerance thresholds applied per category
Assessment

Risk assessment

Identification, analysis and evaluation, treated as three distinct steps rather than a single scoring exercise.

  • Identification capturing sources, events and consequences
  • Analysis of likelihood, consequence and control effectiveness
  • Evaluation against criteria to decide what needs treatment
  • Inherent and residual positions held separately
Treatment

Risk treatment

Selecting and implementing treatment options, then assessing the residual risk and deciding whether it is tolerable.

  • Treatment option recorded with its rationale
  • Treatment plans with owners, dates and cost
  • Residual assessment after implementation
  • Secondary risks introduced by treatment captured
Monitoring and reporting

Monitoring, review, recording and reporting

Planned monitoring and review of the process and outcomes, with recording and reporting that reaches decision makers.

  • Review schedules per risk and per control
  • Key risk indicators with thresholds and trends
  • Complete audit trail of who changed what and when
  • Reporting tailored to board, committee and management

Getting ISO 31000 coverage in place

4 steps from where you are today to a ISO 31000 position your auditor can rely on.

Book a demo

The risk policy, mandate and accountabilities are loaded, and the criteria that determine significance are configured to your context rather than to a default scale.

How Dimeri covers ISO 31000

Recording and reporting as a by-product

ISO 31000 expects records that support reporting and preserve the basis of decisions. In Dimeri every assessment, rating change and treatment decision is recorded with its author and date automatically, so the record exists without anyone maintaining it.

Integrated with decisions, not parallel to them

Project risks, compliance obligations, audit findings and business continuity all sit in the same register with the same criteria. Risk stops being a separate exercise that runs alongside the organisation's decisions.

Customised without being bespoke

Criteria, scales, categories and appetite are configured to your context, which is what the standard's principles ask for, while the underlying structure stays consistent enough to report across the organisation.

ISO 31000 questions

Can we get certified against ISO 31000?

No. ISO 31000 provides guidelines rather than requirements, and it is not a certifiable management system standard in the way ISO 9001 or ISO 27001 are. Organisations demonstrate alignment through the quality of their framework and process, and through independent assessment such as internal audit, rather than through a certificate.

What changed in the 2018 edition?

The 2018 revision simplified the standard considerably and moved leadership and commitment to the centre of the framework, with a stronger emphasis on integrating risk management into governance and decision making. The process steps were also clarified, including making recording and reporting an explicit part of the process rather than an afterthought.

Should we use ISO 31000 or COSO ERM?

They answer slightly different questions. ISO 31000 is a concise, sector neutral guideline that works well as the operating method for a risk function. COSO ERM 2017 is more detailed and more explicitly tied to strategy and performance, which suits organisations whose board wants risk framed in those terms. Many organisations run both, and Dimeri maps controls once across the two.

Does Dimeri support our own risk scoring scales?

Yes. Likelihood and consequence criteria, the number of levels, the labels, appetite and tolerance thresholds and category specific scales are all configurable. The standard explicitly asks for the framework to be customised to the organisation, so a fixed scale would work against it.

Is this a substitute for the standard itself?

No. This page describes how Dimeri implements the ISO 31000 process. The standard is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to work to it.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.